7 ms·
So you have targets (basically employees of said company) browsing popular sites and becoming infected. You can't deny access to all popular sites. Would it be
by digitalengineer 13y ago
So you have targets (basically employees of said company) browsing popular sites and becoming infected. You can't deny access to all popular sites. Would it be possible to build a 'scraper' that copies content and places it on your local network for your employees? Perhaps also allowing comments to be placed back on your behalf? You'd give the employees access to things they want to read, but stop attacks correct?
- adamnemecek 13y agoThat's kinda now Richard Stallman browses the internet. https://stallman.org/stallman-computing.html https://stallman.org/stallman-computing.html Search for wget.
- e12e 13y agoI'm not sure if truly defeating such attacks is feasible, but if you demand employees use a (ssl terminating) proxy, you can at least monitor and/or log all traffic (not necessarily legal or ok in many jurisdictions) -- and so have a reasonable way to look for malware (possibly only useful after the fact). That is if the routers inside your own network can be trusted. Paranoid turtles, all the way down.
- spindritf 13y agoI don't think the filtering approach is feasible. You need separation. Maybe run separate VMs for casual browsing, work, entertainment, etc? Like Qubes does http://qubes-os.org/trac http://qubes-os.org/trac
- motters 13y agoIt soon begins to become infeasible. Unless you can identify when these quantum attacks are occurring and block them this is really more of a political problem than a technical one.
- dublinben 13y agoDoesn't certificate pinning and inspection identify/block these kinds of attacks?
- lvs 13y agoI disagree. This is also a technical problem. Good engineers need to keep working to minimize the possibility of MITMs in their purview. It's a technical arms race. Also, even if you solve the political problem in one country, you still need to worry about external and criminal threats that operate with the same tradecraft.
- 7952 13y agoThe scraper then becomes the target instead of the users computer. Any machine that maintains the context of a web browsing session will contain private data.