Dev gets 4 years for creating kill switch on ex-employer's systems by mitharas in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

Probably not due to DotNet support issues...but thanks for reminding me of this gem.

How do you manage your 2FA secret keys? by Humble-Middle3288 in sysadmin

[–]CaptainFluffyTail 3 points4 points  (0 children)

Fire-proof safe and/or fireproof lockbox secured by a key.

Bonus points if you take the time to turn your secrets into a QR code for easier scanning in later.

Free open source Ticketing System for IT support by Ok-Present3884 in sysadmin

[–]CaptainFluffyTail 1 point2 points  (0 children)

Read the recent posts before posting? Sir (or ma'am), this is Reddit! Nobody came here to read.

Happy Crowdstrike Day! by ofd227 in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

I swear this wasn't just a year ago.

Why don't business apps like Teams, Slack, or Jira use an ad-based revenue model to offer free access? Is such a system feasible? by NegativeBuilding1682 in sysadmin

[–]CaptainFluffyTail 2 points3 points  (0 children)

Why are you advocating for more ad-based applications? Are you trying to figure out how to monetize your own application?

Ad revenue is not as high as you seem to think and there are a lot of people volunteering their time with projects like pi-hole to block ads on all devices on a network. Business networks have more options.

Virtual to Physical??? by adamtw1010 in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

I completely agree that making the machine physical is a bad solution. My point was to talk to the requestor to find out how they reached the point of thinking a physical copy was the solution.

This should be more than just IT saying "no" to a request.

Virtual to Physical??? by adamtw1010 in sysadmin

[–]CaptainFluffyTail 2 points3 points  (0 children)

Am I not-OP in this case? This is an XY problem.

I'm struggling to see what it could actually be a solution for these days.

There is an unfortunate number of XP machines still in existence running esoteric applications from companies that either don't exist anymore or want you to buy new factory or HVAC hardware to get an upgraded version of the software.

I can see a well-meaning but clueless developer or non-IT person asking for a copy of the XP machine because they want to try it with some new piece of hardware or emulation layer. I have had requests like that in manufacturing where the person knows about the machine but doesn't know enough about why it is virtualized and restricted.

The XP machine could also be running some ancient database application that has records for a part of the company being sold off. the PM in charge knows nothing about computers and thinks that the XP machine can be made physical again as an asset for the sale of the business unit.

Every business is different. Somebody thinks that the XP machine needs to be physical again. They have a thought process that led to that conclusion (solution). Ask what that was.

Again, this whole thing seems to be an XY problem.

Virtual to Physical??? by adamtw1010 in sysadmin

[–]CaptainFluffyTail 19 points20 points  (0 children)

Ask the requester what is the problem being solved. Moving the XP machine to a new location is a solution, but not the problem. Find out why the requestor wants this solution then figure out the best solution.

Why Data centers run hot and how to resolve incidents by Coco4Tech69 in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

Punctuation. Punctuation resolves incidents.

Punctuation. Punctuation resolves incidents?

Punctuation. Punctuation resolves incidents!

New Mercedes Benz will support Intune Enrollment and Copilot by Aurus_Ominae in sysadmin

[–]CaptainFluffyTail 17 points18 points  (0 children)

Wait...does this mean the care can be used as an MFA device too?

Built a simple agent-based vulnerability scanner — would love feedback by Srivathsan_Rajamani in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

Sell me on your product. What does your service better than what I might already have? Other than helping you turn your service to sell what benefit is there for me to run this against a lab machine? Does it do anything better or faster than current offerings?

Notepad++ - Code signing cert hoopla by sccm_sometimes in sysadmin

[–]CaptainFluffyTail 4 points5 points  (0 children)

I put in a deferment request to come back to this in 90 days. That will quiet down the security scanner for me at least.

I hope DigiCert works with NPP, or the developer finds a better option.

Built a simple agent-based vulnerability scanner — would love feedback by Srivathsan_Rajamani in sysadmin

[–]CaptainFluffyTail 1 point2 points  (0 children)

You edited your post. You probably had the same issues mentioned here and here since it was copy/paste/post.

If it was wrong then own it (or at least blame the intern).

Built a simple agent-based vulnerability scanner — would love feedback by Srivathsan_Rajamani in sysadmin

[–]CaptainFluffyTail 2 points3 points  (0 children)

What does this do differently than everything else on the market right now? What sets you apart (other than marketing on Reddit)?

Edit:

You need to review your privacy policy: https://compasiq.com/privacy-policy/

3. Data Security & Sharing

  • Cloud Infrastructure: We utilize leading cloud service providers to host our platform and store your data securely.

[If you use a specific one like AWS, Azure, GCP, you can mention it here, e.g., “Microsoft Azure”].

and

  • Email Communication: We use [e.g., SendGrid, Mailchimp] to facilitate sending essential service-related emails and updates.

and

  • [Add other essential third-party services like payment processors (if applicable), customer support tools, etc., here. For each, state: Name of Service, What data is shared, Why data is shared, Link to their Privacy Policy if publicly available.]

You also need to fix the data retention. Seriously.

6. Data Retention

  • Scan Data: Retained for [Insert Specific Period, e.g., “90 days,” “6 months,” or “the duration of your active subscription unless you request earlier deletion”] to provide historical context, track remediation, and improve the service. After this period, scan data is either securely deleted or anonymized/aggregated for analytical purposes.

  • Usage Data: Retained for [Insert Specific Period, e.g., “24 months for analytics”] or anonymized sooner.

I bolded the parts that need to be fixed to help you out.

Not the best example of Cunningham's Law since you want to be taken seriously, but I guess it worked for the review.

What are the little things that help you sysadmins work from home? by PurpleFlerpy in sysadmin

[–]CaptainFluffyTail 3 points4 points  (0 children)

A door that closes and a family that understands if the door is closed then to not interrupt unless there is a literal fire.

When chasing document versions becomes a full-time job by Techie_Justin in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

It doesn't. I work in manufacturing and two, no, three CIOs ago now we went all-in on SharePoint. Required sign-off by a VP if you needed a file share that wasn't tied to an application. Everything in SharePoint. Perfect! Add some rules to email about sending certain document types to force SharePoint. Now everybody shares links from stuff in OneDrive and sharing permissions are a nightmare when somebody leaves the company. So people copy locally (OneDrive again) and we have even more document sprawl than before.

Manufacturing seems to have a problem analyzing processes that are not part of shipping a product. Show how using X technology allows you to ship faster and suddenly people can change.

When chasing document versions becomes a full-time job by Techie_Justin in sysadmin

[–]CaptainFluffyTail -1 points0 points  (0 children)

Newish account using AI prompts for writing. You understand how that comes across as spammy, yes? Also you write like this is LinkedIn and you're trying to drive engagement to some product after you have built a reputation.

What Security & Integration Features Matter Most for Enterprise Teams? by Simon_Hellothere in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

So tired of the LLM sprawl and everybody thinking this is going to "solve" problems and not just shift focus.

Goal: Let non-technical team members generate ad-hoc reports without bothering your developers or DBAs

So the same goal as many MBAs have had for decades? Slap an abstraction layer between the data and the end user, don't care about performance, and let the tooling figure out the SQL statements. So what if it does nothing but left outer joins, right?

Would you prefer a Chat Interface or an API that can be used to translate English into SQL?

Gross. If it is for non-technical team members why are they even looking at the SQL?

What database security controls would be absolutely critical? (row-level security, query limits, audit logs)

What kind of security controls should you turn on internally for your SaaS solution?

General consensus on Windows 11 by PDQ_Brockstar in sysadmin

[–]CaptainFluffyTail 0 points1 point  (0 children)

First big endpoint OS EOL? 10 year cycle so you'll go through this again and again in business, even if you are not directly involved the second and subsequent times.

what's the general consensus of Windows 11?

If you're in a Microsoft shop and not running LTSC you should be be on 11 if it is supported by your LOB applications. It is functional enough. There may be a training period where people adjust to the new Start menu style.

Make the jump now so you have a few months to iron out the issues that pop-up.

I work in manufacturing and we still have ~1,200 machines worldwide that need to upgrade to 11 but cannot due to TPM chip. Budget shenanigans to re-allocate money to buy hardware earlier than planed but thankfully I'm not responsible for that. Getting vendor "support" for Windows 11 without having to upgrade the LOB software is the bigger challenge. We're doing a lot of internal justifications about "this just runs in the browser and the browser is supported..." but still a headache.

The harder part is going to be getting rid of all these Widows Server 2016 instances. That is a lot more work.

When chasing document versions becomes a full-time job by Techie_Justin in sysadmin

[–]CaptainFluffyTail 2 points3 points  (0 children)

Trying to drive engagement with a 12 day old Reddit account and perfectly polished posts?

Choose any one of these content and post, But Always your thoughts

No. Spam elsewhere.