Live data from Hacker News

Ask HN: My client want an agent on my laptop. Is this the new normal?

news.ycombinator.com

291–300 of 506 posts

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#291

If you are a freelancer then your contract should allow you to do work for others. In which case, your response to this client has to be "Sorry, but my business laptop potentially has data from other clients on it. I can't let you install this monitoring agent without violating my contractual confidentially agreement with those other clients. I always maintain client confidentiality and will do the same for you. If y…

> If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it And they will install a trojan which would eavesdrop your talks, scan your home network and analyze its traffic.

Where are these IT depts that have all this unlimited time and resources to spy on their employees?

Sure you might get a bad actor voyeur, but as a matter of policy, companies just don't care what you're doing at home as long as their security interests are protected.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#292
I've being running a contract development shop for about 20 years and I think that this is very out of line.

That said, our usual approach to dealing with customer-required installs like VPN clients is to just spin up a VM using VMWare Workstation on our development machines and do all of the things that touch their network with that. Given the nature of our work, we connect to their environments as little as possible and we leave those VMs off at all other times. We haven't had any problems with that approach thus far.

Additionally, we don't offer our clients the option of giving us development laptops for our work with them. That just makes us churn hours without producing anything while we deal with whatever local IT silliness they have.

Technical considerations aside, the idea that they want to spy on their contractors is troubling and I'd get away from that situation as soon as possible. Unless they decide to pull back on these requests, it sounds like they'll be just be emboldened to micromanage even more.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#293
Since this 'Drata' thing is intended to keep employees/contractor computers in check with policy requirements, runs as (equivalent of) root, and auto-updates, I assume it must be:

* completely open source

* have gone through security audits with public reports, and a favorable outcome

* have reproducable and verifiable builds, and those are the only ones distributed, and the end user can easily verify that their binary copy is an official build?

Right?

Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application?

[edit: formatting bullet list]

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#294

Earlier quoted context omitted.

SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it. It’s an absurd system.

Reminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we…

The point, with a TON of these certifications/auditing/whatever, is usually "Are you aware of risk X/Y/Z and are you either mitigating it or accepting it?" In this case, you are now aware that all outbound traffic is allowed, and you are accepting that risk as a risk of doing business with that payment processor.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#295

If you are a freelancer then your contract should allow you to do work for others. In which case, your response to this client has to be "Sorry, but my business laptop potentially has data from other clients on it. I can't let you install this monitoring agent without violating my contractual confidentially agreement with those other clients. I always maintain client confidentiality and will do the same for you. If y…

> If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it."

That's what Statnett in Norway did when I did some work for them a year ago (Lenovo X1 Carbon). The difference being that installing anything on it was pretty much impossible. All traffic went through the Statnett VPN. It's the most security conscious company I have had any experience of.

But I was also able to use my own laptop by installing the Citrix client and that was much better. I had never used Citrix before and was pleasantly surprised at how fast it was.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#298

Earlier quoted context omitted.

My company is going through our SOC2 audit. We do not have such software and everyone is remote. I call BS as to the justification. This smells like a desire for corporate monitoring.

SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it. It’s an absurd system.

Yes and no. SOC2 doesn't say you need to install an agent, and may not be explicitly prescriptive about whether computers that have access to production data or systems need encrypted drives, screenlocks, etc. But a non-hack SOC2 auditor is going to expect you to have some reasonable policy and controls in that area. So yeah, the main thrust of SOC2 is "are you following your own internal policies", but the auditors are also expected to hold you to some minimal standards on your policies (or ask you to provide a good explanation why they shouldn't apply in your case). You definitely would't want to tie yourself to a particular agent in your policy, but the auditors will want to see some kind of policy and then require evidence for that, either from something like an agent or screenshots/etc.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#299
post #167

Earlier quoted context omitted.

I think this is the correct advice, but keep in mind that procuring the laptop might be a difficult thing for them to do bureaucratically. On the other hand, you renting a laptop and charging them for it, would be pretty simple, presumably your contract covers expenses and all you'd need is an OK from the manager. I worked for a big company that had various spyware thingies installed on all the company laptops, but t…

Arguably, the new laptop being difficult to procure is a feature, not a bug. It serves as a deterrent to installing that agent, if it's easier to just make an exception.

Or they reimburse the consultant when they procure their own dedicated laptop for the client's work.
Post reply on HN