Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Wow, someone is angry, or is this what everyone was talking about before?

I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Adbot
ADBOT LOVES YOU

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD
yes

Thanks Ants
May 21, 2004

#essereFerrari


Yeah someone in the infosec thread got a bit sensitive about something.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE


:gary:Lol, I'm butthurt, gonna go spend 50bux to show those fuckers that I'm mad about them calling me a jerk.


(this was clearly what infosec crybaby was thinking)

MF_James fucked around with this message at 00:22 on May 6, 2016

Segmentation Fault
Jun 7, 2012
honestly this is the funniest thing to happen to the thread since the last update from Larches' old job

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

bleh shouldn't do this

This kind of made my day :)


*edit* Also, someone in IRC just brought up that according to offical SA rules, we just won the internet

MF_James fucked around with this message at 00:38 on May 6, 2016

Thanks Ants
May 21, 2004

#essereFerrari


As Goons, we are all far from winners.

Proteus Jones
Feb 28, 2013



online friend posted:

goondolences


i'm still not entirely sold on the concept of BYOD from a security standpoint, so if it were up to me that's exactly how it'd be. i'd rather have an asset that i can control than one that is only in the office from Monday-Friday from 9AM to 5PM, but that's just me, and i am by no means saying that i'm an expert on the subject.

You can save users from their own stupidity only so much.

We have a BYOD policy, *but* you have to agree to have policy applied (mostly password and remote-wipe enforcement) if you connect to our email, you can't connect to resources that aren't cloud based, and even then you need a cert installed to access them.

Plus you get your own special-snowflake VLAN, WLAN and BSSID on the APs that's ACL'd away from anything internal. Oh, and you also have your own gateway that's separate from corporate's and has lower bandwidth and a shittier SLA than our corporate network links.

It is useful for the person who wants to access email, calendar, and contacts on his own phone or tablet. And we do reimburse a percentage of the monthly bill. But at the same time the end user acknowledges that IT don't support their poo poo, and if their device causes problems it will be blacklisted faster than they can blink. And not get un-listed, not even if you're an SVP. No one can cry ignorance, since all the security policies are online and some of the more important ones are even broken down into simple explanatory documents. We have online training resources available as well. Howls of "I didn't know" are cast into the void, as they get, at the least, a written reprimand in their employee record (which is fairly serious and involves probation).

It mostly works out, and you get the occasional complaint from the new guy, but overall both IT and real people are OK with it.

Proud Christian Mom
Dec 20, 2006
READING COMPREHENSION IS HARD
yeah byod works if youve got the infrastructure in place to treat that poo poo like a leper and enough c-level backbone to make it stick. otherwise you're just asking for a giant bag of problems

Migishu
Oct 22, 2005

I'll eat your fucking eyeballs if you're not careful

Grimey Drawer

Colorfinger posted:

So I noticed you guys liked the VOD of us performing this so I recorded it properly (without me making a bunch of mistakes in the piano) and then I got real ambitious and made a lyric video, here it is

https://www.youtube.com/watch?v=yqjpJtL5D-k

Also probably doing another show on Saturday (5/7) around 5PMish, so come along and hang out with us if you like :)

http://www.twitch.tv/sacolorfinger

Since it was hit at the bottom of last page.

This is amazing and everyone should watch.

Thanks Ants
May 21, 2004

#essereFerrari


go3 posted:

yeah byod works if youve got the infrastructure in place to treat that poo poo like a leper and enough c-level backbone to make it stick. otherwise you're just asking for a giant bag of problems

I think in the least you can save yourself a gently caress load of hassle by asking these sorts of questions before accepting a job offer if it's going to be your responsibility. I have worked in a place where IT weren't allowed to push back on things and it was horrific, and having someone decent heading up your department makes a huge difference. If your representative to the rest of the company is a grumpy sarcastic prick then your life will become a hell of cloud services that you didn't know about and problems that go on for months without being reported.

Edit: Also what Migishu said.

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



I bet the goon who did this really loves checkboxes and marking off his lists during audits where he can get them wiley users and IT people.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Virigoth posted:

I bet the goon who did this really loves checkboxes and marking off his lists during audits where he can get them wiley users and IT people.

Nah probably loves when machines need to be re-images because "LOLZ DUMB USER GOT CRYPTO ON THERI MACHINE AND WIPED THEIR OWN FILEZA"

Not realizing that having to re-image machines constantly causes OTHER people work, but he can sit and :smuggo: because he doesn't have extra work to do.

alright I'm done poo poo talking :)

SyNack Sassimov
May 4, 2006

Let the robot win.
            --Captain James T. Vader


what the gently caress did I miss :psyduck:

uPen
Jan 25, 2010

Zu Rodina!
But what's the best anti-virus software?

Kinetica
Aug 16, 2011
We need it for our accreditation but I'll just tell the guys who do it that it's bad and we don't need it- I'm sure that will be fine with them

Moatman
Mar 21, 2014

Because the goof is all mine.

uPen posted:

But what's the best anti-virus software?

The friendships we made along the way

Paul MaudDib
May 3, 2006

TEAM NVIDIA:
FORUM POLICE

Potato Alley posted:

what the gently caress did I miss :psyduck:

yosposers who are salty about internet pixels, if you can believe it

'twasn't I who did the deed, but damned if I'm not lol'ing at how poorly they take their own medicine :laugh:

Paul MaudDib fucked around with this message at 01:14 on May 6, 2016

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

uPen posted:

But what's the best anti-virus software?

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

MF_James posted:

Nah probably loves when machines need to be re-images because "LOLZ DUMB USER GOT CRYPTO ON THERI MACHINE AND WIPED THEIR OWN FILEZA"

Not realizing that having to re-image machines constantly causes OTHER people work, but he can sit and :smuggo: because he doesn't have extra work to do.

alright I'm done poo poo talking :)

you actually seem more angry about the this than the person who gave you the av

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Paul MaudDib posted:

yosposers who are salty about internet pixels, if you can believe it

'twasn't I who did the deed, but damned if I'm not lol'ing at how poorly they take their own medicine :laugh:

you said a lot of dumb poo poo and then someone gave you an av that tells other people how much you love to say dumb poo poo

seems reasonable imo

Thanks Ants
May 21, 2004

#essereFerrari


Maybe we can stop trying to say how much we don't care that someone gifted us the red text and move on from this dumb derail.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

jre posted:

Using anti virus has become more of a compliance thing than actually improving the security of your network.

This should be quoted so many times that the button becomes a useless, flaming wreckage of what once was a useful function of posting.

It's only purpose is to catch the lowest hanging fruit imaginable.

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin
Anti-virus is 99% useless, but for that 1%, its worth it.

You install it for compliance these days, that's about all.

Thanks Ants
May 21, 2004

#essereFerrari


I think there's an element of CYA about it as well. If you compile a bunch of papers to show how AV is no help in terms of security, fight the auditors and prove that you have other ways of mitigating the sorts of attacks that AV is advertised as protecting you from, and then get Crypto'd, you're going be in a pretty vulnerable position.

Edit: I guess CYA and compliance are actually pretty similar. Or at least you can use 'we are compliant with x and these auditors say so' as part of a CYA strategy if required.

Thanks Ants fucked around with this message at 02:07 on May 6, 2016

Baxta
Feb 18, 2004

Needs More Pirate
First of all i'm pissed I didn't get red text.

Second, ESET has a "Track my device" function for when poo poo goes missing that I like.

Thanks Ants
May 21, 2004

#essereFerrari


Every AV is adding random poo poo on though to try and gain one over the competition. If you need to manage your endpoints then use MDM on them or something designed for anti-theft which (I assume?) doesn't have the same exploitable low-level OS hooks in it. In the Apple world you can use DEP which is straight up awesome.

Had a client running Sophos Endpoint Protection which comes with a firewall element and it just flat out stopped people doing anything on the Internet, and their support were less than useless at handling it.

Wiggly
Aug 26, 2000

Number one on the ice, number one in my heart
Fun Shoe

Thanks Ants posted:

They're pretty secretive about it on the website, but they do say you just change your DNS records. Does this gently caress things up for clients that are in the office needing to access internal resources since they don't get the internal DNS servers any more, or is there an agent that deals with swapping the servers out?

Your internal DNS servers still work normally but you put the OpenDNS servers as forwarders on them so they talk to OpenDNS for external queries and will drop or block any requests to sites that are blacklisted.

Baxta
Feb 18, 2004

Needs More Pirate

Thanks Ants posted:

Every AV is adding random poo poo on though to try and gain one over the competition. If you need to manage your endpoints then use MDM on them or something designed for anti-theft which (I assume?) doesn't have the same exploitable low-level OS hooks in it. In the Apple world you can use DEP which is straight up awesome.

Had a client running Sophos Endpoint Protection which comes with a firewall element and it just flat out stopped people doing anything on the Internet, and their support were less than useless at handling it.

Yeah the key things to remember when tasked with choosing AV for a business are:

1. It won't stop poo poo. Sort your firewall out properly and educate users.
2. Make sure your backup solution is solid.
3. Make sure whatever bandaid you buy doesn't open more security holes.
4. Try to get one that doesn't use too many system resources and is easily administered.

EDIT: My new fortinet is spazzing out over false positives such as gmails tracking bullshit eg: http://secure-au.imrworldwide.com/cgi-bin/cfg so yeah nothing is going to be set and forget.

Thanks Ants
May 21, 2004

#essereFerrari


Wiggly posted:

Your internal DNS servers still work normally but you put the OpenDNS servers as forwarders on them so they talk to OpenDNS for external queries and will drop or block any requests to sites that are blacklisted.
No sorry, I got that bit. I mean where it talks about how it can protect people when they take laptops out the office - presumably it needs to manually set the DNS servers when that device leaves the corporate network? I was wondering how seamless that part is. I don't need people connecting to hotspots and having the redirect to the captive portal failing etc.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Wrath of the Bitch King posted:

This should be quoted so many times that the button becomes a useless, flaming wreckage of what once was a useful function of posting.

It's only purpose is to catch the lowest hanging fruit imaginable.
You'd think people could wrap this around their head, but then they still want the best antivirus with the best heuristics and the best reviews and the best memory/cpu footprint, and they will link at all sorts of reviews and parrot numbers they don't understand to defend their choice. But if the best reason for antivirus is to fill in an auditor's checkbox or to catch the lowest of the low-hanging fruit, then all of those metrics are completely meaningless, and you should instead go with the least bad antivirus.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

online friend posted:

you actually seem more angry about the this than the person who gave you the av

Not mad just amused.

for actual content: Today I raged for like 15 minutes trying to sort out a permissions issue, the user I am using to run a scheduled task has full control to the folder structure, but keeps failing to move a file. I forgot to put the directory to work from in the "start (in)" aka the working directory, felt dumb :(

KoRMaK
Jul 31, 2012



Im not on helpdesk, but here's what I do to secure myself

1) Use chrome
2) install ublock origin
3) disable all plugins and require a user click to enable
4) gently caress the intenret without a condom cuz I can tell which ones is nasty


Clean bill of health so far. Most of the malware I used to get was from lovely plugin exploits (flash, acrobat), so without the ads and the click to run I'm pretty good. Thats just my two cents, not saying its what everyone should do or that its right.

Paul MaudDib
May 3, 2006

TEAM NVIDIA:
FORUM POLICE

Thanks Ants posted:

Every AV is adding random poo poo on though to try and gain one over the competition. If you need to manage your endpoints then use MDM on them or something designed for anti-theft which (I assume?) doesn't have the same exploitable low-level OS hooks in it. In the Apple world you can use DEP which is straight up awesome.

Had a client running Sophos Endpoint Protection which comes with a firewall element and it just flat out stopped people doing anything on the Internet, and their support were less than useless at handling it.

If you're concerned about the threat posed by AV then you should forget about anti-theft software, stuff like LoJack can actually live in the BIOS image and drops an executable that is automatically copied on startup (if removed) and run with system-admin privileges by Windows installations. The mechanism is called the Windows Platform Binary Table. I'm sure you can imagine like a half-dozen practical exploits for any vulnerability in that executable. The host file in particular is probably super vulnerable.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Paul MaudDib posted:

If you're concerned about the threat posed by AV then you should forget about anti-theft software, stuff like LoJack can actually live in the BIOS image and drops an executable that is automatically copied on startup (if removed) and run with system-admin privileges by Windows installations. The mechanism is called the Windows Platform Binary Table. I'm sure you can imagine like a half-dozen practical exploits for any vulnerability in that executable. The host file in particular is probably super vulnerable.
Uh, yeah, that's called a rootkit?

Thanks Ants
May 21, 2004

#essereFerrari


Yeah it's the same method that Lenovo (and possibly Dell, not sure) used to make little helper apps persistent across OS re-images. Standard MDM that hooks into the OS APIs shouldn't do that. And yes you lose the ability to track the device down if it's stolen and wiped but to be honest that's what insurance is for. You only need to be concerned about ensuring the data isn't readable.

Thanks Ants fucked around with this message at 02:37 on May 6, 2016

Baxta
Feb 18, 2004

Needs More Pirate

Paul MaudDib posted:

If you're concerned about the threat posed by AV then you should forget about anti-theft software, stuff like LoJack can actually live in the BIOS image and drops an executable that is automatically copied on startup (if removed) and run with system-admin privileges by Windows installations. The mechanism is called the Windows Platform Binary Table. I'm sure you can imagine like a half-dozen practical exploits for any vulnerability in that executable. The host file in particular is probably super vulnerable.

Thats not how the ESET anti theft stuff works though. It creates a shadow user with limited privileges. A quick CVE search doesn't show any exploits with it yet so linking it with rootkits is a bit simplistic.

3D Megadoodoo
Nov 25, 2010

Data Graham posted:

Curious, what would be better?

CLI

Ren and Stimpire
Oct 28, 2013

Fun Shoe

Thanks man, I am ready to go forth and IT even harder than before.

With paddles.

Adbot
ADBOT LOVES YOU

divabot
Jun 17, 2015

A polite little mouse!

anthonypants posted:

You'd think people could wrap this around their head, but then they still want the best antivirus with the best heuristics and the best reviews and the best memory/cpu footprint, and they will link at all sorts of reviews and parrot numbers they don't understand to defend their choice. But if the best reason for antivirus is to fill in an auditor's checkbox or to catch the lowest of the low-hanging fruit, then all of those metrics are completely meaningless, and you should instead go with the least bad antivirus.

All antivirus are as good as each other at the task of dealing with malware, because all the researchers know each other and talk to each other. And hate marketing. Some are better for some threat this month, next month it'll be another one. (source: used to work at one.)

The important difference is all the crap on top and how much of a PITA it is to administer, so think in terms of that.

  • Locked thread