It's totally insane to send them to a remote service controlled by another organization.
It's totally insane to send them to a remote service controlled by another organization.
1) employees are trusted with secrets, so we have to audit that employees are treating those secrets securely (via tracking, monitoring, etc)
2) we don’t allow employees to have access to secrets whatsoever, therefore we don’t need any auditing or monitoring
It works the same way for biometrics like face unlock on mobile phones
Factually, it is necessary for auditing and absolutely correlates with the extreme of needing to monitor the “usage” of “secrets”.
In a highly auditable/“secure” environment, you can’t give secrets to employees with no tracking of when the secrets are used.
This does not seem to require regularly exporting secrets form the employee's machines though. Which is the main complaint I am reading. You would log when the secret is used to access something, presumably remote to the users machine.
Sending env vars of all your employees to one place doesn't improve anything. In fact, one can argue the company is now more vulnerable.
It feels like a decision made by a clueless school principle, instead of a security expert.
Repeat after me: Security is not a bolt on tool.
Good start, might need a little more work around the edges.
If you lean in the direction of keylogging all your employees, that's not only lazy but ineffective on account of the unnecessary noise collected, and it's counterproductive in that it creates a juicy central target that you can hardly trust anyone with. Good auditing is minimally useful to an adversary, IMO.
Yeah. So you track them when they are used (which also gives you a nice timestamp). Not when they’re just sitting in the env.
IMHO needing to be monitored constantly is not being "trusted" by any sense of the word.
Similarly employees can be trusted enough with access to prod, while the company wants to protect itself from someone getting phished or from running the wrong "curl | bash" command, so the company doesn't get pwned.
Right, but doesn't that mean there is no risk from sending employee laptop ENV variables, since they shouldn't have any secrets on their laptops?