Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: Gentoo mailing list <gentoo-user@l.g.o>
Subject: Re: [gentoo-user] {OT} Allow work from home?
Date: Mon, 18 Jan 2016 17:06:23
Message-Id: CAN0CFw0ixp7qd7itUbFuN67NyV4BS8sMyahys9EOzB8z6LE7Lw@mail.gmail.com
In Reply to: Re: [gentoo-user] {OT} Allow work from home? by Rich Freeman
1 >> Suppose you use a VPN connection. How do does the client (employee)
2 >> secure their own network and the machine they're using to work remotely
3 >> then?
4 >
5 > Poorly, most likely. Your data is probably not nearly as important to
6 > them as their data is, and most people don't take great care of their
7 > own data.
8
9
10 This is the same mentality I have.
11
12
13 > As I mentioned in my other post, there might be some exceptions if
14 > you're dealing with highly-skilled IT security employees or something
15 > like that, but most people don't take nearly the level of care with
16 > their clients as you're probably going to want them to.
17
18
19 Generally my employees are not technically inclined.
20
21
22 > It sounds like Grant is concerned enough about his application to
23 > restrict logins to a specific IP (presumably it uses SSL and sign-ons
24 > as well). If you care THAT much about where valid users can connect
25 > from, I don't see why you'd just let them VPN into your LAN running
26 > who-knows-what-rootkit on their workstations.
27 >
28 > If you're truly 100% web-based I'd just go the chromebook route. If
29 > not, I'd issue laptops that you control with full-disk encryption, and
30 > you can then set them up however you need to.
31
32
33 I am 100% web-based. I don't want to administrate machines outside of
34 my LAN so I can imagine a Chromebook would end up vulnerable
35 eventually.
36
37 Someone mentioned 2-factor authentication which sounds interesting.
38 Are there good options for that besides SMS and Google Authenticator
39 (or a similar mobile app)? Is there a good 2FA server in Portage? Is
40 2FA ever defeated in real life without the user's phone?
41
42 - Grant

Replies

Subject Author
Re: [gentoo-user] {OT} Allow work from home? Rich Freeman <rich0@g.o>