Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Zamujasa
Oct 27, 2010



Bread Liar
yoink :rip:

Adbot
ADBOT LOVES YOU

Wiggly Wayne DDS
Sep 11, 2010



crabrave.pw

Crime on a Dime
Nov 28, 2006
taking that as a no

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
*borat voice*

MAIFILE.cn

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Crime on a Dime posted:

viewed any images or links on any of these lately?

got your anti grabify on lock?

crab rave. SHREK IS LIFE

efb

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

sb hermit posted:

I don't see smartphones as a good mechanism for passwordless logins in high security situations. Heck, for certain areas, having a powered-on smartphone itself would be an auditable event. Much better to have a smartcard or yubikey, paired with a reasonable password, for secure mfa authentication.

And yeah, for better or for worse, sms 2fa is better than no mfa, but not good enough for domain admins or accounts that require reasonable confidentiality.

The problem is cost associated with providing those tokens. I'm pushing for FIDO Keys like Yubikey for our privileged users, but man it adds up fast.

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face
wondering which hardcore shrek fanfic cosplay community they are trying to phish

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

CommieGIR posted:

The problem is cost associated with providing those tokens. I'm pushing for FIDO Keys like Yubikey for our privileged users, but man it adds up fast.

am i stupid or do nfc stickers seem like a cheap way of doing this

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Beeftweeter posted:

am i stupid or do nfc stickers seem like a cheap way of doing this

It would be cheaper, but then you have to ensure everyone has NFC readers or laptops/machines with NFC readers built in.

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

CommieGIR posted:

It would be cheaper, but then you have to ensure everyone has NFC readers or laptops/machines with NFC readers built in.

which a lot of enterprise laptops do have and i think a bulk purchase of usb readers or something would probably be cheaper than $30-50/yubikey

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Beeftweeter posted:

which a lot of enterprise laptops do have and i think a bulk purchase of usb readers or something would probably be cheaper than $30-50/yubikey

Yeah, a lot do, I know mine does. But we also have a lot of legacy stuff hanging around. I'd still push for FIDO keys for Admins and Domain Admins at the end of the day.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
a hundred bucks of yubikeys for each person is like, several orders of magnitude smaller than the other costs you have associated with that employee

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Jabor posted:

a hundred bucks of yubikeys for each person is like, several orders of magnitude smaller than the other costs you have associated with that employee

when you have a gazillion users they're not gonna do gently caress all unless it's as cheap as conceivably possible even if a security breach would be infinitely more expensive

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
i love my yubikeys

Shame Boy
Mar 2, 2010

can't you get the cheap yubikeys that only do fido or whatever, if you wanna be real cheap

Shame Boy
Mar 2, 2010

CRIP EATIN BREAD posted:

i love my yubikeys

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Shame Boy posted:

can't you get the cheap yubikeys that only do fido or whatever, if you wanna be real cheap

sure, but "as cheap as conceivably possible" in my book also includes burning the fido tags to a 3¢ sticker that could also work with phones

pseudorandom name
May 6, 2007

Isn't FIDO an interactive protocol? Which NFC stickers won't support?

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

pseudorandom name posted:

Isn't FIDO an interactive protocol? Which NFC stickers won't support?

well yeah, that's why i threw in "that works with phones". i could see unique tags being used to bring up an authentication prompt that gives you an actual token, kinda like microsoft authenticator

pseudorandom name
May 6, 2007

If the 2FA is being run on the phones then what's the point of the NFC tag?

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

CRIP EATIN BREAD posted:

i love my yubikeys

Me too.

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

pseudorandom name posted:

If the 2FA is being run on the phones then what's the point of the NFC tag?

some physicality to make sure the person is present?

e: it was just a half-baked idea in response to a post anyway, i don't actually implement this poo poo. i just analyze it, recommend alternatives, etc. to make sure the cost-cutting doesn't seriously impact security. if i had my way we'd be spending hundreds of millions that are truly necessary

Beeftweeter fucked around with this message at 16:36 on May 9, 2022

Crime on a Dime
Nov 28, 2006

Beeftweeter posted:

well yeah, that's why i threw in "that works with phones". i could see unique tags being used to bring up an authentication prompt that gives you an actual token, kinda like microsoft authenticator

lol

Crime on a Dime
Nov 28, 2006

Beeftweeter posted:

some physicality to make sure the person is present?

beside them biometricaly unlocking their phone and app and approving auth?

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Beeftweeter posted:

am i stupid

(the answer is yes)

Shame Boy
Mar 2, 2010

yeah either you accept the phone as not being compromised and therefore needing a person physically there to operate it, or you assume the phone is compromised in which case this whole argument is moot

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Crime on a Dime posted:

beside them biometricaly unlocking their phone and app and approving auth?

tbf you can't always assume phones have a biometric lock. alot of our workers have lifeline phones that do not

Crime on a Dime
Nov 28, 2006

Beeftweeter posted:

tbf you can't always assume phones have a biometric lock

Shame Boy posted:

yeah either you accept the phone as not being compromised and therefore needing a person physically there to operate it, or you assume the phone is compromised in which case this whole argument is moot

Sickening
Jul 16, 2007

Black summer was the best summer.
I am just going to trust nothing and make my systems impossible to operate. Totally secure.

I am also going to debate the the fact that the microsoft authenticator and apps like it are not totally secure while also allowing the most basic of security blunders to happen in my org. I just want to sound really smart in conversations.

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face

Beeftweeter posted:

Beeftweeter posted:

am i stupid
(the answer is yes)

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

dpkg chopra posted:

*borat voice*

MAIFILE.cn

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Sickening posted:

I am just going to trust nothing and make my systems impossible to operate. Totally secure.

I am also going to debate the the fact that the microsoft authenticator and apps like it are not totally secure while also allowing the most basic of security blunders to happen in my org. I just want to sound really smart in conversations.

Cut the wires, shut down the system, totally secure.

Crime on a Dime
Nov 28, 2006

Sickening posted:

I am just going to trust nothing and make my systems impossible to operate. Totally secure.

I am also going to debate the the fact that the microsoft authenticator and apps like it are not totally secure while also allowing the most basic of security blunders to happen in my org. I just want to sound really smart in conversations.

best of both worlds

Beeftweeter
Jun 28, 2005

a medium-format picture of beeftweeter staring silently at the camera, a quizzical expression on his face
real talk i actually use this thing and i like it fine. it's pretty versatile

BlankSystemDaemon
Mar 13, 2009



You, too, love CHIP EATING BREADs Yubikeys?
:same:

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
Any time I've given the olds any sort of small device that is not their phone, they lose it within 2 months, and within those 2 months they maybe remember to actually bring it with them maybe 2 days. Giving them yubikeys to be able to do their job sounds like hell.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

dpkg chopra posted:

the olds ... sounds like hell.

Presto
Nov 22, 2002

Keep calm and Harry on.
I don't even lock my phone. :colbert:

RFC2324
Jun 7, 2012

http 418

Presto posted:

I don't even lock my phone. :colbert:

Mouse jiggler > yubikey

Adbot
ADBOT LOVES YOU

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

RFC2324 posted:

Mouse jiggler > yubikey

RFC2324 posted:

Mouse jiggler > yubikey

while(workinghours) {
jiggled = again;
}

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply