Live data from Hacker News

IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

openera.com

51–53 of 53 posts

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#51
post #32

The "cloud" is a huge problem in the finance, legal, healthcare, and educational fields. Confidential client/patient/student data leaking out all over the place is a disaster waiting to happen, not to mention often outright illegal. Let me give you an example: I recently bought a Livescribe Skypen, the new one with Wifi. It automatically syncs with Evernote, and works like a charm. But I can't use it for purpose, tak…

Evernote, Dropbox, Google Docs. All have TOS and things like Apps can have contracts. Apps has a DoD clearance.

There is a legal distinction between subcontracting out services and sharing data. One that has no difference from paying for a service contact that allows a vendor to login and fix your db.

There are very few situations where EVERYTHING must be internal.

Google Apps is big in education, so "sharing" data under contract must be legal.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#52
post #18

Sadly in large companies with IT departments that have accountability and as such have internal costing to another department. Well in those sitauation it is often common for one department head to go behind official channels and outsource for a cheaper price. This sadly bypasses alot of security and other standards the company has. It's not new, and will happen again and again. One example would be bank that had a w…

WTF?

Sorry I realy don't understand your question!

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#53
post #50

Earlier quoted context omitted.

Just to clarify: are you more concerned about the Googlebot reading your documents to sell you consumer products than you are about employees attaching business or customer data to email or shared docs? Because I'm operating with a much different threat model. Email is not and never has been secure. It is sent in plaintext unsecured from one unauthenticated mail server to the next. The moment the user attaches data t…

Uploading patient/client data to the cloud where a Google bot can read it is a breach of that patient/student's privacy. Blackberry email and the like can make email within the organization secure, and most teachers/doctors have the sense not to email sensitive documents to people outside the organization. However, most don't realize that emailing something to your gmail or uploading it to google docs is a problem. T…

Maybe you've been subjected to more complete DLP systems than I have, but email "within the organization" is not and never will be "secure".

Every time I've seen customer demographic data emailed (although admittedly this hasn't been in the medical field), both the sender and the receiver have been employees (including myself) who weren't entitled to see that data. Organizations need to find more appropriate ways to collaborate, which don't needlessly expand the pool of people with access to sensitive data.

You seem to trust a pool of 100 people, even if they have acronyms following their names, more than you trust a search engine, to not share data in legally negligent ways. That seems ill-advised to me. If the Googlebot were generating lawsuits for breach of privacy we would have heard about them.

I don't think this sensitive customer data should be in Gmail, because I don't think it should be in any email system period.

Post reply on HN