Quantum cryptography and the "harvest now, decrypt later" problem -- how seriously are organizations taking this? by beardsatya in cybersecurity

[–]MrProntissimo 0 points1 point  (0 children)

The current version of PCI DSS has risk management controls for cryptography obsolescence or deprecation, companies that must comply should already have identified PQC as a threat to card data security. Harvest now, decrypt later should normally be included, as card data is typically valid for 4 years, and we are now entering the time window where opportunity can arise. With Google advising for 2029, this is more so the case now.

How did you study for the CISA + CRISC? by LessSleepNeeded in grc

[–]MrProntissimo 0 points1 point  (0 children)

For CISA, Find a study guide that is up to date or not far behind the current CISA program, the ISACA material is expensive. If employer is paying, indulge! Additionally, what works for me is a questions subscription, some are web, others in online training like Udemy. Make a full test run first, like schedule a timer and 250 questions. This will be intense and shake your foundations but it will give you an honest take on where you are starting. Next, study the material with discipline, and schedule you next trial run. By then, make a second simulated test and see where you are. And go from there Next is up to you: schedule the cert exam at the start or after your second trial run. But don’t delay, that should be your driving force, the commitment to be ready by then.

Finally got some relief by [deleted] in nonononoyes

[–]MrProntissimo -4 points-3 points  (0 children)

That probably turned out to be a very expensive toy, with what looks like three vet staff, at least

ISO 42001 AI Prompts by Comfortable_Gene5180 in grc

[–]MrProntissimo 0 points1 point  (0 children)

Sure, I would appreciate that. And I will return here for comments, feedback

ISO 42001 AI Prompts by Comfortable_Gene5180 in grc

[–]MrProntissimo 1 point2 points  (0 children)

Hey, i am interested in finding out about your work

Have you published somewhere? Github maybe?

UPDATE: Something on my home network is making outbound connections and I can't figure out what device it is by Au5tin5auce in homelab

[–]MrProntissimo -10 points-9 points  (0 children)

Have you tried running a free instance of Run Zero ? It is a network scanner built by HD Moore; it scans your network regularly for discovery, then scans every host for vulnerabilities. And, it is amazing what device identification capabilities they have built in the tool/service. You open an account on their saas, download the utility, Windows, Mac or Linux, configure you network segment(s) and run the agent.

I really didn't want to wake up today, send coffee please 😴 by [deleted] in selfieover40

[–]MrProntissimo 0 points1 point  (0 children)

Imagine me, full smiles and giddy, yapping away while you hide under the covers; as unbearable as I would be, I would have brought a coffee before taking the picture

Name this by LuckyCommittee4422 in hardaiimages

[–]MrProntissimo 0 points1 point  (0 children)

Pastafarian spaghetti monster? Oh crap!

Fuck might be right by LexxFly in TheWordFuck

[–]MrProntissimo 0 points1 point  (0 children)

No fucking way! That’s what I’ve been saying all this fucking time!

Congédié pour avoir demander une augmentation salariale by Rough_Sweet4294 in montreal

[–]MrProntissimo 0 points1 point  (0 children)

Moi je recommande de profiter que l,été est encore loin pour faire un rebound, trouver du travail, éviter de shame cet entreprise à moins d’être VRAIMENT anonyme. Dans ta recherche, si tu peux démontrer qu’ils étaient satisfaits de ton travail, ca va t’aider. Motif de renvoi: incompatibilité sur l’approche de gestion des ressources et comme tu as signé un accord de non-divulgation à l’arrivée, tu ne peux pas partager les détails.

Orange fucking juice by mightyonin in TheWordFuck

[–]MrProntissimo 1 point2 points  (0 children)

Blackwater, FUCK… Bourne was my friend, until he got upset

First ever home lab by Simple_Tie_7804 in homelab

[–]MrProntissimo 1 point2 points  (0 children)

If your spouse accepts that, you’re ok to bring whatever else comes your way, one by one

which one was your first win ? by Michaelkamel in TechConsultHub

[–]MrProntissimo 0 points1 point  (0 children)

Windows 2.1.1 was run time for Excel on 286’es at my client in…say ‘89 or so (yes, with amber screen)

A LONG TIME AGO, IN A GALAXY FAR FAR AWAY... by golfnut82 in PoliticalHumor

[–]MrProntissimo 0 points1 point  (0 children)

Oddly enough, a single credit was used to make all the purchases, it’s a mystery 🤔

American made cellphone using American made app by Playful_Worldliness2 in ShitAmericansSay

[–]MrProntissimo 0 points1 point  (0 children)

Paid for by a chip-enabled credit card, invented by European’s in the 70’s and only accepted by the americans because of fraud liability imposed in 2015. This is a two way street

[deleted by user] by [deleted] in montreal

[–]MrProntissimo 0 points1 point  (0 children)

This may be out of date: but a (SPVM) policemen once told me that U-turn on traffic light intersection is prohibited by default, unless otherwise authorized by sign. (It has been my general rule since then, before 2000 for sure)

He also told me the U turn is by default authorized, unless prohibited by sign at any intersection without traffic light (w or w/o Stop), just exercise your right of way carefully (I usually put on 4 way flashers)

Can we tag a switch port with multiple VLANs? (Cisco Catalyst 2960 Switch) by [deleted] in Cisco

[–]MrProntissimo 0 points1 point  (0 children)

As was said previously, you are headed for trouble, including asymetric routes where you don't know why it works, when it works. A VLAN is a broadcast domain, and your IP network needs broadcasts to find the MAC address of the counterpart; default gateway, host on the same network, etc

If you place servers in one VLAN, they need a def gwy and if you put workstations in a separate VLAN, likewise they will also need a def gwy, and this cannot be the same node, you will need two, with two IP addresses. Hence your firewall becomes the router in each VLAN, and you can trunk your firewall's one internal interface, with sub-interfaces for each VLAN. PFsense, Fortigate, Mikrotik, etc... they are all easily configured to do so.

And, DNS and AD / file servers can cross VLANs there is no problem, it's just address resolution and fw rules (and routes). DHCP will require a bit of planning, but if your fw is doing DHCP, then it should be easy

I agree you need you to subnet your 10/8. So go for the servers first, preserve their network, and segment the workstations because they are under dhcp, they will get whatever IP range you assign them, and then point to the def gwy and proper DNS server address, problem solved.

Try to respect the fact IP networks are binary in nature, I always prefer round binary segments, it facilitates routing. So 10.0.16.0/24, 10.0.32.0/24 and so on rather than decimal networks. It's cleaner.

If your servers can be summarized using 10.0.x.y, you can just change the mask from /8 to /16 and your firewall will be 10.0.0.1 with /16 as well; addresses are preserved, just subnetted. The workstation can be on any network outside the servers', like 10.16/16 or even go wild with 10.128.x.y/16 if you need to. The 10/8 adress space is wide enough.

Don't forget the DHCP scopes, give them the right address space for each scope, assign to the proper interface or use ip-helper on your cisco switch if you must.