TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft security tools questioned for treating employees as threats

79 点作者 Dotnaught9 个月前

7 条评论

Nerada9 个月前
&quot;Employee surveillance&quot; sounds a lot more nefarious than the reality of these systems for most organizations.<p>Your network admin has had access to the proxy, and by extension, all your browsing history since forever. Now, your UEBA does that, but mainly just sits there and flags things like a user normally hitting a single host to suddenly hitting 300 hosts on the network, or a user having an average data upload of 500MB&#x2F;week to 200GB in a single session.<p>Very few people care if you&#x27;re using the corporate network to listen to YouTube Music (or even looking for other jobs), most just want to be notified of data exfiltration, compromised accounts, or malicious network activity.
评论 #41377265 未加载
评论 #41378474 未加载
评论 #41378191 未加载
Animats9 个月前
This sort of thing that makes me miss the classified world.<p>Counterintelligence people definitely view employees as risks. But they&#x27;re not your boss. They work for a different organization entirely. They&#x27;re watching your boss, and your boss&#x27;s boss, too. They only care about threats to national security. If they find other things, they log them, but don&#x27;t tell your management. They have nothing to do with performance evaluation. The three-letter agencies worked out the rules on this stuff decades ago.
评论 #41375399 未加载
dugite-code9 个月前
If you have paid any attention to cyber security... well anything in the last 5-10 years this should be expected?<p>&quot;Insider threats&quot; are typically the one group that any security firm can actually do anything about in an <i>active</i> manner. Every other threat group comes at you, not the other way around.
评论 #41374275 未加载
评论 #41374235 未加载
评论 #41374211 未加载
crvdgc9 个月前
&gt; Both suggest targeting &quot;disgruntled employees&quot; and those with bad performance reviews as potential insider threats – Forcepoint even mentions &quot;internal activists&quot; and those who had a &quot;huge fight with the boss&quot; as risks.<p>&gt; Forcepoint offers to assess whether employees are in financial distress, show &quot;decreased productivity&quot; or plan to leave the job, how they communicate with colleagues and whether they access &quot;obscene&quot; content or exhibit &quot;negative sentiment&quot; in their conversations.<p>This far surpasses the normal surveillance, which is more technical in nature. It&#x27;s trying to combine mind reading and minority report to enforce a Stalinist level of thought control. How much can be delivered in reality remains to be seen, though.
评论 #41375064 未加载
评论 #41378013 未加载
SoftTalker9 个月前
A good way to avoid malicious insiders is to pay well enough that employees won’t risk their jobs by violating the trust placed in them. That said, there’s a place for monitoring like this, to detect compromised accounts or malware activity.
评论 #41407945 未加载
评论 #41375357 未加载
michaelmrose9 个月前
Any test with a very small true positive and even negligible false positive rate risks an unreasonably high number of false positives when applied to a large population. This is especially bad with a squishy non-scientific topic.<p>If you have 50,000 employees and are screening for a risk that is 1 in 1M with a 5% false positive rate you are going to be very disappointed when over the next decade it identifies 25,000 would be shooters when you have zero actual active shooters. Even better you will probably stop disregarding such a test and miss if if it actually happens.<p>As awesome the fact that skynet is always watching will probably cause people to manage their workspace personas to a psychotic degree that will surely ratchet up workspace stress to new highs. Deprived of actual data on what triggers the eye of sauron 100 wrong theories about how to avoid doing so will proliferate and your studied population will both diverge from the norm the system was designed to operate on and become progressively worse.<p>A few years later a study will prove that the AI inadvertently learned to discriminate against minorities, women, or people in other time zones through things the training population did without thinking and the people pushing it will look like bigots. Instead of ejecting we will try to fix it. Either this doesn&#x27;t work or if it does people accuse skynet of being woke.
评论 #41374783 未加载
chris_wot9 个月前
How do they know an employee is in financial distress? Because they company pays them peanuts?
评论 #41378024 未加载