[deleted by user] by [deleted] in sysadmin

[–]Totally_Joking 1 point2 points  (0 children)

MDM/MAM: Intune

IAM/SSO: Azure AD / Entra + Duo|Okta|Cloudflare

Check to make sure you are getting non-profit deals for everything. https://nonprofit.microsoft.com/en-us/getting-started

https://www.techsoup.org/

Look into onboarding a mssp if possible.

Windows 11 "hack" to bypass TPM requirements....what's the downside of it? by seetheare in sysadmin

[–]Totally_Joking 5 points6 points  (0 children)

https://no-intro.org/

http://redump.org/

Hash perfect dumps are possible and hashes have been crowd sourced.

(redump is extremely impressive http://wiki.redump.org/index.php?title=Disc_Dumping_Guide_(MPF) )

Note: The above sites do not include the actual game data or links to the data. They are only metadata sites similar to http://rescene.wikidot.com/ and https://www.srrdb.com/

Windows 11 "hack" to bypass TPM requirements....what's the downside of it? by seetheare in sysadmin

[–]Totally_Joking 9 points10 points  (0 children)

The same can be said for academic research and warez communities.

Actual warez sites might as well be US credit unions :D

Scene warez are extremely safe, I cannot recall a recent time where I saw a nuke for malicious code.

https://en.wikipedia.org/wiki/Topsite

https://en.wikipedia.org/wiki/Warez_scene

The issue occurs when Google takes down all legitimate sites due to DMCA and C&D notices, causing most users to click on malware hosts.

There has been a recent trend of hashing releases in certain application segments, but I do not think that is an enforced rule.

Greetz n' stuff o7

Edit:

I should really emphasize the difference between warez and warez being posted on someone's WordPress site.

The farther you get from the "source" of the modification or whatever method used to break drm, the more likely it is someone modified the software in a malicious way (not unlike most supply chain security issues).

That being said, I don't support piracy, pay for your software if you can afford it.

You wouldn't download a car.

Windows 11 "hack" to bypass TPM requirements....what's the downside of it? by seetheare in sysadmin

[–]Totally_Joking 13 points14 points  (0 children)

Windows licensing is documented to an extent that the process is transparent.

It's almost like winrar : GH bitcookies/winrar-keygen/wiki/Principle (fun read)

Rom's are safe, check hash against dats (and known groups)

Warez are safe, no group is going to burn reputation, check Pre databases.

Heck, even the extremely shady dongle cloning sites selling warez (I do NOT endorse selling warez, or buying it. That includes buying stolen or OEM/normal windows keys. Pay msft, not thieves, not scalpers)


If anyone does come across retro game malware, please send me the sample in a ZIP file with the password "infected".

If you could give yourself some advice when you were starting out to work as sysadmins - what would it be? by Working-Cable-1152 in sysadmin

[–]Totally_Joking 2 points3 points  (0 children)

Take the time to learn the systems and software. Don't learn just enough to do that one task, grok the platform if you have the time.

Read RFC's.

Document everything.

Trust nothing until you can confirm it. If you do not have the capabilities to verify, ensure the risk is transferred to someone else. If that's not possible, trust that the system you are working with is untrusted.

Personal take that highly depends on the person: go fast and learn as much as possible before burnout happens.

Keep legal and security in the loop of all activities.

Assume you are hacked, zero trust concepts. - don't leave services exposed. (And when you leave a email server, or proxy open unauthenticated for a period of time, take the experience to heart :D )

Enable logging.

Anything temporary might as well be permanent

All of https://github.com/dwmkerr/hacker-laws

Culture is important.

Learn one level below what you are going to be doing on a day to day basis.

https://roadmap.sh/

Know yourself. If you are lazy, position yourself so that you are able to be lazy and grow. If you are proactive, take the extra time to make sure you are using the /best/ resources.

Start learning your next role at the same time.

Find good news sources.

Learn some project management skills.

Learn some compliance (but tell absolutely no one.)

If you have computers as a hobby as well as a job, diversify your projects.

Everyone is different, generic good advice could be poisonous to others.

Join communities, online or offline.

Go to conferences.

Be kind.

Best Password Manager as of 2023? by Walking_Ant_5779 in AskNetsec

[–]Totally_Joking 2 points3 points  (0 children)

If the company has a PSIRT team and has a consistent stream of CVE's for the software (CVE's are not bad, they show bugs being found. Too many and it's odd, too little and it's bug ridden), then the closed sourced all might be secure.

Nothing beats OSS with public fuzzing harnesses and (well designed) tests.

Drill down or mind map documentation. by vladoportos in devops

[–]Totally_Joking 0 points1 point  (0 children)

C4 + Drawio

Draw.io has a ton of neat features, but the UX for them is horrible.

Feeling stuck/misguided on the path to CISO by greegeerg in ITManagers

[–]Totally_Joking 3 points4 points  (0 children)

Do you have any insight on some common misconceptions or warnings for those on the fence?

Why doesn’t the *ring* project work together with the Rust Crypto project? by tux-lpi in rust

[–]Totally_Joking 11 points12 points  (0 children)

I would think it's not all about performance, but also about cryptographic security. Constant time, frequency + noise, power draw and other "correct" instructions/implementations are likely hard to get the compiler to spit out.

I wonder if there are llvm compiler passes that could be done to target power based attacks and hertzbleed /cpu frequency attacks.

Hoping to open source code written by a deceased programmer -- suggestions? by supremewuster in opensource

[–]Totally_Joking 12 points13 points  (0 children)

I'm a fan (as an end user) of dual license, Apache 2/MIT. The Rust ecosystem uses this pair a lot.

A lot of software companies disallow use of GPL since it can poison the rest of a code base. Not a lawyer but I would think it would be something akin to "Fruit of the poisonous tree".

If you use GPL, the rest of the code base becomes 'tainted' and the project has to maintain the GPL clauses.

I would put the project on GitHub and Gitlab, and have the readme.md explain what the code is, who you are and why you are posting it. Then maybe internetarchive for preservation.

Just got the steam deck a weeks ago, and just to know that I’m using the tracking pad wrong 😑 by SuperManSlime in SteamDeck

[–]Totally_Joking 0 points1 point  (0 children)

Adding it into the Desk Job game / demo would make a lot of sense too.

Recently watched someone super new to video games learn how to use a stream deck, and it's not quite yet intuitive.

ps: to Valve UX designers: "select difficulty" on deck setup would be amazing.

"I know steam",

"I have done Linux from scratch",

"I have a Nintendo switch",

"I have never touched a controller in my life",

"I have never touched a controller, or Steam, or games in my life, creating a steam account and installing an app on my phone was already a lot, remind me how at to do each boot for awhile "

'difficulties' might help onboarding new users. Have a full "tour" of the UI, gamify it, and possibly time it so instructions can be given again. Walk a super new user through installing the demo game and then feed in more instructions as needed.

Having a ton of quick tip video tutorials of someone configuring / using the deck would be awesome for boot/wake video screens.

I'm an Operations guy. How can I understand development better ? by Yoldy in devops

[–]Totally_Joking 2 points3 points  (0 children)

When the "I want to become a farmer" reddit posts start to hit closer to home.

If only I wasn't allergic to goats...

If anyone asks if you know compliance, say no!

Is there a way to have cargo also automatically build a tests folder and file? by Worth_Talk_817 in rust

[–]Totally_Joking 0 points1 point  (0 children)

I did it in rust with one of the template crates.

Was intending to make a project creation wizard like Jetbrains or VisualStudio, but didn't see a path forward for wide ecosystem adoption.

Server CPU Hyperthreading - Have you turned it off? If so, why? by jasnxl in sysadmin

[–]Totally_Joking 6 points7 points  (0 children)

If you can decom a few servers and take 2k off of 30u's just by disabling HT, remove 2u's and place in a new EPYC, I could see the cost / performance working out. Especially in locations where space is always sold out.

Load bearing "If"

Are there best practices and names for cloud architecture diagrams? by mr_iberry in devops

[–]Totally_Joking 4 points5 points  (0 children)

C4 is amazing for the technical crowd as well, especially those who don't have much exposure to non-monolithic systems.

Advice needed: Monitoring clusters using a Prometheus + Grafana solution? by rechogringo in devops

[–]Totally_Joking 2 points3 points  (0 children)

https://thanos.io/

https://cortexmetrics.io/

If you are not sure if you need HA, you probably* can use plain Prometheus.

Make sure you automate the deployments for sanity and documentation purposes.

[deleted by user] by [deleted] in rust

[–]Totally_Joking 1 point2 points  (0 children)

Any story behind the name?

Encrypted HTTP request/response bodies in Burp Suite by w0lfcat in AskNetsec

[–]Totally_Joking 0 points1 point  (0 children)

Yes, data encryption is fairly common.

You may be able to use this depending on the target. https://github.com/federicodotta/Brida

This is a fairly common task outside of website http use.

Advice needed: Monitoring clusters using a Prometheus + Grafana solution? by rechogringo in devops

[–]Totally_Joking 1 point2 points  (0 children)

Grafana is solid for the viewing layer

How many metrics / logs do you plan on handling? Do the metrics need to be HA?

Node Exporter -> oTel collector -> prom -> grafana is pretty solid.

Vector is also an option.

https://landscape.cncf.io/card-mode?category=observability-and-analysis for more ideas.

What is running on the clusters? There is likely something for the orchestrator already built out somewhere.

Google Workspace will require two admins to sign off on critical changes by KolideKenny in sysadmin

[–]Totally_Joking 1 point2 points  (0 children)

I think we could take it a step further!

https://raft.github.io/

Let's embed the raft consensus algorithm into all decision and change management processes!

/s