And do you always check for keylogger thumbdrives and such?
And do you always check for keylogger thumbdrives and such?
This was a corporate requirement where I used to work, unofficially reinforced by the local jokers who would rotate the screen and / or send prank messages if you didn't.
Same here. The all time favorite is sending a resignation notice to the person's manager (the manager usually gets a fair warning first and plays along with it).
Or a message that says "I love you very much"
My colleagues edited my .bashrc to echo "lock your screen next time"
(Kidding obviously, at least for the latter).
I think at first the colleague might assume it's a bug in the terminal not someone had replaced the command with an alias
or just alias them to echo, so that it prints out the file name, not even the file content
Check for keylogger thumbdrives: I use a laptop so it would be immediately obvious. But now that you say it I haven't checked the charger USB-outlet on the back of my cabled keyboard.
[1]: it has happened I have failed. Once a year or something.
[2]: I sometimes try to allow myself to go downstairs in my own house to fetch a cup coffe without locking when I am alone, but I find it so stressful in practice I always lock it. I don't need to know but it is a good habit. I'm otherwise normal :-)
For example IT enforces that your screen becomes locked after 15 minutes of inactivity and also ties in your local computer 's user login password to your SSO login to access everything. It's a contradiction around password best practices. If you force people to input their password multiple times a day then naturally people will gravitate towards easier to type passwords.
If the idea is "but what if you go AFK in a public place and forget to lock your screen?!?", that's not a valid reason. If you were working in a coffee shop and went to use the restroom for 4 minutes or turned your back for 2 minutes then your machine could be compromised (or even worse stolen). It's extremely reckless to leave your gear unattended in a public place.
It can really break morale to input your password and MFA half a dozen times a day, especially when you're alone in a locked apartment where the laptop hasn't left that location in a year.
> For example IT enforces that your screen becomes locked after 15 minutes of inactivity
If your OS is MS-Win, try playing an audio file when you don't want the auto-lock to go off. Provided IT's "checkbox security" parameters [1] did not include turning this off, MS-Win does not timeout lock the system if an audio file is playing, which makes playback of an audio file a way to prevent the timeout auto-lock from happening. Note that this won't help with any 'presence' indicators that go "idle" or "away" with no activity for some time.
If this works, then you can create an audio file of 'silence' with sox to use to play back when you don't want the auto-lock to trigger:
sox -n silence.wav trim 0 10:0.0
Creates a ten minute long wav of 'silence'. If you want it smaller, compress the wav with lame into an mp3 or fdkaac into an aac file. Then launch playback of the silence file, and set windows media player to "loop" when it reaches the end of the file.[1] Much corporate/govt. IT "security" is "checkbox security". It is the equivalent of IT having a "compliance form" with a long list of "configured settings" with check-boxes next to each, and so long as they can go down the form and "check all the boxes" they deem their setup "secure". Whether it is actually secure is not important, just that it "checks all the boxes" on the "compliance form".
This puts you into a grey area though no? You could make a case this is willingly trying to circumvent security protocols which could be grounds for being fired.
I dealt with this as a policy issue recently. Controls like aggressive screen lockouts are one of the few options available to allow some categories of workers to work outside of a company controlled premises.
The argument that you live alone etc is irrelevant as I have no idea (and don’t want to know) whether that’s true. I can tell you that people have done shockingly dumb things with remote work and the company has to try to control risk as best it can.
What does the policy really protect against?
If it's being locked out after 15 minutes of inactivity because of roommates or kids it doesn't protect you against anything in the grand scheme of things. For example if I leave my office for lunch and you step in 10 minutes later then you have a solid 40-50 minutes to do whatever damage you plan to do while I'm gone.
The only time it makes a difference is if it locks really fast, such as 30 seconds but then using the computer naturally would be ridiculous because you couldn't stop touching the keyboard or mouse without being locked out.
Also, what if your room mate planted cameras in your office that let them see exactly what keys you're pressing on what screens without ever compromising the machine itself? Now everything is compromised and they have full reign to do whatever they intend to do.
> The argument that you live alone etc is irrelevant as I have no idea (and don’t want to know) whether that’s true
This is the real problem. Everyone gets treated like an equal criminal when in reality none of the measures taken really do anything to provide the security they were designed to do. It reminds me a lot of "for the children" but applied to corporations for "compliance reasons".
I'd be more ok with the precautions if they worked.
Re: the “treat people like a criminal” take. A common approach organizations are taking is employee surveillance. I don’t want to know that your girlfriend has a conviction or that your kid sits next to you with sensitive data in your screen, etc. And I don’t want to force you into an office.
There’s a difference between “security” and risk management. If the discussion was pure security with low/no risk tolerance, you’d be working on a locked down terminal server in an office.
If you're on windows, there's a powertoy[1] called "Awake" that can keep your screen on indefinitely despite IT rules. I liberally use this on machines I'm remotely connected to because there's 0 reason why a remote session should lock if I'm active on the computer looking at a different window.
Then they don't type most of the time and the length of 'memorable passwords' (like correct-horse4BATTERY!staple) isn't a problem.
Ah, no mention of water proofing computer to protect against robotic dog innocently spilling moring coffee/tea on computer.
On Windows, Win-L to lock.
When home, I always have to lock or my cat would typeeeeeeeeawww
I haven't used a use usb stick in +10 years.