Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

surebet posted:

actual anti-secfuck content: is there a npt bad combination of password managers and ad blockers?

apart from the lack of backups (which is being resolved today) the two largest issues i found are passwords under the keyboard/in my_passwords.txt and the occasional malware infection from fake flash update pop-ups

i used to use lastpass but this thread showed me it's now bad, what's the new good one?

i also personally use ublock, what kind of horror stories are there about rolling this out in an office environment?
1password for personal use, secret server for the office

ublock origin is the adblocker you should use. do not use ublock. you can add disconnect, which is kinda like ghostery but not owned by an ad agency. i think there's another one people like too

Adbot
ADBOT LOVES YOU

negromancer
Aug 20, 2014

by FactsAreUseless

pr0zac posted:

having a cissp or oscp is not an indicator of a good security person any more than a college degree is, esp not in the area of infosec I'm trying to hire for

course I might just be saying that cause I have neither and my college GPA was 2.6

I have both of those certs, because
a) I'm black, so I have to.
b) My years of work experience in IT aren't representative of my actual time doing computer touching in life
c) I'm black, your HR hurdles are my HR mountains.
d) My college degree is an asociates in Nursing
e) I didn't pay for any of my 6 certifications, so...why not get them on the company dime if its low-effort and poo poo you're already doing anyways?

graph
Nov 22, 2006

aaag peanuts

Volmarias posted:

Aren't we all!

:makes jerking off motions: eventually!

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
I keep reading TV as television and imagine this is what the future internet of things will be like

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
i thought people only used teamviewer when beiung tech-support scammed, learn something new every day

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

pr0zac posted:

having a cissp or oscp is not an indicator of a good security person any more than a college degree is, esp not in the area of infosec I'm trying to hire for

course I might just be saying that cause I have neither and my college GPA was 2.6

oh 2.6? you fancy, huh?

surebet
Jan 10, 2013

avatar
specialist


anthonypants posted:

1password for personal use, secret server for the office

ublock origin is the adblocker you should use. do not use ublock. you can add disconnect, which is kinda like ghostery but not owned by an ad agency. i think there's another one people like too

didn't know there was a ublock & a ublock origin, i'm using origin. guess i'll roll that out

re: secret server, i'll have a look, seems nice. i've been considering a smart card approach since we're also shopping for a physical access control system, what kind of hell am i inviting in my life regarding lost credentials?

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
also there's a weird part of me that wants to get my CISSP for funzies. this is a bad idea right? (see above gpa joke)

spankmeister
Jun 15, 2008






anthonypants posted:

i think there's another one people like too

privacy badger, which is backed by the EFF so that counts for something imo

i use disconnect tho because it works and i hadn't heard of pb before switching from ghostery to disconenct

apseudonym
Feb 25, 2011

I completely ignore certifications when reading resumes, who cares?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

surebet posted:

didn't know there was a ublock & a ublock origin, i'm using origin. guess i'll roll that out

re: secret server, i'll have a look, seems nice. i've been considering a smart card approach since we're also shopping for a physical access control system, what kind of hell am i inviting in my life regarding lost credentials?

if you're doing physical credentials right, losing them should be no problem - report lost, revoke credential, issue new card

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


apseudonym posted:

I completely ignore certifications when reading resumes, who cares?

i ignore anything that i do not recognise and have myself because obviously if i dont have a cert, its not worth having

actually i don't but i guarantee this logic is used irl

pr0zac
Jan 18, 2004

~*lukecagefan69*~


Pillbug

gfsincere posted:

I have both of those certs, because
a) I'm black, so I have to.
b) My years of work experience in IT aren't representative of my actual time doing computer touching in life
c) I'm black, your HR hurdles are my HR mountains.
d) My college degree is an asociates in Nursing
e) I didn't pay for any of my 6 certifications, so...why not get them on the company dime if its low-effort and poo poo you're already doing anyways?

oh yeah, i'm not saying having them is a BAD thing by any means, just they aren't a strong indicator of good in my experience

not being a cis white male actually is though since if you're not and are still willing to put up with the biased bullshit in this industry you probably give enough of a drat about it to do well

negromancer
Aug 20, 2014

by FactsAreUseless

surebet posted:

didn't know there was a ublock & a ublock origin, i'm using origin. guess i'll roll that out

re: secret server, i'll have a look, seems nice. i've been considering a smart card approach since we're also shopping for a physical access control system, what kind of hell am i inviting in my life regarding lost credentials?

I'd get it just to say you had it and you can (to HR) make wildly unreasonable salary demands and they will actually sound reasonable to them.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

apseudonym posted:

I completely ignore certifications when reading resumes, who cares?

HR robots who cannot read and evaluate resumes without buzzwords do. The actual interviewers won't.

graph
Nov 22, 2006

aaag peanuts
hr does not read any resumes and hasnt for more than a decade and a half

hr puts the resume onto a scanner that scans them in to a program like resumix which groups them by buzzwords

flakeloaf
Feb 26, 2003

Still better than android clock

it seems the only applicant we got was a resume with this weird computer code gobbledygook at the top, all the other applications are blank oh well

negromancer
Aug 20, 2014

by FactsAreUseless

pr0zac posted:

oh yeah, i'm not saying having them is a BAD thing by any means, just they aren't a strong indicator of good in my experience

not being a cis white male actually is though since if you're not and are still willing to put up with the biased bullshit in this industry you probably give enough of a drat about it to do well

Oh man, there's so many paper tigers out there. I've met so many CISSPs (pretty much exclusively Indian) that didn't know the very basics of IT. As in I was in an advanced training class for Qualys (job-mandated) and I poo poo you not a dude from India with a masters in Information Security (from New Delhi Basement University I'm sure) legit raised his hand and asked what subnetting was. The rest of the Indians in the class were also wondering, meanwhile literally everyone else in the class was dumbfounded, because HOW.

HOW.

And this guy was a CISO somewhere. I wish I would have gotten his card so I could have emailed his job like "Bro. This guy is awful."

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
when i worked at $av_vendor, i had a customer i worked with frequently who'd send me screenshots sent via his iphone. now if this were some sort of airgapped network i wouldn't have had given much thought to this as this was not uncommon in situations where clearance was a non-issue (and me being a foreign national, etc), but this was a university computer and dameware was installed according to the icons in the systray

the guy also was a 5-year cissp

to make matters funnier, i ended up working with him as a consultant at another company and he was what i expected

nice person but i think he didn't know how to take a screenshot at all

negromancer
Aug 20, 2014

by FactsAreUseless

OSI bean dip posted:

when i worked at $av_vendor, i had a customer i worked with frequently who'd send me screenshots sent via his iphone. now if this were some sort of airgapped network i wouldn't have had given much thought to this as this was not uncommon in situations where clearance was a non-issue (and me being a foreign national, etc), but this was a university computer and dameware was installed according to the icons in the systray

the guy also was a 5-year cissp

to make matters funnier, i ended up working with him as a consultant at another company and he was what i expected

nice person but i think he didn't know how to take a screenshot at all

They are usually always nice people, but they usually don't know poo poo about poo poo, including the stuff they have certs in. Cheating is SUPER rampant in India, so I pretty much consider any cert gained while in India fraudulent until proven otherwise.

Wiggly Wayne DDS
Sep 11, 2010



owasp are accepting data to build the top ten web vulns for 2016 https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

gfsincere posted:

They are usually always nice people, but they usually don't know poo poo about poo poo, including the stuff they have certs in. Cheating is SUPER rampant in India, so I pretty much consider any cert gained while in India fraudulent until proven otherwise.

http://attrition.org/errata/charlatan/ankit_fadia/

this guy takes the cake

flakeloaf
Feb 26, 2003

Still better than android clock

but not the plastic off his laptop, what the hell

Shame Boy
Mar 2, 2010

is there a free practice test or something for cissp, because I'd like to try my hand at it since I get the feeling I can answer 80% of the questions already but I'm not actually looking to get one right now so I don't want to pay for the ~official materials~ or whatever

Shame Boy
Mar 2, 2010

or i could just google "cissp practice test" and pick the first result like a big boy

Wiggly Wayne DDS
Sep 11, 2010



things cissp can't cover: https://samvartaka.github.io/exploitation/2016/06/03/dead-rats-exploiting-malware

Winkle-Daddy
Mar 10, 2007

haha, holy poo poo, this guy http://attrition.org/errata/charlatan/ankit_fadia/fadia13.html

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
Stop watching porn, dude! Start your browser, connect to www.cooltunnel.com and then use it to connect to your favorite blocked websites. Works most of the time!

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

rape accusations at Tor :(

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost

gfsincere posted:

Because if so, I might be selling myself short.
most of us are in the simultaneous condition of being overpaid while also selling themselves short

thats the weird thing about cs really

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Captain Foo posted:

rape accusations at Tor :(
buh bye ioerror

Sharktopus
Aug 9, 2006

Captain Foo posted:

rape accusations at Tor :(

details?

is this some bs like the assange stuff or a real accusation from a non us-govt payroll person?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

details?

is this some bs like the assange stuff or a real accusation from a non us-govt payroll person?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

details?

is this some bs like the assange stuff or a real accusation from a non us-govt payroll person?

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Sharktopus posted:

details?

is this some bs like the assange stuff or a real accusation from a non us-govt payroll person?

aardvaard
Mar 4, 2013

you belong in the bog of eternal stench

Sharktopus posted:

details?

is this some bs like the assange stuff or a real accusation from a non us-govt payroll person?

what was bs about the allegations against assange?

Sharktopus
Aug 9, 2006

and they dont care if he's out raping they just dont want him part of the tor organization? or is this a dont talk to cops thing? would germany even extradite him for a trial in the US?

Sharktopus
Aug 9, 2006

also thanks for linking I dont particularly care for ioerror and am not defending him here, this already smells more legit than the assange stuff ever did

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


we use a lot of offshore resources provided by firms in india for some bullshit accounting reason and whenever we get a good person they always leave because they know it and just junp ship to some other company

then we get given a replacement that is without fail someone whose experience is 100% the firms own training courses and is poo poo

they quite literally use us to train their staff, i just refuse to let them work on my stuff as they are without fail an actual negative

Adbot
ADBOT LOVES YOU

Sharktopus
Aug 9, 2006

Powerful Two-Hander posted:

they quite literally use us to train their staff, i just refuse to let them work on my stuff as they are without fail an actual negative

lol that some CFO thinks he's adding to the bottom line by doing all this

  • Locked thread