12 ms·
Yeah but that's because "getting things done" for many people involves stupid stuff like installing malware-infected warez copies of Photoshop because they can'
by native_samples 5y ago
Yeah but that's because "getting things done" for many people involves stupid stuff like installing malware-infected warez copies of Photoshop because they can't be bothered getting approval to expense a copy.
I used to think IT departments were dicks, until I worked at Google and went to a tech talk by their WinOps divison (what's called IT in every other firm). They were explaining why they were transitioning Windows users to binary whitelisting - literally not a single EXE runs unless it's whitelisted by IT. I thought wow, how tyrannical, that's surely a Dilbert-esque IT power trip.
And then they told us about all the stupid stuff people did with their Windows desktops. There was literally nothing so ill advised people didn't try it, and even worse, those people were sometimes very senior engineering executives. You might think such people would know better but ... no. Also, engineers aren't any more immune to phishing than anyone else, it turns out.
- p_l 5y agoPretty sure they did the same to MacOSX systems, too, with custom kernel module even
- azalemeth 5y agoIsn't the whole drive towards zero-trust network configurations to allow BYO device to work, i.e. to assume that every device will be compromised and plan accordingly? Seems much better (to me) than crippling the desktop environment of your employees and hobbling their productivity.
- thebean11 5y agoNot sure how you could accomplish that safely without crippling users in different ways