Which is clever, but given the current level of small scale integration you could just as easily hide the same exploits inside of a charging cable, a USB fan, or really any other small-form factor USB-pluggable gadget. The problem isn't them discriminating between "hacked" and "non-hacked" devices -- it's them plugging _anything_ non work related or issued into their USB ports.
(I'm genuinely surprised that the standard DELL and HP corporate workstation doesn't have its front USB ports deleted and its rear port access covered by a lockable metal cowl.)
So you'll have to replace all of your intentionally-broken computers with good ones, which will cost a fortune on top of all the employees' lost work time and no one will want to buy the broken computers from you so you'll have to pay to have them scrapped.
The person with the accounting data on a USB stick will get a formal reprimand for breaking the security policy.
At work, we keep a couple of power-socket-to-USB chargers around, if people want to charge their smartphone they can grab one. But simply disabling the USB ports on our users machines is not a realistic option at this point.
Surely by now all corporate desktops should be configured to not respond to any USB devices other than the generic HID for mouse and keyboard, plus a whitelist of approved devices (e.g. fingerprint readers, Yubikeys). Inserting a USB mass storage device into a corporate workstation should result in nothing. Plug-and-play shouldn't be triggered. The mass storage driver should not load.
Bonus points: don't mount the drive directly, instead connect it to a centralised server on the corporate network that scans for threats and mounts a sanitised version of the drive's contents as a network share.
Triple word score: audit everything contained on every drive and everything that is copied on and off.
Sell that for $200 per unit to Fortune 500 companies and paranoid government agencies worldwide... and you'll retire early.
I expect someone sells hardened ultra-secure corporate NAS boxes, but I've never seen any in the wild.
Whoops, my tin-foil hat appears to have slipped.
We are dragging people to a corporate cloud solution, however we are finding that the drive to cloud has severely underestimated the volume of data that people will sync across the network, and how much work is done outside official corporate systems and in Excel instead.
This is having 2 effects our network capacity is being drained, and users are reporting performance issues due to latency associated with poorly developed excel applications.
Conducting that test produced something tangible for whoever made the purchasing decision: It clearly illustrated a need for the services rendered, did it in a way that offered job security to management by giving them license to assert the position over their subordinates, and established a metric by which to evaluate the security company's performance which can be easily, repeatably, and predictably improved over time.
It also checked a lot of boxes that will be useful in court if they ever need to prove that they weren't negligent on privacy and security, which is a form of insurance that has real measurable value when it comes to legal claims.
I'd say it's 40% paranoid arse-covering by IT department heads, 35% whatever middle management incorrectly assumes to be current best practices, 20% ego-stroking by the CIO, and 5% sensible context-driven decision-making by IT front-line staff.
* A ban on mail attachments of certain types (excel, zip files...) * mailbox limits from the 1990’s (100MB or so) * a ban on Dropbox, Gdrive or any other file sharing service * No public facing sftp or similar * A web site so mired in red tape that it takes 6 months and a dozen approvals to get anything uploaded.
Often the USB drive or something similar is the only way for employees to actually do their jobs.
I have seen this kind of situation, too. It sucks, but if you play by the corporate rulebook and lobby for better rules, you will be either worn out or retired by the time those rules get updated.
Sorry for mixing windows and Linux but conceptually something like this should work on windows if you don't require password in your UAC prompts.
Hm, perhaps.. is anything like that available already?
While your final comment is accurate, it is impractical as usb mass storage is still required in many places. Also, you can't effectively block HID, and an attacker can use HID disguised as or in a thumb drive to successfully attack a network.
Second, it can emulate an HID keyboard device and type keystrokes faster than you can react and pull it out, at which point it’s far too late - it’s pulled a secondary payload down or mounted a USB mass storage device and you’re owned.
You know those little desk fans that come with a USB now and also an adapter to plug into the electrical outlet. I don't plug those into my laptops ever - who knows if there's a payload on them.
I will say this. I currently work, and have worked at, a few secret and top secret facilities - and the number of people I see plugging those (and similar) devices into their laptops is scary.
If such a device is able to cause a compromise / incident in a secure facility, well, several different "failures" at several different levels have occurred in order for it to get to that point.
You may want to double check your CentOS desktop's defaults (you might be surprised).
My most critical machines have a file named /etc/modprobe.d/disabled.conf with entries such as these for dozens of filesystems, network protocols, and such:
install usb-storage /bin/false
install vfat /bin/false
When absolutely required, they can quickly be temporarily commented out (but not by mistake) and there's some very extensive auditing rules that keep an eye on things at that point.It's really not that hard to lock a machine down and yet still have it actually remain usable. With the exceptions of the few security-focused distributions (Qubes OS, Tails, etc.), I can't think of any Linux distribution / desktop environment that even comes remotely close to doing anything like that (OOTB) by default, though.
Aren't you shooting the messenger?
I don't necessarily disagree, but power users often get frustrated by red tape applied to everyone and not just those who consistently misuse their computer privileges.
Simple and effective, although it destroyed any resale value of the PCs.
when they were life expired they were given over to a recycling company, whom I assume would take the time to pick the epoxy out of the USB sockets or probably just replace them. I think buying new USB sockets and connecting ribbons to the motherboards is probably quite cheap these days
Time and time again the technology industry has failed to consider security as a serious issue, never mind develop systems that are robust and transparent.
We don't have botnets, booby-trapped mail attachments, script-hackable servers, USB drives that can carry a viral payload, and all the rest because users are stupid, but because the industry's default culture is to think of security as an esoteric side issue, and not a non-negotiable critical feature in all IT systems.
Thing #1 to remember if you're in infosec is that you must pitch it based on the money saved by not having expensive problems like having to hire outside consultants and auditors after a breach.