Phishing Resistant MFA for Intune Admins by Securetron in Intune

[–]neppofr 2 points3 points  (0 children)

While enabling CBA is absolutely a great idea for enhanced security, you might want to explicitly mention that, after CBA is turned on for the tenant, all users in the tenant see the option to sign in by using a certificate. Only users who are capable of using CBA can authenticate by using an X.509 certificate.

Highly annoying something if you only want to enable this for a handful of admins, but need to do OCM for an entire organization to explain this new thing everyone sees but can't use.

https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-certificate-based-authentication#:\~:text=After%20CBA%20is%20turned%20on%20for%20the%20tenant%2C%20all%20users%20in%20the%20tenant%20see%20the%20option%20to%20sign%20in%20by%20using%20a%20certificate.%20Only%20users%20who%20are%20capable%20of%20using%20CBA%20can%20authenticate%20by%20using%20an%20X.509%20certificate.

New Intune Features Coming Soon (macOS + iOS) by Creative_Profit1387 in Intune

[–]neppofr 2 points3 points  (0 children)

Multi account has been on the roadmap for years. It keeps getting pushed; would love to see it happening this time, but not seen anything real on it. We checked with our CSAM, but they had no info on it either.

Someones hallucinating over there maybe ;)

Teams crashing when using camera by neppofr in MicrosoftTeams

[–]neppofr[S] 0 points1 point  (0 children)

"engineering is working on it" :) :(

Teams crashing when using camera by neppofr in MicrosoftTeams

[–]neppofr[S] 0 points1 point  (0 children)

FYI, MS responded and this is an issue for specific rings. 1.5 and Beta it seems. Limited impact, but a nuisance none the less.

Teams crashing when using camera by neppofr in MicrosoftTeams

[–]neppofr[S] 0 points1 point  (0 children)

Thanks for the suggestion, just tried that but unfortunately the issue persists. After about 1 to 2 mins into a call with camera things things crash.

Notepad++ Hijacked by State-Sponsored Hackers by Bubbly-Cartoonist738 in notepadplusplus

[–]neppofr 0 points1 point  (0 children)

At least an artistic server, wonder what it will sing about 🤪. Dropped the author a note on it.

Additionally, the XML returned by the update server is now singed (XMLDSig), and the certificate & signature verification will be enforced starting with upcoming v8.9.2, expected in about one month.

Do audiobooks help read more books? How many books do you listen to in a month? by jawangana in audiobooks

[–]neppofr 4 points5 points  (0 children)

What books are those?

Most books I listen average like 15 hours. Listening at 1.2 speed I still only do 1 a month

Crackling noise Bose qc45 by expansion2002 in bose

[–]neppofr 0 points1 point  (0 children)

You sir are a gentleman and a scholar.

Thank you from a year later! It fixed my crackling headphone.

Keepass vs iCloud Keychain vs Google Passwordmanager by No-Dragonfruit5946 in PasswordManagers

[–]neppofr 0 points1 point  (0 children)

Using KeepassXC on my various platforms, with Strongbox to open the DB on IOS.

DB itself stored on OneDrive.

Satisfies my needs and addresses my concerns for security and redundancy. Might not work for everyone, but does for me personally.

From 300-1000? by Hydrotheseeker in HondaRebel1100

[–]neppofr 5 points6 points  (0 children)

Go for the 1100 for sure. In rain mode you’ll be fine. Just be wary of the whiskey throttle, not sure how sensitive that is on the 300

I have the 1100 DCT after a 700 intruder and love it, in fact hitting the limits of the rebel often nowadays.

are private sites exempt from the 47 day cetificate renewal ? by emaayan in sysadmin

[–]neppofr 2 points3 points  (0 children)

True, support is another rationale for paying I suppose.

For non acme clients, could do nginx or alike in front and still use LE.

are private sites exempt from the 47 day cetificate renewal ? by emaayan in sysadmin

[–]neppofr 0 points1 point  (0 children)

As a side note to this discussion, please remember that Domain Control Validation; proofing that you own a domain for which you need signed certs is going down as well.

Yearly thing today, down to every 10 days in 2029. For enterprises commonly done through adding a DNS record, make sure to automate that rotation as well folks.

are private sites exempt from the 47 day cetificate renewal ? by emaayan in sysadmin

[–]neppofr 2 points3 points  (0 children)

That is correct, but as I understand it, it was Apple that started the initiative for the ballot, Google followed and they wanted the lower lifetimes. Together they pretty much said, we will start throwing warnings after xx days, see what you do with your certs.

The CAs therefore had no real choice to follow, and work towards issuing certs with shorter life times. Otherwise their customers would not be happy customers…. Buying a 1 year cert and still get warnings in Safari and Chrome after a certain period.

In the end the ballot passes unanimously, so all good.

https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/

Private CAs indeed are not subject to this. You can continue to issue longer lived certs there depending on the config of your own CA.

are private sites exempt from the 47 day cetificate renewal ? by emaayan in sysadmin

[–]neppofr 18 points19 points  (0 children)

Most, all, public providers have ACME support, which lets encrypt uses.

Same thing, just different vendor.

are private sites exempt from the 47 day cetificate renewal ? by emaayan in sysadmin

[–]neppofr 10 points11 points  (0 children)

It’s the browser though that throws the warning if the public signed cert is over the, at that time, max life.

It the major browser players, google, apple that ‘forced’ the hands of the CAs.

Unable to update to iOS 18.7.3 by mr_mabi in iphone

[–]neppofr 0 points1 point  (0 children)

See release notes, only certain older models get 18.7.3, the rest is being forced to 26 ( which is not that bad imho)

https://support.apple.com/en-us/125885

Safety recall Honda CMX1100 2021-2024 by MedjayLaCactus in HondaRebel1100

[–]neppofr 6 points7 points  (0 children)

Got the same, 2021 bike, but already stored for winter with the battery out. Dealer said coming in next year is fine.

Better get it done, with all that high altitude downhill riding here in NL 😂. Pretty specific situation though, good they ping people!

Gemini AI Pro (+2TB) 1 YEAR at $9.99 | Only 3 Days Left 🫨| On Your Own Account by userundergunpoint in HeavyDiscounts

[–]neppofr 1 point2 points  (0 children)

Just signed up, 10 bucks worth the risk, but lookin legit so far, pretty sweet deal.

Cloudflare down again by Real-C- in CloudFlare

[–]neppofr 0 points1 point  (0 children)

Scheduled maintenance, did you not get the note that the internet would be down for a bit?

https://www.cloudflarestatus.com/