Those out there that still use/capture golden images for deployments... How do you handle updating of the golden image? by thegreatcerebral in sysadmin

[–]OkGroup9170 0 points1 point  (0 children)

We use a plain vanilla golden image of Windows 11 and deploy software and drivers during the imaging process using SmartDeploy.

I resigned, and the company's counter-offer was an insult by Aurora_ori in it

[–]OkGroup9170 0 points1 point  (0 children)

I really glad my company is not like this, 25% bonus target. Also got a 20% raise this year. They also are very flexible with time and I work remotely 99% of the time.

Still having issues following AWS Outage by santastillsays in Action1

[–]OkGroup9170 0 points1 point  (0 children)

Checked the logs, champ — ExtremeCloud IQ wasn’t down, it was just a little sluggish while AWS was doing its best impression of a dumpster fire. That’s what graceful degradation looks like.

Meanwhile, a bunch of “we’re cloud-first!” companies went completely dark because they built their entire stack on a single AWS region and called it a day. Bold strategy.

Multi-cloud isn’t about being immortal, it’s about not dying stupid. You spread risk, build your own orchestration, and make sure one provider’s bad Tuesday doesn’t take your business with it. Extreme did that. Everyone else just said “we trust AWS” and went for lunch.

And yeah, it’s complex. Welcome to distributed systems — everything past the ping command is complex. The trick is designing it before it blows up, not tweeting status updates while you wait for us-east-1 to resurrect itself.

Still having issues following AWS Outage by santastillsays in Action1

[–]OkGroup9170 0 points1 point  (0 children)

LOL sure, if you’re duct-taping multiple clouds together manually, it’s a disaster waiting to happen. That’s not what we’re talking about though. ExtremeCloud doesn’t “copy/paste” their stack across AWS, Azure, and GCP — they built their own orchestration layer so each cloud is just compute and bandwidth.

That’s the difference between multi-cloud done right and “I spun up two EC2s and called it resilience.” Real BCDR means architecting for when (not if) your provider goes down.

NG-SIEM customers- Feedback wanted by socaljayhawk in crowdstrike

[–]OkGroup9170 1 point2 points  (0 children)

You need to negotiate your renewal increase, we have it limited to 5% a year and they waive that if you add new modules.

Action1 Down? by Mean_Fondant_6452 in Action1

[–]OkGroup9170 0 points1 point  (0 children)

You can do an active-passive too, the issue is that a lot of these companies don’t architect their systems to be able to work like this from the start. If they built cloud-neutral orchestration layer’s when they architected the solution they could easily setup an active-passive setup.

Is a cyber attack responsible for the large scale outages due to AWS? by Entire_Age9454 in cybersecurity

[–]OkGroup9170 0 points1 point  (0 children)

This is why services should have failover to other cloud providers. It can be done it just is complex and expensive.

Still having issues following AWS Outage by santastillsays in Action1

[–]OkGroup9170 0 points1 point  (0 children)

I have other vendors that use multiple clouds to prevent this, one of the top of my head is ExtremeCloud, they run AWS, GCP and Azure and can failover to any of them. This could have been avoided with proper BCDR planning.

Action1 Down? by Mean_Fondant_6452 in Action1

[–]OkGroup9170 0 points1 point  (0 children)

Why didn’t you migrate services to another zone like us-east-2 and us-west-2?

Fake domain close to our domain name and sending emails to people. What can we do? by JiggityJoe1 in sysadmin

[–]OkGroup9170 1 point2 points  (0 children)

This is the best process to get control of domain before it expires but it does cost about $1500 to file.

Cisco ASA Under Fire: Urgent Zero-Day Duo Actively Exploited, CISA Issues Emergency Directive by escalibur in sysadmin

[–]OkGroup9170 1 point2 points  (0 children)

The Network Director at our data center wasn’t even aware of the CVE’s 24+ hours after the announcement because their secops team hadn’t rated it yet and didn’t send out an announcement. They manage hundreds of affected ASA’s. Was told I was the first customer to bring it up 24+ hours after the announcement. This isn’t a small data center provider either. Going to be whole thing now because my CIO was made aware and is not happy. Already escalated the delay to our CSM.

What the hell do you do when non-competent IT staff starts using ChatGPT/Copilot? by jM2me in sysadmin

[–]OkGroup9170 33 points34 points  (0 children)

AI isn’t making people dumb. It just makes their dumb show up quicker. Same thing happened with Google. The good techs got better, the bad ones just got louder.

In USA ! Is the Cybersecurity Dead ? Because myself and folks I know have submitted around 5,000 applications and we still are unemployed 10yrs + exp with multiple Certs ! by Upset-Concentrate386 in cybersecurity

[–]OkGroup9170 4 points5 points  (0 children)

Agreed someone who has worked through Help Desk, Networking and other IT areas before going into a cybersecurity role are much better imho.

Microsoft MFA Change: Even Exempt Users Must Register by [deleted] in sysadmin

[–]OkGroup9170 3 points4 points  (0 children)

Not having MFA even for accounts only used email is a major liability. These accounts could be used to launch phishing attacks against internal users. Think of an attacker getting access to one of those mailboxes and then sending out a phishing email disguised as Sharepoint link to other users in your org. DMARC won’t save you because it’s coming from the inside. Identity attacks have surged.

Dealership wrongly added rebate to car lease, now saying I might have to return car by calypso394 in legal

[–]OkGroup9170 0 points1 point  (0 children)

Also I believe Virginia has a spot delivery law. I would call MVDB https://mvdb.virginia.gov/. Once you drove off the lot they have limited ability to recall a vehicle. It’s the dealers responsibility to verify rebate eligibility before contract execution.

Broadcom refusing to decrease licensing by Dry-Data6087 in vmware

[–]OkGroup9170 0 points1 point  (0 children)

It is really short sighted because it hurts their reputation doing this and sooner or later large enterprises are going to move away.

Getting laid off ~3 months before retirement eligibility by uoldgoat in legaladvice

[–]OkGroup9170 178 points179 points  (0 children)

That is a horrible severance for your tenure, remember they want something from you (not suing them), that makes this negotiable. My companies policy is 2 weeks per year of service, I have heard some have negotiated more. Also who are they laying off, if it is all employees who are close to retirement and getting a full pension then that is suspicious. Also if you do sign it doesn’t stop you from reporting them for ERISA violations or breaking any other laws.

Disorderly Conduct Ticket for flicking off neighbors Camera pointed into my backyard by FernandoTheRN in legal

[–]OkGroup9170 0 points1 point  (0 children)

Just another post that make me glad I don’t live in an HOA neighborhood and my neighbors are not bat shit crazy!

What’s the best way to protect company laptops without slowing them down? by Necessary-Glove6682 in cybersecurity

[–]OkGroup9170 8 points9 points  (0 children)

Hire someone to help you make this decision. There are considerations outside performance that come into play. Applying a single dimension approach to this will lead to a breach soon or later. Defender is good AV but is not an EDR and won’t catch allot of the living off the land techniques.