Employees Are The Biggest Security Threat
blankmange writes "BBC News is reporting that the employees of a company pose the biggest threat to security. "Digital cameras, MP3 players and handheld computers could be the tools that disgruntled UK employees use to sabotage computer systems or steal vital data, warn security experts. The removable memory cards inside the devices could be used to bring in software that looks for vulnerabilities on a company's internal network. The innocent-looking devices could also be used to smuggle out confidential or sensitive information." Unfortunately, this is not news, but it is amazing how slowly the general public, corporations included, comes around on issues like these. "
Yes, sounds stupid, but I would find it to be a better idea than to implement some kind of 1984/Farenheit 451 security "utopia". It should also help the companys success in the future. Happy people work better and doesn't try to screw you over (in the bad sense that is).
Ultimately it is employers who set the tone for a company. Employees actions are (in part) a reflection of how they are treated by employers.
I just thought of something, if a person wanted to KILL a whole bunch of people...they probably could. DUH!!
This is some serious social breakdown we're seeing here. I remember the days when you would get hired by a company, and then not only would your employer actually give a fuck about you...they would assume that you were on their side by default. Maybe this should tell us something about the mindset of modern management. They hate us...they naturally assume that we hate them. Gattaca here we come.
If people consider PDAs, MP3 players, and digital cameras a security threat as a channel for bringing data in and/or out of a company, just wait for the next generation cell phones/PDAs. When you have a 3G/GPRS/GPS/Bluetooth/802.11/IrDA/Ethernet/USB/Fir ewire/etc. capable personal phone, would employers let you bring it into work? Even if you had no hostile intentions yourself, your phone might be compromised by a trojan or virus that might attempt to spread from your phone into the corporate network over whatever communications medium is available.
With the wireless connectivity becoming so common, network security is losing its "air gap".
It might be noted that the IP Rights protection software might end up being a problem for Open Source software acceptance in the market and work place. Not necessarily due to (most) corporations really concerning themselves about people copying music, but with employees copying confidential files to unsecured devices.
An operating system/networking system that provided built-in guards for transferring confidential/private data from secured/official devices to unsecured/private devices might have a lot more appeal to a corporation than one that has no protections against random file copying.
(Given that we are reaching the point where we have more memory and CPU power in computers than we know what to do with, I would be highly interested in seeing more OS development that allows for (security) meta-data to be associated with areas of memory as far as the permissions/state of that memory goes. It would be really nice to see a system where, say, image data loaded from a website might be marked in the OS as "image (jpeg) from foo.bar.com -- unauthenticated, non-executable", so that if some thing else tried to trigger the CPU to jump to that area of memory and execute it, the OS would reject the attempt. This is going to be more important with Bluetooth/ad-hoc connectivity, 'media' which are almost programs in themselves (Flash, Java, JavaScript, etc.) -- simply turning off all support for 'dangerous' media may not be practical if their use becomes wide-spread. This sort of internal OS meta-data system would have a high overhead, of course. And yes, the side effect is that it makes IPR-type enforcement much more possible, but the security issues may start pushing systems development in that direction. Free software folks should think about this one -- it would be highly ironic if by implementing IPR management software in Windows, Microsoft then stepped up and managed to make an OS with a superior internal security model based on extending the IPR system to manage internal data/executable security. Better start looking for quad Athlon servers...)
Sadly, the NTFS file system has a richer system of file and directory permissions than anything Linux has to offer. Which is of course made moot by exploits that give the Microsoft user system level privileges, but the simplistic owner/group/world permission structure common to *nix systems is not a key selling point. The best permission structure I've personally dealt with was Novell's NDS, but they mistreated their sales channel so badly over the years they'd have troubling selling water to a guy who was on fire. Too bad, their cascading inheritance model was just amazing.
All of this is beside the point anyway, as the article deals with folks misusing resources they already have access to, not problems with people getting at files they are not normally allowed to see. A Linux user is just as capable as a windows user of burning files he has rights to onto a CD.
You're just jealous 'cuz the voices talk to *me*
And your guests stand for this?
Folks, three times in recent months I've walked out on places, or canceled tickets to an event that said they wanted to search me. Yes, it's their right to ask, and it's my right to say "No". Then it's up to them to decide which they want more - me, or their rule
To quote a Sci-Fi story being written by a guy on the net:
-- 73 de KG2V For the Children - RKBA! "You are what you do when it counts" - the Masso
The theoretical permissions are one thing, the actual ones used in practice are another. As Microsoft Office requires the %WINNT% directory to be world writable, that means in practice, the majority of NT setups are insecure.
Just how exactly does it improve the security of your systems to punish employees for exposing flaws? This guarantees that the only people scanning for vulnerabilities are outsiders and insiders with evil intent. Give scanning tools to employees and offer to pay them a bonus for reporting problems!
There is so much wrongheaded thinking out there, it is no wonder to me that security problems remain so numerous.
I originally thought the same thing - the employers are making the crappy workplace. That may or may not be the case. Over the last 8 years, I have seen so many slackers, dead-wood employees that have been kept on for no good reason. I started to wonder why. Then I heard about the pending lawsuits from former employees. Nowadays, you can't even fire someone without getting sued. It is stupid. People get stuck in a hole, and the company doesn't want to give them anything worth doing. Since they can't fire them for being un-driven losers, they give them crap jobs. Instead of working harder to actually reverse the situation, the employee just gets more bitter and lazy. I have seen people steal many many things from a company, because they feel the company "owes them". In one case, a guy claimed 20 hours of OT every week for about 8 months. His manager signed off on it because he was too spineless to challenge him. I know he didn't work it, because *I* was working it and he was nowhere to be found. In true corporate fashion, when it was discovered (by me), nothing was done. Nobody wanted to confront the situation. The guy eventually got PROMOTED! I figure he made out with about $30k.
I guess my argument is that no matter what your environment is like, people are going to try to screw the company. Granted, the worse the environment, the more it probably happens, but there are always going to be those disgruntled nut-jobs who feel the world owes them something. And I have seen companies do pretty crappy things too, like during the company meeting, announcing layoffs and those who weren't at the meeting were being escorted out of the building by police. This was to "preserve their dignity". Uh-huh.
Believe me, I know what it is like to be unhappy at a job. But you know what I did? I left. Employers have to cover their asses even more nowadays, when someone with the knowledge could easily F up their network, steal code/secrets, etc. Saying "don't piss off your employees" is no solution. Of course companies should have a good work environment, that is a no-brainer. But there will always be someone who wants more. You let people wear jeans, someone wants to wear shorts. Let them wear shorts, someone walks in with their bag hanging out. Let them wear sandals, someone walks around barefoot. No matter where I have worked, there has always been someone who was unhappy.
My beliefs do not require that you agree with them.