[HN Gopher] Bring Your Own Disaster
       ___________________________________________________________________
        
       Bring Your Own Disaster
        
       Author : robin_reala
       Score  : 50 points
       Date   : 2022-09-19 08:35 UTC (14 hours ago)
        
 (HTM) web link (mjg59.dreamwidth.org)
 (TXT) w3m dump (mjg59.dreamwidth.org)
        
       | afandian wrote:
       | > The user gets to use hardware they're familiar with, and which
       | matches their ergonomic desires
       | 
       | Why can't the employer buy the employee their preferred
       | equipment? Would cut out a lot of hassle.
        
         | BrandoElFollito wrote:
         | Because they would need to support it.
         | 
         | When you run your Windows 10 with four zillion applications and
         | twice the number of drivers, you have a continuous queue to the
         | help desk. Sometimes from reasonable users, sometimes from
         | bozos.
         | 
         | Now imagine I come with my favourite Atari 400 and the 10 Gbps
         | driver does not work.
         | 
         | It is easy to dream of users being self-managed, but this will
         | not happen, ever.
        
         | layer8 wrote:
         | It would be a pain for IT having to review and support
         | different hardware for each employee.
        
           | afandian wrote:
           | If business continuity demands hardware support, how does it
           | account for BYOD?
        
         | bsder wrote:
         | > Why can't the employer buy the employee their preferred
         | equipment? Would cut out a lot of hassle.
         | 
         | Most of the friction I bumped into is about their phone, not
         | their laptop. Most people are just fine having a corporate
         | laptop.
         | 
         | But most don't want their "preferred equipment" for mobile,
         | they want _their own singular phone_ and nothing else. And that
         | 's where the issues all come into play.
        
         | gw99 wrote:
         | I'm having that argument now.
         | 
         | The story is that the IT teams are detached completely from the
         | reality of their end users and are driven by compliance box
         | ticking, off the shelf corporate malware sales marketoids,
         | incompetence and ignorance.
         | 
         | Any attempt to confront anyone on that is met with defensive
         | use of politics and budgetary concerns which don't make logical
         | sense at all. In reality the staff aren't very good and can't
         | cope with the requirements of the organisation and this is
         | being carefully hidden by the folk trying to protect their
         | positions.
         | 
         | Thus we have several hundred people with inadequate hardware,
         | inappropriate poorly configured software and friction so bad
         | that doing an hour of productive work is a miracle. Of course
         | corporate surveys that are sent out never address the concerns
         | because that would mean someone has to be accountable for it.
         | 
         | At the same time IT teams are pushing BYOD for mobile devices
         | because you can push a policy out which fucks the end user's
         | devices once a week and causes actual data loss on the personal
         | side of things. So no one uses BYOD because it risks their own
         | personal stuff and no one carries a corporate phone so no work
         | gets done on the road.
         | 
         | The end game is I use my own hardware and do everything in
         | clean room and push it to GitHub and pull it back into
         | corporate env for integration.
         | 
         | The scary thing is I know enough people working at different
         | organisations to know that this is the status quo. You can
         | blame Gartner, Microsoft, the whole security sector and the
         | army of solutions providers for mandating this mess.
        
           | tempodox wrote:
           | > do everything in clean room and push it to GitHub and pull
           | it back into corporate env
           | 
           | Wouldn't using GitHub for proprietary stuff incur the risk of
           | industrial espionage?
        
             | gw99 wrote:
             | Agree entirely. I also objected to that.
        
           | briffle wrote:
           | > and are driven by compliance box ticking
           | 
           | For many IT departments, passing audits is a huge deal, that
           | is very important to senior management. I know for my last
           | set of compliance audits, I had to show evidence that every
           | employee workstation was encrypted, patched, and running up
           | to date Anti-virus software. (My company deals with PHI data)
           | 
           | I know there are other ways to solve many of the problems,
           | but ensuring disk encryption and patching especially can be
           | difficult if you have a mix of systems, and OS's.
           | 
           | I think 2 of the biggest pushes for this lately is the huge
           | cost of 'cyber insurance' for things like ransomware atacks,
           | as well as reporting requirements for lost/stolen laptops
           | that could potentially have PHI on them.
        
             | gw99 wrote:
             | Oh completely agree with all of these but it's possible to
             | deliver them without the malfeasance of actually measurably
             | damaging the productivity of your staff.
             | 
             | The big problem with modern IT teams is they are an
             | independent authority that never actually wears the user's
             | shoes for a moment.
        
           | tut-urut-utut wrote:
           | > The end game is I use my own hardware and do everything in
           | clean room and push it to GitHub and pull it back into
           | corporate env for integration.
           | 
           | ... and by doing that, you are breaking a number of corporate
           | policies and rules and are leading yourself into a world of
           | pain whenever they find out. Losing a job would be a least of
           | a trouble.
           | 
           | Honestly, don't do that. Don't use your equipment if the
           | company did not explicitly permit that. If you can't do the
           | job as quickly as you want using company provided equipment,
           | maybe that's the price the company is willing to pay for
           | having all those "compliances". Live with it or leave, but
           | bring yourself in trouble by ignoring all "safety" measures.
        
             | gw99 wrote:
             | Bold of you to assume I haven't read and understood the
             | contents of my contract which implicitly does not disallow
             | this.
             | 
             | Realistically I build spikes and prototypes on my own
             | hardware and only push to the environment never pull.
             | Production code, credentials and data never goes near
             | personal equipment.
        
           | giancarlostoro wrote:
           | > The story is that the IT teams are detached completely from
           | the reality of their end users and are driven by compliance
           | box ticking, off the shelf corporate malware sales
           | marketoids, incompetence and ignorance.
           | 
           | At a former employer we all used custom built Linux boxes.
           | Made it easier to say "sorry, that doesn't seem to run on
           | Linux" and since most of our code was on Python, Linux was
           | just fine for all of us.
           | 
           | I don't mind some amount of corporate software, its not my
           | hardware, but dont deter me from being able to install
           | things.
        
           | afandian wrote:
           | The latter part is the bit I can't understand. If their risk
           | calculus allows be my BYOD why can't they supply a custom
           | machine that would fall in the same envelope?
        
             | gw99 wrote:
             | I don't understand any of it. Mostly it's selfish CYA
             | mentality rather than the business responsibility of being
             | a service provider, and you know, actually providing
             | service.
        
       | teddyh wrote:
       | If someone works from home (in some capacity) and has an
       | internet-connected security camera in their home, and they
       | subscribe to a service who monitors those cameras, would that
       | service also be subject to approval from their employer? How
       | about the firmware in their webcam and microphone? Their phone?
       | Their hearing aid?
       | 
       | Let's face it, there is now entirely _too much_ technology which
       | is able to compromise a person's security that employers _can't_
       | realistically declare all of it to be off-limits for employees.
        
         | izacus wrote:
         | > Let's face it, there is now entirely too much technology
         | which is able to compromise a person's security that employers
         | can't realistically declare all of it to be off-limits for
         | employees.
         | 
         | Oh but they'll surely try. You can't say that small things like
         | "reality" ever really touch corporate IT and box ticking
         | auditors.
        
         | BiteCode_dev wrote:
         | I have a client that wants me to work only on their official
         | locked down laptop, which I do. But it has a terrible camera
         | and microphone, so I use my own better gear.
         | 
         | It made a huge difference in the quality of life of all my
         | coworkers with which I spend hours peer coding or in conf
         | calls.
         | 
         | It's also better for myself, as my client takes me more
         | seriously because in a meeting, as I'm the only one with good
         | sound and image.
         | 
         | Were I to use only approved hardware, I would not be able to
         | make our work life better.
        
           | JohnFen wrote:
           | > But it has a terrible camera and microphone
           | 
           | Mine has no camera or microphone at all -- which I greatly
           | appreciate!
        
           | [deleted]
        
         | kixxauth wrote:
         | Yeah, correct me if I'm wrong, but I believe the vast majority
         | of hacks are along the social hacking vector. If we believe
         | this is generally true, then the best ROI of our security
         | resources is in training personnel to withstand the attacks.
         | 
         | There are some challenges to overcome.
         | 
         | First, success will require that leadership within an
         | organization understands that we cannot simply throw more
         | technology at the problem. We need good security professionals
         | who know how to educate the general public. Organizations need
         | to find creative ways to make it part of their cultural DNA to
         | learn the skills required for breach avoidance.
         | 
         | Second, as any medium advances it takes time for people to
         | catch up and approach it in a way that is not so naive. If we
         | are honest with ourselves, technology is as much a medium as it
         | is a tool. For example: When a film of an oncoming train was
         | shown to early audiences who had never seen motion picture
         | before it made them instinctively duck as the train approached
         | them. It was like a thrill ride today. It takes time for social
         | groups to desensitize from a new medium. We took the naive
         | approach with social networks, and now we are learning the
         | consequences.
         | 
         | The problem is that technology is introducing new mediums at
         | such a rapid pace that many people don't have enough time to
         | become more sophisticated in its use.
        
       | bzmrgonz wrote:
       | Doesn't remote desktop services take care of this? That way all
       | you are dishing out to their devices are pixels.
        
       | s_dev wrote:
       | I've repeated this multiple times already but one way to stay
       | compliant and get to use a laptop for work and play is to use
       | bootable hard drives.
       | 
       | This keeps everyone happy. Employers are happy to be compliant
       | and employees are happy to use their laptops for gaming machines
       | on the Weekend or even vice versa. It may be against company
       | policy but not against GDPR or PCI or Tax Laws.
       | 
       | I have two external drives -- one bootable one and time machine
       | backup. I've been doing this for years -- works on all my
       | machines mac OS as well as Windows and Linux. People expect
       | problems with SIP or performance or something etc but I haven't
       | had them.
       | 
       | So bring your own SSD is the way forward.
        
       | JohnFen wrote:
       | Your personal devices should never be used for work, and should
       | never even be connected to your employer's network or other
       | machines. This article covers one of the reasons why.
       | 
       | In the end, it's about risk management. Keeping a hard wall
       | between work and personal machines protects both you and your
       | employer. I am honestly amazed that people are willing, and even
       | eager, to break through that wall.
        
       ___________________________________________________________________
       (page generated 2022-09-19 23:02 UTC)