Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Craft beer names are getting weirder

:perfect:

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Porter seems like the easy one to go with.

Border Gateway Porter

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

I was trying so hard to come up with an LDAP one. You win though.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
It's too hard, you see.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

22 Eargesplitten posted:

How bad is Bluetooth in a home environment? I would really like to have headphones that don’t involve me constantly rolling over the cable, but I hate the idea of making my network less secure.

Actually, my wife already uses a Bluetooth speaker, so the horse is already out of the barn isn’t it?

Generally consumer devices are class 1 and don't do too well beyond... 10 meters I think? Maybe a little less? Having some headphones on while laying in bed/on the couch are hardly going to draw too much worry. If you're using your phone and worried about it, you can always just turn Bluetooth off when not using the headphones.

e: added quote for new page

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Klyith posted:

https://www.defcon.org/html/links/dc_press/archives/12/esato_bluetoothcracking.htm

definitely set all your bluetooth stuff to only pair manually

hahaha right. I forgot this was a thing :>

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Avenging_Mikon posted:

Sweet. I'm really enjoying security stuff. Not "glamorous" stuff like pen testing or red teams, but setting up an environment that allows users to do what they need, no more, no less, while minimizing risk of data breeches. HIDS and NIDS and all that fun poo poo. It's something I'd like to get in to as my focus. Just don't know what aspect yet. Really appeals to my nit-picky nature.

My Edmonton infosec group is me and one other guy. You are more than welcome to join our ranks.

The Calgary group is way better for basically all the reasons CLAM stated.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
PM'd, friend.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

The Fool posted:

Here’s your opportunity to advocate against that terrible policy.

Please do this.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

cheese-cube posted:

Read up on RBAC and principle of least privilege, then apply these concepts to your environment.

I have a client with an instance of RBAC that has gone completely out of control. The base concepts are all still there but they really went a little too HAM on the whole idea.

ie: They literally make a new group for every new permission they want to grant. Add somebody to the existing Accounting group? Well this guy isn't in Accounting, but every other Tuesday needs access to this one folder in the Accounting share, let's make a new role for this and add all of Accounting to it as well!

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Truga posted:

computers were a mistake

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I thought VMware started releasing patches last night? I'm going to try and dig up confirmation of that because now everything might just be blurring together.

edit: https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html Your admin is lazy.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Bump so the edit doesn't get missed.

Also today I seem to get to explain to my entire office exactly why this is such a big deal and exactly why AV needs to patch properly.

edit: Seems we're on it lol

Proteus Jones posted:

Depends. Is he talking about Meltdown? Probably better off using OS patch for that.

For Spectre, sounds like he's lazy AF or doesn't know where to look. VMWare released a patch addressing both Spectre CVEs last night.

https://www.vmware.com/security/advisories/VMSA-2018-0002.html

Yeah.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Jowj posted:


But it gets sliiiiiightly more murky. As it turns out, if you're running two AVs (lol i know) then you can get this patch pushed to you and make you vulnerable to BSODs. For a real life example, Defender comes installed by default on Win10 builds, and even if its disabled / stopped / set to manual, the "this is a good AV" reg key appears to persist. Thus, even when running only 1 AV (that's 3rd party) that ISN'T supported, you can still get the patch and put yourself into dangerous situations.


Hmm I haven't run into this yet, but good to watch out for.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Rescue Toaster posted:

It would be super cool if in Windows 10 there was any way whatsoever to see if a particular update had been installed. All the update history lists in 10 are completely useless and don't show any security updates.

Trying to help my parents understand if they have the right patch yet is driving me crazy, since *I* can't even tell if my PC is patched.


EDIT: Thanks CALM DOWN, apparently my PC just is not getting any updates at all anymore. Nothing since 12/17 anyway. Pretty sweet.

That's about reasonable for the last patch cycle.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else


Well it's a start I guess.



Hmmmm

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Oh yeah this processor is old as hell. i5-3337U. We're full party mode over here.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Hmm now that you mention it I remember reading something about that in all this fuss. Maybe one of the whitepapers.

e: Obviously I'm just seeing what can be done for workstations. Server patching and fixing is already well under way.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

OddObserver posted:

What's the Intel ME tool, BTW?

It was the tool they released for the IME explosion of poo poo back in Nov/Dec.

Found here: https://downloadcenter.intel.com/download/27150?v=t
Note this is checking for CVE-2017-5707, CVE-2017-5706, and CVE-2017-5705.

I just figured I'd check for this everywhere since I'm touching so many machines already.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

incoherent posted:

https://community.sophos.com/kb/en-us/128053

Just a repost from the last few pages, update through sophos endpoints are going out today to apply that registry entry.

Those in AV extended groups (example 03/xp) will not receive the registry entry and must be manually entered.

Also there is no real good way to confirm what version of the Sophos endpoint is running without just checking the registry entry for the version number. At that point it might be easy to just look for the key it's supposed to add, but I'll leave that decision up to those scripting checks.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

NIGARS posted:

My systems:

Ivy Bridge:


Haswell:


Looks like there's finally a compelling reason to upgrade from Sandy and Ivy.

drat. That's rather interesting.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Hungry Computer posted:

Is my Powerbook G4 safe :ohdear:

The battery might explode, but that's only tangentially related.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

apseudonym posted:

AV remains terrible

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Holy poo poo this owns.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Proteus Jones posted:

Yeah, still funny.

Yep.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

If he puts as much effort into it as he did with his delivery of The Aristocrats then I am sold.

Same, actually. This would be great.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Klyith posted:

gently caress, next you'll tell me they have hentai-sniffing dogs and my Important Secret Data will never be safe!

Please don't doxx me

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I still use deluge :( Am I the old man in the room who refuses to change his ways?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

fyallm posted:

Not sure if you all got to witness the glorious social media marketing fiasco that was Cygilent last night..

They have since deleted the tweets, but it's the internet.. It was so amazing

https://twitter.com/mattifestation/status/961833483243941888

Beautiful.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Maybe now you'll be able to afford the Canadian internet and wireless prices to post from home rather than Tim Horton's across the street.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

What lol

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Marvelous.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Sickening with the sick anti-joke punchline

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Sickening posted:

I couldn't help it, the joke was terrible.

It arguably made it more funny.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
It's all relative, really.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Potato Salad posted:

What if KB42069 trades a known exploit for one that nobody's discovered and leveraged yet :ohdear:

Wait I thought this was the whole point of patching.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I know, I just wanted to post and couldn't come up with anything better :smith:

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
Why is the de-facto argument of people who don't care about privacy, "I have nothing to hide"? It's the most tiring conversation to have since literally ever.

Adbot
ADBOT LOVES YOU

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Thanks Ants posted:

Especially as it’s not true. Any request for them to let you borrow their unlocked phone would be met with resistance.

Holy gently caress your new AV lmao

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply