Restrict USB Mass Storage Policy Issue

As if that policy will stop the determined:

1. Open laptop
2. Take out internal storage
3. Connect hard drive to other "clean machine" with USB to SATA or whatever
4. Copy data
5. ???
6. Profit
7. Chuckle at Bionic

Watches Bionic implement some kind of encryption on internal storage where only IT support will have the encryption keys... cause users are lusers.

Just hope it all applies to Bionic (and all execs as well, no exceptions) and he has to provide 1st line support for people encountering road blocks. I'm sure this is why this silliness died at our place, the IT support overhead, lost productivity and execs being impacted.

But to at least try to appear helpful, what about getting the LTE dongles that get seen as a network card? That should work, since no local/provider software BS.
 
As if that policy will stop the determined:

1. Open laptop
2. Take out internal storage
3. Connect hard drive to other "clean machine" with USB to SATA or whatever
4. Copy data
5. ???
6. Profit
7. Chuckle at Bionic

Watches Bionic implement some kind of encryption on internal storage where only IT support will have the encryption keys... cause users are lusers.
Have you ever heard of Bitlocker? I assume if they are security conscious, they would have that in place. Bitlocker encrypts everything and you can't read it from another machine. Bitlocker is part of Windows and stores recover keys in Active Directory that support can provide if necessary.
I've never had a work laptop without drive encryption and for the past 10 years at least, that's been Bitlocker.
 
Have you ever heard of Bitlocker? I assume if they are security conscious, they would have that in place. Bitlocker encrypts everything and you can't read it from another machine. Bitlocker is part of Windows and stores recover keys in Active Directory that support can provide if necessary.
I've never had a work laptop without drive encryption and for the past 10 years at least, that's been Bitlocker.

Of course I have heard of it, and now he will be using it, or something else, to block my method. You did not expand on the blocking of the user being able to view the Bitlocker key whenever they want (normally they would be able to), thus not having any impact on my attack vector, so did you even consider that aspect? Which is why I put the IT support only part in there. Even then there is bypass I have identified for the truly determined, and an even more draconian measure to stop "only IT support" has the keys bypass.
 
Of course I have heard of it, and now he will be using it, or something else, to block my method. You did not expand on the blocking of the user being able to view the Bitlocker key whenever they want (normally they would be able to), thus not having any impact on my attack vector, so did you even consider that aspect? Which is why I put the IT support only part in there. Even then there is bypass I have identified for the truly determined, and an even more draconian measure to stop "only IT support" has the keys bypass.
Bitlocker recovery key is usually only available to administrators on a PC. Best practice would be for standard users not to be admins and only support personal to have dedicated admin accounts. I think the only exception is if you store the key in Azure AD, then I think the user gets access by default, but not if stored in AD - AD doesn't even track a relationship between a user and a computer
 
Data leakage prevention is my mandate. I dont trust the employees with data management especially going to our competitors
How are you going to prevent people from uploading to the cloud, or even taking pictures of the screen? Disabling USB storage is not going to help you and is only going frustrate users.
 
How are you going to prevent people from uploading to the cloud, or even taking pictures of the screen? Disabling USB storage is not going to help you and is only going frustrate users.
What do you use a USB storage device for? I can't remember the last time I needed one.
USB storage is considered a massive risk for both data breaches and as an entry point for malware.

You can't block everything, but just because it's not possible to block everything doesn't mean you shouldn't bother. For reference, with the likes of POPI, GDPR and various regulatory frameworks, you have to prove you've taken all reasonable steps.
If you look at the TSA (responsible for security in American airports), their checks (including baggage checks, metal detectors and body scanners) fail to identify weapons 95% of the time when tested. Even with something that ineffective, they still act as a deterrent.

In regards to uploading to the cloud, you can use a proxy to block a lot of cloud shares and monitor the proxy logs to see when someone has uploaded a file to a website.
 
Don't understand some of the really visceral responses to the OP.

I am the IO locally, and we enforced encryption on USB storage devices 8 years ago. Was it a pain - yeah it was. But the regularity that people kept on losing flash drives ,etc and not remembering what was on them was concerning.

With POPI, we banned USB storage devices altogether. Not blocked ,just banned. If they plug it in, and want to write to it, it will need to be encrypted first.

In any case, with cloud storage , easier to share data internally or externally with all the security that brings.

And all endpoints (PC's, mobile devices ) are required to have encryption on internal drives before corporate data can be accessed. Our zero trust model applies to us admins too. Nobody has admin access (dedicated accounts for admin actions). On PCs - local admin passwords changed daily.

Many of this enforced by the CISO and their SOC. Fok , it's amazing how they've picked up cases of phishing, exfiltration of data (outlook rule to forward mail somewhere) , large copy of files , etc.

Is it a a palaver? In some cases, yes , but I can tell you that I am glad IT security ops is something I don't have to do.
 
To get back to the question:
The 3G card probably does a mode-switch when it is plugged in. So you likely have to whitelist 3 VID/PID pairs - the one before the modeswitch, and the 2 after modeswitch (mass storage and modem).
 
For us, a local policy was created, and we cannot save data to a thumb at all. The PC doesn't access it. I am told this is done by the OS itself. So even laptops that are not connected to the network have the same rules. It just doesn't work at all.

But we are temps, so I know that the full-time staff runs something called active directory, and it does stuff that is above my one little braincell.

I would love to learn this stuff, but I am too stupid for it
 
How are you going to prevent people from uploading to the cloud, or even taking pictures of the screen? Disabling USB storage is not going to help you and is only going frustrate users.
Blocking USB is only one security control - it can't solve every problem. It is a valid one for most businesses though - apart from DLP, USB can be a vector for malware.

If you have proper business appropriate file sharing solution like Onedrive or Dropbox for Business IMHO there are very, very few situations where use of USB can't be avoided. Usually you find the person making the most noise about how they can't do without their USB drive is the one that you'll pick up an AV detection for a trojan on their drive full of pirated music and series.
 
Top
Sign up to the MyBroadband newsletter
X