Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sickening
Jul 16, 2007

Black summer was the best summer.
Who else has devs freaking out about the .net upgrade to 4.7.2 in azure who had been notified but done nothing until today?

Adbot
ADBOT LOVES YOU

CLAM DOWN
Feb 13, 2007




GreenNight posted:

Our security team approved it. By which I mean me. By me I mean I don't care anymore.

Yikes dude.

Sickening posted:

Who else has devs freaking out about the .net upgrade to 4.7.2 in azure who had been notified but done nothing until today?

Was that the v2 function app thing they broke?

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

CLAM DOWN posted:

Lol fight me irl bitch, Everton sucks

If you finish that thought by saying Chelsea owns, I’d agree with you.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE


I wonder what happens when their DC is on fire and the agent can't check in?

AlternateAccount
Apr 25, 2005
FYGM

Internet Explorer posted:

NIST says no more frequently changed passwords, so I have been pushing back on our auditors that request that. I hope in 10 years that will filter down to them, but I'm not holding my breath.

1000x this. Whenever I feel like being an idiot, I try this fight again and fail because entrenched idiots can't see their way clear to such a "major" shift in password policy, even though it's an improvement in every possible way.

Inspector_666 posted:

Yeah, a lot of poo poo is because of PCI (and now I guess SOX) compliance checkboxes, our security people know what's theater and what's actually useful.

SOX doesn't have any explicit password requirements. You could implement the referenced NIST recommendations wholesale, and while your external idiot auditors might poop themselves until you talk them around on it, you're fully compliant.

AlternateAccount
Apr 25, 2005
FYGM
Ugh, I just had a user put in a ticket that "wants his MacBook rebuilt." How bad must you have hosed up to feel you need your OS reloaded to fix it?!

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

AlternateAccount posted:

1000x this. Whenever I feel like being an idiot, I try this fight again and fail because entrenched idiots can't see their way clear to such a "major" shift in password policy, even though it's an improvement in every possible way.


SOX doesn't have any explicit password requirements. You could implement the referenced NIST recommendations wholesale, and while your external idiot auditors might poop themselves until you talk them around on it, you're fully compliant.

Luckily we've gone the route of less frequent password changes (I think it's quarterly now, maybe less) but more complex, also 2FA on anything accessed externally. It's a mix of SMS 2FA and real token 2FA, hopefully we'll get away from SMS at some point, but it's better than nothing for now.

mewse
May 2, 2006

"When is a good time for me to come by and look at these computers?"

"Oh, any time. Or we could set a time"

... ok I'll just show up whenever, thanks

18 Character Limit
Apr 6, 2007

Screw you, Abed;
I can fix this!
Nap Ghost
Member of a group supporting applications on thousands of linux machines, several minutes ago: "What is /etc ?"

:eng99:

AlternateAccount
Apr 25, 2005
FYGM

MF_James posted:

Luckily we've gone the route of less frequent password changes (I think it's quarterly now, maybe less) but more complex, also 2FA on anything accessed externally. It's a mix of SMS 2FA and real token 2FA, hopefully we'll get away from SMS at some point, but it's better than nothing for now.

The best is when you have a very low failed attempt lockout threshold of like... 3, so then they change their AD password on their computer, but dont change it on their phone fast enough and the Mail app hits the server 3 times and WELP.

It's all so tiresome.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:


:hmm:

The Iron Rose fucked around with this message at 19:24 on Sep 7, 2018

lampey
Mar 27, 2012

AlternateAccount posted:

The best is when you have a very low failed attempt lockout threshold of like... 3, so then they change their AD password on their computer, but dont change it on their phone fast enough and the Mail app hits the server 3 times and WELP.

It's all so tiresome.

AD has a feature where using your old password doesn't count towards lockout attempts. They should only be locked out if an even older password is cached.

AlternateAccount
Apr 25, 2005
FYGM

lampey posted:

AD has a feature where using your old password doesn't count towards lockout attempts. They should only be locked out if an even older password is cached.

I... did not know that. Clearly that's not working in our case, I'll investigate.

CloFan
Nov 6, 2004

Is that based on a domain function level? Cause I don't think that's the case in my environment either.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




mewse posted:

"When is a good time for me to come by and look at these computers?"

"Oh, any time. Or we could set a time"

... ok I'll just show up whenever, thanks

Check their calendar, show up when they're busy.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

CloFan posted:

Is that based on a domain function level? Cause I don't think that's the case in my environment either.

Not working in mine either. We enforce password history, but the attributes are empty. Interesting. Like this would legit make life easier for us if I can figure out why it isn't working.

skipdogg fucked around with this message at 22:08 on Sep 7, 2018

Ham Equity
Apr 16, 2013

The first thing we do, let's kill all the cars.
Grimey Drawer

lampey posted:

AD has a feature where using your old password doesn't count towards lockout attempts. They should only be locked out if an even older password is cached.
For realsies?

Anyone have an article?

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

quote:

New Features in the Windows Server 2003 Family

To improve the experience for users and to decrease the overall total cost of ownership, Microsoft made the following changes to the behavior of domain controllers in the Windows Server 2003 family:

Password history check (N-2): Before a Windows Server 2003 operating system increments badPwdCount, it checks the invalid password against the password history. If the password is the same as one of the last two entries that are in the password history, badPwdCount is not incremented for both NTLM and the Kerberos protocol. This change to domain controllers should reduce the number of lockouts that occur because of user error.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Thanatosian posted:

For realsies?

Anyone have an article?

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc775412(v%3dws.10)#ntpwdhistory

https://social.technet.microsoft.co...rum=winserverDS

http://virot.eu/finding-password-cheaters/

So if I run the powershell from the last link, the ntPwdHistory has a lastoriginatingchangetime value, but the attribute value itself is blank. Maybe that's normal....

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

skipdogg posted:

Not working in mine either. We enforce password history, but the attributes are empty. Interesting. Like this would legit make life easier for us if I can figure out why it isn't working.
Which attributes? Passwords should be stored in the SAM database, not the LDAP directory. unicodePwd is writable under certain conditions, but should never be readable.

Krispy Wafer
Jul 26, 2002

I shouted out "Free the exposed 67"
But they stood on my hair and told me I was fat

Grimey Drawer
Nothing like walking in on a Monday morning to the offshore team telling me to reboot a device in the datacenter, going down, realizing it’s in the high security cage, locating the device, double checking all my notes, rebooting it, coming back upstairs only to find out they sent me to the wrong device.

Hiding down in the datacenter racks right now.

H110Hawk
Dec 28, 2006

Krispy Wafer posted:

Nothing like walking in on a Monday morning to the offshore team telling me to reboot a device in the datacenter, going down, realizing it’s in the high security cage, locating the device, double checking all my notes, rebooting it, coming back upstairs only to find out they sent me to the wrong device.

Hiding down in the datacenter racks right now.

You rebooted the correct server. They would also like you to reboot a second server.

Krispy Wafer
Jul 26, 2002

I shouted out "Free the exposed 67"
But they stood on my hair and told me I was fat

Grimey Drawer

H110Hawk posted:

You rebooted the correct server. They would also like you to reboot a second server.

Keep rebooting until something stops alarming (or something else starts alarming).

18 Character Limit
Apr 6, 2007

Screw you, Abed;
I can fix this!
Nap Ghost

Krispy Wafer posted:

Keep rebooting until something stops alarming (or something else starts alarming).

3rd reboot: the monitoring server

Methanar
Sep 26, 2013

by the sex ghost
Tell them to do it themselves with ipmi

H110Hawk
Dec 28, 2006

Methanar posted:

Tell them to do it themselves with ipmi

Didn't you read its the high security cage! Can't have people doing things willy-nilly with proper access control and logging, you send someone down there to hopefully push the button on hopefully the correct server!

Internet Explorer
Jun 1, 2005





Something, something, arrange icons by penis.

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

Internet Explorer posted:

Something, something, arrange icons by penis.

I somehow have an arrangebypenis program that I believe was written by some goon way back in 2010.
I'd share it but, :filez:

GnarlyCharlie4u fucked around with this message at 18:41 on Sep 10, 2018

Internet Explorer
Jun 1, 2005





Blast from the past -

https://www.youtube.com/watch?v=uRGljemfwUE

CrazyLittle
Sep 11, 2001





Clapping Larry

GnarlyCharlie4u posted:

I somehow have an arrangebypenis program that I believe was written by some goon way back in 2010.
I'd share it but, :filez:



https://sourceforge.net/projects/arrangebypenis/

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

yes! thank you.

H110Hawk
Dec 28, 2006
Oh good. This site is supposed to be all Torx drive M6 caged nuts and fasteners. In addition to the #2 philips floating around this is how one random rack is setup:

Thanks Ants
May 21, 2004

#essereFerrari


Torx is a bit overkill for fixing stuff into racks, isn't it?

H110Hawk
Dec 28, 2006

Thanks Ants posted:

Torx is a bit overkill for fixing stuff into racks, isn't it?

Nope.

SyNack Sassimov
May 4, 2006

Let the robot win.
            --Captain James T. Vader



I was going to laugh at this, then I remembered the last time I did a lot of rack mounting (i.e. the physical task) and how little it took for the Phillips screws to strip.

Granted, I think I prefer square to Torx, but yeah I don't disagree with this.

Thanks Ants
May 21, 2004

#essereFerrari


I hate the Pozi bolts as well, but you can put so much force through a torx that I'd be concerned about people giving it the beans and damaging the equipment and/or stripping the threads out of the rack.

When I racked a load of stuff a while ago I used hex head bolts, because people seem to always have allen keys, and they cam out before a torx would.

H110Hawk
Dec 28, 2006

Thanks Ants posted:

I hate the Pozi bolts as well, but you can put so much force through a torx that I'd be concerned about people giving it the beans and damaging the equipment and/or stripping the threads out of the rack.

When I racked a load of stuff a while ago I used hex head bolts, because people seem to always have allen keys, and they cam out before a torx would.

That's why you use caged nuts and give people a slip clutch on the drill. I have nothing against posi, just I am having to slum it with a #3 philips because I don't have posi bits. I'm not even supposed to have philips bits.

Super Soaker Party! posted:

I was going to laugh at this, then I remembered the last time I did a lot of rack mounting (i.e. the physical task) and how little it took for the Phillips screws to strip.

Granted, I think I prefer square to Torx, but yeah I don't disagree with this.

Or fall off the bit into the great beyond, or get overtorqued, or circle-bitted, or :suicide:

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin
Just use a Phillips on those. Pozi is Japanese for Phillips.

Sickening
Jul 16, 2007

Black summer was the best summer.
I haven't had an issue with the screws that have come with anything I have racked myself.
:shrug:

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


They're different heads and the reason every single one I am not the first person to get to is totally hosed up is because they are close enough that the wrong screwdriver works on them.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply