Serious Discussion [Extension] Symantec browser protection(Symantec intelligence)

g the security measures in enterprise sector.
I understand that, but during installation, they should have users set up a password to protect the extension from being tampered with, ensuring both parties are satisfied. This would be a very simple fix to keep everyone happy.
 
  • Like
Reactions: Khushal
I understand that, but during installation, they should have users set up a password to protect the extension from being tampered with, ensuring both parties are satisfied. This would be a very simple fix to keep everyone happy.
They have fears the empolyee with password could be ignorant enought to use its password to get authority to except some dangerous websited from being blocked by the extension, keeping the exclusion exclusively for IT persons.
 
  • Like
Reactions: Khushal
They have fears the empolyee with password could be ignorant enought to use its password to get authority to except some dangerous websited from being blocked by the extension, keeping the exclusion exclusively for IT persons.
If a password falls into the hands of someone who shouldn’t have access to it, that ultimately comes down to the responsibility of the IT person or whoever is managing the systems not necessarily the security product itself. If someone leaks sensitive information or intentionally exposes it, that is a user or process error rather than a flaw in the product. I understand why they may have concerns or doubts about handling it a specific way, but security isn’t the only consideration. Product usability is just as important. A security solution can be extremely secure, but if it’s overly complicated or difficult for people to use correctly, that can create its own security risks. Like a false positive blocking a medical site or mychart health information that a person may need to acess becaouse of a health releated concern.
 
  • Like
Reactions: Khushal
If a password falls into the hands of someone who shouldn’t have access to it, that ultimately comes down to the responsibility of the IT person or whoever is managing the systems not necessarily the security product itself. If someone leaks sensitive information or intentionally exposes it, that is a user or process error rather than a flaw in the product. I understand why they may have concerns or doubts about handling it a specific way, but security isn’t the only consideration. Product usability is just as important. A security solution can be extremely secure, but if it’s overly complicated or difficult for people to use correctly, that can create its own security risks.
You did not get it.
The password offered by IT dep to the right employee.
The empolyee want to watch p..., so he is going to except the blocked site.
Then the empolyee clicks on malvertisement, redirecting to phishing page, and then goodbye.
They are trying protecting empolyee, not IT persons, from their dark desires consequences.
 
  • Like
Reactions: Khushal
You did not get it.
The password offered by IT dep to the right employee.
The empolyee want to watch p..., so he is going to except the blocked site.
Then the empolyee clicks on malvertisement, redirecting to phishing page, and then goodbye.
They are trying protecting empolyee, not IT persons, from their dark desires consequences.
An IT professional should not provide a password to a regular employee to bypass a website restriction, regardless of the circumstances. If an employee needs access to a blocked site, IT should first verify that the website is legitimate, safe, and appropriate before allowing access or making an exception. I get what you're saying, but there are safeguards in place to prevent these kinds of things from happening.
 
An IT professional should not provide a password to a regular employee to bypass a website restriction, regardless of the circumstances. If an employee needs access to a blocked site, IT should first verify that the website is legitimate, safe, and appropriate before allowing access or making an exception. I get what you're saying, but there are safeguards in place to prevent these kinds of things from happening.
Exactly.
So with current absence of exceptions in Symantec extension, the empolyee cannot bypass the security layer and except any websites.
So lack of exceptions comply with the function of the product, inspite of not being welcome by home users, as us, which is not designed to be used by.