2 ms·
Hot (and perhaps tangental) take here, but I can't understand why companies that attempt to enforce these policies for security reasons, do not just mitigate th
by CuriousRose 2y ago
Hot (and perhaps tangental) take here, but I can't understand why companies that attempt to enforce these policies for security reasons, do not just mitigate their largest attack vector and move to macOS for their endpoints where possible. Far more reliable in terms of stability and security, and dramatically less patch management required for macOS clients. I'd argue a more productive user experience also, instead of fighting the advertising, new AI integrations, Candy Crush and layout changes that Windows generously provides every 30 days. Hardware is also pretty easy to resell, AppleCare covers replacements and the fleet can be pretty uniform with stock available anywhere if needed. Keep incompatible apps that are required in a Citrix Workspace or equivalent for isolation. This doesn't address social engineering or file leaks due to malicious employees obviously.
- LaffertyDev 2y agoAll that follows is from someone who mainlines linux (just mild ubuntu) and macos but wouldn't complain too much about a windows workstation. > Hot (and perhaps tangental) take here, Indeed. > but I can't understand why companies that attempt to enforce these policies for security reasons, do not just mitigate their largest attack vector and move to macOS for their endpoints where possible. Citation needed that Macos is more secure than windows. > Far more reliable in terms of stability and security, In my experience, macos/windows are about par for security and the "stability" also seems par. If anything, windows is _more_ stable since it is backwards compatible to a fault. > and dramatically less patch management required for macOS clients. Fair, but I think this is mostly a boon to IT teams who want more control from windows. > I'd argue a more productive user experience also, instead of fighting the advertising, new AI integrations, Candy Crush and layout changes that Windows generously provides every 30 days These concerns are not generally applicable in an enterprise environment. I feel them on my gaming machines, but corporate is generally locked down pretty tightly. Also, I mean, Macos is famously getting new AI integrations in 18.2 so this seems like a false comparison. > Hardware is also pretty easy to resell Admittedly this is a boon to Macos, but I think there is an argument that the cheaper windows machines may have a better full cost-of-ownership metric than macs. > AppleCare covers replacements Everywhere I have worked, the company pays for replacements out-of-pocket or has _very_ generous enterprise agreements. > and the fleet can be pretty uniform with stock available anywhere if needed. Fair. I'm not sure that it matters for enterprises that already have a locked down hardware procurement process but its pretty hard to argue against the 2023MBP16GB is more uniform than {windows soup}. > Keep incompatible apps that are required in a Citrix Workspace or equivalent for isolation. This doesn't address social engineering or file leaks due to malicious employees obviously. I'm not sure what you're saying here, but I'm hard pressed to see how this applies to any specific OS and not others.
- hnbear 2y agoEven with the Mac there are still security reasons to enforce certain controls on it. eg. if you lose it and it's not encrypted, doesn't have strong login creds required, lock screens, etc then all the data on it is out in the world. That can include customer data, access to your production systems, your companies code and ability to check it in and introduce other bad behavior in the product, etc. Some of the other controls will be able access to internal systems. eg. VPNs, or cert-base auth controls other make sure that only employees can access those systems to protect them. If you're on an uncontrolled machine you lose the ability to guard who and what is connecting. Some of the controls protect employees themselves. MDM on your laptop allows IT to reset your password and/or fix your machine in other ways. I'm all for switching to macOS, but they still need the same controls in place.
- mango7283 2y agoI was going to say "but DLP" but you covered it in your last sentence. So...yes. Use the corporate device, you do NOT want to be under investigation for being unable to account for if you've leaked data you had access to from outside the perimeter.