Live data from Hacker News

IBM bans USB, SD cards, flash drives and portable devices from every office

theregister.co.uk

121–130 of 202 posts

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#121
post #108

Earlier quoted context omitted.

I am sorry if it came across as a personal attack, I didnt want to imply that you are personally negligent or unqualified to make that call. For all I know it is your job to make those policies at your place off work. The problem is a User with this attitude whos job isnt to make that call. Strictly speaking, If a user in a workplace where this behavior is against the security policy acts like this or expresses this…

The problem with blanket policies like this for an entire organization is that they don't consider the type of work being done. A publicist for example has as their job to distribute information publicly, you aren't helping them by making it impossible to drop off a USB key to someone. A software developer has a need to install operating systems much more frequently than an average user. You can net-install but usb m…

That doesnt make individual users less of a security risk. This boils down how much harm an individual user can do, most of which the individual user doesnt have the full grasp off. It can be a simple as introducing something into a system and enabling an inside attacker or walking around with a audio keylogger in form of a usb stick. Your laptop with a borrowed usb stick can record the sound of someone way above your security clearance typing in sensitive data while being in the same room. This sensitive data might be a trivial as a cost center number.

Those rules arent draconian, someone somewhere was hired to make a risk assessment and found them to be necessary. You dont circumvent them period. Thats the responsibility of each an every employee. No matter if you think they are stupid, it isnt your call to make, except if someone hires you for exactly that, then they are your responsibility to do right.

Most attacks arent some espionage stuff, its plain and simply precaution against fraud and theft. And they target people who are to proud for their own good who never think of themself being at threat. Which is sadly something a lot of computer scientists have a bit of a problem with. No one wants to believe they could be duped like that, they surely would know it better. Security policies are there to not have to rely on individual egos and look at it more realisticly. Most of us will be duped when taken advantage of in a bad moment without enough time to think about it. Thats why people do it.

There is a reason even the CEO and CSO have to wear their badges. There is a reason a lot of Snowdens colleges started to get really scared once it became clear which credentials he used to access the files. And they were lucky, he could have been a criminal and sure as hell wouldnt have mentioned that those data leakages where his responsibility. He could have simply been a criminal transferring money in their names.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#122
post #26

Earlier quoted context omitted.

How do you connect a keyboard or mouse?

To be fair, they are not completely locked down like I may have made it sound. The usb port restriction is absolutely true for laptops, but colo desktops probably do not have this restriction, or just a more lax restriction. Also, its not true for all laptops of the company, but usb access does require explicit permissions and a new-issue laptop, so they do have a list of people who have riskier laptops, and may need…

The solution I have seen for desktops is to put them inside a locked metal case.

You cannot access anything besides the power button.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#123

Earlier quoted context omitted.

An implementation I’ve seen had all ports locked down on the laptop itself and physically locked with a plastic plug that can’t be removed without leaving evidence. The keyboard and mouse were connected to a dock. On the OS level only HID devices were allowed via USB you could bypass this if you had admin rights but it would leave a trail. The idea behind these like most other security controls is to prevent accident…

> On the OS level only HID devices were allowed via USB Of course that's enough to run malware. Just inject Win+R, cmd, enter,

You are missing the point you don’t need a rubber ducky to input malware, all you need is a sheet of paper and some time.

On restricted workstations even if you can run command prompt which isn’t guaranteed it won’t lead to anything.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#124

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

I used to work in semi- in Asia, and it was pretty loose compared to Financial and Pharma. Maybe things have gotten tighter, but...

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#125

Earlier quoted context omitted.

> you could bypass this if you had admin rights but it would leave a trail A move I've seen being put in place at several locations, is removing local admin rights from all users. Those with advanced needs, like developers, gets a VM which is limited to a specific VLAN, with no access to the production environments. The principle is sound, implementation is ... difficult, to say the least.

I’ve not seen this approach, but it’s definitely an interesting one. What do you do about the people who actually need production access?

Well, bias towards "infrastructure as code" and minimise the need to actually access the servers. Read logs through Splunk, configure through version controlled Puppet (or similar tools).

The only machines that can actually SSH into prod at least have screen-session-recording software, perhaps are kept in a separate room, with a policy of two staff present at all times. The general idea is that the closer you actually get to being able to bypass the checks and controls, the more attention you bring to yourself and your errand.

Yes, it can't be Git and Puppet all the way down, at some point someone will necessarily have access to do something as root on the server that hosts the Git repo that Puppet runs from. But instead of that being every dev on every laptop anywhere in the world, you can make sure it's a very small group of people, from a small number of workstations.

This is difficult and requires a substantial and very competent team to implement correctly.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#126
post #121

Earlier quoted context omitted.

The problem with blanket policies like this for an entire organization is that they don't consider the type of work being done. A publicist for example has as their job to distribute information publicly, you aren't helping them by making it impossible to drop off a USB key to someone. A software developer has a need to install operating systems much more frequently than an average user. You can net-install but usb m…

That doesnt make individual users less of a security risk. This boils down how much harm an individual user can do, most of which the individual user doesnt have the full grasp off. It can be a simple as introducing something into a system and enabling an inside attacker or walking around with a audio keylogger in form of a usb stick. Your laptop with a borrowed usb stick can record the sound of someone way above you…

I would love to see the cost benefit analysis that showed a company wide ban on USB keys would save more money than it cost.

Meetings happen daily, an iffy wifi connection is enough to waste the time of everyone in the meeting (10 minutes x 15 people is 2.5 person hours). These mundane things happen day in and day out. Someone walking around with an audio based keylogger is dramatically less likely to happen (and this ban on USB drives wouldn't prevent that anyways).

If you ignore the cost of people's time then pretty much every security idea makes sense. But its not a good way to run a business.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#127

Earlier quoted context omitted.

Awesome! A GMSK modem in js? Good on you. Submit for show HN? Have you tried other modulations?

Thanks! It made the rounds on show HN a couple years ago. Also my dirty secret is that it isn't really JS, it's C via emscripten https://github.com/quiet/quiet Currently supports everything Liquid DSP supports which is GMSK, PSK, QAM, OFDM and a lot more. Working on adding DSSS soon edit: Here's a sort of lab/playground https://quiet.github.io/quiet-profile-lab

So what transmission rate can you hope to get with this?

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#128

I hope employees don't use sonoff wifi plugs :)

Is there something particularly bad about Sonoff (as opposed to most other IoT devices, where the saying "the S in IoT stands for security" applies)?

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#129

Within a business, security has to be understood in the context of risk analysis. Will the measures taken damage the company more than the benefit of the increased security? In my eyes, banning storage media without a practical replacement is on the wrong side of the risk analysis equation. Sure, it's not desirable that files can be moved without full access control and auditing, but if people don't have a tool that…

In this case, is cloud storage not a practical replacement?

The analog loophole. If I can access the resources from my local device. The odds are I can get a copy of it without the protections on it.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#130

This is common at many semiconductor companies. Not only is it a ban at one specific semiconductor oem I know of, the usb-ports are disabled and the usb-ports on new issue computers are epoxied to prevent trying to use them. Semiconductor technology is one of the areas of global-technological competition which surely benefit from secrecy. For example, several years ago one of the c-level executives at this specific O…

> Given their history of borrowing technology from other countries without attribution, Impressive choice of words!

It's always been an arms race and nations and companies have always strategically opened themselves up to acquire knowledge.

When Germany was trying to catch up to the industrialised UK, they send business people to the UK to copy the layout of factory floors to reimplement them at home. For the longest time, Japan only allowed trade under restrictive conditions to maximise exposure to foreign technologies while minimising the impact of foreigners in Japan. It's a story as old as history and I honestly don't get why people are upset about it.

It's even beneficial for the ecosystem overall because it helps transmitting knowledge and technology from advanced to disadvantaged regions, which in turn accelerates production and development.

Post reply on HN