There is no explicit content at all in this article. It's all text and hyperlinks.
@dang - wasn't there a "possibly NSFW" tag on this earlier?
I'm reasonably certain that, even if I installed Tor at home to get around the site blocking, that the traffic would never make it through the proxy. Also likely is a call from security about wtf I'm doing.
How would you go about blocking Tor? The point of it is that anyone can access the Internet freely from anywhere, even if you are in Iran or China. Or behind a FascistFirewall, as Tor's config nicely puts it. I'm not sure whether it was a to-do or whether they succeeded in making it look like any https traffic, but it's not trivially blockable, not based on IPs of Tor nodes nor based on port.
> Also likely is a call from security about wtf I'm doing.
I wonder how "security" catches onto you. It's not legal (here anyway) to monitor every employees' Internet usage all the time. Investigating based on alerts may be, but what would trigger the alert in the first place?
I don't know where "here" is, but in the US it is definitely legal to monitor everything you do on company resources.
On the other hand, if things are being stolen or suspected of being stolen from the supply room, hanging up a camera at the entrance is surely a reasonable measure. A judge would have no issues with that security measure. It's all about reasonableness.
Well, as the other poster said already, in the US it is very much legal to monitor your employee's internet. As long as they're "on the clock", and/or using company resources, you can monitor them. I know for a fact that my company's proxy / firewall superbox does on the fly MitM attacks on HTTPS connections. Even though I'm connected over HTTPS right now, they're going to crack this POST open and inspect the contents, potentially even logging it, before sending it on its way.
As far as how they would know about Tor, you're possibly right. They might not... to be honest I've never inspected exactly how Tor gets around the Great Firewall. However, I'm totally not risking it, as I'm 100% sure that intentional, willful bypassing of their security system in that matter is grounds for immediate termination. Maybe they don't notice it at all, maybe they can MitM Tor too, or maybe they notice via abnormal logs coming from my MAC. Either way, it's totally not worth it to me and since I have to use their hardware and their pipe, there are no guarantees anyway.
Pretty simple where I work. First, they block all ports (including tcp 80 and tcp 443) from going out the firewall to the Internet. Second, they make you access web sites via a proxy server. Third, that proxy server uses software from a company called Blue Coat that strips out the actual site's SSL certificate and replaces it with its own that all of our workstations have been configured to trust. Fourth, it then stores all your SSL traffic in unencrypted form.
I work at a bank, but this is an extremely common scenario at all kinds of U.S. based companies. I make sure to not use any personal HTTPS sites while I'm at work for this reason.