Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Happiness Commando
Feb 1, 2002
$$ joy at gunpoint $$

:yotj:

I was super bored at the tiny-rear end MSP that I used to work at. Topped out as sysadmin/PM/architect (for 30-seat offices :smuggo: ) and I could deploy our environments with my eyes closed. Quit my job, traveled for 9 months. In less than a month since my return I landed a gig at a brand new MSP. Going to be the only technical guy there until they grow, which has me a little antsy, but I got a 40% raise and building a technical organization from the ground up would be quite the feather in my hat.

I'm impostering so hard right now.

edit: YOTJ is the best new page snipe

Adbot
ADBOT LOVES YOU

George H.W. Cunt
Oct 6, 2010





Happiness Commando posted:

:yotj:

I was super bored at the tiny-rear end MSP that I used to work at. Topped out as sysadmin/PM/architect (for 30-seat offices :smuggo: ) and I could deploy our environments with my eyes closed. Quit my job, traveled for 9 months. In less than a month since my return I landed a gig at a brand new MSP. Going to be the only technical guy there until they grow, which has me a little antsy, but I got a 40% raise and building a technical organization from the ground up would be quite the feather in my hat.

I'm impostering so hard right now.

edit: YOTJ is the best new page snipe

I hope my return is just as smooth. I’ve been off work for 7 months now. Hiked the AT and am currently fumbling around Europe. I’m definitely getting antsy and just want to work again and make money.

Grassy Knowles
Apr 4, 2003

"The original Terminator was a gritty fucking AMAZING piece of sci-fi. Gritty fucking rock-hard MURDER!"

Proteus Jones posted:

Pleas include dissertation either supporting or refuting the theory that Alexander Dumas' later works were produced by a stable of ghost writers.

Time to reread Club Dumas

hihifellow
Jun 17, 2005

seriously where the fuck did this genre come from

Vulture Culture posted:

Some of the very specific product-oriented ones like /r/kubernetes are not terrible but in general Reddit is a horrible thing and should be avoided

Sometimes I am very bored at work and reddit has a lot of things to read and all I have learned is crowd sourcing your quality control makes for extremely boring content.

Also that layout is balls.

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
I hate bringing my work bag through TSA. Every drat time I get flagged for extra screening. This time I took all the weird poo poo out but forgot I had 20 optics rolled up in a rubber band.

Peachfart
Jan 21, 2017

hihifellow posted:

Sometimes I am very bored at work and reddit has a lot of things to read and all I have learned is crowd sourcing your quality control makes for extremely boring content.

Also that layout is balls.

Reddit is the true definition of 'quantity, not quality'. Sometimes interesting discussions or effort posts appear, but good luck finding them under an avalanche of memes and no content garbage.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Dick Trauma posted:

Screw this dumb world; I'm just going to read fiction!
I, too, enjoy a nice TheDailyWTF from time to time.

Kinda shocked that almost zero people in this thread use twitter.

OhDearGodNo
Jan 3, 2014

Hey let’s spend all this money on a Nexus 9k/3k/2k setup with all this nice 40Gb connectivity and forget that the IPS it goes through only supports 3Gb - aggregated.

abigserve
Sep 13, 2009

this is a better avatar than what I had before
If your data centre traffic goes anywhere near an ips you've already hosed up the topology somewhere

OhDearGodNo
Jan 3, 2014

abigserve posted:

If your data centre traffic goes anywhere near an ips you've already hosed up the topology somewhere

It’s not in the data center- this is between the 9k and another 9k before that (I should have been more clear)

OhDearGodNo fucked around with this message at 14:10 on Oct 28, 2017

Paladine_PSoT
Jan 2, 2010

If you have a problem Yo, I'll solve it

abigserve posted:

If your data centre traffic goes anywhere near an ips you've already hosed up the topology somewhere

This is not true, but it depends on what you're doing in the datacenter. My project has numbers that horrify network engineers.

The Fool
Oct 16, 2003


anthonypants posted:

I, too, enjoy a nice TheDailyWTF from time to time.

Kinda shocked that almost zero people in this thread use twitter.

I've attempted twitter a few times now, and every time I give up because I have problems filtering out the signal from the noise.

I'm still light years ahead of most of my coworkers as far as tech new goes just from reading these threads and a couple podcasts.

Antioch
Apr 18, 2003
I use Twitter a lot for new and interesting stuff. Follow @SwiftOnSecurity and @Munin then everyone they retweet.
I pretty much only check it once or a day, it's not much of a time investment.

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Paladine_PSoT posted:

This is not true, but it depends on what you're doing in the datacenter. My project has numbers that horrify network engineers.

We push a lot of scientific data and plan around not having an ips anywhere near it (check out "science DMZ") . There is no ips on the market that is suitable for a data centre environment, they all have severe performance limitations.

If you have a bunch of tenants I can imagine you'd be stuck having to do it though, though at that point I'd probably say stick to basic firewalling if performance is a concern.

22 Eargesplitten
Oct 10, 2010



What do I need to know about working on Sharepoint, aside from increasing my alcohol budget?

I would be junior on it, probably mostly doing coding grunt work.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

abigserve posted:

If your data centre traffic goes anywhere near an ips you've already hosed up the topology somewhere

Ask me about S3 topology... in a single AZ. :smug:

OhDearGodNo
Jan 3, 2014

abigserve posted:

We push a lot of scientific data and plan around not having an ips anywhere near it (check out "science DMZ") . There is no ips on the market that is suitable for a data centre environment, they all have severe performance limitations.

If you have a bunch of tenants I can imagine you'd be stuck having to do it though, though at that point I'd probably say stick to basic firewalling if performance is a concern.

If your firewall is anything more than a glorified ACL, you’ll hit the same performance concerns.

You don’t put an IPS internal within a segmented tenant, but I’ll be drat sure I do when facing an untrusted zone.

Methanar
Sep 26, 2013

by the sex ghost

Agrikk posted:

Ask me about S3 topology... in a single AZ. :smug:

Tell me about S3 topology. I want to know

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

Methanar posted:

Tell me about S3 topology. I want to know

After reflection, Im not too sure how much I can share in a public forum.

That said, AWS had to basically write it’s own protocol stack because TCP/IP was too slow and too inefficient. This heavily customized version of TCP/IP runs on our own custom switches that are our own hardware and software design that is tailored to our network traffic.

The actual storage and retrieval of an object occurs like a hard disk, with a controller on the disk coordinating read/writes to a platter, but in our case the controller is a PC and the platters are other storage PCs and the writes are to multiple storage PCs and reads are pulled from multiple machines and assembled by the controller to be sent to the originator of the request.

Let’s just say that some of Netflix’s patterns are things to behold.

OhDearGodNo
Jan 3, 2014

Agrikk posted:

After reflection, Im not too sure how much I can share in a public forum.

That said, AWS had to basically write it’s own protocol stack because TCP/IP was too slow and too inefficient. This heavily customized version of TCP/IP runs on our own custom switches that are our own hardware and software design that is tailored to our network traffic.

The actual storage and retrieval of an object occurs like a hard disk, with a controller on the disk coordinating read/writes to a platter, but in our case the controller is a PC and the platters are other storage PCs and the writes are to multiple storage PCs and reads are pulled from multiple machines and assembled by the controller to be sent to the originator of the request.

Let’s just say that some of Netflix’s patterns are things to behold.

Go on...

abigserve
Sep 13, 2009

this is a better avatar than what I had before

OhDearGodNo posted:

If your firewall is anything more than a glorified ACL, you’ll hit the same performance concerns.

You don’t put an IPS internal within a segmented tenant, but I’ll be drat sure I do when facing an untrusted zone.

Yeah of course. The issue is people generally classify untrusted zones too broadly and these causes so many problems when you start putting IPS's/NGFWs in the way. I had one place that classified every department as their own security zone and it's like that's fine but you need to accept the issues with doing so.

