Earlier quoted context omitted.
I work for a crypto currency company and it was the first time in my career that I was issued a YubiKey (I once had an RSA 2fa token for vpn access). It took some getting used to but now I just keep in on my keychain and I always have it with me. I need it for SSO, git, VPN, and basically all internal services. They aren't sufficient by themselves however, they don't protect from is malicious internal employees.
Preparing for malicious internal employees seems to me like preparing for "the big one," in the northwest. Do a cursory amount of preparation. Outside of basic measures, you're probably doing more harm to the business than good. The likelihood of internal malicious attackers is very low in the grand scheme of things, and the attack surface is huge. Most companies are going to be compromised by outside attackers—its t…
https://www.washingtonpost.com/national-security/former-twit...
If you're hit by a paywall:
https://web.archive.org/web/20200717083254/https://www.washi...