Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Wibla
Feb 16, 2011

Defenestrategy posted:

is everyone else going through steps to rearchitecting their jobs network to a more "zero trust based" network or is it just me?

I hate this, I hate zero trust, I hate everything involved in it, and I just want to check out until this is all over. Having to do all this crap in place instead of just blowing away the network and starting fresh is annoying.

We're rolling out a greenfield underlay network based on SR-MPLS for all our OT poo poo, then moving all our existing poo poo over to that network piece by piece. We can only do this because we have spare fibre capacity going literally everywhere, and I am eternally grateful for that fact. Trying to "do it live" would have sucked so hard.

Adbot
ADBOT LOVES YOU

Wibla
Feb 16, 2011

BlankSystemDaemon posted:

KeePass and SyncThing work extremely well together if you have at least one machine you can leave running all the time.

I use KeePass with Dropbox, seems to work fine.

Work has 1password, so I get a free personal account there, I should probably switch.

Wibla
Feb 16, 2011

Thanks Ants posted:

I know because it happened to us this week, someone got phished, we reset their password and authentication methods and then they set their password back to the same thing it was before, and someone submitted a bunch of emails through it :suicide:

Oh for fucks sake :negative:

Wibla
Feb 16, 2011

I blocked 445 outbound from my WiFi segment just in case. Don't use outlook on my personal machines anyway.

Wibla
Feb 16, 2011

This should be a fun one to deal with :haw:

https://twitter.com/ItsSimonTime/status/1636857478263750656

Wibla
Feb 16, 2011

BlankSystemDaemon posted:

The one thing Edge got right, is that it implements a sandbox that's enforced from a higher privilege (ie. by using VMENTER/VMEXIT for hardware-assisted virtualization).

That is literally the only thing they got right. Beyond that it's full of Microsoft bullshit.

Wibla
Feb 16, 2011

RFC2324 posted:

Its a home lab for my partner and me, between my system overengineering, and her network overengineering, it's pretty rare for us not to have something broken.

That's why you have a separate uSFF box for the stuff that you actually need online :colbert:

Wibla
Feb 16, 2011

jaegerx posted:

Don’t use google authenticator sync to cloud

:allears:

Wibla
Feb 16, 2011

some kinda jackal posted:

MOVEit the gently caress off your network

:golfclap:

Wibla
Feb 16, 2011

KS posted:

gently caress Cisco.

:emptyquote:

Wibla
Feb 16, 2011

Thanks Ants posted:

No you see to be compliant with what this third party says we have to give up our passwordless identity platform and return to enforced password complexity with 30 day expiration.

Yeet the third party out a window.

Wibla
Feb 16, 2011

It's time to move off Azure, y'all

https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr

:yikes:

Wibla
Feb 16, 2011

Head Bee Guy posted:

Do you guys like your jobs?

Most days of the week.

Not the days of the week I have to be in meetings to deal with Azure Stack HCI though.

Seems pretty hollow to implement full network micro-segmentation and spending stupid amounts of money on Palo Alto firewalls, only to have IT move our SCADA VM stack from VMware to Azure Stack HCI ... that requires all VMs to talk to the loving cloud :negative:

Wibla
Feb 16, 2011

They say it keeps working, but we obviously lose all the fancy functionality.

Wibla
Feb 16, 2011

i am a moron posted:

Stack has nothing to do with Azure regions being available afaik. I’ve been doing azure consulting for… I dunno a decade or something but I’ve never actually implemented it so I could be wrong. That would be counter to the entire premise of using it. It’s dumb for a billion other reasons though

Stack will run up to 30 days offline, yeah.

It's still really dumb.

Wibla
Feb 16, 2011

Internet Explorer posted:

But please don't turn this into a troubleshooting thread. These poor infosec folks have been abused enough.

Thank you :glomp:

I got a mail from a consultant on the way home from work today, they want all the things opened to the internet from one of our SCADA zones because of Azure bullshit. Of course it has to happen yesterday. I want to strangle someone.

A stiff drink feels very tempting at this point.

Wibla
Feb 16, 2011

I have a well stocked liquor cabinet ... that I have to refill regularly.

Wibla
Feb 16, 2011

BonHair posted:

Be sure that the guys understand that you can't solve everything with automation, you gotta think a bit too. And also make sure they can talk to people, even in kinda hostile situations. You don't want introvert nerds who will break to any stupid demand unless you have someone to take all the battles for them. I dunno, try lightly teasing the candidates about their education or something and see if they fight back or just agree with your dumb opinions. But they also gotta be flexible, so don't get too arrogant young white men.

The. What?

E: ok now that my brain has had some time to simmer down from that, here's some actual content: When you lead a team, they work for you, they're your people. Your job is to make them the best they can be, and to shield them from the inevitable bullshit that comes from (upper) management. If you take care of your people, they will take care of you.

Wibla
Feb 16, 2011

GrunkleStalin posted:

Thank y’all for the advice. It helped me calm down and recover from my doom spiral.

The fact that you're worried means you'll more than likely be fine.

Wibla
Feb 16, 2011

I had no meetings today :sun:

Wibla
Feb 16, 2011

BonHair posted:

Preferably, get a buddy you can set up fake meetings with, since calendar time marked "busy" will often just get ignored by the meeting people.

Be ruthless when declining meetings. They'll get the point sooner or later. Or they'll make do without you in that meeting.

Diva Cupcake posted:

What's it like being on vacation?

I'm not on vacation :colbert:

(See also: the above).

Wibla
Feb 16, 2011

cr0y posted:

I just had an OT engineer shocked, SHOCKED that we run CrowdStrike on our industrial control servers. He had an unrelated issue, and is now making enough noise that we should:

Disable windows firewalls
Disable all automatic updates
Remove AV
If AV can't be removed, disable ALL automatic definition updates.

On our fleet of um.... a lot of servers.

I'm an OT (networking) engineer, and I would fire this person.

some kinda jackal posted:

If this is part of an active incident with operational impact then help triage and trouibleshoot and disable with proper incident management approval. If he's just making noise then feed him a security policy exception form to get signed off by the CIO or whoever. Let them explain why they don't need to follow policy.

This is the only exception I will allow, it's been several days since the last time we had to do it :smith:

Wibla
Feb 16, 2011

We recently implemented geofiltering and cut down on inbound crap by a lot. 10/10 would recommend.

Wibla
Feb 16, 2011

BonHair posted:

It's true, buying a pentest is a one time, measurable and budgetable action which does something related to security. Having a guy just telling you what the test would find is nebulous in all the important ways, especially since the recommendations are gonna include stuff like "keep things updated regularly" which is just gonna keep being nebulously expensive forever.

We ran a pentest, literally everyone went :stonklol:, now we're spending millions on upgrades, and plan on running another pentest after we're done fixing the major issues.

We're 100% going to find a bunch of new poo poo that the old test didn't find, I just know it. But I also know that our networks will be in much better shape, with new firewalls and a lot of work put into re-establishing proper segmentation that had eroded over years of "gently caress it stopped working, we gotta fix it now now now" type maintenance.

Wibla
Feb 16, 2011

MustardFacial posted:

Vibe check this statement for me:

It checks out.

Wibla
Feb 16, 2011

I feel seen.

I jumped from railway-oriented industrial automation to being an OT network engineer at a metro transit authority in January 2022. Now I am basically the principal engineer responsible for four separate city-wide OT networks, and while I have a reasonably good grasp of how things work, and we're doing a pretty good job of designing and rolling out a new SPBm/fabric based consolidated OT network, the additional workload from also dealing with network security, particularly for the OT virtualization stack (because IT dropped the ball, those fuckers) is quickly proving to be too much.

At least we're adding headcount, but it takes time to get people up to speed.

Wibla
Feb 16, 2011

We infosec'ed so hard that a redundant pair of PA firewalls that all traffic in the environment has to pass through failed in an odd way and took down everything for an hour because it didn't fail over as designed.

Wibla
Feb 16, 2011

Potato Salad posted:

do you work in my NOC, we had a bad PA fw failover during updates mess us up for a good hour when everyone started filtering back from lunch

No, I'm an OT network engineer at a metro transit authority :v: ... also on vacation!

We also have a change freeze in place for Easter, so it was just normal operations... I'm looking forward to the post mortem.

Wibla
Feb 16, 2011

Testing out KASM as a poor man's PAW solution. For the whopping two hours I spent setting it up, it works well. Latency and performance is nowhere near citrix vdi though...

Adbot
ADBOT LOVES YOU

Wibla
Feb 16, 2011

Cannon_Fodder posted:

Apparently Stuxnet 2 electric boogaloo is now being leveraged against Russian targets by Ukraine and called fuxnet

How long till that starts getting recycled?

Do you have a link to more info about this?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply