Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Potato Salad
Oct 23, 2014

nobody cares


Harik posted:

I hate when purchasing departments have no loving clue what their requirements are. Great work guys, it's only your literal job.

Purchasing isn't usually expected to have a goddamn clue imo. It's up to the data / system owner to know what the gently caress is going on, and I'd spitball that fewer than half of domestic businesses even know what "system owner" means.

Condolences if it turns out the buyer is an entity that absolutely should know/function better.

Adbot
ADBOT LOVES YOU

BonHair
Apr 28, 2007

Purchasing absolutely needs to have a clue. They don't have to know security, but they have to know the standard security requirements and also when to get a security guy involved. Same deal as involving legal and finance more or less. The entire point of a purchasing department is to have guys who can understand all the different stuff involved in a purchase, not just business need and budget like the department that needs the product would.

Rust Martialis
May 8, 2007

by Fluffdaddy
Around Y2K I ordered 4* Sun E220R rack servers. Half a rack.



Purchasing decided they could get Sun E450 servers for less.



Two full racks, plus they're drawing a couple kilowatts

Sickening
Jul 16, 2007

Black summer was the best summer.
If you are moonlighting, don't login to your company poo poo on the wrong company laptop. It might fire off detections. Don't do this especially if the wrong laptop has enforced vpn connections and public ip's with your other companies name tied to them. And if you can't avoid all of this, come up with a convincing story other than "i logged in from my gf's laptop on accident".

You aren't breaking the law. Nobody wants to tattle on you. Give people a reason to move on, I beg you.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




BonHair posted:

Purchasing absolutely needs to have a clue. They don't have to know security, but they have to know the standard security requirements and also when to get a security guy involved. Same deal as involving legal and finance more or less. The entire point of a purchasing department is to have guys who can understand all the different stuff involved in a purchase, not just business need and budget like the department that needs the product would.

I once had a Cisco consultant shop drag their feet on a deliverable, and then send us the invoice for the project. Our AP people sent them a $2500 check without talking to the IT manager (me!).

We never did get that deliverable. I wonder why.

I wish I could remember the name of the consultants, they need their rep trashed.

MustardFacial
Jun 20, 2011
George Russel's
Official Something Awful Account
Lifelong Tory Voter
Probably only relevant to me, but a couple weeks ago London Drugs, a local pharmacy released a statement saying they got hit with a cybersecurity incident. Then they made a statement saying they refused to pay the ransom. Lockbit (the attacker) put a 48h notice on their dark web blog yesterday afternoon




This morning it's gone.


I wonder where they came up with the extra $17mil

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

very interested in that Telekom one, since Telekom Security is a root CA trusted in the major browsers

MustardFacial
Jun 20, 2011
George Russel's
Official Something Awful Account
Lifelong Tory Voter

Subjunctive posted:

very interested in that Telekom one, since Telekom Security is a root CA trusted in the major browsers

Haven't confirmed for myself, but it seems like not a big deal

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

excellent news

Honey Im Homme
Sep 3, 2009

MustardFacial posted:

Probably only relevant to me, but a couple weeks ago London Drugs, a local pharmacy released a statement saying they got hit with a cybersecurity incident. Then they made a statement saying they refused to pay the ransom. Lockbit (the attacker) put a 48h notice on their dark web blog yesterday afternoon




This morning it's gone.


I wonder where they came up with the extra $17mil

Maybe they didn't

https://www.cbc.ca/news/canada/british-columbia/hackers-london-drugs-data-1.7213141


quote:

Retailer London Drugs says cybercriminals who stole files from its corporate head office last month have released some of the data after it refused to pay a ransom.

The company says the files may contain employee information, calling it a "deeply distressing" situation.

More to come.

MustardFacial
Jun 20, 2011
George Russel's
Official Something Awful Account
Lifelong Tory Voter
Yeah, looks like they put it back up. 300GB archive.

Mustache Ride
Sep 11, 2001



Broadcom to acquire Zscaler for $38Bigones

Thanks Ants
May 21, 2004

#essereFerrari


If you’re the product manager for Entra Global Access you’re feeling quite good about now

Sickening
Jul 16, 2007

Black summer was the best summer.

Well, it was a good run.

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


Is there any reason to believe that random substack?

Diva Cupcake
Aug 15, 2005


I want to vomit. It’s been hard enough to get the gently caress off Symantec DLP because of Broadcom’s poo poo.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

rafikki posted:

Is there any reason to believe that random substack?

Not that I can tell. An exchange in the comments indicates that the author might also work for a Zscaler competitor?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD



From Zscaler's CEO:

https://www.linkedin.com/feed/update/urn:li:activity:7200857561930031104/

quote:

Response to Broadcom Rumors

Rumors have been circulating in smaller trade publications and websites that Broadcom is in discussions to acquire Zscaler. I want to set-the-record-straight that neither I nor the Zscaler board of directors are seeking or entertaining any offers to acquire Zscaler. Any reports stating otherwise, are untrue.

Zscaler is at the forefront of a major technology disruption, and I believe that we are in an excellent position to lead the future of zero trust security.

Zscaler investors and others should note that we announce material information to the public about our company, products and services and other issues through a variety of means, including our website (https://www.zscaler.com/), our investor relations website (https://ir.zscaler.com), our blogs (https://lnkd.in/gMer9V2Y), press releases, SEC filings, public conference calls and social media, in order to achieve broad, non-exclusionary distribution of information to the public. We encourage our investors and others to review the information we make public in these locations as such information could be deemed to be material information. Please note that this list may be updated from time to time.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

how did that alleged/denied breach of their poo poo turn out (and why didn’t their systems catch it before it was announced)?

Rust Martialis
May 8, 2007

by Fluffdaddy
iconv () bug in glibc

Patch!

Cve once I get to desk

CVE-2024-2961 https://nvd.nist.gov/vuln/detail/CVE-2024-2961

https://www.ambionics.io/blog/iconv-cve-2024-2961-p1

quote:

The Cisco PSIRT has assigned this bug the following CVSS version 3.1 score. The Base CVSS score as of the time of evaluation is: 9.8 https://tools.cisco.com/security/center/cvssCalculator.x?version=3.1&vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE ID CVE-2023-0687, CVE-2024-2961 have been assigned to document this issue.

Rust Martialis fucked around with this message at 12:46 on May 31, 2024

Sickening
Jul 16, 2007

Black summer was the best summer.
Zscaler has a lovely default feature flag that downgrades your non-browser web traffic to http/1.1. You won't know about it unless you discover it in testing or find it in its dreadful documentation. It won't be visible in your configuration console unless the feature flag is flipped.

Have fun!

Diva Cupcake
Aug 15, 2005

RIP

https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features

spankmeister
Jun 15, 2008







All I'm reading is that it's going to continue to work.

Wiggly Wayne DDS
Sep 11, 2010



spankmeister posted:

All I'm reading is that it's going to continue to work.

Raymond T. Racing
Jun 11, 2019


NTLM, now brought to you by Entrust

Diva Cupcake
Aug 15, 2005

spankmeister posted:

All I'm reading is that it's going to continue to work.
Sometimes, simply announcing your intentions can serve as a motivating factor to improve. It's like making a New Year's resolution to go to the gym.

Wiggly Wayne DDS
Sep 11, 2010



smb v1 was superseded in 2007, publicly depreciated in 2014. then took until 2017 to be no longer installed by default. yet i can still hear of smb v1 use in the wild..

Wiggly Wayne DDS fucked around with this message at 19:41 on Jun 4, 2024

Adbot
ADBOT LOVES YOU

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Look Windows for Workgroups won't run itself

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply