Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Bob Morales posted:

Sure, I would be happy to assist you with this question.

To add to the list, she also keeps repeating these things:

Kristen B: Thank you
Kristen B: Gotcha!
Kristen B: One moment to take a look into this for you.
Kristen B: Great! Checking with you now

Maybe she's a robot!

Bob Morales fucked around with this message at 21:17 on Oct 16, 2017

Adbot
ADBOT LOVES YOU

Thanks Ants
May 21, 2004

#essereFerrari


Judge Schnoopy posted:

Don't run mobile banking on wifi for a while.

If your bank is susceptible to an HTTPS downgrade attack then change banks

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Judge Schnoopy posted:

I haven't read of any Windows patches that mitigate this. Don't trust wifi on windows, even fully up to date, until Microsoft dead-on confirms a certain patch resolves the Krack exploit.

Apple is vulnerable as well but there are fewer ransomware exploits in the wild so as long as you don't send secure, private data over wifi you're more or less OK.

edit3: Android and Linux were the most vulnerable because they can be made to simply not encrypt their traffic (encryption key of all 0). Don't run mobile banking on wifi for a while.

You're safe if you don't see a pimply kid nearby with KALI linux and a USB wifi dongle with an antenna nearby.

nielsm
Jun 1, 2009



Judge Schnoopy posted:

I haven't read of any Windows patches that mitigate this. Don't trust wifi on windows, even fully up to date, until Microsoft dead-on confirms a certain patch resolves the Krack exploit.

How about this one from last week? MS silently included a patch for it in the October 10th package.

22 Eargesplitten
Oct 10, 2010



Thanks Ants posted:

If your bank is susceptible to an HTTPS downgrade attack then change banks

Well I guess technically your mattress isn’t vulnerable, but they aren’t very good about processing direct deposits.

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

22 Eargesplitten posted:

Well I guess technically your mattress isn’t vulnerable, but they aren’t very good about processing direct deposits.

Your direct mattress deposits tend to dry up over night I've heard.

Jowj
Dec 25, 2010

My favourite player and idol. His battles with his wrists mirror my own battles with the constant disgust I feel towards my zerg bugs.
Posting from infosec thread:

Proteus Jones posted:

https://papers.mathyvanhoef.com/ccs2017.pdf

It's not getting the PSK, it's forcing re-use of the temporal keys due to a flaw in 802.11i 4-way handshake. It allows packet replay and decryption with AES and packet replay, decryption and forging with TKIP and GCMP. It's especially bad for TKTIP and GCMP due to the forging and really no one should be using it anymore anyway.

This is a vulnerability in WPA/WPA2 in general, not *just* WPA/WPA2-PSK.

And iOS is not vulnerable since they break spec and don't allow msg 3 to be resent in eapol. Windows breaks spec the same way. Both iOS and Windows are vulnerable to the GTK attack. Android is completely owned due to it allowing the attack to actually set a temporal key of all 0's.



Also, mitigation appears to be possible at either end. So either the AP needs a hotfix to enable a key re-use check or on the client side. If only one of the sides won't allow it, this won't work.

So, it sounds like windows was never vulnerable to the majority of the vulns since it didn't fully implement wpa2 spec, but was vuln to the group key attack hence that microsoft patch.

porkface
Dec 29, 2000

Irritated Goat posted:

With the Krack poo poo going around, I was discussing it with the boss\admin. Idly discussing wireless security, he's insistent on hiding the SSIDs of the wireless APs. :sigh:

Despite the fact of me saying that devices connected to hidden SSIDs just scream out the name anyway and it's actually a bit more hassle for guests, he's not budging.

I kind of feel like none of my security related suggestions are going to go anywhere. I feel like I'm fortunate as it is to push for an imaging solution and getting servers off 2003.

Here's a concise explanation from an authority:
https://blogs.technet.microsoft.com/steriley/2007/10/16/myth-vs-reality-wireless-ssids/

Here's one with more punch from a lesser authority:
https://lifehacker.com/5636856/is-hiding-your-wireless-ssid-really-more-secure

Good luck finding anything of repute that suggests hiding them is a good idea. At the very least, make him a wager on the increase in the number of tickets you expect out of this.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.

porkface posted:

Good luck finding anything of repute that suggests hiding them is a good idea.

Is Tony considered reputable? :q:

Methylethylaldehyde
Oct 23, 2004

BAKA BAKA

Dick Trauma posted:

Is Tony considered reputable? :q:

The Dunning-Kreuger effect means that in his own mind, he's the most reputable person around!

Irritated Goat
Mar 12, 2005

This post is pathetic.

porkface posted:

Here's a concise explanation from an authority:
https://blogs.technet.microsoft.com/steriley/2007/10/16/myth-vs-reality-wireless-ssids/

Here's one with more punch from a lesser authority:
https://lifehacker.com/5636856/is-hiding-your-wireless-ssid-really-more-secure

Good luck finding anything of repute that suggests hiding them is a good idea. At the very least, make him a wager on the increase in the number of tickets you expect out of this.

The worst part is, he knows drat good and well it isn't helping security so.. :shrug: "It's always been that way" strikes again.

It's real frustrating when you're in the financial sector, see obvious security issues and want to fix them but get stopped cause it isn't a hit on the audit for some reason.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.
I was just in the consultant/COO's office because he was having issues with Apple Mail and our Exchange server, and I noticed several copies of our floorplan were on his desk. He'd mentioned a little while ago that "major musical chairs" was coming up. I didn't look closely but he indicated the office he was thinking of moving me to.

It was my original office! Except this time there would be furniture. No idea if Bill will end up next to me again but I was stoked to see that he wasn't intending to stick me in a punishment cube or some other drat thing.

I much prefer the view from that office, and it was nice being near the server room, as well as in a place with actual foot traffic. Being at a dead end is too quiet, even for me.

RFC2324
Jun 7, 2012

http 418

Bob Morales posted:

Rackspace's useless, yet 'fanatical' support reps are all spouting this line:

Sure, I would be happy to assist you with this question.

I just envision some guy sitting in a dark room with like 14 chat windows open, frantically typing away at all these tickets and then they've got a list of quick-fire canned responses as buttons on each one.

this is literally true. I've worked those jobs, and you have a huge set of macros and triggered responses to save time.

when i was at hostgator we had a quota of 55 tickets responses per hour.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Judge Schnoopy posted:

edit3: Android and Linux were the most vulnerable because they can be made to simply not encrypt their traffic (encryption key of all 0). Don't run mobile banking on wifi for a while.

Your mobile banking application shouldn't be sending plaintext data in the first place, since the cellular networks are not meaningfully encrypted or robust against attacks like fake cell towers that relay your info. Everything you use on a phone should thus already be something you'd feel safe using on a completely open wifi network.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Oh man I guess I missed out this morning. Apparently one of the trucking companies we do a ton of business with, a rep stopped by with a platter of donuts and apple cider from one of the local places that does $9 caramel apples and hayrides and all that poo poo in the fall.

Owner came down and chewed the guy out for 'bringing that unhealthy poo poo in here, you should have just brought us some apples'

:lol:

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



Bob Morales posted:

Oh man I guess I missed out this morning. Apparently one of the trucking companies we do a ton of business with, a rep stopped by with a platter of donuts and apple cider from one of the local places that does $9 caramel apples and hayrides and all that poo poo in the fall.

Owner came down and chewed the guy out for 'bringing that unhealthy poo poo in here, you should have just brought us some apples'

:lol:

I’m so angry that I don’t have a $9 carmel apple right now.

tomapot
Apr 7, 2005
Suppose you're thinkin' about a plate o' shrimp. Suddenly someone'll say, like, plate, or shrimp, or plate o' shrimp out of the blue, no explanation. No point in lookin' for one, either. It's all part of a cosmic unconciousness.
Oven Wrangler

Agrikk posted:

I'm on vacation, gently caress you if you think I'm taking a work call. If there was a predefined understanding that the employee was on call or pageable while on PTO then the employee is a dumbass.

I'm pissed for that guy.

A little late responding to this one but I wonder if he carried a printer all the way back into the office as well.

Seriously though, a good manager would have run interference for the guy. A few years ago one of our sites had an outage and before our CIO got the full story (our side) she wanted me written up for it. My director refused and told our VP that he would take the heat if needed. My VP ran interference as well, another stand up guy I'm really happy to work for. Our side of the story was that we handed off the change info and the local IT team did not take it to the change board. Oh, and the site decided to not invest in a DR plan because they were trying to save money so we had nothing to fail over to while we were troubleshooting the issue.

Corsair Pool Boy
Dec 17, 2004
College Slice

RFC2324 posted:

this is literally true. I've worked those jobs, and you have a huge set of macros and triggered responses to save time.

when i was at hostgator we had a quota of 55 tickets responses per hour.

When people open chats with our helpdesk, there are tons of canned responses. We weren't required to use them and almost no one did because typing is faster than scrolling through a giant list, but it definitely is A Thing.

You get the same thing with ISPs and stuff that obviously use a script.

RFC2324
Jun 7, 2012

http 418

MANime in the sheets posted:

When people open chats with our helpdesk, there are tons of canned responses. We weren't required to use them and almost no one did because typing is faster than scrolling through a giant list, but it definitely is A Thing.

You get the same thing with ISPs and stuff that obviously use a script.
We weren't required to use them, but we were encouraged to use them and write our own. They also weren't just in a list, they used autotyper(?) so you could type $dnsprop and get the canned response about dns propagation taking time.

The guys with the insanely high ticket counts would macro parts of of sentences and string those together. I could never get my mind to work that way tho.

Samizdata
May 14, 2007

RFC2324 posted:

this is literally true. I've worked those jobs, and you have a huge set of macros and triggered responses to save time.

when i was at hostgator we had a quota of 55 tickets responses per hour.

And, having done tech support, I call such folk "binder monkeys".

Samizdata
May 14, 2007

porkface posted:

Here's a concise explanation from an authority:
https://blogs.technet.microsoft.com/steriley/2007/10/16/myth-vs-reality-wireless-ssids/

Here's one with more punch from a lesser authority:
https://lifehacker.com/5636856/is-hiding-your-wireless-ssid-really-more-secure

Good luck finding anything of repute that suggests hiding them is a good idea. At the very least, make him a wager on the increase in the number of tickets you expect out of this.

The MS article is offline at the current time, so here's the latest Wayback Machine snapshot:

https://web.archive.org/web/20170823020550/https://blogs.technet.microsoft.com/steriley/2007/10/16/myth-vs-reality-wireless-ssids/

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

Bob Morales posted:

Oh man I guess I missed out this morning. Apparently one of the trucking companies we do a ton of business with, a rep stopped by with a platter of donuts and apple cider from one of the local places that does $9 caramel apples and hayrides and all that poo poo in the fall.

Owner came down and chewed the guy out for 'bringing that unhealthy poo poo in here, you should have just brought us some apples'

:lol:

Did a surprisingly large number of staff suddenly take a quick break outside the front entrance at the same time?

Collateral Damage
Jun 13, 2009

Bob Morales posted:

Owner came down and chewed the guy out for 'bringing that unhealthy poo poo in here, you should have just brought us some apples'
I'm starting to wonder if your boss had a girlfriend stolen by a baker in his youth or something.

Zil
Jun 4, 2011

Satanically Summoned Citrus


Collateral Damage posted:

I'm starting to wonder if your boss had a girlfriend stolen by a baker in his youth or something.

He knows the terrible secret of the Muffin Man of Mulberry Lane.

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



Replying in a public chat room to a PM and not realizing it until the time to delete or edit the message has passed.

Corsair Pool Boy
Dec 17, 2004
College Slice

Virigoth posted:

Replying in a public chat room to a PM and not realizing it until the time to delete or edit the message has passed.

The one good thing about Teams. You can delete a message at any time.

How bad is the comment?

Virigoth
Apr 28, 2009

Corona rules everything around me
C.R.E.A.M. get the virus
In the ICU y'all......



MANime in the sheets posted:

The one good thing about Teams. You can delete a message at any time.

How bad is the comment?

Nothing bad. Someone was just asking me a question about something that happened yesterday and I was telling them who worked on it. I save my work bitching for Hangouts with loyal teammates who have been invited in and this dead, gay forum.

Super-NintendoUser
Jan 16, 2004

COWABUNGERDER COMPADRES
Soiled Meat

Virigoth posted:

Replying in a public chat room to a PM and not realizing it until the time to delete or edit the message has passed.

I have a rule that I never say anything in any email, chat, messenger, or on a phone that I won't want our clients to see.

Once at $AWFUL_JOB the owner/boss got me on the phone and asked me to talk about a client, they had just caused a huge production issue and were trying to pass the blame and not pay an invoice. At the time I happened to be logged into our phone system, and I noticed that there as another number called into the boss' line listening it, turned out the be owner the client in question, I recognized the Caller ID. I hemmed and hawed around answering directly, and my boss kept goading me to say something, but eventually I just said "this is going to sound weird, but I'm logged into our phone system and I see that this is a three way call with $CLIENT, is there like a hung channel or something?"

