Then they have to make that decision about every site. And re-evaluate that decision every so often.
Then they have to make that decision about every site. And re-evaluate that decision every so often.
Every time a security practitioner has to make a new decision, that opens up the possibility of making a mistake. Therefore, it is good practice to limit the number of decisions that you have to make.
That's why the standard policy for firewalls is default deny, and you have to make an affirmative decision to let packets in.
That's why we make cost-benefit decisions about blocking policy.
Does it cost NASDAQ to block Tor exit nodes from reading their blog? Not materially. Anyone that desperate to read that material anonymously can ask the Internet Archive for it, or get some other proxy to pull it for them. None of their actual or potential clientele will feel the need to use Tor.
Does it benefit NASDAQ to have a general policy of blocking Tor exit nodes? Yes, it definitely does. If you want to probe a site's security, Tor and rented botnets are the sources of choice.
I don't know whether NASDAQs security people are competent or not in general, but in this specific example, they made a good choice.
Uh... that's worse than a security fetish.
Insurance companies are putting incredible pressure for business to lock down their IT HARDER not less hard.
Seriously, look for tor to get blocked lots more places.
"security fetishists" are going to be making good money for a while yet.
We're rolling out tor blocking our sites where we didn't used to need that. I think more automated options as well will come (think cloudflare) which will help folks with this as well and maybe jam tor users into perhaps recaptcha loops or similar? Not sure what right solution is to filter out the tor users - hard block or try and detect and recaptcha etc.