• 0 Posts
  • 216 Comments
Joined 3 years ago
cake
Cake day: June 19th, 2023

help-circle
  • You have a network for employee’s personal phones and devices, correct? That still leads to the Internet, correct?

    I mean, the entire point of such a network is to keep outside devices off of internal networks that have sensitive data. And because the insides of large buildings can be absolutely sucky at receiving LTE/5G data connections, employees can and will do anything needed to ensure they still have connectivity on personal devices. So just connect the router/bridge to that network, and Teams will be appropriately sanitized and think you are still at home.





  • rekabis@lemmy.catoSelfhosted@lemmy.worldEmail ownership, I give up.
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    14 days ago

    I’ve been running my own eMail server for almost a quarter century, and I have no clue what all the fuss is about.

    Sure, providers are getting very picky about what domains that they will receive eMails from. But that’s why I have gMail, Yahoo, and Microsoft webmail accounts - so I can train their systems by exchanging emails once a quarter.

    And yes, you do have to be running whitelists and blacklists and tarpits and have a good Fail2Ban in place. And good geoIP system if you want to cut out regions that you are unlikely to ever have legitimate mail originate from. But that’s just common sense security.





    1. Actually text me the one-time passcode, rather than saying you sent it to me while instead texting it to the molten core of the earth.

    Uhhh… how about NO??

    In fact, as a casual security professional (it’s not a core part of my job, but I know a lot more than most ppl), I openly advocate making SMS and eMail illegal for transmitting one-time passcodes.

    Why? Because both are critically insecure, cannot be adequately secured outside of laboratory or highly restrictive environments, and can be trivially hijacked.

    The only one-time passcode that should be used are one-time password generators (TOTP) such as Google Authenticator or any other such method.

    Yes, this requires a little more effort on the part of the site owner, but it’s worlds better than SMS or eMail, and far more user-friendly than forcing the user to open the company’s app just to receive the code (looking at you, Canadian banks and other businesses like Telus).


  • I am in IT, and personally speaking, with my own machines, I have never had these power settings not be obeyed.

    And the only time when I have seen these settings “not be obeyed” in other systems is because either,

    1. Someone or some other non-Microsoft software had dicked with power settings through the registry/GPO, or
    2. I’ve been able to trace things down to hardware malfunctions or hardware discrepancies.