3 ms·
I don't understand the threats, risk, or solution here.
by animationwill 6y ago
I don't understand the threats, risk, or solution here.
- notatoad 6y agoi think it's just an amusing anecdote because phones aren't usually bolted to tables.
- tylerchilds 6y ago> I don't understand the threats, risk, or solution here. john_travolta.gif
- BeaglePlaza 6y agoThreat is that the mobile devices could be used to 1) photograph proprietary systems, 2) exfil data over mobile networks or potentially introduce 3) malware via usb ports. I don't really get how bolting the devices is a solution for enabling 2FA, unless the access console is also at the same location. But it would prevent 1) and 3).
- f0ff 6y agoAs long as the table is bolted to the floor, you're replacing posession (of a phone) factor, with location (in SOC) factor. Keeps both client happy, and security architect sleeping soundly. Nice solution.
- Dylan16807 6y agoYou look at the code and then you walk back to your desk to enter it.
- phlo 6y agoThe threat actors are SOC employees or visitors who might (maliciously or unwittingly) use their smartphones to record sensitive data. The risk is data exfiltration. A selfie in front of the SOCs giant screen wall; a compromised phone that keeps recording audio. The problem is that a third-party SOC will generally need a way to connect to their customers' systems. Sometimes that gets properly implemented as a site-to-site VPN with isolated jump hosts and session recording. In other instances, the SOC gets to use normal employee VPN access, and usually a handful of VPN tokens. And now you have a fun conflict: One customer insists that no mobile phones are carried inside the secure SOC area. Another uses a VPN solution that requires a smartphone (and, e.g. Duo Push) as the second factor. How do you satisfy both? You take a set of mobile phones, possibly add some measures to stop them from being used as recording devices, and bolt them to a table so they can't leave the secure area.