Calling all Virtualization Gurus.

OMG, The head of cyber security just took a shot. Signed off, No problem.


We're in business boys.

To all the peers I have lost due to nefarious means after objecting to this. I raise a glass in remembrance. There were 1 or 2 I could truly call my equal. I am saddened by your loss.
 
Policy does not supersede law.
You cannot fight the machine. The Machine always win. Even If it loses it still wins in the end. It might cost them a little extra to get rid of you. But rid of you they will still be.
It took them 3 years to make the last guy leave out of his own will. But he is gone.

They are patient, They never forget nor forgive. The Law above the table has no bearing on actions below the table.

Hence I have given up on fighting a losing battle. They only need to perceive compliance...

Smile and Wave boys...
 
My personal Computer.
Fine, I'd tell them to go ahead with the caveat that they pay for the 16 hours per day of rent for the equipment. Very simple, other than that, it just won't do, you can do some registry manipulation which must be run each reboot.
 
Fine, I'd tell them to go ahead with the caveat that they pay for the 16 hours per day of rent for the equipment. Very simple, other than that, it just won't do, you can do some registry manipulation which must be run each reboot.
Ended going another Route. Spin them some story that I Struggle to get the Drivers working as I borrowed a harddrive to get the Computer working again.

Little bit of background. I am not allowed to perform any computer related work at my place of work. I have no privileges what so ever. Not even logins or account names for that matter.

To everyone's knowledge I am a complete invalid where Computers are concerned.

I constantly get refferd to as "Don't worry about this guy...He is too stupid to do anything. " Which kinda works to my advantage.
 
Ended going another Route. Spin them some story that I Struggle to get the Drivers working as I borrowed a harddrive to get the Computer working again.

Little bit of background. I am not allowed to perform any computer related work at my place of work. I have no privileges what so ever. Not even logins or account names for that matter.

To everyone's knowledge I am a complete invalid where Computers are concerned.

I constantly get refferd to as "Don't worry about this guy...He is too stupid to do anything. " Which kinda works to my advantage.
Your PC, your rules, I'd put in dual boot, once you knock off, boot into the other instance, the instance they install their "stuff" on can be a limited user account, no chance of installation of anything else when they "remote", also, no chance of accessing anything to spoof on the other instance. Lock it down. Consider getting a router, like a mikrotik, that will allow you to log traffic and selectively block, you will also be able to gather evidence of their "hacking" activities for that fateful day.
 
Your PC, your rules, I'd put in dual boot, once you knock off, boot into the other instance, the instance they install their "stuff" on can be a limited user account, no chance of installation of anything else when they "remote", also, no chance of accessing anything to spoof on the other instance. Lock it down. Consider getting a router, like a mikrotik, that will allow you to log traffic and selectively block, you will also be able to gather evidence of their "hacking" activities for that fateful day.
Duel boot was looked at. As it was on older generation hardware I decided against it. In the event of a Crash backup and restore would also have been a pain.

Now I copy a file....Done and dusted.

When the VM is closed,They perceive that My computer is off....
 
Duel boot was looked at. As it was on older generation hardware I decided against it. In the event of a Crash backup and restore would also have been a pain.

Now I copy a file....Done and dusted.

When the VM is closed,They perceive that My computer is off....
Alter your host registry, cpu is the only thing that matters anyways, but you must lock down the VM to ensure that programs like cpuz never see the light of day there, gfx literally doesn't matter as it's not virtualized and therefore untraceable.
 
Like HDD and Grfx which can't be used directly by the VM
Actualleh,you directly pass through a Harddrive on HyperV (Take it offline on the Host,then in HyperV attach the disk and bring it online) - i'm not sure if it displays the actual disk info or some other magic befuddling though
It's a trick to use in Azure to recover VMs
 
Ended going another Route. Spin them some story that I Struggle to get the Drivers working as I borrowed a harddrive to get the Computer working again.

Little bit of background. I am not allowed to perform any computer related work at my place of work. I have no privileges what so ever. Not even logins or account names for that matter.

To everyone's knowledge I am a complete invalid where Computers are concerned.

I constantly get refferd to as "Don't worry about this guy...He is too stupid to do anything. " Which kinda works to my advantage.
But they do worry about you, they worry about you a lot.
 
But they do worry about you, they worry about you a lot.
I understand the Need to worry. If you get 100K plus attacks on your firewall per day You need to worry.

However. First rule of security, DO NOT ALLOW PRIVATE EQUIPMENT! there 98% of problems evaded before you even started. Now just internal patching and the odd unknown hardware vulnerability.
 
You cannot fight the machine. The Machine always win. Even If it loses it still wins in the end. It might cost them a little extra to get rid of you. But rid of you they will still be.
It took them 3 years to make the last guy leave out of his own will. But he is gone.

They are patient, They never forget nor forgive. The Law above the table has no bearing on actions below the table.

Hence I have given up on fighting a losing battle. They only need to perceive compliance...

Smile and Wave boys...
See that's the thing, there is such a thing as constructive dismissal where you can resign and still bring a case for unfair dismissal. If enough employees did this they would have a really hard time justifying their practices and quickly change them. Imo employers like this should be outed and forced out of the environment.
 
I still don't understand what happened here. Or what the requirement was exactly. How can they force you to install software on your machine when as far as they are concerned, you don't even have logins or anything?
If they are investigating attacks and suspecting you, and if it was you, then surely you wouldn't offer up the details to the machine you used? WTF is this thread?
 
I still don't understand what happened here. Or what the requirement was exactly. How can they force you to install software on your machine when as far as they are concerned, you don't even have logins or anything?
If they are investigating attacks and suspecting you, and if it was you, then surely you wouldn't offer up the details to the machine you used? WTF is this thread?
It's company policy. Everyone needs to do it. No exceptions. I'm all for the rules as I know how important security is and how a Business can be crippled or even closed down permanently. How ever the Security consultant took chances and made recommendations which are of no use. And will have no effect on the integrity of the company's network. All to bag some extra coin, As they rent out the software on a per person license base...

I'm sure the true nature and use of the software evades management completely as they are not skilled or educated in computer systems and/or Computer Security.

I feel for these guys as they are duped into something they spend a great deal of money on. But they don't listen to employees complain to them. We just need to bare with the problem and no way to fight it. That is wrong.

In life you deal with a Problem by sorting out the Cause. Not by ignoring it and steamrolling ahead. This is the quickest way to Close your doors. We were mighty. We were the strongest. Now every startup with a semi plausible idea scares the crap out of me.

All in all this is a Management problem Wrong Policy combined with uneducated staff/poorly educated staff.

This can only end in disaster.

Oh and once the software is on, it is on...There is no way to remove or disable it. Short of hard formatting the whole machine.

I have found a way to remove it. But the damage it does is permanent. And there no way to restore any setting it has changed.

This is completely acceptable in a high secure network where all equipment needs to be constantly monitored for breaches or illegal software loaded or accessed. even our browsers are blocked. You cant do didly squat on the Infected machine.

Now take a Hike. MY PC, I pay for it. I will bloody well run anything on it I want. If I want a virus then I will Load a Virus. If I want keyloggers to make the Chinese very negative then I want a Keylogger.

If I want to run a torrent then I want to run a torrent. Not everything is illegal. I paid for all my usual software packages. Windows, Office ect ect. Then they tell me oh no sorry you need to buy this. you need to use that. this might have a problem next month sorry you have to buy everything over again if you don't like it get another JOB.

Well since it is my Personal Equipment I can run anything on it I want. As long as I stay out of Kitty porn and not draw the attention of the CIA and FBI I will be fine. That is pretty much my hard limit.
 
It's company policy. Everyone needs to do it. No exceptions. I'm all for the rules as I know how important security is and how a Business can be crippled or even closed down permanently. How ever the Security consultant took chances and made recommendations which are of no use. And will have no effect on the integrity of the company's network. All to bag some extra coin, As they rent out the software on a per person license base...

I'm sure the true nature and use of the software evades management completely as they are not skilled or educated in computer systems and/or Computer Security.

I feel for these guys as they are duped into something they spend a great deal of money on. But they don't listen to employees complain to them. We just need to bare with the problem and no way to fight it. That is wrong.

In life you deal with a Problem by sorting out the Cause. Not by ignoring it and steamrolling ahead. This is the quickest way to Close your doors. We were mighty. We were the strongest. Now every startup with a semi plausible idea scares the crap out of me.

All in all this is a Management problem Wrong Policy combined with uneducated staff/poorly educated staff.

This can only end in disaster.

Oh and once the software is on, it is on...There is no way to remove or disable it. Short of hard formatting the whole machine.

I have found a way to remove it. But the damage it does is permanent. And there no way to restore any setting it has changed.

This is completely acceptable in a high secure network where all equipment needs to be constantly monitored for breaches or illegal software loaded or accessed. even our browsers are blocked. You cant do didly squat on the Infected machine.

Now take a Hike. MY PC, I pay for it. I will bloody well run anything on it I want. If I want a virus then I will Load a Virus. If I want keyloggers to make the Chinese very negative then I want a Keylogger.

If I want to run a torrent then I want to run a torrent. Not everything is illegal. I paid for all my usual software packages. Windows, Office ect ect. Then they tell me oh no sorry you need to buy this. you need to use that. this might have a problem next month sorry you have to buy everything over again if you don't like it get another JOB.

Well since it is my Personal Equipment I can run anything on it I want. As long as I stay out of Kitty porn and not draw the attention of the CIA and FBI I will be fine. That is pretty much my hard limit.

Chances are, some of your searches already pinged somewhere. I still don't get it. Just tell them you don't have a PC. You had one, but loadshedding killed it.. Or something. But c'est la vie.
 
Chances are, some of your searches already pinged somewhere. I still don't get it. Just tell them you don't have a PC. You had one, but loadshedding killed it.. Or something. But c'est la vie.
I was in the Deep web. I dabbled a bit in the DarkWeb. watched a few idiots do some silly suff. had some Lols. nothing illegal. It exists. no one is going to take it away. Yes the FBI knows about me. the moment you click download on a browser they know about you. I don't car about that as I do it for educational purposes. If you really want drugs just go and stand on any street street corner.

We have everything that exists in the world. And Krokodil really scares me. Don't google unless you have some serious nerves.

They know exactly what we have. Declaration is not negotiable.
 
I was in the Deep web. I dabbled a bit in the DarkWeb. watched a few idiots do some silly suff. had some Lols. nothing illegal. It exists. no one is going to take it away. Yes the FBI knows about me. the moment you click download on a browser they know about you. I don't car about that as I do it for educational purposes. If you really want drugs just go and stand on any street street corner.

We have everything that exists in the world. And Krokodil really scares me. Don't google unless you have some serious nerves.

They know exactly what we have. Declaration is not negotiable.

Are you working in like a law enforcement role or something? I cannot grasp why anyone would allow their employer access to their personal machine. I would ensure my PC was reported as stolen or something. How would they know?

Also, deepweb and darkweb are two separate things.
 
Did OP mention or anyone ever find out what spyware/software is being used or the name of it? Chances are we know one or two and could offer some insights.

Is the company not able to just use BYOD device enrollment/InTune or something?

I'm lost. WTF actually happened to cause such a communist requirement?
 
Easy way. Go buy a 2nd hand laptop for a few K.
Reload it as new and tell them that is your pc , but you dont use it much.

Take it in and let them load whatever kak it is they want on it. Every now and again do a web search or some arb **** on it.

If they want to do a home visit tell them to get a warrant
 
Top
Sign up to the MyBroadband newsletter
X