Live data from Hacker News

IBM bans USB, SD cards, flash drives and portable devices from every office

theregister.co.uk

1–10 of 202 posts

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#2
Seems like the move addresses accidental data leaks through portable device misplacement. I don't think it can do much to protect against intentional leaking. I mean, they want people to be able to work from anywhere from the sake of business, so I guess this addresses 1 vector. Hopefully, they understand this.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#3
I remember they came to our school to show off their new hot desk software they wrote. Look how efficiently we can use space! I saw it as saying your so unimportant we won't even give you a dedicated desk.

Now apparently you can't even use common tools to get the job done. If I had a big meeting I wouldn't take a chance on the network to keep my presentation.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#5
Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof!

Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#6
Within a business, security has to be understood in the context of risk analysis.

Will the measures taken damage the company more than the benefit of the increased security?

In my eyes, banning storage media without a practical replacement is on the wrong side of the risk analysis equation. Sure, it's not desirable that files can be moved without full access control and auditing, but if people don't have a tool that works the same way then all your employees who rely on it will suffer.

It would have been great to see a standard encrypted portable drive, probably with the decryption software on a different partition establish a foothold in the world. With the addition of DLP software, that could have allowed employees to continue to do their work while mitigating the risk of lost or stolen data.

edit: what this doesn't cover is transferring large files quickly, or transferring files to a computer that isn't currently configured with the systems required for file transfers.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#8

Seems like the move addresses accidental data leaks through portable device misplacement. I don't think it can do much to protect against intentional leaking. I mean, they want people to be able to work from anywhere from the sake of business, so I guess this addresses 1 vector. Hopefully, they understand this.

Well, it's still not going to stop the general institutional incompetence that permeates the company when it comes to security. For example: https://www.nytimes.com/2017/07/25/world/europe/ibm-sweden-d...

Keeping sensitive data off the cloud altogether is the more sensible option.

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#9
post #5

Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof! Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

Anyways, did IBM have a big leak recently or something?

Yes, this is almost certainly about leaks to publications such as El Reg. Eg. https://www.theregister.co.uk/2018/02/26/ibm_gives_services_...

Re: IBM bans USB, SD cards, flash drives and portable devices from every office

#10
post #9
post #5

Ha! If I worked at IBM they would never catch me. My flash drive is disguised as a tiny sports car! Foolproof! Anyways, did IBM have a big leak recently or something? This seems rather draconian to have been put into place without some fairly strong motivations.

Anyways, did IBM have a big leak recently or something? Yes, this is almost certainly about leaks to publications such as El Reg. Eg. https://www.theregister.co.uk/2018/02/26/ibm_gives_services_...

Wow, wouldn't want valuable corporate secrets such as your particular form of Agile leaking to outside sources. How devastating.
Post reply on HN