Earlier quoted context omitted.
It makes me sad every time I think about it, but Aaron Swartz did this during his saga. Well, sort of: he incremented the MAC address by 1. Point being, it's not foolproof. If some clever undergrad is thinking about dodging the suits, win by fooling them, not by fighting them. If you do insist on fighting, though, start at https://www.whonix.org/wiki/Mental_Model and then read the entire Whonix wiki https://www.whoni…
building a new computer. want to be able to trust it 100% for at least a moment. i can't figure out how to "buy" a trusted copy of any linux and don't have any machines i have 100% trust in (who does), so can't burn it. current plan is to buy a chromebook solely for the purpose of downloading and burning ubuntu. alternatively, buy MSWindows, install on the new machine, burn, and then replace but this mental exercise…
Tor is a great sysadmin tool (2020)
111–120 of 125 posts
Re: Tor is a great sysadmin tool (2020)
#112Earlier quoted context omitted.
“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…
> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.
You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this from happening. Nor are you the one who has to clean up the damage if something goes badly.
I also think you’re vastly overestimating the average developers awareness of security issues. Perhaps you are very well versed in this topic, but many developers are utterly clueless, even when it comes to basic application security practices.
Re: Tor is a great sysadmin tool (2020)
#113Earlier quoted context omitted.
> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.
“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…
Re: Tor is a great sysadmin tool (2020)
#114Earlier quoted context omitted.
Also circumventing this sort of thing in many orgs is a first class ticket to finding a new job. Friend of mine did that, they walked him to the curb with his cardboard box that day. His sin? Turned off virus scanning because it was taking 4 hours to do a 20 min build.
The organization did him a favor. Many other, far more well paying companies response to doing that is working with the developer to figure out a system to make them both happy, or just silently ignoring it until they figure out a better solution. Or just talking to the person and asking them to stop, vs firing.
Re: Tor is a great sysadmin tool (2020)
#115Earlier quoted context omitted.
> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.
“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…
Re: Tor is a great sysadmin tool (2020)
#116Earlier quoted context omitted.
“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…
I'm curious how you think an SSH service exposed over TOR is going to create a security issue? SSH is exposed all over the public internet.
I don't even disagree with the logic, but the BigCorp Infosec Team heavy-handed approach to working with developers invites the developers to produce creative circumventions.
Re: Tor is a great sysadmin tool (2020)
#117Earlier quoted context omitted.
Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…
Especially when, since it's Tor, potential attackers cannot be traced
Re: Tor is a great sysadmin tool (2020)
#118Earlier quoted context omitted.
Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…
Especially when, since it's Tor, potential attackers cannot be traced
Re: Tor is a great sysadmin tool (2020)
#119Earlier quoted context omitted.
at our lab the tor traffic would be noticed by the cyber security group's ids and all traffic from your host would start dropping at the border so fast your head would spin. you'd get an unpleasant phone call or visit to your office and be warned never to try side stepping the bastion ssh hosts that log all the things ever again.
Is tor traffic that easy to detect?
Re: Tor is a great sysadmin tool (2020)
#120Earlier quoted context omitted.
"What did you accomplish during your time with X research group?" "Nothing since all our equipment broke, but we documented how it was all IT's fault. You shoulda seen the looks on their faces when we called them out on it to the dean!"
It seems weird to dump on IT when they’re a department responding to the incentive structure they’re placed under like everyone else. You going to the Dean/someone with actual authority to get top down approval for IT to give you what you want is basically how IT operates in large orgs. I have nigh infinite technical power but in return I am bound politically by polities that I’m explicitly not allowed to have any au…
Everyone else is responding to incentive structures too, it's no less legitimate for lab workers to circumvent IT due to their incentives than it is for IT workers to be unhelpful due it their incentives.