I don't understand why people always try to "get around" these restrictions. If there is a legitimate business need, then get it approved. These preventions are put in place for a reason. The more open the network, the more risk. The more risk means more virus, trojans, botnets, data leakage, etc. IT then has to cleanup your mess.
Besides, SSH tunnels won't work on my network. I've got all protocols being intercepted by the proxy (including encrypted). Then an application firewall behind that to make sure the proxy is doing it's job. Social networking is blocked. End of story. And yes, management backs me.
Want to screw off at work? Get an smartphone and do it on your own device. Get a netbook with an aircard. I don't give a fsck what you do at work. It's not my job to make sure you're spending your time wisely. However, it is my job to protect our computers/network and I do that by blocking "risky" sites.