Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Potato Salad
Oct 23, 2014

nobody cares



Burning a dumpster full of passwords would be waaaaaay better than volunteering passwords.

Like, take a moment to appreciate that this metaphor is better than reality.

Adbot
ADBOT LOVES YOU

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

Jabor posted:

The general motivation is that the database needs to be continuously synced with other machines, while sharing the keyfile is a one-time thing. So there is a meaningful difference if you're concerned about, say, your password database being leaked by your cloud storage provider.

I thought the keyfile was a poor-man's "thing you have" - keep a 256 byte dump of random bits on a USB stick? Plug it in to unlock, pull it as soon as you're unlocked, etc etc. (I've never used one that way, but that's what I thought of when I saw the option.)

I can see how keeping it away from your butt storage makes some sense as well.

B-Nasty posted:

KeePass for Windows supports the YubiKey in, I think, HOTP mode. It reencrypts the DB using the next code that you then enter the next time you open it.

edit: http://keepass.info/plugins.html#otpkeyprov

Doesn't this require fairy dust to make older copies of your database dissapear? one-time-crypto just isn't something supported by the laws of physics as we know them.

Three-Phase
Aug 5, 2006

by zen death robot
So this Turkish group is threatening to wipe a couple hundred million Apple devices unless they get... $75000?

https://forums.macrumors.com/threads/hackers-claim-access-to-300-million-icloud-accounts-say-apple-refused-to-pay-75-000-ransom.2038152/

What's your take on this? Fake or real?

I would be super surprised if Apple's database of credentials was stolen in plaintext or passwords that were hashed without salt. Now I could see data from other breaches like email addresses and passwords being combined. Many of them would work but many (people not reusing passwords) would not.

Three-Phase fucked around with this message at 03:54 on Mar 23, 2017

astral
Apr 26, 2004

Three-Phase posted:

So this Turkish group is threatening to wipe a couple hundred million Apple devices unless they get... $75000?

https://forums.macrumors.com/threads/hackers-claim-access-to-300-million-icloud-accounts-say-apple-refused-to-pay-75-000-ransom.2038152/

What's your take on this? Fake or real?

I would be super surprised if Apple's database of credentials was stolen in plaintext or passwords that were hashed without salt. Now I could see data from other breaches like email addresses and passwords being combined. Many of them would work but many (people not reusing passwords) would not.

Considering the bug bounty would've given up to 50k, that seems like way more of a hassle to try to get not even that much more money (or itunes gcs? really?). Most likely you're right and it's from other breaches.

Three-Phase
Aug 5, 2006

by zen death robot
I think the article said they had a video that demonstrated them breaking into one single account.

There is all kinds of stuff that smells funny about this whole thing.

Wiggly Wayne DDS
Sep 11, 2010



that they've gone to the media to coerce payment and didn't make an example of, say, a thousand random devices being wiped says it all

Three-Phase
Aug 5, 2006

by zen death robot

Wiggly Wayne DDS posted:

that they've gone to the media to coerce payment and didn't make an example of, say, a thousand random devices being wiped says it all

Why alert all the users too so they can secure their accounts?

Also Apple has responded and is calling this BS.

Three-Phase fucked around with this message at 10:15 on Mar 23, 2017

Proteus Jones
Feb 28, 2013



You can also log into your "Apple ID" page and see what devices and systems have access to your account.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Wiggly Wayne DDS posted:

that they've gone to the media to coerce payment and didn't make an example of, say, a thousand random devices being wiped says it all

Pretty much this.

some kinda jackal
Feb 25, 2003

 
 
Has anyone done CCSP? Is there anything remotely interesting or useful in there? The outline isn't really a good indicator.

My manager wants me to take it along with her later this year so .. hey, free cert and raise .. but I hope it's more applicable than CISSP.

stoopidmunkey
May 21, 2005

yep

Martytoof posted:

Has anyone done CCSP? Is there anything remotely interesting or useful in there? The outline isn't really a good indicator.

My manager wants me to take it along with her later this year so .. hey, free cert and raise .. but I hope it's more applicable than CISSP.

My understanding is the CCSP is essentially the CISSP without the managerial stuff. If you've got access to Lynda.com, they've got some really good training videos for both. I was going to go for the CCSP, but decided to just work towards the CISSP instead since that's what most employers I'm seeing want.

That said, if it's free, do it. Certs never seem to hurt.

some kinda jackal
Feb 25, 2003

 
 
Yeah, I'm going to go for it just because. Didn't realize Lynda had any CCSP material. I'll have to check it out. Kind of want to go back through CISSP CBTs just to see if it matches up with what the test was like.

apropos man
Sep 5, 2016

You get a hundred and forty one thousand years and you're out in eight!
I use this app on my phone to sync my Keepass db:

https://play.google.com/store/apps/details?id=com.bv.wifisync

I have a cron job set on it every two hours to sync from my home server's samba share and force overwrite the latest version of my kdbx file on to the phone. It takes less than a second to sync. It will only try to sync if it's connected to a specific ssid.

