The building is getting structured cabling.
I've known a lot of people who were amazing at their job, but shitty at running a business. I guess I would have tried to help these lawyers and explain their wrongheaded tech decisions to see what their next move would be. That would give me a better understanding of whether they were an outfit worthy of my time.
On a side note, I have no idea why pgp is not more common in that industry. It's completely insane. In some ways, you'd be better off sending your legal correspondence on a postcard with attorney/client priveledge disclaimer at the bottom.
Maybe because pgp is still the same pain the butt it was back in the 90's. Nothing significant has been done to improve the user experience.
Meanwhile, roll forward to 2022 and there are now dozens of good quality secure document sharing platforms, all of which have full web, desktop and phone/tablet integration.
> Case in point: just a few weeks ago Goldman Sachs mistakenly sent a sensitive email with account information to a random Gmail user because someone fumbled some keystrokes and sent to a “gmail.com” account instead of a “gs.com” account. The email contained such sensitive information that the only recourse Goldman had was to get a court order to require Google to retract the message. Just this month, the UK’s Information Commissioner “sounded the alarm” for lawyers in an attempt to get them to realize that unencrypted email is an unacceptable risk for privacy.
It is by far the weakest link in terms of law firm information security these days.
There are long established standards such as 802.1X which involves mutual TLS encryption for wifi. This is generally called "Enterprise WPA" or something like that. This means that all wifi traffic is encrypted to what I would call: a decent standard.
I hope your friend did a proper analysis of the wifi offering and didn't simply discount it out of hand because it is wifi.
There are a lot of issues here and the wifi vs wired thing is bloody complicated but make sure you understand all of the issues before pontificating about one vs the other ... 8)
(edit: 51 year old commentard here)
Then you do your "due diligence" etc. I think we should all understand at a fairly basic level how wifi and wired works and what to do.
Fire up the VPN!
> For both wired and wireless access, Google uses RADIUS servers to assign devices to an appropriate network, based on 802.1x authentication. We use dynamic, rather than static, VLAN assignment. This approach means that rather than relying on the switch/port static configuration, we use the RADIUS servers to inform the switch of the appropriate VLAN assignment for the authenticated device. Managed devices provide their certificate as part of this 802.1x handshake and are assigned to the unprivileged network, while unrecognized and unmanaged devices on the corporate network are assigned to a remediation or guest network. - https://static.googleusercontent.com/media/research.google.c...
Yes BeyondCorp does allow access to corporate resources outside of the intranet, but as part of a managed device + identity + network evaluation.
Wi-Fi is a shared medium in a crowded and noisy spectrum environment. I can see a dozen networks from my house, and I'm in a (dense) neighborhood of single family homes--it's much worse in a high rise office building. It can have decent bandwidth (almost a gigabit when it gets going) but reliability, latency, and jitter are bad.
I've had another neighbour buy a wireless landline from China that was because "sometimes the phone would crackle, and i hated that" meanwhile it would bring every 5ghz wifi network to its knees when she was taking a phone call.
So, there are other cases, maybe this is a bit more prevalent in countries closer to those with lax spectrum laws.
The licensed frequency bands, in contrast, are congestion free and more polite let’s say. I’d be willing to pay a monthly fee for use of one of those frequency bands. But good luck getting permission from the FCC to do that.
You mean a cordless phone?
If I were a corporation looking to hire a law firm, this would be a serious down-check for them, as I don't want the details of any cases they're handling for me exposed on a shared network.
This could also be considered weak protection of client-attorney communications, and get the state Bar Association involved.