http://codepen.io/anon/pen/ALdqox/right/
This version connects to squareup.com, twitter.com, www.facebook.com, accounts.google.com, accounts.google.com, plus.google.com, login.skype.com, www.flickr.com, www.spotify.com, www.reddit.com, www.tumblr.com, www.expedia.de, www.dropbox.com, www.amazon.com, www.pinterest.com, www.netflix.com, de.foursquare.com, eu.battle.net, store.steampowered.com, www.academia.edu, stackoverflow.com, accounts.google.com, github.com, medium.com, news.ycombinator.com, carbonmade.com, courses.edx.org, www.spiegel.de, slack.com, www.khanacademy.org, www.paypal.com
I mean I think its too much to ask for a tool to be able to block everything right without a little human assistance.
After enabling this filter, 0942v8653's version also failed.
FWIW, Spotify doesn't seem to get recognized properly. I am definitely logged in and it should show up when all my browser protections are disabled. HN showed up when I disabled everything, but not Spoitfy.
So any website (even your own company's internal one) can check stuff like this. And you can't do anything about it. Other than always using private browsing for anything you don't want your company/anyone else to know about.
Personally I view this as a browser and/or protocol issue (the kind that has trickled down from the origins of the web) and really can't fault the author for it. In fact I think it's appropriate the author left these requests in as it reflects an actual attack scenario better perhaps.
Then again, businesses in general aren't exactly paragons of intelligence either, so I wouldn't be surprised if someone made a fuss about it...
If I worked for such a company, all my traffic would be flowing over a VPN, full-stop.
When you work for such a company, all VPNs are blocked and prohibited, full-stop.
Source: worked for such a company
All direct Internet access is blocked and prohibited, with all attempts to access the Internet (tcp/80, tcp/443) transparently proxied via Bluecoat/Websense/Forcepoint/etc proxies, which filter based on URL categorisation. WSS generally doesn't work in this kind of environment. Everything else is dropped.
Any attempts to bypass filtering is a violation of IT policy and is sackable. Visiting sites that are blocked gets logged, doesn't generally get flagged up unless is a daily occurrence, and the first assumption is usually malware.
Source: Worked for several such companies, was responsible for perimeter security in some.
"very NSFW" and "serverS" were overstatements.
IT team then calls in air support