Live data from Hacker News

IBM bans USB, SD cards, flash drives and portable devices from every office

theregister.co.uk

61–70 of 202 posts

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#61
post #5

Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof! Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

I too thought of it as being draconian at first but come to think of it, USB drives seem much less important nowadays than they seemed back in 2007. They're still prolific, but they aren't thought of as a boon as they once were. Maybe IBM is onto something.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#62
post #9
post #5

Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof! Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

Anyways, did IBM have a big leak recently or something? Yes, this is almost certainly about leaks to publications such as El Reg. Eg. https://www.theregister.co.uk/2018/02/26/ibm_gives_services_...

Slack instead of email?

That's hilarious.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#64

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

How can they prevent migration of talented people, given China's infinite war chest ?

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#66

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

> the usb ports are disabled and the usb ports on new issue computers are epoxied to prevent trying to use them.

That means many current day laptops can't be charged.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#67
post #35
post #27

Earlier quoted context omitted.

This is also something very common in banking.

And hospitals (not the glueing part, but the blocking of anything that's recognized as a USB storage medium).

Absolutely - I don't understand why this is "new", "odd" or "difficult".

I work for an European company (travel/tourism) and the day they hired me (4 years ago) I got a corporate laptop with Windows 7 which would accept usb mouses, keyboards, charge smartphones... but would not "mount" anything that had storage. Interestingly enough I can connect my (personal) iPhone, and I can read pictures stored there, but I cannot write to it - I haven't tried installing iTunes because I don't need to backup to my work laptop so no idea how it would work with dedicated sw, but for sure there is no need to use epoxy glue or physical locks.

(Granted, I never tried to see how strong the protection was because it's not my specialty and frankly I don't care, but it looks like it works well enough as it is).

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#69
Would it be possible to just disable the usb driver from the OS(or just limit it, to a very very few tasks). Without it being a burden for UX purposes. One could argue that an exploit might be written in such a way that, it could be triggered before the OS boots from the BIOS. But, at that point, any external user-land exploit would provide the same level of access to sensitive data.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#70

Would it be possible to just disable the usb driver from the OS(or just limit it, to a very very few tasks). Without it being a burden for UX purposes. One could argue that an exploit might be written in such a way that, it could be triggered before the OS boots from the BIOS. But, at that point, any external user-land exploit would provide the same level of access to sensitive data.

Would it be possible to just disable the usb driver from the OS

For that you would need the capabilities of a world-class IT outsourcing company.

Post reply on HN