Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CLAM DOWN
Feb 13, 2007




Tab8715 posted:

For organizations that don't deploy windows updates to desktops immediately after release, how do you keep the latest security threat out?

Some organizations just don't give a poo poo about security man.

Adbot
ADBOT LOVES YOU

Docjowles
Apr 9, 2009

along the way posted:

WSUS is dead easy to implement. Might want to setup a small test group too so you can roll out the updates to them first before approving them for the whole office. Not fun coming into work realizing an overnight update caused every other client PC to not boot/do weird poo poo.

Yes, do this. There was an update to IE ~3 years ago that changed something to do with how it negotiated SSL connections and it broke an app that literally the entire company I worked at relied on daily. That was a fun day.

The takeaway from an incident like that (and every sysadmin probably has one) isn't "don't patch lol". It's to do exactly what Along the way said. Create a test OU that covers a small number of tech savvy users outside of the IT group. People in customer support or development or sales who actually use all of your supported apps and can provide useful feedback if they suddenly break. Don't make your test group consist of just yourself or the IT team; you don't use the apps the same way the real users do. They will catch issues you never would.

Roll updates to the test group. If everything is good for whatever period you deem appropriate, update everyone else. If not, block the update and either wait for it to be reissued or work out a mitigation strategy. And god drat, set up WSUS and stop RDPing into everyone's desktop :420:

Pudgygiant
Apr 8, 2004

Garnet and black? More like gold and blue or whatever the fuck colors these are
IBM did something like that with beta / preview versions of Lotus Notes. You'd apply to be part of the beta program, and if your job title matched something technical like IT Specialist (they have catchall job titles, then job roles are more defined, so it'd be something like IT Specialist / Network Architect) the upgrade would get pushed. It'd be appealing as all hell because the new version would add incredibly basic functionality that every other email client has had for a decade, like the ability to search by sender, or threaded conversations. Then some relatively trivial functionally, but critical from a production perspective, piece of it would break, and you'd put in a bug note to the dev team and ideally get a hotfix back super quick. For instance, threaded conversations with participants in more than two time zones didn't work with 9.0.0. My lead put in a ticket, and a patch was put out within the hour. Pretty great and efficient, outside of edge cases like something critical breaking at night on a holiday, when nobody from the dev team is around to fix it.

Although the only takeaway from using Notes is "never use Notes".

hihifellow
Jun 17, 2005

seriously where the fuck did this genre come from

Tab8715 posted:

For organizations that don't deploy windows updates to desktops immediately after release, how do you keep the latest security threat out?

You still wait 'cause one of the patches in the batch Microsoft rushed out because of Sandworm has a no-boot issue. 99% of the time Windows Updates aren't an issue until they suddenly become a goddam huge one.

WhoNeedsAName
Nov 30, 2013

Tab8715 posted:

For organizations that don't deploy windows updates to desktops immediately after release, how do you keep the latest security threat out?

We deploy to a test machine, let it run for a few days and then deploy to production. To be honest, most SMB environments are too small for the creators of these exploits to bother with. With that said, reducing your external attack surface and training the users can mitigate a lot of malware based attempts.

psydude
Apr 1, 2008

Heartache is powerful, but democracy is *subtle*.

Tab8715 posted:

For organizations that don't deploy windows updates to desktops immediately after release, how do you keep the latest security threat out?

Depending upon your organization's size and budget, most IDS/IPS manufacturers will usually expedite the release of signatures to detect major exploits soon after they're discovered. Generally, your security analysts will specifically look for those exploits during your testing and evaluation phase for patches. This can be an imperfect solution if the exploit is so simple that it would generate a large number of false positives, but it's usually the best tradeoff between breaking your production environment and leaving everything completely unprotected while testing is under way.

CloFan
Nov 6, 2004

We rely on the user to perform the updates :suicide:

Unfortunately that's the case for Adobe and java as well, so we end up with lots of Ask Toolbars and Mcaffee security scans

Lil Miss Clackamas
Jan 25, 2013

ich habe aids

Docjowles posted:

And god drat, set up WSUS and stop RDPing into everyone's desktop :420:

We don't RDP into user's machines, we only patch the servers on patch days. Desktop patching is up to the user, but my users are quite tech-savvy and we've had zero problems decentralizing that part of the process. No Ask toolbars or anything. I like my users.

BaseballPCHiker
Jan 16, 2006

along the way posted:

WSUS is dead easy to implement. Might want to setup a small test group too so you can roll out the updates to them first before approving them for the whole office. Not fun coming into work realizing an overnight update caused every other client PC to not boot/do weird poo poo.

At least once a year Microsoft has to rollback a patch that they sent out that ends up loving something up. Just be like a week behind on your updates and you'll be fine.

I'm about to head to my 5th meeting about getting automatic updates pushed out. 5th! Why does something so simple have to take forever?

Bloodborne
Sep 24, 2008

psydude posted:

Depending upon your organization's size and budget, most IDS/IPS manufacturers will usually expedite the release of signatures to detect major exploits soon after they're discovered. Generally, your security analysts will specifically look for those exploits during your testing and evaluation phase for patches. This can be an imperfect solution if the exploit is so simple that it would generate a large number of false positives, but it's usually the best tradeoff between breaking your production environment and leaving everything completely unprotected while testing is under way.

Yep exactly this. Example: http://emergingthreats.net/daily-ruleset-update-summary-10142014/

I don't know if I'm a fan of ET's rules, but they kick them out quickly and you get to say in response meetings that signatures are in place if the platform vendor hasn't released theirs yet.

Zero VGS
Aug 16, 2002
ASK ME ABOUT HOW HUMAN LIVES THAT MADE VIDEO GAME CONTROLLERS ARE WORTH MORE
Lipstick Apathy
I like how I installed Windows 2012 Datacenter and it is running 6 VMs with Hyper-V, and it is telling me right now that it needs to reboot to apply updates, and if I click "later" it will restart in a day.

Who the gently caress do you think you are, server?! You have a lot of responsibilities now, you reboot when I tell you.

Edit: Also is HP's driver download portal down right now, is this the loving twilight zone?

Zero VGS fucked around with this message at 15:18 on Oct 16, 2014

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.
If you have a decent imaging infrastructure, you don't have to worry about breakages from patching right away because rolback becomes trivial. :eng101:

along the way
Jan 18, 2009

BaseballPCHiker posted:

At least once a year Microsoft has to rollback a patch that they sent out that ends up loving something up. Just be like a week behind on your updates and you'll be fine.

I do the test groups mostly to test for updates that aren't broken from MS's perspective but which might break our in-house or third party apps. Rare occurrence, but it happens. As someone suggested above, I have a group of power users from each department who get the updates first so they can test these issues for me by basically just working as they normally do and report back if there are any major problems with their apps/system potentially caused by an update. After a couple weeks and no issues, I begin approving the updates for the rest of the office.

Zero VGS
Aug 16, 2002
ASK ME ABOUT HOW HUMAN LIVES THAT MADE VIDEO GAME CONTROLLERS ARE WORTH MORE
Lipstick Apathy

Misogynist posted:

If you have a decent imaging infrastructure, you don't have to worry about breakages from patching right away because rolback becomes trivial. :eng101:

And on that note I just bought $3000 worth of Snap Deploy 5 licenses and this thing sucks. True Image has worked perfectly for me every time I've used it yet Snap Deploy from the same company has tossed out 10 different errors with 10 different models of PC. Restoring the same image (which Snap Deploy created) with True Image works fine yet Snap Deploy can't restore them itself. I feel like I'm beta testing their poo poo for them. They even had the gall to send me to India tech support a day after I bought this stuff. They used to just bring an engineer into the call.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Zero VGS posted:

I like how I installed Windows 2012 Datacenter and it is running 6 VMs with Hyper-V, and it is telling me right now that it needs to reboot to apply updates, and if I click "later" it will restart in a day.

Who the gently caress do you think you are, server?! You have a lot of responsibilities now, you reboot when I tell you.

Edit: Also is HP's driver download portal down right now, is this the loving twilight zone?

Some defaults are the worst, here's a big pet peeve of mine.



Why would you ever leave this off?

along the way
Jan 18, 2009

Tab8715 posted:

Why would you ever leave this off?

User response: "It takes up too much room."

FISHMANPET
Mar 3, 2007

Sweet 'N Sour
Can't
Melt
Steel Beams

Pudgygiant posted:

IBM did something like that with beta / preview versions of Lotus Notes. You'd apply to be part of the beta program, and if your job title matched something technical like IT Specialist (they have catchall job titles, then job roles are more defined, so it'd be something like IT Specialist / Network Architect) the upgrade would get pushed. It'd be appealing as all hell because the new version would add incredibly basic functionality that every other email client has had for a decade, like the ability to search by sender, or threaded conversations. Then some relatively trivial functionally, but critical from a production perspective, piece of it would break, and you'd put in a bug note to the dev team and ideally get a hotfix back super quick. For instance, threaded conversations with participants in more than two time zones didn't work with 9.0.0. My lead put in a ticket, and a patch was put out within the hour. Pretty great and efficient, outside of edge cases like something critical breaking at night on a holiday, when nobody from the dev team is around to fix it.

Although the only takeaway from using Notes is "never use Notes".

One of the schools my wife teaches at uses Lotus Notes for email. She asked me how she could search. I poked around the interface, I googled, I can't figure out how to search. So yeah, never use Notes. When she first showed it to me I was like wuuuuuuuuuuut :what:

Bloodborne
Sep 24, 2008

Tab8715 posted:




Why would you ever leave this off?

Is this a real question? Because I like and want the choice to display or hide what I like.

Japanese Dating Sim
Nov 12, 2003

hehe
Lipstick Apathy
Thank you, iTunes, for causing a Code 19 on this laptop's DVD drive. :argh:

Took all of 10 seconds to Google after reinstalling the drivers didn't fix it. But seriously, why are you so bad iTunes.

bobmarleysghost
Mar 7, 2006



Tab8715 posted:

Some defaults are the worst, here's a big pet peeve of mine.



Why would you ever leave this off?

Because I have a shitload of poo poo running

Pudgygiant
Apr 8, 2004

Garnet and black? More like gold and blue or whatever the fuck colors these are

FISHMANPET posted:

One of the schools my wife teaches at uses Lotus Notes for email. She asked me how she could search. I poked around the interface, I googled, I can't figure out how to search. So yeah, never use Notes. When she first showed it to me I was like wuuuuuuuuuuut :what:

Everything before 9.x has a really loving hidden magnifying glass button in one of the left pane menus. 9.x has a search bar at the top, so that's an improvement. Unfortunately the search backend is still a Mexican kid reading through all your emails, so a search of a mailbox with 3 emails takes an hour and locks up your entire system. Also as of when I left earlier this year you could only search plain text, not anything fancy like "sender: " or "date: ".

SyNack Sassimov
May 4, 2006

Let the robot win.
            --Captain James T. Vader


Santa is strapped posted:

Because I have a shitload of poo poo running



Looks like you need a bigger monitor then.

(That's not a joke, if you can't fit all the poo poo you're running in your systray you need a bigger monitor. I'm totally with Tab on this one, should be a default to show all icons).

along the way
Jan 18, 2009
I force the notification tray to show via GPO so I can see immediately if there is any WeatherBug, etc bullshit going on if I have to troubleshoot a workstation.

FISHMANPET
Mar 3, 2007

Sweet 'N Sour
Can't
Melt
Steel Beams

Pudgygiant posted:

Everything before 9.x has a really loving hidden magnifying glass button in one of the left pane menus. 9.x has a search bar at the top, so that's an improvement. Unfortunately the search backend is still a Mexican kid reading through all your emails, so a search of a mailbox with 3 emails takes an hour and locks up your entire system. Also as of when I left earlier this year you could only search plain text, not anything fancy like "sender: " or "date: ".

Also she uses the web interface exclusively.

CLAM DOWN
Feb 13, 2007




Potato Alley posted:

Looks like you need a bigger monitor then.

(That's not a joke, if you can't fit all the poo poo you're running in your systray you need a bigger monitor. I'm totally with Tab on this one, should be a default to show all icons).

That's dumb, I hide a lot of stuff in my system tray, why on earth do I always need to see Outlook "O" icon while I have Outlook open on one screen 24/7. It makes total sense to hide some icons.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Santa is strapped posted:

Because I have a shitload of poo poo running



Make it double-wide?

I want to know what's running on my workstation or what isn't running. It's not like display real estate is at a high-cost with HD Monitors.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

CLAM DOWN posted:

That's dumb, I hide a lot of stuff in my system tray, why on earth do I always need to see Outlook "O" icon while I have Outlook open on one screen 24/7. It makes total sense to hide some icons.

Why the gently caress does every app need an icon? :argh:

DrAlexanderTobacco
Jun 11, 2012

Help me find my true dharma

Tab8715 posted:

Make it double-wide?

I want to know what's running on my workstation or what isn't running. It's not like display real estate is at a high-cost with HD Monitors.

Then tick the button.

Phil Tenderpuss
Jun 11, 2012
I wanted to say thanks for the career advice you guys gave me a little while ago about taking the job with the Indian staffing company that seemed shady. I declined their offer. Turns out that a much better position which I had applied for that I thought was a long shot has offered me a contract! I'll be working on a project for the government that I think will really further my career. I just accepted the offer today.

I'm new to not only contracting, but government jobs as well so I'm excited but a bit nervous. I need to get my Security+ certification and pass a secret clearance investigation before I can log into a government server and really start work. Good news is that until then I'll still be billable and will just be working in an advisory role to the rest of the team.

Does anybody have any advice on studying for and passing the Security+? I don't have any other certs so I'm a complete newbie there, too. Also, can anyone tell me what to expect from a secret clearance investigation and give me any advice on the process?

Che Delilas
Nov 23, 2009
FREE TIBET WEED

Bob Morales posted:

Why the gently caress does every app need an icon? :argh:

Gotta have something to associate with those loving balloon announcements that never matter ever.

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!

Phil Tenderpuss posted:

I wanted to say thanks for the career advice you guys gave me a little while ago about taking the job with the Indian staffing company that seemed shady. I declined their offer. Turns out that a much better position which I had applied for that I thought was a long shot has offered me a contract! I'll be working on a project for the government that I think will really further my career. I just accepted the offer today.

I'm new to not only contracting, but government jobs as well so I'm excited but a bit nervous. I need to get my Security+ certification and pass a secret clearance investigation before I can log into a government server and really start work. Good news is that until then I'll still be billable and will just be working in an advisory role to the rest of the team.

Does anybody have any advice on studying for and passing the Security+? I don't have any other certs so I'm a complete newbie there, too. Also, can anyone tell me what to expect from a secret clearance investigation and give me any advice on the process?

Congrats! Sounds awesome. You should have np with the clearance, it just takes a while. They care more about credit history than they do actual criminal offenses, and there isn't a very high bar set either.

As for Sec+: http://blogs.getcertifiedgetahead.com/security-blog-links/ this and only this.

Potato Alley posted:

Looks like you need a bigger monitor then.

(That's not a joke, if you can't fit all the poo poo you're running in your systray you need a bigger monitor. I'm totally with Tab on this one, should be a default to show all icons).

I have 2 24" monitors and still hide my notifications because I don't give a poo poo.

But I do have taskbar buttons set to "never combine"

Fiendish Dr. Wu fucked around with this message at 20:26 on Oct 16, 2014

Yeast Confection
Oct 7, 2005
Can anyone recommend any decent security blogs? I'm not well-informed on that side of the industry because it's outside of my purview, but I would like to stay informed.

CloFan
Nov 6, 2004

Ashley Madison posted:

Can anyone recommend any decent security blogs? I'm not well-informed on that side of the industry because it's outside of my purview, but I would like to stay informed.

Krebsonsecurity.com if you aren't already visiting it. He's the guy who broke the Target breach story late last year, and a few other big stories besides.

THF13
Sep 26, 2007

Keep an adversary in the dark about what you're capable of, and he has to assume the worst.

Ashley Madison posted:

Can anyone recommend any decent security blogs? I'm not well-informed on that side of the industry because it's outside of my purview, but I would like to stay informed.

It's not a blog but I really like the Security Now podcast to stay up to date.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Ashley Madison posted:

Can anyone recommend any decent security blogs? I'm not well-informed on that side of the industry because it's outside of my purview, but I would like to stay informed.

Security like what?

Bloodborne
Sep 24, 2008

Ashley Madison posted:

Can anyone recommend any decent security blogs? I'm not well-informed on that side of the industry because it's outside of my purview, but I would like to stay informed.

A few and in no order:

http://www.darknet.org.uk/

http://www.wired.com/category/threatlevel/

http://krebsonsecurity.com/

http://nakedsecurity.sophos.com/

http://threatpost.com/

http://blogs.technet.com/b/security/

http://www.fireeye.com/blog/

http://blog.sucuri.net/

Bloodborne fucked around with this message at 20:56 on Oct 16, 2014

Phil Tenderpuss
Jun 11, 2012

Fiendish Dr. Wu posted:

Congrats! Sounds awesome. You should have np with the clearance, it just takes a while. They care more about credit history than they do actual criminal offenses, and there isn't a very high bar set either.

As for Sec+: http://blogs.getcertifiedgetahead.com/security-blog-links/ this and only this.

Awesome thanks! I'll get that book and start studying. Good to hear that the clearance investigation isn't as strenuous as I thought it might be. I've got exceptional credit so that won't be a problem. Do you know how much talking to my former employers will factor into their decision? I was fired from my last job due to some personal problems I was having at the time (they still said they'd give me a recommendation so not on bad terms) and at the job I had before that the boss hates me since I kinda screwed him over. If they talked to my last employer I'm not sure what they'd say but if they talked to that guy, he'd definitely try to gently caress me over.

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin
From my understanding of the security clearance process, there's only one real question: Are you susceptible to blackmail or bribery?

Having a manageable amount of debt isn't a big deal, but if you reach a point where they think you'll be under enough stress to do something dumb to get money, that's a risk.
Being gay isn't a big deal, being secretly gay might be a problem if they think you'd do something dumb to keep it secret.

DrAlexanderTobacco
Jun 11, 2012

Help me find my true dharma
Money/lack thereof is viewed as most important because historically, that's what informants/spies fall for. If you have a weakness it's important to demonstrate how you're actively working to resolve that weakness.

Here's a list of judgements from 2012. Industrial, but other categories are listed on the site as well.

http://www.dod.mil/dodgc/doha/industrial/2012.html

Adbot
ADBOT LOVES YOU

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

Misogynist posted:

If you have a decent imaging infrastructure, you don't have to worry about breakages from patching right away because rolback becomes trivial. :eng101:
hahahahahaha

try reimaging hundreds of PCs over <10mbps WAN links. Hell, some of my branch locations still only have 1x or 2x MPLS T1s.

We auto approve critical and security updates, and manually approve anything else. We have yet to have a serious issue.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply