4 ms·
If espionage is a concern, you first have to handle the low lying fruits (and I'd assume you already do) like you only allow your own hardware: no employee may
by minot 6y ago
If espionage is a concern, you first have to handle the low lying fruits (and I'd assume you already do) like you only allow your own hardware: no employee may use their own computer to connect to work.
You should probably also require hardware keys and things like that but really I'd think it all depends on how much an adversary wants your stuff because I'd assume at some point it becomes viable to just send someone to work for you and steal your stuff.
- raxxorrax 6y agoI am not suggesting to be that diligent, but yes, for some industries it might be the way to go. But I don't think these are low hanging fruits compared to using SaaS or cloud services on the net. There are real additional risks when using these.
- minot 6y agoAbsolutely. If you go by the marketing, all of aws staff is now potentially working for you when you use aws. You could say this means if any of the aws employees is compromised, so are you. As a contractor, all my code goes through a code review from one of the employees. I only have access to the development environment (even qa is off limits except the publicly available stuff). It is all on azure though. I think it is fine for must work done by peons like me. I once used an application to take a screenshot of the while display every minute (on my own computer) and it amazes me that the application didn't need root at all on Windows. In short, I agree that you should avoid the public cloud for sensitive work but you should probably do a lot more (even regular training?)