Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sickening
Jul 16, 2007

Black summer was the best summer.

MF_James posted:

Someone got a little butthurt, thanks for the title infosec, you made my day :)

Bah, same title, wrong dude.

Sickening fucked around with this message at 02:18 on May 13, 2016

Adbot
ADBOT LOVES YOU

Sickening
Jul 16, 2007

Black summer was the best summer.

ratbert90 posted:

I didn't see it here, but the other infosec thread is talking about AV again. :allears:



:vince:



Tell me again why AV is good? :laffo:

MF_James posted:

but it opens you up to other vulnerabilities! GOD DON'T YOU loving GET IT.

Because running windows, linux, iOS, a router, X brand firewall, and the other 100000 software/hardware things you run don't make you vulnerable to poo poo, it's clearly only AV that could possibly be opening you up to vulnerabilities.

oh wait it's just that other vulnerabilities aren't getting headlines, or, more likely, the good ones that affect X appliance/application aren't known by more than a few "hackers" and they keep them secret so that they don't get fixed.

Sickening
Jul 16, 2007

Black summer was the best summer.

Subjunctive posted:

If PayPal or your bank get owned, they're going to eat the damages, not you. If LastPass gets owned you might get an apology email. (And as you say, the purpose of the basket is to hold all your eggs.)

The bank doesn't eat anything. The sellers of whatever the unauthorized person bought eats them.

Sickening
Jul 16, 2007

Black summer was the best summer.

stevewm posted:

Any PCI experts in here? I can't seem to get a straight answer from anyone, and cannot really wrap my head about the PCI council documentation I can find on the topic..

We are getting ready to implement a PCI validated point-to-point encryption system for taking credit cards/EMV. (Verishield Protect). With this, the customer's account data is encrypted on the pad with a per device key and stays that way to our processor. Our POS software never sees any part of the CC data, it only receives status codes. We have zero access to any card holder data period, and it never travels over our network in a unencrypted form.

I cannot get a straight answer on how much this reduces our PCI scope.. Our POS software provider is telling us it puts us out of scope entirely, i.e. zero PCI requirements. But I am not believing that. Our processor doesn't really have a answer for us either.

Is anyone familiar with such systems?

I feel like that might be something you pay a consultant to walk you through. Right?

Sickening
Jul 16, 2007

Black summer was the best summer.

"Khablam" posted:


Also ~130 bits of entropy is enough to defend against an offline attack for as long as the Sun is going to shine for. No one wants your data that badly.

20 mb hard drive is all your are ever going to need.

Sickening
Jul 16, 2007

Black summer was the best summer.

mod saas posted:

You're right. There is absolutely no possibility the allowed password length will increase over time.


RFC2324 posted:

No, don't you see, once you set your password you can never change it. That kind of functionality would me MADNESS!!!

Don't sperg out over even the lamest of jokes. :itwaspoo:

Sickening
Jul 16, 2007

Black summer was the best summer.

ChubbyThePhat posted:

Looks like some cute fireworks blowing up around the BetterDiscord community. Haven't read into anything that's going on, my twitter feed is just getting a few people throwing red flags around.

Why would you post this but not post the content?

Sickening
Jul 16, 2007

Black summer was the best summer.

andrew smash posted:

I wonder if it's a hipaa violation if I'm required to unlock a device with patient info on it by border patrol

Borders crossings in the US and US border patrol is a magical land of no constitution or laws. There is nothing to wonder. All sense of reality is suspended there.

Sickening
Jul 16, 2007

Black summer was the best summer.
Phone posting!!!! N/m

Sickening fucked around with this message at 00:43 on Mar 28, 2017

Sickening
Jul 16, 2007

Black summer was the best summer.

Martytoof posted:

I... don't get it.

Phone posting mishap.

Sickening
Jul 16, 2007

Black summer was the best summer.

Wiggly Wayne DDS posted:

yeah there's a high burnout rate in security of people who actually care and want to get things fixed running against people who just want a paycheck and will patch around the issue to make sure that paycheck keeps coming

Don't leave out the Nessus scan results middlemen.

Sickening
Jul 16, 2007

Black summer was the best summer.

ozymandOS posted:

What's UpGuard?

http://lmgtfy.com/?q=upguard

Sickening
Jul 16, 2007

Black summer was the best summer.

ChubbyThePhat posted:

Sickening with the sick anti-joke punchline

I couldn't help it, the joke was terrible.

Sickening
Jul 16, 2007

Black summer was the best summer.

Avenging_Mikon posted:

unwarranted confidence?

Hey! I got an idea for a porn stage name...

Sickening
Jul 16, 2007

Black summer was the best summer.

Double Punctuation posted:

This is what Libertarians actually believe.

Come on, let’s pretend this is a thread for smart people talking about real things.

Sickening
Jul 16, 2007

Black summer was the best summer.

wolrah posted:

This was about once a month for me in college. It was before there was official wireless in the dorms, so people would just hook up their own stuff and inevitably a bunch of them got hooked up with the LAN side connected to the campus network. They had nice switches but apparently hadn't enabled snooping and were really slow about actually doing anything about it.

After the second time I came to the same conclusion about default passwords and would change the SSID to something obvious, disable DHCP, and then go out hunting. Locate the signal, knock on the door, and give them a bit of poo poo about it. If they were nice I'd help them get it set up properly, if they were lovely about it I'd play on their ignorance and tell them I was with IT (technically true) to threaten them with consequences. I couldn't actually enforce those things and didn't even work in the right department, but it usually worked. Repeat offenders may have had their device reflashed to OpenWRT.

What an incredible chud you are.

Like does anyone hear that story from you and think "wow, so cool!"?

Sickening
Jul 16, 2007

Black summer was the best summer.

Potato Salad posted:

They weren't going over the actual raw logs with their eyes to see if if any info wasn't being consumed :shrug:

Or, at least until someone eventually did


Maybe having every celebrities password in the world was a thing their nerds wanted?

Sickening
Jul 16, 2007

Black summer was the best summer.

Lain Iwakura posted:

Tooting my own horn again here:
https://blog.keigher.ca/2018/03/performing-your-own-dentistry.html

So yeah. We just finished our migration off of Splunk Cloud. I will not and cannot recommend it.

I dug the windows nt screenshot. Nice.

Sickening
Jul 16, 2007

Black summer was the best summer.

Diametunim posted:

I can't take this PCI audit anymore. Six months of auditing is too god drat long for everybody to pass their laundry list of blunders over to InfoSec because we're responsible for everything in the end. I just want to die.


Auditing is a huge part of infosec? Crazy

Sickening
Jul 16, 2007

Black summer was the best summer.

Proteus Jones posted:

Via SecFuck thread


So who else is going to inspect their server hardware for tiny bumps that could hack their entire system?

Sickening
Jul 16, 2007

Black summer was the best summer.
Governments are for the rich and the protection of their assets.

Sickening
Jul 16, 2007

Black summer was the best summer.

Martytoof posted:

CISSP was the most worthless cert I ever achieved. That said, it was also the most profitable.

The entire thing is baffling. The test is fairly easy yet the dumb outside requirements and corporate adoption keeps it a thing.

Sickening
Jul 16, 2007

Black summer was the best summer.

Proteus Jones posted:

Remember, this is the same company that was knocking people’s mobile hotspots out of the air to force them to use their pay-to-access guest network at conferences and hotels. And got slapped by the FCC for $600K fine.

The hilarious thing is I know the product they used and the vendor SPECIFICALLY told them using that particular feature in the way they wanted was illegal and HIGHLY NOT RECOMMENDED.

Oh no, not 600k.

Sickening
Jul 16, 2007

Black summer was the best summer.

Mystic Stylez posted:

I'm going to ask some very dumb questions, but please bear with me.

I'm currently working from home, so my boss installed OpenVPN in order for me to be able to access all the documents that are hosted in the company's server.

Whenever I'm connected through OpenVPN to access those work files, can he see anything that I do in my computer at all? Like, which websites I'm browsing right now or my browser traffic, for example. Or any other stuff that's personal like my computer files, etc.

What porn are you watching this morning?

Sickening
Jul 16, 2007

Black summer was the best summer.

Mystic Stylez posted:

So if I can get a separate computer with the VPN installed and only my work stuff there is it sufficient or do I need anything more?

Please make sure your work pays for this other computer.

Sickening
Jul 16, 2007

Black summer was the best summer.

Boris Galerkin posted:

And I’m saying the time to assume Facebook isn’t doing awful evil poo poo is over. It’s time to assume they are unless they can show otherwise.

I don’t see the benefit to be this emotionally invested.

Sickening
Jul 16, 2007

Black summer was the best summer.

Klyith posted:

Context. The same image can be CP is one context and innocent in another.

Let's not have this stupid discussion.

Context: you are a loving idiot.

Sickening
Jul 16, 2007

Black summer was the best summer.

Virigoth posted:

You are right they don't BUT they have always been super transparent and explanatory on what they are doing for X and Y just like we are when we provide tooling to our developers. This is a strong turn towards just yelling out mandates randomly after an audit with little to no explanation. This is a disturbing and growing trend. They usually provide these explanations, metrics, etc because we all like to learn and grow from how we do things on our product and how our culture is setup. This is a big step backwards for our culture and product to start throwing up walls and not communicating. I'm glad it looks like a standard tool, and I don't do any weird illegal poo poo on my laptop anyway because I'm not a complete fuckup, but I always like to try to check / learn as much as I can about these things.

I think its reasonable to not thoroughly discuss your security watch dog tools with the people its intended to watch over. I don't think its anything to get concerned over.

Sickening
Jul 16, 2007

Black summer was the best summer.

The Fool posted:

Welp, I can't think of a more impactful anti-endorsement than that.

No poo poo.

Sickening
Jul 16, 2007

Black summer was the best summer.

Ranter posted:

Yes I have full insight, our mfa service requires a small app on their device so I know we have old android devices out there. If we cut them off because we require a minimum version of android, but we also explicitly won't reimburse them for a new phone or at least partially reimburse, that's a dick move, no? They can say "I can't afford a new phone but you require me to have it to log in to our systems. Either pay for a new phone for me, give me a phone, or disable the 2fa requirement when logging in to applications."

I wonder what goons opinion on this is, I feel like I need to have management change company policy to reimburse for phones since we currently require byod and 2fa leveraging the device they bring.

Or just accept the risk and allow old android 6 or android 7 devices?

My company is getting into the legal jungle of this right now. My company doesn't want to pay a stipend to its 10k employees. We will see how it shakes out.

Sickening
Jul 16, 2007

Black summer was the best summer.

AlternateAccount posted:

Uhhh, that's not a thing. You can always ask for it, but confiscation of personal property, regardless of what you think it may or may not contain, is a good way to get sued in a slam-dunk easy fat settlement. Do no do this.

I find it disturbing that someone even assumes they can take an employees personal property.

Sickening
Jul 16, 2007

Black summer was the best summer.
Please don’t put a belt clip on a phone.

Sickening
Jul 16, 2007

Black summer was the best summer.

I like the comments. This person could have gotten 2k in bounties!

Microsoft bounty program is such poo poo.

Sickening
Jul 16, 2007

Black summer was the best summer.
Its really not a good idea to rock the boat right away. Even something as dumb as that. Humans are just weird and its usually always better to right it down and revisit it in the near future.

Sickening
Jul 16, 2007

Black summer was the best summer.

PBS posted:

Are you the guy that got a bunch of people, rightfully, fired within like a month of joining a new company?

True.

They were people who report to me and reading the C level email is a big deal. I wouldn't put those two things in the same category. I could have gotten fired for not take action the way I did.

Sickening fucked around with this message at 00:27 on Jun 4, 2019

Sickening
Jul 16, 2007

Black summer was the best summer.
The mpl both recently invited some great people as well as cemented that they absolutely no clue on the direction of the mpl.

Sickening
Jul 16, 2007

Black summer was the best summer.

Internet Explorer posted:

We had an issue with Adobe Acrobat and ADFS due to our non-persistent VDI. They basically stopped offering serial keys with their cloud products, so you have to use their "log into account = licensed" scheme. The problem is that it would intermittently log users out between VDI sessions with no rhyme or reason. Then add in that the user actually had to log in, instead of SSO just logging them in automatically, and it was a huge headache. Users would be prompted for username and password and when they'd enter the username field and tab/click down to password, it would pass them through. Problem with that is users would panic and call because they didn't know their password.

~6 months of troubleshooting with Adobe and they could never figure it out. They also couldn't say that they were working on login-less SSO. The poo poo I had to pull to get us a refund on our yearly subscription so we could outright buy non-cloud licenses was insane. It was one of the dumbest and most painful things I've had to deal with in IT. Their outsources support and "developers" were completely awful and there was no one in North America that knew enough or cared enough to escalate to. I had to threaten our VAR to switch all of our business to another VAR to get it resolved.

[Edit: The authentication would then cause all sorts of awful problems. It would break the Adobe Distiller, even once users got logged into Adobe Acrobat. Same with the PDF preview pane, the browser plugin, etc. gently caress Adobe.]

Do you use fslogix by chance?

Sickening
Jul 16, 2007

Black summer was the best summer.
Does the CISSP test as easy as it looks?

Sickening
Jul 16, 2007

Black summer was the best summer.

xtal posted:

A good alternative is nothing because certifications don't really matter at all

I wish we lived in a world where this was always true.

Adbot
ADBOT LOVES YOU

Sickening
Jul 16, 2007

Black summer was the best summer.

xtal posted:

I wasn't even trying to be controversial, I've never met anybody who cares about certifications. I could see it being useful as a freelancer if you need to convince laymen, or if you're starting off and don't have anything on your resume yet.

If only it mattered who you have met. It’s not the end all be all or even super important, but to say it doesn’t matter is naive.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply