Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

kalstrams posted:

0day posting

Adbot
ADBOT LOVES YOU

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

w
o
w

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

minivanmegafun posted:

a friend of mine broke her ankle and is TSA pre check approved and just went through hell at Newark because crutches might have explosives or something?

or it might be because she's half-Chinese idk

crutches are hollow also security theater

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
real sec talk: what's the right way to handle app secrets? it used to be you'd inject them as env vars for the user running your application but that's still really vulnerable because if the box gets owned your db creds are leaked.

we're investigating using hashicorp vault but i can't help but think this is a solved problem already and we're just reinventing the wheel

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

ErIog posted:

Umm.. why's your poo poo logging into a db directly from a client? Isn't that kind of a no no?

Shouldn't the users have their own creds and only access the database via some interface you've put between users and the actual DB?

Are you Tommy Refenes?

uh what the gently caress are you talking about? of course db access is sitting behind an api. client in this case refers to a service or set of services. the goal in my case is the most secure way of delivering the connection string to an ec2 instance so the app hosted on it can use it to access a database

e: everything is behind a private subnet with restrictive security groups. it's more a question of how to federate access to secrets in such a way that they're not available to all apps, including those that might not need them. case in point, we have a service that needs cassandra credentials and one that needs mysql creds. there's no reason the app that needs c* creds should ever be able to get mysql creds.

Blinkz0rz fucked around with this message at 14:40 on Jun 28, 2016

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

jony ive aces posted:

define them as constants in each app's config.php file

don't trigger me plz

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Cocoa Crispies posted:

use PKI to allocate, rotate, and revoke per-instance client certificates; auth secrets don't move over the network, each client can be revoked or rotated independently, and your server config can be just validate clients are signed by the CA and acceptable by OCSP

that still doesn't really solve the problem because the app has to query the db somehow. we've thought about putting another dal app in front that handles cert validation, auth, etc. but that's a huge bottleneck even if we scale horizontally and doesn't buy us anything over temporary credentials like vault does.

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Subjunctive posted:

Yeah, we can push a config change those 10e5+ systems in under 2 minutes, or the whole thing would fall apart.

There was someone talking earlier about someone else who denigrated chef/ansible/hypershell/etc as being equivalent to bash scripts, but I don't know that they were in a position of power.

idk if you can share but it'd be cool to know how fb does infrastructure. we use a golden image model but it still takes between 15-20 minutes to bake an ami from mvn release to ami available even though a lot of it is resolving artifacts from nexus and tests

the downside to this is that if we need to make low level changes to the whole fleet everything has to be rebaked and that takes a bunch of time and coordination

are you guys doing anything similar or is it a whole different model?

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Volmarias posted:

So should I be concerned, or aroused, or both, or what?

mainly aroused imo because a bug bounty program worked perfectly and the company paid out without any issue

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Parallel Paraplegic posted:

why does nobody in the world understand how to do regex right :smith:

because regex is terrible

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
not to doxx myself but corp communications just emailed the company telling us to look for our logo in the new bourne movie and it gave me a hearty lol

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

BeOSPOS posted:

are you the bad guys in the movie?

i'm tommy lee jones

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Subjunctive posted:

I guess my order of priorities are: (appless) RF convenience, then keypad for other users, then the IoT control via zwave or zigbee or whatever, then logging and monitoring and break-in sirens and poo poo. I'll find the home automation thread, thanks all for the reassurance that locks all suck so I might as well go for convenience.

what's wrong with a key?

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

VikingofRock posted:

YOSPOS › Security Fuckup Megathread - v12.1.6 - The security aspect of cyber is very, very tough

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

k

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
idk if he's well known but i met jason chan who's the director of cloud security at netflix at reinvent and the poo poo they're doing is so loving ownage i want to work there so bad

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

Maximum Leader posted:

in america you can vote without an id. hosed up but true. people on reddit will actually defend this.

if it costs money in your state to get an idea then gently caress yeah you should be able to vote without an id

poll taxes are illegal hth

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
is there a secfuck thread approved, not-poo poo, consumer-grade networking hardware list floating around?

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

ratbert90 posted:

You know how I said I like Ubiquiti products.
My EdgeRouter wouldn't let me log in today. I held the reset button down for 10 seconds as per the instructions, and then it never came back up.

I yanked the cover off and connected a USB->Uart adapter to the pins, and saw that it's now kernel panicking because they were dumb enough to use NAND instead of EMMC.

Uboot has an option for TFTP boot though, so that's good right? Oh wait, Ubiquiti doesn't offer recovery firmware for the EdgeRouter X; fantastic.

So now I am making an OpenWRT initramfs image that I can hopefully use to format the NAND and put the stock firmware back on. JFC Ubiquiti.

well i'm sold

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS
but realtalk i'm stuck with a fios modem/router and i don't want to do nat bridging or any of that poo poo, just want a reliable, secure router with a strong wifi radio that i can use as an app to extend my network

Adbot
ADBOT LOVES YOU

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

ate all the Oreos posted:

i have a fios modem/router and the modem doesn't actually care if you're using the router, i'm pretty sure all i had to do was clone the MAC address on the WAN port and the modem happily connected to it and gave it a public IP. the FIOS router is also responsible for routing the coax data stuff for the TV part of FiOS but it seems perfectly fine with doing that while behind my router (on a separate network segment just for good measure)

i did that with a older buffalo router with tomato on it and remembering to redo some of the settings if the modem restarted was a huge pain. i'm sure someone figured out a better way but honestly :effort:

  • Locked thread