Live data from Hacker News

Ask HN: My client want an agent on my laptop. Is this the new normal?

news.ycombinator.com

261–270 of 506 posts

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#261

Earlier quoted context omitted.

> And they will install a trojan They WILL > which would eavesdrop your talks That absolutely WILL - use the microphone and listen to everything being said (why not the camera too and watch everthing?) > scan your home network and analyze its traffic. That absolutely WILL - do all this stuff I mean if this is definately going to happen, then the company can go ahead and cut an 8 figure cheque straight away. Which com…

> why not the camera too and watch everthing Because who doesn't have a lid/sticker over their webcam yet? I have also kill-switched the built-in mic in the BIOS set-up but I'm not sure how secure this is. I would prefer there to be no built-in microphones in any hardware (except phones) at all. Sadly every modern laptop is equipped with a mic.

That's one plus point for desktops and nettops with no-frills motherboards. No mic, no speakers, no bluetooth, no wifi.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#262

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

> The poster says "Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advertising". Do you have any evidence for this?? I read their Privacy Policy. They are quite explicit about what they plan to do to you. I raised the issue with them in an email (among 5 other issues). Their…

> I read their Privacy Policy. They are quite explicit about what they plan to do to you.

OK, well, I've skimmed it and I can't see anything that suggests they are going to spy on our employees and sell the data to advertisers. I hate to drop it back on you but which passages make you think they do that?

These things do often sound terrifying because things like "I'm going to use Google Analytics to see which parts of the product people aren't using so we can email them reminders" get turned into passages like "We will upload all your activity to a third-party advertising company for marketing purposes".

> I have worked with computer security at an advanced level ... A hostile agent would decrease the security on my network. That was my first thought when I got that awful email.

I believe you! 100%!

But you are unusual, and without verification a control such as "All laptops should have screens that lock after 5 minutes" won't be followed by everyone. NOT EVEN CLOSE to everyone.

> Also, I don't get it why that need such a thing on my PC. I don't have credentials to production systems or production data. I am a software developer. I work with code and documentation. That's it.

Sure. Another commenter in the thread has said that because of that this isn't strictly required for SOC2. I'm sure they're right.. but I'm not sure I want anyone working on our codebase at all who doesn't have basic security settings set on on their laptop (Again, I know YOU do :) )

Back to the using your own computer thing again - this is why I think lots of companies say "You use our hardware for all company work but IF you really really want to do BYOD then you have to accept some of these agents". Not sure if that's the attitude at your firm, but that seems reasonable.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#263

Earlier quoted context omitted.

You keep your work laptop in your home network? Tut tut.

If I couldn't trust my company on my home network, why would I work for them?

My employers laptop is in a separate VLAN. What makes you sure that no-one else than the employer has access to it. This laptop has Windows 10 installed for example. And a shit-ton of McAfee crap. I would trust my employer but not the many companies who have a foothold on the machine as well because my employer is too cheap to install decent stuff on it.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#265
post #257

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

Maybe I'm very naive here but does SOC2 explicitly require monitoring? Can't a contractor simply sign a form that says all relevant rules are followed on their end and thus if that's not the case, the company is off the hook? If active monitoring is really required than the only solution I see is one device/customer and thus as a freelancer I'd have to request said device be provided by the customer.

SOC2 auditors require evidence for controls being followed - repeated evidence over a long period of time.

What's evidence? I can't remember the exact details but imagine something like ... a screenshot of the security page of the Settings app on macOS, taken by every employee, on every laptop, once a week.

Or install the Drata Agent on all company laptops.

Perhaps a form would be enough evidence that you wouldn't have to repeatedly collect it... but I doubt it. Because otherwise couldn't ALL employees just sign a form and that would be that? Auditors know that people don't actually follow the rules carefully even if they claim they are going to.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#266

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

> The poster says "Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advertising". Do you have any evidence for this?? I read their Privacy Policy. They are quite explicit about what they plan to do to you. I raised the issue with them in an email (among 5 other issues). Their…

>> The poster says "Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advertising". Do you have any evidence for this??

> I read their Privacy Policy. They are quite explicit about what they plan to do to you.

That's not evidence, only your interpretation.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#267

Earlier quoted context omitted.

If this is really the kind of things this company would do… why are you working for them?

> If this is really the kind of things this company would do… Because, until last week they didn't. Now I have to figure out if I'm just an unreasonable, stubborn old guy, or if this requirement is out of band.

It is out of band. Refuse or this becomes normal.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#268

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

The underlying problem is they are asking you to trust Drata implicitly, sight-unseen, and give them unfettered access to their laptop. There is nothing preventing Drata from changing their minds and altering how their agent works or what it collects. Then there's the unintentional aspect. There is, of course, no guarantee their agent is bug-free. Data leaks and compromises happen all the time, by every facet of comp…

Grown-up companies doing SOC2 usually provide developers with hardware, and in that case the company is installing an agent from a vendor they have selected, onto their own computers.

True, the grey area is slightly odd situations like this where the protagonist is a freelancer rather than an employee and presumably also the company isn't willing to provide hardware to them in that case?? Because they're a freelancer?

Sounds like a case that isn't going to survive too long in any company that's getting serious about compliance and risks.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#269
We solved this by issuing company owned and controlled laptops to our contractors.

Disk encryption, screen time outs, remote wipe etc. contractor machines with code and production access are treated as critical assets and are fully under IT control.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#270

Earlier quoted context omitted.

Are you able to, as Your Company LLC, (self) certify yourself as a SOC2 complaint entity? Maintain your own records and be able to provide them for audits from the parent company? I agree with much of what has been said, security theatre etc etc; but at the highest level, should companies take IT security seriously , absolutely. Is the implementation correct? Probably / certainly not. The real cancer is the total dis…

> Are you able to, as Your Company LLC, (self) certify yourself as a SOC2 complaint entity? Maintain your own records and be able to provide them for audits from the parent company? I recognize that you are just making a creative suggestion here, but that is impossible. SOC2 certification is incredibly complex and hard to manage (not to mention, costing tens of thousands of dollars a year). It is difficult to the poi…

[deleted]
Post reply on HN