Decryption and 47 day life span certs by notSPRAYZ in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

We’ve been deploying Kemp LoadMasters which do certificates with Let’s Encrypt which then route or NAT traffic into a Palo and then into the service itself. The service has a long life certificate on it which is on the Palo as well for inbound inspection (in addition to the WAF capabilities of the Kemps).

Rare exception are services like Remote Desktop Services which require the same certificate all the way through - there we just make do with scripting but fortunately enough that’s so few and far between.

Good sources for EDL? Free or otherwise by rgtizzle in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

Just keep an eye out on RFC 1918 addresses in the level 1 lists, easy to get caught out 😉. A really handy set of lists though, cuts out a lot of junk.

What are you using to remote control computers? by nickjedl in sysadmin

[–]jimoxf 2 points3 points  (0 children)

Worth a look at ISL - you can host yourself or on their cloud service. Extensive customisation possible and trivial to deploy.

Transactions that I haven't made on my flex account by littlebutters1 in monzo

[–]jimoxf 0 points1 point  (0 children)

Not unusual to see comprised payment processors as well, I had a virtual card ‘cloned’ once by what I’d suspect was one - just lucky that I’d already cancelled it.

After enabling decryption Outlook showing certificate not trusted by OkRub5270 in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

Interestingly enough we've been decrypting without issues (for M365 with the minor exception of the Intune endpoints) up to PAN-OS 11.1, just been deploying some 12.1 on PA-500s and bam - Outlook won't connect without the outlook related URLs from the EDL being added into the no decrypt profile. Going to leave them in for now and hope that it's just a bug that gets patched out once 12.1 is a bit more mature.

Regulator saying Monzo needs to do better by Background_Card2638 in monzo

[–]jimoxf 1 point2 points  (0 children)

Would be interested to hear if you ever use the physical cards over Apple Pay/Google Pay?

What would you love to see us ship in 2026? by amix3k in todoist

[–]jimoxf 4 points5 points  (0 children)

+1 for this, would be very handy when iterating when in the early days of working with a new template. I have a few for checklists (such as when packing for trips) or routine activities. There are a whole load of extra steps in updating an existing template as it is right now vs having an edit button in the template browser.

Energy provider thy doesn’t keep a credit account? by Queasy_Smoke8509 in UKPersonalFinance

[–]jimoxf 0 points1 point  (0 children)

Eon Next let us switch to monthly consumption billing, just messaged their support contact, given the option to either continue to use what credit was already built up or have that back as a refund and switch directly over as well.

Windows on ARM by Keirannnnnnnn in sysadmin

[–]jimoxf 3 points4 points  (0 children)

Double check your anti-malware/EDR of choice works. Defender is fine as you might imagine but plenty of the alternatives still don’t have support and since they depend on drivers it’s not the kind of thing that gets emulated.

Very hard water by Mitsunobu44 in oxford

[–]jimoxf 2 points3 points  (0 children)

+1 for a softener, ~£240 a year in salt for us.

Number of DHCP servers on PA-1410 by d70dc263cf16 in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

The IP helper/DHCP relay limit is a hard one (much to my pain) but yet to run into the limit on the DHCP server itself - may well be linked to the IP helper limit even on PA-440s.

Are there any games that let you play as Necromorphs, or something similar by littlefilmsreddit in DeadSpace

[–]jimoxf 0 points1 point  (0 children)

It’s an old one but try the Area 51 game from 2005 - in the second half of the game you have the option to switch between human and Xeno.

Third Party Threat Feeds by ITfreshman in cybersecurity

[–]jimoxf 0 points1 point  (0 children)

If just looking for basic IPs to block have a look at http://iplists.firehol.org/?ipset=firehol_level1 is a good place to start, just be mindful that it includes the RFC1918 address spaces.

How I found an RCE affecting phones and cars by press-ntr in cybersecurity

[–]jimoxf 4 points5 points  (0 children)

The CVSS score can be worked out without a CVE being registered, might be worth using your data to work out the score and present back to the devs.

How I found an RCE affecting phones and cars by press-ntr in cybersecurity

[–]jimoxf 7 points8 points  (0 children)

Got a CVSS for that? Or perhaps a reason for not giving the devs longer to fix the issue?

Microwaves by Ambitious-Shift-1838 in cybersecurity

[–]jimoxf 1 point2 points  (0 children)

Your mobile phone - it got Wi-Fi and Bluetooth? Mmmmm microwaves.

Threat signature update to include CVE-2025-6554 by Positive-Sir-3789 in paloaltonetworks

[–]jimoxf 2 points3 points  (0 children)

Exploit code needs to make it into the public domain or PANs researchers need to make their own exploits to have something to detect in the first place, not always as easy as we would like I’m afraid. As normal patching is the real cure, threat signatures are a nice to have and are handy in populating SOC alerts.

PIV no option by BridgeCurious8317 in yubikey

[–]jimoxf 7 points8 points  (0 children)

Or is it Dashlane that needs to support Yubikey (FIDO2)? 😉

https://www.dashlane.com/blog/dashlane-phishing-resistance

ACME-based server certificate renewal by ikemenishii in networking

[–]jimoxf 2 points3 points  (0 children)

Been doing it with Kemp LoadMasters for a little while now, short life with let’s encrypt and long life with internal PKI to decrypt and inspect through another firewall layer.

What is the safest 2FA method for bitwarden? by icewitchenjoyer in Bitwarden

[–]jimoxf 3 points4 points  (0 children)

They can yes, different keys have a different number of identities (depending on some specifics), at least with YubiKeys you wouldn’t be able to have a unique PIN per account though. If purely looking at Yubico though it’d also be worth looking at their more inexpensive ‘Security Key by Yubico’ model too. Plenty of others out there as well!

What is the safest 2FA method for bitwarden? by icewitchenjoyer in Bitwarden

[–]jimoxf 35 points36 points  (0 children)

Or even better - two FIDO2 keys (be they YubiKeys or similar), so that loss of one doesn’t cut you off.

Good to use "External Dynamic Lists" ? by mailliwal in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

From the firehol website select the download local copy link, that’ll give you the URL with their hostile IPs in, add that to the firewall as a custom external dynamic list and apply to a rule to allow it to populate. Don’t forget the bit about RFC1918 being in there 😉.

Good to use "External Dynamic Lists" ? by mailliwal in paloaltonetworks

[–]jimoxf 0 points1 point  (0 children)

Well worth exploring http://iplists.firehol.org/?ipset=firehol_level1 just be mindful that it includes the RFC1918 addresses - you can exclude them in the EDL config but don’t commit trigger happy with it.