5 ms·
I don't think I've ever heard of a company that actually does this in practice. I suspect it ends up simply being more trouble than it's actually worth. I kno
by Merad 8y ago
I don't think I've ever heard of a company that actually does this in practice. I suspect it ends up simply being more trouble than it's actually worth. I know at that company the list of approved device would probably end up being dozens of pages long... and yeah, thumb drives and USB hard drives were used a decent amount, especially outside of IT.
- acct1771 8y agoAnecdote for anecdote, I have.
- sjwright 8y agoMaybe someone needs to invent a USB-based thumb drive reader that only allows generic mass storage devices to be attached but does not work as a hub, rather as a proxy device. Bonus points: don't mount the drive directly, instead connect it to a centralised server on the corporate network that scans for threats and mounts a sanitised version of the drive's contents as a network share. Triple word score: audit everything contained on every drive and everything that is copied on and off. Sell that for $200 per unit to Fortune 500 companies and paranoid government agencies worldwide... and you'll retire early.
- thecatspaw 8y agoisnt that a NAS basically?
- TheOtherHobbes 8y agoA consumer (i.e. workplace for people who don't know better) NAS is usually Linux with a few hard drives attached via a cheerful and brightly coloured web UI - occasionally useful, some way short of secure. I expect someone sells hardened ultra-secure corporate NAS boxes, but I've never seen any in the wild.
- gargravarr 8y agoThe trouble is, the sort of people who would buy a pre-hardened NAS are also the sort of people who would be suspicious of a pre-built unit. I know for sure I wouldn't trust anything off the shelf, I'd take the base OS and build something around it. Whoops, my tin-foil hat appears to have slipped.
- lllr_finger 8y agoYour triple word score is already handled by a dozen different companies doing endpoint security from advanced heuristics at the kernel level like Crowdstrike, or just filenames and hashes like Code42.
- deadmanwalking 8y agoWork at a fortune 500 company, we're currently eliminating USB ports for data devices - but leaving them open for other devices that do not identify as media. We are dragging people to a corporate cloud solution, however we are finding that the drive to cloud has severely underestimated the volume of data that people will sync across the network, and how much work is done outside official corporate systems and in Excel instead. This is having 2 effects our network capacity is being drained, and users are reporting performance issues due to latency associated with poorly developed excel applications.