This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Application control - poor decisions

Well I've not been back here for a while but it's time for another post and this time I'd like feedback from you guys about a decision Sophos has made regarding app control.

We use app control extensively and I block most things not related to our business by default (games, peer to peer etc). One noteable change recently was for Sophos to now add a Firefox V7 and higher policy option. Now while I fully understand the reason for this because of the mindless version updates vomiting out of the Mozilla labs at the moment, I don't understand why they don't pick off the major version numbers and especially, the ability to block beta versions. I've about 20% of users at  my organization that use Firefox and of those, about a third watch the firefox website like hawks always wanting the latest, greatest version even if it's not tested and released. Previously, by allowing specific versions and blocking everything else, I had the ability to lock down to only released versions and I also had the ability to lockout old defunct versions that were either to vulnerable or really not fit for purpose (v7 immediately springs to mind!). Now, my users are freely downloading v9 beta, installing it, using it and I have absolutely no control over that with Sophos because they've adopted a v7+ identity only. How bad is that!

I'd like to get some feedback on whether you feel this is the right approach or not. As administrators, we know that the FF version change every 30 days is a big problem and I know there will be a few people out there that don't really care that users can get to higher versions even untested betas and alphas but I and many others do. How does the community feel about this approach?

 Should we at the very least still continue to get individual version control? Should we have the v7+ AND the individual version control?

Matt

:19333


This thread was automatically locked due to age.
Parents
  • Hi Dan,

    You're missing the point though. By only creating a single identity, you've killed the effectiveness of the system. I had control over versions previously and now I don't. I had the ability to say that users could ONLY run the approved versions this prevented them from downloading and installing anything not approved. Now, they are free to fetch any version 7+ and higher including betas, alphas, unreleased submissions to the project etc. and run without any argument from Sophos. That's the killer! I'm quite happy if you create an 'unknown' versions (i.e. a versions not yet released) identity for those that want to give users this ability and you can update that as rapidly as you like once released (including removing FF versions when released from this identity) but give me back the individual versions - even if it does take a month to release - I'm sure you could produce one NOW for v.9 (the projects been running several weeks already) and release in the next apps update similarly, there's nothing stopping you from producing a v7 and v8 identity and releasing so I can kill off v7, allow v8 and be prepared for v9 once it's stable and released - looks like v9.01 might be stable enough. 9.0beta looks like it's a dog.

    Matt

    :19559
Reply
  • Hi Dan,

    You're missing the point though. By only creating a single identity, you've killed the effectiveness of the system. I had control over versions previously and now I don't. I had the ability to say that users could ONLY run the approved versions this prevented them from downloading and installing anything not approved. Now, they are free to fetch any version 7+ and higher including betas, alphas, unreleased submissions to the project etc. and run without any argument from Sophos. That's the killer! I'm quite happy if you create an 'unknown' versions (i.e. a versions not yet released) identity for those that want to give users this ability and you can update that as rapidly as you like once released (including removing FF versions when released from this identity) but give me back the individual versions - even if it does take a month to release - I'm sure you could produce one NOW for v.9 (the projects been running several weeks already) and release in the next apps update similarly, there's nothing stopping you from producing a v7 and v8 identity and releasing so I can kill off v7, allow v8 and be prepared for v9 once it's stable and released - looks like v9.01 might be stable enough. 9.0beta looks like it's a dog.

    Matt

    :19559
Children
No Data