Comment by lern_too_spel
14 days ago
> But if they don't isolate the network then it's all on them, they do not get to check all devices.
This is a ridiculous point to think that I disagreed about. Of course they don't get to check that your TV and your washing machine have been rooted. I explicitly specified your devices connected to your employer's network. You're trying to interpret this in a way that doesn't make sense simply to find a point of disagreement where there is none.
Ha, now I feel like you're going out of your way to misinterpret me.
"the network" is the same network we've been talking about the entire conversation. Employer's network.
Obviously they can't control what I plug into a network they don't know about, I don't know why you think I was trying to argue that or how it's the strongest interpretation of my comment.
> "the network" is the same network we've been talking about the entire conversation. Employer's network.
That's the same network I'm talking about. I don't know why you think I'm referring to any other network. You are not allowed to connect untrusted devices to many employers' networks, and this works via remote attestation. They don't care if your TV is rooted as long as you don't connect it to their network, but if you do, they will want to make sure it isn't rooted.
> I don't know why you think I'm referring to any other network.
You started talking about my TV and my washing machine, so I thought you were accusing me of bringing in other networks to "find a point of disagreement".
Now I'm just confused why you brought up the idea of attaching them to my employer's network.
> You are not allowed to connect untrusted devices to many employers' networks, and this works via remote attestation. They don't care if your TV is rooted as long as you don't connect it to their network, but if you do, they will want to make sure it isn't rooted.
And that highlighted part is what I take issue with. They should not ask for that. Either allow my devices or ban them. They should never get to look at the attestation report for my devices (literal "my").
2 replies →