Live data from Hacker News

IBM bans USB, SD cards, flash drives and portable devices from every office

theregister.co.uk

51–60 of 202 posts

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#51
post #26

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

How do you connect a keyboard or mouse?

A docking station.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#52
post #31
post #15

Earlier quoted context omitted.

With the rise of VPNs, fast home internet, and fairly ubiquitous public wifi along with laptops gaining enough power for most applications the question is what's the real use case that requires removable media that can't be accomplished with an internal FTP/network drive/email and using company laptops?

>"fairly ubiquitous" If I'm giving a presentation to hundreds or thousands of people in 30 minutes and a laptop goes down/won't connect to projector, presentation wasn't loaded or was corrupted on the speaker laptop, things go sideways in a bunch of other ways (and they do), I don't want to be in the position of depending on the network to pull down a presentation from somewhere. Especially if I don't have my own lap…

Sometimes security is annoying, and sometimes security means you don't get to do what you needed to do. An event with hundreds or thousands of people should have rehearsals and spare speaker laptops, but if they don't, your need to present doesn't trump your (or someone else's) employer's cyber security stance.

Show up at a building site without your helmet and hiwiz? Unless there's a spare set around, you're going home. We need to get into the same mindset around cyber security.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#53

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

Are cases locked / glued shut? It seems like it would be easy enough to connect a new usb header...

While visiting a Chinese division of an American company I worked for about 8 years ago they had Dell desktops, in a tower configuration and they had a metal (steel) super structure around them. A case within a case.

You could unlock it, plug in USB, monitors, ethernet, etc. route the cables out through a slot and then lock it. You couldn't reach the the different ports and sockets when it was locked. It was all relatively stout too.

Interestingly, they did have internet in the building but you had to have management permission and go to the security office to access it. If you wanted to download something, it was a fairly involved procedure. They were paranoid about people stealing their stuff and then also very paranoid about misappropriating something they shouldn't and creating legal problems in Europe or North America. They didn't seem to be all that concerned about stealing other people's IT but they wanted to control everything such that it didn't contaminate anything they wanted to sell where it mattered.

I nearly created a situation when I pulled out my phone to take a picture of an "engrish" sign they had on the wall.

It'll be interesting to see how the security culture in the US changes or doesn't, a lot of younger developers would be put off if you attempted to somehow restrict their access to the internet from work computers or restricted your ability to plug a phone or some arbitrary device in for charging of whatever. At every job I've had this century it has been fairly trivial to download nearly all of their source code and take it home if you wanted to. Trying to take the politics out of it, we're very much engaged in a cyber cold war with a number of nations that absolutely want to take our secrets; I won't speculate on the real impact but the Russians did meddle in our election.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#54
post #13

This is already standard practice for several industries. For example, you’d be hard pressed to find a pharma company nowadays that allows the use of any removable media. The likely “replacement” is that IBM employees will have to use some sort of corporate VPN to work remotely.

[deleted]

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#55

Just another act of IBM's security theatre, and a testament to their backwards views on employee experience.

You're not wrong on their poor employee experience, but there's very little theater involved - there's good reason to protect their IP. Any firm that invests multi-millions in original design will want to protect their property from theft. Semiconductors were mentioned, but also think about someone like Pixar.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#56
post #22
post #15

Earlier quoted context omitted.

With the rise of VPNs, fast home internet, and fairly ubiquitous public wifi along with laptops gaining enough power for most applications the question is what's the real use case that requires removable media that can't be accomplished with an internal FTP/network drive/email and using company laptops?

Offshore work, for instance. Lots and lots of vessels have painfully slow satellite links - think Trust me, in such conditions you do not want to cough and ask whether you can download your training material off the corporate VPN... (Heck, in many cases, shipowner policy prevents any third party computer from being connected to any onboard IT infrastructure, anyway.)

In context of the original post though, it's unlikely IBM engineers are doing much work on ocean going vessels with 64-512kbps satellite links

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#57
post #9
post #5

Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof! Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

Anyways, did IBM have a big leak recently or something? Yes, this is almost certainly about leaks to publications such as El Reg. Eg. https://www.theregister.co.uk/2018/02/26/ibm_gives_services_...

when i viewed that link there was an ibm advertisement on the top and an interstitial one as well. couldn't help but chuckle.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#59

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

Another common approach is thin clients that connect to VM's running on servers in protected rooms. My company does that. From there, most critical apps are web apps they monitor. Specific things that need Windows or Linux run in the VM's. There's even some solutions that support connecting USB devices to thin clients for use on remote VM's with some security on that process. I have no idea if that security is good but there's potential for secure devices designed for these use cases.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#60
post #31

Earlier quoted context omitted.

>"fairly ubiquitous" If I'm giving a presentation to hundreds or thousands of people in 30 minutes and a laptop goes down/won't connect to projector, presentation wasn't loaded or was corrupted on the speaker laptop, things go sideways in a bunch of other ways (and they do), I don't want to be in the position of depending on the network to pull down a presentation from somewhere. Especially if I don't have my own lap…

Sometimes security is annoying, and sometimes security means you don't get to do what you needed to do. An event with hundreds or thousands of people should have rehearsals and spare speaker laptops, but if they don't, your need to present doesn't trump your (or someone else's) employer's cyber security stance. Show up at a building site without your helmet and hiwiz? Unless there's a spare set around, you're going h…

It's going to depend on the circumstances and, perhaps, we really will decide over time that moving USB keys among untrusted laptops is simply a bridge too far. But, literally just this afternoon, used a USB stick to transfer a presentation to a (supposedly clean) speaker laptop that hadn't been preloaded like it was supposed to be. The circumstances (~100 person event, no rehearsals or heavyweight IT support) made that seem reasonable.

Cybersecurity is indeed important. But it's about managing risk, not minimizing it no matter the cost. And what I'd do at an event like this one is quite different from Defcon where I'd take the most stringent precautions possible.

Post reply on HN