Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Is there some new security thing where you gotta display a legal banner before logging into an app the government of the USA has to follow?

Made sure to mention which government so the Canuck doesn’t freak out.

E: crossposting cause I forgot this thread exists.


E2: stig appears to be what I’m looking for

E3: https://www.stigviewer.com/stig/apache_site_2.2unix/2014-03-10/finding/V-6373

This guy

jaegerx fucked around with this message at 04:20 on Feb 13, 2021

Adbot
ADBOT LOVES YOU

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Security dudes. Millions of the Pentagon’s dormant IP addresses sprang to life on January 20 https://news.ycombinator.com/item?id=26924883

What are your thoughts? Apparently alibaba and China used these addresses on their internal network.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

Yup. They sound immoral and unethical as gently caress. Not sure why you'd want to work there.

I gotta get paid.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


https://twitter.com/atrupar/status/1425495109798354951?s=20

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Which of you hackers made a batch file and boot rom?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


A cop can’t write batch files

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


if only they knew that infosec jobs was basically to stop us looking at porn

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


What does appriver spam filtering offer over just using gmail? We currently use gsuite. CSO wants to buy appriver cause he worked at appriver. I don’t see what benefit they provide over the largest email host in the world.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Is the cissp brain dump questions somewhat accurate?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


As to why I’m asking infosec questions. We hired a questionable cso that keeps purchasing from companies he’s previously worked for. He bought us appriver despite us using gmail and I just noticed today that he only changed the mx records dns for our .com and not our .org. Both places go to us.

Hence my cissp brain dump cause I honestly thought it was a hard test and I’m just in shock about how stupid those questions are.

E: had to say mx records.

jaegerx fucked around with this message at 03:33 on Apr 1, 2022

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


My cso is a complete idiot so I’m gonna brain dump it to pass and add it to my signature like he does. Yes. He’s a cso that has his certs in his signature.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

that's more and more tempting every day tbh

ted kazinski did that. I think you're right. You should go.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Sickening posted:

What do your policy templates look like if you don't mind me asking. I use mcas alot but haven't made any for BI.

Mast Cell Activation Syndrome (MCAS)

Mast cells are allergy cells responsible for immediate allergic reactions. They cause allergic symptoms by releasing products called “mediators” stored inside them or made by them. In allergic reactions, this release occurs when the allergy antibody IgE, which is present on the mast cell surfaces, binds to proteins that cause allergies, called allergens. This triggering is called activation, and the release of these mediators is called degranulation.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

it's a CASB

Is that what you caught in vegas during defcon?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


klosterdev posted:

Got assigned KnowB4 training and some of the advice feels really dated.

- Looking for typos in an email to determine if is a phishing email (maybe like 5-10 years ago)
- VPN = required for a secure internet connection in public (lol if your company uses split tunneling, most business web resources use HTTPS, VPN is being migrated away from nowadays)
- Common character substitutions in passwords made of common words makes you immune to brute force attacks (pretty sure any modern BF software looks for '3' where an 'e' would go)

Is that the one with the little girl that just wants free icecream? I loving love that one.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Do you guys debate ciphers in here? I never ever wanted to look into tls this deep at all but my loving god. How the gently caress are you people actually like normal human beings? Are you solving prime numbers in your head in poo poo?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Subjunctive posted:

I use a VPN to access my home machines when I travel or used to go to the office. Tailscale these days, thank heavens.

tailscale is awesome

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

mastodon is stupid and loving sucks, like most open source things

Yeah that Linux thing is never gonna take off.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Subjunctive posted:

Lots of things that suck take off and get to be huge. I think maybe you haven’t been paying attention to…anything.

Yeah windows is still a thing

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

don't you have some english football to watch your team lose at

How are the canadiens doing?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Not to be anti mod here but the fact that most of the world cup apps by qatar are basically invading all your privacy so the world cup is kinda a topic.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


KozmoNaut posted:

There are two – one is a mandatory Covid-19 tracing app, the other is possibly mandatory for visitors from abroad. Both have insane levels of tracking and permissions.

Insane? They’re reading txt messages and poo poo.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

Pretty sure that's what they mean by "insane".....

https://appleinsider.com/articles/22/11/20/eu-warns-against-downloading-qatar-world-cup-apps

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


icloud keychain

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

I've never heard of someone having this much trouble with 1password. Even my senior citizen mom could set it up.

can't fix stupid

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


As I recall, the GC issue was because of uh, that lovely intel bug from years ago.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Why don’t you just use touchid on your laptop?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


horse_ebookmarklet posted:

To clarify, I am using TLS1.2, have been the entire time. TLS_PSK_WITH_AES_128_GCM_SHA256 is a TLS cypher suite.

I initially tried with TLS_ECDHE_whatever, but it took like 30 seconds+ for the key exchange to occur, just not feasible in a low power, low compute application.
If I shouldn't use PSK because generating the key is 'rolling my own', I am not sure where I should go from where.

What should I be using?

I loving hate that I know all those acronyms after doing infosec.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


I threw up a little in my mouth

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


https://maia.crimew.gay/posts/how-to-hack-an-airline/

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Silly Newbie posted:

Today a member of one of our accounts payable teams, which has been stung multiple times by compromised vendor payment rerouting, mentioned that she avoided something weird the other day. See, a vendor emailed asking to change from us sending a check to ACH. The vendor got weirdly aggressive when it didn't happen enough, so AP person went to the vendor's public website, compared the address on the ACH to all available addresses for the company, and found that none matched. She immediately called our Project Manager who works with the vendor and told him to call the vendor at a number he had for them before the whole thing started and verbally figure out what was going on. Crisis averted in a way that (more or less) followed the policy I wrote for them the last time they gave away six figures.
They can learn!

BUY LOTTERY TICKETS TONIGHT!

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Sickening posted:

It feels good when the bad thing is prevented. It feels bad to know , in your soul, that if a full audit was performed RIGHT NOW, more than 6 figures has left the door and its just not be noticed.

You're just a glass half full guy aren't you?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Sickening posted:

I know you are enjoying this security money now (that doesn't stop), but you have just begun your journey to really be exposed to how loving dumb these big organizations are jfc.

In november, I spoke to a finance person whose only job is to pay PO's, tell me she has never questioned a po that has crossed her desk. She probably pays more than 100m in po's in a given year. When he statement was brought it up in conversation to her leaders, they didn't flinch.

I feel more like the sheriff for "no country for old men" every passing day of my life.

I’m not quite sure I can drink more but I’ll try for for the money

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


So basically I find the accounting department. Send them a txt I need 10k in $500 Apple Card’s and it works? My mom is 67 and doesn’t fall for that poo poo

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


It depends, can we break it up into age brackets. I figure 18-30 is probably 30%. Anything above that is 10% tops.

e: I don't have access to the latest browser statistics, but based on a survey conducted by NordPass, about 56% of people use a password manager in 2021. However, it's worth noting that this number may vary depending on the source and the specific population surveyed.

That's what chatgpt says.

Further edit, if we think about mobile now cause lets face it, our 60 year parents aren't using a computer, they're on a ipad or a droid. I can see it being more prevalent if they actually new how to use it.

jaegerx fucked around with this message at 02:38 on Jan 22, 2023

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Has a video game got a cve before?

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


CLAM DOWN posted:

I hate it when I'm in america.

Enough said

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Don’t use google authenticator sync to cloud

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


https://www.macrumors.com/2023/04/27/google-authenticator-cloud-sync-no-e2e/

Adbot
ADBOT LOVES YOU

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Try to reinstall it immediately. If they won’t let you or add poo poo on then you’re monitored. I always reinstall my poo poo right away because I tell them I don’t want the manufacturer software on it.

Since it’s Apple you’ll want to create a new Apple ID with their email address as well.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply