https://xkcd.com/838/ Well, if you have an incident list and nobody's checking it twice ...
Remove “This incident will be reported.” from user warnings
21–30 of 302 posts
Re: Remove “This incident will be reported.” from user warnings
#22So no one checks these reports? No wonder we've had so many high profile breaches. Maybe this is what all those layoffs are about.
Re: Remove “This incident will be reported.” from user warnings
#23Earlier quoted context omitted.
Or you set up your system so mail for root gets redirected to an smtp server with an actual inbox read by actual people
Yeah, I kind of lament them removing this warning if I'm going to be honest. It feels like something such as that should be more common best practice. Of course decent log collection/monitoring should also be able to catch authlog stuff and alert accordingly and I'm sure most organizations rely on solutions like that instead of letting things get lost in email
Re: Remove “This incident will be reported.” from user warnings
#24For those wondering where the reports go, under systemd-based linux distributions ideally you can get them with this: sudo journalctl /bin/sudo Historically speaking however the sysadmin with access to the 'mail' command would be able to run that and see mail delivered to root@localhost for these reports. I think at least OpenBSD still does things this way [1], but they moved away from sudo YEARS ago now [2] [1] http…
Or you set up your system so mail for root gets redirected to an smtp server with an actual inbox read by actual people
Re: Remove “This incident will be reported.” from user warnings
#25Stressful message to see back when I was a clueless child. I'm glad its getting removed.
Re: Remove “This incident will be reported.” from user warnings
#26Re: Remove “This incident will be reported.” from user warnings
#27Re: Remove “This incident will be reported.” from user warnings
#28Re: Remove “This incident will be reported.” from user warnings
#29So no one checks these reports? No wonder we've had so many high profile breaches. Maybe this is what all those layoffs are about.
A+ joke.
The fact that our infrastructure STINKS of this is one of the major indications we do not take security seriously.