Was the argument by the bankers basically a complaint that retooling would be very expensive? and/or that employee surveillance would be more difficult? (yeah, I'm sure everyone is a fan of that!)
Was the argument by the bankers basically a complaint that retooling would be very expensive? and/or that employee surveillance would be more difficult? (yeah, I'm sure everyone is a fan of that!)
Are you a fan of laws like "people who sell you financial products are not permitted to lie" and "financial institutions must make an effort to ensure that their salesmen are not lying to customers" or at least "there need to be records so we can sort it out on the lawsuit after the fact"?
That's one of the main things employee surveillance is for in financial services.
Security is hard. Hard problems are easier when there are fewer of them. It's easier to build one big wall than lots of little ones.
Surveillance of employees is a cornerstone of enterprise security because humans are inherently untrustworthy. One part of the solution to this problem is to define a distinction (using golf[+] of all things as an analogy) between the rough, the fairway and the green. Because defining a border between the rough and the course is easy, and untrustworthy humans aren't all that bad most of the time, the distinction between the fairway and the green easily becomes blurred.
While employers may polish up the distinction between their workaday desktops and their locked-down servers they will never abandon the difference, and nor should they, between their systems and everyone else's systems.
[+] You have my permission to use this analogy with your manglers.
The reason it's a cornerstone is because your clients, especially laptops, are huge gaping attack vectors. They visit other networks and browse the web. Even if they're browsing the web 100% of the time through a web proxy it's not going to catch everything.
And it's for that same reason Google decided to shrink their perimeter. The distinction between their systems and someone else's is still maintained, but they've accepted and embraced the fact that the laptops used by their employees can and will get owned. So instead of acting as a bridge between the internet and internal squishy networks they sit out there with the internet.
But I'm hardly doing the concept justice. In fact I'm probably hurting it more than helping it. If you haven't read it Google discusses the security concepts in a short paper you can get here: http://research.google.com/pubs/pub43231.html
Yes.
Everyone else should be more vulnerable to MitM attacks and insecurities, because it's too expensive for them to fix their endpoints.
I don't care. Security protocols are hard enough to design correctly, without adding crap like that. And, I don't care enough about their crappy business model to support it by giving up some of my security.
It's 2016, people. Grow up, or get out.
The problem here is really they were way, way, behind on getting their concerns out there.