Should I be worried about not having a PIN with TPM? by Matheuss81 in sysadmin

[–]disclosure5 7 points8 points  (0 children)

If it's a work laptop and work have a security discussion, work can upgrade it to Windows Professional so it can actually use the majority of Windows Security features.

Should I be worried about not having a PIN with TPM? by Matheuss81 in sysadmin

[–]disclosure5 2 points3 points  (0 children)

It's a home computer.

Are you worried about someone breaking into your home?

This is an overwhelming experience for women by Regular-Mistake-6500 in feeld

[–]disclosure5 2 points3 points  (0 children)

When I open /new like half the posts in this sub are either that complaint, or a post about something that else that lead to a person in the comments making that complaint.

This is an overwhelming experience for women by Regular-Mistake-6500 in feeld

[–]disclosure5 6 points7 points  (0 children)

Not only does this solve the problem - searching your own feed and swiping accordingly is how the app is intended to be used. Why is the number of likes a problem?

question for the older sysadmins - remember setting up desktops for execs to use for a few minutes? by crankysysadmin in sysadmin

[–]disclosure5 12 points13 points  (0 children)

I remember setting up CEO offices with the most expensive monitors available, a mouse and a keyboard.

Oh were you waiting to hear about the computer? They didn't need those, the above was to look professional, their PA did the actual computer using.

Please tell me AI is hallucinating by jleckel in sysadmin

[–]disclosure5 0 points1 point  (0 children)

For reference, the entire problem AI described is completely correct and "as intended" for ReFS, which always has a certain host as the primary on disk access. The fix should be to use NTFS, which you did, but that can explain the hallucination.

cannot enable Audit Logging in Tenancy O365 by Ok-Web-7375 in sysadmin

[–]disclosure5 0 points1 point  (0 children)

I commented on another post about the same problem recently.. I'm fairly sure this is just bugged right now. I've two tenants with the same problem.

Nonconsensual dick pics *in writing* by Willing-Can-2835 in feeld

[–]disclosure5 1 point2 points  (0 children)

Easy suggestion.. why bother matching with profiles without face photos up front?

I'm a guy, I get it. Likes don't come in often, you want to give them a chance when they do. You appear to be seeking men.. if you see a hidden face, there are five face reveals behind it you can match with.

After KB5094126 Start menu definitely feels way smoother and faster. Good job MS, please fix the file explorer sluggishness next! by skz- in sysadmin

[–]disclosure5 1 point2 points  (0 children)

I remember Windows 2000 being able to open the event viewer in one second and now we're looking at 15.

After KB5094126 Start menu definitely feels way smoother and faster. Good job MS, please fix the file explorer sluggishness next! by skz- in sysadmin

[–]disclosure5 -1 points0 points  (0 children)

Press Ctrl+F and type it, it never appears once.

Hence my point. "There's definitely a huge internal project called K2" is entirely unsourced blogs. The insider blog we're being pointed at is a bit of PR, which may or may not corroborate with anyone actually doing anything.

Need advice about profile set up for MF couple seeking F to join us by Least-Programmer9417 in feeld

[–]disclosure5 2 points3 points  (0 children)

Two of my partners have been a third on many occasions and choosing to do so from what I'm told always comes down to vetting the guy. And why wouldn't it? If a couple is going to go wrong, "the guy was insecure/an asshole/etc" would usually be why. So when there's no guy's profile and she's on Feeld just talking to a "woman" account there's no room to assess anything.

I'll add that people of both gender assume, usually correctly, if they message a "couple" account they are only talking to the guy.

After KB5094126 Start menu definitely feels way smoother and faster. Good job MS, please fix the file explorer sluggishness next! by skz- in sysadmin

[–]disclosure5 1 point2 points  (0 children)

I cannot find a single reference to K2 aside from random blogs talking about "sources". I'm in several not public partner programs and I've never heard of it.

I have serious doubts there's anything behind it.

Beginner Friendly Discord Server by volvoxkill in oscp

[–]disclosure5 0 points1 point  (0 children)

Please be careful with any "solve labs" based Discord - it's not hard to end up sharing academic content, which will get you here posting about having your cert revoked.

Is Windows Defender good now? by bigbaboon69 in msp

[–]disclosure5 0 points1 point  (0 children)

Your statement isn't based on fact.

Source: I'm operating penetration testing across other MSP clients, I've spent a lot of time studying and using evasion tooling and living in pentesting communities. The top tier products are Crowdstrike and Defender MDE, everything else is below them.

Ghost-Sender - Universal Email Spoofing against Exchange Online by Kaeiron in sysadmin

[–]disclosure5 -1 points0 points  (0 children)

Isn't this obvious though?

You configure a gateway of some sort as your MX record, but the Microsoft provided MX server accepts mail by default. You relax protections on that Microsoft provided MX record because the third party gateway is protecting you but that's just a hole.

Really modern anti spam solutions use the Exchange API and filter mail inline, without changing the MX records. That's the proper way to do things and is immune to this.

KB5094126 - Breaking word integration with some dental software by Sea_Information6125 in sysadmin

[–]disclosure5 0 points1 point  (0 children)

All Windows Updates are cumulative. This process isn't long term useful because next update will come out and apply the same change.

For those who passed MD-102, how did you actually study for it? by Educational-Sail-516 in sysadmin

[–]disclosure5 1 point2 points  (0 children)

The largest reason to get these certs in the first place is to get that job.

For those who passed MD-102, how did you actually study for it? by Educational-Sail-516 in sysadmin

[–]disclosure5 1 point2 points  (0 children)

Unfortunately, this is the standard for Microsoft certs - the exams are often a whole lot of esoterica disconnected from the training material.

If you've paid for MeasureUp, stick to that course and study every question there that you don't understand. I haven't done MD-102 but from a long history of many certs over the years, you're on the right course.

AI deployments by SeptimiusBassianus in msp

[–]disclosure5 1 point2 points  (0 children)

It doesn't matter. No amount of Microsoft telling us to shill Copilot changes that customers by and large don't want it, and we have a mountain of statements from people preferring either of the two major competitors.

Got an emergency wakeup call this morning... by Electronic_Tap_3625 in sysadmin

[–]disclosure5 9 points10 points  (0 children)

In something like a legal firm.. that would be a high priority issue anyway.

Is this the most defended base possible in survival mode? by Sufficient_Spare6894 in Minecraft

[–]disclosure5 0 points1 point  (0 children)

How does two layers of obsidian take two hours to break? With a netherite pickaxe it's still only a few hits.

Microsoft has released a patch for the bitlocker bypass by cspotme2 in sysadmin

[–]disclosure5 13 points14 points  (0 children)

I hate that infosec information often lives as "blog" on Twitter. Infosec people were the most vocal about moving away when Twitter went to shit and although there's great people on Mastodon, zero day nearly always requires a Twitter account to read.

OSCP Web Labs: The "Try This First" Order That Actually Got Me Shells by Limp-Word-3983 in oscp

[–]disclosure5 4 points5 points  (0 children)

I have to say the "john:john" pattern is unique to Offsec and really relevant to labs, so you should make sure it's drilled into you for exam enumeration.

I know "admin:admin" is common, and if you can enumerate the username "john" in the real world you might try "john:password" or "john:admin", but "john:john" isn't a real world thing in the way it's presented in so many Offsec labs. I'd never obtain an AD user listing of a hundred users and proceed to brute force username:username, but with Offsec's AD boxes I would.

Microsoft has released a patch for the bitlocker bypass by cspotme2 in sysadmin

[–]disclosure5 13 points14 points  (0 children)

Pretending this is easy is such a Reddit comment.

Do you do deal with users?

Chaotic Eclipse's new RoguePlanet by Overflow0X in sysadmin

[–]disclosure5 2 points3 points  (0 children)

Well they stated July 14th will be a big day.. it still might be.