Live data from Hacker News

IBM bans USB, SD cards, flash drives and portable devices from every office

theregister.co.uk

91–100 of 202 posts

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#91
post #64

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

How can they prevent migration of talented people, given China's infinite war chest ?

> How can they prevent migration of talented people, given China's infinite war chest ?

The Renminbi is very difficult to convert.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#92

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

> Given their history of borrowing technology from other countries without attribution, Impressive choice of words!

Strictly speaking, borrowing assumes returning at some point.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#93
Most companies that are somewhat serious about their business and the privacy of their clients (and their clients' clients) have a removable media policy. IBM's is nothing special in that respect. Besides cutting down on exfiltration vectors it also nicely takes care of some ways in which you might end up with malware on your corporate systems.

If your company does not have some kind of removable media policy then you are probably working for a very small company.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#94
post #3

I remember they came to our school to show off their new hot desk software they wrote. Look how efficiently we can use space! I saw it as saying your so unimportant we won't even give you a dedicated desk. Now apparently you can't even use common tools to get the job done. If I had a big meeting I wouldn't take a chance on the network to keep my presentation.

>Now apparently you can't even use common tools to get the job done. If I had a big meeting I wouldn't take a chance on the network to keep my presentation.

Then you are an active threat to your networks security. You sound like you have an incentive and willingness to put in effort and take personal risks to circumvent the security protocol at your workplace. Looking at employees without bad intents, this is as bad as it gets.

This is a great example why social engineering is unlikely to go out of style anytime soon. People who think they know better and are confident in being qualified to take a risk are never in short supply.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#95

Earlier quoted context omitted.

An implementation I’ve seen had all ports locked down on the laptop itself and physically locked with a plastic plug that can’t be removed without leaving evidence. The keyboard and mouse were connected to a dock. On the OS level only HID devices were allowed via USB you could bypass this if you had admin rights but it would leave a trail. The idea behind these like most other security controls is to prevent accident…

> you could bypass this if you had admin rights but it would leave a trail A move I've seen being put in place at several locations, is removing local admin rights from all users. Those with advanced needs, like developers, gets a VM which is limited to a specific VLAN, with no access to the production environments. The principle is sound, implementation is ... difficult, to say the least.

And if you're willing to run a lot of screencaps or re-type the stuff you see on another computer you can still get the data out. Before modems were common in the hands of unwashed masses my friend and I would transfer files on the phone by spelling out blocks in hex. Slow but with a checksum every 16 bytes it was good enough to get some work done. If the data is high value enough it would probably be worth it.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#96
post #35
post #27

Earlier quoted context omitted.

This is also something very common in banking.

And hospitals (not the glueing part, but the blocking of anything that's recognized as a USB storage medium).

I met with a medical specialist at a huge hospital in New York - I had a usb drive with about 50G imaging data (pet, ct, mri) and they refused to access it.

Fortunately I was also hosting it on my own server in various formats - nope, they can’t access the external network.

I ended up burning the whole set to a spindle of dvds, which they could then import .. and shred.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#97
post #94
post #3

I remember they came to our school to show off their new hot desk software they wrote. Look how efficiently we can use space! I saw it as saying your so unimportant we won't even give you a dedicated desk. Now apparently you can't even use common tools to get the job done. If I had a big meeting I wouldn't take a chance on the network to keep my presentation.

>Now apparently you can't even use common tools to get the job done. If I had a big meeting I wouldn't take a chance on the network to keep my presentation. Then you are an active threat to your networks security. You sound like you have an incentive and willingness to put in effort and take personal risks to circumvent the security protocol at your workplace. Looking at employees without bad intents, this is as bad…

First, using USB drives was never against security policy at my work - so your personal attacks are unjustified. But secondly my powerpoint presentation isn't exactly top secret classified material.

If we were talking about handling the private signing keys I would agree with you. Different types of data have different levels of security needed. Over classifying trivial data just makes it harder to get things done.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#98
post #75

Interesting but seems kind of late, no? Even the US State Department has banned USB drives since at least 2008. I don't think US government is particularly well known for being good at security.

It’s one thing to ban stuff and another to actually provide practical solutions for people so that they can continue working. Banning stuff looks good on paper, but sometimes the clever work arounds people invent are then much worse than the original thing.

Practical example from past. Policy denies creating user accounts for externals. In big orgs you anyways sometimes have the need to have some external do work on systems. Idealistic view is that employee baby sits the ext guy and performs everything on behalf of him. But in reality people have their own work and deadlines, so it becomes tempting to just log on and let the ext work on your credentials.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#99
post #35

Earlier quoted context omitted.

And hospitals (not the glueing part, but the blocking of anything that's recognized as a USB storage medium).

I met with a medical specialist at a huge hospital in New York - I had a usb drive with about 50G imaging data (pet, ct, mri) and they refused to access it. Fortunately I was also hosting it on my own server in various formats - nope, they can’t access the external network. I ended up burning the whole set to a spindle of dvds, which they could then import .. and shred.

Many companies do not allow the physical removal of “hard drives” and must be shredded before they can exit a door, which is why the “keep your drive” warranty policy is quite popular with many companies.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#100
post #92

Earlier quoted context omitted.

> Given their history of borrowing technology from other countries without attribution, Impressive choice of words!

Strictly speaking, borrowing assumes returning at some point.

Is it "returning" a thing to sell it back to the people from whom you "borrowed" it?
Post reply on HN