Live data from Hacker News

Using Brave's “Private Window with Tor” could get you fired

old.reddit.com

41–50 of 72 posts

Re: Using Brave's “Private Window with Tor” could get you fired

#41
I've been working in the IT industry way too long. Any devices provided by my employer will only have whatever the employer has preloaded in terms of software. I will not browse any private or personal things on that device. I'm under constant assumption that device is keylogged/monitored. Even when working from home, I have it connect to it's own private network on it's own VLAN.

If I do go into the office, I'll just use my cell-phone for personal browsing.

Re: Using Brave's “Private Window with Tor” could get you fired

#42
post #23

Earlier quoted context omitted.

That seems super risky. How did you know the file was authentic? What if the archive contains backdoored code?

Yeah it was risky. It is quite common for excessive security practices to actually decrease security and that particular example was not nearly the most egregious one in that company.

I don't really get why you did it though. You risked your job, and potentially regulatory issues for the company just to get a build done? I'd have just submitted a request to unblock the official download site. Then it's security's problem.

Re: Using Brave's “Private Window with Tor” could get you fired

#43
post #41

I've been working in the IT industry way too long. Any devices provided by my employer will only have whatever the employer has preloaded in terms of software. I will not browse any private or personal things on that device. I'm under constant assumption that device is keylogged/monitored. Even when working from home, I have it connect to it's own private network on it's own VLAN. If I do go into the office, I'll jus…

I have that same mindset, but at the last two companies I've been at, I was a bit disturbed that the software policy was basically, "If you need it, just go to the website and download it. Don't download a virus, good luck!"

Re: Using Brave's “Private Window with Tor” could get you fired

#44
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

From another perspective (perhaps not popular here): How does allowing access to restaurant websites help the bottom line? What is the risk? One malware outbreak can be enormously damaging. How much time should IT employees spend unblocking restaurant websites instead of, for example, developing new applications that increase productivity? Arguably, an IT employee who is spending time unblocking restaurant websites m…

Yes. Exactly. Which is why they shouldn't be blocked, forcing people to spend time and energy unblocking them.

Re: Using Brave's “Private Window with Tor” could get you fired

#45

There are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their o…

What do they do about personal devices?

Re: Using Brave's “Private Window with Tor” could get you fired

#46

There are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their o…

It's absolutely reasonable to have security requirements. It's not reasonable to fire someone for a single, accidental violation. I hope the people in the above story realize that they've made a mistake.

It is if you have a zero-tolerance policy and they break it.

Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware!

But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people.

There’s a popular view with some freedom folks that we shouldn’t have the right to search people who are visiting family in jail, and while they’re right from a purely theoretical “my rights” standpoint, from a pragmatic stance it is generally understood that it’s fair to try not to let weapons be given from visitors to criminals, even if abrogation of rights occurs — and if you forget and bring a knife someday, you may get banned from the jail, even though it’s just a mistake, because of how serious the safety and lives are at stake.

Re: Using Brave's “Private Window with Tor” could get you fired

#47
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

Meanwhile at work I can't convince the "firewall guy" to block YouTube to save bandwidth for actual work ... Even porn websites aren't blocked!

Re: Using Brave's “Private Window with Tor” could get you fired

#48

Earlier quoted context omitted.

It's absolutely reasonable to have security requirements. It's not reasonable to fire someone for a single, accidental violation. I hope the people in the above story realize that they've made a mistake.

It is if you have a zero-tolerance policy and they break it. Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware! But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people. There’s a p…

Who would be comfortable working under such a policy? You'd never know what accidental action on your computer could lead to you being fired. Using a computer to do work is not like getting dressed and carrying a knife with you. You knew you put the knife there, you chose it. If you weren't thinking about the rules, that's on you.

A regime where any accidental fat-finger or triggering of an unknown keyboard shortcut results in dismissal will quickly produce an environment where nobody is able to work or do anything useful - as seems to be happening here.

Re: Using Brave's “Private Window with Tor” could get you fired

#49
post #24
post #23

Earlier quoted context omitted.

That seems super risky. How did you know the file was authentic? What if the archive contains backdoored code?

Seems like an odd proposition for an attack vector. Maybe, just maybe if I make this look like a misconfigured server, maybe, just maybe, someone will grab the boost files from the server and compile them? I can’t imagine.

I've heard of people doing similar things before. Maybe people working in high security environments downloading libraries from random websites is common enough that some attackers are actually targeting those people by backdooring common Python packages, C++ libraries, etc. and trying to get their server to bypass enterprise blocking somehow.

Re: Using Brave's “Private Window with Tor” could get you fired

#50
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

From another perspective (perhaps not popular here): How does allowing access to restaurant websites help the bottom line? What is the risk? One malware outbreak can be enormously damaging. How much time should IT employees spend unblocking restaurant websites instead of, for example, developing new applications that increase productivity? Arguably, an IT employee who is spending time unblocking restaurant websites m…

Indeed. Somehow people managed to eat lunch before the internet.
Post reply on HN