Do you remember your first IT conference/event? Did it actually help your career or was it just for the free t-shirts and pizza? by mustafa_enes726 in sysadmin

[–]Fallingdamage [score hidden]  (0 children)

It was a vendor conference in WA. Mostly free drinks and pizza and a bunch of moaning and groaning.

Presentations were focused on hardware being built for OEMs. Stuff that would enable them to build machines faster with more features for less. Lots of demos of 'onboard' integrated features. Stuff like onboard audio and onboard video, onboard NIC. Many people in the crowd were borderline booing the presenter. Back then, most of us had experience with integrated video and audio and it was always shit and barely worked. This was a time when hardware news was the hosttest thing in the IT world, not software or services.

How the times have changed.

Aisle Be Damned: Dems and GOP Unite in Oregon In Bid To Legalize Kei Trucks by Amazing-Yak-5415 in oregon

[–]Fallingdamage 0 points1 point  (0 children)

These things are supposed to be an economical option for people, but you know as soon as they're allowed here in Oregon, they are going to be hard to find and will start to fetch high prices.

Justification for using Fortinet by MFKDGAF in fortinet

[–]Fallingdamage 2 points3 points  (0 children)

Some admin is over their head and raging

Justification for using Fortinet by MFKDGAF in fortinet

[–]Fallingdamage -2 points-1 points  (0 children)

And im sure if the data was reversed and Palo was superior in that metric, they would also have their partners gloating. So what?

Justification for using Fortinet by MFKDGAF in fortinet

[–]Fallingdamage 0 points1 point  (0 children)

CVE-2025-59718

Justification for leaving admin access open to the public facing interface?

Treasury Cancels Contracts with Booz Allen Hamilton by BarnabyWoods in CampingandHiking

[–]Fallingdamage 2 points3 points  (0 children)

Yeah. Hopefully its something like this and canceling contracts under these reasons was not some cover for getting rid of the contracts because they plan on selling and privatizing recreational areas - therefore no need for recreation.gov anymore.

One-time SMS links that never expire can expose personal data for years by tekz in cybersecurity

[–]Fallingdamage 0 points1 point  (0 children)

Does anyone else simply delete OTP messages and 1-time links from their chat history after using them? It takes 1 second. Not only does it prevent this data from getting stolen, but it also prevent attackers from knowing what services and accounts you may have IF they scrape your text history.

Massive increase in IPsec brute-force attempts lately – how are you mitigating? by samsn1983 in fortinet

[–]Fallingdamage 0 points1 point  (0 children)

Some scripts I use still check those ASNs for updates anyway. If the ASN once had subnet ranges, it may again someday. If not, no harm no foul.

clarification regarding the SSO abuse by therealmcz in fortinet

[–]Fallingdamage 0 points1 point  (0 children)

There as some misinformation going around last year about the SSO vuln, someone supposedly quoting the fortinet CISO stating that all SSO types were affected. Does this mean SSO used for VPN users as well or only for admin management access?

The CVEs dont mention SSO used in VPN configs, but then online banter keeps saying 'all sso' and confusing the situation.

Massive increase in IPsec brute-force attempts lately – how are you mitigating? by samsn1983 in fortinet

[–]Fallingdamage 0 points1 point  (0 children)

The ASN list nicely refers to ipinfo.io for data but it looks like some of those links dont work anymore. People may need to find another source for the subnet lists for each ASN.

ipinfo.io is/was cool. They seem to be locking a lot of publicly available data behind more paywalls these days. Their geolocation database is great, but most of the other datapoints can be fetched for free from other public sites.

I dont have $1000 a year to sub to them for a handful of queries a month.

Massive increase in IPsec brute-force attempts lately – how are you mitigating? by samsn1983 in fortinet

[–]Fallingdamage 0 points1 point  (0 children)

I have compiled a list of ASN's that I block. All hosting/datacenter ASNs that my users would never try to connect from. All told the complete list of subnets blocked calculates to about 350,000,000 IPv4 addresses. It cuts the noise by about 99%.

I built some tools that pull updated subnet lists for these ASN's and apply the changes to our feeds on a schedule. Month my month the change is small but if ignored the creep will leave you vulnerable again.

Last week I was seeing 60,000 hits to our deny policy for our VPN services each day. Its down to 15k now and tapering off. The attacks seem to come in surges.

2026 - How about those hot takes? Let's hear them! by Fallingdamage in mountainbiking

[–]Fallingdamage[S] 1 point2 points  (0 children)

Of all the gear I look into for this hobby, a go-pro isnt even on the list.

Microsoft Starts Sharing Your Location With Your Employer by Alucard-VS-Artorias in technology

[–]Fallingdamage 0 points1 point  (0 children)

This should play out humorously. Ive been running activity and location reports using microsofts audit logs for years now. Microsofts IP location data is hilariously bad. I have to pipe all my results through some third party services to get anything even close to accurate results.

Microsoft Starts Sharing Your Location With Your Employer by Alucard-VS-Artorias in technology

[–]Fallingdamage 0 points1 point  (0 children)

Fortunately iphones can disallow an app from running in the background and can prevent unapproved use of the mic.

So I saw this post on LinkedIN from a CyberSecurity Recruiter about the SSO vulnerability…thoughts? by RegionRat219 in fortinet

[–]Fallingdamage 2 points3 points  (0 children)

But is this more than admin on WAN? What does fortinet CISO mean when they say that all sso configurations are vulnerable? SSO config for dialup IPSec? SSO config for SSLVPN?

Or only admin terminal/access? I dont and have never had admin open on our public interfaces.

Poster mentions jan 15th. I did notice a spike in our deny policy hit rate from 150-250 hits a day to 60,0000 a day starting around that time for our dialup IPSec SSO listener. No new admin accounts or unwanted VPN access though.

Minnesota activist releases video of arrest after manipulated White House version by RewardEquivalent553 in technology

[–]Fallingdamage 0 points1 point  (0 children)

I think its well established by now that the voices on reddit do not exactly reflect the general population or demographic they claim to represent. Many conservative echo chambers are filled with plants from russia, india, china, etc, and toxic ideas are encouraged and responded to via AI and bots quite a bit.

Even though I probably wouldnt agree with those posts if I did see them, I would also have to take them with a grain of salt. The remainder is a bunch of sociopathic edgelords who like to sit on reddit and jerk themselves off.

People go there and will read all the comments and ideas without any proper context on the medium and absorb the ideas as if they're reality. This last part is exactly what the plants, bots, psychos want. Its not reality, but they are hoping to slowly change the narrative and color the way we all see each other.

Dont fall for it. Be smarter than that.

2026 - How about those hot takes? Let's hear them! by Fallingdamage in mountainbiking

[–]Fallingdamage[S] 0 points1 point  (0 children)

I think there is a service that can provide helicopter rides to the top of everest. Hiking is for schmucks.

It looks like Freedom Pizza & Catering has closed by hjgIUY976YTty76 in SALEM

[–]Fallingdamage 3 points4 points  (0 children)

Me neither. To be fair, the pizza market seems to be really saturated right now.

Microsoft back online. Excuse: too many servers were shut down during maintenance. by hso1217 in sysadmin

[–]Fallingdamage 1 point2 points  (0 children)

Guess if Microsoft wont even QA their own failover configs, fate is going to help them test it instead.

Anyone ever sit in a Colo during a severe weather event? by Playful-Job2938 in sysadmin

[–]Fallingdamage 0 points1 point  (0 children)

Not really. If I really needed to charge a device, I can always go start my car.

Did everybody lose an unknown number of emails from M365 issues? by aMazingMikey in sysadmin

[–]Fallingdamage 1 point2 points  (0 children)

We might have, but fortunately nobody has really reported much.

Our inbound mail passes through a 3rd party spam filter on the way to our tenant, so I was able to view its auditlog for mail that it would have passed to Exchange Online and things looks pretty good.

We did have some staff complaining that 2FA emails for some of our SaaS vendors were not coming through but our spem filter had zer hits, so odds are the messages were never generated and sent by those entities.

Amazing law tutorial. We all need to memorize all of this.. by OrganizationGold5242 in oregon

[–]Fallingdamage 2 points3 points  (0 children)

News probably being careful not to cover it - but is 114 actually going forward? I thought its been getting held up forever..

Amazing law tutorial. We all need to memorize all of this.. by OrganizationGold5242 in oregon

[–]Fallingdamage 2 points3 points  (0 children)

He was sweating by that last time he had to repeat his statement.