The main drawback is that if I'm out of the house and I want to sign up for something I just make a note of the password and enter it into my keepass db manually on my laptop. I have a cron job on my laptop to rsync the latest copy of my kdbx to the server every hour.

Secondary drawback is that if I join a site on my laptop and save the new creds then it can take a couple of hours before the latest kdbx is on my phone, but I rarely join something so critical that I need portable access immediately.

Main positive from this set up is not relying on a third party to handle my db.

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

apropos man posted:

I use this app on my phone to sync my Keepass db:

https://play.google.com/store/apps/details?id=com.bv.wifisync

I have a cron job set on it every two hours to sync from my home server's samba share and force overwrite the latest version of my kdbx file on to the phone. It takes less than a second to sync. It will only try to sync if it's connected to a specific ssid.

The main drawback is that if I'm out of the house and I want to sign up for something I just make a note of the password and enter it into my keepass db manually on my laptop. I have a cron job on my laptop to rsync the latest copy of my kdbx to the server every hour.

Secondary drawback is that if I join a site on my laptop and save the new creds then it can take a couple of hours before the latest kdbx is on my phone, but I rarely join something so critical that I need portable access immediately.

Main positive from this set up is not relying on a third party to handle my db.

That seems pretty unnecessary and a lot of annoyance/effort. Just use Dropbox/Google Drive? Your kdbx database is encrypted out of the gate and you can use a key file, etc to take it even further.

apropos man
Sep 5, 2016

You get a hundred and forty one thousand years and you're out in eight!
Yeah, I know it's convoluted. I quite like it, though.

Last Chance
Dec 31, 2004

apropos man posted:

Main positive from this set up is not relying on a third party to handle my db.

Except for the Android app that hasn't been updated in almost two years?

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

apropos man posted:

Yeah, I know it's convoluted. I quite like it, though.

Yes, but why? As said, that app hasn't been updated in years, and you would have a FAR easier and better and faster and smoother experience by just using Dropbox or Drive.

some kinda jackal
Feb 25, 2003

 
 
Anyone using Tenable's products to run CIS benchmarks against assets? Just wondering how well that works vs running CIS's own benchmarking tool. I'm trying to revamp our CVA processes and I'd love to just kill two birds with one.. software.. Strip out my custom cis-cat cronjob on every server, etc.

some kinda jackal fucked around with this message at 22:37 on Mar 27, 2017

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

Martytoof posted:

Anyone using Tenable's products to run CIS benchmarks against assets? Just wondering how well that works vs running CIS's own benchmarking tool. I'm trying to revamp our CVA processes and I'd love to just kill two birds with one.. software.

Yes, Tenables is a lot better imo. We did have to craft our own scan templates though.

some kinda jackal
Feb 25, 2003

 
 
Swank. I'm setting up a tenable.io trial right now. I like the idea of controlling everything from the cloud but I'm going to have to do a lot of due diligence to sell keeping a list of vulnerabilities and IPs in the cloud to my C-levels.

Sickening
Jul 16, 2007

Black summer was the best summer.
Phone posting!!!! N/m

Sickening fucked around with this message at 00:43 on Mar 28, 2017

some kinda jackal
Feb 25, 2003

 
 

I... don't get it.

some kinda jackal fucked around with this message at 00:54 on Mar 28, 2017

Sickening
Jul 16, 2007

Black summer was the best summer.

Martytoof posted:

I... don't get it.

Phone posting mishap.

some kinda jackal
Feb 25, 2003

 
 
Phew, I thought I was just missing something obvious by not making a connection.

apropos man
Sep 5, 2016

You get a hundred and forty one thousand years and you're out in eight!

Last Chance posted:

Except for the Android app that hasn't been updated in almost two years?

Maybe it's perfect.

Proteus Jones
Feb 28, 2013



apropos man posted:

Maybe it's perfect.

Yes, I'm sure it is. People here in The Infosec Thread must be crazy to raise concerns about a convoluted method using a product that appears abandoned.

Don't listen to them. You be you.

Thanks Ants
May 21, 2004

#essereFerrari


Oh, it wasn't sarcasm

Proteus Jones
Feb 28, 2013



Thanks Ants posted:

Oh, it wasn't sarcasm

How could it be? I've never met a sarcastic goon in my life.

psydude
Apr 1, 2008

My girlfriend's roommate asked for suggestions on a VPN solution to their house, so I recommended OpenVPN because it's free and easy to configure. He replied "Free usually means exploitable."

He's a software engineer.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

psydude posted:

My girlfriend's roommate asked for suggestions on a VPN solution to their house, so I recommended OpenVPN because it's free and easy to configure. He replied "Free usually means exploitable."

He's a software engineer.

So what languages does he code in primarily?

PBS
Sep 21, 2015

OSI bean dip posted:

So what languages does he code in primarily?

HTML

oh

PBS fucked around with this message at 01:38 on Mar 29, 2017

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


Trust me, that poo poo is full of holes.

How much did he pay for his browser?

CLAM DOWN
Feb 13, 2007

nesaM killed Masen

psydude posted:

He's a software engineer.

Sounds about right.

Gyshall
Feb 24, 2009

Had a couple of drinks.
Saw a couple of things.
Not sure if this is the best place, but I'm a 20 year SysAdmin/Network admin and I'm looking to get into more of an infosec position in the next year or so.

I'm reading about CISSP certification.... Is this a good route to take? Any recommendations on methods or practice material?

beepsandboops
Jan 28, 2014
After learning about the new ISP privacy law, our DBA immediately tried to install Tor on his workstation :allears:

some kinda jackal
Feb 25, 2003

 
 

Gyshall posted:

Not sure if this is the best place, but I'm a 20 year SysAdmin/Network admin and I'm looking to get into more of an infosec position in the next year or so.

I'm reading about CISSP certification.... Is this a good route to take? Any recommendations on methods or practice material?

What sort of position are you looking for? Infosec is a wide wide field.

CISSP requires five years of "verifiable" work experience in three (I think) of its domains which you can probably talk your way through if you did any serious jack of all trade sysadmin duties, and it'll get you on recruiter lists but to be honest it won't really land you a job in and of itself without actual security experience. What material I'd recommend would depend entirely on the path you want to choose. CISSP is too "managerial" so even if you just wanted to use it to learn instead of get your foot in the door I still wouldn't recommend it as a source of real world security knowledge.

SANS runs a lot of good courses but you need to sell a kidney if work isn't paying for them. OSCP I guess if you're interested in offensive security. I don't really know much about the entry level sec certs like Sec+ or CEH though, sorry.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

beepsandboops posted:

After learning about the new ISP privacy law, our DBA immediately tried to install Tor on his workstation :allears:

The new activity repealed a law that wasn't yet in effect, so what's his motivation? It's not a new law, it's exactly the opposite: keeping a new law from taking effect.

Furism
Feb 21, 2006

Live long and headbang

Gyshall posted:

Not sure if this is the best place, but I'm a 20 year SysAdmin/Network admin and I'm looking to get into more of an infosec position in the next year or so.

I'm reading about CISSP certification.... Is this a good route to take? Any recommendations on methods or practice material?

It certainly is a good way to pick up some background knowledge about different aspect of security. Given how many domains there are in the course, you're bound to learn a lot of things. Some of it is boring and abstract (security models), some is amazing (cryptography), but overall I think it's a Good Thing to go through the book even if you don't attempt or pass the actual certification. Note that the exam, being so long (250 questions and up to 6 hours), doesn't really test your technical skill but rather your endurance and ability to regurgitate 800+ pages of content.

I think this certification will open up new job opportunities but only that; opportunities. It doesn't guarantee a job (not in any company worth working for I think).

some kinda jackal
Feb 25, 2003

 
 
Just my two cents but I have to believe that there are way better sources for picking up cryptography than the ISC2 material.

Maybe check out the 11th Hour CISSP book for a much more readable version of the syllabus if you're really interested.

Adbot
ADBOT LOVES YOU

Solaron
Sep 6, 2007

Whatever the reason you're on Mars, I'm glad you're there, and I wish I was with you.

Martytoof posted:

Just my two cents but I have to believe that there are way better sources for picking up cryptography than the ISC2 material.

Maybe check out the 11th Hour CISSP book for a much more readable version of the syllabus if you're really interested.

I've been working in IT (starting as a field tech, moving into tech support, then network/system admin and finally security ops) for 15 years now. My experience studying for CISSP has been that it's a good way to ensure that people talking cyber security have a shared vocabulary and perspective, but that's about it. It's very broad and focuses on a managerial mindset, so in some ways it's counter to the way a lot of us think. It seems like most security positions in my area (Cincinnati) want you to have it or be working towards it, and I'm sure having the cert can help your salary, but it definitely doesn't impart any skills or specific information to make you a better hands-on technician.


I definitely agree on the 11th Hour book by Eric Conrad. It's a pretty quick read that covers the domains quickly but enough that you'll understand the main concepts and maybe make a determination at that point if that's what you really want to focus on.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply