ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Teleworking causes serious security threat

Scott Berinato, ZDNN ZDNet US

Published: 20 Nov 2000 09:07 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

In the wake of the hack into Microsoft's network, many security administrators have turned their attention to what some believe is the greatest security challenge facing corporations: teleworkers.

Network administrator at US firm SR Equipment Craig LaHote is struggling with it now, and just a week ago he had a meeting with executives about it. "We're having a hard time controlling it. It's a real grey area with home computers accessing the network and the Internet," he said. "We really have a hard time enforcing policies there. We have a policy but no real way to audit [users] except basically asking them to comply."

The problem is both social and technical, experts say. For one, users on home machines behave differently, even if they're accessing work assets and if policies are in place. They tend to disable security when they can wanting more control over it themselves.

It's a hard-to-define behavioural issue, one expert said. "Technology will solve less than half this problem," said Fred Rica, a partner in the technology risk services practice at US-based PricewaterhouseCoopers. "The other portion is working with people's behaviours, and I'm not sure anyone knows how to do that with telecommuters yet."

On the technical side, the rise of always-on connections such as DSL (digital subscriber line) and cable at home means users will tend to leave connections open more. Without a personal firewall, such a computer is a gaping hole for an enterprise.

Hackers can either access information off the home hard drive or use that computer to find their way back into the corporate network. VPN (virtual private network) connections also allow email messages with dangerous payloads a free ride right into the corporate network.

"A lot of companies are talking to us about this very issue," said Fred Felman, marketing vice president at Zone Labs, based in San Francisco. "People plug into their DSL or cable line and walk right past security. Or they have a VPN set up, and you're creating a secure tunnel for users who might use that tunnel to send a Trojan horse unknowingly. If that telecommuter is out on the Internet on one side and talking to the enterprise on the other side, you have no security. It's really scary to security guys."

At the same time, technologies such as anti-virus software tend to be less rigorously updated, and others, such as encryption, are hardly used at all, even if they're used at work, experts said.

It is enough to keep Jeff Uslan, security administrator at 20th Century Fox, in Los Angeles, from permitting telecommuters to access the Internet through their VPN lines. And that, Uslan said, is difficult to enforce, especially with many executives working from home. "It's caused a lot of arguments from people who just expect Internet access at home," he said. "But I can't control them at home. I won't give them the slightest chance to open that backdoor. My greatest fear is the person screaming at me, 'How could this have happened?"

Pick your firewall: Protect you and your PC from Internet threats with a personal firewall. We've gathered a wide range of top-rated security tools for every kind of Internet user. Many are free!

To have your say online click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
46 out of 104 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment