Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Greentext
  3. Anon witnesses excellent security

Anon witnesses excellent security

Scheduled Pinned Locked Moved Greentext
greentext
112 Posts 74 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W [email protected]

    OPNsense is also a viable alternative.

    S This user is from outside of this forum
    S This user is from outside of this forum
    [email protected]
    wrote last edited by
    #64

    Tried that for awhile at home, just didn't seem as robust. Also, you can get Netgate hardware if the company doesn't want a 10-yo Dell running the edge.

    N M 2 Replies Last reply
    1
    • S [email protected]

      My boss went so far as to buy Macs because we have "special needs" (we don't) because otherwise we'd be forced to use the corporate locked down crap. I'm not a big fan of macos (prefer Linux), but root access sure is nice.

      C This user is from outside of this forum
      C This user is from outside of this forum
      [email protected]
      wrote last edited by
      #65

      I had to move to a Mac because of iOS development. Now I'm stuck with a Mac because the fucking thing refuses to break.

      1 Reply Last reply
      3
      • W [email protected]

        Often times when you pay for the product, you are still the product.

        C This user is from outside of this forum
        C This user is from outside of this forum
        [email protected]
        wrote last edited by
        #66

        I'm the product in the sense that poo is the product of the intestines.

        1 Reply Last reply
        1
        • D [email protected]

          insert thats the neat part meme

          Eventually it was decided I would write Javascript on a web page I made. Skills I never declaired having I told them I was a java dev.

          T This user is from outside of this forum
          T This user is from outside of this forum
          [email protected]
          wrote last edited by
          #67

          Javascript is a part of Java, duh!

          D 1 Reply Last reply
          0
          • S [email protected]

            Tried that for awhile at home, just didn't seem as robust. Also, you can get Netgate hardware if the company doesn't want a 10-yo Dell running the edge.

            N This user is from outside of this forum
            N This user is from outside of this forum
            [email protected]
            wrote last edited by
            #68

            I've had opnsense running for 7 years without a single issue. It might be the most reliable part of my whole setup.

            1 Reply Last reply
            1
            • A [email protected]

              I hate sites that make me constantly change passwords. it's been shown time and time again that making users change passwords often decreases security by a pretty large factor, and yet a lot of sites still do it

              B This user is from outside of this forum
              B This user is from outside of this forum
              [email protected]
              wrote last edited by
              #69

              Interesting, stopped seeing this a while back. Forced change after the inevitable hack though of course

              O 1 Reply Last reply
              2
              • P [email protected]

                It's not more secure, it's so they can offload blame and have people to sue if/when something ugly happens. Liability control, essentially.

                We had to pay for fucking Docker container licenses at my last job because we needed an escalation to the vendor in case our SMEs couldnt handle things (they could), and so we had a vendor to blame if something out of our control happened. And that happened: we sued Mirantis when shit broke.

                B This user is from outside of this forum
                B This user is from outside of this forum
                [email protected]
                wrote last edited by
                #70

                Ever hear how the suit turned out, generally?

                1 Reply Last reply
                1
                • A [email protected]

                  I hate sites that make me constantly change passwords. it's been shown time and time again that making users change passwords often decreases security by a pretty large factor, and yet a lot of sites still do it

                  mrsdoyle@sh.itjust.worksM This user is from outside of this forum
                  mrsdoyle@sh.itjust.worksM This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #71

                  Our workplace did that. You had to change every month and you weren't allowed to just add a digit. It meant that people started writing their passwords on post-its stuck to the monitor.

                  Mind you, back in the 90s your password was the same as your username. It was very handy, because if someone went home leaving a document locked, you could just log in and unlock it. Our first "proper" IT professional was horrified.

                  1 Reply Last reply
                  2
                  • Q [email protected]

                    Everyday my misnathropy is justified

                    vanilla_puddinfudge@infosec.pubV This user is from outside of this forum
                    vanilla_puddinfudge@infosec.pubV This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #72

                    Print the fucking t-shirt man. I'll buy one for every day of the week.

                    1 Reply Last reply
                    2
                    • P [email protected]

                      Don't forget your new 32 character/symbol/number/nordic rune passwords that will need to be changed every 17 days.

                      W This user is from outside of this forum
                      W This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #73

                      And don't forget required 2-factor authentication, in an age where that becomes 1-factor authentication as soon as someone has your phone, because both factors are accessible there!

                      2FA is utterly worthless in the age of smartphones, and whenever my employer tries to implement it, I refuse and tell them that, if they want me to do 2FA, they can either provide me with a work phone, or they can give me a USB key that is just going to sit in my desk drawer.

                      a_wild_mimic_appears@lemmy.dbzer0.comA gutek8134@lemmy.worldG 2 Replies Last reply
                      4
                      • W [email protected]

                        And don't forget required 2-factor authentication, in an age where that becomes 1-factor authentication as soon as someone has your phone, because both factors are accessible there!

                        2FA is utterly worthless in the age of smartphones, and whenever my employer tries to implement it, I refuse and tell them that, if they want me to do 2FA, they can either provide me with a work phone, or they can give me a USB key that is just going to sit in my desk drawer.

                        a_wild_mimic_appears@lemmy.dbzer0.comA This user is from outside of this forum
                        a_wild_mimic_appears@lemmy.dbzer0.comA This user is from outside of this forum
                        [email protected]
                        wrote last edited by [email protected]
                        #74

                        which still requires someone to swipe the phone and the owner not recognizing it long enough to do a remote wipe. I am not someone who hangs on the smartphone 8 hours per day, and even i would realize my phone is gone within 15 - 30 minutes, giving an attacker a pretty small time window to act.

                        e: and they have to break into the phone as well - if it's updated, that might buy more than enough time

                        1 Reply Last reply
                        1
                        • A [email protected]

                          Every day I wake up I thank God I'm not an MBA 🙏

                          F This user is from outside of this forum
                          F This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #75

                          MBAs would just buy an LLM software subscription to fix it

                          1 Reply Last reply
                          2
                          • B [email protected]

                            Interesting, stopped seeing this a while back. Forced change after the inevitable hack though of course

                            O This user is from outside of this forum
                            O This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #76

                            Could be because OWASP now actively recommends against periodic password changes.

                            Ensure credential rotation when a password leak occurs, at the time of compromise identification or when authenticator technology changes. Avoid requiring periodic password changes; instead, encourage users to pick strong passwords and enable Multifactor Authentication Cheat Sheet (MFA). According to NIST guidelines, verifiers should not mandate arbitrary password changes (e.g., periodically).

                            1 Reply Last reply
                            1
                            • M [email protected]

                              Vim? Oh wow. I'd be looking into a USB Keyboard that types the entire source code of vim into the machine, assuming there isn't an easier option.

                              F This user is from outside of this forum
                              F This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #77

                              Fork vim, rename it, sell it back to your company

                              K 1 Reply Last reply
                              3
                              • L [email protected]

                                I could really see companies just fork open source and give it a tweak like UI or new switches...

                                Terrible.

                                F This user is from outside of this forum
                                F This user is from outside of this forum
                                [email protected]
                                wrote last edited by
                                #78

                                New wealth redistribution method?

                                1 Reply Last reply
                                1
                                • W [email protected]

                                  At one point my company made us buy Eclipse from a vendor because free software was not allowed. It had no tweaks or support, just out of date Eclipse that I had to wait for purchasing to get

                                  A This user is from outside of this forum
                                  A This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #79

                                  Whenever I hear about shit like this I wonder if I should just start a company and package free software lol. Could like donate a bunch of the profit to the actual projects.

                                  F 1 Reply Last reply
                                  1
                                  • S [email protected]

                                    Tried that for awhile at home, just didn't seem as robust. Also, you can get Netgate hardware if the company doesn't want a 10-yo Dell running the edge.

                                    M This user is from outside of this forum
                                    M This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #80

                                    Bought some of the higher end negate routers for work. 1u rack mount. Five locations all linked with fail over tunnels. I run our filter and monitoring on them as well . Pfblockng works great for general purpose filtering. When you filter porn you really need a lot of ram. The intel boards they have are a little finicky on the type of SFP you can install but other than that they work great.

                                    S 1 Reply Last reply
                                    0
                                    • F [email protected]

                                      Fork vim, rename it, sell it back to your company

                                      K This user is from outside of this forum
                                      K This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by
                                      #81

                                      Donate cost back to vim

                                      F 1 Reply Last reply
                                      1
                                      • W [email protected]

                                        OPNsense is also a viable alternative.

                                        M This user is from outside of this forum
                                        M This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #82

                                        Sure, I've tried it but honestly there wasn't much difference. I use pfsense because its what I started with. I imagine if you started with opnsense it would be the same thing. I use pfsense+ licensing for all the routers at work and that makes the higher ups happy that its has commercial support if needed.

                                        1 Reply Last reply
                                        1
                                        • N [email protected]

                                          As if the Eulas don’t make it all arbitration?

                                          What software company allows liability for mistakes in a EULA?

                                          D This user is from outside of this forum
                                          D This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by
                                          #83

                                          Companies and individuals play by different rules.

                                          When a big company purchases software a team of people from both parties (whose entire job and career are based on doing this) negotiate with each other to decide exactly who is liable for what and to what degree.

                                          When you purchase software you agree to let the company fuck you over at their leisure because you literally do not have enough hours in the day to even read everything you agree to, let alone understand it, let alone argue with it. And even if you did you don't have enough bargaining power to make a large company care.

                                          1 Reply Last reply
                                          2
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups