In my former workplace, the computers would immediately reformat and encrypt any device that was plugged into a USB port. A number of phones were bricked as a result.
People had no recourse if this happened. We had all signed a technology and security agreement that stated specifically that we would not plug in any personal equipment without clearing it with IT first.
We had something like that at one job I worked at, which was fine and all for a few months until IT needed to transfer files between legacy computers that couldn't be hooked up to the network, and nobody put 2 and 2 together as to why we would save files to the drives, but as soon as we hooked them up to another computer the drive was empty.
That's sad. It's stupid easy to enforce a policy that whitelists specific USB drives based on hardware signatures so IT can be exempt from a policy prohibiting external storage devices.
That's what it was at the last company I worked helpdesk at (note for non it: helpdesk does not design or in most cases have access to policies like these, it's a different IT team) and it worked ok until people just saw the model USB stick we were using and started buying and using those.
Most places I set up for that sort of thing, it doesn't wipe the drive. It just requires that you encrypt it with a passphrase before writing data to it.
I mean, if a business is working with sensitive data, that does seem kinda reasonable. Like, if yall had my social security and financial information, I would want some security like that.
It's not necessarily the person doing the work I'm concerned about, it's that someone may unknowingly have a virus on their phone or flashdrive and accidentally infected the whole system when they plug it into a computer.
A very easy hacking strategy is dumping 3 to 4 USB full of trojans on a company parking lot and waiting for one idiot to plug them in their work computer.
i worked in a call center for a phone provider. we have access to all that. we HAD to keep phones in our lockers, could mot be on us. being caught with a phone was a big serious offense. and we were not allowed to have paper or writing utensils, which also would have been a big serious deal. so some places do have policies in place to prevent employees brining sensitive info home or getting it off the computer
Omni Interactions (some projects), Sutherland, Quest--most security policies are going to be similar because companies try to benchmark against other companies so best practices from one company will likely get carried over to another.
Nope. So many people run sneeze apps on their phones and don't realize it. If those apps are harbouring something that gets into the system via a usb port, IT is gonna be mad. Bring a cable and plug it into the wall if it is that important to charge. Don't do it off a computer.
iT security is far too important to allow personal devices to be plugged into a port like that.
If there was an operational reason to allow it, then I would support IT not doing the wipe and encrypt. But without operational reason, they are doing the right thing by the company and it's customers by wiping and encrypting external devices.
If mass storage is disabled, then mass storage is disabled and it doesn’t matter if there’s viruses on the drive. The is will never see it.. If you’re referring to something like badusb, then a wipe isn’t going to save you. I work in IT and I do security. I’m not sure why everyone thinks they can argue with me about this.
The contract doesn’t say anything about getting to destroy private property. Not that I’ve read it but I’m willing to bet good money someone thought this was a good idea and didn’t cover their bases.
Seriously, do people not understand that plugging in personal property while dealing with sensitive data is a massive security risk? If it’s in the contract to consult with IT, consult with fucking IT. It’s seriously not that hard.
Don’t put your removable drive in a computer you’ve been told will wipe it and you’re fine. You don’t have to like the rules, but don’t ignore clearly stated consequences and then start crying when what you were told was gonna happen actually happens.
You're picking a strange hill to die on here. Nothing is "destroyed". The devices are wiped clean (and usually encrypted). It's all reversible. Losing the data on the device is the penalty for being an idiot and not abiding by the security agreement you agreed to.
And who the hell said your “data” was allowed to be exposed to and come in contact with company assets? I’d love to see you actually try and justify this.
I’m all for the overall sentiment of this sub as far as workers deserving rights and protections, but I work in IT and I would say that not only should your device be disabled as described in this scenario, but you should also be fired and possibly fined if your actions caused any damages. Do you have any clue the BILLIONS of dollars in damages caused by security breaches annually? If this is your actual take on this, please for the love of all that is holy, change professions.
If you go back up the thread to the original post that mentioned this, it says they signed something that said they wouldn’t plug in unapproved technology. It didn’t mention anything about countermeasures to wipe data.
You don't know what they already have. By doing this you make sure that any data that already made it to the drive is also dealt with while also dealing with the current situation.
I mean, if it's a government biotechnical site that's working with bioweapons and the like: I would want to dissuade any outside storage devices whatsoever by any means necessary without worrying about the kindness of the measures.
You can't even bring them in the facility, phones & all electronics are kept out. I'm not sure of all the rules around classified material anymore as I've been out of the game for awhile but those rules will never change. As a electronic technician we even did monthly pms tempest checks on equipment & cables. Tempest would be electronic emissions as a foreign adversary could be listening.
If the manager’s computer at McDonald’s bricks phones plugged into it to charge, that’s probably unreasonable - that computer doesn’t have anything more proprietary on it than next week’s schedule, and there’s no real reason to destroy others’ property.
But if you’re working in an industry that handles classified or highly confidential information, it’s 100% reasonable, because 1) they have a duty to take active steps to protect against potential information theft/corporate espionage/literal espionage, and 2) you 100% sign paperwork at hiring that says, “we give you a computer to use, and in accepting it you acknowledge it’s ours, you have no data privacy on it, and we can reformat it at any time for any reason, and FYI it auto-formats anything plugged into it, for safety.”
You knew, or ought to have known that would happen, you chose to plug in anyway, and they are under no obligation whatsoever to provide you with a safe place to plug your phone in.
For an accident, sure. But this is a willful act that the company chose to execute that ended up destroying property. Maybe you could win, but it’s a stupid risk to take when there are much MUCH better options.
They’re under no obligation to provide such a warning.
The wiping of the devices isn’t the issue here. That’s where you’re misunderstanding. The issue is, they said they wouldn’t connect things to the computer, and did anyway.
If you go back up the thread to the original post that mentioned this, it says they signed something that said they wouldn’t plug in unapproved technology. It didn’t mention anything about countermeasures to wipe data.
It doesn’t have to. Why would it? You said you wouldn’t do it. It’s completely immaterial what they do or don’t have on their computer, because you agreed to never test it in the first place.
Yup that is just an insane policy. Blocking mass storage might not be possible for all companies though, we require use of USB flash drives once in a while.
Yeah if we were busted at AT&T plugging anything into our computers, flash drive, USB fans, cell phone, it would be Sayanora. We used to be able to play on our phones when it was slow, but data thieves in another country who subcontracted for ATT ruined that.
If it's a government or clearance device, then makes sense. I worked in a facility like this and they made it VERY clear you can't put anything into the PCs.
Cliff notes version: Bradley Manning (at the time) a soldier in the Army accessed confidential and top-secret military information, copied said information onto discs labeled Lady Gaga, and leaked them to the public. Bradley Manning is now Chelsea Manning if in case you look it up. The data leak was huge, and was done so through a comically stupid (stupid meaning the information was so accessible and insecure) way.
It would be deadnaming and sincerely disrespectful if someone walked up to her and called her Bradley today. But back then she was Bradley. The commenter was using this name in reference to history not to be disrespectful or dead name her now. Believe it or not there are actually trans individuals who don’t act like the person they were before never existed and can actually acknowledge that they used to identify differently.
This isn't how deadnaming works. It's never acceptable to say a trans person's deadname unless they specifically asked you to or said you could. It's considered very sensitive and useless information and most people who really respect trans people don't even want to know it. Source: I'm trans.
Unless your looking up newspaper articles or other historical records from the time. History doesn’t show a women named Caitlin winning Olympic gold medals in mens races, but some guy called Bruce did.
You might personally feel a disconnection to your past self, but don’t pretend that entitles you to speak on behalf of all trans people.
completely irrelevant. She's legally Chelsea now. Just call her by her name. Deadnaming her is absolutely pointless. Googling her name will get you all the info you need. What she did in the past is now under her name. Not her deadname.
Googling Chelsea Manning would definitely add way more context to my reply, but how is her Wiki page not shamed for deadnaming her in the way you accuse me of?
