Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
BlankSystemDaemon
Mar 13, 2009



florida lan posted:

idk about freebsd on the desktop but it is p drat good as a server
I mean I probably have a case of Stockholms syndrome, but I've been using it on the desktop since 2000, and on a laptop for the past two years or so.

Adbot
ADBOT LOVES YOU

PIZZA.BAT
Nov 12, 2016


:cheers:


flakeloaf posted:

i'd say whichever of expressvpn and nordvpn is cheaper for you in the moment, because your clients are probably nosy simpletons and not some three-letter thingy, so time spent thinking about it beyond that is probably time wasted

works 4 me

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
i know that it's extremely unnecessary, but I keep a shutdown EC2 ubuntu instance with Wireguard installed that I can spin up via the AWS app at any time.

other than an a half-hour of initial setup it's easy to run and Suits My Needs and I pay less than a buck per month since it's honestly fairly rare I even need it.

Hed
Mar 31, 2004

Fun Shoe
If you're gonna go that route, use Algo. I use ExpressVPN for your original purpose because I'm lazy and agreed, just trying to avoid snooping / open wifis

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Hed posted:

If you're gonna go that route, use Algo. I use ExpressVPN for your original purpose because I'm lazy and agreed, just trying to avoid snooping / open wifis

Sorry, yeah, I meant Algo, I just use the WireGuard app to connect. I'm honestly not even that worried about the security of the VPN (although there's been quite a few fuckups on that side), I'm just super cheap.

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan
why even connect to a WiFi network if you think people will snoop on it

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

Vomik posted:

why even connect to a WiFi network if you think people will snoop on it

Sometimes I have bad reception, or I'm travelling without a decent data plan, sometimes I need to download a large file or watch youtube and I don't want to blow through my data caps.

Hed
Mar 31, 2004

Fun Shoe

Lain Iwakura posted:

they’re all their own flavour of bad

taiyoko posted:

Is there something about the RSA SecurID that you dislike?

Thanks guys. No particular hatred of the RSA thing, just looking for alternatives because most of the links that turned up seemed outdated.

So I don't X/Y the poo poo out of this:

I'm really just looking for an off-premise hosted webmail provider (think Exchange or GSuite) that allows for 2FA with the ability for me to also authenticate against the same service for other applications, so using RADIUS or something like it so that users can use the same creds/factors for a custom web app or VPN auth or whatever. I see some people doing 2FA with Google Auth (which is fine) but would also want the ability to use a disconnected token option like RSA SecurID or similar. Buying two services would be fine, would just want as much hosted off-premise as possible.

I can take this to the grays if it gets super off topic

mystes
May 31, 2006

Ur Getting Fatter posted:

i know that it's extremely unnecessary, but I keep a shutdown EC2 ubuntu instance with Wireguard installed that I can spin up via the AWS app at any time.

other than an a half-hour of initial setup it's easy to run and Suits My Needs and I pay less than a buck per month since it's honestly fairly rare I even need it.
Doesn't the instance's IP change when you restart it? Is there some automated way to set this up so you don't have to manually change the settings on the client? Or are you using DNS?

PIZZA.BAT
Nov 12, 2016


:cheers:


Vomik posted:

why even connect to a WiFi network if you think people will snoop on it

my clients tend to work in giant steel buildings which double as a faraday cage. just submitting this post takes a full 30 seconds to a minute. i want to be able to browse SA while I poop

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

mystes posted:

Doesn't the instance's IP change when you restart it?

no

https://aws.amazon.com/ec2/pricing/on-demand/#Elastic_IP_Addresses

ewiley
Jul 9, 2003

More trash for the trash fire

FIPSMODE Squad will bust your poo poo for even the wrong reasons

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
Extinction Level Event for FIPSmode yubikeys

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

ate poo poo on live tv posted:

Can you even get 4K 55" OLED Monitors? Or even just 4K OLED?

They're sold as "digital signs" mostly, they just TVs with the minimum necessary to show current signals

mystes
May 31, 2006

No? Isn't the default that the IP will change unless you allocate an elastic ip address? Plus, if you do that aren't you paying $3.6/mo just for the IP address even if you just keep the instance stopped? Ur Getting Fatter said he/she was paying less than a dollar a month, so I don't think that can be how he/she had it set up.

mystes fucked around with this message at 16:07 on Jun 18, 2019

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

A thing of beauty.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
that also appears to be a usb device that will be physically impossible to remove if it is fully inserted into the slot

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

mystes posted:

Doesn't the instance's IP change when you restart it? Is there some automated way to set this up so you don't have to manually change the settings on the client? Or are you using DNS?

yeah, I use No-IP.org for dynamic dns. Means you need to wait about 60 seconds after launching the instance for the dns update to go through, but other than that it's fairly painless.

The Fool
Oct 16, 2003


Hed posted:

Thanks guys. No particular hatred of the RSA thing, just looking for alternatives because most of the links that turned up seemed outdated.

So I don't X/Y the poo poo out of this:

I'm really just looking for an off-premise hosted webmail provider (think Exchange or GSuite) that allows for 2FA with the ability for me to also authenticate against the same service for other applications, so using RADIUS or something like it so that users can use the same creds/factors for a custom web app or VPN auth or whatever. I see some people doing 2FA with Google Auth (which is fine) but would also want the ability to use a disconnected token option like RSA SecurID or similar. Buying two services would be fine, would just want as much hosted off-premise as possible.

I can take this to the grays if it gets super off topic

O365 + Azure MFA will check all of those boxes.

Shaggar
Apr 26, 2006
yeah theres an azure MFA plugin for NPS so you can have azure do MFA for anything that supports radius

ewiley
Jul 9, 2003

More trash for the trash fire

Hed posted:

Thanks guys. No particular hatred of the RSA thing, just looking for alternatives because most of the links that turned up seemed outdated.

So I don't X/Y the poo poo out of this:

I'm really just looking for an off-premise hosted webmail provider (think Exchange or GSuite) that allows for 2FA with the ability for me to also authenticate against the same service for other applications, so using RADIUS or something like it so that users can use the same creds/factors for a custom web app or VPN auth or whatever. I see some people doing 2FA with Google Auth (which is fine) but would also want the ability to use a disconnected token option like RSA SecurID or similar. Buying two services would be fine, would just want as much hosted off-premise as possible.

I can take this to the grays if it gets super off topic

Yeah Azure will do this just fine. They are adding support for OATH tokens soon so you buy whatever tokens you want that are standard OATH with seeds and use them with Azure if you really love hard keyfobs.

https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

today in secfuck: I log into aws for work and the first thing that pops up is: secwarning, this function sends your credentials as strings use function_safe instead

how long has this been the case? it’s left as a thought exercise for the reader

Hed
Mar 31, 2004

Fun Shoe
Thanks guys for the help with the multi factor... looks like the Azure stuff is actually good

Partycat
Oct 25, 2004

entrust has a token as well

I’ve had to “synchronize” my token a few times by providing the serial and then several subsequent generated codes but it works otherwise

DrPossum
May 15, 2004

i am not a surgeon

ewiley posted:

FIPSMODE Squad will bust your poo poo for even the wrong reasons

FIPSMODE is the greatest

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
fails in providing security

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

~Coxy posted:

this should default to off now that everyone has 4G with decent data caps

ios has so much jank in it left behind from the 2008 days that they've never revisited

the thing that boggles my mind is that there have been third-party android apps that manage your wifi radios silently and efficiently for years, but the ios behaviors for the same task are garbage. the open-source android apps record the cell-tower and/or GPS data around where your saved wifi networks are, and then just straight up turn the radio off if you aren't near them, which is a great. it improves your security and it saves battery too. the ios equivalents to this are just awful

part of this is ofc the fact that android lets you download any old sketchy app to do important system functions like "turn wifi on and off" but c'mon timb!! your poo poo is garbage over here

Bulgakov
Mar 8, 2009


рукописи не горят

D. Ebdrup posted:

I mean I probably have a case of Stockholms syndrome, but I've been using it on the desktop since 2000, and on a laptop for the past two years or so.

my tv runs freebsd. works for me.

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



Bulgakov posted:

my tv runs freebsd. works for me.

lol, i bet your tv cant even run any of the popular viruses, just lmao

Proteus Jones
Feb 28, 2013



Are Samsungs Android TVs, or do they run that garbage fire OS they developed in-house?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
idk if they're tizen branded now now, but they used to be a generic linux platform developed by samsung in house

they were also insecure as poo poo back in the day and samsung has actually had malware scanning for their tvs for quite a while

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

infernal machines posted:

malware scanning for their tvs

What an amazing future this turned out to be

Bulgakov
Mar 8, 2009


рукописи не горят

Lutha Mahtin posted:

the thing that boggles my mind is that there have been third-party android apps that manage your wifi radios silently and efficiently for years, but the ios behaviors for the same task are garbage. the open-source android apps record the cell-tower and/or GPS data around where your saved wifi networks are, and then just straight up turn the radio off if you aren't near them, which is a great. it improves your security and it saves battery too. the ios equivalents to this are just awful

part of this is ofc the fact that android lets you download any old sketchy app to do important system functions like "turn wifi on and off" but c'mon timb!! your poo poo is garbage over here

that anroid behavior sounds completely awful

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Bulgakov posted:

that anroid behavior is really something awful

flakeloaf
Feb 26, 2003

Still better than android clock

infernal machines posted:

idk if they're tizen branded now now,

they are

as are their digital displays so if you think you're saving money buying a QH55H display instead of a Q8FN television.... well maybe you're better at google than me, cause i see no way that's the case

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


love to put success conditions in the url and not validate them anywhere

quote:

Yesterday, the SEC announced that they'd found a second, even more disturbing pattern of cheating, one that went right to the top, with Big Four accounting firm KPMG's most senior staff cheating on their integrity exams. The tests were delivered online, and in the URL for the test was a variable that set the percentage needed for a passing grade: "MasteryScore=70" -- by lowering this value, cheaters could turn any number of right answers into a pass

http://fcpacompliancereport.com/2019/06/day-reckoning-kpmg-failures-ethics/

spankmeister
Jun 15, 2008






duz posted:

love to put success conditions in the url and not validate them anywhere


http://fcpacompliancereport.com/2019/06/day-reckoning-kpmg-failures-ethics/

Hahah, well earned imo

The Fool
Oct 16, 2003


This is timely, since I have a bunch of KPMG auditors running around the place right now.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
quick request for anyone running fedora or similar, with selinux enabled, booting with grub and efi

please paste me the output of:
ls -lZ /usr/sbin/grub2-set-bootflag /boot/grub2/grubenv /boot/efi/EFI/fedora/grubenv

many thanks

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

Rufus Ping posted:

quick request for anyone running fedora or similar, with selinux enabled, booting with grub and efi

please paste me the output of:
ls -lZ /usr/sbin/grub2-set-bootflag /boot/grub2/grubenv /boot/efi/EFI/fedora/grubenv

many thanks

i'm running centos, that counts right

code:
ls: cannot access /usr/sbin/grub2-set-bootflag: No such file or directory
ls: cannot access /boot/grub2/grubenv: Permission denied
ls: cannot access /boot/efi/EFI/fedora/grubenv: Permission denied

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply