4 ms·
My client is quite reasonable, and is willing to compensate a new laptop. It took me less then a few minutes after I read the mail to come up with algorithms t
by illud_tempus 5y ago
My client is quite reasonable, and is willing to compensate a new laptop.
It took me less then a few minutes after I read the mail to come up with algorithms to implement this thing without compromising my security or privacy. VM. Using an old laptop and remove the wi-fi card. Get a new PC or laptop. Wire whatever I choose on a vlan that goes directly to a VPN server in another country.
However, I still don't like the idea of running an agent on my/a machine. It's a road I feel strongly against going down. But then, I came from a different time, when people still trusted each other and acted in good faith.
- zepolen 5y agoJust get the laptop, use it for work only. This is the best way forward. They are looking for their interests (minimize security breaches) and that's a perfectly understandable position and solution to the problem. In this day and age the risk from a breach is much larger than in the past. Since they are willing to provide the necessary equipment for that then there is no issue from your end.
- alserio 5y agoSince when a backdoor is useful to minimize security breaches?
- periheli0n 5y agoWhen you don’t trust the person on whose machine you want to install the backdoor.
- illud_tempus 5y ago> They are looking for their interests (minimize security breaches) No. This comes from the sales people. They want to provide a "SOC 2 Audited" certificate to their potential customers. They don't give a rats ass about actual security. The upper management does care about security. But I don't think this particular requirement offer much of that.
- zby 5y agoI googled "SOC 2 Audited" - and I've got: """ A SOC 2 audit is a company-wide certification that evaluates an organization's standards regarding its core data security infrastructure, information handling practices, consumer privacy, and confidentiality. For this purpose, an SOC 2 auditor needs to evaluate various aspects of a company's systems and processes """ So it is about security. I guess your point is that it is just a security theatre and not related to the real thing - but that is a different discussion. It would be a discussion about https://slatestarcodex.com/2014/07/30/meditations-on-moloch/ https://slatestarcodex.com/2014/07/30/meditations-on-moloch/ and https://www.amazon.com/Moral-Mazes-World-Corporate-Managers/dp/0199729883 https://www.amazon.com/Moral-Mazes-World-Corporate-Managers/... and etc
- justinclift 5y agoIt's trivial for software inside to VM to detect that. So, I'd expect any competent agent software to report that back to base. Whether or not the people monitoring the agent's output will care, is a different question. ;)
- sofixa 5y ago> It's trivial for software inside to VM to detect that QEMU can get you very far in masking the presence of a VM. If it can work around Nvidia's cash grab of not allowing consumer cards to be used in VMs, it should be able to deal with whatever bullshit spyware.
- justinclift 5y agoIf you run `dmidecode` inside a Linux VM running (on QEMU), do the returned strings not show extremely obvious VM-only things? When doing so on VMware or KVM, things are extremely obvious. I haven't tried just plain QEMU though. :)
- sofixa 5y agoWith QEMU you can configure that and make it say whatever you want ( which is how you can lie to an Nvidia card).
- justinclift 5y agoCool. That's definitely useful then. :)
- kevin_thibedeau 5y agoBut then you have to install an authenticator app on your phone for 2FA and they won't run on a SIM-less burner.
- GoblinSlayer 5y agoRFC 6238? It can be implemented on any hardware.
- zoomablemind 5y ago> ...My client is quite reasonable, and is willing to compensate a new laptop. I wonder, if "in the spirit and for the strength of mutual trust" would they be willing to provide you with the reports on the agent-collected data about you. Basically, the copy of how you are being shown in those dashboards. It's fairly reasonable, as you're not an employee by definition, yet such policy or a requirement to operate on client-controlled work means is an employee's realm, not an independent contractor's one. Here's IRS independent contractor test: https://www.irs.gov/businesses/small-businesses-self-employed/independent-contractor-self-employed-or-employee https://www.irs.gov/businesses/small-businesses-self-employe...
- GoblinSlayer 5y agoYou can be spied with a microphone: https://github.com/ggerganov/kbd-audio https://github.com/ggerganov/kbd-audio