Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
abigserve
Sep 13, 2009

this is a better avatar than what I had before

ewiley posted:

I don't get the hate for microsegmentation, I mean it's already baked-in to AWS and Azure, NSX is expensive but it's not insanely complex to implement once you get past the vSwitches that you should be using anyway.

Of course you should be concentrating on OS's and endpoints, but most have terrible built-in firewalls and many more apps don't even have the ability to limit their own listeners by IP. So sure, I'm segmenting my OS's but I also want to segment my network without making everyone re-IP, what's wrong with that? At least with central firewalling I can log east-west traffic to one place and (at least with hypervisor-based firewalls) it's not impacting performance.

aws and azure are infinitely easier to manipulate than network firewalls. If you really think it's worth popping a firewall between nodes on the same segment for whatever reason my argument is that it's far more transparent to implement it at the OS layer rather than the hypervisor or network.

yoloer420 posted:

Little Snitch my man! Or alternately windows firewall. Whatever works for you.

I meant network firewalls, I should have clarified. EDR's like carbonblack also offer some pretty impressive network flow collection which tie network traffic to processes, users, etc.

Adbot
ADBOT LOVES YOU

Workaday Wizard
Oct 23, 2009

by Pragmatica
i love seeing traffic from java.exe. what could it be? who cares.

Wiggly Wayne DDS
Sep 11, 2010



yoloer420 posted:

Little Snitch my man! Or alternately windows firewall. Whatever works for you.
those really aren't the same...

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER


Shinku ABOOKEN posted:

i love seeing traffic from java.exe. what could it be? who cares.

business critical api or data extraction by an unknown entity? no one knows, or can know, as the person who built it all left

Cybernetic Vermin
Apr 18, 2005

i too make all my important security decisions exclusively based on any adjacent filename i happen to spot

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Shinku ABOOKEN posted:

i love seeing traffic from java.exe. what could it be? who cares.

lmao if you still have the java runtime on your computer

Shame Boy
Mar 2, 2010

Krankenstyle posted:

lmao if you still have the java runtime on your computer

lmao if you think you got rid of the java runtime just because you don't have java installed

Midjack
Dec 24, 2007



Shinku ABOOKEN posted:

i love seeing traffic from java.exe. what could it be? who cares.

motherfuckers act like they forgot about jre

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Midjack posted:

motherfuckers act like they forgot about jre

lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Midjack posted:

motherfuckers act like they forgot about jre

simble
May 11, 2004

Midjack posted:

motherfuckers act like they forgot about jre

ate shit on live tv
Feb 15, 2004

by Azathoth

abigserve posted:

Generally it's fairly easy to use automation to stand up new stuff but ongoing cleanups and sanity-checking requires a lot of complicated logic that is hard to implement - ask anyone who is using Ansible (for example) for network automation how do they detect and then cleanup stuff when it's decommissioned and you'll get some interesting responses. Can you guess what happens when new changes are easy to automate but old policy is very hard to get rid of?


Yea, this is where I'm at. Idempotent is a fun word, and ansible/network changes AREN'T.

I can spin up (from scratch) an almost unlimited number of switches or routers that will be configured identically with dynamically assigned ip addresses, and hostnames, and ACLs etc etc. But tell me that you want to change our production vlan from 100 to 101 and I'll be at a loss to figure out how to do that cleanly and remove the old vlan :/

univbee
Jun 3, 2004




Midjack posted:

motherfuckers act like they forgot about jre

flakeloaf
Feb 26, 2003

Still better than android clock

Midjack posted:

motherfuckers act like they forgot about jre

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Midjack posted:

motherfuckers act like they forgot about jre

ate shit on live tv
Feb 15, 2004

by Azathoth

abigserve posted:

my point was regardless of what layer you are doing "firewalling" it's always terrible but the microseg solutions don't even try going above layer 4 so it's even worse than usual

Security though ip/port whitelisting is obsolete. The security should be on the end point, the firewall should be providing NATing or allowing selective in-bound from the internet. That's it.

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Midjack posted:

motherfuckers act like they forgot about jre

haveblue
Aug 15, 2005



Toilet Rascal

Midjack posted:

motherfuckers act like they forgot about jre

Pile Of Garbage
May 28, 2007



Midjack posted:

motherfuckers act like they forgot about jre

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

Midjack posted:

motherfuckers act like they forgot about jre

:golfclap:

cinci zoo sniper
Mar 15, 2013




as usual, i dont get it

flakeloaf
Feb 26, 2003

Still better than android clock

https://www.youtube.com/watch?v=QFcv5Ma8u8k

cinci zoo sniper
Mar 15, 2013




lol :golfclap:

jre
Sep 2, 2011

To the cloud ?



Midjack posted:

motherfuckers act like they forgot about jre

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Soricidus
Oct 21, 2010
freedom-hating statist shill

Krankenstyle posted:

lmao if you still have the java runtime on your computer

I need it to run a large number of useful java programs, most of which I wrote

it doesn’t have unrestricted permission to talk to the network tho

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones

Midjack posted:

motherfuckers act like they forgot about jre

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Midjack posted:

motherfuckers act like they forgot about jre

vanity slug
Jul 20, 2010

Midjack posted:

motherfuckers act like they forgot about jre

haveblue
Aug 15, 2005



Toilet Rascal
"secfuck megathread - v18.0 - motherfuckers act like they forgot about jre" is a few chars under the cap

Methanar
Sep 26, 2013

by the sex ghost

cinci zoo sniper posted:

as usual, i dont get it

The song Dr.Dre Ft. Eminem- Forgot About Dre includes the lyrics 'And motherfuckers act like they forgot about Dre'

pseudorandom name
May 6, 2007

haveblue posted:

"secfuck megathread - v18.0 - motherfuckers act like they forgot about jre" is a few chars under the cap

somebody has to volunteer to touch the poop in order to force the creation of a new thread

flakeloaf
Feb 26, 2003

Still better than android clock

I'm not digging through a dump of data collected by a parental spyware app thanks

simble
May 11, 2004

mods can rename threads my dude

and they should

pseudorandom name
May 6, 2007

simble posted:

mods can rename threads my dude

and they should

we have traditions in the secfuck thread that must be upheld

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Midjack posted:

motherfuckers act like they forgot about jre
:hmmyes:

haveblue posted:

"secfuck megathread - v18.0 - motherfuckers act like they forgot about jre" is a few chars under the cap

it's a 17.1, dawg

DELETE CASCADE
Oct 25, 2017

i haven't washed my penis since i jerked it to a phtotograph of george w. bush in 2003

Midjack posted:

motherfuckers act like they forgot about jre

The Sweetling
May 13, 2005

BOOMSHAKALAKA
Fun Shoe

Midjack posted:

motherfuckers act like they forgot about jre

jesus lol

yoloer420
May 19, 2006

Wiggly Wayne DDS posted:

those really aren't the same...

The question was about process aware firewalls that work. They do work, I'm not aware of any enterprise level solutions (for anything) that work though. The tech exists however.

abigserve posted:

I meant network firewalls, I should have clarified. EDR's like carbonblack also offer some pretty impressive network flow collection which tie network traffic to processes, users, etc.

Absolutely fair, I don't know that there are any network firewalls that properly do anything close to that. If there were they'd need to be heavily dependent on host based reporting anyway.

yoloer420 fucked around with this message at 23:05 on Mar 26, 2019

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



i'd never call windows firewall is a process-aware firewall that works

last time i saw a windows firewall as effective as little snitch for end users was over a decade ago

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply