Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Shame Boy
Mar 2, 2010

BangersInMyKnickers posted:

I prefer quad9 for some amount of malicious domain filtering

Your ISPs local DNS resolver might be a bit faster than google/cloudflare/ibm/whatever, you can benchmark your options if you want https://www.grc.com/dns/benchmark.htm

my ISP's local resolver also hijacks not-found domains to display "helpful" ad pages search pages so that's straight out

never heard of quad9, i'll check it out thanks

Adbot
ADBOT LOVES YOU

Shaggar
Apr 26, 2006

CommieGIR posted:

PLCs and most SCADA/Industrial Automation has little to nothing in the way of actual security, and tends to utilize outdated OSs and Software to handle the backend.

Right now, the best way to secure a PLC/SCADA network is to not let it touch the internet or corporate network. At all.

the problem is one of the big benefits of those systems is realtime monitoring so you need access to that data from outside the control network. this means you cant totally airgap the system and you need to setup some kind of gateway between your control and operations networks. the goal is to limit what can get in and out.

remote vendor access for maintenance is a whole other thing and in that case you tell them to pound sand and send someone out.

Shaggar fucked around with this message at 15:26 on Apr 3, 2019

Shaggar
Apr 26, 2006

Shame Boy posted:

my ISP's local resolver also hijacks not-found domains to display "helpful" ad pages search pages so that's straight out

never heard of quad9, i'll check it out thanks

TWC used to do this, but it looks like after spectrum bought them they don't anymore? atleast according to that test. I ended up setting 1.1.1.1 and some other server on my unifi gateway and now its like 15 ms faster than my isp for uncached responses!!

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Shaggar posted:

the problem is one of the big benefits of those systems is realtime monitoring so you need access to that data from outside the control network. this means you cant totally airgap the system and you need to setup some kind of gateway between your control and operations networks. the goal is to limit what can get in and out.

remote vendor access for maintenance is a whole other thing and in that case you tell them to pound sand and send someone out.

The solution for some systems is to setup a seperate Monitor Only network that has no connection to the PLCs, a lot of power companies do this with remote Substations: All you can do is monitor, and if something needs to actually happen, someone has to be sent out.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

CmdrRiker posted:

For those of us not in infosec and are just the regular programmers that are super annoying about security, why is it a joke?

e: My security training is self taught from reading the owasp wiki, pci compliance docs, reading code changes for security patches, and constantly trying to break my own code. Any other sources I should know about?

For the most part the industry is 10+ years behind everyone else, they typically run networks like some lovely SOHO environment from the mid-00's.

Monolithic flat lan with no redundancy or segregation/flood control? Check.
Border firewall with an un-monitored and weak VPN service? Check.
Absolutely no logging or log analytics? Check.
Border firewall configured with a default outbound allow-all rule? Check.
Running on commodity OS's without any hardening beyond a lovely AV install? Check.
Patched? Probably not.
Host firewalls? Disabled.
Default vendor credentials that have never been rotated? You better believe it.

You basically have a single protection layer of a border firewall with inbound deny rules but even that is often misconfigured and the second you're through that there's practically no protection or detection mechanisms left and an attacker can go loving hog wild on the place.

BangersInMyKnickers fucked around with this message at 15:37 on Apr 3, 2019

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

CommieGIR posted:

The solution for some systems is to setup a seperate Monitor Only network that has no connection to the PLCs, a lot of power companies do this with remote Substations: All you can do is monitor, and if something needs to actually happen, someone has to be sent out.

Yeah, we started asking around for NERC-compliant facilities that use any of the vendors' remote access solutions and it was absolute crickets. At least the IT people that are running the large scale plants know enough that the border firewall is their only truly effective control and they refuse to compromise it. Our solution has been to dump the remote access appliances in the DMZ and firewall them off to the point that only the monitoring functionality works.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/GalaxyKate/status/1113315381697949696

I laughed

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
the term "gender reveal" is pretty loving stupid for obvious reasons

ewiley
Jul 9, 2003

More trash for the trash fire

BangersInMyKnickers posted:

For the most part the industry is 10+ years behind everyone else, they typically run networks like some lovely SOHO environment from the mid-00's.

Monolithic flat lan with no redundancy or segregation/flood control? Check.
Border firewall with an un-monitored and weak VPN service? Check.
Absolutely no logging or log analytics? Check.
Border firewall configured with a default outbound allow-all rule? Check.
Running on commodity OS's without any hardening beyond a lovely AV install? Check.
Patched? Probably not.
Host firewalls? Disabled.
Default vendor credentials that have never been rotated? You better believe it.

You basically have a single protection layer of a border firewall with inbound deny rules but even that is often misconfigured and the second you're through that there's practically no protection or detection mechanisms left and an attacker can go loving hog wild on the place.

Oh and you can't ever scan it with a vuln scanner or run effective pen tests because half of the stuff will poo poo the bed and shut down a production line costing $$$/hour losses.

flakeloaf
Feb 26, 2003

Still better than android clock


:same:

ymgve
Jan 2, 2004


:dukedog:
Offensive Clock
the best way to monitor SCADA is to have it display on a screen locally, then have a webcam on a completely different network pointed at the screen

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Chris Knight posted:

the term "gender reveal" is pretty loving stupid for obvious reasons

i'm the obvious reason

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Chris Knight posted:

the term "gender reveal" is pretty loving stupid for obvious reasons

invite your friends and family to a gender reveal party and it's just a presentation about how gender is a social construct and distinct from biological sex

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
click here to request a gender reset email

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
scada bad because availability is one of the CIA services and the only one that mattered in industrial controls prior to computerization (confidentiality and integrity were provided by the building and not people touching the process)

flakeloaf
Feb 26, 2003

Still better than android clock

well of course there was a male goose inside the cake, didn't you fuckers read the card

Main Paineframe
Oct 27, 2010

gotta admit, I didn't think FB would be this blatant

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Meat Beat Agent posted:

click here to request a gender reset email

i laughed

haveblue
Aug 15, 2005



Toilet Rascal
your gender must be at least eight characters long and contain a number

evil_bunnY
Apr 2, 2003

ymgve posted:

the best way to monitor SCADA is to have it display on a screen locally, then have a webcam on a completely different network pointed at the screen
unironically agree.

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

ymgve posted:

the best way to monitor SCADA is to have it display on a screen locally, then have a webcam on a completely different network pointed at the screen

would hooking a VGA cable into a KVM-over-IP box be acceptable? suppose you could rip out the E-DDC pins if you're concerned about somehow hacking over VGA

pseudorandom name
May 6, 2007

Main Paineframe posted:

gotta admit, I didn't think FB would be this blatant

hey, it worked (briefly) for LinkedIn

CmdrRiker
Apr 8, 2016

You dismally untalented little creep!

Shame Boy posted:

that subtitle reminds me of this for some reason:



I feel like that subtitle gets me. I want it as my epitaph.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

ymgve posted:

the best way to monitor SCADA is to have it display on a screen locally, then have a webcam on a completely different network pointed at the screen

There's a couple Shodan feeds Ive seen like that

Soricidus
Oct 21, 2010
freedom-hating statist shill

Cocoa Crispies posted:

invite your friends and family to a gender reveal party and it's just a presentation about how gender is a social construct and distinct from biological sex

"sex reveal party" sounds like something rather different

Shaggar
Apr 26, 2006

haveblue posted:

your gender must be at least eight characters long and contain a number

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

haveblue posted:

your gender must be at least eight characters long and contain a number

Sorry, someone else has already chosen this gender, please try again.

The gender and confirm gender fields must match, please try again.

pseudorandom name
May 6, 2007

your gender may not contain SELECT or ;

Phone
Jul 30, 2005

親子丼をほしい。
your gender is too similar to a previously used gender

Proteus Jones
Feb 28, 2013



If you've forgotten your gender, please click this button to have a temporary gender assigned.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe
your gender has expired, please enter a new one

Soricidus
Oct 21, 2010
freedom-hating statist shill
forums hacked, 1.5m unencrypted genders for sale on dark web

Shame Boy
Mar 2, 2010

Proteus Jones posted:

If you've forgotten your gender, please click this button to have a temporary gender assigned.

you'll be asked to present as one of your security genders first

pseudorandom name
May 6, 2007

Please consult your Autheticator application for your time-limited temporary gender.

flakeloaf
Feb 26, 2003

Still better than android clock

something you have and something you are could be two different factors

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
Sorry, that gender is too common. Please pick something else.

My Linux Rig
Mar 27, 2010
Probation
Can't post for 6 years!

Wiggly Wayne DDS posted:

i thought teslas set themselves on fire to avoid this data loss problem

they also veer the car into trucks as a brave new strategy where the user will never have to worry about their data being stolen cause they’ll be dead

Midjack
Dec 24, 2007



gender strength: good

mystes
May 31, 2006

Shifty Pony posted:

apparently if you have an adblocker running it shows a phone verification page instead.
That's smart; that way surely the people who would know that this is bad will never find out!

Also, trying to hide stuff always looks good when you're caught and try to pretend you didn't know it was bad.

Adbot
ADBOT LOVES YOU

Soricidus
Oct 21, 2010
freedom-hating statist shill

flakeloaf posted:

something you have and something you are could be two different factors

:golfclap:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply