3 ms·
> If the experience of the procuring department is that "BSI finds everything is insecure", then you procure without letting BSI know or have a say in it, and t
by themulticaster 5y ago
> If the experience of the procuring department is that "BSI finds everything is insecure", then you procure without letting BSI know or have a say in it, and then you look good for getting the procurement completed.
Sounds plausible. Especially looking at years of (German) data protection officials recommending against using Windows 10/Office 365 in government agencies, followed by officials explaining that only Microsoft's products are able to fulfill their "extremely complicated requirements".
I'm not entirely convinced that only Windows 10 has the necessary features for registering a vehicle title...
- g_p 5y agoOf course it doesn't! I've yet to meet a procurement team that actually understands what they are buying. Companies like Microsoft focus heavily on "training" and "awareness" of their products and solutions - pure slideware, but speaking the right language. At enterprise-scale, I must concede that Microsoft have a really sleek sales pitch. Group Policy in AD offers a level of "managed desktop" that a low-pay, mid-skill sysadmin can operate. That lets you set and enforce "policies", and they get enforced on the computers, and this is something that entirely non-technical senior managers can understand and feel confident in. Any OS could be used to register a vehicle title, but MS' option gives you a fleet of relatively cheap and accessible talent with an "official certification" (MCSP or whatever it has become) - governments love certifications, as it helps them de-risk things they don't understand. The clever enterprise vendors understand this, and try to ensure the market is awash with "their people". It's probably controversial to say, but governments love technology that is able to be run (by-design) by hiring mediocre people to run it. Windows Server with a shiny GUI to edit group policies and apply updates hits that spot for many organisations. I wouldn't be surprised to find the "extremely complicated requirements" for the vehicle registration government agency are the ability to run some (procured) proprietary endpoint protection client (which probably runs everything it sees unsandboxed, as NT AUTHORITY\SYSTEM [1]), and enforce a whole host of client-side restrictions (which could easily be network-layer) to prevent people using personal email on managed devices. [1] https://www.recon.cx/2018/brussels/resources/slides/RECON-BRX-2018-Reverse-Engineering-Windows-Defender-s-JavaScript-Engine.pdf https://www.recon.cx/2018/brussels/resources/slides/RECON-BR... like Windows Defender did (!)
- themulticaster 5y agoOh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction! Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)? My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office?
- g_p 5y ago> Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction! Afraid it's not fiction. I see it pretty regularly. > Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Several reasons I've seen. Firstly, don't underestimate the importance of protecting people's data at scale. If staff can use their Gmail on a computer, someone will email themselves someone's personal data. Maybe it won't be malicious, but it's still a breach. Maybe it was some software running on the computer (malware) that got in via an ad or game, that simply emails out information. Governments (and large enterprise) operate at a scale where you need to be careful of data exfiltration by malicious users or software. While you might be able to trust people in a team of 5, it's very hard to scale that trust up to 5000 people. > Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)? This implies that the person's manager is competent enough to actually notice this, and has enough understanding of what they do to act. Filtering network traffic is often more about preventing data egress of other people's personal information than it is about spotting someone playing candy crush. > My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office? In financial services and other regulated sectors, they pretty much did/do that, albeit recorded rather than having someone listen all day long. I agree with you that these kinds of active MITM firewalls likely introduce more issues than they solve - many don't themselves validate the certificate of the site they're MITM'ing properly, therefore introducing a whole new attack vector if you can convince the MITM box to serve up a valid certificate for your site's invalid certificate. Unfortunately though, for as long as the goal is to make it possible to work at big scale and minimise the risk posed by individual employees, you'll continue to see this be the default way of working, I reckon.