Big Brother Gets Bigger

February 10, 2007 / by anacoana

Big Brother get bigger....
 
C.J. Kelly is a real world Information Security Officer whose identity has been hidden to protect her employer


The technology I am most familiar with is a proxy appliance from BlueCoat.com and recently I heard that the company enhanced the appliance with the ability to decrypt SSL traffic, inspect and filter it against the policy database, re-encrypt it and send it on its way or block it, depending upon whether the traffic passed or failed the policy check.
 
The significance is this - If you are at work and you do your SSL protected online banking or use an SSL protected email program, such as Google's gmail, the security guys administering this type of appliance now have access to your sensitive personal information.  I know you should have no expectation of privacy at work, but most companies allow occasional personal use of email and/or the telephone. It's how we keep our lives running while we are away from them.
 
Someone at some level is Big Brother and that could be the pimply-faced fresh out of college security analyst at your company. I wonder how many companies create policies prior to installing these sophisticated devices - policies about the usage of the device directly aimed at the users of the device - the security analysts. It seems to me that it is a huge responsibility having access to that kind of data.
 
I also understand that the device itself handles the decryption, policy check, re-encryption, and pass or fail functionality, not the analyst. But what I want to understand is, is the information cached or logged anywhere? Or is that also a configurable option? Is the information stored somewhere for later retrieval? How is that information protected? The more we monitor, the more we have to protect the information that is gathered. I'd rather my access to my bank be blocked altogether than worry about someone having access to my accounts.  I talked to a good friend of mine who administers the appliances at his place of employment and he assures me that no information is stored anywhere.  Hmmmm.

Filed under : Security

http://www.computerworld.com/blogs/node/2000?source=quigo2000

http://www.computerworld.com/news/index.jsp

1 comment on Big Brother Gets Bigger

Add a comment

To add comments without entering your email and image verification, you must be logged in. Login or Join Blogster

  • Type the words in the box below the image.

Email this blog post to a friend

To email posts to friends, you must be logged in. Login or Join Blogster

Friends

View All