Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Raere
Dec 13, 2007

Shaggar posted:

do security scanners still not take redhate backporting into account and just look at base version number?

Nessus definitely takes it into account with few exceptions (they generally revise pretty quickly it if they get it wrong). If your security scanner is just naively looking at mainline version numbers it's probably a trash scanner anyway.

Adbot
ADBOT LOVES YOU

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

narrator:

Shaggar
Apr 26, 2006

Raere posted:

Nessus definitely takes it into account with few exceptions (they generally revise pretty quickly it if they get it wrong). If your security scanner is just naively looking at mainline version numbers it's probably a trash scanner anyway.

nessus was the one that didnt take it into account last time i used it, but thankfully i havent had to deal with linux poo poo in ages

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

nessus bitcoin mining station

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

fwiw this isn't an automated scanner flagging us, they asked for an inventory of all VMs with the vulnerable version and we told them and said we had applied 3.0.1.-43.el9 or w/e as per the RHSA and they came back with the "not best practice" gem

sb hermit
Dec 13, 2016





Volmarias posted:

What does your heart tell you?

I'm the one applying what I believe is best practice, which is to just use what the vendor provides

I'm just arguing against the logic of these cybersecurity analysts

sb hermit
Dec 13, 2016





carry on then posted:

fwiw this isn't an automated scanner flagging us, they asked for an inventory of all VMs with the vulnerable version and we told them and said we had applied 3.0.1.-43.el9 or w/e as per the RHSA and they came back with the "not best practice" gem

this is a great paper trail to use to justify dropping them later

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

sb hermit posted:

this is a great paper trail to use to justify dropping them later

why do you think this is a vendor? this is the infosec office.

sb hermit
Dec 13, 2016





carry on then posted:

why do you think this is a vendor? this is the infosec office.

then this is a good paper trail to getting the infosec office management fired

sb hermit
Dec 13, 2016





to be very clear, I'm half shitposting, and half serious

I am 100% serious when I say that I don't want to be in your shoes

Shame Boy
Mar 2, 2010

we're going to be deploying some automated version checking poo poo soon, i am so excited

Main Paineframe
Oct 27, 2010

Shame Boy posted:

we're going to be deploying some automated version checking poo poo soon, i am so excited

better start practicing the phrase "no, that's a false positive"

sb hermit
Dec 13, 2016





Main Paineframe posted:

better start practicing the phrase "no, that's a false positive"

sb hermit
Dec 13, 2016





someone turn that poo poo into a smiley please

sb hermit
Dec 13, 2016





Shame Boy posted:

we're going to be deploying some automated version checking poo poo soon, i am so excited

I ran an application repository and users kept submitting updates without changing the version numbers and it got real tiring so we just told them that we'll just bump it internally, silently, and (for real) it never caused any issues

Cybernetic Vermin
Apr 18, 2005

sb hermit posted:

someone turn that poo poo into a smiley please

it'd get so many people banned for anime though

RFC2324
Jun 7, 2012

http 418

Cybernetic Vermin posted:

it'd get so many people banned for anime though

where do we still ban for anime?

Kitfox88
Aug 21, 2007

Anybody lose their glasses?
i could swear i saw an anime probe from some thread in here within the last few months but like gently caress i'm gonna go dig for it lol

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

RFC2324 posted:

where do we still ban for anime?

smoka posts a bunch that nobody wants to see then graph probes him for it

its just a part of life in the 'pos

mystes
May 31, 2006

Sniep posted:

smoka posts a bunch that nobody wants to see then graph probes him for it
I think smoka is a girl

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
probes her for it

RFC2324
Jun 7, 2012

http 418

I was expecting it to be hbag eating an anime probe, tbh

sb hermit
Dec 13, 2016





we still have stuff like :bigdog: and no one's been probed for using it yet

haveblue
Aug 15, 2005



Toilet Rascal
:nyoron:

Kitfox88
Aug 21, 2007

Anybody lose their glasses?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mystes posted:

I think smoka is a girl

ok

infernal machines posted:

probes her for it

thanks

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Shaggar posted:

do security scanners still not take redhate backporting into account and just look at base version number?

what does your heart tell you

best part of cloudflare job was working next to the security team and getting to hear the person we hired specifically for their connections in the security auditor industry moan out loud about some of the less competent vendors flagging poo poo yet another time after they'd called execs at said vendors to explain the mitigations in excruciating detail

champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER

VSOKUL girl posted:

what does your heart tell you

best part of cloudflare job was working next to the security team and getting to hear the person we hired specifically for their connections in the security auditor industry moan out loud about some of the less competent vendors flagging poo poo yet another time after they'd called execs at said vendors to explain the mitigations in excruciating detail

my girlfriend works in a food biotech company and for the above reason, unrelated to computers, they have a standard document dated and signed which explains why x and y aren't an issue.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
my lastpass renewal is coming up and im finally gearing up to ditch this thing.

i have an iphone and a pc but I'm kinda leaning towards just going full keychain and just rocking the icloud extension for Chrome/Edge?

my wife is extremely not tech savvy but she knows that if anything happens to me she can access my icloud accounts as my emergency contact so that solves a problem.

just wondering if you guys have any ~~~thoughts~~~

dpkg chopra fucked around with this message at 05:02 on Nov 8, 2022

sb hermit
Dec 13, 2016





:shrug:

sb hermit
Dec 13, 2016





I am planning on getting two yubikey security keys to give to each of my parents so that my parents can use their own key as well as the key of the other to unlock accounts as a 2nd factor. Probably better than right now where it's either SMS or no 2FA at all. And I get the bonus of not buying backup keys for both of them just in case.

I might register my emergency yubikey as their backup 2fa on their accounts too, though.

Just have to get them on board with actually using the things.

sb hermit
Dec 13, 2016





dpkg chopra posted:

my lastpass renewal is coming up and im finally gearing up to ditch this thing.

i have an iphone and a pc but I'm kinda leaning towards just going full keychain and just rocking the icloud extension for Chrome/Edge?

my wife is extremely not tech savvy but she knows that if anything happens to me she can access my icloud accounts as my emergency contact so that solves a problem.

just wondering if you guys have any ~~~thoughts~~~

probably the most I would suggest is what you would do with most disaster plans. Write the recovery plan out in reasonable detail, then test it within reason.

this plan could also include the step of "give these steps to a trusted individual to execute with your supervision", which is totally acceptable as long as you have decent friends or relatives or descendants

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

dpkg chopra posted:

my lastpass renewal is coming up and im finally gearing up to ditch this thing.

i have an iphone and a pc but I'm kinda leaning towards just going full keychain and just rocking the icloud extension for Chrome/Edge?

my wife is extremely not tech savvy but she knows that if anything happens to me she can access my icloud accounts as my emergency contact so that solves a problem.

just wondering if you guys have any ~~~thoughts~~~

i like bitwarden vov

Raymond T. Racing
Jun 11, 2019

dpkg chopra posted:

my lastpass renewal is coming up and im finally gearing up to ditch this thing.

i have an iphone and a pc but I'm kinda leaning towards just going full keychain and just rocking the icloud extension for Chrome/Edge?

my wife is extremely not tech savvy but she knows that if anything happens to me she can access my icloud accounts as my emergency contact so that solves a problem.

just wondering if you guys have any ~~~thoughts~~~

I would not use iCloud Keychain without at least one Mac tbh

iirc there’s a few things from a management perspective that can’t be done from iPhone

sb hermit
Dec 13, 2016






Buff Hardback posted:

I would not use iCloud Keychain without at least one Mac tbh

iirc there’s a few things from a management perspective that can’t be done from iPhone



I couldn't access the $30 or so I had in apple cash when my iphone 6s hit the drink until I got a hand-me-down iPhone 7 about three years later

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
while looking into how to export from LastPass to BitWarden

quote:

Warning
Some users have reported a bug which changes special characters in your passwords (&, <, >, and so on) to their HTML-encoded values (for example, &) in the printed export.

If you observe this bug in your exported data, use a text editor to find and replace all altered values before importing into Bitwarden.

I'm sure this won't be a problem

dpkg chopra fucked around with this message at 19:18 on Nov 8, 2022

devmd01
Mar 7, 2006

Elektronik
Supersonik
is anyone going to Oktane? It’s a total junket conference, which is why I booked flights so I could have most of today and Thursday afternoons evening free to do things around the city.

gonna go see the wwII sub hell yeah

git apologist
Jun 4, 2003

dpkg chopra posted:

while looking into how to export from LastPass to BitWarden

I'm sure this won't come be a problem

lol at the fix

Adbot
ADBOT LOVES YOU

Xakura
Jan 10, 2019

A safety-conscious little mouse!

dpkg chopra posted:

while looking into how to export from LastPass to BitWarden

I'm sure this won't be a problem

:rubby:

I moved from lastpass to bitwarden back when lastpass had their first major security breach, and I didn't have any trouble exporting.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply