ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ProjectSend

    Scheduled Pinned Locked Moved IT Discussion
    storageprojectsend
    157 Posts 9 Posters 81.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @coliver
      last edited by

      @coliver said:

      So if the user is liable for their own account why are you tracking IP addresses? You just said after you give them the information you are no longer responsible for how they access it.

      Hmm.. I'll have to think on that. Not talking about the law specifically, but why would I want to? To help ensure that only proper access is being used. If there is no reason for someone in Japan to be accessing my systems, yet I see an IP in Japan accessing it, I need to know that.

      coliverC scottalanmillerS 2 Replies Last reply Reply Quote 0
      • coliverC
        coliver @Dashrender
        last edited by

        @Dashrender said:

        @coliver said:

        So if the user is liable for their own account why are you tracking IP addresses? You just said after you give them the information you are no longer responsible for how they access it.

        Hmm.. I'll have to think on that. Not talking about the law specifically, but why would I want to? To help ensure that only proper access is being used. If there is no reason for someone in Japan to be accessing my systems, yet I see an IP in Japan accessing it, I need to know that.

        At that point you would want to look into a intrusion detection system rather then doing it at the application level.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @dafyre
          last edited by

          @dafyre said:

          @scottalanmiller I'd agree with @Dashrender here. If something happens and a user's account is being used from Japan when the live in Texas... that would be information nice to have.

          To whom would you supply that info? And what would you say "Our database that isn't accurate says you should be here but are using an IP address here?"

          Remember they do NOT know that you should be in Texas nor do they know that the IP address is Japan. Those are both presumptions based on information a medical facility would not have.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @Dashrender
            last edited by scottalanmiller

            @Dashrender said:

            Hmm.. I'll have to think on that. Not talking about the law specifically, but why would I want to? To help ensure that only proper access is being used. If there is no reason for someone in Japan to be accessing my systems, yet I see an IP in Japan accessing it, I need to know that.

            No, you certainly do not need to know that.

            dafyreD 1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender
              last edited by

              @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

              But, tracking IPs to show that an IP that is significantly outside the range of those normally used to access your system while possibly a red herring, is still useful as a stepping stone when looking for inappropriate access.

              coliverC scottalanmillerS 3 Replies Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Things you cannot know:

                • That the IP is from Japan
                • That the person is not supposed to be in Japan

                You know neither of these things. How do you want to react with misleading information that makes you assume one thing but doesn't mean that?

                drewlanderD 1 Reply Last reply Reply Quote 0
                • coliverC
                  coliver @Dashrender
                  last edited by coliver

                  @Dashrender said:

                  @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                  But, tracking IPs to show that an IP that is significantly outside the range of those normally used to access your system while possibly a red herring, is still useful as a stepping stone when looking for inappropriate access.

                  This goes beyond the scope of an application like ProjectSend though. This would be more along the line of an IDS.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Dashrender
                    last edited by

                    @Dashrender said:

                    @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                    And as normal, every day end users use international VPNs to access media and content as users from all over the world.

                    And as people travel. If you have my US medical records, would you want to deny them to me when I am traveling or living abroad?

                    DashrenderD dafyreD 2 Replies Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said:

                      But, tracking IPs to show that an IP that is significantly outside the range of those normally used to access your system while possibly a red herring, is still useful as a stepping stone when looking for inappropriate access.

                      How could that be useful? Why would you want to track the "Normal Range" for a user? Are you prepared to disclose to all of your customers that you are doing Google-like tracking of them? As a medical facility, I would never want to hold onto that kind of personal information unless a court order made me do it.

                      J 1 Reply Last reply Reply Quote 1
                      • J
                        Jason Banned @scottalanmiller
                        last edited by

                        @scottalanmiller said:

                        @Dashrender said:

                        But, tracking IPs to show that an IP that is significantly outside the range of those normally used to access your system while possibly a red herring, is still useful as a stepping stone when looking for inappropriate access.

                        How could that be useful? Why would you want to track the "Normal Range" for a user? Are you prepared to disclose to all of your customers that you are doing Google-like tracking of them? As a medical facility, I would never want to hold onto that kind of personal information unless a court order made me do it.

                        You have to do a lot of tracking to determine what is normal. IPs change. People move around a lot. People use Cellular devices. Heck the actual IP address for Celluar devices will often show different states.

                        scottalanmillerS drewlanderD 3 Replies Last reply Reply Quote 2
                        • scottalanmillerS
                          scottalanmiller @Jason
                          last edited by

                          @Jason said:

                          @scottalanmiller said:

                          @Dashrender said:

                          But, tracking IPs to show that an IP that is significantly outside the range of those normally used to access your system while possibly a red herring, is still useful as a stepping stone when looking for inappropriate access.

                          How could that be useful? Why would you want to track the "Normal Range" for a user? Are you prepared to disclose to all of your customers that you are doing Google-like tracking of them? As a medical facility, I would never want to hold onto that kind of personal information unless a court order made me do it.

                          You have to do a lot of tracking to determine what is normal. IPs change. People move around a lot. People use Cellular devices. Heck the actual IP address for Celluar devices will often show different states.

                          Use me as an example. I travel all over the US and around the world. I access from desktops, laptops, cell phones, over VPN connections back to the US, etc. I have no idea how you would ever determine normal for me and attempting to do so would seriously violate my privacy. Only in a way that I implicitly allowed, but it does so all the same. But storing that information and using it to determine patterns about me seems very illegal in a medical context. As any medical in the US is a partial extension of the government (doctors are government agents via certification and not performance workers like normal people in the workforce) this is an extension of the government using my medical needs to track me. I don't like this idea at all. There is no positive use case for it but lots of negatives.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Jason
                            last edited by

                            @Jason said:

                            You have to do a lot of tracking to determine what is normal.

                            And even then, it would constitute opinion.

                            1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said:

                              @Dashrender said:

                              @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                              And as normal, every day end users use international VPNs to access media and content as users from all over the world.

                              And as people travel. If you have my US medical records, would you want to deny them to me when I am traveling or living abroad?

                              LOL, our current EHR company does ban access to their systems from most middle east and chinese based IPs. So yeah, they do deny you. Is it right? who am I to say?

                              scottalanmillerS drewlanderD 2 Replies Last reply Reply Quote 0
                              • dafyreD
                                dafyre @scottalanmiller
                                last edited by dafyre

                                @scottalanmiller said:

                                @Dashrender said:

                                Hmm.. I'll have to think on that. Not talking about the law specifically, but why would I want to? To help ensure that only proper access is being used. If there is no reason for someone in Japan to be accessing my systems, yet I see an IP in Japan accessing it, I need to know that.

                                No, you certainly do not need to know that.

                                I disagree. If I am the one responsible for that server, I want to know everything that is happening. You may not think I need to know it. And you may be right, but it is my system, and I want to know, it so I will have it logged. Period.

                                Edit: The above paragraph is assuming log files from a web server that are generated any way, not any extra logging or analitics is being done with the data aside from identifying country of origin.

                                If somebody's IP address shows up in Japan, and they live 5 miles down the road from the office, I will block that IP address until the user calls me saying "Hey, I can't get to the file website.". I believe in erring on the side of caution.

                                @scottalanmiller said:

                                Things you cannot know:

                                • That the IP is from Japan
                                • That the person is not supposed to be in Japan

                                You know neither of these things. How do you want to react with misleading information that makes you assume one thing but doesn't mean that?

                                I can easily answer the second question. dials phone "Hey, are you in Japan? No? Okay, that's all I need to know. hang up ... block ip

                                scottalanmillerS 2 Replies Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @Dashrender
                                  last edited by

                                  @Dashrender said:

                                  @scottalanmiller said:

                                  @Dashrender said:

                                  @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                                  And as normal, every day end users use international VPNs to access media and content as users from all over the world.

                                  And as people travel. If you have my US medical records, would you want to deny them to me when I am traveling or living abroad?

                                  LOL, our current EHR company does ban access to their systems from most middle east and chinese based IPs. So yeah, they do deny you. Is it right? who am I to say?

                                  Aren't you the ONLY one to say? Who is getting to determine that Americans in those countries are banned?

                                  DashrenderD 1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender @scottalanmiller
                                    last edited by

                                    @scottalanmiller said:

                                    @Dashrender said:

                                    @scottalanmiller said:

                                    @Dashrender said:

                                    @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                                    And as normal, every day end users use international VPNs to access media and content as users from all over the world.

                                    And as people travel. If you have my US medical records, would you want to deny them to me when I am traveling or living abroad?

                                    LOL, our current EHR company does ban access to their systems from most middle east and chinese based IPs. So yeah, they do deny you. Is it right? who am I to say?

                                    Aren't you the ONLY one to say? Who is getting to determine that Americans in those countries are banned?

                                    The vendor is, not us.

                                    1 Reply Last reply Reply Quote 0
                                    • dafyreD
                                      dafyre @scottalanmiller
                                      last edited by

                                      @scottalanmiller said:

                                      @Dashrender said:

                                      @scottalanmiller does have a good point that Geo IP tracking is becoming more fruitless as IP blocks are being bought and sold in areas of the world they were not originally destined to be used, and GEO IP's aren't being updated as frequently as they could be.

                                      And as normal, every day end users use international VPNs to access media and content as users from all over the world.

                                      And as people travel. If you have my US medical records, would you want to deny them to me when I am traveling or living abroad?

                                      That is solved with a simple phone call, and verification. If it is something that you need to have done in an emergency, they would likely be working on you while they are waiting on your medical records (if it were life threatening, for sure!). Granted, I know nothing of medical protocol outside of the US.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @dafyre
                                        last edited by

                                        @dafyre said:

                                        If somebody's IP address shows up in Japan, and they live 5 miles down the road from the office, I will block that IP address until the user calls me saying "Hey, I can't get to the file website.". I believe in erring on the side of caution.

                                        That's very, very bad. That could easily trigger a discrimination lawsuit.

                                        You are not erring on the side of cautious, you are erring on the side of personal control over other people's information. IT should have literally zero say in this. It should be management, legal and customers only. If IT is involved in blocking people from their medical reasons on IT's own opinion that answer is wrong, every time.

                                        dafyreD 1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch
                                          last edited by

                                          As far as I understand the use @Dashrender is implying, this is tracking employee location not clients. Employees should not be randomly logging in from unexpected locations.

                                          This has nothing to do with tracking people traveling.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 1
                                          • scottalanmillerS
                                            scottalanmiller @dafyre
                                            last edited by

                                            @dafyre said:

                                            You know neither of these things. How do you want to react with misleading information that makes you assume one thing but doesn't mean that?

                                            I can easily answer the second question. dials phone "Hey, are you in Japan? No? Okay, that's all I need to know. hang up ... block ip

                                            1. Really? You are going to call anyone and everyone that accesses your systems? You, in IT, are going to start pulling their HIPAA regulated data illegally to do so? This violates HIPAA very clearly. As an IT pro, you don't have a need to see my HIPAA data, which includes my location and phone number. If I get that call, I call a lawyer. This means your systems are bleeding my data and that's very bad.

                                            (Baylor Hospital in Texas did this, they got in huge trouble for selling data.)

                                            dafyreD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 8
                                            • 2 / 8
                                            • First post
                                              Last post