Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Does anyone under 40 even know what a carbon copy is?

Adbot
ADBOT LOVES YOU

HalloKitty
Sep 30, 2005

Adjust the bass and let the Alpine blast
Yes. Ok, I'm 39

HalloKitty fucked around with this message at 18:49 on Apr 30, 2024

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Just like a 3d printed save icon.

DrBrezo
May 13, 2009

A ticket came in



and Security want us to refresh every 2016 & 2019 server because Qualys says it's EOL/EOS. Thats nearly everything we have. What the gently caress can I do to bat this away? MS say themselves that the security updates will continue with extended support but that doesnt seem to be enough for these guys

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

DrBrezo posted:

A ticket came in



and Security want us to refresh every 2016 & 2019 server because Qualys says it's EOL/EOS. Thats nearly everything we have. What the gently caress can I do to bat this away? MS say themselves that the security updates will continue with extended support but that doesnt seem to be enough for these guys

As someone in security - push this back to them, in the first case its not your job to fulfill someone at management level needs to make that call, since that is a big spend for licensing. What they need to do is log it as a risk and assign risk ownership to whoever owns the servers, not your job to fix/fulfill.

I'd toss this up the chain to your management.

DrBrezo
May 13, 2009

Thanks man, I just pretty much did the same just now in a call - Raised the licensing cost and scale of the project of renewal and pushed it up the chain.

I've got (a few) more calls on this tomorrow so hopefully the lions share of these dev environments can be pushed back to the projects and teams owning them, I'm already working through our CBAs under my own steam. Thanks again

Internet Explorer
Jun 1, 2005





The way I look at that sort of thing is that it's security's job to make sure they are raising security issues and it's the business's job to tell them it's not feasible when it's not feasible. In this case it sounds like maybe they don't have their ducks in a row, which will hurt them as the business pulls at those threads. I wouldn't look at it as adversarial, just people trying to do their jobs with different primary goals/objectives.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Internet Explorer posted:

The way I look at that sort of thing is that it's security's job to make sure they are raising security issues and it's the business's job to tell them it's not feasible when it's not feasible. In this case it sounds like maybe they don't have their ducks in a row, which will hurt them as the business pulls at those threads. I wouldn't look at it as adversarial, just people trying to do their jobs with different primary goals/objectives.

Oh its not adversarial, of course, but Security also needs to understand the onus of ownership of risk, and its not opening some ticket for support, its meeting with the infrastructure team with a list of affected systems and determining the stomach the business has to resolving the risks and how those risks can either be mitigated or resolved, especially when you are talking something like essentially an OS refresh on multiple boxes. If they determine that tickets needs to be opened, its at that point, because otherwise you are just opening tickets that cannot be fulfilled or even acted upon by support.

CommieGIR fucked around with this message at 17:11 on Apr 30, 2024

Internet Explorer
Jun 1, 2005





For sure, agreed. "We need you to do hundreds of hours of work" requires a longer conversation and is not "submit a ticket" level of work, security or not. Something for all of us to keep in mind.

Prescription Combs
Apr 20, 2005
   6

DrBrezo posted:

A ticket came in



and Security want us to refresh every 2016 & 2019 server because Qualys says it's EOL/EOS. Thats nearly everything we have. What the gently caress can I do to bat this away? MS say themselves that the security updates will continue with extended support but that doesnt seem to be enough for these guys

lol. Company I work for is just now upgrading the DCs from 2012 to 2019

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Prescription Combs posted:

lol. Company I work for is just now upgrading the DCs from 2012 to 2019

Now let's see if they upgrade the forest too, seen so many companies put in new DCs and upgrade old ones but never raise the domain and forest levels to 2019 usually because of some legacy functionality.

Did an engagement where we hit their AD after they patted themselves on the back about upgrading only to find out the Domain was still operating at a 2008 R2 level. That's usually the part that sucks anyways as that's when things will really start to break - AD 2022 can emulate all the way back to 2008 levels, and then you start to lose legacy features that unknown legacy apps depend on and find out after the upgrade is completed.

CommieGIR fucked around with this message at 17:25 on Apr 30, 2024

DrBrezo
May 13, 2009

Prescription Combs posted:

lol. Company I work for is just now upgrading the DCs from 2012 to 2019

lol so are mine, my insistence we get rid of all the 2012 DC's led to someone throwing this poo poo at me kinda like " hey , while you're at it " LOL no thanks

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

DrBrezo posted:

A ticket came in



and Security want us to refresh every 2016 & 2019 server because Qualys says it's EOL/EOS. Thats nearly everything we have. What the gently caress can I do to bat this away? MS say themselves that the security updates will continue with extended support but that doesnt seem to be enough for these guys

One of the (few) nice things about working at a big rear end organization, is poo poo like this is a non starter. If I fielded a request like this (which I wouldn't generally to begin with), I'd redirect them to project management, program management, and our product owner. Make them jump through all our intake requests, go through planning exercises, costs analysis, add it to the backlog, eventually plan it in 6 to 9 months and so many other layers of bureaucratic BS they tend to just give up. It's like when Mila Kunis' character in Jupiter Ascending tries to claim her title and is bounced around from dept to dept.


It can work the other way around on us though. Disabling RC4 was a multi year project where we had to track down app owners and go through the process to force them to stop using it. We're trying to get TLS 1.0 and 1.1 (internally) disabled by this time next year.

Charliegrs
Aug 10, 2009
Anyone know how I can test whether our various Cisco routers and switches will reply to ICMP with timestamps? Our security group has flagged basically everything for this but they don't know poo poo so my main job is proving to them they don't know poo poo. I have access to nping and I did some googling and it seems like to test it you enter this command in nping:
Nping --icmp-type 13 <IP address>
A type 13 ICMP from what I understand is requesting a ICMP response with the devices timestamp. But when I run it nping tries to initiate a TCP handshake for some reason? Which fails. So I definitely don't think I'm testing this right.

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

CommieGIR posted:

Oh its not adversarial, of course, but Security also needs to understand the onus of ownership of risk, and its not opening some ticket for support, its meeting with the infrastructure team with a list of affected systems and determining the stomach the business has to resolving the risks and how those risks can either be mitigated or resolved, especially when you are talking something like essentially an OS refresh on multiple boxes. If they determine that tickets needs to be opened, its at that point, because otherwise you are just opening tickets that cannot be fulfilled or even acted upon by support.
Yeah, Hanlon's razor—it's usually not malice, just someone not knowing any better. Most people working in infosec are new to the processes around risk management in businesses. The way most companies are structured, especially in tech, you're expected to work directly with your cross-functional peers instead of making everything turn into some kind of management conversation. So, people are going to bias that way, and do as much of the work as they're personally capable of before handing something off.

Thanks Ants
May 21, 2004

#essereFerrari


The other thing about a request to upgrade all Server 2016 / 2019 boxes to 2022 is that it massively depends on what the application supports. It might be possible to use this request to your advantage to get as much legacy crap replaced as possible, the likelihood of that working is very organisation specific.

BaseballPCHiker
Jan 16, 2006

Extended support for server 2016 isnt until 2027? What is Qualys worried about? Mainstream support?

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
Personal consumer question. My father needs to fax some documents to his insurer. I have been blessed with avoiding email to fax services in my professional career, but I’m curious if yall would recommend any particular software products here. Lowest cost is best obviously.

Wizard of the Deep
Sep 25, 2005

Another productive workday
Depending on org size, 2024 might be the right time to start the upgrade project (which would include identifying software that won't work on Server 2022 for whatever reason, budget planning, resource coordination, et cetera) for Server 2016's EOL in 2027.

Our 2012 Decom Project should be done by the end of next year. Yes the Extended Support is very expensive. But we started the upgrade project late, so here we are.

A flotilla of ww2-era cruise ships take time to change direction.

Thanks Ants
May 21, 2004

#essereFerrari


The Iron Rose posted:

Personal consumer question. My father needs to fax some documents to his insurer. I have been blessed with avoiding email to fax services in my professional career, but I’m curious if yall would recommend any particular software products here. Lowest cost is best obviously.

If this is a one-off then can a copy shop handle it? Do the insurer really have nothing other than fax?

ilkhan
Oct 7, 2004

I LOVE Musk and his pro-first-amendment ways. X is the future.
Any Staples store could do it for a buck or two. Easiest option by far. Faxes are considered "secure" for some dumb reason for a lot of industries.

Wizard of the Deep
Sep 25, 2005

Another productive workday
Yea, unless it's a big bundle of papers or an on-going thing, just go to Staples/OfficeDepotMax/Kinkos/UPS Store or whatever and pay a few bucks for six minutes on their fax machine.

tokin opposition
Apr 8, 2021

I don't jailbreak the androids, I set them free.

WATCH MARS EXPRESS (2023)
Back when I worked in healthcare the worst part of my day was when I had to deal with loving faxes. It's not even slightly secure!

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


I'm so glad freaking faxes and other telephony technology are finally loving gone. That stuff might have worked in the 1990s office but goddamn that stuff was unreliable and notoriously difficult to troubleshoot.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

Gucci Loafers posted:

I'm so glad freaking faxes and other telephony technology are finally loving gone. That stuff might have worked in the 1990s office but goddamn that stuff was unreliable and notoriously difficult to troubleshoot.

have you been to a doctor’s office recently

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
Also copy shop was by far the most sensible answer, thank you all!

Dandywalken
Feb 11, 2014



Gotta replace this Thursday. Director ordered ~200 one-foot ethernet cables... but its like 2+ feet across.

Im JUST new enough to the industry be more excited than annoyed.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




Dandywalken posted:

Gotta replace this Thursday. Director ordered ~200 one-foot ethernet cables... but its like 2+ feet across.

Im JUST new enough to the industry be more excited than annoyed.

Goonspeed! And share the After photo!

ilkhan
Oct 7, 2004

I LOVE Musk and his pro-first-amendment ways. X is the future.

Gucci Loafers posted:

I'm so glad freaking faxes and other telephony technology are finally loving gone. That stuff might have worked in the 1990s office but goddamn that stuff was unreliable and notoriously difficult to troubleshoot.
Tell that to the thousands of pages of faxes we deal with weekly (not joking, wish I was).

Prescription Combs
Apr 20, 2005
   6

CommieGIR posted:

Now let's see if they upgrade the forest too, seen so many companies put in new DCs and upgrade old ones but never raise the domain and forest levels to 2019 usually because of some legacy functionality.

Did an engagement where we hit their AD after they patted themselves on the back about upgrading only to find out the Domain was still operating at a 2008 R2 level. That's usually the part that sucks anyways as that's when things will really start to break - AD 2022 can emulate all the way back to 2008 levels, and then you start to lose legacy features that unknown legacy apps depend on and find out after the upgrade is completed.

I vaguely recall them mentioning they were upgrading AD from 2012 to 2016 level if that sounds right? I'm not an AD guy but 2016 stuck out.

Collateral Damage
Jun 13, 2009

tokin opposition posted:

Back when I worked in healthcare the worst part of my day was when I had to deal with loving faxes. It's not even slightly secure!
I used to work for a fund manager. Some (big money) customers insisted on sending orders via fax rather than through the encrypted, two-factor authenticated web interface or API we offered. The only authentication performed on the faxes was that the page header matched the fax number we had on file.

You know, that field the sender can set to anything they want.

tokin opposition
Apr 8, 2021

I don't jailbreak the androids, I set them free.

WATCH MARS EXPRESS (2023)
Finally got an invite for an interview... It's for a bigger org, but the pay scale is less than what I get ranging to slightly more than what I get, minus the bonus I get for doing DEI work. Plus it's two days a week in office. Still gonna interview, but I'm not thrilled this is the one I got a bite on.

It also took them a month to get back to me, which I know is normal but c'mon

Thanks Ants
May 21, 2004

#essereFerrari


Prescription Combs posted:

I vaguely recall them mentioning they were upgrading AD from 2012 to 2016 level if that sounds right? I'm not an AD guy but 2016 stuck out.

One of the functional levels gets you the AD recycle bin which I have no idea why it wasn’t a thing up until that point.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




Thanks Ants posted:

One of the functional levels gets you the AD recycle bin which I have no idea why it wasn’t a thing up until that point.

We went from 2003 to 2016 in one project, staged I think 2003 -> 2008 and 2008 -> 2016. I once commiserating with a friend over his woes trying to set some policies that were introduced with Win10. Poor guy, the DCs had no idea what he was trying to do.

devmd01
Mar 7, 2006

Elektronik
Supersonik
I’ve been here long enough that I’ve taken this place from 2008r2 (w/2003dfl) to 2022 for their DCs. Thankfully it’s a small footprint; I can rip and replace them all in a week.

tehinternet
Feb 14, 2005

Semantically, "you" is both singular and plural, though syntactically it is always plural. It always takes a verb form that originally marked the word as plural.

Also, there is no plural when the context is an argument with an individual rather than a group. Somfin shouldn't put words in my mouth.

Gucci Loafers posted:

I'm so glad freaking faxes and other telephony technology are finally loving gone.

Healthcare IT:

lol, lmao

22 Eargesplitten
Oct 10, 2010



A couple weeks ago I posted about me making a Hail Mary suggestion to HR at my side job that hey I'm qualified and interested in this IT job posting but the pay is ridiculously low. The manager is apparently going to talk to the person who has the authority to increase the pay rate. I thought this guy was leaving and turns out he's now the manager, and I'm not aware of the other IT person leaving. So my conclusion is that they're going to try to keep increasing the number of underpaid unqualified people until things work right rather than getting one qualified mid-level/senior person and one helpdesk person and paying them appropriately.

Mr. Fix It
Oct 26, 2000

💀ayyy💀


GreenNight posted:

Does anyone under 40 even know what a carbon copy is?

just realized i can't answer these anymore :negative:

Prescription Combs
Apr 20, 2005
   6
Worked for a place back in the day that took delivery orders on sheets that had 3 sub-layers for physical carbon copies. :corsair:

Adbot
ADBOT LOVES YOU

The Fool
Oct 16, 2003


at my old msp job we had a number of car dealership clients that all used impact printers with carbon copy forms almost the way through 2018 when the msp went out of business

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply