Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
power botton
Nov 2, 2011

are you even allowed to say you once worked at oracle if you leave

Adbot
ADBOT LOVES YOU

power botton
Nov 2, 2011

In a similar vein we had some eval company freak out because we flagged like all their admin accounts and service accounts having PASSWORD_NOT_REQD being set (and a bunch of them not having passwords) as an issue.

he couldn't show our product to his boss cause it definitely is not an issue and we're dumb and stupid for thinking it is!!!

It was something about smart cards. "best practices" was thrown around a bunch. Either its the same company or this is a more popular way of solving login/lockout problems than I thought.

power botton
Nov 2, 2011

didn't chase or capital one or some bank let you just type in someone else account number once you were logged in a few years ago

power botton
Nov 2, 2011

Rufus Ping posted:

i remember a british bank forgot to key their http cache on the logged in userid and customers suddenly started seeing other peoples account details

https://nypost.com/2018/02/22/chase-says-glitch-gave-customers-access-to-wrong-accounts/

apparently that's popular. this is probably what I was thinking of.

power botton
Nov 2, 2011

I hope fire eye asks if bill ever tried the cigar trick with her... in a secure manner. boom on topic.

power botton
Nov 2, 2011

what's so lovely about splunk in production

power botton
Nov 2, 2011

wow rude

power botton
Nov 2, 2011

i got an email to my work address from myself saying i got hacked and theyre gonna release nudes to everyone in my contacts so long story short everyone at work knows what my penis looks like

power botton
Nov 2, 2011

lets not forget persistant malware in your bios that exfiltrates data through microwaves or morse code or something

power botton
Nov 2, 2011

... and to my dad, i leave my suicidegirls account

power botton
Nov 2, 2011

its probably the same thing as everyone else - checking haveibeenpwned, and will coincidentally break just along with every other vendor once HIBP goes private

power botton
Nov 2, 2011

crazysim posted:

it'll break if they don't pay HIBP.

so then half these vendors will change it to a susbcription based "identity protection service" for an extra 2 bucks/month or something. 1password is already subscription based and set up nicely for this. lower the cost of the normal version by a dollar or whatever and increase the cool HIBP integration to like 2$/month or whatever.

either way im going to assume a lot of these services will go pay only or break, so you don't have to worry about it unless you actually opt in.

power botton
Nov 2, 2011

Patents are good. Our patent lawyer at work does like 0 due diligence so they all get rejected but I get 1000 bucks if I submit an application so I keep throwing poo poo at the wall.

power botton
Nov 2, 2011

i accidentally opened up lDAP to the internet and the past month my azure vm uploaded like 17 tb. it was only like 6 or 700 bucks which seems pretty reasonable

power botton
Nov 2, 2011

sure thats bad to add to DOS attacks, but it also felt kinda good to finally be part of something bigger than myself

power botton
Nov 2, 2011

its cool theyre all posting uhh... that was from the staff who are definitely outside the room

power botton
Nov 2, 2011

Symantec has OEMed us and what you are all saying is very hurtful.

please understand there are human beings behind the software you use and just because it doesn't work as you think it should thats no cause for being an asshat

power botton
Nov 2, 2011

Shaggar posted:

setting up a new AD domain is super easy and if you want to copy everything its also real easy. the problem w/ migrations is always in scenarios where you're migrating from one domain into an already well established domain as in a merger or something. even then its just about make sure you know which objects you want to migrate and if there will be collisions rather than the actual migration.

migration is just copying ldap objects which is super simple.

yeah I dont see how migrating the actual domain is hard. merging a companies IT resources and all that risk is a real issue and involves the business but standing up a new domain and trust is clicking next like 10 times and changing some samaccountnames. worst case scenario just rely on sid history and wide open trusts.

power botton
Nov 2, 2011

infernal machines posted:

well, sid history only works as long as the original domain is online, so there's that

at no point did i say it was hard, i said it was expensive. which it is, because it's time consuming to do right. but yes, if you handwave all the complexity of doing it in a live environment with an active business, it's actually very simple and probably anyone could do it essentially for free.

so you agree it's all people problems and from a technical perspective its pretty easy.

power botton
Nov 2, 2011

evil_bunnY posted:

lol you don't know poo poo

how won't that work? let me just pick a random application you would have to migrate. Exchange?

here's how you migrate exchange:

sid history and trusts.

it works 100% of the time

infernal machines posted:

yes, was that in question?

i have no idea what set off y'alls pedant sense about an anecdote regarding how single label domains are hosed and costly to fix

im just trying to clear up some misconceptions re: "costly" migrations

power botton
Nov 2, 2011

what are peoples thoughts on ping. ADFS seems way less fucky to get working but i dunno.

power botton
Nov 2, 2011

you know hes bitching about this idiot customer to his coworkers too

power botton
Nov 2, 2011

dont vaults like thycotic/cyberark claim to handle that? dunno how well that works in reality though. I got the impression its huge professional service bills to really do the discovery and migration.

natively in AD group managed service accounts handle that but you need a fairly high functional level. migrating to that, much like domain migrations, is actually very easy. GSMAs are cool as h*ck though.

the people I've spoken to do everything they can to find out where that account is being used, and the original purpose of the account to see if that matches up.

sometimes they leave it cause its too sketchy to touch, a lot of times migrating to GSMAs involves creating a bunch of different accounts if the sprawl got too big. ultimately it involves doing your best due diligence up front and hoping your trading system doesn't go down for too long.

power botton
Nov 2, 2011

yeah just checked and thycotic secret server or the cyberark central policy manager does all that stuff. I think thycotic also claims to be able to replace passwords in connection strings in scripts too? which is a perfect summation of enterprise security.

power botton
Nov 2, 2011

BangersInMyKnickers posted:

so you've consolidated all your PII in to a single location and didn't bother with any kind of RBAC or sanitization?

we scan for sensitive data. at first we didnt bring back the actual data that matched our criteria. customers demanded we start saving the actual result in their 99% of the time unencrypted database so they could review results for false positives I guess? I dunno.

either ive learned that a critical part of the process for PCI compliance is copying every CC# and CVV you find verbatim into a database.

power botton
Nov 2, 2011

1password just raised 200 million so dont expect it to be good for much longer

power botton
Nov 2, 2011

CRIP EATIN BREAD posted:

i wonder what they even need that money for unless it's for some massive amount of infrastructure they want to put up, because 1password hasn't really changed in ages. the only thing i can think of is the 1password for teams stuff, which we use at work, or the new-ish browser plugin that syncs with the cloud storage.

1password still owns, though

getting the founders tons of money and then also maybe going after the enterprise vault space?

power botton
Nov 2, 2011

it would be cool to do that. who wants to make a credible threat against my life itt

power botton
Nov 2, 2011

how is that a data breach when its just consolidating publicly accessible information people willing provide

power botton
Nov 2, 2011

push it to the limit

power botton
Nov 2, 2011

mycrimes.mp4

https://www.youtube.com/watch?v=qk2jeE1LOn8

power botton
Nov 2, 2011

ping is cool because if you need to return the objectsid in your contract you need to specifically tell it "ad will return this as bytes please decrypt it into usable S-1-whatever" instead of just working

also it seems like they try to abstract everything in case you need to use the same attributes or filters or whatever in multiple services so configuring it takes like 100x longer than ADFS

power botton
Nov 2, 2011

maybe im stupid but ADFS was super super easy to get working in an afternoon and ping was very very convoluted and I had to reach out to them multiple times when I was trying to configure it

power botton
Nov 2, 2011

Shame Boy posted:

idk how my work email gets on these weird lists


bonus from the fine print at the bottom:


love 2 have my data enhanced

for some reason an electron microscope company account rep keeps emailing me

power botton
Nov 2, 2011

guys I dont want this thread to be closed please stay on topic of security issues

power botton
Nov 2, 2011

Cybernetic Vermin posted:

the late stymies two gimmicks; warning about the dangers of alcoholism, and espousing the inherent immorality of computer touching; were both entirely correct and very effective trolling for yospos. rip~

power botton
Nov 2, 2011

turn off the gas and the electricity before you leave anywhere if its such a big worry

power botton
Nov 2, 2011

at work they made a big announcement about split tunneling to help vpn capacity but either they hosed up configuring it or just blatantly lied and want to catch people loving around.

power botton
Nov 2, 2011

screen reading should be part of the OS. something like a core component called "VoiceOver" or something.

Adbot
ADBOT LOVES YOU

power botton
Nov 2, 2011

my ceiling fans have an open wifi network but I live in a brick + steel building and nothing makes it outside

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply