Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
I've been trying out NextDNS recently, and it seems pretty good. It's a bit like a hosted pihole with various managed blacklists for ads, tracking, etc

Adbot
ADBOT LOVES YOU

Oysters Autobio
Mar 13, 2017
Is 1Password still the thread favourite for online, cross device password managers?

Been meaning to get off using Dashlane for a long time now but kept procrastinating and want to transition to a new one. Particularly interested in password managers that have good family plans so I can setup my partner too. Willing to hear out learning to setup any self-hosting options unless the risk for mistakes from a non-professional outweigh it.

Oysters Autobio fucked around with this message at 17:31 on Nov 5, 2022

Evis
Feb 28, 2007
Flying Spaghetti Monster

There’s also things like 1.1.1.2 for DNS-level malware filtering although I don’t know that it’s likely to block an attack.

Cup Runneth Over
Aug 8, 2009
Probation
Can't post for 2 hours!

Oysters Autobio posted:

Is 1Password still the thread favourite for online, cross device password managers?

Been meaning to get off using Dashlane for a long time now but kept procrastinating and want to transition to a new one. Particularly interested in password managers that have good family plans so I can setup my partner too. Willing to hear out learning to setup any self-hosting options unless the risk for mistakes from a non-professional outweigh it.

1Password is great and its shared vaults are perfect and it has a family plan. Password manager is kinda not something you wanna gently caress with yourself IMHO under the same principles as roll your own, though I hear KeepAss is OK.

RFC2324
Jun 7, 2012

http 418

Bitwarden(secured by yubikey) for personal stuff since I want that internet accessible, KeepAss for work passwords that should never leave my workstation

Note: all my passwords are actually the same, but I am told I should keep them in a vault for some reason

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Duplicate passwords let the store compress better, so you’re really just being environmentally friendly.

Magnetic North
Dec 15, 2008

Beware the Forest's Mushrooms

Subjunctive posted:

Duplicate passwords let the store compress better, so you’re really just being environmentally friendly.

Good idea. Also I've heard short lowercase passwords save even more space.

RFC2324
Jun 7, 2012

http 418

Magnetic North posted:

Good idea. Also I've heard short lowercase passwords save even more space.

just stick with all numbers. if adding one to a password makes it stronger, making them all numbers must be the strongest

Cup Runneth Over
Aug 8, 2009
Probation
Can't post for 2 hours!

Magnetic North posted:

Good idea. Also I've heard short lowercase passwords save even more space.

Absolutely, those are lower unicode numbers so the bit map of your passwords will be smaller

CaptainSarcastic
Jul 6, 2013



Cup Runneth Over posted:

Absolutely, those are lower unicode numbers so the bit map of your passwords will be smaller

Make your password the same as your username and you save even more space.

astral
Apr 26, 2004

Oysters Autobio posted:

Is 1Password still the thread favourite for online, cross device password managers?

No, since they no longer support standalone vaults or licensing.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

astral posted:

No, since they no longer support standalone vaults or licensing.

OP explicitly asked about online multi-device

astral
Apr 26, 2004

Rufus Ping posted:

OP explicitly asked about online multi-device

When it comes to password managers, one of the biggest questions is trust. If you no longer have the option to keep a hold of your own data because the company in question waffled on their own stated commitments to let you do just that before ending support for it it forever this time for real, it's hard to maintain trust that they'll take good care of your passwords or not suddenly drop support for some other useful or important feature.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Yeah, we use 1Password at work so I could have a family license for free (or have the company pay for it, I forget) but I’m sticking with (paid!) Bitwarden. I don’t know if I’ll ever host my own storage, but the fact that it’s possible makes me feel better about the odds that someone could offer a compatible service if the wheels fell off. Wish it worked better offline, though.

RFC2324
Jun 7, 2012

http 418

Subjunctive posted:

Yeah, we use 1Password at work so I could have a family license for free (or have the company pay for it, I forget) but I’m sticking with (paid!) Bitwarden. I don’t know if I’ll ever host my own storage, but the fact that it’s possible makes me feel better about the odds that someone could offer a compatible service if the wheels fell off. Wish it worked better offline, though.

When i figured out that I can incorporate bitwarden into my ansible playbooks, service accounts became my favorite thing

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Ooooh, that’s interesting!

RFC2324
Jun 7, 2012

http 418

https://docs.ansible.com/ansible/latest/collections/community/general/bitwarden_lookup.html

It owns.

Oysters Autobio
Mar 13, 2017

Rufus Ping posted:

OP explicitly asked about online multi-device

So Bitwarden wouldn't work in terms of accessing the same set of passwords on my phone and my PC? Is there any way to have personal vaults but still be able to access them across devices?

hooah
Feb 6, 2006
WTF?

Oysters Autobio posted:

So Bitwarden wouldn't work in terms of accessing the same set of passwords on my phone and my PC? Is there any way to have personal vaults but still be able to access them across devices?

Bitwarden indeed can do that, just like any popular password manager. I may not understand exactly what you mean by "personal vaults", though.

The Fool
Oct 16, 2003


The bitwarden mobile apps support connecting to your self-hosted instance, if thats what you're asking.

RFC2324
Jun 7, 2012

http 418

also, last I checked bitwarden self hosting is free, you don't need to be a paid user.

the things you pay for are the ability to store files and do org type poo poo

in conjunction with the above bw + ansible, I have certs and ssh keys stored in bitwarden that can be pulled down and autoinstalled.

my home lab is hilariously overengineered

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

RFC2324 posted:

my home lab is hilariously overengineered

I love it.

RFC2324
Jun 7, 2012

http 418


legit how the hell are you supposed to figure this stuff out without a home lab? one of the newbies at my job has realized that he just can't keep up with this industry by treating it as a 9-5 type thing, and is planning on re-enlisting lmao

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?

RFC2324 posted:

my home lab is hilariously overengineered
Take that back. There's no such thing!

To your later post: I think one of the single best thing companies can do for their engineers is just give them a budget of a grand a year and say, "Go build random things and break them. Just not on our network tia."

RFC2324
Jun 7, 2012

http 418

Ynglaur posted:

Take that back. There's no such thing!


I have yubikey auth in front of a glorified torrent search engine. its a *wee* bit much sometimes lol

Zorak of Michigan
Jun 10, 2006

My #1 requirement for early next year is an AWS budget just for my infrastructure team's lab, so they can have a place to go mess about and break poo poo. Home lab is great if you're into it, but I firmly believe that $employer should provide the resources you need for professional development, and that includes lab space.

RFC2324
Jun 7, 2012

http 418

Zorak of Michigan posted:

My #1 requirement for early next year is an AWS budget just for my infrastructure team's lab, so they can have a place to go mess about and break poo poo. Home lab is great if you're into it, but I firmly believe that $employer should provide the resources you need for professional development, and that includes lab space.

agreed, but in over a decade of being a sysadmin something like this has existed for exactly 3 months, only because I fought tooth and tail for it for the rest of the team, and the moment I stopped fighting it got cannibalized into something else.

I still have a repo with the crude bash scripts I wrote to make something in libvirtd for it

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
Is Sophos still a recommended malware scanner? My parent's ISP called them and said they received complaints about malicious traffic coming from their IP. A scan of my mom's PC did hit something, but the software didn't specify what it was before forcing a reboot. I also noticed what appears to be SSH fishing from my dad's Surface to our NAS (repeated attempts with common default usernames etc) so I'm looking for something I can run on all the Windows machines to help clean them out.

WattsvilleBlues
Jan 25, 2005

Every demon wants his pound of flesh

Takes No Damage posted:

Is Sophos still a recommended malware scanner? My parent's ISP called them and said they received complaints about malicious traffic coming from their IP. A scan of my mom's PC did hit something, but the software didn't specify what it was before forcing a reboot. I also noticed what appears to be SSH fishing from my dad's Surface to our NAS (repeated attempts with common default usernames etc) so I'm looking for something I can run on all the Windows machines to help clean them out.

Assuming the call from the ISP was legitimate, with that degree of poo poo going on you should format both parents' machines.

Cup Runneth Over
Aug 8, 2009
Probation
Can't post for 2 hours!
Yeah, flatten and reinstall.

RFC2324
Jun 7, 2012

http 418

Its the only way to be sure

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
Yeah I figured as much :sigh: I've never had an ISP have an actual human pick up the phone and call so that's pretty worrying. Hopefully mom just clicked on the wrong Facebook link and was part of a botnet for a bit VS something more actively malicious. No evidence of that yet at least.

CatHorse
Jan 5, 2008
Also make them limited users so they can't turn off Defender.

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
Well this is embarrassing :blush: After continuing to try and chase down what particular PC was causing the issue, I got around to looking up their public IP on abuseipdb.com and saw that it had been reported over 800 times since Dec 8th, always for SSH brute force attacks. The reports were coming in pretty consistently, at least one an hour, so we started taking PCs offline and watching for the reports to slow down. Turns out the one that seemed to make a difference was my own Linux desktop :negative:

Now that we had things narrowed down to SSH spam I threw Wireshark on there and ran a capture filtered for SSH and I got thousands of packets instantly. Exactly 1/3 of my total network activity was SSH. This PC did have a port open so I could SSH in to it, as I have been doing for a good decade now. I always saw IPs scanning in the auth logs it but I figured using a non-standard port and running fail2ban would keep me safe. Which it did. Until it didn't.

Currently taking some notes on the way I have stuff like hosts and fstab configured, then I'll swap in a spare SSD for the current main drive and do a fresh Xubuntu install. Sorry for victim blaming you parents and/or Windows :(

WattsvilleBlues
Jan 25, 2005

Every demon wants his pound of flesh
I don't know what most of that means but it made me chuckle anyway. Like I'm laughing at a mystery fart or something. Glad you're getting sorted anyway 🙂

DoctorTristan
Mar 11, 2006

I would look up into your lifeless eyes and wave, like this. Can you and your associates arrange that for me, Mr. Morden?
Please tell me you at least installed updates at some point during those 10 years.

DerekSmartymans
Feb 14, 2005

The
Copacetic
Ascetic

DoctorTristan posted:

Please tell me you at least installed updates at some point during those 10 years.

Lol at the thought…

Obi Wan: He’s more malware now than man; twisted and evil.

RFC2324
Jun 7, 2012

http 418

Lol

Lmao

One of my tasks at work is remediations because no one else gives a gently caress about security, and every time I see a new name on my list I know I am gonna be patching for hours

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


Is this the right forum to ask about recommendations of home music servers, network file system, and backup software? (All tied together, as one issue.) If not, where? I have a large set of FLAC files on an ancient network drive, and I need to modernize.

Adbot
ADBOT LOVES YOU

tuyop
Sep 15, 2006

Every second that we're not growing BASIL is a second wasted

Fun Shoe

Arsenic Lupin posted:

Is this the right forum to ask about recommendations of home music servers, network file system, and backup software? (All tied together, as one issue.) If not, where? I have a large set of FLAC files on an ancient network drive, and I need to modernize.

The NAS thread is here https://forums.somethingawful.com/showthread.php?threadid=2801557&perpage=40&noseen=1&pagenumber=759

The selfhosting thread might also give you some cool ideas about other stuff you might want to do once you get into this stuff https://forums.somethingawful.com/showthread.php?threadid=3985071&perpage=40&pagenumber=1&noseen=1

tuyop fucked around with this message at 05:16 on Jan 30, 2023

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply