Ask an IT security guy anything
Ask an IT security guy anything
Author
Discussion

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
I've nearly 15 years in dedicated IT functions and a good few years before closely linked to IT controls. I am sure like others that I am not alone in this field and in the spirit of the AMA threads here, one on this topic might be informative and interesting.

Fire away smile

Clifford Chambers

28,977 posts

212 months

Saturday 6th March 2021
quotequote all
When will the engineer guy answer his questions?

The jiffle king

7,492 posts

287 months

Saturday 6th March 2021
quotequote all
What are the 3-4 things people can do to protect themselves and their families ?

Phunk

2,097 posts

200 months

Saturday 6th March 2021
quotequote all
Have you tried turning it off and on?

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
The jiffle king said:
What are the 3-4 things people can do to protect themselves and their families ?
In no particular order:

1. Avoid installing random software and apps on your devices. It all needs updating, it increases your attack surface
2. Keep whatever you have up-to-date including antivirus
3. Use a big email service such as Gmail or Outlook - it does a massively good job at getting rid of most of the crap
4. Consider using a password manager such as BitWarden. This will create random passwords for you, plug into browsers and phones to fill passwords (on the correct site and not a phishing site) - there you avoid the risk to have your email address and same password used against you

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
Phunk said:
Have you tried turning it off and on?
I leave that to Roy Trenneman wink

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
Clifford Chambers said:
When will the engineer guy answer his questions?
The answer is, that there is no spoon.

Your Dad

2,285 posts

212 months

Saturday 6th March 2021
quotequote all
What's your most frequently used password?

otolith

68,782 posts

233 months

Saturday 6th March 2021
quotequote all
Are you not sick of stupid questions from people who think you should be an expert in anything electronic?

“Can you fix my satnav?”

Erm. Dunno.

(possibly a bad example, since I did figure out how to factory reset it...)

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
Your Dad said:
What's your most frequently used password?
The password to my smartcard at work closely followed by my password to BitWarden, my password manager (with FaceID/TouchID on phone/tablet).

I assume you're not actually asking for my password biggrin

A little toilet reading here: https://en.wikipedia.org/wiki/List_of_the_most_com...

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
otolith said:
Are you not sick of stupid questions from people who think you should be an expert in anything electronic?

“Can you fix my satnav?”

Erm. Dunno.

(possibly a bad example, since I did figure out how to factory reset it...)
Actually, this stopped a few years ago but I was the go-to "IT support guy" for my family for a good amount of time.

One funny tail I can tell you is when my ex-brother-in-law wanted me to speed up his PC and some Intel chipset drivers caused his Dell to bluescreen. The problem for him was that I was leaving 10 minutes later to go to the airport and gave in to his pressure to support him.

He never asked again.

My 16-year-old has been told that malware on his computer is his problem to fix as he managed to infect his PC and his grandmother's PC within hours of them being unboxed. I can happily dissect malware and remove most of it but had to tell him that it has to stop. biggrinbiggrin

otolith

68,782 posts

233 months

Saturday 6th March 2021
quotequote all
Ah, tough love - I might have to try that!

hyphen

26,262 posts

119 months

Saturday 6th March 2021
quotequote all
What do you think of John McAfee biggrin

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
hyphen said:
What do you think of John McAfee biggrin
Genius turned fkwit.
Recent McAfee products have potential but are annoying and quirky. I was at the Executive Briefing Center in Amsterdam some years ago and they showecased the product suit they were bringing to the market. You buy them all, they link together really well - but defence in depth really needs a variety of products.

Your Dad

2,285 posts

212 months

Saturday 6th March 2021
quotequote all
eeLee said:
I assume you're not actually asking for my password biggrin
I think I know it already, can you just reply back to be to confirm? thx

SCEtoAUX

4,119 posts

110 months

Saturday 6th March 2021
quotequote all
Just how much of a trail does lesbian threesome filth leave on your PC after you've deleted your history?

Asking for a friend.

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
SCEtoAUX said:
Just how much of a trail does lesbian threesome filth leave on your PC after you've deleted your history?

Asking for a friend.
<jeopardy mode>What is private browsing mode?</>

Of course your ISP knows at least the site/IP you went to but if it is HTTPS then they have no idea about the actual filth viewed.

Sonie

250 posts

137 months

Saturday 6th March 2021
quotequote all
Top 5 AV solutions for business and also personal
Which AV/EDR software do you have installed?

Ever been hit by ransomeware?

Puggit

49,794 posts

277 months

Saturday 6th March 2021
quotequote all
Why don't companies spend enough money on backup and DR to give themselves a last line of defence against ransomware ?

eeLee

Original Poster:

1,008 posts

109 months

Saturday 6th March 2021
quotequote all
Sonie said:
Top 5 AV solutions for business and also personal
Which AV/EDR software do you have installed?

Ever been hit by ransomeware?
I would recommend looking at www.av-test.com for the current list. I use Windows built-in antivirus.

In corporate terms, antivirus teamed with additional layers to prevent and detect malware.

We have not been hit by malware but as a company we are assessing our preventive controls as well as running scenarios presently to see how we can recover to a run-the-business point. It is important to prevent, detect quickly and have a recovery plan that really can get you back to a RPO that does not break the business.

Side note: anyone giving servers and administrator consoles Internet access without really thinking hard about it is just asking for trouble. You could not exfiltrate Gigabytes of data from our network (the current ransomware method is infect -> encrypt -> steal -> threaten to disclose -> DDoS to force payment).

Double side note: if you allow admins permanent admin access to resources, you are also asking for trouble.