Many years ago, when we first released ‘Setiri’ one of the controls that we preached was website white-listing. As talk-back trojans would connect back to arbitrary web servers on the Internet, we argued that companies should create shortlists of the sites employees are allowed to visit. This, we argued, was much more feasible than trying to identify and block known ‘bad’ sites. Of course, there are a number of other compelling reasons for implementing this kind of white-listing, and of course nobody does it (even though I’ve seen fairly good technical implementations of this concept).