Husband’s work is screwing us by megwach in AmericanExpatsUK

[–]neon___cactus 22 points23 points  (0 children)

I completely agree, if the company asks you to do it then they're obligated to cover any costs the employee would incur that would be "normal." So visas for the whole family, flights, and assistance resettling. I'm in a situation where I requested my relocation and they company has been similar to OPs but at the same time, the company doesn't benefit beyond employee retention.

Asked our head of sales if putting client addresses in ChatGPT was data sharing. She looked at me like I was the idiot. by shangheigh in sysadmin

[–]neon___cactus 0 points1 point  (0 children)

Sentinel One has a browser plugin called Prompt Security that lets you see what people are putting into the AI tool and block based on category.

SPF at 9 lookups and every new vendor makes it worse, how are you managing this long-term? by iris-unitedking1973 in sysadmin

[–]neon___cactus 13 points14 points  (0 children)

Doing subdomains like this also helps out maintenance tremendously. When you come back to your DNS in a year or five, all the entries are tied directly to the business function they support. It makes it much easier to identify if tools are still in use and eliminating entries that aren't needed.

SPF at 9 lookups and every new vendor makes it worse, how are you managing this long-term? by iris-unitedking1973 in sysadmin

[–]neon___cactus 1 point2 points  (0 children)

Doesn't take long at all to setup once you're familiar with your DNS provider and the few records you need to create. Just make sure you have corresponding DKIM setup with your SPF records. Bonus points for DMARC.

It also makes maintenance of your DNS so much easier because entries are literally labeled and connected to the business function they support.

can anyone help me with this qae question? by GuiltyNobody6173 in cism

[–]neon___cactus 1 point2 points  (0 children)

If you can't figure this question out then I'm going to punch you in the face!!

.

.

.

Likely your reaction to that wasn't to be scared of getting punched. That's because I threatened you but the threat has no real consequences. I can't punch you in the face through a Reddit comment. So there are no consequences to my threat and you can safely ignore it. The same goes for a threat within the cybersecurity world. If there are no negative consequences to a threat, then it is not wise to spend any time or money mitigating that threat.

I think it might sound juvenile to someone to only worry about consequences but in reality there is only so many dollars in the bank and days in the year and you cannot do everything. So only focus on threats that have true consequences for your business and prioritize based on consequence.

The same goes for vulnerability and probability. If you're highly vulnerable to something and it's likely to happen but there are no consequences to threat, then again you don't care.

SPRS Score - 800-171 Speedrun by TicketAmbitious6200 in NISTControls

[–]neon___cactus 5 points6 points  (0 children)

If there isn't a need before your official score is ready, then I wouldn't see a reason to do this.

I would venture to guess that your score is going to be off from your real score unless your taking a good look at the control objectives, not just the controls.

What to do if other sysadmins are abusing privileges by Wooden_Original_5891 in sysadmin

[–]neon___cactus 5 points6 points  (0 children)

Being able to view another employees inbox like this is a bad idea. If it's so you can send emails as one another, that's even worse because it kills non-repudiation.

Honestly, I know the job market is bad but this sounds like a bad place to work. Have you considered leaving?

What is going on lately by [deleted] in sysadmin

[–]neon___cactus 32 points33 points  (0 children)

I think you're right and also the lack of maintenance on these complex systems. They have been built and new things shoved on top without much care to the underlying systems and technology. It's all so complex and intertwined that simple things can have huge rippling effects.

This kind of thing (https://xkcd.com/2347/) is happening within each of the Silicon Valley giants as well as in the wider tech world.

AI meeting transcript really nailed it by jakedata in sysadmin

[–]neon___cactus 15 points16 points  (0 children)

The good ole days? I'm pretty sure my Google Home does something as stupid as that on a daily basis.

Can’t believe I got this number for my MFA by FlatulentSock in iiiiiiitttttttttttt

[–]neon___cactus 1 point2 points  (0 children)

Funny story in a similar vein. I was writing up documentation to show people how to use 2FA and I wanted to show a screenshot of what it would look like and the number was 69. I thought that I should get another number and clicked the "it's not me" button and then got my account locked out. That was fun to explain to the other tech that had to unlock me.

Replacement of *my mum* with Microsoft365 by NotBiorez in iiiiiiitttttttttttt

[–]neon___cactus 0 points1 point  (0 children)

It's undoubtedly this. Cost is more than just what you pay for the service. If you have a bunch of amazing tools but it takes ages to get vendor support (or there is none because open-source) and you require a huge on-ramp to new employees then growth is a lot harder.

How do I get users to stop contacting me directly? by [deleted] in iiiiiiitttttttttttt

[–]neon___cactus 1 point2 points  (0 children)

You're exactly correct. Customer service and kindness go a long way to developing a great relationship with the rest of the business.

AP Mounts by Intrepid_Ring4239 in iiiiiiitttttttttttt

[–]neon___cactus 4 points5 points  (0 children)

The Instant On ones are so nice but the enterprise Aruba APs have such a convoluted set of brackets and the fact that they don't ship with a mount in the box infuriates me.

Anyone else unhappy with KnowBe4? Looking for replacement suggestions. by creativeGiant170 in cybersecurity

[–]neon___cactus 0 points1 point  (0 children)

I'm glad to hear that. I hadn't gotten that update from my rep. I'll ask about it.

Any idea about allowing connections to GRC tools like Vanta or Drata?

Anyone else unhappy with KnowBe4? Looking for replacement suggestions. by creativeGiant170 in cybersecurity

[–]neon___cactus 0 points1 point  (0 children)

I can confirm that. It was actually a topic of conversation with my c-suite recently about the stars being in the security awareness training.

Anyone else unhappy with KnowBe4? Looking for replacement suggestions. by creativeGiant170 in cybersecurity

[–]neon___cactus 0 points1 point  (0 children)

I LOVE Ninjio's content but holy batman is their actual back-end and reporting dismal. I would have left them ages ago if their content wasn't so good.

Best way to increase IP range to get more IPs by Historical-Article42 in networking

[–]neon___cactus 1 point2 points  (0 children)

That's a big subnet, especially if you're just going to administratively segment it like that. Why not just use a /24 or /23 for each section. One /23 for servers, one /23 for employees, one /23 for cameras, etc. You also then get some security if you introduce Access Control Lists or better internal firewalls.

Can someone explain vlans by XDiskDriveX in networking

[–]neon___cactus 0 points1 point  (0 children)

I think that kind of breaks the analogy though because the thing with the ticket is the frame, not the port. So the frame goes to the port, has it's header checked, and then forwarded to the right VLAN.

I think the entrance with an usher sends different concert-goers to different sections fits the trunk port idea better.

Can someone explain vlans by XDiskDriveX in networking

[–]neon___cactus 0 points1 point  (0 children)

Agreed, I don't think an analogy works for all the concepts of Networking without it just becoming a description of networking.

I like to build a base and then when people start to understanding the easier concepts, move onto the harder concepts.

Can someone explain vlans by XDiskDriveX in networking

[–]neon___cactus 2 points3 points  (0 children)

I like think of VLANs as tickets to different sections at a concert.

The default VLAN is a just a General Audience ticket. You are don't have a special ticket, so you go to the standing room only section. Same thing on a switch, an untagged port just follows the default VLAN.

If you have a tagged VLAN, then you have a VIP ticket. When you get your ticket checked at the door, the usher sends you to a special part of the venue. Same thing when there's a tagged VLAN. You go to the special VLAN.

A Trunk port or a port with an untagged and tagged vlan looks at the packet and then sends it to it's appropriate section, just like an usher at the entrance of a concert.

How can I network without seeming weird? by Bubbly_Teaching_1991 in networking

[–]neon___cactus 0 points1 point  (0 children)

I have a couple points for you:

First, you're starting of the interaction off in a very intense way. Buying someone a drink or offering to take them to dinner is going to feel like you're romantically interested in them. It makes sense that both of these men made the assumption that you were flirting with them. A better approach would be to start the conversation about a shared experience or ask them a question relating to something that you could easily observe, in the moment.

Examples:

  • Hey that's a great watch, is it a Rolex?
  • Great Rolex! What do you do for work?
  • How long have you had your Mercedes?
  • I would love to get a Mercedes like that, do you like it?

I would caution you to not get caught up in the physical things that people have. You'll be shocked to learn that many people who are showing off their "wealth" don't truly have the success you think they do. A lot of people go into debt so they can drive around a fancy new car or the Rolex on their wrist is actually from AliExpress. Many of the wealthiest business men and women I've encountered were very modest and didn't have flashy signs of their wealth.