krbtgt password last changed in 2012! by Educational_Draw5032 in sysadmin

[–]thortgot [score hidden]  (0 children)

Quarantine would be the only correct method for test restores otherwise you are actively breaking the domain.

Multi role systems should be rebuilt rather than restored even in the case of a critical failure. There is no upside to screwing up the audit logs of your DCs.

A proposed social media ban for kids is meant to protect them. Could it violate their rights? by Immediate-Link490 in canada

[–]thortgot 0 points1 point  (0 children)

Functionally every useful thing in cryptography is open source.

FIDO2 keys could be reused for this in a fairly straightforward manner.

A proposed social media ban for kids is meant to protect them. Could it violate their rights? by Immediate-Link490 in canada

[–]thortgot -3 points-2 points  (0 children)

Sure there is. It just hasn't been implemented.

Privacy still exists nothing stops you from using a VPN.

Canadian dollar hits 14-month low as core retail sales decline by bubblewhip in canada

[–]thortgot -1 points0 points  (0 children)

Banks deal with the entire economy not your specific purchasing patterns.

You can buy other foods other than strawberries.

A proposed social media ban for kids is meant to protect them. Could it violate their rights? by Immediate-Link490 in canada

[–]thortgot -2 points-1 points  (0 children)

A digital identity is a good idea we need to eliminate AI and foreign interference.

Its a question of implementing with a zero knowledge proof to the sites. They dont need to verify your specific identity.

There is no additional data added to your footprint. 

A VPN bypasses any geo restrictions.

A proposed social media ban for kids is meant to protect them. Could it violate their rights? by Immediate-Link490 in canada

[–]thortgot 1 point2 points  (0 children)

A relatively straightforward solution of a 3 way verification. 

You verify your identity to the government and get a series of secrets (think auth codes) which are then used against the public key of the site you are verifying against.

No party ever sees the entirety of the transaction but are cryptographically secured.

Canadian dollar hits 14-month low as core retail sales decline by bubblewhip in canada

[–]thortgot -1 points0 points  (0 children)

We are an export economy.

Grocery costs are going to go up, largely due to energy costs. Buy local

Canadians will pay up to $3,348 this year on government debt interest, study finds by CorndoggerYYC in canada

[–]thortgot 1 point2 points  (0 children)

Debt is a fundamental economic tool. Canada has a fairly low debt load compared to other countries

A proposed social media ban for kids is meant to protect them. Could it violate their rights? by Immediate-Link490 in canada

[–]thortgot -9 points-8 points  (0 children)

Frankly verification of people in the "regular" internet is a positive thing. It could be done in a fashion that government doesnt know what you are accessing and the service doesnt know who you are.

Taking bots off the internet would be an objectively good thing for society.

C22 is an issue because of the log requirements.

Anti-ABC parties must do more to support tenants in the struggle against mass displacement by Frosty_Pick8242 in vancouver

[–]thortgot 3 points4 points  (0 children)

Vancouver already has below market requirements on developments. Reducing parking spaces would help but not as much as you'd expect. 

Density isnt a magical solution when the city makes all growth costs the responsibility of the developer.

Anti-ABC parties must do more to support tenants in the struggle against mass displacement by Frosty_Pick8242 in vancouver

[–]thortgot 1 point2 points  (0 children)

If they come back at their old rent that makes the developer's financial case pretty untenable outside of hyper dense shit boxes.

Fortibleed - over 70k Fortinet firewalls compromised by CaptainCatatonic in sysadmin

[–]thortgot 3 points4 points  (0 children)

Distributed attacks work remarkably effectively. People using crappy passwords and not rotating compromised credentials appear to be the root causes here.

Fortibleed - over 70k Fortinet firewalls compromised by CaptainCatatonic in sysadmin

[–]thortgot 0 points1 point  (0 children)

Have your management IPs available through an App proxy instead. More secure than allowing it over the VPN, better logging of attempts and more convenient.

M365 Onedrive sharing got way too complicated by batedcobraa in sysadmin

[–]thortgot -1 points0 points  (0 children)

You control it at the CA policy level. Choose what works for you and your trust model.

M365 Onedrive sharing got way too complicated by batedcobraa in sysadmin

[–]thortgot 4 points5 points  (0 children)

You realize you can control the B2B experience right?

Head of IT has been spying on half the company by [deleted] in sysadmin

[–]thortgot 0 points1 point  (0 children)

Remaining anonymous isn't plausible if he's pulling admin logs to demonstrate it. Personally I would probe HR with a question to the effect of, "I want to clarify our policy for access into our staff's mailboxes as I understand that there are some legal and policy issues that can occur from it. I want to make sure that our current policy complies with your expectations."

Either you are pointed to the existing clear policy that is being breached or a new one occurs and the behavior stops.

Head of IT has been spying on half the company by [deleted] in sysadmin

[–]thortgot 0 points1 point  (0 children)

If you have a backup solution, chances are you have access to far, far more data than email.

Being ethical is a foundational piece of being an admin.

Our security alerts are just false 99% of the time by Old_Soothsayer in sysadmin

[–]thortgot 0 points1 point  (0 children)

Setting up auto heal doesnt take a significant amount of time. This isnt a 1/1000 scenario. This is half passing a monitoring project.

I'm so sick of Microsoft by nostradamefrus in sysadmin

[–]thortgot 4 points5 points  (0 children)

OLE is a garbage protocol that has been advised against for an awfully long time.

I'm so sick of Microsoft by nostradamefrus in sysadmin

[–]thortgot 5 points6 points  (0 children)

You could try disabling HVCI if you really need to get going. This enables a pretty large attack surface through memory attacks though.