5 ms·
Always assumed they block everything they cannot spy, it's not for security. Https they inject their certificates, ssh you can have your key and they'll be blin
by aulin 2y ago
Always assumed they block everything they cannot spy, it's not for security. Https they inject their certificates, ssh you can have your key and they'll be blind. And they spy to prevent exfiltration they say. I cannot ssh into my home network but I can drop tons of company code into an LLM prompt.
Everything else, MFA, password rotations, approved software, stupid training videos... is all there to tick some boxes in a certification process or to easily shift the blame when something bad happens.
- necovek 2y agoBecause of MITM-ing TLS with their own certificates, they could also stop you from dumping tons of code into an LLM prompt by blocking all public LLMs (or even all sites not on an allowlist). The reason it's silly is really that you can always take "secrets" with you, be it by taking photos with your phone ("lets ban phones") or memorizing or writing on paper. Security is useful when it prevents accidental, inadvertent leakage of information ("stop me from shooting myself in the foot"). Anything else, and the inconvenience will make people figure out ways around it. And the real reason people won't leak information is either ethics and morality, or legal liability.
- MattPalmer1086 2y agoYou overestimate the intelligence of a lot of people. We have caught attempts at exfiltration over channels we can easily monitor. Is it perfect? No. Can reasonably intelligent people find a way around them? Sure. But we are still going to control that information flow where we can.
- necovek 2y agoSo, as the OP claims, it is working for the 35% of the employees, right? And it likely inconveniences a full 100%. Does that sound like a smart trade-off?
- MattPalmer1086 2y agoWhat is the alternative? I have actually worked in places that prevented all personal electronic devices in the building, had security guards and bag searches on every floor and no internet access on your desktop. You don't know what inconvenience looks like!
- necovek 2y agoI am sure it can be even worse than what you describe. I, however, do not aspire to taste it. The question is not what "inconvenience looks like", but rather, what is "enough security with the least inconvenience?" The alternative is in the answer to that question: if your "measure" is likely to be "bypassed", it is worse than not having it in the first place (because bypassing usually puts sensitive data on even worse medium like flash devices, public cloud, external servers etc). If your security policy was simply "Do not keep sensitive work data on unencrypted storage" and had informed your employees they are legally liable to adhere to this, they would either choose to not use personal devices or understand the risks if they do. So like always, getting to that point requires "simply" being reasonable and smart ("common sense" which is, unfortunately, "not that common").
- ars 2y agoYou can just encrypt your stuff and upload it via http. You can even run ssh over http if you work at it. Encryption is as easy as using zip. And if you uploaded a very large file, they can't realistically log it - so you could even upload it in the clear and it won't be caught unless they are specifically looking.
- MattPalmer1086 2y agoWe scan all file uploads and block encrypted files. Your move.
- ars 2y agoI challenge you to automatically tell the difference between an encrypted file with a fake header and a jpeg. A human could see it's not a real image, a tool would not. And that's not even getting into steganography - just literally add a jpeg header to the encrypted file and it will fool most things. Or any kind of streaming upload. The thing about media compression is that the compression process leads to a file that looks 100% random, an encrypted file also looks that way.
- MattPalmer1086 2y agoYeah, you would probably get past it like that, good one. Steganography could also be used to exfiltrate data. The point of these systems though isn't to stop a determined attacker on the inside. It's to prevent people foolishly, accidentally, or intentionally (because they're lazy) from sending potentially sensitive data out. This happens all the time.