Don't let your networks speak to strangers

Devices are invading the workplace


Desktop Run a scan over any company network and you will probably be surprised by what has been connected to it. Staff can be very creative, plugging in everything from printers to tablet devices to departmental servers and network-attached storage devices.

They are not circumventing IT policies either, or so they think – just deploying the tools they need to do their jobs. Tablets and smartphones in particular are frequently connected to intranets and document stores.

It is not a new trend. This has been happening since the first desktop PC sneaked into an office on a departmental purchase order, ready to run Lotus 123 and save time delivering those pesky TPS reports to avoid the boss leaning over a cubicle wall and asking someone to come in over the weekend.

Leaky vessels

There are risks. User-provided hardware could easily be a route for data to leak out of a network. That’s why system administrators run regular audits to track down rogue hardware or use tools such as network access protection to quarantine it.

Active Directory helps police computer connections, but phones and other devices are harder to control.

At home they are using the latest MacBook or a Windows 7 multimedia gaming PC

Today’s users are increasingly likely to bring in their own hardware. After all, extended desktop lifecycles often leave them working on Pentium 4 hardware running Windows XP, while at home they are using the latest MacBook or a Windows 7 multimedia gaming PC with one of Intel’s latest Core i7 processors.

They want something more capable, even if budgets offer no prospect of getting new hardware soon. Technologies such as Windows Thin PC and RemoteFX can give them the Windows 7 experience on older hardware, and are well worth considering if you want to eke out PC lifespans.

Isolation ward

So how can businesses manage user expectations and how can they control the hardware being added to their networks? It’s something that today's convergence of several IT industry trends has made a lot easier to deal with.

First, the shift from device-centric to information-centric security models makes it easier to partition data so it doesn’t leak from your servers.

Policy-based security models prevent unmanaged devices from connecting to data sources (which also makes it less attractive for users to bring them into the office), and encrypted storage can prevent unauthorised connections.

That means user-provided hardware can’t connect to sensitive data. Security is still a problem, however, so divert all machines into quarantined network-attached storage until they are running anti-malware software and meet a baseline standard for system updates.

If users persist in connecting their own PCs to your network, you can take advantage of the same managed desktop techniques used to support home workers and temporary staff: virtual desktops with access to separate virtual LANs.

Tools like Microsoft’s System Center Configuration Manager are an important part of the equation, as they allow you to audit systems connected to your network – especially to wireless devices that support Exchange ActiveSync (EAS).

Nothing personal

Managing other devices is harder but enforcing EAS policies can reduce risk, as long as the devices in question support the policies they are accepting.

Users will be able to access secure IT infrastructure from their virtual desktops, while their personal applications and internet browsing are done on a low-security virtual network not connected to core business systems.

It’s an approach that requires more thought but it means that staff bringing in tablet devices or WiFi smartphones can use their untrusted devices alongside trusted hardware and trusted virtual desktops. ®


Other stories you might like

  • North Korea pulled in $400m in cryptocurrency heists last year – report

    Plus: FIFA 22 players lose their identity and Texas gets phony QR codes

    In brief Thieves operating for the North Korean government made off with almost $400m in digicash last year in a concerted attack to steal and launder as much currency as they could.

    A report from blockchain biz Chainalysis found that attackers were going after investment houses and currency exchanges in a bid to purloin funds and send them back to the Glorious Leader's coffers. They then use mixing software to make masses of micropayments to new wallets, before consolidating them all again into a new account and moving the funds.

    Bitcoin used to be a top target but Ether is now the most stolen currency, say the researchers, accounting for 58 per cent of the funds filched. Bitcoin accounted for just 20 per cent, a fall of more than 50 per cent since 2019 - although part of the reason might be that they are now so valuable people are taking more care with them.

    Continue reading
  • Tesla Full Self-Driving videos prompt California's DMV to rethink policy on accidents

    Plus: AI systems can identify different chess players by their moves and more

    In brief California’s Department of Motor Vehicles said it’s “revisiting” its opinion of whether Tesla’s so-called Full Self-Driving feature needs more oversight after a series of videos demonstrate how the technology can be dangerous.

    “Recent software updates, videos showing dangerous use of that technology, open investigations by the National Highway Traffic Safety Administration, and the opinions of other experts in this space,” have made the DMV think twice about Tesla, according to a letter sent to California’s Senator Lena Gonzalez (D-Long Beach), chair of the Senate’s transportation committee, and first reported by the LA Times.

    Tesla isn’t required to report the number of crashes to California’s DMV unlike other self-driving car companies like Waymo or Cruise because it operates at lower levels of autonomy and requires human supervision. But that may change after videos like drivers having to take over to avoid accidentally swerving into pedestrians crossing the road or failing to detect a truck in the middle of the road continue circulating.

    Continue reading
  • Alien life on Super-Earth can survive longer than us due to long-lasting protection from cosmic rays

    Laser experiments show their magnetic fields shielding their surfaces from radiation last longer

    Life on Super-Earths may have more time to develop and evolve, thanks to their long-lasting magnetic fields protecting them against harmful cosmic rays, according to new research published in Science.

    Space is a hazardous environment. Streams of charged particles traveling at very close to the speed of light, ejected from stars and distant galaxies, bombard planets. The intense radiation can strip atmospheres and cause oceans on planetary surfaces to dry up over time, leaving them arid and incapable of supporting habitable life. Cosmic rays, however, are deflected away from Earth, however, since it’s shielded by its magnetic field.

    Now, a team of researchers led by the Lawrence Livermore National Laboratory (LLNL) believe that Super-Earths - planets that are more massive than Earth but less than Neptune - may have magnetic fields too. Their defensive bubbles, in fact, are estimated to stay intact for longer than the one around Earth, meaning life on their surfaces will have more time to develop and survive.

    Continue reading

Biting the hand that feeds IT © 1998–2022