Why corporate IT should unchain our office computers(slate.com)
slate.com
Why corporate IT should unchain our office computers
http://www.slate.com/id/2226279/pagenum/all/
21 comments
Why should an IT person get to decide what sites are non-productive? Ridiculous.
I like this article on Google's approach: http://www.cio.com/article/144500/IT_s_Third_Epoch...and_Run...
"On Sarbanes Oxley Gmail IS a violation because S.O. requires the companies themselves to archive all e-mails. So if he leaves and takes his gmail with him than he'll have an archive but the company will be in violation." The article clearly stated he was forwarding his email to gmail- so you are the one that has it wrong, the company would still have a copy. The problem here would not be SO compliance, but rather corporate document retention (destruction) policies where they want to get rid of records as soon as it is legal to do so.
"any IT person in Health Care will tell you IM programs are a HIPAA violation because they allow for encrypted transfer of files" Do you mean unencrypted? Regardless- I can think of 100 ways to transfer an unencrypted file. Why single out IM, which has many useful properties.
Here's what's happening in the real world- the corporate network/desktop that is overly locked down gets circumvented. People bring in laptops and use cell modems, people use their phones, people install virtual machines.
I like this article on Google's approach: http://www.cio.com/article/144500/IT_s_Third_Epoch...and_Run...
"On Sarbanes Oxley Gmail IS a violation because S.O. requires the companies themselves to archive all e-mails. So if he leaves and takes his gmail with him than he'll have an archive but the company will be in violation." The article clearly stated he was forwarding his email to gmail- so you are the one that has it wrong, the company would still have a copy. The problem here would not be SO compliance, but rather corporate document retention (destruction) policies where they want to get rid of records as soon as it is legal to do so.
"any IT person in Health Care will tell you IM programs are a HIPAA violation because they allow for encrypted transfer of files" Do you mean unencrypted? Regardless- I can think of 100 ways to transfer an unencrypted file. Why single out IM, which has many useful properties.
Here's what's happening in the real world- the corporate network/desktop that is overly locked down gets circumvented. People bring in laptops and use cell modems, people use their phones, people install virtual machines.
Why should an IT person get to decide what sites are non-productive? Ridiculous.
Generally you will find that suck policies come from HR and IT people aren't particularly enthusiastic about them either.
Generally you will find that suck policies come from HR and IT people aren't particularly enthusiastic about them either.
I really don't know how to answer your first question without sounding a little rude so you'll have to forgive that but the bottom line is if the IT dept. gets to pick which sites are productive it's because the company has entrusted them to do so and the company owns the equipment so it's their right to control how it's used. Though a good IT dept. will listen to individual employees and allow sites they might not normally allow if there's a good reason.
On Gmail the question was "why were they banning Gmail" not was his personal use of gmail a violation so the point still stands (though I'll admit I read it wrong)
Finally, if your security gets circumvented than your security is flawed. Any IT department that chooses not to implement security on the argument that it will inevitably get circumvented probably needs to re-evaluate how they're handling things.
On Gmail the question was "why were they banning Gmail" not was his personal use of gmail a violation so the point still stands (though I'll admit I read it wrong)
Finally, if your security gets circumvented than your security is flawed. Any IT department that chooses not to implement security on the argument that it will inevitably get circumvented probably needs to re-evaluate how they're handling things.
Most financials don't care if it's your personal email you're going out to Google for. I've seen people get fired for that --- and just for that.
Do you decide who people can call on the phone too? Do you decide if they can read the newspaper??
What I mean by circumvent is that if you tell an employee they can't use Facebook during breaks, they'll whip out their phone and use Facebook. If you tell a developer they can't use an IDE they like, they'll buy their own.
What I mean by circumvent is that if you tell an employee they can't use Facebook during breaks, they'll whip out their phone and use Facebook. If you tell a developer they can't use an IDE they like, they'll buy their own.
I'm the author.
1) Another poster has already responded to your Gmail comment; as he pointed out, I was forwarding mail, not deleting it, so the company still had all my mail.
2) Regarding the use of IM at the hospital: This would be a sensible explanation if the hospital also blocked all other unencrypted communication. They do not. Here is the senselessness of this policy: They allow people to use Gmail but disable the chat portion of Gmail; the only reason for this is to stop them from goofing off.
1) Another poster has already responded to your Gmail comment; as he pointed out, I was forwarding mail, not deleting it, so the company still had all my mail.
2) Regarding the use of IM at the hospital: This would be a sensible explanation if the hospital also blocked all other unencrypted communication. They do not. Here is the senselessness of this policy: They allow people to use Gmail but disable the chat portion of Gmail; the only reason for this is to stop them from goofing off.
I think you have the HIPAA encryption requirement backwards --- from experience --- but your argument still stands.
I think GP was saying roughly "IM provides a means for encrypted communication, including the transfer of files. By HIPAA, we have to prevent the transfer of files containing patient medical information. The firewall can't distinguish among that encrypted traffic in order to PERMIT text chat but PREVENT all file transfers, thus the ability to transfer files securely via IM is an exploit as far as HIPAA is concerned."
Yeah, this tangent is snowballing a little bit. I think the original post literally just had a typo.
Having said that, again, in several places I've worked where HIPAA is a constant presence, it hasn't killed IM. It's a dealbreaker for a lot of financials though.
Having said that, again, in several places I've worked where HIPAA is a constant presence, it hasn't killed IM. It's a dealbreaker for a lot of financials though.
I honestly don't know what you mean by this but I'd be curious to hear an elaboration
they allow for encrypted transfer of files and hence represent a risk to medical records
This could go either way, actually. Unencrypted transfer of files is obviously risky and if it's through a 3rd party provider (AOL, GTalk, etc.) then there is a risk of confidential medical information being intercepted.
Alternatively, maybe there needs to be internal records of who has sent or received which files. Encrypting files makes it harder for the administration to know who has what.
I'm leaning towards the first explanation of the danger of unencrypted file exchange, but I could be wrong.
This could go either way, actually. Unencrypted transfer of files is obviously risky and if it's through a 3rd party provider (AOL, GTalk, etc.) then there is a risk of confidential medical information being intercepted.
Alternatively, maybe there needs to be internal records of who has sent or received which files. Encrypting files makes it harder for the administration to know who has what.
I'm leaning towards the first explanation of the danger of unencrypted file exchange, but I could be wrong.
HIPAA isn't like GLBA; it doesn't have the tracking requirement. It's just unusually explicit that PHI needs to be encrypted in flight.
HIPAA requires you to encrypt medical information.
(Also, lots of heavily HIPAA-regulated places allow IM.)
(Also, lots of heavily HIPAA-regulated places allow IM.)
This article is depressingly bad.
Even a sysadmin runs their computer as root or sudo 2% of the time and should not run non-SOP software on a work computer...
How could you manage giving regular users the ability to install while maintaining a secure environment?
On our networks website restrictions are for bandwidth reasons not for 'net-nannying' reasons. And occasionally be have to adjust for silly dansguardian mis-flags...
But how can you seriously argue what this guy is putting forth?
I have played with the idea of giving users a VirtualBox install of Win XP that they can trash to their heart's content while having a more secure Linux desktop for the work applications (Firefox/ Thunderbird/ OpenOffice). But I am not convinced that is really secure. But that is more the way to go with something like this.
Even a sysadmin runs their computer as root or sudo 2% of the time and should not run non-SOP software on a work computer...
How could you manage giving regular users the ability to install while maintaining a secure environment?
On our networks website restrictions are for bandwidth reasons not for 'net-nannying' reasons. And occasionally be have to adjust for silly dansguardian mis-flags...
But how can you seriously argue what this guy is putting forth?
I have played with the idea of giving users a VirtualBox install of Win XP that they can trash to their heart's content while having a more secure Linux desktop for the work applications (Firefox/ Thunderbird/ OpenOffice). But I am not convinced that is really secure. But that is more the way to go with something like this.
"How could you manage giving regular users the ability to install while maintaining a secure environment?"
Don't put your important data on the desktop. An intranet app over VPN is definitely safer than walking around with the company data on a laptop.
I like your idea of giving people an virtual machine to worth with. I use virtual machines to do a lot of real work (as a contractor) where the corporate IT policies don't let you do work.
I like your idea of giving people an virtual machine to worth with. I use virtual machines to do a lot of real work (as a contractor) where the corporate IT policies don't let you do work.
I wouldn't be surprised if in a few years more tech savvy employers require/allow employees to bring their own computer. With better "type 1" hypervisors, you could have your Home OS image and your Work OS image running at bare metal speeds with the ability to simply flip between the two.
Employers could save money and employees could do whatever they wanted on their "home" OS.
Employers could save money and employees could do whatever they wanted on their "home" OS.
[deleted]
Perhaps this would be better as an Ask HN:
What kind of IT restrictions (if any) do startups here impose as they grow beyond founders?
What kind of IT restrictions (if any) do startups here impose as they grow beyond founders?
I work for a software startup that has grown to about 30 people. Last month we had a "security week" where the entire engineering team worked on. As usual, we audited our own product and wrote some code to make things more secure. But we also found that our internal desktops were one of our biggest -- and most unprotected -- attack vectors.
In response to that, a couple of our engineers developed an IT policy for corporate computers. These are laid out as relatively straightforward requirements, like "you must not use IE 6", or "you must edit the registry and change the default timeout of the Beezlebop service."
These prescriptions were written up as corporate security policy, although employees are trusted and no one is policing it. If you have a legitimate business need to ignore a policy, like needing IE 6 around for testing, then no one's going to stop you. But be smart about it and don't use that browser to download warez.
I like the free and unrestricted nature of working for a startup, but I completely understand the rationale for these policies. Everything they recommended was due to known security holes and known vulnerabilities in default installations. It's irresponsible NOT to fix these holes. If our security was compromised because of a long-known Windows attack, it would make us look awfully stupid.
In response to that, a couple of our engineers developed an IT policy for corporate computers. These are laid out as relatively straightforward requirements, like "you must not use IE 6", or "you must edit the registry and change the default timeout of the Beezlebop service."
These prescriptions were written up as corporate security policy, although employees are trusted and no one is policing it. If you have a legitimate business need to ignore a policy, like needing IE 6 around for testing, then no one's going to stop you. But be smart about it and don't use that browser to download warez.
I like the free and unrestricted nature of working for a startup, but I completely understand the rationale for these policies. Everything they recommended was due to known security holes and known vulnerabilities in default installations. It's irresponsible NOT to fix these holes. If our security was compromised because of a long-known Windows attack, it would make us look awfully stupid.
What does everyone think about the idea of having fairly minimal IT restrictions, but requiring the use of tools like Rescue Time? Would you take that tradeoff?
But this author is a tool.
First, anyone whose dealt with consumers in general knows that most computer users get themselves into trouble doing benign things. For example, in my experience, most people get malware while searching for pictures on Google. They find the picture they want, click on it and before you know it they're infected. So how trustworthy they are isn't really an issue.
Second he dramatically misunderstands the laws he quotes. On Sarbanes Oxley Gmail IS a violation because S.O. requires the companies themselves to archive all e-mails. So if he leaves and takes his gmail with him than he'll have an archive but the company will be in violation. As for his fiance, the Medical Professional that can't use IM, any IT person in Health Care will tell you IM programs are a HIPAA violation because they allow for encrypted transfer of files and hence represent a risk to medical records (I work for a mental health organization and we have to scan at our firewall for files going out and have protection software to prevent certain files from being copied to flash drives)
I guess what I'm saying is there are certainly IT people who take security too far. But, as this writer proves, there are also users who ask for too much.