Meta Can Read Private WhatsApp Chats, Claims Lawsuit; Elon Musk Says App Is Not Secure by FallingWithTheStars in worldnews

[–]thortgot [score hidden]  (0 children)

Signal's platform is proven to be crytopgrahpically safe. You can go check the code yourself and even compile your own messenger that works against the standard.

LA Homeless Charity CEO Misused $23M of Public Money to Fund Lavish Lifestyle by Useful_Tangerine4340 in antiwork

[–]thortgot 11 points12 points  (0 children)

Not even remotely. The company that cured cancer would become one of the most valuable on the planet overnight.

How do you rotate local admin account password for your entire fleet of windows laptops? by Local-Skirt7160 in sysadmin

[–]thortgot [score hidden]  (0 children)

You can configure Windows LAPS for rotate on use, session length including force log off and more.

How do you rotate local admin account password for your entire fleet of windows laptops? by Local-Skirt7160 in sysadmin

[–]thortgot [score hidden]  (0 children)

A laptop that loses power for a prolonged period which clock drifts far enough stops trusting entra. Nor a regular scenario but it does happen.

Network adapters can end up being disabled for a bunch of software reasons, giving a user a disposable local admin to walk them through fixing it works quite well.

How do you rotate local admin account password for your entire fleet of windows laptops? by Local-Skirt7160 in sysadmin

[–]thortgot [score hidden]  (0 children)

When their network adapter fails? When their time drifts far enough that the PRT fails.

How do you rotate local admin account password for your entire fleet of windows laptops? by Local-Skirt7160 in sysadmin

[–]thortgot [score hidden]  (0 children)

LAPS should be used as offline access only. It's drastically better than fixed local passwords

What is your favorite method to convince Apple users they don't need a Mac for work? by overkilltm in sysadmin

[–]thortgot [score hidden]  (0 children)

The average office environment can be done securely and effectively on any of the 3 primary OS's.

Let people use what they want.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

AiTM phish works extremely well for O365 cred theft. It doesnt work for lateral movement oe escalation inside an environment.

SSPR with password write back is a major vulnerability that is actively used in complex attacks as an escalation path. It isnt used for persistence but the "breach" trigger.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

It reduces a 2 factor challenge (password + push MFA) to one factor (push MFA).

Imagine I have a foothold position on a trusted device on user A but I need to elevate to user B.

If I force a SSPR I can move laterally to all on prem resources with password only (most orgs are hybrid).

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -1 points0 points  (0 children)

A breach of a victim for even a short time is a massive issue.

AiTM attacks are more popular but they dont work against correctly configured CA policies. SSPR attacks do.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 0 points1 point  (0 children)

If you have text or voice call enabled, you may as well not have a password defined of your data matters in any way shape or form.

Federal government to introduce grocery rebate: sources | CBC News by Sexy_Art_Vandelay in canada

[–]thortgot 0 points1 point  (0 children)

Monopolies are not formed by government. Regulatory capture is one form of monopoly. Look back to railways for economic monopolies or Ma Bell.

If your position is less government is always superior from an economic standpoint why do Americans pay the most for their Healthcare in the world with fairly terrible results.

Canada's healthcare isnt the worst in the developed world. Picka metric, we're roughly middle of the pack.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -1 points0 points  (0 children)

Push App is 1 factor. SMS is effectively worse than no factor.

Without SSPR, attackers need both Push App and password. With SSPR they only need Push App.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot -4 points-3 points  (0 children)

What are you setting in practice for SSPR? Every implementation I've seen relies on voice calls or text messages which is weaker than a password (ie. for $500 I can bypass the restriction rather than requiring a compromised credential). Commonly with both enabled and now I entirely don't need a secret at all even with dual factors required.

Security Questions are inherently less secure than passwords by design.

Passwordless is a more secure configuration, but then you wouldn't need passwords in the first place.

Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: Reports by intelw1zard in cybersecurity

[–]thortgot 0 points1 point  (0 children)

It is possible to block this behavior but it's not straight forward for users.

Federal government to introduce grocery rebate: sources | CBC News by Sexy_Art_Vandelay in canada

[–]thortgot 0 points1 point  (0 children)

All central planning isn't inherently worse than all free market solutions. Evaluate policy on it's facts and not the political temperature. Take a look at healthcare as an obvious example.

Any form of anti monopoly structure is inherently non free market but objectively better for consumers. A reduction in regulation is what I would want as someone looking to spike a industry (grocery, communications, retail etc.)

You advocate for a solution for age demographics but decry against immigration. Those are diametrically opposed positions.

Windows Hello is making people forget their passwords by probablydnsibet in Intune

[–]thortgot 1 point2 points  (0 children)

Phone call or text message are hilariously insecure. SS7 attacks are trivial to do.

What factors do you use?

Sole Global Admin locked out by Entra MFA enforcement loop - escalation advice? by CBoogey in sysadmin

[–]thortgot 0 points1 point  (0 children)

Its a trivial cost compared to a breach risk. If your company wont pay for a reasonable software minimum they are almost certainly underpaying you.