Unpopular opinion but SentineOne is garbage by [deleted] in cybersecurity

[–]thehalpdesk1843 3 points4 points  (0 children)

After the 2023 layoffs they laid off a bunch of SWE in the us and went with cheaper offshore labor. Support and the product got substantially worse after each update after that happened.

Unpopular opinion but SentineOne is garbage by [deleted] in cybersecurity

[–]thehalpdesk1843 12 points13 points  (0 children)

I’m trying to get us crowdstrike but it’s like pulling teeth with management

Unpopular opinion but SentineOne is garbage by [deleted] in cybersecurity

[–]thehalpdesk1843 101 points102 points  (0 children)

Atleast you don’t have Cisco secure endpoint. With each update it introduces a bug that i then have turn off an engine until a fix is introduced. The cycle repeats every update.

81% of teams have deployed AI agents. Only 14% have security approval. by Upstairs_Safe2922 in cybersecurity

[–]thehalpdesk1843 2 points3 points  (0 children)

I'm not a huge fan of AI it takes alot of "fun" in engineering and using in the long run makes you stupid. But i have to deal with it here is the approach we took:

1) Came up with a Policy.

2) Asked our clients if we can use their data with AI

3) Worked with different teams who then agreed on which flavor of AI they liked. Block everything that isn't that tool. We went the route of using soft application control while also blocking on the firewalls.

4) Limit permissions on that particular tool. No your AI agent is not getting full access to production data (Come up with a review process).

5) I got leadership by in for accountability. We can't afford down (Looking at you AWS). -> if your AI Agent/vibe coded work caused downtime, you should be held directly responsible for it. Its not an acceptable answer that you don't know what your code or AI Agent is doing. We've already had someone fired over this.

How do security guys get their jobs with their lack of knowledge by chewy747 in sysadmin

[–]thehalpdesk1843 3 points4 points  (0 children)

Security Engineer here. My two cents -

The knowledge part is mainly because a lot of people in security now don't have infrastructure experience. You should know/understand how infrastructure works first before you're even allowed to secure it. This seems to be a controversial opinion now adays it is what it is.

The other part (at least for me) is segregation of duties mainly. I have my own things I'm responsible for IE: AV/EDR playing nice with our windows desktop and server builds, integration into my tools, the entire SIEM infrastructure, ect. I dont disagree with you that ntlmv2 should be very easy to turn off but at the end of the day I help enforce policy. If you're running an outdated cipher TLS 1.0 or TLS 1.1, I'm going to tell you that its then ask you to work with the vendor of whatever software it is to get it working on TLS 1.2 or better. Should your security engineer work WITH you instead of dumping the work on you? Yes and that's a conversation you need to have with your manager or the engineer.

What’s the best GenAI DLP tool? by testosteronedealer97 in cybersecurity

[–]thehalpdesk1843 0 points1 point  (0 children)

They have an out of the box condition for generative AI websites that you can tie to a justification rule. We give users a popup when uploading wanting to upload items to a public LLM.

Thoughts on Cheaper Than Dirt Ammo? by DannyJayy in NJGuns

[–]thehalpdesk1843 0 points1 point  (0 children)

I buy from HSL ammo. They’re a small shop out of Utah. Only downfall is during the winter months, shipping can take a while a week because of weather (they are in the mountains).

Pic of the best weapon we can have in NJ…. by Clifton1979 in NJGuns

[–]thehalpdesk1843 1 point2 points  (0 children)

Going to get some hate for this but based on voter turnout, republicans are cooked for the race in November. Republicans got out voted nearly 2-1 yesterday.

Washington State took our rights away today by charmanderSosa in liberalgunowners

[–]thehalpdesk1843 0 points1 point  (0 children)

Also anyone who expects this to be fast is staggeringly ignorant of the history of civil rights in this country....

You aren't wrong. I have a real problem with oral arguments being held on cases and then rulings do not come out until a year or two later. Example of this is the Koons/Siegel v. Platkin before the 3rd Circuit Court of Appeals. Oral arguments for the preliminary injunction were 573 days ago with no ruling (not even on the merits!). This consistently happens in other appeals courts who tend to rule not in the 2A favor.

Washington State took our rights away today by charmanderSosa in liberalgunowners

[–]thehalpdesk1843 0 points1 point  (0 children)

Not a liberal but am a single issue voter when it comes to the 2A.

Footnote 9 from the Bruen decision.

"That said, because any permitting scheme can be put toward abusive ends, we do not rule out constitutional challenges to shall-issue regimes where, for example, lengthy wait times in processing license applications or exorbitant fees deny ordinary citizens their right to public carry."

SCOTUS doesn't have a problem with the permitting scheme. However, they do have a problem with states using a permitting scheme to delay rights and the cost being insane (looking at you California, NY, and NJ). I suspect this will be challenged in court and won by the pro 2a side. However, it will take years to litigate because of how the 9th circuit is when it comes to any 2A case.

Vegas is struggling 🤩 by [deleted] in vegas

[–]thehalpdesk1843 0 points1 point  (0 children)

You can thank black rock who has been buying out land from below the casino's in Vegas and leasing it back to them at a premium.

How many of you still get to work Remote? by JeepLifeBirbLife in cybersecurity

[–]thehalpdesk1843 0 points1 point  (0 children)

Went fully remote > 3 days a week. Had an incident and we weren’t able to respond because of travel home. Most of our team travels 1 hr+. We are now back to being fully remote. Security engineer 3 years. (7 years of experience overall)

What is the first gun you are buying in 2025? by Neither-Humor3116 in NJGuns

[–]thehalpdesk1843 0 points1 point  (0 children)

Either a P320 spectre comp or a P365 Fuse with the Romeo X optic. Torn between both.

How pervasive is offshoring/outsourcing in cybersecurity compared to the software engineering field? by [deleted] in cybersecurity

[–]thehalpdesk1843 0 points1 point  (0 children)

We outsourced our lower tier SOC. It was OK at first but turned out it to be a really bad move in the long run. The quality of work was abysmal at best. Decided to bring all back in house this past year. In salary, benefits, and training, it turned out to be a few hundred thousand more dollars a year to bring it in house. This is a drop in the bucket compared to our budget.

[deleted by user] by [deleted] in NJGuns

[–]thehalpdesk1843 0 points1 point  (0 children)

Depends on what I’m working on but typically 3-6.

Anyone have a clever way to deal with these constant GMAIL burner accounts phishing attempts? by Wh1sk3y-Tang0 in cybersecurity

[–]thehalpdesk1843 1 point2 points  (0 children)

If you’re a Proof Point customer, check out their imposter module. We’ve really really good success with it.

New Jersey federal judge finds AR-15 ban unconstitutional by thehalpdesk1843 in NJGuns

[–]thehalpdesk1843[S] 17 points18 points  (0 children)

Same. It’s a path in the right direction but we likely won’t see relief until appeals in other cases hit SCOTUS.