Hacker News new | ask | show | jobs
by stephengillie 2787 days ago
Is the USGS too small to require firewalls that block obviously NSFW websites? At my workplace, going to such sites bring up a page saying the request was blocked before it left the corporate network.
4 comments

Theres not really any place "too small" for systems like that that I can imagine anyway. we only have 15 people here and we implement filters like that. or in a rough pinch, use one of those free external DNS servers (opendns maybe?) that already have porn filtered out.

The other side Ive seen is "we're all adults, we don't need any filters here" coming from the higher ups. from my experiences, that usually means someone with significant say wants to look at that shit, or more rarely, feels that filters aren't a good use of ITs time.

just CYA on everything in those situations because it usually will end with fingers pointed at IT

USGS is fairly big since they ended up with all the BIE (Bureau of Indian Education) lines. I get the feeling the person who did this doesn't have a problem getting around the firewall / web proxy since they control the thing.
No,you can even do that for your house. Porn is not hard to block.
It is not hard to block in the trivial case; after that you're playing cat & mouse and dealing with false positives.
Not in the trivial case. I meant most porn sites. All you have to do is use a reputation service and block uncategorized sites. Cisco OpenDNS actually offers a free DNS resolver that filters out most porn sites.

Also,surprised at the amount of responses on HN today that presume details....

> use a reputation service and block uncategorized sites

This is what I was thinking of when I said "dealing with false positives"; those services make mistakes, and haven't hit every site.

I don't think anyone aims for perfection but a 90%+ true blocks and less than 5% false would be a high standard.
Ah, the long tail tautology. Everything is easy in the trivial case.
The problem is malware, not the porn.