Live data from Hacker News

Using Brave's “Private Window with Tor” could get you fired

old.reddit.com

61–70 of 72 posts

Re: Using Brave's “Private Window with Tor” could get you fired

#61
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

I work in IT security and this overzealous blocking is also a problem. Many sites with great security info are blocked because of the "hacking" category. Um yeah that's work-related for me so...

I'm surprised they didn't just block tor though. I'm sure we do though I've never tried :) Our proxy MITMs everything.

Re: Using Brave's “Private Window with Tor” could get you fired

#62
post #23

Earlier quoted context omitted.

That seems super risky. How did you know the file was authentic? What if the archive contains backdoored code?

Yeah it was risky. It is quite common for excessive security practices to actually decrease security and that particular example was not nearly the most egregious one in that company.

I've also come across this at a major international company. Came there to install an update. Too big to email so I had a clean USB stick. No way to use it in their workstations though, so the IT guy offered to just walk to the DC and plug it directly into the server.

Pretty sure that was not the intention of that policy. The problem is, that they didn't seem to have considered this usecase at all. More security theater than anything.

Re: Using Brave's “Private Window with Tor” could get you fired

#63
post #41

I've been working in the IT industry way too long. Any devices provided by my employer will only have whatever the employer has preloaded in terms of software. I will not browse any private or personal things on that device. I'm under constant assumption that device is keylogged/monitored. Even when working from home, I have it connect to it's own private network on it's own VLAN. If I do go into the office, I'll jus…

Exactly. It's the employer's property, and aren't there such things as devices you own?

Why blur the lines on something like that? This reads more like an overreaction to a lapse of judgment more than anything else.

Re: Using Brave's “Private Window with Tor” could get you fired

#64

Earlier quoted context omitted.

Don't browsers these days loudly warn you if something like that is happening?

Most browsers (with the exception of Firefox which has its own store) trust root certificates installed on the OS (at least for Windows/Linux/macOS.) With mobile devices (iOS/Android), web browsers also trust custom root certificates, but apps have the ability to reject them.

Firefox on Windows can also be configured to use the system store. Most corporate admins would do this because it makes for only having to manage them in one place. On Mac it can't though, and on Linux there isn't really a definitive system one (unless you consider OpenSSL's).

Re: Using Brave's “Private Window with Tor” could get you fired

#65
post #12

Earlier quoted context omitted.

Most of them use group-policies and other software to install root-certs onto company devices. HTTPS won't help you with MITM in that case.

Don't browsers these days loudly warn you if something like that is happening?

No not if the cert is preloaded into the system store or browser.

However mobile platforms are more finicky now. For example in Android 7 and above you can no longer add certs to the system store in most management modes. Only to the user store. And apps can choose whether to obey the user store or not. So many apps then refuse to work.

There's a few management modes that do allow it but they require a full wipe to start the enrollment process which starts from the setup wizard.

Re: Using Brave's “Private Window with Tor” could get you fired

#66
post #34

Earlier quoted context omitted.

From another perspective (perhaps not popular here): How does allowing access to restaurant websites help the bottom line? What is the risk? One malware outbreak can be enormously damaging. How much time should IT employees spend unblocking restaurant websites instead of, for example, developing new applications that increase productivity? Arguably, an IT employee who is spending time unblocking restaurant websites m…

Not restaurant specifically, but I suspect the loss of innovation from the general chilling effect is pretty high. When I have trouble researching something, that’s money lost for them in time I am wasting, and potentially worse from the side effects. Every time an engineer doesn’t look into something at all, because they know odds are good they’re not going to be able to, that’s potentially millions lost.

Yeah imagine a developer not being able to use stackoverflow or one of the many similar sites that just happen to have the bug that they're struggling with. Could cost hours of extra work.

Re: Using Brave's “Private Window with Tor” could get you fired

#67
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

From another perspective (perhaps not popular here): How does allowing access to restaurant websites help the bottom line? What is the risk? One malware outbreak can be enormously damaging. How much time should IT employees spend unblocking restaurant websites instead of, for example, developing new applications that increase productivity? Arguably, an IT employee who is spending time unblocking restaurant websites m…

> From another perspective (perhaps not popular here): How does allowing access to restaurant websites help the bottom line? What is the risk? One malware outbreak can be enormously damaging.

Just visiting a website shouldn't be a major risk. Any code injection exploits can be mitigated in the proxy (those MITM proxies are not just for logging!). And proper patching.

Really if you run browsers so old that they can be exploited in this way you have a bigger problem than banning unknown websites solves.

Re: Using Brave's “Private Window with Tor” could get you fired

#68

Earlier quoted context omitted.

It is if you have a zero-tolerance policy and they break it. Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware! But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people. There’s a p…

I thought in American prisons visitors mostly talk through glass? But maybe that's just something used in movies. Never been to an actual prison even here lol.

I'm not an expert, but my understanding is: Often, but not all the time. Depends on how high-security the prison is, and what the purpose of the visit is. Meeting with an attorney, for example, you're likely in private and there may or may not be glass.

The addition of plexiglass (for instance) was considered an unwelcome one recently in some prisons: https://thecrimereport.org/2021/07/20/captives-behind-plexig...

Re: Using Brave's “Private Window with Tor” could get you fired

#69

In the interim, have the IT folks setup a group policy to disable Brave's Tor feature so no one else accidentally gets caught in this: https://support.brave.com/hc/en-us/articles/360039248271-Gro...

But would you if it isn't even an allowed application in the first place?

Re: Using Brave's “Private Window with Tor” could get you fired

#70

I can fully understand why a company doesn't want Tor traffic coming from inside the firewall. But this case, if the sort description is accurate, should have been cleared up with a conversation with the employee possibly resulting in temporarily banning Brave until they can actually deploy it in a configuration that works with company policy. Again, IF the description is accurate, the employee was using a browser al…

According to what I read, the manager attempted to go to bat for the employee, and basically did everything they could short of flat out refusing to fire the person. After this incident, the manager and most of the remaining devs on the team are now looking for new jobs. I can't say as I blame any of them.
Post reply on HN