• 0 Posts
  • 28 Comments
Joined 1 year ago
cake
Cake day: June 20th, 2023

help-circle




  • To be clear, an operating system in an enterprise environment should have mechanisms to access and modify core system functions. Guard-railing anything that could cause an outage like this would make Microsoft a monopoly provider in any service category that requires this kind of access to work (antivirus, auditing, etc). That is arguably worse than incompetent IT departments hiring incompetent vendors to install malware across their fleets resulting in mass-downtime.

    The key takeaway here isn’t that Microsoft should change windows to prevent this, it’s that Delta could have spent any number smaller than $500,000,000 on competent IT staffing and prevented this at a lower cost than letting it happen.







  • Dran@lemmy.worldtoTechnology@lemmy.worldCrowdStrike Isn't the Real Problem
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    1 month ago

    With enough autism in your overlay configs, sure, but in my environment tat leakage is still encrypted. It’s far simpler to just accept leakage and encrypt the OS partition with a key that’s never stored anywhere. If it gets lost, you rebuild the system from pxe. (Which is fine, because it only takes about 20 minutes and no data we care about exists there) If it’s working correctly, the OS partition is still encrypted and protects any inadvertent data leakage from offline attacks.


  • We do this in a lot of areas with fslogix where there is heavy persistent data, it just never felt necessary to do that for endpoints where the persistent data partition is not much more than user settings and caches of convenience. Anything that is important is never stored solely on the endpoints, but it is nice to be able to reboot those servers without affecting downstream endpoints. If we had everything locally dependant on fslogix, I’d have to schedule building-wide outages for patching.


  • Dran@lemmy.worldtoTechnology@lemmy.worldCrowdStrike Isn't the Real Problem
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    2
    ·
    edit-2
    1 month ago

    Separate persistent data and operating system partitions, ensure that every local network has small pxe servers, vpned (wireguard, etc) to a cdn with your base OS deployment images, that validate images based on CA and checksum before delivering, and give every user the ability to pxe boot and redeploy the non-data partition.

    Bitlocker keys for the OS partition are irrelevant because nothing of value is stored on the OS partition, and keys for the data partition can be stored and passed via AD after the redeploy. If someone somehow deploys an image that isn’t ours, it won’t have keys to the data partition because it won’t have a trust relationship with AD.

    (This is actually what I do at work)





  • You’re making a lot of assumptions about my choices. I choose to live well below my means because I don’t want this to happen to me. I don’t have pets, despite wanting them. I didn’t buy a nice house on an expensive loan; I rent a small crappy place in a decently safe area. I don’t buy cars on loans, I fix them myself until I need to buy a new one in cash… I live as if I make half as much as I do, and have done so since working my way through school.

    She should be making 40+/HR for what she does. Hard work out in the sun all day is brutal and should be adequately compensated. But until society figures it’s shit out, people have to be willing to make hard choices. It can be done, it’s just hard and people generally don’t like making hard choices.



  • I would criticize anyone wasting money on an animal while living so close to their means that homelessness could conceivably be in their near future. Sometimes you have to make choices you don’t want to; she probably never had the means to support those animals. The argument isn’t that she should get rid of them, it’s that she never should have had them in the first place. Animals are expensive, and I also wonder what she could do now if she had all the money she spent on them over the years of ownership.

    To be clear, I’m not advocating for $20/hr being considered a livable wage. Disney should be ashamed. Anyone working a full time job should be able to afford a pet if they want one. I just also believe in personal accountability.