Nope. I don’t talk about myself like that.

  • 0 Posts
  • 24 Comments
Joined 1 year ago
cake
Cake day: June 8th, 2023

help-circle
  • you would realise security even without the cloud is critical to protecting systems

    Wazuh, the software I specifically called out. Is not “cloud”. They offer a cloud service, yes (that’s how they make money, on lazy admins or orgs that are too small to house their own infra). But it is self-hosted and designed to be run within the network.

    You clearly have no idea what the current security market looks like. Nor what half of the terms you use actually mean.

    Edit: Forgot to address this too

    Virtualising every single system endpoint is practically impossible, which Wazuh seems to rely on.

    No. The agent can be installed on ANY system. They recommend you install the orchestration/control node virtualized, which you don’t have to do. You can install it on a raw system though that would be a huge waste of resources. You seem to have missed that.


  • It is clear what you engaged in was attempting to malign all Lemmy.ml and lemmygrad.ml users

    By pointing out the correct answer to a persons question?

    Are you okay? You realize that my answer was basically the same as the other answer given by the lemmy.ml user in a different part of the thread. Just not an essay’s worth of content when a sentence is sufficient.

    You are a piece of shit. If Kiwifarms goes after people like you

    So a call to action to dox people? Why are you threatening people and calling them names? Aren’t you a mod? I mean you might have a case or argument if the votes weren’t kept on the platform itself.


  • The latter is beyond lacking in open source ecosystem

    And yet software like Wazuh (https://github.com/wazuh) exist… Which are complete SIEM and XDR platform. Which does more than any antivirus could ever dream to do. But somehow OSS security is lacking? Sounds like you haven’t looked at the security field seriously in decades. Kaspersky doesn’t lead the pack in anything and it isn’t in a “level field”. Quite the contrary Antivirus as a concept has been commodified in IT. They’re all generally drop in replacements for each other and are not what is actually used to prove to security auditors that systems are secure. You may get %1 detection differences between platforms or maybe an update 30 minutes or an hour earlier. This is generally meaningless and the modern tools actually used to prove security go way deeper than an antivirus.

    Lying to yourself is never going to solve problems.

    Seems to work for you though?








  • Saik0@lemmy.saik0.comtoAsklemmy@lemmy.mlCan I refuse MS Authenticator?
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    6 months ago

    Because that shit only works in fantasy land.

    Glad to know my company, and the companies I contract for are fantasy land then.

    employees WILL expect support

    And they will get it if they use the company default options.

    Nothing about this is losing. I’m CIO for 3 separate companies (2 by contract). None of them have issues with this type of policy. We do bare minimum to not limit the toolset they can use and support a specific set of tools that we like the best. That’s it. Those who are smart enough to use their own tools clearly know enough about IT to make good decisions that we can trust. The rest use the default tools… and we support those tools explicitly.

    More importantly, we’re not shitting on those who ARE making good decisions overall, but just have a preference. That makes the employees feel heard and keeps them happy. Keeping them happier keeps everyone more productive.


  • This is disingenuous though… You can simply reset the TOTP seed on any account to achieve the same operation. We use AuthLite on a local domain… I can disable an account domain-wide by simply resetting the TOTP seed or disabling the account. Using an Azure domain and MS app doesn’t add any value in that regards. All of the online office stuff can be linked onto a local domain as well and would also be disabled.


  • Saik0@lemmy.saik0.comtoAsklemmy@lemmy.mlCan I refuse MS Authenticator?
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    6 months ago

    I’m pushing to make us exclusive because I’m sick of the IT support guys trying to support a dozen apps.

    While I understand this… Why not just refuse to support and NOT remove the capability for all those who don’t need support and work just fine with their own? It’s not like TOTP isn’t a solved problem at this point.

    Eg. “we only support MS auth, If you choose to use your own you will not receive any company support.”


  • Not sure I understand what the faraday cage would accomplish. It’s the companies device. You’d be skipping this presumption outlined earlier in the thread

    they are entitled and expected to track it as much as my work laptop or any other company equipment.

    Leaving the work phone at work is a valid answer to me. Assuming that doesn’t actually come with any other downsides (working offsite and having to return to the office on unpaid time just to drop off the phone for example).


  • Saik0@lemmy.saik0.comtoAsklemmy@lemmy.mlCan I refuse MS Authenticator?
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    6 months ago

    Or I brought up a point that you didn’t consider, and rather than addressing it you need to resort to low level ad hominem. You contradicted yourself. Either explain the contradiction or move on. There’s no point in this comment unless you’re attempting to discredit me without reason which just makes you look bad.


  • Saik0@lemmy.saik0.comtoAsklemmy@lemmy.mlCan I refuse MS Authenticator?
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    6 months ago

    Your point is illogical.

    You stated

    they are entitled and expected to track it

    Just to turn around and back-peddle

    If I don’t want them tracking me I just turn it off

    Are they entitled to it or not? If they’re entitled, then why do you have a right to cut it off? I’d argue they have no right to it to track me off hours at all… regardless of the device used. u2f tokens like yubikey would be just as sufficient for 2fa with none of the tracking.




  • Rolling up a chip bag once every couple of days when you have chips isn’t going to cause hearing loss.

    Go look up a video of these bags. Mere handling them is loud as shit. Not just when you roll them up when you’re done.

    NIOSH standards say that at 95db, you shouldn’t be exposed to more than ~45 minutes of it. Where-as an alternative “loud” bag was 77 db, which is longer than 50 hours of exposure (exceeds the rolling period and is thus “safe”).

    Noise exposure is additive during a rolling period. So just saying “once every few days” is bullshit. This isn’t something that happens or can be in a vacuum. It’s adding to the total exposure that you’re exposed to every day. On top of the rest of your day the 95db chip bag is a really stupid fucking way to damage your hearing. Because you chose to eat some chips while watching a movie one night.

    As someone with tinnitus… Fuck people who downplay hearing loss/damage. You should be doing everything possible to keep your exposure to anything above 80db to a minimum.