Boss was silent for a minute, I asked again, and then he said "well, ok $CLIENT he got us, yeah, he's on the call." I was pretty stunned, I still don't know what he was trying to do.

Koskun
Apr 20, 2004
I worship the ground NinjaPablo walks on

Jerk McJerkface posted:

I have a rule that I never say anything in any email, chat, messenger, or on a phone that I won't want our clients to see.

Once at $AWFUL_JOB the owner/boss got me on the phone and asked me to talk about a client, they had just caused a huge production issue and were trying to pass the blame and not pay an invoice. At the time I happened to be logged into our phone system, and I noticed that there as another number called into the boss' line listening it, turned out the be owner the client in question, I recognized the Caller ID. I hemmed and hawed around answering directly, and my boss kept goading me to say something, but eventually I just said "this is going to sound weird, but I'm logged into our phone system and I see that this is a three way call with $CLIENT, is there like a hung channel or something?"

Boss was silent for a minute, I asked again, and then he said "well, ok $CLIENT he got us, yeah, he's on the call." I was pretty stunned, I still don't know what he was trying to do.

Something about being under a bus comes to mind.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.

Koskun posted:

Something about being under a bus comes to mind.

But how would one get under a bus?

MC Fruit Stripe
Nov 26, 2002

around and around we go

Jerk McJerkface posted:

I have a rule that I never say anything in any email, chat, messenger, or on a phone that I won't want our clients to see.
This is a lesson that everyone has to learn, unfortunately. I've been burned a few times. I'm never outright unprofessional in email, but I can be pretty flippant. And I've had a few times where I replied to an email with a small trusted group with a comment like "I'll be happy to do that as soon as customer stops blocking us at every turn", only to find that reply buried 4 deep in a chain that now includes the customer. I'll usually create a reason to reply all to the thread, while quietly removing the offending email from the chain.

Also whoa, that scenario you described is very, very weird. I'd have been pretty upset about that, as I imagine you were.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.

MC Fruit Stripe posted:

This is a lesson that everyone has to learn, unfortunately. I've been burned a few times. I'm never outright unprofessional in email, but I can be pretty flippant. And I've had a few times where I replied to an email with a small trusted group with a comment like "I'll be happy to do that as soon as customer stops blocking us at every turn", only to find that reply buried 4 deep in a chain that now includes the customer. I'll usually create a reason to reply all to the thread, while quietly removing the offending email from the chain.

Also, you never put something in an email you wouldn't want someone other than the recipient to see. Because that recipient will forward and/or print out that email and other people will see it. And you'll be hosed.

Say it in person.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
I've had a number of people mention / complain that my emails come off as very dry and toneless, as if I'm unaware or that I'm not doing it on purpose.

I've had one vendor tell me I should lighten up and include some smilies so they can feel more comfortable with my emails. They got fired this year.

xzzy
Mar 5, 2009

Sounds like you need to send everything in comic sans and find a nice tiling pink background on a wallpaper site.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

tactlessbastard
Feb 4, 2001

Godspeed, post
Fun Shoe
I've got 100k to spend on a machine and one of the sales apes I've been subjected to only uses email to notify me that he's going to call, just called, or is calling now. I've repeatedly told him I prefer to stick to email and he keeps calling and calling and guess what dickhead I don't care if your machine gives handies and is way under budget, I'll never ever buy it from you :argh:

Sickening
Jul 16, 2007

Black summer was the best summer.

tactlessbastard posted:

I've got 100k to spend on a machine and one of the sales apes I've been subjected to only uses email to notify me that he's going to call, just called, or is calling now. I've repeatedly told him I prefer to stick to email and he keeps calling and calling and guess what dickhead I don't care if your machine gives handies and is way under budget, I'll never ever buy it from you :argh:

100k on a single server? Why?

Thanks Ants
May 21, 2004

#essereFerrari


It could be a CNC

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer

Judge Schnoopy posted:

I've had one vendor tell me I should lighten up and include some smilies so they can feel more comfortable with my emails. They got fired this year.
We have one extremely passive-aggressive administrator who does this and it only makes the messages seem even more passive-aggressive.

Adbot
ADBOT LOVES YOU

tactlessbastard
Feb 4, 2001

Godspeed, post
Fun Shoe

Thanks Ants posted:

It could be a CNC

More or less, yes.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply