7 ms·
I hate corporate IT. Security with decades old arcane practices. Killing user experience with any way possible. MITM all around..
by fsniper 3y ago
I hate corporate IT. Security with decades old arcane practices. Killing user experience with any way possible. MITM all around..
- Bluecobra 3y agoBlame viruses, malware, phishing, ransomware, etc. IT has a responsibility to keep the network secure. Google is already experimenting with no Internet access for some employees, and that might be the endgame.
- blkhawk 3y agoThis has nothing to do with security and more with ineffective practices based on security where nobody knows why its done just that its done. Running MitM on connections basically breaks basic security mechanism for some ineffective security theater. This is basically "90-day password change" 2.0.
- Spivak 3y ago> where nobody knows why its done just that its done Compliance. You think your IT dept wants to deploy this crap? How ever painful you think it is as an end user multiply it having to support hundreds/thousands of endpoints. Look, I hate traffic inspection as much as the next person but this is for security, it's just not for the security you want it to be. This is so you have an audit trail of data exfiltration and there's no way around it. You need the plaintext to do this and the whole network stack is built around making this a huge giant pain in the ass. This is one situation where soulless enterprises and users should actually be aligned. Having the ability in your OS to inspect the plaintext traffic of all incoming and outgoing traffic by forcing apps off raw sockets would be a massive win. People. seem to understand how getting the plaintext for DNS requests is beneficial to the user but not HTTP for some reason. Be happy your setup is at least opportunistic and not "block any traffic we can't get the plaintext for."
- steve_taylor 3y ago> You think your IT dept wants to deploy this crap? Yes, they do.
- bigstrat2003 3y agoNo, they really really don't. Source: I've worked in corporate IT for many years, and this kind of shit is always forced upon us just as much as it is on you guys. We hate it too.
- betaby 3y agoCompliance with exactly what? Their own rules?
- antod 3y agoNot the OP, but currently I work in a regulated industry (financial) where Corporate Risk and Legal depts ask for this stuff (and much more) to satisfy external auditors. The IT people hate it just as much. I had never experienced just how much power a single dept could hold until we got acquired by a large finance enterprise and had to interact with the Risk dept.
- betaby 3y agoStill, what exactly has changed in the last year that Zscaller/Netskope became prevalent? What law has changed? Can someone pinpoint on it. I work for telecom company for example, two years ago there was no zscaller/netskope MITM in my request from the corporate laptop to Internet, today there is one. What law has changed if any what mandates that? If that matter ISP is registered at NJ.
- antod 3y agoNot in your country, but my point about compliance wasn't that a law requires it specifically (laws don't specify technical "solutions" anyway) - just that often the IT dept is compelled by other depts (eg Risk) to implement and support stuff that allows that other dept to show auditors that they are doing something rather than being negligent.
- Bluecobra 3y agoMitM can absolutely stop threats if done correctly. A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire. Not saying MitM is an end all be all, but IMHO the more security layers you have the better. At the end of the day, it's not your network/computer. There's always going to be some unsavvy user duped into something. If you don't like corporate IT, you're free to become a contractor and work at home.
- fsniper 3y ago"A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire." Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all. ? DPS/MITM are not security layers but more of privacy nightmares.
- EvanAnderson 3y ago> Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all. ? Sure. Then come the complaints that this slows down endpoint devices and has compatibility issues. Somebody gets the idea to do this in the network. Rinse. Repeat.
- fsniper 3y agoOur CorpIT has that and fine tuned it to perfection. No one complains now. So it's possible. Unfortunately they still do MITM which breaks connections regularly.
- EvanAnderson 3y agoIt's a knife's edge. One OS patch, or one vendor change in product roadmap, and you can be right back to endpoint security software performance and compatibility hell. Stuff has gotten better but it's still fraught with peril.
- neon_electro 3y agoLink for more info? That seems impossible to make work.
- pmarreck 3y agoI know that they have a gigantic intranet, that might make the lack of internet during the workday less painful
- mschuster91 3y agoI read this recently for sysadmins at Google and Microsoft that have access to absolute core services like authentication, which does make sense to keep these airgapped
- eep_social 3y agoThis sounds like a misunderstanding of the model. Usually these companies have facilities that allow core teams to recover if prod gets completely fucked e.g. auth is broken so we need to bypass it. Those facilities are typically on separate, dedicated networks but that doesn’t mean the people who would use them operate in that environment day to day.
- Bluecobra 3y agoSource: https://arstechnica.com/gadgets/2023/07/to-defeat-hackers-google-wants-employees-to-work-without-internet-access/ https://arstechnica.com/gadgets/2023/07/to-defeat-hackers-go...
- fsniper 3y agoThere are real valuable practices that helps security, and there are practices just break security. Particularly MITM practice is a net negative. Rolling password resets and bad password requirements are also net negatives. Scanners which does not work as intended, which are not proofed at all and introduce slowness, feature breaks are possible negatives. Also at some places they introduce predatory privacy nightmares like key loggers, screen recorders..
- dobin 3y agoFull inspection of user traffic is required to implement: * Data leakage policy (DLP; insider threat, data exfiltration) * Malware scanning * Domain blocking (Gambling, Malware) * Other detection mechanisms (C2) * Logging and auditing for forensic investigations * Hunting generally I dont see how this breaks security, and of course you also didnt elaborate on why it should be. Assumed TLS MitM is implemented reasonably correctly. Dont worry tho, zero trust will expose the company laptops again to all the malicious shit out there.
- acdha 3y ago> I dont see how this breaks security You’re training users to ignore certificate errors – yes, even if you think you’re not – and you’re putting in a critical piece of infrastructure which is now able to view or forge traffic everywhere. Every vendor has a history of security vulnerabilities and you also need to put in robust administrative controls very few places are actually competent enough to implement, or now you have the risk that your security operators are one phish or act of malice away from damaging the company (better hope nobody in security is ever part of a harassment claim). On the plus side, they’re only marginally effective at the sales points you mentioned. They’ll stop the sales guys from hitting sports betting sites, but attackers have been routinely bypassing these systems since the turn of the century so much of what you’re doing is taking on one of the most expensive challenges in the field to stop the least sophisticated attackers. If you’re concerned about things like DLP, you should be focused on things like sandboxing and fine-grained access control long before doing SSL interception.
- ngrilly 3y ago> IT has a responsibility to keep the network secure. Yes, but TLS inspection is not the solution. > Google is already experimenting with no Internet access for some employees, and that might be the endgame. Source? And I'm pretty sure they are not considering disconnecting most of their employees who actually need Internet for their job.
- Bluecobra 3y agoSource: https://arstechnica.com/gadgets/2023/07/to-defeat-hackers-google-wants-employees-to-work-without-internet-access/ https://arstechnica.com/gadgets/2023/07/to-defeat-hackers-go... Eventually I think the endgame here is that you use your own personal BYOD device to browse the internet that is not able to connect to the corporate network.
- ngrilly 3y agoThanks for the link. I’ve seen it done if the defense industry. Interesting to see Google doing this for a small subset of their employees not needing Internet for their job.
- kccqzy 3y agoGoogle disabling Internet access is very different from your typical company doing that. Watching a YouTube video? Intranet and not disabled. Checking your email on Gmail? Intranet and not disabled. Doing a web search? Intranet and not disabled. Clicking on a search result? Just use the search cache and it's intranet.
- est 3y ago> IT has a responsibility to keep the network secure By chopping the head off?
- FuriouslyAdrift 3y agoBlame the law. Companies are bound by it. Actually blame terrible programming practices and the reluctance to tie the long tail of software maintenance and compliance to the programmers and product managers that write them.
- peoplefromibiza 3y agocompanies can be held liable for what people using their networks do, so they need a way to prove it's not their fault and provide the credentials of the malevolent actor. it's like call and message logs kept by phone companies. nobody likes to keep them but it's better than the breaking the law and risking for someone abusing your infrastructure. it would also be great if my colleagues did not use the company network to check the soccer stats every morning for 4 hours straight, so the company had to put up some kind of domain blocking that prevents me from looking up some algorithm i cannot recall from the top of my mind on gamedev.net because it's considered "gaming"
- ric2b 3y agoLooking up soccer stats is not illegal so the company doesn't have to block it. Blocking the website instead of punishing them in their performance reviews (assuming it does impact their performance, if they're still productive why even care) is useless, they'll use their phones and still spend time on it.
- peoplefromibiza 3y ago> Looking up soccer stats is not illegal so the company doesn't have to block it. it's not because it's illegal, it's because they are wasting time on the job using company's equipment for something not work related. And usually they end up clicking everywhere on shady ads, trackers etc. We are in Italy, there's no such thing as performance review here, if you get hired you get paid every month (actually 13 times a year, sometimes 14) and nobody can fire you ever again. > they'll use their phones and still spend time on it. their choice on their equipment