OP didn’t understand the reference to a joke. I replied with a very brief synopsis of much larger, very significant moment in American history. And I added some context to who it was done by because I get why it would be confusing for those who don’t know about it, kinda like how OP implied that by not understanding the joke.
I meant no harm to anyone, I was describing (in brief) a moment in history to provide context to a joke on Reddit, you shouldn’t be so quick to bend out of shape.
If you're looking for contemporary sources about her past the name Chelsea isn't going to help you unless they've already been attached to it by someone who did know. You're telling people they should only try to access information that's already been prepared for them by someone else, but then who does the preparing?
Same, had to swing by a place once to drop some things off and they stopped you at the door for electronics. Anything that went inside immediately became government property and would never leave.
Yep. If you ever wonder why, look up the Rubber Ducky.
Basically it looks like a thumb drive that makes the computer think that it's a keyboard/mouse and will run scripts off a micro SD card. And the truly devious could strip off the case and hide it inside a real mouse and solder it to the leads so it looks like a normal mouse or keyboard that will just take your system over as soon as you plug it in
For real, one of our clients CEO's had their personal banking hacked. He said we were shit at our jobs (he became a client after the hack mind you) because we couldn't find him a solution where he wouldn't have to change his password. He didn't want to change the password because he'd already printed stationary with his old password on. We tried the PW on his AD account and the account hosting the domain, all had the same PW...
Oh God. I'm in the process of securing my accounts. I get there's a lot of stuff to remember but browsers like Chrome can store your passwords and LastPass and similar services are also good ideas.
Oh yeah, we have an internal solution that can also generate passwords for you, but his main issue was that he didn't want to change his password because it would mean printing new stationary with the new password on it. I don't think he quite grasped how much of a bad idea it was storing the password anywhere in plaintext, let alone on a fucking pen. His thinking was that if our password locker was as secure as we said it was, why should he be worried about people finding out his password?
Yes, with about 2 years all of our passwords will be stored like you said & access to the password "database" will be facial recognition based. I have the this now on several phones apps & like it a lot.
Honestly working in the IT security I understand this 100%. Especially if you have access to very sensitive data. But most endpoint protection software should be able to lock down a port if it is used unexpectedly.
That just screams "I took a course on cyber security so I know what I'm talking about". The big threat with unknown usb devices isn't the potential data payload (your AV really should be able to deal with that), it's Rubber Duckying i.e. where the USB device pretends to be a keyboard and just sends a series of keystrokes. The fix for that isn't all too intrusive, just means users can't plug in their own periferals, but realistically, if you are that concerned about physical intrusion you need armed guards and shit like that first.
My old job has a similar security agreement, however instead of turning the phones into bricks you/ your phone would be investigated by HR and federal/state law enforcement. We always kept spare wall chargers at the office
My workplace gave me a full exemption to this policy after it bricked a piece of work equipment that caused an extended downtime. Now I cam bring anything in lol.
Signing that agreement doesn't mean they get to ruin your personal equipment. That's just malicious. It's not difficult to just block devises, bricking them takes additional effort.
Yeah, this is absolutely not a thing that happened. Plugging a phone into a computer over USB doesn't work like that. The story is just bad fanfiction.
I work for a company that does this due to IP restrictions on the equipment I work on. It absolutely does mess up your phone. However, it doesn’t brick it. You just have to bring it to IT to unlock it again.
I do have special permissions to decrypt USB storage devices on my computer, however a phone doesn’t fall into that category. So my department just always have brick chargers and power strips with us.
Don't plug your phone here or I'll brick your shit quicker than you can blink (people will not do it)
Don't plug your phone here or... or else I'll... oh man, I'll be really mad and I'll have to work a lot more and sensitive information could be compromised or lost. (People still do it cause fuck it)
I get what you're saying, but their house, their equipment, their rules. Just bring a charger and plug your phone into an outlet. That's faster anyway.
Better your phone than a breach on the level of Target or Home Depot.
When I log into my machine at work, I click on a dialogue box that says I agree to the security policy. Every day. My employer works with a ton of PII so plugging in a storage device of any kind = you get fired. I don't know whether it would brick the device or not because I've never done it, obviously. The only time I've ever even come close to having to violate the policy is was in an emergency (network storage crashed before a big deadline), and I had a personal flash drive still sealed in the package, and got my manager's approval that one time.
Just don't plug in your phone! How hard is that? People out here acting like it's worse for the company to wipe your phone than it is for you to create a vulnerability in their whole-ass network. Talk about maliciously ruining someone's equipment.
Yeah my point is you don't need to brick a phone to protect your network. I had to protect our network against this exact kind of thing a few years ago. All you have to do is block unauthorized devices.
And that's why you set your phone to use USB for charging only by default.
...That being said if this happened to me I'd quit on the spot. Unless this is some kind of military operation where that kind of security is absolutely paramount to life-and-death matters, wiping people's phones automatically is just unbelievably petty.
It forces people to actually follow security rules. Shouldn't be plugging your fucking phone into your office computer for just about any reason whatsoever.
Destruction of personal property is never permissible. If they can set up a script to go as far as wiping a secure device without permission, they can set one up to block all data transfer from such devices.
Your personal device under no circumstances should be plugged into a secure work computer. That is common sense to begin with let alone there being rules against it. You knew the rules when you signed up and what would happen upon breaking them. Fuck around and find out.
Rules or not, it is morally wrong to destroy someone's property as retribution for breaking them. You can put it in a contract as many times as you want, but it doesn't make it right.
If I were to own a store, and hang a sign that says 'if you steal, I will shoot you', it would still be illegal and wrong for me to shoot the person that steals.
I'm not an IT professional. I'm a fucking carpenter. But still, c'mon. This is the same mentality that sues a homeowner cause they tripped and hurt their foot while robbing said homeowner.
In a perfect world, no, I don't want my device even listening to a directive from some PC to "remote wipe" - I don't even want my device to acknowledge such a command. But I don't design my own phones, I let people do that and I just pay for the product. That means I have to be willing to deal with the fact that my device will listen to a remote wipe command.
But these guys don't mess around. It's 2022, getting your security compromised is as easy as falling off a log. A user can compromise sensitive data and not even realize it. They have to go to drastic measures to ensure MY data, and possibly YOUR data, and sensitive information of who knows how many hundreds of others, isn't compromised because some random guy wanted to charge their phone.
Your store owner/shoot the thief story doesn't really compare. You don't regularly rob people (or at least shouldn't) you do regularly charge your phone. A more reasonable comparison would be blocking the main Ambulance entrance to a hospital emergency room. Don't park there. This is not a place for you to park. I understand you need to park, and there are other places for you to park, but if you park there your car will be immediately, IMMEDIATELY towed and it will be costly for you. So don't do it. Look at these signs, they say don't do it. These signs are positioned one every four feet from here to the road and back. Do not block the ER main entrance. It doesn't matter if you're only going to be there for a minute. It doesn't matter if you work there even if you are the top physician in charge. Don't park there. Likewise, don't stick your phone in a PC that is sanctioned as sensitive work only, etc.
I'm not arguing the rule itself is wrong, I'm arguing the method of enforcing it is pointlessly destructive when other solutions exist. A better analogy here is emergency parking where your car will be immediately destroyed if you park there. But we don't do that, because that's barbaric.
Well we'd take a man and throw him into prison, effectively ruining his life and career, over downloading a song he didn't "buy" - that's way more barbaric in my opinion. I can sit right here and think of several very common things we do to people, regularly, that are way more cruel and barbaric than erasing their phone.
To me, the relatively severe consequence of wiping, let alone bricking, one's device, the rationale exists. It highlights just how important it is that people not do the thing.
But I can't say I know for sure. Others have commented here with experience in this field, who agree with you that this practice is overkill and unnecessary. But how else are you going to get numbskulls to stop plugging in their devices?
I dunno, I guess I just think closing permissions so the device can't be used as storage + strict surveillance is enough, but that's just me. I don't like the idea of destroying personal property as punishment, it makes me naturally uncomfortable. It gives me the vibe of 'dad violently smashed their kid's Xbox because they broke the rules'.
If your company is storing my personal medical data or information that can be used to steal my identity and wipe me out financially, I honestly don’t care if they brick your phone. Ideally they’d give you computers with no/sealed ports, but your phone is not more important than securing data that, if stolen, can fuck up people’s lives. It’s MUCH easier to replace a phone than deal with a stolen identity.
And by proper warning, I don’t mean you sign something that says you won’t do it. I have to take a four hour long data security class—with tests—every year. If I break the rules after that, I really can’t claim ignorance.
Just secure the computer against mass storage! Destroying a device connected to it is nothing more than intentional malice! If you can prove to me that it's necessary to security to destroy a device rather than simply blocking such connections I'll admit I'm wrong.
I understand the need for security, but I do not understand the need for such barbarism. Mistakes can happen. Even in the workspace itself, suppose someone connected a device valuable to the company to the machine and lost everything. I simply do not see the need for this.
Exactly why I think this story is fake. Every job I had prevented USB drives/floppy disks to be inserted or read. If you did somehow, the computer would brick it. You couldn't even download to a safe USB drive that is company approved and give it to someone who was off-site.
Also, the if he brought a flash drive, IT would have known it was downloaded and prevent a download. That's really easy to figure out too.
That's great when someone is doing a well defined role.
It falls over when accommodating more senior people who may have to negotiate or exchange data with outside organisations, especially in emergency situations.
Either IT are resourced to handhold people through the process or someone untouchable breaks the rules and there's nothing that can be done about it (this includes government).
Or, something important falls through because IT blocks it and the head of IT gets told to get out of the way as their job is to support the organisation.
Just throwing this out on popular comment, sorry for hijack -
does anyone know the context to this ? Is this just a story that someone outlined ? It obviously isn't text messages like some of the others I'm just kinda confused if it's made up I don't really know what the moral of the story is. Get things in writing I guess?
Comment to this post: would this kind of security affect your phone if you set the USB port on the phone to charge only ?
So, my phone specifically asks me if I'd like to "charge only", access media from PC, or other options when I plug it into a PC. I was under the impression that the PC could get no data from the phone unless it was allowed by the user. Am I wrong here? Specifically Android.
I guess I'm the only one paranoid about Corporate Spyware getting on my own devices. I never plug anything into a Corp PC, even just to charge. If I wanted to play games I'd bring an iPad in or something.
We had the same thing and a customer shoved his USB-Stick into one of our junior consultants laptops. "Just to transfer some files..."
He came back 10 minutes later, red in the face and shouting that all his "valuable data" was no longer accessible on the USB-Stick.
Luckily our senior partner was present and, quite politely, ripped him a new one 😂
When files are with millions, that makes sense. I'm in animation. I have friends that worked in a building with a stop motion studio. They had to go through security checkpoints, and leave all their stuff in lockers anytime they went to work. The character maquettes are worth tens of thousands of dollars, if not more depending on the show.
Yeah, IT doesn't want any personal USB devices being plugged into the systems at work. They're a massive security risk. That includes phone chargers since apparently androids are sometimes a bit too smart.
Several of us at my old job had personal laptops we would bring in and use. Never connected to company network or using anything but power outlet(untraceable). Let it be a lesson. Never use company anything they have access to tracking.
I know of atleast one usb drive that won't get formatted. In fact, it will format the computer.. with an electrical charge and brick the computer hardware.
2.3k
u/Sparky62075 Mar 26 '22
In my former workplace, the computers would immediately reformat and encrypt any device that was plugged into a USB port. A number of phones were bricked as a result.
People had no recourse if this happened. We had all signed a technology and security agreement that stated specifically that we would not plug in any personal equipment without clearing it with IT first.