back

by rdl·16y ago·view on hn ↗
Yes, the author of this post clearly has no idea about enterprise/government security policies -- they exist for security and for contractual compliance. He used the example of Manning in Iraq (who was allegedly inside a SCIF, but consciously violated security policy, whether or not you think what he did was right) -- the purpose of all of that is to make sure your honest and trustworthy employees aren't accidentally compromising sensitive information, and to protect from outsiders. You don't body cavity search your own cleared engineers because that is not generally the threat, and it's highly invasive.

There is information protected against willful disclosure by trusted individuals, and that information is kept inside a hardware security module and/or is never accessible to individuals. e.g. nuclear weapons have a "no lone zone" around them, such that if any person (even the commander of the base) is in that space alone, he is presumed to be doing something evil, and is supposed to be stopped (using lethal force if necessary) on sight.

That level of security just isn't warranted for most things, but "work on material in a secure room, and the information doesn't leave the room except by defined channels" is a pretty good level of security. DoD has a lot of security vulnerabilities, but security would not be improved by allowing telecommuting!