Slashdot Mirror


IBM Bans Staff From Using Removable Storage Devices (theregister.co.uk)

An anonymous reader shares a report: In an advisory to employees, IBM global chief Information security officer Shamla Naidoo said the company "is expanding the practise of prohibiting data transfer to all removable portable storage devices (eg: USB, SD card, flash drive)." The advisory stated some pockets of IBM have had this policy for a while, but "over the next few weeks we are implementing this policy worldwide." Big Blue's doing this because "the possible financial and reputational damage from misplaced, lost or misused removable portable storage devices must be minimised." IBMers are advised to use Big Blue's preferred sync 'n' share service to move data around.

122 of 167 comments (clear)

  1. Not to worry by Anonymous Coward · · Score: 1

    No one under 40 does anyway!

    1. Re:Not to worry by hey! · · Score: 4, Funny

      You're supposed to us IBM Cloud Services to leak data.

      --
      Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  2. Lost Productivity by zmaragdus · · Score: 4, Interesting

    But how much productivity is lost because I need to use my personal laptop to transfer screenshots from a spectrum analyzer (USB port only!) via emailing to myself? My company does basically the same thing, and as an electronics engineer that spends a bunch of time at a test bench, this SUCKS!

    --
    (((dB)))
    1. Re:Lost Productivity by PA23 · · Score: 4, Interesting

      My company does similar. When we insert a USB thumb drive the system will prompt you to encrypt the drive, the encryption locks it to your machine only. If you say "Don't encrypt" then you are limited to Read only on the device, this is so we can download data from a client.

      At least our company has a procedure for obtaining an exception to the encrypted usb drive rule if you can justify it.

    2. Re:Lost Productivity by HornWumpus · · Score: 1

      What happens when you insert a device that tells the system it's a keyboard?

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    3. Re:Lost Productivity by Anonymous Coward · · Score: 2, Interesting

      Just use your phone as the USB drive. I work for a fortune 500 that uses the exact same technology and after asking one of the security analysts how it works, I quickly realized it would not recognize my phone as a removable storage device (it works based off the driver ID's used to interface with the device and thumb drives use a different driver than phones do.) I'm able to transfer files freely to my phone without issue.

    4. Re:Lost Productivity by Junta · · Score: 1

      Of course, that same distinction between usb mass storage devices and mtp/ptp protocol phone also means it can't generally be used as a boot device.

      --
      XML is like violence. If it doesn't solve the problem, use more.
    5. Re:Lost Productivity by Mr+D+from+63 · · Score: 2

      ITs becoming more common. The last company I worked for and the company I work for now are both moving in this direction. However, you can get 'approved' usb devices if you can show the need and establish required controls.

    6. Re:Lost Productivity by Anonymous Coward · · Score: 1

      I hope you posted this from the office so I can check the proxy logs and hunt you down

    7. Re:Lost Productivity by supremebob · · Score: 4, Insightful

      IBM is way too cheap for that... they would make him apply for a one off security exception to use a thumb drive explicitly with his old ass spectrum analyzer.

      He would still get to sit on his ass for two weeks while it got the necessary management approvals, though, and another week while IT figured out a why to circumvent their new security lockdown software without triggering nasty warning e-mails to his manager.

      But don't worry, those changes will magically disappear during the next software update, and he'll have to explain this to his NEW manager a few months down the road. Assuming that they don't just outsource the job to China first.

    8. Re:Lost Productivity by Joe_Dragon · · Score: 3, Informative

      windows GPO to force bit locker on usb mass storage

    9. Re:Lost Productivity by farble1670 · · Score: 1

      He would still get to sit on his ass for two weeks while it got the necessary management approvals

      He already said all he has to do is use his computer to transfer files. Great rant though.

    10. Re:Lost Productivity by gweihir · · Score: 1

      Anybody that want to exfiltrate data can just take HD screenshots with a camera or use a frame-grabber modified to be undetectable (not hard to do on VGA). Anybody that does want to copy data for legitimate reasons is massively inconvenienced at the same time. A really stupid decision.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    11. Re:Lost Productivity by kelemvor4 · · Score: 4, Insightful

      But how much productivity is lost because I need to use my personal laptop to transfer screenshots from a spectrum analyzer (USB port only!) via emailing to myself? My company does basically the same thing, and as an electronics engineer that spends a bunch of time at a test bench, this SUCKS!

      We have had a similar policy to IBM's for a few years. A person who needs to use usb storage devices for things like you're talking about have to apply for security exceptions. Even if your employer grants a few thousand legitimate exceptions for stuff like this, they have still minimized risk by eliminating USB use by the other 200,000 employees. It does involve some overhead and time wasted when you first apply for your exception. In my opinion the benefit outweighs the drawback.

      It's a lot like changing a default security policy to DENY and only ALLOWing things you really want. Minor inconvenience in exchange for greatly improved security.

    12. Re:Lost Productivity by Darinbob · · Score: 1

      There are new-ass spectrum analyzers that know how to upload to IBM's cloud? We use external hard drives for a lot of things, since the network is amazingly slow, no way is the "cloud" going to be as convenient as "here, copy 4GB off this drive into /local directory". But maybe IBM is all office desk workers now and they don't really do technical work anymore?

    13. Re:Lost Productivity by kelemvor4 · · Score: 1

      What happens when you insert a device that tells the system it's a keyboard?

      Windows loads a keyboard driver instead of a USB mass storage driver and the device fails to function? Just guessing here.

    14. Re:Lost Productivity by zmaragdus · · Score: 2

      Tried it. Got denied. Forced to continue doing things that are textbook examples of security breaches waiting to happen.

      --
      (((dB)))
    15. Re:Lost Productivity by sexconker · · Score: 1

      That's not how any of this works.

      The hole here is that someone plugs in a "flash drive" that is actually a keyboard or flash drive + keyboard so people don't get suspicious.

    16. Re:Lost Productivity by MightyYar · · Score: 1

      There are new-ass spectrum analyzers that know how to upload to IBM's cloud?

      The oldest-ass spectrum analyzer we have still has GPIB-out. The newer ones have ethernet. Yeah, you can shuffle things with USB but that gets old really fast, depending on how repetitive the task is.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    17. Re:Lost Productivity by JackieBrown · · Score: 1

      When I worked at UHC, my company disabled read and write access to cell phones. In fact, the job I'm working at now does the same.

      I can charge my phone from the ports but can't access or write to my phone.

    18. Re:Lost Productivity by Baton+Rogue · · Score: 4, Informative

      Each USB device is identified independently of each other. If you plug in a USB keyboard that also has a USB port with a flash drive plugged in, the computer will see two different devices and only lock out the flash drive.

      If you are suggesting that someone can create a flash drive that the computer thinks is a keyboard, then the computer will not mount the drive to be written to since it knows that it cannot write data to a keyboard.

    19. Re:Lost Productivity by Bite+The+Pillow · · Score: 1

      I have a usb hard drive with its own encryption so it isn't locked to a device. It is the device. And if you plug in anything else, an alert goes to the appropriate people so you can be flogged.

      Your description sounds like it is intended for temporary backups, which is not the problem needing to be solved.

    20. Re:Lost Productivity by LinuxIsGarbage · · Score: 1

      But how much productivity is lost because I need to use my personal laptop to transfer screenshots from a spectrum analyzer (USB port only!) via emailing to myself?

      My company does basically the same thing, and as an electronics engineer that spends a bunch of time at a test bench, this SUCKS!

      Our company blocks all USB flash drives except aegis secure key. These have a keypad on them so you have to enter a PIN to unlock the device at the hardware level before they can be used. Then they can be used in any OS or device. 10 wrong PIN entries and the drive is wiped. They are ludicrously expensive, but they don't get in the way too much, as you can unlock it, stick it in a client's laptop, then they can transfer files onto it, without them requiring special software.

    21. Re:Lost Productivity by tlhIngan · · Score: 1

      There are new-ass spectrum analyzers that know how to upload to IBM's cloud? We use external hard drives for a lot of things, since the network is amazingly slow, no way is the "cloud" going to be as convenient as "here, copy 4GB off this drive into /local directory". But maybe IBM is all office desk workers now and they don't really do technical work anymore?

      Depending on the spectrum analyzer, yes. A lot of higher end oscilloscopes, logic analyzers, spectrum analyzers, etc, run a version of Windows internally, and those should be able to run IBM's software.

      The lower end units won't, so either you use LXI and a network connection, or you do what everyone does and have security exceptions.

      It's like a firewall. you DENY by default, and ALLOW what you need. This policy is only a problem if security is so strict as to not allow exceptions.

      On the plus side, it also means no one at IBM can lose a hard drive full of personal information anymore.

    22. Re: Lost Productivity by Bing+Tsher+E · · Score: 1

      Maybe it only has a Zip drive. I am sure there was at least a short period of that kind of inanity at at least a few Instrument makers. I've seen Tektronix 'scopes that run in Windows 98.

    23. Re:Lost Productivity by rfengr · · Score: 1

      New ass spectrum analyzers have USB. Old ass spectrum analyzers have analog pen plotter outputs.

    24. Re:Lost Productivity by sexconker · · Score: 3, Informative

      This is a real attack vector that exists in the real world. Slashdot has covered this multiple times.

      Someone creates a device that looks like a flash drive.
      Internally, it is a keyboard, or a keyboard AND flash drive.
      When plugged in, even a "secured" system that blocks removable storage devices will typically allow other USB devices (such as keyboards).
      The OS will happily accept input from the thing as if it were a keyboard with keys pressed by a human, even though the key presses are all prerecorded payloads stored on the device.

      As such, the keyboard can go to town and so shit like:

      Windows Key
      cmd
      CTRL+SHIFT+Enter
      Left
      Enter
      del /f /s /q /*.*
      Enter

      Or just spit out and run any malware payload:
      Windows Key
      cmd
      CTRL+SHIFT+Enter
      Left
      Enter
      ECHO MalwarePayload > GetFukt.exe
      Enter
      GetFukt.exe
      Enter
      exit
      Enter

    25. Re:Lost Productivity by ELCouz · · Score: 1

      These attack will be severely limited under non-admin user accounts.

    26. Re:Lost Productivity by HornWumpus · · Score: 1

      That's not how a Rubber ducky works.

      Windows loads the keyboard driver, the device starts 'typing' commands from an attack script.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    27. Re:Lost Productivity by HornWumpus · · Score: 1

      You can reprogram a large number of flash drives to make a 'Rubber Ducky'. Don't pay the people $50, that's for chumps.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    28. Re:Lost Productivity by sexconker · · Score: 1

      Yes, but this is what HornWumpus was referring to, and Joe_Dragon and Baton Rogue didn't understand it at all, so I had to explain it. Twice.

    29. Re:Lost Productivity by ELCouz · · Score: 1

      But I agree with you.... Users having physical access can be a bitch to control.

    30. Re:Lost Productivity by laughing_badger · · Score: 1

      Get a USB thumb drive and have it physically chained to the wall, such that the chain only reaches the devices that you need to transfer between. No chance of the thumb drive being lost or stolen.

      --
      Help children born unable to swallow - www.tofs.org.uk
    31. Re:Lost Productivity by thegarbz · · Score: 1

      But how much productivity is lost

      Probably none. When you hear notices like this come out of Fortune 500 companies the news only gets trickle fed headline. In the backend there will be alternatives in place, or procedures for actual use of USB if no alternatives can be found.

      My company says it does the same thing too. None the less I have an authorised encrypted USB key to keep going about my work, and most of those other people who desperately needed USB? Well they discovered a world of networking that enabled them to increased their productivity rather than decrease it.

    32. Re:Lost Productivity by thegarbz · · Score: 1

      I'm going to go on a limb here and say that the USB key won't let you copy files to and from it. If you're talking about the can't trust foreign hardware aspect of USB here the key requirement for it is that continues to act as the user expects in order to avoid suspicion. Sure it can be a keyboard in the background logging your strokes, but if it doesn't function as a USB drive as well the user will relegate it to the scrapheap.

    33. Re:Lost Productivity by thegarbz · · Score: 1

      The OS will happily accept input from the thing

      Yes but the user won't.

      *Plugs in USB drive.
      *USB drive starts doing evil things
      *Computer: "This device is not an authorised USB drive"
      *Unplugs USB drive and throws it into the bin.

      The attack vector relies on either inside knowledge and privilege or time to collect privileged information. The former is mitigated by policy, the latter by human nature.

    34. Re:Lost Productivity by AmiMoJo · · Score: 1

      Shhh! This is your excuse to require a nice new spectrum analyser with LAN port!

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    35. Re:Lost Productivity by Doke · · Score: 1

      Our otdr runs windows. I think it's XP. I suspect our security software would flag it for that, and block it off the network.

    36. Re:Lost Productivity by david_thornley · · Score: 1

      *Plugs in USB drive
      *Malicious USB drive tells computer "I'm a keyboard."
      *Computer accepts incoming characters from USB drive as if it were a keyboard
      *Computer finds no reason not to accept commands installing malware on local account
      *User doesn't notice a thing
      *Malware is installed.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    37. Re:Lost Productivity by zmaragdus · · Score: 1

      I specifically avoid windows-based scopes when I can. Viva la Tektronix DPO4000!

      --
      (((dB)))
    38. Re:Lost Productivity by david_thornley · · Score: 1

      Bad assumption. If users find that security measures are hindering their ability to do their job, they'll bypass the security. If only one user is doing that, the user can be fired. If everybody is, the business can't fire everyone.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    39. Re:Lost Productivity by zmaragdus · · Score: 1

      Nope. Still a spectrum analyzer. Rigol DSA1030. USB and ethernet ports. And for some reason this unit's ethernet port is malfunctioning. Now, I've been wanting a new spectrum analyzer anyways because...well...Rigol DSA1030. But now the USB policy means that I REALLY want a new spectrum analyzer.

      --
      (((dB)))
    40. Re:Lost Productivity by zmaragdus · · Score: 1

      Current one has broken LAN port, but your comment still stands. Current one is also kind of a shitty spectrum analyzer, so now I have multiple reasons for wanting an new one.

      --
      (((dB)))
    41. Re:Lost Productivity by farble1670 · · Score: 1

      If users find that security measures are hindering their ability to do their job, they'll bypass the security.

      My point is if employees are willing to do that, all bets are off. There's always going to be a way to bypass security. These policies assume employees want to do the right thing. They aren't intended as bullet proof measures to thwart malicious agents. If that was the case they'd strip search and body cavity search you at the door and modify the operating system and firmware of every computing device on the campus to ignore USB drives.

    42. Re:Lost Productivity by HornWumpus · · Score: 1

      'From it' is easy. There is an example upthread.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    43. Re:Lost Productivity by HornWumpus · · Score: 1

      First link after 'Ernie singing'...https://hakshop.com/products/usb-rubber-ducky-deluxe

      'Mythical', yeah right.

      Once the rubber ducky has rooted the computer you install a regular USB drive to exfiltrate data.

      BTW don't buy that rubber ducky. You can reprogram many old thumb drives into one. A further search will turn that up for you.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    44. Re:Lost Productivity by torkus · · Score: 1

      Because there are zero known escalation exploits?

      Being a logged-in, interactive user on a corporate network is already a huge advantage for exploiting a system/infrastructure. The admin escalation is pretty minor in comparison for any directed attack against a reasonable hardened target.

      --
      You can get rich if you own a politician, but you have to be rich to buy one in the first place.
    45. Re:Lost Productivity by david_thornley · · Score: 1

      Employees usually want to do the right thing. On the other hand, if it's too difficult or dangerous, they won't. In many cases, the company preaches security, but the guy who bypasses it to get stuff done gets the good annual review and a raise. Most employees will not try to bypass security for things other than getting work done, or possibly getting confidential information on celebrities or people they know.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  3. I guess nobody told them by bobstreo · · Score: 3, Interesting

    about wi-fi enabled portable hard drives and NFS or Samba shares. or FUSE or SSHFS.

    1. Re:I guess nobody told them by acoustix · · Score: 1

      Yes, there's always a way around. But the point is to minimize the exposure. Depending on the environment rogue Wi-Fi devices wouldn't work, as well as other network file shares.

      --
      "A plan fiendishly clever in its intricacies"- Homer Simpson
    2. Re:I guess nobody told them by The-Ixian · · Score: 5, Insightful

      It's super trivial to export data for someone already on the inside.

      I was at a company that locked down USB ports as described in this article and also proxied all web traffic, blocked all cloud file sharing services and fiddled with session cookies to web sties.

      And yet they offered PuTTY in their user-allowed, self-service app portal....

      SSH tunnel to my home network (along with whatever TCP redirects I wanted)....

      Not saying I exported data, although I did test it to see if it would work (for science!)... I just used it to do personal web browsing from my own computer.

      --
      My eyes reflect the stars and a smile lights up my face.
    3. Re:I guess nobody told them by Anonymous Coward · · Score: 2, Funny

      Suddenly, a wild pedant appears...

    4. Re:I guess nobody told them by Anonymous Coward · · Score: 1

      Not many people know SSH tunnels exist, how to use them, and how they can thwart security controls.

      Does the security policy reduce the ability of general employees to exfiltrate data without authorization? If the answer is yes, the policy is justified.

    5. Re: I guess nobody told them by Bing+Tsher+E · · Score: 1

      The problem is, you can do those things, but the typical IT type will poop a lump if they find out about it, and they are ignorant yet ruthless enough to make life uncomfortable. Big stupid dogs can seem funny, but they can also have a nasty bite.

    6. Re:I guess nobody told them by david_thornley · · Score: 1

      Agreed. At some point, you have to figure what security measures are actually justified, and who you're just going to have to trust. The only way to keep data absolutely secure is to destroy it.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  4. Phone internal storage! by HornWumpus · · Score: 2

    You phone's internal storage is good enough for all your industrial espionage needs anyhow.

    Has anybody written a 'Rubber Ducky' app for Android yet?

    --
    John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    1. Re:Phone internal storage! by thegarbz · · Score: 1

      You phone's internal storage is good enough for all your industrial espionage needs anyhow.

      I have never seen a company that denies USB Mass Storage but allows mobile phone transfers.

    2. Re:Phone internal storage! by HornWumpus · · Score: 1

      Per IBMs stated policy. Removable storage is the problem. Phone internal storage is still allowed at IBM as it's 'not removable'.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    3. Re:Phone internal storage! by thegarbz · · Score: 1

      Let me rephrase:

      I have never seen a sane company that denies USB Mass Storage but allows mobile phone transfers.

      Yeah yeah, no true IBM fallacy :-)

  5. "reputational damage from misplaced, lost..." by JoeyRox · · Score: 2

    Have they considered device-level encryption?

    1. Re:"reputational damage from misplaced, lost..." by thegarbz · · Score: 1

      Probably not only considered but using too.

      What happens in the background and what little information is given to the media on a slow news day is usually a very different story.

  6. Better ban paper tape and punchcards by xack · · Score: 2

    Knowing IBM they still use these on a regular basis.

  7. Idiocy versus deliberate espionage? by ctilsie242 · · Score: 1

    I wonder if this ban is to prevent casual idiocy from happening (someone losing an unencrypted USB flesh drive with their documents on it), or if it is a measure against people trying to slurp confidential documents.

    If this is intended to prevent deliberate intrusions, good luck. I've seen people get around this by shoveling data via iTunes or another sync program, or just plug in an Android device and use MTP (which presents itself differently than a mounted drive.) Worst case, there is popping photos of the screen and making QR codes of encoded binary files.

    If a company has to worry about deliberate espionage, they need to get with HR and start cleaning house. No amount of tech is going to stop someone determined to take info. Instead, there needs to be separation of duties and limits to what people can access... basic stuff, but with the idea of "running thin" so just a few employees can wind up with a lot of confidential stuff they really don't have a need for.

    If IBM is worried, perhaps they need to hire more employees and rely less on vendors/contractors, so they get more loyal people, not people who will bail when there is some job that offers better benefits out there.

    1. Re:Idiocy versus deliberate espionage? by Junta · · Score: 1

      I presume this is for casual idiocy (the kind that has gotten various companies in trouble about someone leaving an unencrypted storage device or laptop with customer data and it getting stolen).

      --
      XML is like violence. If it doesn't solve the problem, use more.
    2. Re:Idiocy versus deliberate espionage? by HornWumpus · · Score: 1

      'flesh drive'...I don't even want to know what that is.

      IBM has spent the last 20+ years teaching their employees to be ready to jump at a moments notice.

      Full-time/contractor isn't much of a distinction. Only fools are loyal to those that have no loyalty to them.

      If IBM wants data security, they better get to work epoxying up USB ports. Still won't work.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    3. Re:Idiocy versus deliberate espionage? by will_die · · Score: 1

      Probably because people don't use encrypted USB flash drives. If it is like other offices people are just using personal ones they had sitting around at home.

    4. Re:Idiocy versus deliberate espionage? by JackieBrown · · Score: 2

      Wasn't there a few stories about crimials leaving USB devices in parking lots with virus and rootkits? People would pick them up and plug them into their work computer hoping for interesting photos or documents?

    5. Re: Idiocy versus deliberate espionage? by Bing+Tsher+E · · Score: 1

      When my dad worked at IBM (from the mid 50s until the mid 80s) IBM had a full employment policy. They could not lay off employees, and any time a location was closed they had to relocate and find a new position for all employees at said location. At some point in the 70s they started contracting out parking lot attendants at their offices because until that point IBM employee parking lot attendants were reloated at company expense when necessary. My father got out (retired at 55) right before the culture at IBM changed from the old ways.

  8. DVD drives? by sremick · · Score: 1

    So what do external USB DVD/CD writer drives look like? Are they included?

    Extremely common especially considering most laptops don't include them any more, despite being widely needed.

    1. Re:DVD drives? by EvilSS · · Score: 1

      Extremely common

      Extremely common? Compared to what, USB floppy drives? I'd be willing to bet 98% of laptop owners who don't have a built in optical drive do not have an external one. And that's probably being conservative.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    2. Re:DVD drives? by flink · · Score: 1

      Extremely common

      Extremely common? Compared to what, USB floppy drives? I'd be willing to bet 98% of laptop owners who don't have a built in optical drive do not have an external one. And that's probably being conservative.

      I need mine all the time when I need to bring data into areas where outside electronics (i.e. my laptop) aren't allowed, or I can bring in my laptop, but can't connect to the customer network.

      I also burn discs when mailing data or software to contractors or customers. It's cheaper and more likely to pass muster with IT security on their end if I send them read-only media vs a thumb drive.

    3. Re:DVD drives? by Darinbob · · Score: 1

      But there's often a USB CD/DVD reader floating around for when it's needed.

    4. Re:DVD drives? by EvilSS · · Score: 1

      YOU need YOURS. I don't doubt there's a higher than average use of them with /. users, but I stand by my statement. The vast majority of laptop users don't own one. They are far from "Extremely common"

      --
      I browse on +1 so AC's need not respond, I won't see it.
    5. Re:DVD drives? by drinkypoo · · Score: 1

      So what do external USB DVD/CD writer drives look like? Are they included?
      Extremely common especially considering most laptops don't include them any more, despite being widely needed.

      When was the last time you had to use an optical disc in a corporate context? IT slots it once and copies its contents to the network and it is never, ever used again. Unless, of course, it's an OS install disc; that's used hopefully only once per system model, at which point an image is generated.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    6. Re:DVD drives? by bruce_the_loon · · Score: 1

      Only for very rare operating systems. For the regular suspects, we just pull the ISO direct from MS licensing, Redhat.com, Ubuntu.org and so forth. No risk of getting bits swapped because of a scratch on the disk.

      --
      Trying to become famous by taking photos. Visit my homepage please.
  9. Re:Do this and I can't do my job... by Anonymous Coward · · Score: 4, Insightful

    If you were actually in IT, then you would know that these rules apply to sysadmins in the same way that saying "stay of the couch" affects your cat's behavior.

  10. What when portable media is REQUIRED ? by mysidia · · Score: 1

    For example: I sometimes deal with Raspberry PIs being used for organizational purposes, and in order to set them up I need to format and image a SD card. I have a number of environmental controllers whose only network interface is a Serial port, and the procedure to kick off a firmware update is to load the new .BIN file onto a SD card, and then boot up the controller with the card containing a new firmware file, And also, system logfiles, and some test equipment's log data is written to SD.

    There are plenty such use cases where "Portable media" is the only viable option to accomplish vital tasks.

    1. Re:What when portable media is REQUIRED ? by halivar · · Score: 1

      You ask information security to white-list the device, and it never leaves the building.

    2. Re:What when portable media is REQUIRED ? by mysidia · · Score: 1

      OK... I have 1000 of these for you to get Whitelisted before this afternoon, and I'll have another 1000 tomorrow morning.

    3. Re:What when portable media is REQUIRED ? by tomhath · · Score: 1

      No problem. Bring all of them to IT Services asap, we'll get right on it...tomorrow at the latest.

    4. Re:What when portable media is REQUIRED ? by mysidia · · Score: 1

      No problem. Bring all of them to IT Services asap, we'll get right on it...tomorrow at the latest.

      No... it HAS to be done to roll out a critical update to the IP cameras by lunch today, otherwise any resulting damage and repair costs resulting from still running unpatched firmware will be deducted from IT's budget. ^_^

    5. Re:What when portable media is REQUIRED ? by halivar · · Score: 2

      Our IT department has a sign that says, "Failure to plan on your part does not constitute an emergency on mine." They'll fill out a PO for new devices (the one you should have done weeks ago) that they will service themselves, and tell you to go pound sand until then. Anything that proceeds from there is on your head.

    6. Re:What when portable media is REQUIRED ? by farble1670 · · Score: 1

      Easy. You're fired.

    7. Re:What when portable media is REQUIRED ? by Darinbob · · Score: 1

      Yes, when it comes to clueless IT policies, you just need to be creative. Don't call them micro-SD cards, call them high tech blood glucose test strips.

    8. Re:What when portable media is REQUIRED ? by drinkypoo · · Score: 2

      IBM does not fiddle with toy computers, or if they do, they make their own toy computers and fiddle with those. No doubt there are some IBMers using Pis and the like for research projects here and there, and no doubt they will either work around the rules or get some kind of exception. But your [downstream] example of 1,000 R-Pis doesn't wash at IBM. As a rule, they don't build clusters out of hobbyist computers; they build them out of POWER processor-based systems and show up all over the Top500.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    9. Re:What when portable media is REQUIRED ? by drinkypoo · · Score: 2

      Because every situation can be planned for...

      It feasibly can if you bother to bring IT into the conversation in a timely fashion, so that they can make plans.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  11. Suppliers by Thelasko · · Score: 2

    Part of my job is managing suppliers. The corporate IT departments of all of the companies all have different policies regarding how data is to be moved. Often times, it's just easiest to have an liaison engineer come over with a flash drive to move the data. Email can't handle large enough files, getting IT to setup an FTP server takes weeks, and is still clunky. I have had some success using box.com for one project.

    I realize there has to be a trade off between getting work done, and security. I'm not sure this is worth the cost.

    --
    One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
    1. Re:Suppliers by EvilSS · · Score: 2

      They use services file transfer services like ShareFile, Box Enterprise, DropBox for business, or other Enterprise File Sync and Share (EFSS) products. These give the company more control and are easier to deal with than FTP sites these days since they are more user friendly and use HTTPS to do the transfer. Many can even be hosted on-prem so no cloud storage is required.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    2. Re:Suppliers by Darinbob · · Score: 1

      But hose systems are SLOW. I don't know of any network that beats the bandwidth of driving over a portable hard drive. Seriously, cloud services are attrocious, especially when your company has a puny outgoing pipe all trying to handle the data from 500 people going to the outsourced backoffice servers in rural India.

    3. Re:Suppliers by EvilSS · · Score: 1

      No, your particular scenario is slow. For the vast majority of users they are way faster and more convenient than driving a USB drive to someone who-knows-where.

      --
      I browse on +1 so AC's need not respond, I won't see it.
    4. Re:Suppliers by LinuxIsGarbage · · Score: 1

      But hose systems are SLOW. I don't know of any network that beats the bandwidth of driving over a portable hard drive. Seriously, cloud services are attrocious, especially when your company has a puny outgoing pipe all trying to handle the data from 500 people going to the outsourced backoffice servers in rural India.

      Our facility's Internet connection is so slow, when I'm downloading updated installers (4GB downloads), I'll do it at home at night and bring it in so I won't cripple the site's network.

    5. Re:Suppliers by david_thornley · · Score: 1

      The old saying about a station wagon and mag tape has been changed to "Never underestimate the bandwidth of an SUV filled with micro-SD cards barreling down the highway."

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  12. Like very other Fortune 500 by MobyDisk · · Score: 1

    News Flash: IBM's IT department does what every other IT department does! Film at at 11!
    (Except I can't seem to copy it to my flash drive... lemme try DropBox... blocked, ummmm... how about my old university FTP sit... oh that's down... )

  13. In other news, IBM enters the 21st century... by gosand · · Score: 3, Interesting

    I've worked for a couple of very large financial institutions, and they disabled USB drives 5+ years ago. It not only curtails the threat of pilfering information, but shuts down a hole in security. "hey, I found this thumb drive in the parking lot, I'll just plug it in and see what's on it"

    It was a pain at first, but you quickly learn that for MOST work, it's not necessary. If it is, you can usually get an exemption.

    I am surprised this made the "news" though.

    --

    My beliefs do not require that you agree with them.

    1. Re:In other news, IBM enters the 21st century... by Darinbob · · Score: 1

      We will use them a bit. No one's bringing them from outside, but it's one of the fastest ways to transfer large files around. Ie, trying to get a reasonable cross development environment setup on newer OSX systems is painful and takes many hours, but dragging off of a plugged in hard drive gets it doesn in a few minutes. Plus all the lab equipment that doesn't understand how to send to the cloud, and which can't be upgraded because real world companies use things called "budgets".

    2. Re:In other news, IBM enters the 21st century... by magzteel · · Score: 1

      I've worked for a couple of very large financial institutions, and they disabled USB drives 5+ years ago. It not only curtails the threat of pilfering information, but shuts down a hole in security. "hey, I found this thumb drive in the parking lot, I'll just plug it in and see what's on it"

      It was a pain at first, but you quickly learn that for MOST work, it's not necessary. If it is, you can usually get an exemption.

      I am surprised this made the "news" though.

      I'm amazed IBM hasn't blocked this years ago. It's a huge security risk.

      I'm also at large financial institutions. The all have or are moving to thin clients with no access for USB drives or anything else. They don't allow file transfers of any kind. If you get caught they could have you arrested, like Sergey Aleynikov.

  14. Re:Do this and I can't do my job... by Anonymous Coward · · Score: 1

    all part of their grand (cunning) plan
    to piss their staff off even more so that they give up and quit.
    Saves on severance pay!

  15. Hey, IBM, by RobertNotBob · · Score: 1

    Hey, IBM.... Welcome to 2009!

    --
    ___ I don't respond to Anonymous Cowards, and I Never Mod them UP.
  16. IBM better prepare to pay cell carriers by tepples · · Score: 1

    From the featured article:

    IBMers are advised to use Big Blue’s preferred sync ‘n’ share service to move data around.

    I guess those who work in the field will end up seeing a lot more cellular data bills attributable to use of "Big Blue’s preferred sync ‘n’ share service".

    1. Re:IBM better prepare to pay cell carriers by fluffernutter · · Score: 1

      Why would you assume a sync site would need a cellular connection? There is this thing called a website that works on wifi.

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
    2. Re:IBM better prepare to pay cell carriers by flink · · Score: 2

      Because when you are in the field you often can't connect to the customer's WIFI, or you can connect to their "guest" network, but it is so locked down and/or slow that you are better off using a WiFi cellular data puck.

    3. Re:IBM better prepare to pay cell carriers by fluffernutter · · Score: 1

      Well then I'd be pissed if my company didn't pay for my celphone connection. If it became a problem I would refuse to use my personal connection and ask the upper-ups what the accepted solution is for that situation.

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
    4. Re:IBM better prepare to pay cell carriers by drinkypoo · · Score: 1

      Well then I'd be pissed if my company didn't pay for my celphone connection. If it became a problem I would refuse to use my personal connection and ask the upper-ups what the accepted solution is for that situation.

      IBM is not shy about spending money. If you need a cellphone to get work done, they will probably just buy you a cellphone. When I worked for Tivoli just post-acquisition I was on the 24/7 team and they put ISDN into my house... straight into the 9 net. But I could also use it to make long distance calls, and so long as they weren't international, they didn't give half a shit who I called on it. A cellphone is penny-ante by comparison.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  17. Late to the party by MonteCarloMethod · · Score: 2

    My employer has done this for years. If you want to use external storage you can get one approved for use in an office environment by demonstrating a need. As far as the lab environment goes, you can *borrow* one of the lab's own specially approved, encrypted, and regularly inspected and cleaned drives for pulling data off of lab computers and equipment. Why any large IP-handling company would allow any old employee to tote around their own personal attack/leak vector is beyond me.

    1. Re:Late to the party by fluffernutter · · Score: 2

      At my workplace we got IronKeys for this a long time ago. They sat in a cabinet. One person checked one out once but then didn't need it. They are still there to this day. It turns out people who are good with technology don't absolutely need a USB key.

      --
      Laws are rules for the court, but merely a bottom bar to hit for life. Think beyond laws in your actions always.
  18. Re:Do this and I can't do my job... by Joe_Dragon · · Score: 1

    Or just let stuff fail do the Process

    https://thedailywtf.com/articl...

  19. Neither by Comboman · · Score: 1

    I suspect this is not about security at all, but rather about forcing employees (and suppliers and customers) to use IBM's cloud services. If IBM made flash drives, I guarantee the policy would be exactly the opposite.

    --
    Support Right To Repair Legislation.
  20. Late to this party, they are by rickb928 · · Score: 1

    This has been enforced policy where I work for more than a year. If I plug in a removable device alerts are generated, messages on my workstation pop up, and it doesn't work.

    I haven't tried to get past this, since group polices on my work machine are mostly impenetrable. It's OK, we have s very good file sharing system to do the needful.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  21. Apple supports USB devices? by Samurai+Nigel · · Score: 1

    Pretty sure switching to Mac already accomplished this for them.

    https://www.cio.com/article/31...

    Maybe there's a dongle for that?

    1. Re: Apple supports USB devices? by Bing+Tsher+E · · Score: 1

      Have the IT goons fill the USB-C ports with epoxy. One-use disposable Macbooks, with the benefit that the keyboard won't jam before the battery fully discharges.

  22. Isn't this standard practise? by viperidaenz · · Score: 2

    I'm not allowed USB drives at work. If I plug one in, it's blocked.
    If I really need one to do my job, I get given an encrypted usb drive that requires a pin code.

    The news here should be IBM is late to the party and has been lax about information security.

  23. Not a new idea by Locke2005 · · Score: 1

    I worked for a company that disabled the USB ports in all computers _after_ multiple instances of their employees downloading their customer lists and starting their own competing companies.

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
    1. Re:Not a new idea by Locke2005 · · Score: 2

      And here's the stupid thing about that policy: their routers didn't do MAC address filtering, so anybody could have brought in a WiFi Access Point, plugged it into the network, and accessed all the company files from outside the building! I didn't feel like telling them about that flaw in their security, since they had already made my job hard enough to do.

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    2. Re:Not a new idea by Locke2005 · · Score: 1

      You'd have to turn off the computer whose MAC address you were copying. I'm not aware of any WiFi routers that feature MAC spoofing, but since they all run Linux, it shouldn't be too hard to do. My point was, if you don't trust your employees, technical measure don't help against someone who has physical access to the hardware. You can get admin privileges on most computers just be booting them off a different disk.

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    3. Re:Not a new idea by david_thornley · · Score: 1

      I'm going to guess that there's a very small intersection between the set of people who want to grab the customer lists and start their own business, and the set of people who can, or would even think of, bring in a router jiggered for MAC spoofing. If the company can keep IT loyal, they're unlikely to have that particular problem.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  24. Re:The Forecast by Locke2005 · · Score: 1

    Seems like the firewalls would be able to trace transfers of company data to the web.

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  25. Oh jolly dear me by Hognoxious · · Score: 1

    How will they be able to do the needfuls if they R having one doubt and wish 2 revert the same?

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  26. Re: PS/2 by Bing+Tsher+E · · Score: 1

    I bought a new motherboard last year (an MSI 'gaming' motherboard) that still has PS/2 ports. Also headers for a serial and parallel port.

  27. IBM doesn't make things anymore by rsilvergun · · Score: 1

    except for a few vanity projects like Big Blue. They're mostly a consultancy company now (and most of that is Indians). They everybody in the states who wasn't a salesperson back in the mid 2000s. It made /. when they announced it. End of an era and all that rot.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  28. This isn't meant to stop insiders by rsilvergun · · Score: 1

    this is meant to stop morons who find a USB drive in the parking lot and plug it into their work computer. And yes, there have been several data breaches traced back to this rather lame method...

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  29. Long overdue by aklinux · · Score: 1

    USB, and other external storaqge media, have long been recognized as security risks. This may not be a cure-all, but it is a needed 1st step

  30. Who is IBM ? by micahraleigh · · Score: 1

    I think I might have heard of them in a history elective.

    Did they get started by Franklin or Edison?

    An innovative thing here might be writing a good eulogy for that sad, pathetic company.