Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Albinator
Mar 31, 2010


Good for small numbers of users; they just released a business version with AD integration if you like it but need a bit more manageability (can’t say I’ve tried that version, mind you).

Adbot
ADBOT LOVES YOU

Albinator
Mar 31, 2010

Who would you report to? You need high level buy in from the start; if you don’t have that, or are not in a position to be able to quickly build it things might be tough.

Albinator
Mar 31, 2010

Proteus Jones posted:

I'd definitely go for it.
Same. Sounds like a great opportunity.

Albinator
Mar 31, 2010

That is not the news I wanted to start my day with.

Albinator
Mar 31, 2010

Additionally, if something bad happens, who will actually be called on the carpet?

If there's an AD password policy, who made it, and who keeps it updated?

e: basically, it's weird. If you're big and mature enough to have a FTE explicitly in a security role, I'd expect your security policies and procedures and who does them to be pretty fully fleshed out and written down.

Albinator fucked around with this message at 15:51 on Feb 1, 2019

Albinator
Mar 31, 2010

fyallm posted:

We have O365 but for some reason the beta of teams at our place doesnt have a mobile option? Wtf? No phone app?
E: beaten

Albinator
Mar 31, 2010

Guy Axlerod posted:

I have a dumb email question: If I have DKIM set up, do I also need SPF for DMARC? I thought both should be aligned. I was checking our SPF record and noticed that mailchimp was missing. They don't have any SPF info on their site and their support just told me that they don't require me to put it in.

As far as I can see, you need
code:
include:servers.mcsv.net
in your SPF record for mailchimp. You will need it for DMARC; set p=none until you're sure everything is set up right.

Albinator
Mar 31, 2010

Cup Runneth Over posted:

If I remembered the account that messaged me, I would go and report it, but it was a distant acquaintance and they make sure to block everyone after they're done running the script or deviate from it, so I can't pull them up again. Hopefully someone else on their friends list alerts them.

The psychology of phishers/scammers is interesting; I watch a lot of scambaiting videos on YouTube and occasionally the uploader will get through to the scammer at the end of the saga and confront them about what they're doing. Indeed, most of them believe themselves morally sound; after all, why would you keep doing it day after day if it didn't rest easy on your conscience? It's good to hear that they're focused on items and not going to try and resell my email on the darkweb or something (joke would be on them, it doesn't exist anymore), or try to lock me out/compromise related accounts, but obviously I'm not going to take any chances!

e: I also hope this inspires some of you to go on a password updating/MFA enabling spree like I did when I posted about my friend's Twitter account being mysteriously compromised a while back. Bought me some peace of mind!

Awareness is of course important too - we've been laughing at dumb goons getting caught by this over in the Steam thread for months now :v:

e: glad nothing of value was lost because you had defense in depth, but of course the true defense is to not have any friends

Albinator fucked around with this message at 02:40 on Apr 4, 2021

Albinator
Mar 31, 2010

BrianRx posted:

It's surprising to me that the people sending these emails go to the trouble of setting up the slightly off domain and matching the design of a chase email but can't find anyone who can write a paragraph of English without making grammatical mistakes. I used think it was to get dumb people to self-select as marks, but this kind of attack seems to be meant to work on anyone.

I don't see much wrong with the language on this one - maybe just "an unusual activity" is odd and would be better with "some", but I think plenty of native speakers wouldn't even pick up on it. It's miles more convincing than most.

Albinator
Mar 31, 2010

I am exceedingly glad I'm "between jobs" and not responsible for any linux machines in Azure right now.

Albinator
Mar 31, 2010

Klyith posted:

Phrases are just as hard to memorize with many unique passwords as anything else.
Not my experience, but that's with generating and keeping most creds in a password manager, so only a need for memorizing a handful of things.

Adbot
ADBOT LOVES YOU

Albinator
Mar 31, 2010

What is that, the 4th? 5th? this month?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply