Date: 2007-08-01 03:01 pm (UTC)
From: [identity profile] thecrazyfinn.livejournal.com
'How to get fired for security breaches in 10 easy steps' is more like it.

(no subject)

From: [identity profile] xforge.livejournal.com - Date: 2007-08-01 05:47 pm (UTC) - Expand

Date: 2007-08-01 03:19 pm (UTC)
From: [identity profile] asbrand.livejournal.com
LOL - I'm sure most of us already knew all of this. ;-)


-Az

Date: 2007-08-01 03:23 pm (UTC)
From: [identity profile] taleya.livejournal.com
They need a huge disclaimer:

"DOING THIS SHIT WILL GET YOUR ARSE FIRED"

Surprisingly, we are employed to work. Mindboggling I know, but it's true...

(no subject)

From: [identity profile] taleya.livejournal.com - Date: 2007-08-01 03:44 pm (UTC) - Expand

(no subject)

From: [identity profile] taleya.livejournal.com - Date: 2007-08-01 04:10 pm (UTC) - Expand

(no subject)

From: [identity profile] taleya.livejournal.com - Date: 2007-08-01 04:16 pm (UTC) - Expand

(no subject)

From: [identity profile] jon787.livejournal.com - Date: 2007-08-01 07:43 pm (UTC) - Expand

(no subject)

From: [identity profile] xforge.livejournal.com - Date: 2007-08-01 06:13 pm (UTC) - Expand

(no subject)

From: [identity profile] sethb.livejournal.com - Date: 2007-08-01 07:19 pm (UTC) - Expand

(no subject)

From: [identity profile] superbus.livejournal.com - Date: 2007-08-01 10:23 pm (UTC) - Expand
(deleted comment)
(deleted comment)

Date: 2007-08-01 03:29 pm (UTC)
From: [identity profile] vertelemming.livejournal.com
... the last five tips sent me into a panic attack just thinking of having to deal with this. What the fucking fuck, WSJ.

Date: 2007-08-01 03:34 pm (UTC)
brotherflounder: (Default)
From: [personal profile] brotherflounder
Wow, that News Corp buyout destroyed the WSJ's intelligence even faster than I thought it would.

Date: 2007-08-01 03:35 pm (UTC)
From: [identity profile] the-s-guy.livejournal.com
Meh, most of those workarounds won't, in any workplace with competent security policies and practices.

Let's see...
Online emailing services - BLOCKED.

Unauthorised software sites - BLOCKED.
Unauthorised programs on USB sticks - BLOCKED.
USB storage devices in general - DISABLED. (Non-storage devices still work.)

Proxy sites - BLOCKED.

Company laptops attempting an internet connection to anything except the corporate VPN tunnel: LOCKED DOWN.
or
Uses copy of latest version of corporate blacklist: SITES BLOCKED.

Putting corporate documents on third-party servers: BANNED VIA POLICY, plus the sites themselves are BLOCKED, plus any resident third-party program which handles the interface is BANNED and AUTO-DELETED.

Encryption settings in corporate email: LOCKED DOWN.
Encryptable IM software: BANNED and AUTO-DELETED.

Auto-forwarding all corporate email to an external account: BANNED, and email rules which incorporate it are AUTO-DELETED.

Reading webmail on a Blackberry: OK, as long as it's a corporate Blackberry where the automatic and ultra-paranoid virus scanners are LOCKED DOWN and the device is automatically given a thorough checkup and cleaning whenever it's plugged into the corporate network. Note also that it will only be configured to access the corporate webmail and users will not have the access to add personal accounts.

Surfing/slacking at work: All well and good, except that every URL and every click you make is recorded by the corporate proxies and monitoring software. If your boss wants a list of every site you visited and when, one call to IT is all it takes.

Summary: This is a lame list. Any place with an IT department worth its salt will already be way, waaaay ahead of the game with these. Yeesh, it didn't even mention using IP addresses instead of DNS names (BLOCKED!) or tunnelling to an external source over port 53 (monitor tripping!). And some of the activities it suggests (large file transfers, YouTube) are going to be picked up by the bandwidth monitors anyway, regardless of what convolutions the path to get them takes.

Out of Curiosity

Date: 2007-08-01 05:08 pm (UTC)
From: [identity profile] necessitysslave.livejournal.com
Do you block VBA access in microsoft office related products (and do you block wsh script files ect.)

I've always found even in the places I've worked with strong policies there is always someone with a word document that when you open it it gives you more rights/alows the install of programs/does something else you're not supposed to do.

Re: Out of Curiosity

From: [identity profile] the-s-guy.livejournal.com - Date: 2007-08-03 11:55 am (UTC) - Expand

Re: Out of Curiosity

From: [identity profile] benatwork.livejournal.com - Date: 2007-08-08 06:24 am (UTC) - Expand

Re: Out of Curiosity

From: [identity profile] necessitysslave.livejournal.com - Date: 2007-08-08 06:32 am (UTC) - Expand

Date: 2007-08-01 10:28 pm (UTC)
From: [identity profile] superbus.livejournal.com
This is all well and good, but not every IT department has the tools at it's disposal to get these things done. At my last job, all it took was one person with ties to the CEO to complain, and next thing you know, I'm being called in on Sunday to install DVD software on someone's laptop while he stands over me, smirking, knowing that I'm his bitch now.

Date: 2007-08-01 03:53 pm (UTC)
From: [identity profile] swwinchester.livejournal.com
Mmmm. This is a good list, and from a reputable source. I will have to take pains to ... selectively provide this information to some people.

I can already smell the evolutionary processes at work ...

*smiles* One techie's nightmare is another techie's evolutionary chainsaw. It all depends on the careful and well-measured deployment of the information.

Date: 2007-08-01 04:07 pm (UTC)
From: [identity profile] forever-damned.livejournal.com
Any sysadmin worth his salt can block all of that shit anyway and probably already has.

People must be retarded if they think using "You send it" disguises the fact they uploaded, or downloaded, 2Gb in one session.

It never ceases to amaze me how people can claim complete disbelief that someone (or something) magically used a ton of data/bandwidth.

(no subject)

From: [identity profile] forever-damned.livejournal.com - Date: 2007-08-01 04:22 pm (UTC) - Expand

(no subject)

From: [identity profile] superbus.livejournal.com - Date: 2007-08-01 10:29 pm (UTC) - Expand

(no subject)

From: [identity profile] jarad.livejournal.com - Date: 2007-08-01 07:57 pm (UTC) - Expand

Date: 2007-08-01 04:41 pm (UTC)
From: [identity profile] rorted.livejournal.com
What's with TFA's obsession with capitalising URL's et Google.com, ESPN.com, BoingBoing.net?

</irrational annoyance>

IT is just like your mom!

Date: 2007-08-01 04:51 pm (UTC)
From: [identity profile] guinevere33.livejournal.com
So your mom doesn't want you to stay out late with my friends on school nights - she says something about education being important. How lame! Here are most-requested tips for getting around your parents' silly rules!

1. How to play in traffic

2. How to sneak home at 3 a.m. without being caught

3. How to hide the smell of pot

4. How to alter your report card

5. How to hide your Asian teen gangbang porn

6. How to hide the evidence of a wild party

7. How to pass off a hangover as the flu

8. How to meet up with strangers from the internet

9. How to get bailed out of jail without admitting what you actually did

10. How to get a quickie abortion

Re: IT is just like your mom!

Date: 2007-08-01 10:30 pm (UTC)
From: [identity profile] superbus.livejournal.com
And just like my mother, I can give a DAMN good spanking when my lusers get caught. :D

Date: 2007-08-01 06:57 pm (UTC)
From: [identity profile] yndy.livejournal.com
but it's missing the one I kept looking for:

The Risk: losing your job when your boss/company/etc find out that you've been circumventing security measures and making the company's proprietary information vulnerable and potentially public.

Date: 2007-08-01 07:24 pm (UTC)
From: [identity profile] sethb.livejournal.com
The article is clueless.

A logo that says Verisign proves the identity of the site? When did that start happening?

https secures the files you upload from the bad guys running the uploading service?

Date: 2007-08-01 07:38 pm (UTC)
From: [identity profile] ihateemo.livejournal.com
Why on earth would someone use YOUFUCKINGSENDIT to share corporate files? Hello, shared drives! Sheesh.

Date: 2007-08-01 07:39 pm (UTC)
From: [identity profile] ihateemo.livejournal.com
Also, does anyone REALLY wish they could take MORE of their work with them out of the office? Stupid WSJ! Bad dog!

Date: 2007-08-01 08:05 pm (UTC)
From: [identity profile] ateji.livejournal.com
The Lifehacker (http://lifehacker.com/software/top/10-things-your-it-department-wont-tell-you-284192.php) comment thread this spawned is full of anger and great commentary by you types. :)

Date: 2007-08-01 11:37 pm (UTC)
ext_74: Baron Samadai in cat form (My ancestors)
From: [identity profile] siliconshaman.livejournal.com
wow... never thought I'd be grateful to be unemployed...

I can just see what'll happen back at my previous position when that does the rounds via intranet email/netchat.
*wince*
ok, time for my brain-bleach.

Date: 2007-08-02 12:52 pm (UTC)
From: [identity profile] teriwyn.livejournal.com
... thank $diety that tomorrow is the last day of my contract. Seriously, this is a great big load of WTF.
Page generated Mar. 19th, 2026 09:06 pm
Powered by Dreamwidth Studios