Hey guys I saw this thread on reddit about someone getting caught using a KVM device on their work laptop and wanted to see what others have to say about the comet pro's risk in this regard. Apparently this guy had changed the EDID. It’s unclear how his IT team found out so am looking for any insight that would be relevant to the GLI/comet pro community before people rely on it to travel and work.
To our more technical folks on the forum who may have an IT/security background, what are best practices to prevent detection beyond the GUI’s EDID settings? What else can be done to minimize chance of detection?
yes bro i was one of them you need to change edid and some specific settings both in GUI and terminal. You also need to isolate the KVM from the network so programs like crowdstrike cant network scan and find. DM me if you have any question
lol annoying IT dude? You do realize that the IT guys arent doing this for fun right? I rather spend my time hunting for other things on the network than a legit user on my network traveling in a different country
There are legal ramifications regarding taxes in certain countries, violating these comes with large fines/penalties from said country if violated. (loss of jobs)
Or it could be based of a contract and clients requirements (sometimes dealing with taxes/country laws above). Some of these contracts are worth millions+ dollars that have stipulations regarding their data is handled within the bounds of the contract. If they contract is violated, that could mean a loss of contracts/jobs for a company (which could also mean MY job)
With the recent North Korean IT workers being discovered this is now another threat to be worried about
You do what you want to do, im just giving you a bit of insight why companies have these policies in place.
I’ll bow out of this convo and let you all have at it
the problem is that your not hunting that. your hunting regular individual and preventing ways for them to live a comfortable lifestyle. Because if the individual has valid documentation proper IP etc and no suspicious activity why are you still digging deeper in the subject if their is no indication they are spoofing location etc. By the way the north korean situation was mainly because of false identities. So if your company let that through what else can you do? Thats your companies fault for not identifying identity properly.
“your hunting regular individual and preventing ways for them to live a comfortable lifestyle.”
Did you miss the whole government and client contract sections in my last post? Or did you just ignore all that because you cant have an adult discussion on how the real world works when it comes to business and government laws? Again a majority of this is something outside of the IT and the decision makers in the companies hands. Are there bosses out there that are jerks? Sure but im trying to explain to you where these decisions are coming from so you understand why they are in place because right now you seem to think its some kind of attack on your livelihood.
Regarding the taxes, in some countries its where the individual is physically sitting and doing the work not what ip address they are coming from OR the country you are sitting in might have some tax ramifications for your company (again outside of your companies control). The company literally has no say when it comes to how a company handles a country does their taxes (or a country has work restrictions).
I will also note that client contracts and data handling also come from country laws and whatnot.
I like legit agree with everything you are saying above espically with the cost of living compared to other countries however the decisions regarding taxes (or clients contracts) dictate these requirements and a company has NO say if they want to do business and well I got bills to pay. So I rather the company keep their contracts/business so I can feed my family
Anyways we could probably go on about this for hours post wise and it sounds like we are just gonna have agree to disagree. Either way anyone who is asking these questions need to understand the ramifications of trying to skirt IT restrictions. I will continue to post this to any future discussions here as its important to understand these things before they go down this road
All I will say is no matter what anyone tells you on here, there are ways to find you (new threat detections are coming out daily) so if you get caught dont come back complaining if you are fired
Thanks, but are you able to offer any insight into the specific identifiers outside of the GUI that should be changed?
I think everyone is aware that using these devices and home VPNs for travel without authorization is rolling the dice. Not trying to rehash the argument about whether people should be attempting to do this for the millionth time on this site lol. Just looking for information to improve the odds for people who want or need to take that risk for whatever reason