Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
Weedle
May 31, 2006




The headmaster sent a bulletin out to everyone outlining our plans for school closure in the event of an outbreak. Apparently we are prepared for extended remote learning, which is news to me and my department. Most teachers have desktops in the classroom and we don't yet know how many of those teachers have home computers they can use for remote instruction, but we have about a dozen unused laptops we can give out as needed. Hope that's enough!

Adbot
ADBOT LOVES YOU

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


2 cases confirmed in MI. CEO announcement at noon.

Kinda hoping I don't have to commute for the next month or so.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Well after reading more about covid-19, I am slightly worried, my wife has asthma and I have high blood pressure. I'm supposed to be traveling to the east coast in 3 weeks for work as well....

Wibla
Feb 16, 2011

MF_James posted:

Well after reading more about covid-19, I am slightly worried, my wife has asthma and I have high blood pressure. I'm supposed to be traveling to the east coast in 3 weeks for work as well....

Sounds like your trip is about to get cancelled!

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Wibla posted:

Sounds like your trip is about to get cancelled!

Probably, I told them to book refundable tickets, but we're in illinois which is seeing a bunch of cases so it might not matter anyway from an infection standpoint.

Weedle
May 31, 2006




I will absolutely get coronavirus in about ~2 weeks because of the brain genius parents who refuse to cancel their spring break cruises

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

Darchangel posted:

I'm desktop support, and a literal computer toucher, so can't WFH. I'm also a contractor, so, that's... good, I guess.
Of course, our AV Lab team is talking about WFH, and for some reason that's going to require me to build 23 temporary laptops for them. I still can't get a clear answer why, but my manager seems satisfied with making me and the guy who builds out images (because of course they need bespoke special snowflake loadouts) waste our time building these things. Eh, ain't my budget. Don't want to hear about slow response to tickets, though. Gonna make sure they get the crappiest old laptops I can find. I think I have some Lenovo T420s and Dell 6400s still hanging around for some reason...
Did I mention that every employee in this company has a laptop already?
I *think* these machines are so they can remote into their lab "infect" box, which is exposed to the internet.

Oh, and confirmed cases of COVID-19 in the state I live in. And county. :ohdear:


The last part answers your question :v:. Working off dedicated laptops is more secure than god-knows-what might be lurking on random home computers, I guess.

Oyster
Nov 11, 2005

I GOT FLAT FEET JUST LIKE MY HERO MEGAMAN
Total Clam

AlexDeGruven posted:

2 cases confirmed in MI. CEO announcement at noon.

Kinda hoping I don't have to commute for the next month or so.

I'm out in west Michigan. Was told today that if we get it let our managers know and we'll get paid sick leave, if we don't let them know it'll be unpaid. Otherwise business as usual.

SixFigureSandwich
Oct 30, 2004
Exciting Lemon

MF_James posted:

Well after reading more about covid-19, I am slightly worried, my wife has asthma and I have high blood pressure. I'm supposed to be traveling to the east coast in 3 weeks for work as well....

The company I work for has prohibited all non-essential domestic and international travel, globally. Check with your line manager and/or HSSE person - don't be afraid to suggest the trip should be cancelled.

dragonshardz
May 2, 2017

An email came in.

:byodame: "Microsoft Access crashes with an error message that says System resource exceeded! Can someone reinstall it and make sure I have the latest patches?"
:sun: "What are you typically doing when you see this error message?"
:byodame: "Simple stuff like copying/pasting, running queries. The program may need to be reinstalled or is there a patch?"
:sun: "Are you having problems working with a specific Access file, or all files in general?"
:byodame: "I work with a few Access files and they are all doing it."
:sun: "Can you tell me what those Access files are, with the full file path and name?"

Ongoing but apparently this is the week of dumb questions.

wolrah
May 8, 2006
what?

CaptainJuan posted:

This article says it abuses accessibility privileges (screen reader, I assume) - what stops it from using those same privileges on the MS auth app?
It's possible to flag an app as "secure" which limits the ability other apps have to screenshot it or otherwise access it. Apparently the Google Authenticator does not have this flag set, and since it hasn't been updated in over two years it's assumed that they have no plans to change that.

The open source "AndOTP" app does have this (plus a few other nice features), as I understand it Authy and MS's app also do.

-edit-
I just tested because I haven't fully moved off Google Authenticator. On my unmodified OnePlus 6T running Android 10 even the standard Android screenshot feature has no problem grabbing an image of the Google Authenticator. Attempting to do the same with AndOTP resulted in a notification that the app had disabled screenshots.

I then attempted the "Snapchat trick" of switching to the app switcher and taking a screenshot there, but AndOTP cleared its window when it left the foreground so it was just a grey panel with an app title. Google Authenticator was, of course, still entirely visible.

It's also worth noting that Google Authenticator offers no internal protection, if someone manages to get a hold of your phone while unlocked they can access it all. Other apps offer the ability to encrypt their database and require additional authentication when you launch the app and/or switch back to it.

I don't really know any more advanced tricks to acquire data from another app that doesn't want you to, but if Google Authenticator fails these easy ones it's a pretty safe bet it's not protected against the more advanced stuff either.
-/edit-


The Fool posted:

Yeah, it's not an issue with the auth app specifically it's an issue with googles entire app ecosystem and how permissions are managed.
While I won't argue that the Android permissions model has a lot of issues (though it is much better in recent versions, the number of apps targeting older versions and devices that will never get an update limit how happy one can be with that), in this case the Google Authenticator app is specifically worse than basically any other TOTP app that's actively developed.

It's unfortunate because as far as I've found none of the other apps have a WearOS counterpart, and that's the main way I used it, but using an abandoned app for security functions is not good in any way.

Arquinsiel posted:

TBH having dug into how most 2FA solutions actually work in practice they are at best 1FA, but twice.

Then when you actually implement the good operation modes that don't render the user susceptible to just MITMing a session and changing the creds/2FA app the CEO just gets angry and hits "allow" to let the attacker into his emails.
Software TOTP type 2FA like this is still effective against attacks resulting from password reuse, shoulder surfing, keylogging, etc. Obviously if the device is compromised the software TOTP setup is likely to be compromised as well, but it still helps in a lot of cases.

A number of password managers these days offer a soft token functionality too, which if you were to use for a site that has the credentials stored in the same database would be effectively 1FA with extra steps, but even that works just as well for basically any scenario that doesn't involve the attacker having access to your password manager.

Given that the majority of users I deal with either memorize their passwords or put them on sticky notes within glancing distance of the monitor, properly using a password manager plus a soft token of any sort would still be a significant improvement.

For obvious reasons of course it'd be preferable to use hardware tokens or at least separate the password manager from the soft tokens for anything where a targeted attack is really plausible.

wolrah fucked around with this message at 19:30 on Mar 11, 2020

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

wolrah posted:

Software TOTP type 2FA like this is still effective against attacks resulting from password reuse, shoulder surfing, keylogging, etc. Obviously if the device is compromised the software TOTP setup is likely to be compromised as well, but it still helps in a lot of cases.

A number of password managers these days offer a soft token functionality too, which if you were to use for a site that has the credentials stored in the same database would be effectively 1FA with extra steps, but even that works just as well for basically any scenario that doesn't involve the attacker having access to your password manager.

Given that the majority of users I deal with either memorize their passwords or put them on sticky notes within glancing distance of the monitor, properly using a password manager plus a soft token of any sort would still be a significant improvement.

For obvious reasons of course it'd be preferable to use hardware tokens or at least separate the password manager from the soft tokens for anything where a targeted attack is really plausible.
I am salty about my phone provider who still insist on texting you a pin code despite being able to tell that you are contacting them via their app on the device matching the IMEI linked to your account using the data plan of the phone number you hold with them. Multiple factors ignored in favour of a plaintext broadcast over the air. It's one thing to take basic steps to shut out script kiddies, it's another entirely to undermine yourself like this. Of course both are moot if someone watches me unlocking my phone and then yoinks it, but that's an inevitable problem of concentrating authority into a single highly portable source of authority.

BlankSystemDaemon
Mar 13, 2009



dragonshardz posted:

An email came in.

:byodame: "Microsoft Access crashes with an error message that says System resource exceeded! Can someone reinstall it and make sure I have the latest patches?"
:sun: "What are you typically doing when you see this error message?"
:byodame: "Simple stuff like copying/pasting, running queries. The program may need to be reinstalled or is there a patch?"
:sun: "Are you having problems working with a specific Access file, or all files in general?"
:byodame: "I work with a few Access files and they are all doing it."
:sun: "Can you tell me what those Access files are, with the full file path and name?"

Ongoing but apparently this is the week of dumb questions.
But OP, that's every week!

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

dragonshardz posted:

An email came in.

:byodame: "Microsoft Access crashes with an error message that says System resource exceeded! Can someone reinstall it and make sure I have the latest patches?"
:sun: "What are you typically doing when you see this error message?"
:byodame: "Simple stuff like copying/pasting, running queries. The program may need to be reinstalled or is there a patch?"
:sun: "Are you having problems working with a specific Access file, or all files in general?"
:byodame: "I work with a few Access files and they are all doing it."
:sun: "Can you tell me what those Access files are, with the full file path and name?"

Ongoing but apparently this is the week of dumb questions.

I'm not even in a support role any more and I have to deal with X-Y problems almost daily.

Darchangel
Feb 12, 2009

Tell him about the blower!


Neddy Seagoon posted:

The last part answers your question :v:. Working off dedicated laptops is more secure than god-knows-what might be lurking on random home computers, I guess.

No it doesn't.
Every employee in this company has a laptop already. Why they need a second one for this is the question - however, new information is that some will be used for the AV threat research part of their jobs, which of course one wouldn't want to use a production machine for. Still doesn't explain the 9 "Production" machines in the mix, though.

dragonshardz posted:

An email came in.

:byodame: "Microsoft Access crashes with an error message that says System resource exceeded! Can someone reinstall it and make sure I have the latest patches?"
:sun: "What are you typically doing when you see this error message?"
:byodame: "Simple stuff like copying/pasting, running queries. The program may need to be reinstalled or is there a patch?"
:sun: "Are you having problems working with a specific Access file, or all files in general?"
:byodame: "I work with a few Access files and they are all doing it."
:sun: "Can you tell me what those Access files are, with the full file path and name?"

Ongoing but apparently this is the week of dumb questions.


Playing 20 questions is the main part of our jobs in any sort of end-user-facing support role.
Also, are you sure it doesn't need to be reinstalled or patched? :haw:

ChubbyThePhat posted:

I'm not even in a support role any more and I have to deal with X-Y problems almost daily.

Those, too.
I believe it was this thread, or the general "I work in IT" thread that taught me the term "X-Y Problem."

dragonshardz
May 2, 2017

Darchangel posted:

No it doesn't.
Every employee in this company has a laptop already. Why they need a second one for this is the question - however, new information is that some will be used for the AV threat research part of their jobs, which of course one wouldn't want to use a production machine for. Still doesn't explain the 9 "Production" machines in the mix, though.



Playing 20 questions is the main part of our jobs in any sort of end-user-facing support role.
Also, are you sure it doesn't need to be reinstalled or patched? :haw:


Those, too.
I believe it was this thread, or the general "I work in IT" thread that taught me the term "X-Y Problem."

As of when I left work for the day, I had two specific Access fuckpiles databases that :byodame: is having trouble with, and another user is also having trouble with those same fuckpiles databases.

So there's nothing wrong with Access. Their fuckpiles databases are breaking poo poo. Now I just have to figure out how to tell them that without making it enough of my problem that I have to bugfix their fuckpiles databases.

stevewm
May 10, 2005

dragonshardz posted:

As of when I left work for the day, I had two specific Access fuckpiles databases that :byodame: is having trouble with, and another user is also having trouble with those same fuckpiles databases.

So there's nothing wrong with Access. Their fuckpiles databases are breaking poo poo. Now I just have to figure out how to tell them that without making it enough of my problem that I have to bugfix their fuckpiles databases.

Ugh.... Microsoft Fuckpiles. How I don't miss it. A ERP/EDI/POS software we used to use was built entirely around a older version of it. Had to love the random database corruption when too many users connected. The real fun happened when we started to bump into the 2GB limit at some locations. Their "solution" was to split the database up into multiple files, putting a few tables into different files.

Access is fine for simple poo poo, but it always seems like someone's pet project eventually grows and gets turned into some massive pile of poo poo doing something Access was never meant to do.

It is much like some quoting software we currently use. It is built entirely as a gigantic Excel macro. They are doing poo poo in Excel I didn't think was possible.. Did you know you can render a perspective view of a building in Excel? I sure didn't, but they made it happen somehow. It takes more than a minute to do so and will completely peg a single core the entire time even on a modern system.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

stevewm posted:

Did you know you can render a perspective view of a building in Excel? I sure didn't, but they made it happen somehow. It takes more than a minute to do so and will completely peg a single core the entire time even on a modern system.

I knew this, much to my chagrin.

AlternateAccount
Apr 25, 2005
FYGM
Excel is easily, easily, the most tortured and abused piece of software ever created.

Sickening
Jul 16, 2007

Black summer was the best summer.

AlternateAccount posted:

Excel is easily, easily, the most tortured and abused piece of software ever created.

The office drone who can make spreadsheets have the most job security though.

TinTower
Apr 21, 2010

You don't have to 8e a good person to 8e a hero.
https://twitter.com/choplogik/status/1238246361239302144?s=21

GnarlyCharlie4u
Sep 23, 2007

I have an unhealthy obsession with motorcycles.

Proof

Darchangel posted:


Oh, and confirmed cases of COVID-19 in the state I live in. And county. :ohdear:

There's confirmed cases in all the counties surrounding my 2 square mile city.
Trust no one.

Sywert of Thieves
Nov 7, 2005

The pirate code is really more of a guideline, than actual rules.

Our boss just called an all-hands meeting to discuss COVID-19 handling. We're all supposed to lug our desktops home and use the VPN, instead of using remote viewing software, or laptops. I guess?

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


Another CEO announcement at 12:30 today.

IT folks were already told to WFH as of yesterday, but to plan on coming in on Monday. I have a feeling the announcement today, after the school closures and everything else, will be more along the lines of "Nah, gently caress that. Stay home if you can"

CaptainJuan
Oct 15, 2008

Thick. Juicy. Tender.

Imagine cutting into a Barry White Song.
A phishing attempt came in, to our desktop support manager..... Who proceeded to forward it, UNREDACTED, to company-all (as a "don't fall for this" warning).

Same thing happened two years ago btw. How is this man employed

MJP
Jun 17, 2007

Are you looking at me Senpai?

Grimey Drawer
Big shoutout to everyone here and all the homies not in this thread that aren't getting or won't be getting WFH, and/or have to deal with helpdesk or support stuff during this time. I can't imagine it's easy to deal with the influx of "my VPN no worky" crap, doubly so if they're still making you come into the office.

I will do all I can not to add to your burden from my end. Stout hearts, comrades.

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


Mandatory WFH through April 6th.

D34THROW
Jan 29, 2012

RETAIL RETAIL LISTEN TO ME BITCH ABOUT RETAIL
:rant:

dragonshardz posted:

An email came in.

:byodame: "Microsoft Access crashes with an error message that says System resource exceeded! Can someone reinstall it and make sure I have the latest patches?"
:sun: "What are you typically doing when you see this error message?"
:byodame: "Simple stuff like copying/pasting, running queries. The program may need to be reinstalled or is there a patch?"
:sun: "Are you having problems working with a specific Access file, or all files in general?"
:byodame: "I work with a few Access files and they are all doing it."
:sun: "Can you tell me what those Access files are, with the full file path and name?"

Ongoing but apparently this is the week of dumb questions.

I do Access as a work-related hobby and I want to hear the end of this :allears: I know Access is poo poo on a network, and Sharepoint lists don't offer nearly the same relational capabilities, and 2013 (at least) refuses to work with remotely stored files.

devmd01
Mar 7, 2006

Elektronik
Supersonik
No WFH policy yet but 90% of our employees provide support services to hospitals so lol.

Boss is WFH today so I hosed off work at 1030 to go drink with a former coworker. :getin:

Renegret
May 26, 2007

THANK YOU FOR CALLING HELP DOG, INC.

YOUR POSITION IN THE QUEUE IS *pbbbbbbbbbbbbbbbbt*


Cat Army Sworn Enemy

MJP posted:

Big shoutout to everyone here and all the homies not in this thread that aren't getting or won't be getting WFH, and/or have to deal with helpdesk or support stuff during this time. I can't imagine it's easy to deal with the influx of "my VPN no worky" crap, doubly so if they're still making you come into the office.

I will do all I can not to add to your burden from my end. Stout hearts, comrades.

Our WFH situation is such a disaster I'd rather just come in to work.

It's super embarrassing that, for one of the most critical departments in the entire company, we've had absolutely no disaster recovery plan to speak of. And in trying to get it fixed, it's all spiraling out of control.

The VPN team ran out of IP address space so they need to add more scopes. Our internal networks are a behemoth, it's not an easy task. Every time they change the scope on my team, some tools break, and earlier broken tools start working again. In their defense they're extremely responsive, but they can't concern myself with my team's individual needs until they finish re-addressing.

mattfl
Aug 27, 2004

devmd01 posted:

No WFH policy yet but 90% of our employees provide support services to hospitals so lol.

Boss is WFH today so I hosed off work at 1030 to go drink with a former coworker. :getin:

I work IN a hospital, we won't be getting WFH anytime soon :(

nielsm
Jun 1, 2009



Yup mandatory WFH here too. Phones are melting, everyone trying to figure out how to VPN or even just get on webmail.

Hughmoris
Apr 21, 2007
Let's go to the abyss!

mattfl posted:

I work IN a hospital, we won't be getting WFH anytime soon :(

:hfive:

I'm tired of being 'essential' personnel. Trying to transition out of informatics and in to BI sooner than later...

mattfl
Aug 27, 2004

Hughmoris posted:

:hfive:

I'm tired of being 'essential' personnel. Trying to transition out of informatics and in to BI sooner than later...

I was team "a" during the hurricane last year and got to be here when the hospital locked down for the duration of it :(

Rooted Vegetable
Jun 1, 2002
Smuggly, we (although not me personally) deployed DirectAccess last year. Must remember that we get poo poo right most of the time.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




We've had a major push towards open work spaces combined with strong WFH options over the last few years. Pretty much everyone has a laptop and a VPN client. It's a major benefit, except I had to connect through a Midwest gateway this morning as the local is full.

AlexDeGruven
Jun 29, 2007

Watch me pull my dongle out of this tiny box


When I worked in IT for Sears (lol), our vpn endpoint was in KC, MO. Our offices were in Troy, MI, and Hampton Estates (Chicago), IL.

When I would WFH, my round-trip was a minimum of 130ms, even though the Troy office is only 30 miles from home.

The Fool
Oct 16, 2003


The guest Wifi at all of our sites authenticates to a radius server that is here at our hq.

This makes the WiFi totally unusable for some of our sites because authentication keeps timing out.

The internal WiFi works fine since it just authenticates over local ad.

LethalGeek
Nov 4, 2009

Heners_UK posted:

Smuggly, we (although not me personally) deployed DirectAccess last year. Must remember that we get poo poo right most of the time.

Meanwhile we just got done ripping DA out cause it doesn't play nice with a lot of our legal stuff . I wasn't involved too much in fixing the darn thing but I will not miss it. Instead the actual VPN it got replaced with Just Works unless you are apparently on some dumb ISP that is using some IPs in a range like 192.168.x.x with local LAN access enabled.

Adbot
ADBOT LOVES YOU

Rooted Vegetable
Jun 1, 2002

LethalGeek posted:

Meanwhile we just got done ripping DA out cause it doesn't play nice with a lot of our legal stuff .

If refering to actual software used by your Legal department (i.e. software compatibility issue): we left our VPN in place if it's needed for that reason. Most people have been fine without it as we've also had a Citrix push.

If legal requirements: Commiserations, however, were the legal folks not at least consulted ahead of time?

  • 1
  • 2
  • 3
  • 4
  • 5