Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
crazysim
May 23, 2004
I AM SOOOOO GAY
It's also an hourly thing too.

$5/mo is the hourly rate over a month. If you only keep the algo box up for 7 days or some hours, you only pay for that much. Blow away the box when you don't need the VPN. Also, the Algo thing has a one-button deploy to DO button thing as well.

Adbot
ADBOT LOVES YOU

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug
speaking of VPN, anyone have a FIPS 140-2 supported virtual appliance endpoint for aws govcloud? Our F5 is a tire fire that doesn't segregate traffic properly like it's supposed to and crashes on the reg after we apply the STIG. There aren't a lot of options in this space; we'd love to use openvpn but even though they have an open pull request which adds it, it hasn't been merged into the main branch and openvpn.net refuses to support.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
christ, F5.

im sorry. no further insight. but im sorry

Powered Descent
Jul 13, 2008

We haven't had that spirit here since 1969.

Lysidas posted:

i understand the appeal of buying a box but i would recommend just paying $5/month for a cloud vps like from digital ocean or wherever, setting up algo, generating keys for everyone and sending the .mobileconfig profiles to any ios devices

works great for services out of the country, though it would not be hard for things to start noticing "this ip is in the digital ocean/aws/azure/whatever" block, not a residential connection, so it could easily stop working at any time

my mom got a ton of use out of it for history channel and pandora on her ipad when on vacation

i've done the same thing but more half-assed: no vpn, just an ssh tunnel to the vps (or to a box at home), and a socks proxy in the browser.

which reminds me, does iOS let you do ssh tunnels yet? i haven't played around with an iphone/ipad in quite some time, but when i last did, it sure seemed like they really didn't want you coloring outside the lines like that.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I finally got an answer why Symantec SEP admin console is so dogshit and its because instead of making a real HTML console what they're doing is rendering a native java session locally on the server itself and then doing some kind of remote composed view through http and if you do something like resize the window it samples all the redraw events at some set interval and queues them up against the server, but since its slow as dogshit you get stuck watching a slideshow for the next 2 minutes as it works through the queue

graph
Nov 22, 2006

aaag peanuts

BangersInMyKnickers posted:

Symantec SEP admin console

a huge piece of garbage lol

Shame Boy
Mar 2, 2010

so the mikrotik box I have (the hEX) uses this SoC:

https://wikidevi.com/wiki/MediaTek_MT7621

which is dual core / quad thread and has "HW Crypto Engine 200Mbps IPSec throughput", whatever that means

i paid like $50 for it and from personal experience it runs my vpn "fine" so :shrug:

e: on the mikrotik site it says "IPsec hardware encryption (~470 Mbps)" so either it uses both cores at once or they're lying lol

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

graph posted:

a huge piece of garbage lol

I've been forced to reverse engineer pretty much the entire application stack because their support is miserable and useless. Rule of thumb now is to just assume the dumbest, laziest possible way to solve a problem and that's what they did, but even then they've surprised me a few times

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

so the mikrotik box I have (the hEX) uses this SoC:

https://wikidevi.com/wiki/MediaTek_MT7621

which is dual core / quad thread and has "HW Crypto Engine 200Mbps IPSec throughput", whatever that means

i paid like $50 for it and from personal experience it runs my vpn "fine" so :shrug:

e: on the mikrotik site it says "IPsec hardware encryption (~470 Mbps)" so either it uses both cores at once or they're lying lol

Its usually rated by aggregate throughput, 200mbit on a single stream for an arm cpu with aes-ni seems about right

flakeloaf
Feb 26, 2003

Still better than android clock

BangersInMyKnickers posted:

I finally got an answer why Symantec SEP admin console is so dogshit and its because instead of making a real HTML console what they're doing is rendering a native java session locally on the server itself and then doing some kind of remote composed view through http and if you do something like resize the window it samples all the redraw events at some set interval and queues them up against the server, but since its slow as dogshit you get stuck watching a slideshow for the next 2 minutes as it works through the queue

symantec, sponsored by lance armstrong: try it and you'll see why i'm using epo

Shame Boy
Mar 2, 2010

i just noticed chome now reports RSA as obsolete:

quote:

Connection - obsolete connection settings
The connection to this site uses TLS 1.2 (a strong protocol), RSA (an obsolete key exchange), and AES_128_GCM (a strong cipher).

it doesn't flag the connection as "not secure" or anything so it's not really a big deal but yeah. when did that start happening?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Shame Boy posted:

i just noticed chome now reports RSA as obsolete:


it doesn't flag the connection as "not secure" or anything so it's not really a big deal but yeah. when did that start happening?

Anything non-ephemeral is old garbage that belongs in the dumpster

spankmeister
Jun 15, 2008






Agreeing with sausagepants

30 TO 50 FERAL HOG
Mar 2, 2005



Shaggar posted:

I like sophoses for the most part but they also require a subscription for features which is why used ones are cheap. you can run their vm version for personal use for free if you want to tho.

ssl vpn doesnt require a license, i dont think

edit:

yea

code:
Base Firewall
A perpetual Base Firewall license is included in the purchase price of every XG Series appliance.
The Base Firewall includes:
• Network Firewall
• SSL and IPSec VPN (no renewal required but IPSec client licenses are sold separately)
• Complete wireless protection, incl. hotspot support and voucher system

30 TO 50 FERAL HOG fucked around with this message at 20:15 on Oct 15, 2018

evil_bunnY
Apr 2, 2003

Shame Boy posted:

so the mikrotik box I have (the hEX) uses this SoC:

https://wikidevi.com/wiki/MediaTek_MT7621

which is dual core / quad thread and has "HW Crypto Engine 200Mbps IPSec throughput", whatever that means

i paid like $50 for it and from personal experience it runs my vpn "fine" so :shrug:

e: on the mikrotik site it says "IPsec hardware encryption (~470 Mbps)" so either it uses both cores at once or they're lying lol

Unless it specifies a cypher throughput means precisely fuckall

Soricidus
Oct 21, 2010
freedom-hating statist shill

BangersInMyKnickers posted:

Anything non-ephemeral is old garbage that belongs in the dumpster

pretty much yeah

it’s not that rsa is broken, exactly; unless you’re using a stupidly small key size, it’s only breakable in cases where an adversary is recording your sessions and might be able to obtain the server’s private key in future.* but there’s just no reason to choose it now that everything worth using supports well-studied alternatives that don’t have that flaw, and google’s sensible policy is to deprecate things aggressively in such cases

* or has the key already, but in that case the server is compromised and you’re hosed whatever cipher you use

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

evil_bunnY posted:

Unless it specifies a cypher throughput means precisely fuckall

If the hardware supports aes-ni then they are usually accurate. RC4 might be faster but its dead and nobody is using it for there benchmarks, and 3DES is slow compared to modern AES implementations. It's assuredly assuming a best-case scenario of ESP/UDP transport, with proper windowing and no fragmentation problems, and probably 128bit in GCM mode, but that's still a reasonable implementation.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

BangersInMyKnickers posted:

I finally got an answer why Symantec SEP admin console is so dogshit and its because instead of making a real HTML console what they're doing is rendering a native java session locally on the server itself and then doing some kind of remote composed view through http and if you do something like resize the window it samples all the redraw events at some set interval and queues them up against the server, but since its slow as dogshit you get stuck watching a slideshow for the next 2 minutes as it works through the queue

This is a fractal of horrible decisions, and I had to reread this three times to understand what was happening.

Your console is performance art, :five:

post hole digger
Mar 21, 2011

Stabby McDamage posted:

A colleague showed me this today. Apparently huge numbers of database passwords are available in plaintext via google, particularly for users of certain ~PHP FRAMEWORKS~.

https://www.google.com/search?q=production+db_password+filetype%3Aenv+inurl%3Acom

oh my.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
Re vpn: get a ubiquiti er-x and run lochnair's build of wireguard on it. Can do tens of mbps without breaking a sweat, more than enough for streaming video

Wiggly Wayne DDS
Sep 11, 2010



finally
https://twitter.com/agl__/status/1051933087699881984

hobbesmaster
Jan 28, 2008

anthonypants posted:

more importantly, if a router/firewall advertises itself as a vpn endpoint, but its marketing documentation doesn't mention aes-ni, go somewhere else

lol forever at insisting on x86 for this

Mustache Ride
Sep 11, 2001



Rufus Ping posted:

Re vpn: get a ubiquiti er-x and run lochnair's build of wireguard on it. Can do tens of mbps without breaking a sweat, more than enough for streaming video

Does Wireguard have an iOS version that isn't horribly broken?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
No, i missed the part about him using an ipad

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


our security department are running a "design the best phishing mail" competition, thanks to this thread I've added in dumb poo poo like odd characters in urls to make them look legit and even added a dumb word macro document to it that I was briefly extremely tempted to try to get to pop calc.exe before I realised they probably wouldn't appreciate that.

Raere
Dec 13, 2007

Powerful Two-Hander posted:

our security department are running a "design the best phishing mail" competition, thanks to this thread I've added in dumb poo poo like odd characters in urls to make them look legit and even added a dumb word macro document to it that I was briefly extremely tempted to try to get to pop calc.exe before I realised they probably wouldn't appreciate that.

best as in most likely to get people to click or best as in the coolest looking?

Mustache Ride
Sep 11, 2001



I did a "Such and such CIO has shared a document on OneDrive" that got a 98% click rate and a 75% creds in PhishMe when we started an O365 migration a few years ago.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

evil_bunnY posted:

Unless it specifies a cypher throughput means precisely fuckall

the best rfc posted:

2.4. Performance

The NULL encryption algorithm is significantly faster than other
commonly used symmetric encryption algorithms and implementations of
the base algorithm are available for all commonly used hardware and
OS platforms.

it's valid IPSec and beats out all the competition on performance

post hole digger
Mar 21, 2011

Oracle... your software... woof

https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html

we use oracle db

quote:

Oracle Database Server Executive Summary
This Critical Patch Update contains 3 new security fixes for the Oracle Database Server. All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. None of these fixes are applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed.
The highest CVSS Base Score of vulnerabilities affecting Oracle Database Server is 9.8
The Oracle Database Server components affected by vulnerabilities that are fixed in this Critical Patch Update are:
Java VM
Oracle Text
Portable Clusterware
:psyduck:

spankmeister
Jun 15, 2008






Just another Oracle CPU. There's usually a couple very bad vulnerabilities.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Raere posted:

best as in most likely to get people to click or best as in the coolest looking?

it was unclear but I went for "most likely to get clicked" and faked up a "you have outstanding training" mail which is the sort of thing we get spammed with by hr

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

Powerful Two-Hander posted:

it was unclear but I went for "most likely to get clicked" and faked up a "you have outstanding training" mail which is the sort of thing we get spammed with by hr

“Your it ticket has been updated, click here to see it now”

evil_bunnY
Apr 2, 2003

BangersInMyKnickers posted:

If the hardware supports aes-ni then they are usually accurate. RC4 might be faster but its dead and nobody is using it for there benchmarks, and 3DES is slow compared to modern AES implementations. It's assuredly assuming a best-case scenario of ESP/UDP transport, with proper windowing and no fragmentation problems, and probably 128bit in GCM mode, but that's still a reasonable implementation.
Oh yeah you're totally right, that old stuff isn't relevant. My B.

anatoliy pltkrvkay posted:

it's valid IPSec and beats out all the competition on performance
:hmmyes:

evil_bunnY fucked around with this message at 09:00 on Oct 16, 2018

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

Powerful Two-Hander posted:

it was unclear but I went for "most likely to get clicked" and faked up a "you have outstanding training" mail which is the sort of thing we get spammed with by hr

they did one at my firm a while ago that was from someone in hr with subject line "salary review - DO NOT SHARE" with a plausible-looking sharepoint link, followed up immediately with a "<x> wishes to recall this message" and a few minutes later with an email saying that it had been sent by mistake, contained confidential information, should be deleted immediately, and opening it may be a disciplinary matter. something like 85% success rate.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Boiled Water posted:

“Your it ticket has been updated, click here to see it now”

“option grant requires confirmation”

Bulgakov
Mar 8, 2009


рукописи не горят

please login for a chance to participate in the company wide security contest for best phishing exercise

first place $100 applebees gift card

Hed
Mar 31, 2004

Fun Shoe

goddamnedtwisto posted:

they did one at my firm a while ago that was from someone in hr with subject line "salary review - DO NOT SHARE" with a plausible-looking sharepoint link, followed up immediately with a "<x> wishes to recall this message" and a few minutes later with an email saying that it had been sent by mistake, contained confidential information, should be deleted immediately, and opening it may be a disciplinary matter. something like 85% success rate.

:dukedog: drat that’s how it’s done.

~Coxy
Dec 9, 2003

R.I.P. Inter-OS Sass - b.2000AD d.2003AD

Powered Descent posted:

i've done the same thing but more half-assed: no vpn, just an ssh tunnel to the vps (or to a box at home), and a socks proxy in the browser.

which reminds me, does iOS let you do ssh tunnels yet? i haven't played around with an iphone/ipad in quite some time, but when i last did, it sure seemed like they really didn't want you coloring outside the lines like that.

ios will obey a .pac file so you can tunnel web traffic through a SOCKS proxy but some apps are just gonna connect direct without the proxy

Doom Mathematic
Sep 2, 2008

goddamnedtwisto posted:

they did one at my firm a while ago that was from someone in hr with subject line "salary review - DO NOT SHARE" with a plausible-looking sharepoint link, followed up immediately with a "<x> wishes to recall this message" and a few minutes later with an email saying that it had been sent by mistake, contained confidential information, should be deleted immediately, and opening it may be a disciplinary matter. something like 85% success rate.

Was it genuinely from someone in HR? I never know what to do if my phishing threat model is meant to include other people inside my own organization.

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Bulgakov posted:

please login for a chance to participate in the company wide security contest for best phishing exercise

first place $100 applebees gift card

lol

  • Locked thread