Slashdot Mirror


Do You Allow Webmail Use on Your Network?

rtobyr asks: "I don't allow users at my organization to use any third party e-mail. When users complain, I point out that we can't control the security policies of outside systems. End users tend to think that big business will of course have good security; so I ran a test of the 'Big Four': Hotmail, Yahoo Mail, AOL/AIM Mail, and GMail. Yahoo Mail was the only webmail provider to allow delivery of a VBS script. GMail was the only provider to block a zipped VBS script. End users also tend to think that a big business would never pull security features out from under their customers. Of course, we know that AOL and Microsoft have both compromised the security of their customers. I don't know of any security related bad press for Yahoo or Google. Three of my Big Four either allow VBS attachments or have a poor security track records. So, if you are a network administrator, do you limit your users' ability to use third party e-mail, and if so, do you allow for GMail or other providers that you've deemed to have secure systems and reputations?"

7 of 487 comments (clear)

  1. Yes by Ngarrang · · Score: 5, Insightful

    Simply put, yes.

    We would prefer that the work e-mail not be used for personal mailings. One of the reasons is file storage space.

    We are willing acknowledge that the parents are going to communicate with their kids, and other folks with friends and family. It makes for better employee morale when they are permitted access to web mail for such things, leading to less abuse of work systems. It is better to use e-mail than the phone, which needs to be left free for actual business calls with clients.

    Are there security concerns? Though the poster found some concerns, those concerns are easily disarmed by a good anti-virus/anti-spyware program.

    Sure, we could be rather draconian and put the kabosh on all of it, but it comes back to employee morale. A happy worker is a productive worker. Our workers are given the task of being responsible and are rewarded for their success.

    --
    Bearded Dragon
    1. Re:Yes by Aadain2001 · · Score: 5, Insightful

      I just wanted to respond to this post by saying that is exactly how it should be! Peoples' lives do not cease to exist when they walk in their employer's front door. It is much better to allow people to keep their work and personal lives separate by allowing webmail systems for person emails and cell phones for personal calls. Kudos to your company for recognizing that employees are people and if you treat them as such they will have a much better perception of their work place and be happier about working for you.

      --
      Space for rent, inquire within
  2. Shooting the messenger by Jeremi · · Score: 5, Insightful

    Translation: my organizations' computers are not secure enough to safely access the Internet. This is somehow Google/Yahoo/MSN's fault.

    --


    I don't care if it's 90,000 hectares. That lake was not my doing.
  3. A great topic and question! by rindeee · · Score: 5, Informative

    Man, was this ever timely. I just finished setting up a very complete solution for my current location (forward deployed military in the M.E.). Yes, of course I allow Webmail access. Everyone relies on it for 'reach-back' capability. What I do in an attempt to secure things is to setup a very complete firewall/filtering/etc. box. Is it perfect? No, but it's very effective. I'm running a Linux box with a slew of services(HAVP, P3Scan, ProxSMTP, HAVP, Privoxy, frox, ClamAV, RenAttach, Rules Du Jour and of course IPTables plus a bunch of others) and have had outstanding success. I recommend just using IPCop + BOT + CopFilter if you need something quick and relatively painless. I also do regular automated Nessus scans, etc. Man I love my job!

  4. Re:Squirrelmail by brobak · · Score: 5, Insightful

    You know, its not always as sarcasticly simple as you want to make it out to be. The fact of the matter is, things like GLBA and SOX force IT departments to take these kinds of drastic measures whether we like it or not. They REQUIRE that you inventory 'customer sensitive data' and control the flow of that data. The CEO literally signs on the bottom line that the reports you give to the auditors are true. Not to the best of his knowledge or any cop outs like that. So, when the big guns come down from their gilded offices, and demand to know for a 'fact' that you have control over data, it doesn't matter that the steps you have to take might have little to no real world effect. You just have to take them. Yes, as a security professional, *I* understand that if I wanted to get customer sensitve data out of the network, I could write it on my own ass, and press it up against a window for the guy in the next building over to read. But my board of directors doesn't find that amusing. They know they are legally responsible now, and they must be seen to be doing *everything* possible to secure the data. This does include doing our best to block things like mail apps, IM apps, USB drives and the like. Personally, I can see MANY ways in which each of those things would streamline the business process, and provide actual performance and productivity increases for the business, but that doesn't matter because GLBA demands that if we were to use those things, we keep logs of ALL of the ways they were used for 3 years, that are indexed and searchable and online, and another 4 after that in archive format. So when you go to the accounting dept with your new budget with all these new equipment costs, and software costs, and you have to GUARANTEE legally that they can't be used in ways other than intended...guess what the simpler solution is? Thats right, they go away. And lets be honest, for every valid business purpose, there's an equal number of time wasting BS purposes for that stuff that expose the company to legal liability. And the fact of the matter is, if we have policies against it, procedures in place to prevent it, and you still manage to get it done, then we have a pretty damn good case in court to hang YOU out to dry and not the company. CYA for the big wigs, and frankly, for myself. I know as geeks and nerds we think we know best, but if you play hard enough, stuff does break. I know I've had my own little personal web host 'pwned' before, and thats being decently careful to lock things down. I can't imagine my 'lusers' having more access than they already do, and what they might 'accomplish' with that access. For my own sanity, our regulatory requirements, the CEOs CYAs, and to be able to support the secured environment that we do, things like you refer to so sarcasticaly would get you fired. We own that machine, we own the network its on, we own the bandwidth you use to connect to the outside world, and therefore, we get to say exactly what you get to do with it. If you don't like that, thats fine, I totally understand, leave. But sometimes, even though I personally don't like it, I 'get it'.

    --
    --Brian
  5. Re:When users complain by 99BottlesOfBeerInMyF · · Score: 5, Insightful

    Sure folks complain and I'm avoided like the plague at times. But lets see what non-maintenance down time have I needed? Zero. For me and my team the lines are clear cut and boundaries well established.

    Thank you very much. Companies like yours are the reason companies like mine can hire brilliant and talented people away from bureaucratic nightmares and pay them 20% less while getting a significant amount more productivity from them. We have internal Web, IRC, chat, etc. servers. If your AOL IM is not working and it is stopping you from chatting with your girlfriend, IT is happy to help. They'll even grab you a beer from the fridge on the way to your desk. For smart people who know they'll spend a significant portion of their life at work, but who chose their work because they love it... there are companies like mine. You're treated like a real person instead of a cog. If you need to go home for the rest of the day while waiting for the plumber to come to your house, go ahead. Don't bother filling out paperwork or logging your time. So long as your work gets done, it's all to the good. If a friend is in town and stops by the office, go ahead and take a few hours to have a beer and play a video game with them in the lounge. Introduce them to your boss and coworkers.

    We don't lock down Web access to any type of external site. We track everything, but the tracking system is open to all employees so if you want to see what your boss is doing, just log on and look. We don't seem to have a lot of IT emergencies either. Some of our old and out of date servers overheat or fall over now and again and we power cycle them. No big deal.

    Every day I'm thankful I realized early in life that I did not want to take the top dollar offer for my work if it meant I had to put up with nonsense like you advocate. IT's job is not supposed to be to minimize the amount of work they need to do or even to prevent problems. It is supposed to be to facilitate the rest of the company getting work done. Happy employees work harder for the company and stay late to work on something or even come in on a weekend for some project. Happy employees do not quit and move to another company with no notice leaving the company in the lurch. Happy employees are not the largest and hardest to stop threat to the security of your network as they feel it is "wrong" to screw over the company and boss and people who treat them well and with understanding and who are their friends.

    But by all means, keep making yourself hated and keep thinking your employees lives should stop and they should act like machines for 8 hours a day. We'll keep hiring away the smartest people you have.

  6. Right Choice, Wrong Reasons by Anonymous Coward · · Score: 5, Insightful

    The lad has made the correct decision, but for the wrong reasons. The number one reason is because you want all of your "business traffic" to go thru your corporate email system.

    He should be asking himself, "Why do the people who work here feel they need to use the non-corporate system for business work?"

    All my work email goes from my work account, personal goes thru gmail.

    Also, if he doesn't allow people to use personal accounts for personal email, they'll just use the company email for that. Does he want that to happen?