Logging and monitoring can be a form of bullying, and make for lousy infosec
- Reference: 1651496874
- News link: https://www.theregister.co.uk/2022/05/02/surveillance_security_is_bullying/
- Source link:
The flaws of surveillance-based infosec are already appreciated. The European Court of Justice (ECJ) [1]recently found that mass surveillance of the population was an unjustified intrusion into privacy, even when the goal is to combat serious crime. Why, then, do we consider it reasonable to implement invasive surveillance to address the flawed computer systems we choose to use?
Does watching staff 24x7 really make things more secure?
Excessive monitoring is a form of bullying
No, according to Dr Kobi Leins, an honorary research fellow at the Centre for Science and Security Studies, Department of War Studies, King's College, London.
"Surveillance isn't making things more secure. It's reactive, not pro-active, and it's very expensive," Leins says. "Surveillance is mostly used to find a scapegoat after the fact. It's for reinforcing the existing power structures, not creating systemic change."
[2]
Dr Leins argues that the choice to implement surveillance has more to do with the biases of those responsible for the system design than any objective measure of outcomes. "Fear and control doesn't improve productivity, but it is a favored approach of bullies and authoritarians," she says.
[3]
[4]
Lilly Ryan, a penetration tester and security specialist, believes organisations default to surveillance, so had little concern about extending it when remote working became more prevalent during the COVID-19 pandemic, business-managed devices became more common in people's private homes.
"When you take a corporate laptop home, it means you have a camera and a microphone in your private space," Ryan said. "I don't think that people realise just how much people are able to look at," she said. "There's the ability to watch virtually everything."
Unjustified surveillance is risky
Organisations that thoughtlessly decide to add surveillance systems may be creating new risks for themselves, not merely addressing existing risks.
"Staff who become aware of just how much monitoring they are under would have every right – and it would be a reasonable deduction – to consider it excessive monitoring, which is a form of bullying," says Dr Rebecca Michalak, Managing Director of PsychSafe, and a consultant on HR compliance and risk management.
[5]
"In terms of psychological risk management, excessive monitoring is actually a form of bullying, and bullying is a registered psychosocial hazard that you must prevent under Australian safety legislation," she added. "If you're going in and deliberately implementing a system that conducts excessive monitoring, you are deliberately engaging in bullying."
"Basically the organisation is saying to you, in a roundabout way, 'We don't trust you. We don't trust your capability and we don't trust your motivation, so now we're going to bully you on an ongoing basis.' That's how it actually needs to be framed," Dr Michalak said.
That stance, whether stated explicitly or implicitly, sees some people actively resist being surveilled to regain a feeling of autonomy or control. Those who choose to resist can sometimes expend considerable effort to do so, and create new own security risks by doing so.
[6]
"As soon as you implement a surveillance system, even at an organisational level, there's always ways that people can circumvent it," says Dr Monique Mann, senior lecturer in Criminology at Deakin University. "That also perhaps creates greater risks to information security in some regards because people are resisting and not using the approved channels."
Another odd aspect of surveillance-based infosec is that it is often considered as inevitable or unavoidable, a stance that runs counter to the narrative that the information technology and security industries are built on relentless innovation.
"We're living in an era of technological innovation. What's interesting is that we think about innovation from the perspective of advancing technological capabilities, but we don't think about innovation from the perspective of how we implement this safely into our society," says Dr Zena Assaad, senior research fellow at Australian National University's College of Engineering and Computer Science.
"It's making me think that we're shifting the blame and the onus onto people rather than the system. I don't think that we're tackling the issues in a strategic way."
"If you're actually only collecting the bare minimum information, then there are fewer risks from an information security perspective, rather than just surveilling everything," says Dr Mann.
Do this instead
Nicola Nye, chief operating officer at email provider Fastmail, has tried another approach: engineering its systems to safeguard information by default, even from Fastmail's internal support staff.
"To support our customers, we know that our staff will need to have a look at people's support settings all the time, and we don't want to have to audit all of that activity," Nye said. "So we obfuscate everybody's personal data – their mail, their contacts, their calendar entries – it's all turned into lorem ipsum."
We're shifting the blame onto people rather than the system
Staff are still able to do their job, but without getting access to information they don't need. "We've made it easy for our staff to not get hold of this data, and then they can't accidentally or deliberately leak it," says Nye. "We don't have to surveil people because surveilling people is dumb and we have better things to do with our time."
"It's good for them, and it's good for us," she says.
Fastmail's practices suggest it is possible to design and implement IT systems that are secure and respect the inherent dignity of the humans that need to use them. But doing so will require infosec pros and their managers to stop defaulting to easy options like surveillance and consider alternatives.
"The question is really about how do we use these tools in a reasonable and justifiable manner," PsychSafe's Michalak says. "Have you been transparent with people about what is being done and why it's required, and do the people you want to monitor consider it to be reasonable, or excessive?"
"We need to treat our colleagues as colleagues, not subjects or prisoners," says Lily Ryan. "Human dignity needs to factor more into our decisions." ®
Get our [7]Tech Resources
[1] https://curia.europa.eu/juris/document/document.jsf?text=&docid=257242&pageIndex=0&doclang=EN&mode=req&dir=&occ=first&part=1
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YnAAKyoWVcoBBwbE9mKHhQAAAAc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnAAKyoWVcoBBwbE9mKHhQAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnAAKyoWVcoBBwbE9mKHhQAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnAAKyoWVcoBBwbE9mKHhQAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/paasiaas&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnAAKyoWVcoBBwbE9mKHhQAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://whitepapers.theregister.com/
"We need to treat our colleagues as colleagues, not subjects or prisoners," says Lily Ryan. "Human dignity needs to factor more into our decisions."
No. Just no. Most of the userbase here are mouth-breathers who, in days of old, used their CDROM trays to hold their coffee cups. Maybe Ms Ryan works around high-minded, intelligent users, but the users here need a lot more guidance and protection than that.
As to "excessive monitoring", the neat trick is that you don't HAVE to monitor excessively, but you do have to occasionally fuel the mythos that you ARE monitoring excessively. Don't squash those rumors of "I know you can see everything I do", just kind of grunt and nod your head slightly but non-commitally.
As to "bullying" - please. We've got Russians killing innocent people in real life, and these folks are trying to equate keeping our systems (and, by extension, our users) safe with "bullying". Give me a break. What a load of tosh. We're all in IT, most of us were ACTUALLY bullied as kids because we were nerds and bookworms.
"As to "bullying" - please."
There exists more than one form of bullying.
I, personally, was bullied at school for being a socially inept nerd. I have also been bullied at work. The situations look very different, and both can have a very real effect on one's health.
Proving the premise of the article in the second comment, well done!
Surveillance and bullying
This is not a new tendancy.
A few decades ago, when I was a newbie accountant before freeing myself from that morass to become a programmer, I was called upon by an acquaintance to evaluate which accountage package would be interesting for said friend's gym club.
To make a long story short, we went to an official presentation of a well-known accounting package of the time, where we spent over 90 minutes listening to how the application could log down to the keystroke of the employees that were supposed to be working.
That was around Y2K.
I'm glad I'm in programming now, because if you come tell me I'm not hitting the keyboard enough in a given amount of time, I will tell you to fuck right off and do the job in my place if you think you can do better.
Such practices are odious and humiliating and leave no place for intelligent thought - they reduce the human being to a robot that is just supposed to peck the keys sufficiently per minute.
No wonder that beancounters are such soulless individuals - because don't tell me that today's accounting suites are not doing it when they have a million times the resources a PC had back in the day.
Re: Surveillance and bullying
That kind of surveillance can actually backfire rather spectacularly.
One colleague I had in a previous role was generally hailed by management as being the golden boy. He was completing jobs at almost double the rate of the next two high-performers. We couldn't work out how he was doing it.
Until all the jobs he "completed" started coming back for further work. Turns out he wasn't completing them at all, he was just closing them and moving them on. The team was marked on how many jobs were closed, there was no metric for the quality or type of work done. Even after it came to light he wasn't pulled up on it, because after all he was closing a lot of jobs.
The slippery slope to nowhere good or great or worthwhile going ......
Once a system needs to depend upon the truth and/or contrary opinions being hidden deemed a dangerous secret and veiled threat to national security to not be freely shared but censored or monitored and mentored, is that system in inevitable increasingly rapid freefall terminal decline.
Here is a worrying extremely current tale of such a harbinger which you know to be true ....... [1]Panicked CNN Guest Wonders "How We're Going To Control The Channels Of Communications In This Country"
[1] https://www.zerohedge.com/markets/panicked-cnn-guest-wonders-how-were-going-control-channels-communications-country
Big Brother
Surveillance in business was never about security, that was just an excuse.
Surveillance was all about how hard you were working for the company. It was, in part, an enhanced version of the old time clock to track your lunches, coffee breaks, and even bathroom breaks. But it also allows tracking your computer activity, not for security as much as for unproductive time. Are you watching videos? listening to a podcast? Chatting with friends? Taking a nap? Looking for a better job? If you are, management knows (and has a record of it).
Somebody, somewhere, will be caught by surveillance doing something insecure or even nefarious. And then everybody, everywhere, will use it as a justification for continued surveillance.
Re: Big Brother
I agree, that's definitely the mentality of the companies that use it.
Some of the better companies I have worked for take a different attitude. As long as you're getting your work done, don't take the piss and don't do anything unprofessional, they really don't care if you're taking 50 breaks an hour or watching videos while you work. It makes for a fairly relaxed workplace and, amazingly, stuff does actually get done.
Not just for bullying anymore...
Surveillance of any kind in the corporate (and more often, governmental) world is also a beard worn to satisfy, e.g., auditors, banks, insurers, investors, etc. "We did have an incident, but we caught it all on surveillance and were able to share that with the appropriate authorities and experts...[blah-blah-blah]...appropriately minimizing damage and accelerating [whatever]."
It's a bit the institutional equivalent of leaning back with your feet on the desk because "compiling".
Sorted!
Staff are still able to do their job, but without getting access to information they don't need. "We've made it easy for our staff to not get hold of this data, and then they can't accidentally or deliberately leak it,"
So we will be applying the 'Principle of Least Privilege' then. Got it.