8 ms·
Using Brave's “Private Window with Tor” could get you fired
- Lordarminius 5y agoI skimmed through the reddit thread but couldn't find an answer. Why do companies not want you using Tor ?
- nitrogen 5y agoSpeculation: it looks a lot like a data exfiltration attempt, or like malware trying to reach its control network. Just don't do things unrelated to work using work resources.
- smoldesu 5y agoThis is definitely the case. Most of these people are worried about you ferreting away company secrets over a connection they cannot monitor.
- chasil 5y agoI've never used Onionshare, but it would allow untraceable file transfers bidirectionally through any (permitting) corporate firewall, and keybridging/mitm cert rewrites could not see into the session. https://onionshare.org/ https://onionshare.org/
- JohnTHaller 5y agoTor enables content that work can't monitor or block. And it's associated with child porn, dark web drug networks, sex trafficking, and similar. In reality, it's a small part of Tor. In the media, that's all it's used for.
- judge2020 5y agoThe biggest use statistically is bot and malicious traffic. > Based on data across the CloudFlare network, 94% of requests that we see across the Tor network are per se malicious. https://blog.cloudflare.com/the-trouble-with-tor/#:~:text=Based%20on%20data%20across%20the%20CloudFlare%20network%2C%2094%25%20of%20requests%20that%20we%20see%20across%20the%20Tor%20network%20are%20per%20se%20malicious https://blog.cloudflare.com/the-trouble-with-tor/#:~:text=Ba....
- btdmaster 5y agoThis needs to be compared to clearnet for it to paint an accurate picture, which has reached 64% recently[1]. Though this figure comes from summing "good bots" with "bad bots", Cloudflare seems to have done the same ("automated requests", "content scraping"). [1] https://www.digit.fyi/two-thirds-of-internet-traffic-is-now-made-up-of-bots/ https://www.digit.fyi/two-thirds-of-internet-traffic-is-now-...
- brendoelfrendo 5y agoEvery company I've worked for has had DLP, firewalls, and content filtering in place, and circumventing those is a violation of acceptable use policies, and thus grounds for termination... so it seems pretty cut and dry to me.
- Veen 5y agoThe initial post mentions FUD and top-level management, so it's possible management associate Tor with dark net drug dealing, CP, and assinations and so on. Non-tech people aren't likely to have heard of Tor in any other context.
- RF_Savage 5y agoMalware and other attackers use Tor for C&C. So blocking Tor hinders attackers using it.
- 8organicbits 5y agoIn my brush with a similar issue, the intrusion detection system flagged Tor traffic as potential malicious traffic. The IDS can't tell if this is malware calling back to a command and control node via Tor. We allow developers to install their own software, so there isn't a good way to enforce browser policies. We ended up letting the developers know that connections to Tor generate alerts, and that these tie up security resources. That was enough that we haven't seen the issue again. In our case the developer was using Brave and had opened the private window with Tor. That gave us a plausible explanation that didn't include malware, so we closed the ticket. I'd say that there are very few legitimate reasons a Tor connection would come from a corporate network. So we'd like to keep the alert on, but any false positives tie up resources. Developers sometimes accidentally install malware, so we need to be vigilant about detecting and remediating that.
- JohnTHaller 5y agoIn the interim, have the IT folks setup a group policy to disable Brave's Tor feature so no one else accidentally gets caught in this: https://support.brave.com/hc/en-us/articles/360039248271-Group-Policy https://support.brave.com/hc/en-us/articles/360039248271-Gro...
- GekkePrutser 5y agoBut would you if it isn't even an allowed application in the first place?
- jp42 5y agoIts not allowed to installed in my company since long time.
- kgwxd 5y agoI once triggered my domain account and PC intranet connection to be disabled because I started a Linux ISO download via BitTorrent. I didn't get in any trouble. Assuming this is even real, it's obviously just an example of bad management or there's more to the firing than what's being said.
- Symbiote 5y agoI was "caught" torrenting Knoppix on a university computer. I had left it running in the background, and not realised it wouldn't exit when I logged off. After I'd shown what it was, the sysadmins suggested leaving it seeding to see if we could get the university domain name to the top of the "top seeders" list.
- 0xdeadb00f 5y agoWhen I started my CS degree they specifically made a point to say "Do not use bittorrent. Even for legitimate uses like Linux ISOs, you will get in trouble with the IT dept"
- charcircuit 5y agoWhat's next? Using https could get you fired because they can't MITM you?
- zo1 5y agoMost of them use group-policies and other software to install root-certs onto company devices. HTTPS won't help you with MITM in that case.
- Scoundreller 5y agoIt was good while it lasted tho. Fun times getting blocked by the public/corporate firewall for something, hovering the mouse in the right place and pressing “s” and going, ahhh, “fixed it!”
- PopeUrbanX 5y agoDon't browsers these days loudly warn you if something like that is happening?
- watermelon0 5y agoMost browsers (with the exception of Firefox which has its own store) trust root certificates installed on the OS (at least for Windows/Linux/macOS.) With mobile devices (iOS/Android), web browsers also trust custom root certificates, but apps have the ability to reject them.
- GekkePrutser 5y agoFirefox on Windows can also be configured to use the system store. Most corporate admins would do this because it makes for only having to manage them in one place. On Mac it can't though, and on Linux there isn't really a definitive system one (unless you consider OpenSSL's).
- GekkePrutser 5y agoNo not if the cert is preloaded into the system store or browser. However mobile platforms are more finicky now. For example in Android 7 and above you can no longer add certs to the system store in most management modes. Only to the user store. And apps can choose whether to obey the user store or not. So many apps then refuse to work. There's a few management modes that do allow it but they require a full wipe to start the enrollment process which starts from the setup wizard.
- jpollock 5y agoThere are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their own apps for regulated communications just cost JPMorgan USD$200m. https://www.cnbc.com/2021/12/17/jpmorgan-agrees-to-125-million-fine-for-letting-employees-use-whatsapp-to-evade-regulators.html https://www.cnbc.com/2021/12/17/jpmorgan-agrees-to-125-milli...
- oyashirochama 5y agoImagine not having a key logger and mouse tracer on your computer at work. Our machines also lock your account, computer and ID if you plug mass storage devices.
- GekkePrutser 5y agoWhat good will a mouse tracer do without context of what's on screen? Never heard this being put in place for workplace surveillance. Complete screen recording yes but just mouse (or even keyboard which does make some sense) no
- ivraatiems 5y agoIt's absolutely reasonable to have security requirements. It's not reasonable to fire someone for a single, accidental violation. I hope the people in the above story realize that they've made a mistake.
- floatingatoll 5y agoIt is if you have a zero-tolerance policy and they break it. Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware! But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people. There’s a popular view with some freedom folks that we shouldn’t have the right to search people who are visiting family in jail, and while they’re right from a purely theoretical “my rights” standpoint, from a pragmatic stance it is generally understood that it’s fair to try not to let weapons be given from visitors to criminals, even if abrogation of rights occurs — and if you forget and bring a knife someday, you may get banned from the jail, even though it’s just a mistake, because of how serious the safety and lives are at stake.
- donatj 5y agoMy company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-Home started, Brave’s Tor support was a godsend just for getting actual work done. Before my department got bought out, our old company had pretty draconian blocking as well, but if you explicitly plugged into the ethernet ports in the developer area they were wide open. And no, we’re not in any sort of industry where it really matters. Privately held educational software company.
- benttoothpaste 5y agoI used to work for a financial company that used such extensive blocking. One day I had to download a particular version of boost libraries (the C++ ones). Of course all official sites to download from were blocked. So I searched for the specific file name (a tar.gz archive). And eventually I found something that was not blocked: a misconfigured server somewhere in Russia. Misconfigured because it served entire contents of its hard disk - and Google indexed it all. And there it was - my coveted boost archive which I promptly downloaded.
- gruez 5y agoThat seems super risky. How did you know the file was authentic? What if the archive contains backdoored code?
- renewiltord 5y agoWell, it appears to be over zealous management. One might as well say “eating at your desk can get you fired”. The problem isn’t the eating. It’s the management.
- mindslight 5y agoOne of the few comments in this thread that isn't rooted in Stockholm syndrome. Sure, it's prudent to do one's personal computing on personal devices - get a personal laptop or a GPD pocket or something like it for use at work, and only use their uplink via a wireguard link to something else you control (and/or get a cell modem). But management that fires people for using a protocol, and furthermore for using it incidentally? It makes me want to publish everything I do as onion only.
- actually_a_dog 5y agoYeah, the level of idiocy here is almost as high as in the "reporter may be prosecuted for using 'view source'" article.
- yokoprime 5y agoI can fully understand why a company doesn't want Tor traffic coming from inside the firewall. But this case, if the sort description is accurate, should have been cleared up with a conversation with the employee possibly resulting in temporarily banning Brave until they can actually deploy it in a configuration that works with company policy. Again, IF the description is accurate, the employee was using a browser allowed by IT and did not have any ill intentions.
- actually_a_dog 5y agoAccording to what I read, the manager attempted to go to bat for the employee, and basically did everything they could short of flat out refusing to fire the person. After this incident, the manager and most of the remaining devs on the team are now looking for new jobs. I can't say as I blame any of them.
- latchkey 5y agoSounds like they did the employee a favor. Who would want to work in those conditions?
- rdudek 5y agoI've been working in the IT industry way too long. Any devices provided by my employer will only have whatever the employer has preloaded in terms of software. I will not browse any private or personal things on that device. I'm under constant assumption that device is keylogged/monitored. Even when working from home, I have it connect to it's own private network on it's own VLAN. If I do go into the office, I'll just use my cell-phone for personal browsing.
- bryguy32403 5y agoI have that same mindset, but at the last two companies I've been at, I was a bit disturbed that the software policy was basically, "If you need it, just go to the website and download it. Don't download a virus, good luck!"
- zebraflask 5y agoExactly. It's the employer's property, and aren't there such things as devices you own? Why blur the lines on something like that? This reads more like an overreaction to a lapse of judgment more than anything else.