[HN Gopher] Bring Your Own Disaster
___________________________________________________________________
Bring Your Own Disaster
Author : robin_reala
Score : 50 points
Date : 2022-09-19 08:35 UTC (14 hours ago)
(HTM) web link (mjg59.dreamwidth.org)
(TXT) w3m dump (mjg59.dreamwidth.org)
| afandian wrote:
| > The user gets to use hardware they're familiar with, and which
| matches their ergonomic desires
|
| Why can't the employer buy the employee their preferred
| equipment? Would cut out a lot of hassle.
| BrandoElFollito wrote:
| Because they would need to support it.
|
| When you run your Windows 10 with four zillion applications and
| twice the number of drivers, you have a continuous queue to the
| help desk. Sometimes from reasonable users, sometimes from
| bozos.
|
| Now imagine I come with my favourite Atari 400 and the 10 Gbps
| driver does not work.
|
| It is easy to dream of users being self-managed, but this will
| not happen, ever.
| layer8 wrote:
| It would be a pain for IT having to review and support
| different hardware for each employee.
| afandian wrote:
| If business continuity demands hardware support, how does it
| account for BYOD?
| bsder wrote:
| > Why can't the employer buy the employee their preferred
| equipment? Would cut out a lot of hassle.
|
| Most of the friction I bumped into is about their phone, not
| their laptop. Most people are just fine having a corporate
| laptop.
|
| But most don't want their "preferred equipment" for mobile,
| they want _their own singular phone_ and nothing else. And that
| 's where the issues all come into play.
| gw99 wrote:
| I'm having that argument now.
|
| The story is that the IT teams are detached completely from the
| reality of their end users and are driven by compliance box
| ticking, off the shelf corporate malware sales marketoids,
| incompetence and ignorance.
|
| Any attempt to confront anyone on that is met with defensive
| use of politics and budgetary concerns which don't make logical
| sense at all. In reality the staff aren't very good and can't
| cope with the requirements of the organisation and this is
| being carefully hidden by the folk trying to protect their
| positions.
|
| Thus we have several hundred people with inadequate hardware,
| inappropriate poorly configured software and friction so bad
| that doing an hour of productive work is a miracle. Of course
| corporate surveys that are sent out never address the concerns
| because that would mean someone has to be accountable for it.
|
| At the same time IT teams are pushing BYOD for mobile devices
| because you can push a policy out which fucks the end user's
| devices once a week and causes actual data loss on the personal
| side of things. So no one uses BYOD because it risks their own
| personal stuff and no one carries a corporate phone so no work
| gets done on the road.
|
| The end game is I use my own hardware and do everything in
| clean room and push it to GitHub and pull it back into
| corporate env for integration.
|
| The scary thing is I know enough people working at different
| organisations to know that this is the status quo. You can
| blame Gartner, Microsoft, the whole security sector and the
| army of solutions providers for mandating this mess.
| tempodox wrote:
| > do everything in clean room and push it to GitHub and pull
| it back into corporate env
|
| Wouldn't using GitHub for proprietary stuff incur the risk of
| industrial espionage?
| gw99 wrote:
| Agree entirely. I also objected to that.
| briffle wrote:
| > and are driven by compliance box ticking
|
| For many IT departments, passing audits is a huge deal, that
| is very important to senior management. I know for my last
| set of compliance audits, I had to show evidence that every
| employee workstation was encrypted, patched, and running up
| to date Anti-virus software. (My company deals with PHI data)
|
| I know there are other ways to solve many of the problems,
| but ensuring disk encryption and patching especially can be
| difficult if you have a mix of systems, and OS's.
|
| I think 2 of the biggest pushes for this lately is the huge
| cost of 'cyber insurance' for things like ransomware atacks,
| as well as reporting requirements for lost/stolen laptops
| that could potentially have PHI on them.
| gw99 wrote:
| Oh completely agree with all of these but it's possible to
| deliver them without the malfeasance of actually measurably
| damaging the productivity of your staff.
|
| The big problem with modern IT teams is they are an
| independent authority that never actually wears the user's
| shoes for a moment.
| tut-urut-utut wrote:
| > The end game is I use my own hardware and do everything in
| clean room and push it to GitHub and pull it back into
| corporate env for integration.
|
| ... and by doing that, you are breaking a number of corporate
| policies and rules and are leading yourself into a world of
| pain whenever they find out. Losing a job would be a least of
| a trouble.
|
| Honestly, don't do that. Don't use your equipment if the
| company did not explicitly permit that. If you can't do the
| job as quickly as you want using company provided equipment,
| maybe that's the price the company is willing to pay for
| having all those "compliances". Live with it or leave, but
| bring yourself in trouble by ignoring all "safety" measures.
| gw99 wrote:
| Bold of you to assume I haven't read and understood the
| contents of my contract which implicitly does not disallow
| this.
|
| Realistically I build spikes and prototypes on my own
| hardware and only push to the environment never pull.
| Production code, credentials and data never goes near
| personal equipment.
| giancarlostoro wrote:
| > The story is that the IT teams are detached completely from
| the reality of their end users and are driven by compliance
| box ticking, off the shelf corporate malware sales
| marketoids, incompetence and ignorance.
|
| At a former employer we all used custom built Linux boxes.
| Made it easier to say "sorry, that doesn't seem to run on
| Linux" and since most of our code was on Python, Linux was
| just fine for all of us.
|
| I don't mind some amount of corporate software, its not my
| hardware, but dont deter me from being able to install
| things.
| afandian wrote:
| The latter part is the bit I can't understand. If their risk
| calculus allows be my BYOD why can't they supply a custom
| machine that would fall in the same envelope?
| gw99 wrote:
| I don't understand any of it. Mostly it's selfish CYA
| mentality rather than the business responsibility of being
| a service provider, and you know, actually providing
| service.
| teddyh wrote:
| If someone works from home (in some capacity) and has an
| internet-connected security camera in their home, and they
| subscribe to a service who monitors those cameras, would that
| service also be subject to approval from their employer? How
| about the firmware in their webcam and microphone? Their phone?
| Their hearing aid?
|
| Let's face it, there is now entirely _too much_ technology which
| is able to compromise a person's security that employers _can't_
| realistically declare all of it to be off-limits for employees.
| izacus wrote:
| > Let's face it, there is now entirely too much technology
| which is able to compromise a person's security that employers
| can't realistically declare all of it to be off-limits for
| employees.
|
| Oh but they'll surely try. You can't say that small things like
| "reality" ever really touch corporate IT and box ticking
| auditors.
| BiteCode_dev wrote:
| I have a client that wants me to work only on their official
| locked down laptop, which I do. But it has a terrible camera
| and microphone, so I use my own better gear.
|
| It made a huge difference in the quality of life of all my
| coworkers with which I spend hours peer coding or in conf
| calls.
|
| It's also better for myself, as my client takes me more
| seriously because in a meeting, as I'm the only one with good
| sound and image.
|
| Were I to use only approved hardware, I would not be able to
| make our work life better.
| JohnFen wrote:
| > But it has a terrible camera and microphone
|
| Mine has no camera or microphone at all -- which I greatly
| appreciate!
| [deleted]
| kixxauth wrote:
| Yeah, correct me if I'm wrong, but I believe the vast majority
| of hacks are along the social hacking vector. If we believe
| this is generally true, then the best ROI of our security
| resources is in training personnel to withstand the attacks.
|
| There are some challenges to overcome.
|
| First, success will require that leadership within an
| organization understands that we cannot simply throw more
| technology at the problem. We need good security professionals
| who know how to educate the general public. Organizations need
| to find creative ways to make it part of their cultural DNA to
| learn the skills required for breach avoidance.
|
| Second, as any medium advances it takes time for people to
| catch up and approach it in a way that is not so naive. If we
| are honest with ourselves, technology is as much a medium as it
| is a tool. For example: When a film of an oncoming train was
| shown to early audiences who had never seen motion picture
| before it made them instinctively duck as the train approached
| them. It was like a thrill ride today. It takes time for social
| groups to desensitize from a new medium. We took the naive
| approach with social networks, and now we are learning the
| consequences.
|
| The problem is that technology is introducing new mediums at
| such a rapid pace that many people don't have enough time to
| become more sophisticated in its use.
| bzmrgonz wrote:
| Doesn't remote desktop services take care of this? That way all
| you are dishing out to their devices are pixels.
| s_dev wrote:
| I've repeated this multiple times already but one way to stay
| compliant and get to use a laptop for work and play is to use
| bootable hard drives.
|
| This keeps everyone happy. Employers are happy to be compliant
| and employees are happy to use their laptops for gaming machines
| on the Weekend or even vice versa. It may be against company
| policy but not against GDPR or PCI or Tax Laws.
|
| I have two external drives -- one bootable one and time machine
| backup. I've been doing this for years -- works on all my
| machines mac OS as well as Windows and Linux. People expect
| problems with SIP or performance or something etc but I haven't
| had them.
|
| So bring your own SSD is the way forward.
| JohnFen wrote:
| Your personal devices should never be used for work, and should
| never even be connected to your employer's network or other
| machines. This article covers one of the reasons why.
|
| In the end, it's about risk management. Keeping a hard wall
| between work and personal machines protects both you and your
| employer. I am honestly amazed that people are willing, and even
| eager, to break through that wall.
___________________________________________________________________
(page generated 2022-09-19 23:02 UTC)