• 0 Posts
  • 2 Comments
Joined 1 year ago
cake
Cake day: June 6th, 2023

help-circle
  • This is the only reliable solution. To expand:

    1. Provide a Laptop with Windows on it, because that is easier to lockdown.
    2. apply desirable OS lock downs like blocking usb ports prevent storage devices, don’t give the user admin rights, etc.
    3. Setup a VPN server (openvpn should do) and configure the laptop with a VPN client. Configure the client so it blocks network connections that don’t go via the VPN. If you want to give them internet access you’ll need a proxy and firewall and DLP solution. At this point it all gets very complex and expensive.

    The real answer is you are probably screwed without investing a bunch of time, effort, and cost.

    You might get away with more basic security measures if the user has very limited IT knowledge.

    I suggest getting legal advice before you give the user access to your data in the manner you intend.