Live data from Hacker News

Ask HN: My client want an agent on my laptop. Is this the new normal?

news.ycombinator.com

421–430 of 506 posts

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#421

Earlier quoted context omitted.

Reminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we…

> If such an option is allowed by PCI, what is even the point of making it a requirement? The point of all those certifications (I took companies through the processes required for PCI, SOC2, and ISO27001 ) is security theater, a path in the back for the execs, the ability to have "I'm not to blame, I have this cert" in case of some shit happening, and the ability for sales to throw TLAs to prospects to show how Seri…

It's an extremely low bar for cluefulness. There is space between the bar and the ground, but most serious going concerns clear it easily unless they screw up the compliance process and make things hard for themselves.

The problem isn't these low bars, but rather the market for services to "help" people clear them, and the widespread perception that the bars are higher than they actually are.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#422

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

Right, I setup SOC2 compliance processes for a small startup, and we didn't have money to buy all those fancy automation programs. We managed ourselves with recurring JIRA tickets and screenshots taken by personnel. I think the only service we had to pay was for security awareness training, and it was a site that provided security awareness videos..

This is what a lot of companies do for SOC2. There's a cottage industry of consultants and product vendors selling companies on the idea that SOC2 is difficult and needs bespoke automation, but plenty of companies get by with just Jira. For that matter: you probably didn't need to spend money on security awareness videos.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#424

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

You're completely right re Drata as a company (we use a different compliance vendor, but very similar setup re the agent). You're a bit off on whether this would fail a SOC2 audit, thankfully. As the OP said, they don't have access to production systems, which basically means you can treat that employee however you want from a SOC2 (and ISO, and most other control framework perspectives). The company OP is working fo…

That depends on how they wrote their policies. If they were careful, they left themselves room in their policies to be flexible about people who don't have access to prod. If they weren't --- and lots of teams aren't --- then it's tricky to go back and say "oops I got that part of the policy wrong, the new policy says we can do whatever we want in this case". Again: the real thing SOC2 is assessing is consistent enforcement and monitoring. It's not a "security audit".

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#425
post #286

Earlier quoted context omitted.

Do you think? I wasn't sure because although he doesn't have access to production systems a lot of controls are around access to the code, e.g. Github. But quite possibly you are right.

I've been through SOC2 (sat in with auditors and walked them through pretty much all of our stuff around source code and testing and building things). SOC2 is very much a "do you have policies for x, y and z" and "are you actually implementing those policies", with a VERY HEAVY emphasis on "are you doing what you say you'll do". There's nothing that says "You must monitor any place your source code could exist", but…

My understanding is that it's not completely trivial to make these kinds of policy changes once you get past your Type 1. This would be a nitpick except that it implies something important about how you should handle SOC2: don't be ambitious or expansive in your Type 1 audit, and leave yourself room to see what's going to work long term. This is something I've seen a lot of people mess up.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#427

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

I'm going to piggyback on your comment because it's one of the more reasonable and informed takes here. I'm currently in the middle of our company's first evaluation window for SOC2 Type 2. I'm not familiar with Drata, but at a surface-level, it sounds pretty similar to Vanta, who we use. OP says "The motivation is that my client badly want a SOC 2 certification", which sounds about right. If anyone isn't familiar wi…

This is a great comment. But I'm going to push back on your last paragraph, because it is not completely reasonable for a contractor to say "I'll supply screenshots instead of running this agent". Screenshots work for your team because you set up and documented a process for managing them, and then taught your auditors about it. This contractor's client might not --- probably didn't! -- do that work. It may be logistically tricky for them to do so after the fact if they're already doing consistency audits; also, regardless of where they're at, it might not be worth building and documenting and teaching a whole new screenshot collection policy just to placate a contractor (it will doubtlessly cost more for them to do that than to simply supply the contractor with a company laptop for the duration of their project).

For what it's worth: a nit I like to pick with Vanta is that it sets a very ambitious bar for what a company should be doing with respect to IT security, where SOC2 does no such thing. I worry that things like Vanta lead teams into doing all sorts of stuff that might not be a fit, and certainly isn't required to pass a Big 4 SOC2 audit. What was your experience there?

(I ask because SOC2 is sort of looming over us, though obviously it's not something we're jumping to do preemptively).

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#428

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

> Do you have any evidence for this?? I've just been involved in selecting Drata as a vendor for SOC2 compliance planning for our company. If this is true it's a huge deal and totally against my understanding of their business model. It honestly sounds like bullshit to me! But if you have evidence that they do this, please let us know. Unless their agent is Free Software, the reasonable end-user assumption is that th…

This is just a way of saying that every mid-to-large-sized company in the world is doing malicious things, because all of them depend on closed-source agent software of one kind or another. And you might be right about that! Certainly, the industry has not taken the threat of agent-based management tools seriously enough.

But what the hell is your point? This is about as practical an argument as "the only reasonable software for your company to run is free software". Even if it were true, it's so far outside of industry norms that you might as well be asking them to ship all their products on BeOS.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#429
post #293

Since this 'Drata' thing is intended to keep employees/contractor computers in check with policy requirements, runs as (equivalent of) root, and auto-updates, I assume it must be: * completely open source * have gone through security audits with public reports, and a favorable outcome * have reproducable and verifiable builds, and those are the only ones distributed, and the end user can easily verify that their bina…

The agent is intended to ensure devices meet the security/compliance requirements of the company. It is a lightweight read-only osquery based agent that we are happy to share the configuration of with prospects/customers.

To address some of your other points:

* We have been talking about making it open source, though it is not today.

* We do have a third party security validated report that we are happy to share with prospects/customers.

* Builds are pulled directly within the Drata portal and the agent does auto-update to ensure we can push any security updates to it that we need to. We do sign the code and you should be able to validate it.

Source: I am the Drata CTO

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#430

Earlier quoted context omitted.

I’d like to say no, but I’m not sure it’s an unreasonable request. I’ve recently been contracting and the only private account I used was GitHub, and that was a conscious decision to maintain a single public developer identity. Otherwise, I expected them to provide all hardware and software required to perform my role. And likewise, for security purposes, that’s exactly what they wanted as well. Tho I would note, the…

One of the legal guidelines for whether or not someone is a contractor (vs an employee) is whether they provide their own tools. It’s not a hard rule. It’s just one of a number of tests. But contractors are generally expected to provide their own tools.

But in that case I’d agree with the OP. I’m not installing what ever you want on my hardware.

I probably was more of a “temporary employee” than a contractor. But what’s the difference at that point? I was paid more than the value of entitlements as cash. It suited both parties, and was mutually agreed.

In hindsight, having them provide the hardware, and then handing it back at the end of the engagement would be my preference. It reduced any risks for them and me.

Tho I can easily imagine on/off or short infrequent contracting scenarios that this would not work for.

Post reply on HN