You could also reasonably make a case that IPS systems are no way worth the tradeoffs in anything other than a gateway (i.e internet facing) environment but to each their own!

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Agrikk posted:

After reflection, Im not too sure how much I can share in a public forum.

This heavily customized version of TCP/IP runs on our own custom switches that are our own hardware and software design that is tailored to our network traffic.

FYI anyone interested in this, Barefoot networks is starting to build the silicon so theoretically anyone will be able to do this, not just the big boys with enough money and people to throw at it

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

abigserve posted:

FYI anyone interested in this, Barefoot networks is starting to build the silicon so theoretically anyone will be able to do this, not just the big boys with enough money and people to throw at it

Companies like OVH, DreamHost, and Backblaze do it (block storage) with off the shelf networking don’t they?

OhDearGodNo
Jan 3, 2014

abigserve posted:

Yeah of course. The issue is people generally classify untrusted zones too broadly and these causes so many problems when you start putting IPS's/NGFWs in the way. I had one place that classified every department as their own security zone and it's like that's fine but you need to accept the issues with doing so.

You could also reasonably make a case that IPS systems are no way worth the tradeoffs in anything other than a gateway (i.e internet facing) environment but to each their own!

I love asking people, “where do you think the DMZ ends?” Because I always get a different answer. Where do you want to implicitly trust communications on a tiered environment? There are so many answers that span specific requirements. How is the domain structured? How do different domains (if more than one) communicate, and what level of trust is there? Who are you federated with?

So when people say a NGFW or network IPS/IDS doesn’t have value, I often wonder what is being used to come to the conclusion. When it comes to a data breach, the RO should be zero. Look at the impact of Equifax. Why was there no DAM solution to make sure the queries weren’t out of the ordinary? How many times can you let a breach happen? One time- so it’s such a tricky sell to put these in place when many responses are always, “are these necessary when we have never been owned?”

You don’t always need to have an IPS potentially throttling traffic. If you worry about the aggregate throughput, just span the poo poo and use orchestration (or better yet pxGrid/openDXL) to tie in with a host agent. Run that as well as a good data access management solution, and that would have no real impact on east-west traffic but would mitigate the ability of a compromising entity to travel within a trusted zone. It’s still an IPS solution, however more targeted.

abigserve
Sep 13, 2009

this is a better avatar than what I had before

OhDearGodNo posted:

I love asking people, “where do you think the DMZ ends?” Because I always get a different answer. Where do you want to implicitly trust communications on a tiered environment? There are so many answers that span specific requirements. How is the domain structured? How do different domains (if more than one) communicate, and what level of trust is there? Who are you federated with?

So when people say a NGFW or network IPS/IDS doesn’t have value, I often wonder what is being used to come to the conclusion. When it comes to a data breach, the RO should be zero. Look at the impact of Equifax. Why was there no DAM solution to make sure the queries weren’t out of the ordinary? How many times can you let a breach happen? One time- so it’s such a tricky sell to put these in place when many responses are always, “are these necessary when we have never been owned?”

You don’t always need to have an IPS potentially throttling traffic. If you worry about the aggregate throughput, just span the poo poo and use orchestration (or better yet pxGrid/openDXL) to tie in with a host agent. Run that as well as a good data access management solution, and that would have no real impact on east-west traffic but would mitigate the ability of a compromising entity to travel within a trusted zone. It’s still an IPS solution, however more targeted.

Yeah there are a million different variables that can impact how you want to segment your network. However, using an IPS as a piece of that segmentation rarely yields useful results because all network-based IPS's are signature and sandboxing based, and they are best at detecting attacks that are unlikely to be seen as part of an east-west vector unless you are in a hosting position where multiple networks are basically seperate entities and share no infrastructure or management with each other.

My biggest point I try to stress to people is that it is no longer solely the job of the network to keep the clients secure - as engineers (or architects) we can contribute to it through smart design and the use of relevant technologies but the underlying responsibility is with the application owners. If your server is vulnerable to Attack A, it is up to you to ensure that threat is remedied, not relying on network elements to prevent the threat from ever making it to you in the first place.

Your example of DAM is perfect as one of many ways app owners can be proactive in the protection of their own servers, and it's way more powerful than anything we can implement on the network. And if people can't be bothered implementing these sorts of fixes (and hoo boy I'm sure you get as much "we can't patch this server because it'll break everything" as I do) then ripperoni pepperoni, I'm not designing my topology around your poorly designed stuff.

MC Fruit Stripe
Nov 26, 2002

around and around we go

Bob Morales posted:

Companies like OVH, DreamHost, and Backblaze do it (block storage) with off the shelf networking don’t they?
This is the kind of knowledge where I just have to ask, where does one learn this? I mean that these companies are doing X Y and Z. I feel so out of the loop compared to you guys.

tortilla_chip
Jun 13, 2007

k-partite
Conference presentations are a good source. Most webscale organizations are facing the same infrastructure problems as far as distributed systems are concerned. Some are just further along the maturity curve than others.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

MC Fruit Stripe posted:

This is the kind of knowledge where I just have to ask, where does one learn this? I mean that these companies are doing X Y and Z. I feel so out of the loop compared to you guys.

Go to YouTube and search for an AWS service. You will find all manner of interesting stuff at the 300-400 level that was presented at various re:Invents over the years.

That’s a good place to start.

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.
So strangely enough I'm being fast-tracked for a DevOps role even though I possess none of the skillset. I know powershell fairly well and have written some fairly complicated scripts, but I'm pretty far from what anyone would consider a coder.

Since "DevOps" is broad as hell, this is focused on automation and Azure Pack, which will eventually transition to Azure proper. The team that spearheads all of this utilizes (from what I've been able to glean) Packer and Terraform for most of their rollouts. Not sure what they're using for actual provisioning yet.

Feeling a little overwhelmed because I don't really know where to start. I've begun messing around with Packer/Vagrant to get a feel for certain things, but I'd appreciate any direction you ~*Cloud Architects*~ can provide. I'm sure I can get it, but this is absolutely outside of my wheelhouse. Is there a place that would be best for me to start at?

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


DevOps is confusing but I can say Azure Pack is now Azure Stack.

It’s basically hyper-converged infrastructure but runs Microsoft Azure PaaS solutions but on your own hardware.

Sefal
Nov 8, 2011
Fun Shoe
I'm in a powershell slack group. where I mostly absorb and test the stuff they talk about.

But that and this forum is where I read up on IT stuff.

Sefal
Nov 8, 2011
Fun Shoe
HR just invited me to a meeting to talk about my employment contract. It's this friday. This is going to be a long week.
:ohdear:

I had kicked this off by asking my boss. whether or not my contract gets extended. My boss and the CEO have said yes. So I hope this is just to sign the contract with HR to extend it.
This reasoning leads me to believe it's positive, but I can't shake the feeling that it may not be extended.

LochNessMonster
Feb 3, 2005

I need about three fitty


Sefal posted:

HR just invited me to a meeting to talk about my employment contract. It's this friday. This is going to be a long week.
:ohdear:

I had kicked this off by asking my boss. whether or not my contract gets extended. My boss and the CEO have said yes. So I hope this is just to sign the contract with HR to extend it.
This reasoning leads me to believe it's positive, but I can't shake the feeling that it may not be extended.

Not to try and scare you, but if you didn’t have to worry they probably would’ve told you what the meeting would be for. Like:

“Hey I scheduled a meeting with HR to get you the extension you asked me about”.

Start looking so you don’t get caught with your pants down and hope you don’t need it. Unannounced meetings with HR usually don’t mean good news.

Sefal
Nov 8, 2011
Fun Shoe

LochNessMonster posted:

Not to try and scare you, but if you didn’t have to worry they probably would’ve told you what the meeting would be for. Like:

“Hey I scheduled a meeting with HR to get you the extension you asked me about”.

Start looking so you don’t get caught with your pants down and hope you don’t need it. Unannounced meetings with HR usually don’t mean good news.

Thank you for this post. I was feeling uneasy about it. So I gathered up my courage and went to HR to see what this was about.
Turns out it's all fine. The contract will be extended. Just need to sit down with HR, my boss and sign it this Friday.

Vargatron
Apr 19, 2008

MRAZZLE DAZZLE


Anybody have any ideas on how to force Outlook 2016 to prompt for credentials? I've got a user who wants "an extra layer of security" when she accesses her e-mails.

I've tried deleting all stored credentials in Credential Manager but that doesn't have any effect. I also tried to check the "always prompt for login credentials" box in the e-mail profile settings, but that is grayed out. I'm on Office 365 if that makes any difference.

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.
Scheduling meetings that directly involve your career for days in advance without telling you the meeting content is one of the things I hate the most about HR.

Gee assholes, maybe take a moment to think about the implications of a blind, surprise meeting with a subject of “your contract”. Now think of the tailspin you might cause if you schedule that meeting for five, seven, ten days from now.

What would it have taken to send a meeting invite with a title of “your contract” and a body of “this is a routine meeting to renew your contract. You are doing great here and we’d like to extend it.”

JHVH-1
Jun 28, 2002

Agrikk posted:

Go to YouTube and search for an AWS service. You will find all manner of interesting stuff at the 300-400 level that was presented at various re:Invents over the years.

That’s a good place to start.

Yeah AWS posts all their webinars on youtube
https://www.youtube.com/watch?v=channel?UCT-nPlVzJI-ccQXlxjSvJmw

Basically signing up for a free account and playing around helps if you don't have actual infrastructure currently. Also reading the blog helps to learn what is new and hot you can learn about how services work https://aws.amazon.com/blogs/aws/

LochNessMonster
Feb 3, 2005

I need about three fitty


Sefal posted:

Thank you for this post. I was feeling uneasy about it. So I gathered up my courage and went to HR to see what this was about.
Turns out it's all fine. The contract will be extended. Just need to sit down with HR, my boss and sign it this Friday.

Glad it turned out to be nothing and congrats on your extension!

AlternateAccount
Apr 25, 2005
FYGM

MF_James posted:

Has anyone used Egnyte or heard from someone that does? My fiancée's work currently uses google drive for filesharing needs, they are a 10 person company, no domain or anything, hosted VOIP solution blah blah blah. They fall under HIPAA (google is compliant apparently, I have never looked) and the owner + another person complain that google drive is hard and want something more user friendly, Egnyte came up and I'm trying to ask around since I have no loving clue.

Is it good? Easy to use? Any pitfalls? poo poo like that.

Hey, this is old, but we looked at it a few years ago and Box just beat the poo poo out of it on every level.

Adbot
ADBOT LOVES YOU

Sickening
Jul 16, 2007

Black summer was the best summer.
Today I witnessed a Christmas miracle.

Phishing attempts have been pretty consistent lately. User gets random attachment, that user open attachment, that user then gives the internet their office 365 user information. The fake office 365 pages they have fell for are awful. Attackers are even putting in effort anymore. Some of them have looked like MSpaint jobs.

Last week we went through extensive user education. Users were shown examples of lots of phishing emails and the general attack types. The training was well thought out and executed. People were told that real consequences were going to happen if they leak their sign on information this way. Everyone attended from the CEO down. The CEO even sent out an email saying his patience was exhausted.

Fast forward to this morning where we find out someone has been compromised. I put together the timeline of events.

The employee changed his password at 9:30 that morning as required of his entire department. The employee attends training at 10. The employee then after training at 12:30 open an attachment with a phishing hyperlink. Visits the webpage, enters his credentials. The employee then gets an email from the company with the compromised account that sent him the previous phishing email he fell for saying that they had sent out the compromised link and apologized. The employee then read the email, deleted it, and then deleted it from his trashcan. The employee never tells another soul and goes about his week like nothing happened.

They walked him out with all his poo poo about 30 minutes ago. Apparently he admitted to falling for the phishing attack and then not telling anyone.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply