Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
kiwid
Sep 30, 2013

Currently doing an MFA roll-out and it's going as well as I expected. Not because of the implementation, but because of the users.

User calls me up, same office so I go help him out.

This is what transpired:

Ask user to open their phone and download the Microsoft Authenticator.
Can't. Doesn't use an apple ID.
Ok ask user to create an apple ID.
Watch him for 15 minutes try to create and confirm a secure password typing at 1 letter per minute.
Finally gets apple id created after moaning about privacy and them needing his birth date, etc.
Ok, ask user to go download the microsoft authenticator.
Can't. apple id needs to verify email address first.
gently caress, walk my rear end back to my desk to disable MFA for this user because they can't check email without MFA.
Walk back tell them to check email and verify. Ok verified now.
Ask user to go back to app store and download the microsoft authenticator.
Can't, apple id needs a billing address even if you're downloading a free app.
Again, watch this user type the address and other details at 1 letter per minute.
Continue to watch as they struggle to type their phone number wrong at least 5 times with missing digits
Finally all setup, great, ask user to go to app store and download the microsoft authenticator.
Downloaded. Ok walk my rear end back to my desk to re-enable MFA.
Walk my rear end back to employee and ask them to try signing into Teams to prompt the MFA setup.
Ok done, now open the microsoft authenticator.
Can't. User doesn't use a pin/passcode on the phone itself.
Wait for user to create a pin on their phone after arguing why its required. 1 letter per minute later.
Ok, open the authenticator and scan that QR code
Popup appears to allow camera access, user clicks dont allow before I can say anything.
gently caress. Walk the user through the settings to go allow camera access for the authenticator.
Great, now scan this QR code. Scans it, then another popup appears to allow notifications (for the MFA prompt). User again clicks dont allow.
Kill me. Walk the user through settings again to re-enable notifications.
Go scan the QR code again, scans it and gets the code to type. Great, we're done. User complains that this is overly complicated and doesn't want to use MFA.

Not exaggerating that this 2 minute process took an hour.

Also, no, we don't use an MDM currently (small business)

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


How were they using an iPhone without any apps

xzzy
Mar 5, 2009

Safari is all anyone really needs.

And I can kind of respect people having the first instinct to deny camera and notifications access. Better than the alternative.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
explaining how TLS/SSL works to developers :negative:

Rawrbomb
Mar 11, 2011

rawrrrrr

Thanks Ants posted:

How were they using an iPhone without any apps

Lotta people just use the stock phone with the apps that come with it. Same reason they cannot understand why someone would have a pin/password to protect their device from access. From there POV, there is "nothing" of worth on that phone.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
There's nothing of worth on my phone beyond the MS Authenticator I use for work stuff. My tablet however...

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


The Iron Rose posted:

explaining how TLS/SSL works to developers :negative:

https://tls12.xargs.org and mic drop

kiwid
Sep 30, 2013

I've come across quite a few people that don't have an apple id on their phones and use it stock. They've all been of boomer age, it's never the young folk.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

oh it’s just basically the worst app ever, cubeJS. It’s a cacheing and query normalization layer between a client and a variety of data sources… and it has precisely 0 documentation about how to terminate TLS via its HTTP or Postgres compatible SQL API. That’s fine for the HTTP API because we can terminate TLS at the nginx proxy level, but obviously not for the SQL API since nginx cannot terminate TLS for an encrypted Postgres connection.

Internet Explorer
Jun 1, 2005





kiwid posted:

Currently doing an MFA roll-out and it's going as well as I expected. Not because of the implementation, but because of the users.

You work for a law firm, don't you?

kiwid
Sep 30, 2013

Internet Explorer posted:

You work for a law firm, don't you?

Farm/agriculture. Lots of tech illiterate.

Internet Explorer
Jun 1, 2005





I never knew there was so much of an overlap between attorneys and farmers!

Volguus
Mar 3, 2009

kiwid posted:

Farm/agriculture. Lots of tech illiterate.

They were happy people that did not need that poo poo. Until you came along.

kiwid
Sep 30, 2013

Volguus posted:

They were happy people that did not need that poo poo. Until you came along.

Two of our competitors were ransom-wared. I'd hope at least some of them understand.

xzzy
Mar 5, 2009

Internet Explorer posted:

I never knew there was so much of an overlap between attorneys and farmers!

It makes sense, both professions are masters at exploiting the system to get paid.

CitizenKain
May 27, 2001

That was Gary Cooper, asshole.

Nap Ghost
We are starting a rollout of new switches at our branches as we are hitting EOL at the end of the year. A date we will absolutely not hit, but that is for other reasons. I started a location close to me that only has a handful of users, and they almost always leave right at 5, or maybe stay until about 5:30.
Not today, as two them decided to sit and have a long conversation in an office for over 90 minutes. I was able to do some prepwork while waiting, but couldn't turn things up until they were done. Then they just left without either of them stopping by to let me know they were done. Big thanks to them.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
To a point that's on you for not asking them if they needed the network for business purposes at whatever time you wanted to start at. Just inform them at like 5PM that you're gonna cut it at 5:30 and then let them deal with that info as they please.

Wibla
Feb 16, 2011

I'd tell them I would be doing network maintenance at 5pm. They can choose what to do about it.

I also wouldn't do it at 5pm, I'd do it at lunch time.

Thanks Ants
May 21, 2004

#essereFerrari


Not much stuff is important enough to need to be done out of hours, which is something you quickly find out if you are a company that charges an uplift to clients to do evening/weekend work. They will always take the "take a longer lunch" or "go home a bit early" option over paying more.

well why not
Feb 10, 2009




Day three and I’ve met my team and have most of my tools sorted. Half the people say we’re busy, half the people say we’re quiet. My responsibilities seem to be none. This may just be good.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




If you need a change to be made outside of business hours you

a) Have one of the teams in a different time zone do it
or
b) You don't need to do that outside of business hours.


Big Change Wednesday or GTFO.

Fragrag
Aug 3, 2007
The Worst Admin Ever bashes You in the head with his banhammer. It is smashed into the body, an unrecognizable mass! You have been struck down.
I work for a small company of four employees and one financial consultant. We had a funded project several years ago and somewhere a Mistake was made and we had to return a considerable amount of money. Nobody in the leadership could adequately explain to me what the Mistake exactly was. Only that It was made. I was sidelined from any meetings on it because I'm just a lowly developer, but our General Co-ordinator was also sidelined. The one person who should follow this up and keep an eye out in the future to make sure we don't make the same Mistake again.

Now we're in another funded project and we had to deliver an interim financial report. Our General Co-ordinator is out with a burn-out, which is another story in itself, so I volunteered to pore over the numbers. I figure out that a part of the received budget is overinflated with a surplus that will have to be returned when the project is finished. I report this to my colleagues and they go "Oh, that must have been what the Mistake was last time" and now they're panicking over it. And I'm just flabbergasted. How the gently caress did they make the same Mistake again? How the gently caress did none of the leadership know what It was? Why are we only figuring this out a year into the project, just because I pored over the numbers on the side?

Maybe if they had involved our General Co-ordinator we might have averted it? Maybe if they involved her a lot more she wouldn't be out with a burnout, rather than just burdening her with the stress and mental load for issues like this that we had flagged a long time ago. Heck, I'm not even trained in this. I just know how to work with a spreadsheet. I suggested them to consult an accountant or financial planner to double check my numbers but that got ignored. Whatever, I don't loving know and I don't care anymore. I've already decreased my hours and now I'm working on the side on my own projects.

CitizenKain
May 27, 2001

That was Gary Cooper, asshole.

Nap Ghost

Arquinsiel posted:

To a point that's on you for not asking them if they needed the network for business purposes at whatever time you wanted to start at. Just inform them at like 5PM that you're gonna cut it at 5:30 and then let them deal with that info as they please.

Sadly, both of their job titles are C level, so I just wait.

Also its the time of year where people rediscover how cameras work, and if you have a room with not bright lighting and very bright light outside, that it will make it difficult for the camera. The solution is to bring down the blinds, but then they lose the nice view.

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Fragrag posted:

How the gently caress did they make the same Mistake again? How the gently caress did none of the leadership know what It was? Why are we only figuring this out a year into the project, just because I pored over the numbers on the side?

Grant/non-profit accounting is a tremendous pain in the dick. Especially when there are 14 pages of clauses and procedures you must follow to spend the money. Going 'oh, whoospie' when there is a 6 figure clawback because you never should have spent that money in the first place despite it sitting in project's account is just how your company seems to roll. Because there's just know way to know how to budget things, best to just guess and see where things end up.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

CitizenKain posted:

Sadly, both of their job titles are C level, so I just wait.

Also its the time of year where people rediscover how cameras work, and if you have a room with not bright lighting and very bright light outside, that it will make it difficult for the camera. The solution is to bring down the blinds, but then they lose the nice view.
Nah, gently caress that. You've got that exactly backwards. If you show up at 5 and check that they need the network or not and they tell you that they do you fire 'em an email saying that they've approve delaying it until the next working day and go home. Nobody's going to challenge you on being told not to do it until tomorrow by the C-suite.

Potato Salad
Oct 23, 2014

nobody cares


kiwid posted:

Currently doing an MFA roll-out and it's going as well as I expected. Not because of the implementation, but because of the users.

User calls me up, same office so I go help him out.

This is what transpired:

Ask user to open their phone and download the Microsoft Authenticator.
Can't. Doesn't use an apple ID.
Ok ask user to create an apple ID.
Watch him for 15 minutes try to create and confirm a secure password typing at 1 letter per minute.
Finally gets apple id created after moaning about privacy and them needing his birth date, etc.
Ok, ask user to go download the microsoft authenticator.
Can't. apple id needs to verify email address first.
gently caress, walk my rear end back to my desk to disable MFA for this user because they can't check email without MFA.
Walk back tell them to check email and verify. Ok verified now.
Ask user to go back to app store and download the microsoft authenticator.
Can't, apple id needs a billing address even if you're downloading a free app.
Again, watch this user type the address and other details at 1 letter per minute.
Continue to watch as they struggle to type their phone number wrong at least 5 times with missing digits
Finally all setup, great, ask user to go to app store and download the microsoft authenticator.
Downloaded. Ok walk my rear end back to my desk to re-enable MFA.
Walk my rear end back to employee and ask them to try signing into Teams to prompt the MFA setup.
Ok done, now open the microsoft authenticator.
Can't. User doesn't use a pin/passcode on the phone itself.
Wait for user to create a pin on their phone after arguing why its required. 1 letter per minute later.
Ok, open the authenticator and scan that QR code
Popup appears to allow camera access, user clicks dont allow before I can say anything.
gently caress. Walk the user through the settings to go allow camera access for the authenticator.
Great, now scan this QR code. Scans it, then another popup appears to allow notifications (for the MFA prompt). User again clicks dont allow.
Kill me. Walk the user through settings again to re-enable notifications.
Go scan the QR code again, scans it and gets the code to type. Great, we're done. User complains that this is overly complicated and doesn't want to use MFA.

Not exaggerating that this 2 minute process took an hour.

Also, no, we don't use an MDM currently (small business)

Honestly you should have encouraged the user to argue their case about privacy and whatever with management, just to see the hilarity of where that goes.

Potato Salad
Oct 23, 2014

nobody cares


(for real I'm sorry you're not in a position where you can manage this user out}

Fragrag
Aug 3, 2007
The Worst Admin Ever bashes You in the head with his banhammer. It is smashed into the body, an unrecognizable mass! You have been struck down.

Methylethylaldehyde posted:

Grant/non-profit accounting is a tremendous pain in the dick. Especially when there are 14 pages of clauses and procedures you must follow to spend the money. Going 'oh, whoospie' when there is a 6 figure clawback because you never should have spent that money in the first place despite it sitting in project's account is just how your company seems to roll. Because there's just know way to know how to budget things, best to just guess and see where things end up.

That's fair enough. The manual for the report was well over 300 pages. I guess it might have been a bit too much to ask for some due diligence from my company to prevent this boondoggle from happening again, but that's non-profit life for you.

Thanks Ants
May 21, 2004

#essereFerrari


The person without a company phone probably has a point and that’s what those OTP fobs are for. If your security posture insists on push notification MFA then it should be on company devices that are managed.

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady
Depending on where they are in the world, they may have legal backing too. I caused some minor problems a few years back when the place I was interning at decided to pay for Facebook Workplace and I told them that I'd rather not have my details handed over for Facebook to do what they please with after a decade or so of preventing exactly that happening.

SlowBloke
Aug 14, 2017

Thanks Ants posted:

The person without a company phone probably has a point and that’s what those OTP fobs are for. If your security posture insists on push notification MFA then it should be on company devices that are managed.

Every currently supported mobile operating system support security keys. Just grab a tray of https://www.yubico.com/us/product/yubikey-5ci/ for people that (rightfully) don't want to put work items on personal phones.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

2 jobs ago used Concur for expenses and poo poo, initially for mileage we'd just use google maps and then put the mileage in for the trips manually in concur.

Corp wanted us to switch to using the concur app w/ GPS, part of the EULA was basically that they would track us everywhere and were allowed to sell the data; the whole engineering team collectively said "gently caress you, no we are not doing that" it was glorious.

teethgrinder
Oct 9, 2002

I want to rant about our corporate takeover/absorption, but figure someone involved is reading this since somethingawful.com is a white-listed url.

Thanks Ants
May 21, 2004

#essereFerrari


We got acquired by private equity and it feels like they're just buying a customer base as there really doesn't seem to be any sort of logic in what is going on

xzzy
Mar 5, 2009

teethgrinder posted:

I want to rant about our corporate takeover/absorption, but figure someone involved is reading this since somethingawful.com is a white-listed url.

Use code words, describe it as if it's a children's birthday party. No one will figure it out.

Thanks Ants
May 21, 2004

#essereFerrari


We had to placate the C-levels with ice cream but there were still two or three pant-making GBS threads occurrences

Arquinsiel
Jun 1, 2006

"There is no such thing as society. There are individual men and women, and there are families. And no government can do anything except through people, and people must look to themselves first."

God Bless Margaret Thatcher
God Bless England
RIP My Iron Lady

teethgrinder posted:

I want to rant about our corporate takeover/absorption, but figure someone involved is reading this since somethingawful.com is a white-listed url.
Whoever whitelisted it can track the other goons in the company if they really want to. This means they're likely to be as pissed about it as you are.

The Fool
Oct 16, 2003


is it actually white listed or just not blocked

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Fragrag posted:

That's fair enough. The manual for the report was well over 300 pages. I guess it might have been a bit too much to ask for some due diligence from my company to prevent this boondoggle from happening again, but that's non-profit life for you.

Oh god, your budget is hosed. Those manuals are the dryest reading imaginable, and half the time are put together by someone actively hostile to the idea of you not being as miserable as they currently are. It takes a very special kind of compliance person to handle those and do it well, which is probably why your Sr. Leadership skimmed it, went TL;DR and assumed nothing bad would happen because of it.

Some not for profits will actively avoid smaller grants, even when they're "here's free money, take it", because a lot of times the reporting burden ends up costing more man hours than the grant was worth. "Here's 5k for STD prevention education", but it comes with the caveat that you now need to collect a ton of specific information about everyone who shows up at your clinic, how much they like dick, how often the dick was enjoyed raw, etc. Then make a very specifically formatted report with a bunch of analysis spelled out in a similarly awful reporting manual.

Adbot
ADBOT LOVES YOU

teethgrinder
Oct 9, 2002

The Fool posted:

is it actually white listed or just not blocked
I mean as far as I can tell it's been manually approved and categorised. From what I can tell, any "unseen" URL is automatically blocked, and seeing how they operate they probably started with zero permitted.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply