The same could happen to mail, where you can only use "certified provider" or you will just be filtered out. Spam and phishing are a problem, sure, but recent IT strategies are highly questionable in this regard.
IMO there's also a failure of government here to both ensure an open internet and to come down on people abusing the system. A related example might be the phone spam calls everyone in the US gets - it's an administrative, legal, and regulatory problem, not a technical one.
My context may be a bit skewed though since I'm a sysadmin turned cybersecurity and I've seen the large numbers of people clicking on the absolute stupidest things. Given the "average" computer use that IT has to deal with I'm much more sympathetic to their plight.
I think it of as a result of high profile hacks. Either a company is hacked once and they go way overboard trying to ensure it doesn't happen again. Or, some high profile company gets hacked, some C*O's see it, overreact and decide they're not going to be next.
Also: polish up your resume and start sending it out.
There has never been anything wrong with them, it's just braindead blocking software purchased by incompetent managers.
Having been that IT person early in my career, responsible for networks, firewalls and policies, what you say sounds cruel. But I could not agree more. Today there is a tragic de-skilling in ICT. When I speak to modern corporate or academic IT people I make the best faith assumptions. I assume they are like we were in the early 90s and speak to them accordingly with technical respect. Then I discover they cannot configure a mail or web server, cannot compile a program, or even use a package manager... they don't know how to read logs or change permissions on a directory.... the mind boggles. I've had senior IT people tell me that they're "not technical" and it turns out they've arrived on some "management track" from an arts-history background.
I'm not knocking arts history, or being "elitist" I hope, but this raises serious concerns for me. What is going on in IT? Have cloud services, tick-box webmin interfaces and packaged solutions led to a brain drain?
One could argue that modern IT people don't need "geeky computer skills" any more, because Google and Microsoft have solved everything. But that doesn't pan out, because when simple things go wrong they cannot fix them (which is their job). Right now I am dealing with an international university whose impeccable pedigree is bedrock in computing history - and their IT people cannot fix a simple email issue, to the extent the staff and students have to set up their own servers. The fact is, they just don't have control over it any longer. I think the entire senior ranks are just marking time till they can retire.
How did that pan out?
On a corporate network, it can make total sense to block non-business sites by default. As someone who used to help manage the proxies at a bank, some of the arbitrary decisions annoyed me (like blocking gTLDs of all sorts by default) but at the end of the day, it was an inconvenience. There were mechanisms to request access if needed.
To me, it starts to get more shady with behavioral analytics software on terminals that measure your known patterns of access and look for aberrations. It becomes intrusive and creepy in its move from "passive" filtering to active, personalized monitoring.
---
All that is irrelevant here, because an ISP fucking with my TLS connection and throwing up warnings is awful.
I don't mean entertainment; I mean suits making decisions about what engineering needs etc.
Again, prior experience, we had brainstormed the idea of denying any executable downloads by frontline workers, while permitting it for IT, since frontline workers both were less likely to need to download random EXEs, and less likely to know how to spot phishing or grayware sites.
Legitimately asking, why do you need access to your private website on corporate resources during work? Access your private stuff on your BYOD.
The problem isn’t what I want to do it’s having an intermediary in the process who only introduces drag.
I 100% understand the frustration of working in a place where lawyers "introduce drag". Lawyer's job isn't to make your job harder/easier, but to protect the company from whatever. Sometimes whatever turns out to be the "well intended" employee. Part of the friction in these situations are very zealous people wanting to do things while they are so scoped in on their task that they are unawares of the larger consequences to the company no matter how well intentioned they may be. As I've become older, I can corrolate that friction with youth. That coefficient of friction becomes smaller with age/experience. It has nothing to do with levels of caring/apathy, but from experiencing the negative affect of "move fast, break things" and being willing to tap the breaks a little bit while changing altitude to see a bigger picture.
Although that is not a very strong justification.
With how verbose and talkative applications today are it wouldn't be appropriate to route their traffic through the company line anyway.
Of course that decreases the security that deactivating split tunneling offers to a degree, but I think we have to live with that. All this security is ineffective anyway if 99% of attacks come through the inbox. That will never be change and people need to be educated and have to trust IT that they don't blame the user since it can happen to everyone and nobody is on guard to 100%. With decent backups the damage can usually be completely mitigated without a lot of expensive security measures.