Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

jamesb

Members
  • Posts

    2,502
  • Joined

  • Last visited

Everything posted by jamesb

  1. A big thank you to @ICTDirect_Dave for helping me spec up a beast of a machine, much more than I thought I'd be able to get on budget.
  2. Van Eck Phreaking was the one mentioned in the Cryptonomicon, so yep, pretty much. https://en.wikipedia.org/wiki/Van_Eck_phreaking The answer of course is to surround yourself with so many gadgets that the data can't be filtered out of the storm.
  3. I'm currently plotting out a new spelljammer-type campaign, planning to start it properly in August. You go to Empire? If so you can find me running the Brass Coast bar. Drop in and mention edugeek for a free drink.
  4. I use K-@ Mail, which I've been very happy with. It also integrates well with APG which is a nice touch.
  5. Just a touch above my current budget sadly, but I'll keep you posted if anything changes.
  6. Is IPv6 enabled on the server, and is that address registered in DNS?
  7. I definitely prefer the firestick myself (have both a Chromecast and a stick) - mainly as the phone app allows you to replace the remote and actually control the interface directly. I always found using the Chromecast rather clunky in comparison, and now mainly use it for presentations so I can throw up slides from the phone.
  8. I do love the ipviking map (it's my screensaver at work, and I have a monitor running it most of the time at home) but no visual aids were allowed.
  9. If you're genuinely worried about backdoors then you'll need to do a full AD audit to cover the most common ones. It's fairly simple though - just make sure that every account is accounted for (heh) by an active user, or an active service. Change the passwords of any service or admin accounts. Disable any accounts not accounted for. 99% of backdoors are just an AD account left in. You almost certainly don't need to worry about the remaining 1%. Oh, if you are really concerned about it then you might also want to check your DCs for the presence of skeleton key or other malware.
  10. Keys and padlocks and boxes inside boxes. Then moving on to point out that a trusted certificate just means that someone your browser/computer trusts has signed it - and an untrusted means they haven't. It will still work for encrypting your data between you and whichever endpoint actually holds the certificate, you just shouldn't automatically believe they are who they say they are. The analogy is one I've heard in various forms before, and goes along these lines: - You have a box and the server has given you a padlock to lock it with. The server has an infinite number of these padlocks and is happy to give them away, but there's only one key which you hold. - You then have a larger (or smaller - it's not a perfect analogy and is designed to get the idea across rather than the exact functioning) box, and a lot of padlocks your computer has made, along with one key that can unlock it. You put the boxes inside one another, send a load of padlocks out, and send the boxes over to the server. - The server then unlocks its padlock, reads the message, sticks a new one in the box and sticks one of your padlocks on it so that only you can unlock it. Repeat until you're done.
  11. Well the talk's now done, and judging by the followup questions (and the several drinks bought for me afterwards) it went well. Managed to stick to just under the 20 minute time limit, or so I thought. Questions and discussions afterwards added another half hour, and I ended up circulating and discussing, debating and answering questions with smaller groups for the next two hours. In the end I went with: - Public wifi and why you should be worried about it, and what to look into to protect yourself - Social engineering and reconnaissance, why all of the 'security' questions companies ask you to fill in are awful and what you can do about it - Basics of encryption - with a focus on PGP and SSL certificates The SSL certificates one I got a particular thank you for, from someone who apparently keeps getting asked how they work and what the certificate alerts mean in their day job and is going to use my analogy in future. Thanks to everyone for your help and advice on this.
  12. If you've got OWA available, what certificate do you see when you reach it?
  13. It looks as though your Exchange cert was provided by Openhive, and is signed by their certificate. If you've removed the certificates from the workstations they'll no longer be trusted. You'll want to replace the Exchange cert with something signed by a trusted CA.
  14. The NUC's a little low for what I'm looking for, while the Recon 3F (if that's what you were referring to) is close, but a little heavy in some areas and light in others. Full spec/wishlist: 8 cores (whether two quads or one oct doesn't matter too much to me) Minimum 5TB storage, at least 1TB fast access while the rest is for bulk data 16GB memory minimum, 32GB ideal Capable of driving at least four monitors Multiple network ports, at least 2, ideally 4 The graphics card(s) don't need to be particularly effective at hashing, as work will be providing me a separate resource for that whenever I need it. Full hardware-based disk encryption would be a bonus. More USB 3.0 ports the better. Ideally water-cooled and in a sound-reducing case for my sanity. I've already got all the monitors, keyboards, trackballs, mice, etc that I could ever need. Also no software or operating system required as I'll be building that up myself. On-board sound is fine, as it'll only really be used for conferencing.
  15. As I said, I don't really have the time or inclination to build it myself right at the moment. If I can't find anything suitable then I will do, but it's a headache I don't want to deal with while changing jobs and house.
  16. My various PCs are slowly dying, and the Frankenbox I scavenged from the parts is getting a bit iffy, so it's time to look for something new. Previously I've used multiple boxes for different purposes but to be frank this is now irritating me, so I'm going to be running specialist boxes on virtual. Does anyone know of any companies or individuals good for very particular custom builds? I've used a few companies before, but they tend to focus on gaming PCs and that's not quite what I'm looking for. I no longer have the time or inclination to trawl through lists and source parts myself, then assemble the thing, so ideally would just like to find someone who can take a list of requirements, a budget, and give me a spec. Any suggestions/offers?
  17. The Cafe Scientifique setup can be absolutely anyone, but does tend to be weighted towards those interested in science and tech (for obvious reasons). I know that last month they had a chat on beekeeping for example, and previous topics have included signal processing and other esoteric subjects.
  18. It appears that in less than a week I've been volunteered to give a Cafe Scientifique talk on Information/Cyber security. Shouldn't be too hard, as it's only a twenty minute talk (with questions to follow) with no presentation materials allowed. Which of course makes life so much easier. The problem is that I know I can blather on for hours about infosec, going on and on and on - but this is meant to be in laymen's terms, and with only twenty minutes I'm struggling to decide on priorities. I think two or three concepts/topics are the most I can cover - ideally related - but I'm having real difficulty working out what's actually of most interest to people outside the field. So I'm going the crowdsourcing approach. Current suggestions I've had include: - the dangers of public wifi and why you should never use it - how North Korea could take down all of our connected infrastructure - the great Russian Bank cyber-heist - DoS and DDoS attacks - why internet-enabled toys and gadgets are the worst idea in existence without proper security (and potentially with) - what personal information is and why you should care about it - how to protect yourself from monitoring on the internet (pretty sure I couldn't cover this in twenty minutes without dropping into overly-technical matters) - symmetric and asymmetric encryption All suggestions are welcome. Basically what I'm looking for is if you were going to something like this, what would you be most interested in hearing about?
  19. There's a nice analysis of the cause here: That EVIL TEXT that will CRASH your iPhone: We pop the hood • The Register So to me it appears that anything using the CoreText library can potentially be affected. Since that appears to be everything Apple I'm fairly sure this'll get worse before it gets better - unless they fix it soon.
  20. Don't worry, we've herd you and I'm sure people will stop flocking in now.
  21. Are ewe saying ewe'd know better? Personally I think it was criminal damage, and no doubt the culprit is now on the lamb.
  22. Counter Intelligence (I used to have John Le Carre read to me as bedtime stories). Oddly enough the new job I'm moving to isn't that far off (though not for the intelligence services, I should point out).
  23. Yes - they're still passing through the server and stored in the mailbox.
  24. If you don't want to/can't do the login thing, or you shouldn't have access to the e-mails yourself (can happen as part of a sensitive investigation) then the Search-Mailbox cmdlet is your friend. Use the copy option, and copy the e-mails either to a target user's mailbox for them to examine (HR or your counsel for example) or to a brand new mailbox just for the investigation. Also has the advantage that you're not connecting to the user's mailbox and potentially seeing sensitive material that they may have stored which is unrelated. https://technet.microsoft.com/en-us/library/dd298173%28v=exchg.141%29.aspx
×
×
  • Create New...