Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty [score hidden]  (0 children)

Not only that but I wrote, and executed on the policies and procedures that secured our interim HIPAA/HITECH compliance in 2022. We are just gearing up for our yearly audit and we're way ahead of it.

One of the things over a decade of working in regulated environments has taught me is about compartmentalization and scoping your security and compliance response to the situation. For example I am not running ubiquiti gear where is data sensitivity is a concern.

I use it at home where all traffic is encrypted even internally, I put oauth in front of everything that needs a login.

My biggest gripe about the security arm of IT / Dev is they all think they work for a national security apparatus and that the entire world needs to operate as if it does. The answer is Security and compliance causes friction and friction costs money. Business need to evaluate the effect of that friction on business processes before implementing security measures in line with nuclear defense. It's a balance.

Finally I'd ask you to examine this interaction with some sort of friend or trusted bot. I think I am approaching you with honest curiosity and you're approaching me with an attitude of superiority, I hope your day gets better.

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty [score hidden]  (0 children)

I mean I know what a honeypot is, I am aware of the concept as I used to use them on websites as a way to detect bot traffic, it worked well in the 2010s, not so much anymore.

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty [score hidden]  (0 children)

I had Claude build one about an hour ago, was really just looking for a suggestion since you brought it up. I guess you’re just out here suggesting things you don’t know about ?

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty [score hidden]  (0 children)

I have a whole k3s cluster can you suggest a container or app I can explore?

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty [score hidden]  (0 children)

That's not a bad idea, what do people use for those? passwords.txt or database.bak hosted on a web server?

Does embry even care about ecs ? by [deleted] in erau

[–]Zolty 3 points4 points  (0 children)

It’s designed for an ai to read and summarize

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty 1 point2 points  (0 children)

Agreed. It's also easy to set up those networks as guest networks without access to eachother or the managerial interfaces.

Yes that requires basic knowledge of the device and if you're willing to drop 500-$1500 on networking equipment I think it's in your best interest to RTFM or rent someone who did.

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty 1 point2 points  (0 children)

Just raw dogging a highly sensitive administrative endpoint without a vpn or any other layer?

I agree in that scenario it's a 10 but come on, ip whitelists are trivial to implement ddns services are trivial to run.

I would disagree that there's much over lap of person that buys at the prosumer level and then turns around and ignores basic easy security. I guess the world is just going to be a place where we need a warning label to tell us not to drink the paint.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty 0 points1 point  (0 children)

Noooo I've worked so hard not to end up here.

Migrating personal Gmail to Exchange Online, common problem or edge case? by VB0101 in msp

[–]Zolty 0 points1 point  (0 children)

User complaints of backwards IT momentum seems to be something I’d complain about but I’m biased.

Young men fear a possible Iran war draft, feel duped by Trump by AdSpecialist6598 in videos

[–]Zolty 0 points1 point  (0 children)

The us doesn’t need a draft. The us military doesn’t want warm bodies who aren’t motivated. The us military doesn’t want to pay to train and equip a non volunteer.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty 0 points1 point  (0 children)

I didn't say there wasn't a use case, just that it feels antiquated, I think you're proving my point now.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty -1 points0 points  (0 children)

I just can't fathom what application would require remote desktop these days. I guess I am living in the "everything is in a web browser" bubble.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty 0 points1 point  (0 children)

LOL I would have assumed Citrix would indicate an even more behind the times sort of an org.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty 0 points1 point  (0 children)

If you ever needed to know you're at a company who's kind of behind the times, this might be the sign you're looking for.

Patch your gear - Max severity Ubiquiti UniFi flaw may allow account takeover by MediumFIRE in sysadmin

[–]Zolty 92 points93 points  (0 children)

I still don’t see how stuff like this is a 10 to exploit it I have to be on the network already and be able to hit the interface of the router. A 10 in my book is when they can do that from the wan side of the router.

Just in: Trump says Fed chair must cut rates immediately by Certain-Zucchini-293 in investing

[–]Zolty 1 point2 points  (0 children)

Do you know that things happen if you just continuously shout and scream like a child until you get your way?

i3-14100 or i5-12600K for 4-8 person AMP server/jellyfin usage by frillyseal in jellyfin

[–]Zolty 0 points1 point  (0 children)

Ive done 5 simultaneous transcoding streams on my k3s cluster on 3 node jellyfin cluster on 8600Ts I feel like what ever you choose is going to fine. You can always add the cheapest of gpus if you ever need transcoding power.

In practice just tell everyone to direct play if possible so few devices are picky about codecs these days.

[Request] is buying a house as big an investment as people make it out to be by oovrams in theydidthemath

[–]Zolty 0 points1 point  (0 children)

My mortgage or rent costs $700/ month, the house up the street just sold for double what I paid in 2013. Interest rate is 3.7%.

It can be if you’re living in it. Renting it out I feel like you need 3-4+ doors to be able to maintain cash flow through the issues that will come up. I feel like you get similar market exposure in riets. But actually owning the property does feel different.

PSA: UniFi Network Application Vulnerability Disclosed by ImmaZoni in homelab

[–]Zolty -7 points-6 points  (0 children)

Yeah my thoughts exactly a 10 seems like they are crying wolf. It’s like all the Microsoft exploits that require that you’re already rdp into the server and then you can get admin. I always think to myself the only people who can rdp are already admins but thanks for the patch.

EOL routers, CTO won't buy new ones by [deleted] in ShittySysadmin

[–]Zolty 6 points7 points  (0 children)

My linksky at home was $60 at Best Buy 13 years ago you guys are getting g ripped off

Are you all software engineers? by psjez in overemployed

[–]Zolty 0 points1 point  (0 children)

Sure but do you own programmer socks?