3 ms·
Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction! Regarding client-side restrictions: I doubt I'll ever understan
by themulticaster 5y ago
Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction!
Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)?
My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office?
- g_p 5y ago> Oh my, your post reads like a bureaucracy horror story, but I fear it is not a work of fiction! Afraid it's not fiction. I see it pretty regularly. > Regarding client-side restrictions: I doubt I'll ever understand why many organizations appear to be so focused on restricting their employees' computers, some even going for full-blown surveillance. Several reasons I've seen. Firstly, don't underestimate the importance of protecting people's data at scale. If staff can use their Gmail on a computer, someone will email themselves someone's personal data. Maybe it won't be malicious, but it's still a breach. Maybe it was some software running on the computer (malware) that got in via an ad or game, that simply emails out information. Governments (and large enterprise) operate at a scale where you need to be careful of data exfiltration by malicious users or software. While you might be able to trust people in a team of 5, it's very hard to scale that trust up to 5000 people. > Maybe I'm just a little naive, but is intercepting and filtering all network traffic really the only way to notice whether an employee is playing browser games all day (instead of, you know, noticing the employee's productivity dropping)? This implies that the person's manager is competent enough to actually notice this, and has enough understanding of what they do to act. Filtering network traffic is often more about preventing data egress of other people's personal information than it is about spotting someone playing candy crush. > My primary concern that those enterprise firewalls intercepting all traffic (including MitM-ing TLS traffic) regularly prevent adoption of new Internet standards. At the same time, the idea of total communication surveillance seems surreal. Image the equivalent situation 20-30 years ago: What would you have said if your employer hired a team in order to eavesdrop on every single telephone call and open every single letter entering or leaving the office? In financial services and other regulated sectors, they pretty much did/do that, albeit recorded rather than having someone listen all day long. I agree with you that these kinds of active MITM firewalls likely introduce more issues than they solve - many don't themselves validate the certificate of the site they're MITM'ing properly, therefore introducing a whole new attack vector if you can convince the MITM box to serve up a valid certificate for your site's invalid certificate. Unfortunately though, for as long as the goal is to make it possible to work at big scale and minimise the risk posed by individual employees, you'll continue to see this be the default way of working, I reckon.