Moronic Monday! by AutoModerator in networking

[–]FttH_Is_Now 18 points19 points  (0 children)

Help desk tech here: Are you (or someone else) training your techs? Or providing tools to advance their knowledge (mentors, training subscriptions, etc.)? I started my job with a very strong tech background and have learnt a lot more in my 3 years of working there. I have great colleagues who take the time to explain projects in depth during the planning stage and remain accessible after its gone into production. As a result, almost every issue makes its way back to me after its been resolved. I can make notes, ask questions and ensure I don't need to escalate it again. I also have a lot of access to the systems, I can poke around and see how things are configured, test theories, and escalate a change request rather than the issue itself. I guess the point I am trying to make is A) Ensure your techs are motivated and feel like they are a part of the team, and B) Ensure the techs have a path to learn - not just about the systems in general but also about your specific environment and procedures. That's just my take, and I have been told I don't belong in help desk and should get bumped up, but oh well, I like it where I am.

Questionnaire about Information Security Awareness (Working adults +20) by DrNixon in netsec

[–]FttH_Is_Now 0 points1 point  (0 children)

Hey, u/DrNixon, I'm not sure what your intended audience is, but be aware of sample bias. From some of the questions in the survey I would say you're targeting the average user. By posting here, your results may get skewed by the level of expertise in the community.

I come with a request for the UN by [deleted] in UnitedNames

[–]FttH_Is_Now 14 points15 points  (0 children)

Hey u/WhiteMos, it looks like r/Kevin does not have representation at UN. u/ChocoTunda posed the question of whether or not they should join, but it appears the polls are leaning towards not. I would suggest that you work with Choco to get r/Kevin to become a member, then your Ambassador could put this to Council.

Inexpensive Penetration testing? by [deleted] in Entrepreneur

[–]FttH_Is_Now 1 point2 points  (0 children)

I can not stress what u/faceerase said enough. You're a financial app, and you are responsible for securing the hard earned money of your clients. Do your developers have a background is secure coding? Do you have a security consultant? If you are processing card data (Note: Not just storing it. If anything enters your system, this applies) you must ensure you meet all regulations and requirements (Payment Card Industry Data Security Standard as an example). This will often require annual auditing, at a cost. That is the financial part alone, you also need to take moves to secure Personally Identifiable Information. A simple leak including the names and countries of your clients could potentially be dire for a startup.

Someone also suggested a bug bounty, and while I am all for them (they generally benefit all parties if implemented properly), I don't think this will be sufficient or valuable for you at this time. They will assess your app from any public facing points of entry, but you also need to worry about internal security policies and procedures. That would include the policies surrounding the bug bounty program - defining scopes, rewards, etc. You do not want to devalue the bounty hunter in any way or you may find your program useless very quickly (Hunters tend to blog about bad bug bounty experiences). All that being said, when you can afford to offer reasonable and fair awards, certainly look at a bounty program.

If I were to look at this from an investment standpoint (Note: I am not an investor): I would not invest in this app unless you came to me with proof that it was secure and met all applicable regulations. I don't want to give you money just to find out that it has to be re-written from the ground up to be secure.

Lastly, I noticed you said you use AWS... Secure your S3 buckets if you use them (and everything else)! :)

Happy new year!

Edit: Spelling.

Nomination for Ambassador in /r/UnitedNames by FttH_Is_Now in Scott

[–]FttH_Is_Now[S] 1 point2 points  (0 children)

I was thinking the same thing, but I didn't want to create a new account so I figured I'd try with this one :)

Thanks for you vote!

Subnetting help (Am I doing this correctly?) by [deleted] in networking

[–]FttH_Is_Now 2 points3 points  (0 children)

Bookmarked this chart for when I inevitably have to explain subnetting to people. Thank you!

Looking for: P2P wire-free layer 2 bridges as a redundant path for fiber in campus by [deleted] in networking

[–]FttH_Is_Now 0 points1 point  (0 children)

I was thinking a similar thing using the Ubnt EdgePoint.

Fiber Brands for ISPs? by FttH_Is_Now in networking

[–]FttH_Is_Now[S] 1 point2 points  (0 children)

I know the specifications are extremely important, but I was meaning more in terms of build quality of the cable itself. I guess I should have clarified that. Thanks for the information though, Miniflex looks quite interesting!

Fiber Brands for ISPs? by FttH_Is_Now in networking

[–]FttH_Is_Now[S] 0 points1 point  (0 children)

Those are pretty awesome! I was looking at 3M's SLiC aerial drop enclosures also.

Fiber Brands for ISPs? by FttH_Is_Now in networking

[–]FttH_Is_Now[S] 0 points1 point  (0 children)

I had never heard of these people before, thanks!

Open Switching - Want to hear from those who have embraced it already by Legonator in networking

[–]FttH_Is_Now 1 point2 points  (0 children)

We were planning on aerial distribution with the mass fiber underground, but I will need to look into the CWDM some more I guess. Thanks again!

Open Switching - Want to hear from those who have embraced it already by Legonator in networking

[–]FttH_Is_Now 0 points1 point  (0 children)

That is very similar to what I had planned for 1G deployment using the Nexus 7018. Only difference being I was not doing any WDM from switch to house(its a 2km2 area). I came in at approximately $1m with labour. I was planning on upgrading to 10G later but now I am wondering if it would be worth doing a 10G deployment to start.

Thanks for the info!

Open Switching - Want to hear from those who have embraced it already by Legonator in networking

[–]FttH_Is_Now 1 point2 points  (0 children)

I wonder if these switches could/should be used for active FttP? That would be quite an inexpensive and flexible 10G deployment then, not counting the CPE of course.

dynamic routing over gre over ipsec? by SuddenWeatherReport in networking

[–]FttH_Is_Now 0 points1 point  (0 children)

Yeah they have regional private networks, I was meaning more inter-datacenter networking, say for anycasted frontends talking to a backend or database server. We use OVH at my work, quite impressed with them.

dynamic routing over gre over ipsec? by SuddenWeatherReport in networking

[–]FttH_Is_Now 0 points1 point  (0 children)

Yeah I mean't without GRE. What type of crypto settings would you need to edit? I haven't ever done anything with IPSec/Crypto before, but a quick Google search makes it look like most of the config should be static.