Live data from Hacker News

Ask HN: My client want an agent on my laptop. Is this the new normal?

news.ycombinator.com

411–420 of 506 posts

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#411

If you are a freelancer then your contract should allow you to do work for others. In which case, your response to this client has to be "Sorry, but my business laptop potentially has data from other clients on it. I can't let you install this monitoring agent without violating my contractual confidentially agreement with those other clients. I always maintain client confidentiality and will do the same for you. If y…

For independent technical consulting for over a decade, I had only a small number of high-value clients, so I ended up dedicating a ThinkPad to each client.

I also had email account specific to each client, so that I could have a mail program on that ThinkPad access only the respective account.

There are many reasons to do one laptop per client (especially if you're WFH, not traveling), including not exposing personal and other-client stuff to whatever weird stuff is in the build environment of one client.

Another reason, though this never came up for me, is that there can be legal orders to permit inspection of the computer, online accounts, etc., including by computer forensics. If that happened for one client, that could be in conflict with your obligations to another client (as well as in conflict with your SO's private vacation photos, if they were on the same device). Being able to reassure that everything for a client was compartmentalized to certain devices and accounts might come in handy.

At one point, I even had color-coded labelmaker tape to help keep track of what was compartmentalized to what. And photos of the devices with the physical labeling on them, in case I ever needed to convey that I took it seriously.

(Related: One time, I had a hard drive fail such that (despite encryption) I couldn't do an approved wipe of it before disposal or warranty return. That client's compliance policies required that I physically destroy the drive platters, and ship the remnants to them via Registered Mail. It was a slightly fun/cool exercise, especially since the platters shattered nicely. And the neighborhood of $100 lost was well-invested in professionalism goodwill with a client who paid a few orders of magnitude of that amount over time.)

(In some ways, I'm now happy to no longer be running a consulting business, mainly because a predictable, consistent amount of money just appears in my bank account every couple weeks. :)

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#412

Earlier quoted context omitted.

SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it. It’s an absurd system.

The same thing happened in the early days of ISO 9000

ISO9000: We make a piece of shit product, but it's a very well documented piece of shit product.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#413
post #17

It's not normal. Ask them if they and Drata are willing to be on the hook for all your potential bank breach in the future, as they are key-logging your online banking access. Ask them if they can put up a surety bond or insurance for any of your financial loss due to breach of privacy.

The Drata agent is a lightweight osquery agent that is read only that reads things like - screen saver timeout, auto-updates turned on, is AV software installed, etc. We collect that data to show the device is compliant with the companies policies and the compliance frameworks they have agreed to. The company this person contracts with requires the agent be installed to monitor compliance for all devices, employee an…

Does your software run as a Windows service? Is it installed as the System user or Local Admin user? Does it auto update over network? It’s just one update away from adding key logging.

Put money on your claim. Put up a surety bond or insurance for users’ data breach. All the security audits won’t beat putting your own financial stake on the table.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#414

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

You in fact have no idea how "innocuous" the Drata agent is. You know only what Drata tells you.

It would be grossly irresponsible for a contractor to rely on one client's assurances about what a third party told them its software did, and expose other clients' data to errors or abuse by that third party. Or their own personal data, for that matter.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#415

Earlier quoted context omitted.

As someone who isn't well versed in networking could you describe your setup in overview? Like, what software/hardware, etc.? Thank you

Sure. I didn't actually use a VLAN: I had a spare TP-Link router lying around, so I installed OpenWRT[1] on that and gave it a static IP on the home network side, then plugged it into my broadband provider's box. On the cloud side, I basically followed a guide, maybe [2] but I don't remember exactly. Once I had pfSense installed, I first set it up as an OpenVPN server. I then went back and configured the OpenWRT box…

Thank you! Though I agree with the sibling comments that it's probably not something to dabble in unless you're pretty confortable with this... May I ask, is this somewhat in your area of expertise, what kind of development do you do (supposing you're a developer?). Sorry if too inquisitive, just curious :).

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#417

Earlier quoted context omitted.

SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it. It’s an absurd system.

Reminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we…

> If such an option is allowed by PCI, what is even the point of making it a requirement?

The point of all those certifications (I took companies through the processes required for PCI, SOC2, and ISO27001 ) is security theater, a path in the back for the execs, the ability to have "I'm not to blame, I have this cert" in case of some shit happening, and the ability for sales to throw TLAs to prospects to show how Seriously(tm) the company takes security. Oh, and to check boxes to be able to transact with some large corporations.

There are plenty of stories of highly certified companies that were deeply penetrated and exposed, and all their security theater did not help.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#418
post #399

Earlier quoted context omitted.

Enforcing/auditing sane security settings on the device. Very much required for compliance, zero trust, protection of IP, and foundational to a reasonable security plan.

I think I added #4 after your comment. Which is essentially my response. It seems like a very weak measure, at the cost of privacy considering it's the worker's personal device... If our solution is to require separate devices anyway, then spyware seems like a waste of time, they should be providing secured hardware/OS. On second thought, this _is_ the answer... they are making a compromise on security, it's an econo…

The ship has totally sailed on whether it's a best practice to instrument machines employees use to conduct work, in the name of compliance and security. That's an utterly standard control, and unless you have a remarkably potent new argument against doing so, arguing that companies shouldn't do this sort of thing is kind of uninteresting. If anything, the prevailing sentiment (for better or worse, mostly worse) is that companies should be doing more of this, not less.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#419
post #336

Earlier quoted context omitted.

This. Every company I’ve ever worked at, and that includes very large ones, will have legal, HR, and finance tell you at some point that “you must do X”. Sometimes X is no big deal and you do it. Sometimes it’s hard, and you ask the business to fund it or remove the requirement. Sometimes it’s nonsensical in your context and at that point the job becomes understanding why X is a requirement and how you can satisfy th…

I had an employer that, once or twice a year would send out mandatory agreements we were "required" to sign-- under threat of dismissal. (I don't think this was legal at all). One day they sent out a particularly onerous "agreement" that said that we agreed not to use a phone while driving a car and doing so would be cause for termination etc. I went down to HR and asked them if they were really trying to regulate wh…

You're in the US --- California, to boot. I'm not sure what you accomplished by making the agreement "unenforceable", as your employer does not need to secure your agreement to terminate you for virtually any reason. Discovering that you text and drive in your spare time, off hours, is something they'll likely have no trouble firing you for, unless you have an employee contract that somehow gives you tenure except for for-cause hiring (almost nobody has one of those).

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#420

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

Right, I setup SOC2 compliance processes for a small startup, and we didn't have money to buy all those fancy automation programs. We managed ourselves with recurring JIRA tickets and screenshots taken by personnel.

I think the only service we had to pay was for security awareness training, and it was a site that provided security awareness videos..

Post reply on HN