Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Rust Martialis
May 8, 2007

by Fluffdaddy

(and can't post for 9 hours!)

BangersInMyKnickers posted:

Clearly lying to auditors is the most viable and prudent path forward

Then the FDA "hi you can't make more drugs now til you fix this poo poo" catches you. :/

Adbot
ADBOT LOVES YOU

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Sounds like someone is pretty bad at lying

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


We have a government project that forbids us from using encryption between internal endpoints because they want to be able to inspect the traffic.

The best was when they wanted auth only to be encrypted for something, but the actual communication needed to be in clear text. Ensuring the secrecy of the credentials was more important than ensuring the integrity of the data those credentials were protecting.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


bull3964 posted:

We have a government project that forbids us from using encryption between internal endpoints because they want to be able to inspect the traffic.

The best was when they wanted auth only to be encrypted for something, but the actual communication needed to be in clear text. Ensuring the secrecy of the credentials was more important than ensuring the integrity of the data those credentials were protecting.

Well it's important to prove that you could encrypt it if you wanted to.

CLAM DOWN
Feb 13, 2007




Rust Martialis posted:

Any Tenable Nessus users here using it to report compliance to templates from Security Center? Either roll-your-own, or the canned templates (SOX, PCI DSS, HIPPA/HITECH, etc.). Looking for good/bad reviews before I try to force security to devote project hours.

Thx

We did this in Tenables and it worked fine, we rolled our own templates for CSOX and a few others.

Catatron Prime
Aug 23, 2010

IT ME



Toilet Rascal
Anyone else here signed up for Kringlecon this year? The recorded talks are pretty good, definitely worth checking out if you weren't previously aware of it.


...that is all... :ninja:

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

bull3964 posted:

We have a government project that forbids us from using encryption between internal endpoints because they want to be able to inspect the traffic.

The best was when they wanted auth only to be encrypted for something, but the actual communication needed to be in clear text. Ensuring the secrecy of the credentials was more important than ensuring the integrity of the data those credentials were protecting.

Eh, as long as you're including some kind of signed digest for the data, and the data isn't something that needs to be secret, it's crazy but not THAT crazy.

There's no digest, I'm sure.

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.
Happy birthday, everyone. :v:

Catatron Prime
Aug 23, 2010

IT ME



Toilet Rascal

TinTower posted:

Happy birthday, everyone. :v:

Wow, you were also born January first 1900? That’s amazing! Thought I was the only one :ninja:

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.

OSU_Matthew posted:

Wow, you were also born January first 1900? That’s amazing! Thought I was the only one :ninja:

I think some of us are 70 years younger than that. :haw:

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
Man I really hope Trump signs that executive order banning Huawei equipment in the US. Connected to a Huawei network before connecting to a VPN like an idiot while travelling and the phishing texts and emails were nearly instantaneous.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


TinTower posted:

Happy birthday, everyone. :v:

Okay, that one took me a while :mmmhmm:

Lambert
Apr 15, 2018

by Fluffdaddy
Fallen Rib

The Iron Rose posted:

Man I really hope Trump signs that executive order banning Huawei equipment in the US. Connected to a Huawei network before connecting to a VPN like an idiot while travelling and the phishing texts and emails were nearly instantaneous.

There's unlikely to be any connection, this sounds like nonsense. Unless you're using unencrypted communication, and in that case I don't think you'd need to be concerned about Huawei.

Lambert fucked around with this message at 12:03 on Jan 2, 2019

BlankSystemDaemon
Mar 13, 2009




Cup Runneth Over posted:

Okay, that one took me a while :mmmhmm:
I apparently have a huge case of the dumbs, because I have no idea.

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

D. Ebdrup posted:

I apparently have a huge case of the dumbs, because I have no idea.

When you register an account that doesn’t matter, do you give your real DOB or do you fake it? What is the easiest fake to enter?

BlankSystemDaemon
Mar 13, 2009




PCjr sidecar posted:

When you register an account that doesn’t matter, do you give your real DOB or do you fake it? What is the easiest fake to enter?
loving hell I feel even dumber now! :v:
That's a pretty good joke, too.

Truga
May 4, 2014
Lipstick Apathy
at one point, steam said something like 90% of its users has a 1/1 birthday lmao

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

4/20/69 baby

Docjowles
Apr 9, 2009


hell, same

CLAM DOWN
Feb 13, 2007





Lmao I'm glad I'm not the only one who does this one

Docjowles
Apr 9, 2009

CLAM DOWN posted:

Lmao I'm glad I'm not the only one who does this one

I'm worried about the maniacs who don't do this

Mystic Stylez
Dec 19, 2009

I'm going to ask some very dumb questions, but please bear with me.

I'm currently working from home, so my boss installed OpenVPN in order for me to be able to access all the documents that are hosted in the company's server.

Whenever I'm connected through OpenVPN to access those work files, can he see anything that I do in my computer at all? Like, which websites I'm browsing right now or my browser traffic, for example. Or any other stuff that's personal like my computer files, etc.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Mystic Stylez posted:

I'm going to ask some very dumb questions, but please bear with me.

I'm currently working from home, so my boss installed OpenVPN in order for me to be able to access all the documents that are hosted in the company's server.

Whenever I'm connected through OpenVPN to access those work files, can he see anything that I do in my computer at all? Like, which websites I'm browsing right now or my browser traffic, for example. Or any other stuff that's personal like my computer files, etc.

This is going to depend on how the routing table and dns is configured for the tunnel.

If its configured for full tunnel then everything is going to be bounced through your work and then out to the internet. A trace route to some common website can probably confirm this.
The content itself (youre poasts) will be encrypted over https in most cases, but other things like the SNI header for the website name or the DNS requests you used to get there could end up being logged on their end.
Even if it isn't a full-tunnel configuration, your DNS requests are most likely going through their corporate servers which will be plaintext and loggable. You can somewhat protect for that by using DNS over HTTPS if your browser supports it https://en.wikipedia.org/wiki/DNS_over_HTTPS
A TOR browser might be another viable option though it will probably set off some flags on common security software.
It may be possible that file shares on your system become exposed on the corporate network when you are connected. Again, depends on the config. If you're giving anonymous/everyone groups permissions to file shares then assume that is exposed.

Mystic Stylez
Dec 19, 2009

BangersInMyKnickers posted:

This is going to depend on how the routing table and dns is configured for the tunnel.

If its configured for full tunnel then everything is going to be bounced through your work and then out to the internet. A trace route to some common website can probably confirm this.
The content itself (youre poasts) will be encrypted over https in most cases, but other things like the SNI header for the website name or the DNS requests you used to get there could end up being logged on their end.
Even if it isn't a full-tunnel configuration, your DNS requests are most likely going through their corporate servers which will be plaintext and loggable. You can somewhat protect for that by using DNS over HTTPS if your browser supports it https://en.wikipedia.org/wiki/DNS_over_HTTPS
A TOR browser might be another viable option though it will probably set off some flags on common security software.
It may be possible that file shares on your system become exposed on the corporate network when you are connected. Again, depends on the config. If you're giving anonymous/everyone groups permissions to file shares then assume that is exposed.

I'm very illiterate when it comes to those things so I guess I don't really follow you.

How can I do a trace route (if I actually can) to confirm if it's a full tunnel?

When you say file shares, what exactly are those? Because when I click on Network on File Explorer, it says "file sharing is turned off", is that enough?

What I meant by access my files is things that are in normal folders in my computer's HD.

E: VVVVVVVVVV Midgets, obviously.

Mystic Stylez fucked around with this message at 15:05 on Jan 3, 2019

Sickening
Jul 16, 2007

Black summer was the best summer.

Mystic Stylez posted:

I'm going to ask some very dumb questions, but please bear with me.

I'm currently working from home, so my boss installed OpenVPN in order for me to be able to access all the documents that are hosted in the company's server.

Whenever I'm connected through OpenVPN to access those work files, can he see anything that I do in my computer at all? Like, which websites I'm browsing right now or my browser traffic, for example. Or any other stuff that's personal like my computer files, etc.

What porn are you watching this morning?

Thanks Ants
May 21, 2004

#essereFerrari


If you go to https://www.whatismyip.com when you're connected to the VPN, and again when you're off the VPN, are the addresses different?

If they are then you're probably in a full tunnel, which means everything can be inspected if it's clear text. If the addresses are the same then you're in a split tunnel but there's no guarantee that your DNS requests aren't being logged or another payload was deployed alongside the OpenVPN installer.

Mystic Stylez
Dec 19, 2009

Yeah it's the same IP whether I'm connected to the VPN or not, which I guess is a little better?

If my DNS requests are being logged and poo poo, is it really easy to check that I'm shitposting at the SOMETHINGAWFULDOTCOMFORUMS or playing Solitaire on Steam or whatever, or would he have to go through some poo poo to check? I don't think he can be arsed to do those things/really cares, but anyway.

Mystic Stylez fucked around with this message at 15:41 on Jan 3, 2019

Docjowles
Apr 9, 2009

It really depends how much of a poo poo he gives. He could have made it very easy for himself to spy on everyone, or he may not be logging anything at all. We have no way of knowing this.

If you are seriously worried about it, just disconnect from the VPN when you need to watch weird rear end porn shitpost on SA. Or request work to provide you with a dedicated machine at their expense so you aren't having to use your personal equipment for their benefit. Assuming openvpn is the only thing you've installed, work will have no visibility into what you did while not on the VPN. It's not queuing up a big report of all your misdeeds to phone home with the next time you connect.

And if they did have you install some kind of tracking software on your personal machine that reports back, especially without your consent, that is ethically terrible and legally dubious.

Docjowles fucked around with this message at 15:59 on Jan 3, 2019

Mystic Stylez
Dec 19, 2009

Yeah, he actually came home and installed it right by my side, it was only OpenVPN. He's actually very cool, so I doubt he would do such things. It's just something to keep me at ease. Thanks for the help, guys!

e: VVV lol

Mystic Stylez fucked around with this message at 16:20 on Jan 3, 2019

CLAM DOWN
Feb 13, 2007




Mystic Stylez posted:

Yeah, he actually came home and installed it right by my side, it was only OpenVPN. He's actually very cool, so I doubt he would do such things. It's just something to keep me at ease. Thanks for the help, guys!

....your boss came to your home and you let him onto your personal computer to install stuff??

Mustache Ride
Sep 11, 2001



Dude get a different computer for work and personal stuff. If something happens in that company there's a possibility they can take your personal computer and do scary forensics on it.

Does work have the option to assign you a computer? Can you buy a cheap Chromebook to watch your Midget Porn on?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Mystic Stylez posted:

Yeah it's the same IP whether I'm connected to the VPN or not, which I guess is a little better?

If my DNS requests are being logged and poo poo, is it really easy to check that I'm shitposting at the SOMETHINGAWFULDOTCOMFORUMS or playing Solitaire on Steam or whatever, or would he have to go through some poo poo to check? I don't think he can be arsed to do those things/really cares, but anyway.

Since you confirmed its not a full tunnel, use Firefox with DNS over HTTPS for browsing and you should be good.

https://www.ghacks.net/2018/04/02/configure-dns-over-https-in-firefox/

DNS requests for things like steam might end up going through the work servers but since those are background services you have a fair amount of plausible deniability there.

Docjowles
Apr 9, 2009

Or just don't do non-work stuff while on the work vpn :shrug:

Mystic Stylez
Dec 19, 2009

It's not like I work for a gigantic company, it's a small business where the owner is a family friend and there's like three other employees. I don't live in the US or Europe. I use the VPN to access a bunch of .doc and .pdf files. I don't have the money to get another computer just to separate things right now, isn't just disconnecting from the VPN and exiting OpenVPN enough? I also don't think he would be upset because I'm browsing news sites during work hours or poo poo, the other employees that actually work there do that all the time.

BangersInMyKnickers posted:

Since you confirmed its not a full tunnel, use Firefox with DNS over HTTPS for browsing and you should be good.

https://www.ghacks.net/2018/04/02/c...tps-in-firefox/

DNS requests for things like steam might end up going through the work servers but since those are background services you have a fair amount of plausible deniability there.

Still this is good to know, thanks for being helpful!

CLAM DOWN
Feb 13, 2007




Mystic Stylez posted:

It's not like I work for a gigantic company, it's a small business where the owner is a family friend and there's like three other employees.

That does not make it okay. You have to cover your own rear end.

Mystic Stylez
Dec 19, 2009

CLAM DOWN posted:

That does not make it okay. You have to cover your own rear end.

So if I can get a separate computer with the VPN installed and only my work stuff there is it sufficient or do I need anything more?

Sickening
Jul 16, 2007

Black summer was the best summer.

Mystic Stylez posted:

So if I can get a separate computer with the VPN installed and only my work stuff there is it sufficient or do I need anything more?

Please make sure your work pays for this other computer.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Mystic Stylez posted:

So if I can get a separate computer with the VPN installed and only my work stuff there is it sufficient or do I need anything more?

That's the general idea.

Sickening posted:

Please make sure your work pays for this other computer.

A hundred thousand times this.

CLAM DOWN
Feb 13, 2007




Mystic Stylez posted:

So if I can get a separate computer with the VPN installed and only my work stuff there is it sufficient or do I need anything more?

Yup that's exactly what you should be doing, and your work should be paying for every cent of this. This is the normal thing to do, when you are required to log in remotely/work from home. Do not, repeat do not, pay for this 2nd computer yourself. Under any circumstance.

Adbot
ADBOT LOVES YOU

Mystic Stylez
Dec 19, 2009

OK, I'll see about that, again thanks for all the help, guys!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply