Forum Discussion
What security threats do you experience the most?
The biggest security threat or vulnerability we are exposed and actually affected by the most are the end users themselves. As a point of clarification I deal exclusively with enterprise line of business devices that are shared. Examples include inventory management devices in warehouses and retail stores, point of sale registers, kiosks, digital signage, etc. The end users leveraging these devices are often the biggest threat that we have to manage. There is a never ending battle to keep these end users off non-productive websites and apps like Youtube, Chrome, etc in order to keep them on task on on their business apps only. This is a constant struggle as these end users have a lot of time on their hands interacting with these devices in order to come up with creative workaround. Think for example a warehouse worker that might be interacting with their device 8-10 hours a day every single week. These users find ways to break out of lockdowns and access websites, apps, and settings that they shouldn't. One of the most frustrating examples is when there is some sort of privacy policy linked within an app that launches out to Chrome, or an in app webview with an editable URL bar. A classic example of this is the stock Calculator app. We provided end users access to this app for legitimate business reasons until we figured out they were accessing the privacy policy which was linking them out to Chrome which led them to get out to the internet. Ironically it was therefore Google itself making our devices more insecure and vulnerable to attack. Why a calculator needs a privacy policy is beyond me.
Either way, I have dealt with countless weekly incidents of end users abusing their devices and working around restrictions. Far far more issues than the ones people seem to pay more attention to. The calls are coming from inside the house, so to speak.
- Emilie_B29 days agoGoogle Community Manager
Thanks for sharing your insights, mattdermody
It was a very interesting read - I was expecting that the end users would be the human error factor but not in the way you mentioned, where they are actively trying to bypass lockdowns to access websites, settings and apps they shouldn’t.
Where do you think they gain this knowledge? How do you manage these incidents?
I enjoyed the urban legend reference, by the way :)