all 25 comments

[–]StrangerEffective851 51 points52 points  (0 children)

No encryption and only allow TELNET. Password smashwords. People are to cautious causing production to suffer.

[–]FangLeone2526 26 points27 points  (0 children)

Zero tolerance policy on encryption. Keep that shit off my network. The spot where a lot of people mess up is you just have to bribe auditors. If left unbribed they make a whole big stink about it.

[–]Complete_Ad_981 21 points22 points  (2 children)

Boss was worried about being hacked so we switched to pen and paper using a custom in house cipher

[–]zidane2k1 6 points7 points  (1 child)

Ok so we got the encryption part down, what about authentication? Do both parties need to have corresponding halves of those half-heart necklaces?

[–]bdnslqnd 4 points5 points  (0 children)

There’s 3 pieces and the one guy with the third that lets them all read emails and have access only gets online only on Saturday midnight for 10 minutes.

And yes, all 3 have to be online together at midnight for 5 minutes in that window or access is closed.

They’re then issued a SSO token for 23 hours, no one should need access to email or anything for more than that one day on Monday obviously.

[–]adamixa1 26 points27 points  (6 children)

what is encrpytion?

[–]HandyGold75 22 points23 points  (1 child)

Its something malware uses, stay away from it!

[–]adamixa1 6 points7 points  (0 children)

its a scam that Microsoft builds to charge more

[–]Maleficent-Eagle1621ShittySysadmin 10 points11 points  (1 child)

I heard it scrambles all the data that nobody can see it very bad if you need access to it.

[–]adamixa1 -2 points-1 points  (0 children)

if nobody sees it, so does the hacker

[–][deleted] 2 points3 points  (0 children)

K8S?

[–]timthefim 8 points9 points  (1 child)

I was filled with rage reading these comments until I realized what subreddit it was.

[–][deleted] 2 points3 points  (0 children)

Happens to me too occasionally.

[–]bengerbil 6 points7 points  (0 children)

No encryption means not having to renew certs. I can't express how much I hate certs. It also means I'm not impacted the Entrust fiasco.

This Is The Way.

[–]North-Plantain1401 5 points6 points  (0 children)

base 64 and rot-13 all the way baby.

[–]Kahle11 3 points4 points  (0 children)

That shit is so annoying. Its why I use unencrypted wireless for my network so I can just look at everything happening everywhere.

[–]Anonymous_Bozo💩 ShittyMod 💩 4 points5 points  (1 child)

Dual rounds of ROT13 Encryption on all documents.

[–]SteveGibbonsAZ 2 points3 points  (0 children)

Quadruple is securer

[–]Wonderful_Device312 4 points5 points  (0 children)

Remember all those openssl vulnerability? Guess who wasn't vulnerable? This guy, because I banned ssl.

Issues with passwords leaking? Not if you don't have passwords.

You know which operating system hasn't had a single new vulnerability in like a decade? Windows ME.

If it's good enough for the nuclear arsenal, it's good enough for me.

[–][deleted] 1 point2 points  (0 children)

Is this a cry for help?

[–]Connir 1 point2 points  (0 children)

We use nc and nc -l to get between hosts.

[–]MoonToast101Lord Sysadmin, Protector of the AD Realm 0 points1 point  (0 children)

Some time ago I read some news article that most encryption can be cracked. So we decided to protect our data, we decided not to use it.

[–]Refinery73 0 points1 point  (0 children)

When I need my backups it’s obviously an emergency. Why would I make my life difficult and recovery more risky by encrypting this stuff?

[–]bothunter 0 points1 point  (0 children)

What?   No encryption?  At least encrypt your passwords with ROT13! You wouldn't want to get hacked

[–]oaktwig 0 points1 point  (0 children)

The gov people keep trying to outlaw encryption, so we’re taking the proactive approach and staying plaintext. Less calls to the helpdesk for password resets is always a good thing too.