This guy was only a “new co-worker” because I was the new employee, but: my first day on a new job I watched a guy get escorted out of the building by security carrying his shit in a cardboard box. His story ended up on the local news. Turned out he was running a prostitution ring from his office, using his work computer even. He had an 800 number that redirected to his office phone, and he kept track of his girls and customers on an Excel spreadsheet on his Windows desktop. The only reason he got caught was that the company upgraded everybody’s computers, and they had techs check through all the old machines to make sure no important documents got deleted, and they found “CallGirls.xls” or something like that right on his desktop. Security through dumbassery.
Even before that, dude didn’t even try to make it look plausibly legitimate so it didn’t invite suspicion for when someone inevitably stumbled on the file.
Dude was definitely never a kid with only shared access to a computer, that’s for sure…
Any mid to large size company has the USB ports of their desktop PCs disabled, disconnected or even glued shut. At least the ones that take security seriously.
I can’t imagine doing my job with a computer like that. I need to be able to plug in scanners and label printers and other specialty equipment and swap out peripherals as they break like how would that even work?
Normally those are pre-approved by IT and you wouldn’t be the one swapping those out. You would put in a request saying hey this item is broken can you please troubleshoot it and somebody would come out troubleshoot it and swap it out as needed.
Then IT needs to be onsite 24/7 and that’s just not realistic for a looot of places. Especially not rural med but I’m in in a hospital in a mid to large size city I’m just in 50 bed or so location that’s in a part of the city nobody GAF about.
Usb devices have addresses that include the vendor and product id. So IT can allow list from approved products or vendors and that will prevent people randomly plugging in devices and infecting the network. Though, it wouldnt stop a malcious device from spoofing an address from a approved device, but an targeted attack needs more sophisticatation security anyway.
I do a lot of work for a hospital system in the intermountain West. They do have rural locations. And they do have IT stuff that is on call 24/7 at every single one of their locations. So it’s not unheard of it’s not unusual it’s pretty normal. I do a good chunk of the work I do for them which is mainly network and systems upgrades as well as Wi-Fi and access points. And I do most of it overnight with one of their IT staff.
As an employee of more years than I care to count, I can safely say the missing component here is “training”. I know this because I am going through that right now (for at least the 20th time in my life).
Why I just leaned that you are NOT supposed to take assets from the company. Amazing knowledge to gain after all these years! They even added that “taking assets” even extends to “taking cash”. Well, I’ll say; I’ve never felt more informed in all my life!
How the heck did I make it this far in life without “knowing” that kind of information? Because everyone knows that employees don’t know anything (or have any morals) until HR tells it to them. /s
This guy was only a “new co-worker” because I was the new employee, but: my first day on a new job I watched a guy get escorted out of the building by security carrying his shit in a cardboard box. His story ended up on the local news. Turned out he was running a prostitution ring from his office, using his work computer even. He had an 800 number that redirected to his office phone, and he kept track of his girls and customers on an Excel spreadsheet on his Windows desktop. The only reason he got caught was that the company upgraded everybody’s computers, and they had techs check through all the old machines to make sure no important documents got deleted, and they found “CallGirls.xls” or something like that right on his desktop. Security through dumbassery.
Stories like this piss me off because they convice me that i would be an absolutely incredible criminal; did this dude not know about usb-sticks?
Even before that, dude didn’t even try to make it look plausibly legitimate so it didn’t invite suspicion for when someone inevitably stumbled on the file.
Dude was definitely never a kid with only shared access to a computer, that’s for sure…
Could have named it GroceryList.xls and would probably still be working there 😂
Or BusinessAssets.xlsxxx /s
Any mid to large size company has the USB ports of their desktop PCs disabled, disconnected or even glued shut. At least the ones that take security seriously.
I can’t imagine doing my job with a computer like that. I need to be able to plug in scanners and label printers and other specialty equipment and swap out peripherals as they break like how would that even work?
Normally those are pre-approved by IT and you wouldn’t be the one swapping those out. You would put in a request saying hey this item is broken can you please troubleshoot it and somebody would come out troubleshoot it and swap it out as needed.
Then IT needs to be onsite 24/7 and that’s just not realistic for a looot of places. Especially not rural med but I’m in in a hospital in a mid to large size city I’m just in 50 bed or so location that’s in a part of the city nobody GAF about.
Usb devices have addresses that include the vendor and product id. So IT can allow list from approved products or vendors and that will prevent people randomly plugging in devices and infecting the network. Though, it wouldnt stop a malcious device from spoofing an address from a approved device, but an targeted attack needs more sophisticatation security anyway.
I do a lot of work for a hospital system in the intermountain West. They do have rural locations. And they do have IT stuff that is on call 24/7 at every single one of their locations. So it’s not unheard of it’s not unusual it’s pretty normal. I do a good chunk of the work I do for them which is mainly network and systems upgrades as well as Wi-Fi and access points. And I do most of it overnight with one of their IT staff.
As an employee of more years than I care to count, I can safely say the missing component here is “training”. I know this because I am going through that right now (for at least the 20th time in my life).
Why I just leaned that you are NOT supposed to take assets from the company. Amazing knowledge to gain after all these years! They even added that “taking assets” even extends to “taking cash”. Well, I’ll say; I’ve never felt more informed in all my life!
How the heck did I make it this far in life without “knowing” that kind of information? Because everyone knows that employees don’t know anything (or have any morals) until HR tells it to them. /s