Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
haveblue
Aug 15, 2005



Toilet Rascal

Presto posted:

Yeah back in the early days they were handing out /8s like candy. Because we'll never use up all the addresses, lol.

256 internet users ought to be enough for anybody

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

haveblue posted:

256 internet users ought to be enough for anybody

I still wish all these drat children and casuals would get off my internet :cloud:

The_Franz
Aug 8, 2003

RFC2324 posted:

I still wish all these drat children and casuals would get off my internet :cloud:

remember, remember, eternal september

spankmeister
Jun 15, 2008






haveblue posted:

256 internet users ought to be enough for anybody

IP was a mistake, NCP should have been the end of it

Feisty-Cadaver
Jun 1, 2000
The worms crawl in,
The worms crawl out.
several years ago I was working on integrating with PC Cafes in Korea and that’s when I found out every PC cafe PC has a public IP address. abs really great internet speeds as well.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
just lmao
https://twitter.com/pdmcleod/status/1493364634556018694

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
this poo poo gets funny when you cross reference this givesendgo data with facebook 'breach'

just saying

brains
May 12, 2004


amazing how when you make wholesale rejection of expertise a plank of modern conservatism all you're left with is complete and total incompetence. who could have seen this coming.

brains
May 12, 2004

but enough about the c-suite,

frh
Dec 6, 2014

Hire Kenny G to play for me in the elevator.
https://twitter.com/MikaelThalen/status/1493614614009028620

frh
Dec 6, 2014

Hire Kenny G to play for me in the elevator.
https://twitter.com/MikaelThalen/status/1493649384625479681

toiletbrush
May 17, 2010
why is it that no matter what conservatives write about, the main themes are always punishment, revenge and a massive persecution complex

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


toiletbrush posted:

why is it that no matter what conservatives write about, the main themes are always punishment, revenge and a massive persecution complex

write what you love

4lokos basilisk
Jul 17, 2008


toiletbrush posted:

why is it that no matter what conservatives write about, the main themes are always punishment, revenge and a massive persecution complex

they know they are terrible people and they are very frightened about being potentially subjected to the same treatment as they currently dish out from a position of power

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

toiletbrush posted:

why is it that no matter what conservatives write about, the main themes are always punishment, revenge and a massive persecution complex

they are White, American and Male and nobody gives a poo poo and that is loving unacceptable.

devmd01
Mar 7, 2006

Elektronik
Supersonik
domain admins before: 31 accounts, 12 of which were service accounts

domain admins after: 6 accounts, of which one is domain\administrator.

global admins in 365 was a similar clean sweep, and I also tightened up Okta admins.

the infosec team doesn’t have any elevated rights except through their tools now. :getout:

Shaggar
Apr 26, 2006
y do u have okta if you have office365/azuread?

Sickening
Jul 16, 2007

Black summer was the best summer.

devmd01 posted:

domain admins before: 31 accounts, 12 of which were service accounts

domain admins after: 6 accounts, of which one is domain\administrator.

global admins in 365 was a similar clean sweep, and I also tightened up Okta admins.

the infosec team doesn’t have any elevated rights except through their tools now. :getout:

I hope you at least PIM'd the AAD roles.

Shame Boy
Mar 2, 2010

Sniep posted:

they are White, American and Male and nobody gives a poo poo and that is loving unacceptable.

canadian

devmd01
Mar 7, 2006

Elektronik
Supersonik

Sickening posted:

I hope you at least PIM'd the AAD roles.

we only have aad P1 licensing. some form of PIM is definitely next on the maturity curve and would be a good first project once my promotion goes through.

we are at least granting access with a separate elevated admin account, we’re not stupid enough to have real people accounts in them.

Hed
Mar 31, 2004

Fun Shoe
this is probably a good time to ask... all the SaaSes seem to gate their SSO connector behind "Enterprise" or a higher tier of service, but GSuite SSO seems to be the exception here.
Were they a first mover in SAML or something...?

SlowBloke
Aug 14, 2017

Hed posted:

this is probably a good time to ask... all the SaaSes seem to gate their SSO connector behind "Enterprise" or a higher tier of service, but GSuite SSO seems to be the exception here.
Were they a first mover in SAML or something...?

SSO on idp is mostly free, microsoft azure ad let you use it for saml without restrictions. Applications are the biggest issue since an awful lot of them demand special licensing to let you use saml or oauth instead of their own user db.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

azuread saml is p good

Hed
Mar 31, 2004

Fun Shoe
I don't think I phrased that well. I'm talking about this (pricing page for Sentry.io)



If you use GSuite, you can get SSO from a smaller tier. SAML2 is crossed out and only becomes available with "Business" or "Enterprise" tiers. I see this all the time for SaaS. Maybe GitHub and GSuite don't use SAML, I haven't looked into them. If so then that's probably my answer.

Progressive JPEG
Feb 19, 2003


"breech"

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

same difference tho if im looking at it objectively

Shaggar
Apr 26, 2006

Hed posted:

this is probably a good time to ask... all the SaaSes seem to gate their SSO connector behind "Enterprise" or a higher tier of service, but GSuite SSO seems to be the exception here.
Were they a first mover in SAML or something...?

not even remotely close to the first. microsoft has been doing saml forever (and wsfed before that) and its been free in all versions of windows server since like 2000. its free in azure ad as well.

Kazinsal
Dec 13, 2011



Sniep posted:

same difference tho if im looking at it objectively

yeah the difference is mainly healthcare vs. AR-15s

Shaggar
Apr 26, 2006
the paid IDP services like otka or ping are scams that own idiot CTOs

Shaggar
Apr 26, 2006

Hed posted:

I don't think I phrased that well. I'm talking about this (pricing page for Sentry.io)



If you use GSuite, you can get SSO from a smaller tier. SAML2 is crossed out and only becomes available with "Business" or "Enterprise" tiers. I see this all the time for SaaS. Maybe GitHub and GSuite don't use SAML, I haven't looked into them. If so then that's probably my answer.

they probably got paid by goog to include gsuite poo poo. either that or they're morons who actually like gsuite and want to promote it in their cheaper tiers.

but yeah consumers like that blocking saml behind more expensive tiers is a scam and a sign of bad software

devmd01
Mar 7, 2006

Elektronik
Supersonik

Shaggar posted:

the paid IDP services like otka or ping are scams that own idiot CTOs

in this case it was our idiot infosec manager. our initial use case was getting fully automated user provisioning from ultipro (nownworkday) set up, then we pivoted to it for sso.

all I know is that I don’t want to go through SSO migration for 100+ apps again so gently caress it we’re here to stay, it’s not my money.

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
i figured okta's actual selling point was that they had an army of people to reach out to other corps and badger them for a one-click setup or smth, since nobody likes configuring SSO

lol if they don't actually do that

frh
Dec 6, 2014

Hire Kenny G to play for me in the elevator.
https://twitter.com/MikaelThalen/status/1493724026144841732?t=syMxR8Jjl1ix69Pi5bO_nQ&s=19

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

I may or may not be tbl_prayers_count

Shaggar
Apr 26, 2006

devmd01 posted:

in this case it was our idiot infosec manager. our initial use case was getting fully automated user provisioning from ultipro (nownworkday) set up, then we pivoted to it for sso.

all I know is that I don’t want to go through SSO migration for 100+ apps again so gently caress it we’re here to stay, it’s not my money.

ultipro fuckin sucks rear end

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Volmarias posted:

I may or may not be tbl_prayers_count

I am almost certainly project_veritas_subscriber

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


shaggar you would lose your mind if you saw the utter shitshow that passes for "identity management" I have to deal with

like, Kerberos doesn't even work properly between parts of the domain without some weird workaround and there is no authoritative source of user entitlements.

E: I cannot Auth a webservice call from a Windows server because "negotiation doesn't work" so I have to call another DLL that gets a token somehow, then pass that in the http header then the receiver uses it to bind to AD I mean what the gently caress

Main Paineframe
Oct 27, 2010

absolutely incredible
https://twitter.com/micahflee/status/1493728697488084994
https://twitter.com/micahflee/status/1493734778427740165

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

hahahahahaha

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013





lomarf

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply