Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
PremiumSupport
Aug 17, 2015

App13 posted:

Got an absolutely cursed request that I am trying to implement in the least damaging way.

Lab System A is running windows 7. Client application requires UAC to be set to “never notify”. System must be connected to the internal network in order to operate, so air-gapping is not possible.

My gut reaction was a horrified “pls no” but we gotta move forward, any suggestions? Already planning to close every non-essential port

If they launch the client using a desktop icon you may be able to create a shortcut that automatically bypasses UAC for that single app. Your mileage may vary depending on what other processes the client launches.

Edit to add quote for new page context.

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

App13 posted:

Got an absolutely cursed request that I am trying to implement in the least damaging way.

Lab System A is running windows 7. Client application requires UAC to be set to “never notify”. System must be connected to the internal network in order to operate, so air-gapping is not possible.

My gut reaction was a horrified “pls no” but we gotta move forward, any suggestions? Already planning to close every non-essential port

Can you give it a static IP and then firewall it off that way? Make a secure subnet that is for old rear end lab equipment that only has needed access to internal resources?

App13
Dec 31, 2011

GreenNight posted:

Can you give it a static IP and then firewall it off that way? Make a secure subnet that is for old rear end lab equipment that only has needed access to internal resources?

This should be possible, though the networking team may get a little crotchety.

The internal resources needed are basically various network share drives and databases. The share drives are what I’m most worried about

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

App13 posted:

This should be possible, though the networking team may get a little crotchety.

The internal resources needed are basically various network share drives and databases. The share drives are what I’m most worried about

Does it need internet access? If not, block it. Create a network account for the pc that has only specific folder access on the shared drives.

Wizard of the Deep
Sep 25, 2005

Another productive workday

App13 posted:

Got an absolutely cursed request that I am trying to implement in the least damaging way.

Lab System A is running windows 7. Client application requires UAC to be set to “never notify”. System must be connected to the internal network in order to operate, so air-gapping is not possible.

My gut reaction was a horrified “pls no” but we gotta move forward, any suggestions? Already planning to close every non-essential port

That does sound like a Grade 4 Shitshow.

When you say "internal network", what exactly do you mean? Does it just need to be able to upload files to a single server, or does it need to be joined to AD and send email and open PowerPoints and that Access database you don't know about but contains 35% of your critical company/research data?

I'd go a step farther than depending on the Windows firewall and segregate this device to its own VLAN that can only talk to the specific hosts required. If it absolutely needs to be part of the domain, that VLAN can talk to a single DC. Ideally there'd be a single service account that can only log into that one machine, and all other accounts blocked from logging in.

It's probably a good time to produce some basic CYA documentation too. Point out that the OS is no longer supported by Microsoft, and likewise the hardware underneath it is almost certainly out of warranty and probably replaceable only at significant cost. It's probably lab equipment that will cost $X0,000-$X00,000 to replace, but you want to build out your "you were warned it would be expensive" letters now. Your goal for this isn't to actually kill the request right now, but cover your rear end when it inevitably fails at the worst possible time. Any internal security teams need to be aware and signing off on the exceptions, too.

Good luck and goonspeed.

Gort
Aug 18, 2003

Good day what ho cup of tea
"Closing every non-essential port" feels like it should be standard operating procedure for every system

App13
Dec 31, 2011

Wizard of the Deep posted:

That does sound like a Grade 4 Shitshow.

When you say "internal network", what exactly do you mean? Does it just need to be able to upload files to a single server, or does it need to be joined to AD and send email and open PowerPoints and that Access database you don't know about but contains 35% of your critical company/research data?

I'd go a step farther than depending on the Windows firewall and segregate this device to its own VLAN that can only talk to the specific hosts required. If it absolutely needs to be part of the domain, that VLAN can talk to a single DC. Ideally there'd be a single service account that can only log into that one machine, and all other accounts blocked from logging in.

It's probably a good time to produce some basic CYA documentation too. Point out that the OS is no longer supported by Microsoft, and likewise the hardware underneath it is almost certainly out of warranty and probably replaceable only at significant cost. It's probably lab equipment that will cost $X0,000-$X00,000 to replace, but you want to build out your "you were warned it would be expensive" letters now. Your goal for this isn't to actually kill the request right now, but cover your rear end when it inevitably fails at the worst possible time. Any internal security teams need to be aware and signing off on the exceptions, too.

Good luck and goonspeed.

Internal network in this instance is our GLP compliant electronic lab notebooks, so that should be easy enough to isolate. My first thought was to airgap the PC entirely and exfil data manually, but that is of course a GLP no-no. I’m thinking this may be a good opportunity to get that whole system reassessed for an upgrade by outlining how much we’d be turbofucked by fines and loss of confidentiality of customer IP if something goes awry. If QA/C-levels read the risk assessment and give the go ahead, that’s fine by me. Wont be my signature.

Anyway thank you all for the multitude of replies. I read them all and they are incredibly helpful. I love this thread.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




App13 posted:

Got an absolutely cursed request that I am trying to implement in the least damaging way.

Lab System A is running windows 7. Client application requires UAC to be set to “never notify”. System must be connected to the internal network in order to operate, so air-gapping is not possible.

My gut reaction was a horrified “pls no” but we gotta move forward, any suggestions? Already planning to close every non-essential port

I got one of those requests. I saved the email as a record, just in case.

App13
Dec 31, 2011

Ha! After a long meeting we’ll be airgapping the PC and simply printing hard copies of the generated reports for our customer. Management assumed this would greatly complicate our compliance stuff, but when I outlined the requirements they were all about it. Securing/revalidating the system was going to cost north of $60k, and this is for a project that will be done by Q1. After that I’m authorized to yeet the whole thing.

Everything old is new again.

xzzy
Mar 5, 2009

App13 posted:

After that I’m authorized to yeet the whole thing.

the lie that management tells us every time.

AlternateAccount
Apr 25, 2005
FYGM
YOU CAN'T YEET OUTDATED TECH! YOU WILL REGRET THIS!

LochNessMonster
Feb 3, 2005

I need about three fitty


xzzy posted:

the lie that management tells us every time.

It’s this or someone coming to your desk in 6-12 months saying they really need it one more time (for real now) and you’ll need to restore the backup.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

What's up with this places that want you to record a video of explaining your resume and why you'd be a good fit?

Eat my entire butt.

Thanks Ants
May 21, 2004

#essereFerrari


Send them the YOSPOS instructional video

Bonzo
Mar 11, 2004

Just like Mama used to make it!

GreenNight posted:

What's up with this places that want you to record a video of explaining your resume and why you'd be a good fit?

Eat my entire butt.

Same companies that only want Rock Stars to apply

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


You gotta be hardcore

H110Hawk
Dec 28, 2006

GreenNight posted:

What's up with this places that want you to record a video of explaining your resume and why you'd be a good fit?

Eat my entire butt.

Is this to prevent interview fraud?

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




H110Hawk posted:

Is this to prevent interview fraud?

One part that, and at least two parts of making it less obvious that they already have a candidate in mind and are just going through the motions. It's a great timesaver for everyone in the hiring process. Except for the candidates who record a video that never gets watched.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I did Easy Apply on LinkedIn. Then I got a message from someone at the org that I should fill out the complete application and then we'll talk.

An hour later I got another message from someone else at the org saying "hey I see you only filled out half the app, how about we have a call tomorrow? Here is my calendar".

So I don't know.

George H.W. Cunt
Oct 6, 2010





Video interviews for hotties only

Mustache Ride
Sep 11, 2001



Who's going to watch that though? Not the hiring manager

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Just be extremely hardcore

tokin opposition
Apr 8, 2021

I don't jailbreak the androids, I set them free.

WATCH MARS EXPRESS (2023)
This is me at hard at work *8 hours of a still image*

you ate my cat
Jul 1, 2007

Mustache Ride posted:

Who's going to watch that though? Not the hiring manager

God I can't imagine watching a series of self-interview videos. I'd rather be dead.

App13
Dec 31, 2011

I watched my own after I joined the company and it was like watching a recording of myself masturbating

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


Mustache Ride posted:

Who's going to watch that though? Not the hiring manager

Your innie

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


App13 posted:

I watched my own after I joined the company and it was like watching a recording of myself masturbating

Is that required now?

Hughmoris
Apr 21, 2007
Let's go to the abyss!

Your innie is kind. Your innie likes to rake rocks as an additional duty.

kensei
Dec 27, 2007

He has come home, where he belongs. The Ancient Mariner returns to lead his first team to glory, forever and ever. Amen!


App13 posted:

I watched my own after I joined the company and it was like watching a recording of myself masturbating

OnlyFans will hire anyone...

(not a shot at you!)

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


kensei posted:

OnlyFans will hire anyone...

(not a shot at you!)

My comrade this is cspam you can make jokes at other posters' expense. It's fine

Internet Explorer
Jun 1, 2005





Cup Runneth Over posted:

My comrade this is cspam you can make jokes at other posters' expense. It's fine

Is it, though? Is it CSPAM?

johnny park
Sep 15, 2009

TIL this is cspam

Diqnol
May 10, 2010

Internet Explorer posted:

Is it, though? Is it CSPAM?

If you look inside yourself you will know that if it isn’t fyad, iz, byob, or d+d, it is cspam.

Zil
Jun 4, 2011

Satanically Summoned Citrus


All threads lead to CSPAM.

The Fool
Oct 16, 2003


ASAPRockySituation posted:

If you look inside yourself you will know that if it isn’t fyad, iz, byob, or d+d, it is cspam.

yospos bithc

Diqnol
May 10, 2010

I’m sorry. Yospos is computer byob.

tokin opposition
Apr 8, 2021

I don't jailbreak the androids, I set them free.

WATCH MARS EXPRESS (2023)
Vale, subjects. Your consoul has widely chosen be integrated into the empire. Ave CSPAM! We'll conquer Byzantium D&D soon, have some wine and succ.

\

tokin opposition fucked around with this message at 07:21 on Nov 17, 2022

KillHour
Oct 28, 2007


Internet Explorer posted:

Is it, though? Is it CSPAM?

You meant this to come off as snarky but in your heart of hearts, you know you asked because you're terrified they're right.

DACK FAYDEN
Feb 25, 2013

Bear Witness

tokin opposition posted:

Vale, subjects. Your consoul has widely chosen be integrated into the empire. Ave CSPAM! We'll conquer Byzantium D&D soon, have some wine and succ.

\

excuse me you can't say Byzantine anymore it's as bad as the N word
https://twitter.com/CSProfKGD/status/1591456435359064064

not pictured: the part where the reviewer literally said "what if instead of the Prisoner's Dilemma we called it the [n-word]'s Dilemma" (censorship mine, not theirs) cause they reviewer removed it

DACK FAYDEN fucked around with this message at 14:21 on Nov 17, 2022

Adbot
ADBOT LOVES YOU

Internet Explorer
Jun 1, 2005





KillHour posted:

You meant this to come off as snarky but in your heart of hearts, you know you asked because you're terrified they're right.

I'm a complex man, I can be snarky and terrified at the same time!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply