Fun fact: The outdated software runs on outdated hardware, too.

43 points

In January 2021, Microsoft pushed a kb that would make your server reboot constantly if it was running server 2012 and was either a domain controller or a hyperV host.

Guess how many domain controllers went down that day.

permalink
report
reply
14 points

Yeah but domain controller so hard to migrate and so sensitive! Better let them rot on old unsupported software versions!

permalink
report
parent
reply
8 points
*

i mean yeah but bean counters up top want me solving the current emergency (caused by similar forms of neglect from years ago)

ill get to it when it breaks i guess

permalink
report
parent
reply
2 points

So fight bean counting with bean counting

Best formula is average employee pay × number of employees × time to fix = money lost.

The trick is to find a solution that is lower than money lost.

Say 20 employees at €35/h for 4 hours. €2800 is how much the company lost in wages.

You will find bean counters are more acceptable to a €5000 server over 5 years if it prevents €2800 of lost wages per patch Wednesday.

permalink
report
parent
reply
10 points

Please tell me that was a bad patch and not on purpose

permalink
report
parent
reply
31 points

Who knows? :D

permalink
report
parent
reply
35 points

Trigger me timbers

What has two thumbs and just spent all week hectoring the boss to upgrade from Server 2008 to 2022 so docker and ssh would finally work?

👍🏻👍🏻

Well girls, we’re living in the future now! Five new 2022 servers, all turned into dumb ssh+docker nodes in my job cluster!

Wipes brow with a trembling hand

Grumble grumble… they wouldn’t let me upgrade to Linux just yet though… But the plan is coming together… evil laugh

permalink
report
reply
20 points

Do they hate money? Paying for Windows server just to run docker is an expensive option.

permalink
report
parent
reply
21 points

There’s two ways to perform every task. There’s the way we say and maintain the illusion of doing. And, there’s the practical way we actually get the work done. If we don’t maintain the illusion then they’ll cut budget. If they cut our budget we can’t even afford the practical way, let alone what they think we’re doing.

Your success in this position will be determined by how quickly you learn both processes and how well you choose which is appropriate for the situation.

permalink
report
parent
reply
16 points
*

TBF all the jobs are a decade old and written by our researchers in dotnet framework as Winforms apps I hacked up to be console apps so it’s gotta be windows. I’m converting them one by one to dotnet core and moving them to my Linux containers but it’s a slow process and I’ve got a v1 release to prepare for next month.

Everyone is just stoked that no longer do a half dozen researchers have to twice a day log in to their pet server, open their Winforms app, run it, and copy paste the results to a shared drive. Now my docker harness does it all on a scheduled task triggered automatically from rundeck server I manage. WE’RE LIVING IN THE FUTURE BABY

permalink
report
parent
reply
2 points

I’m sure it’s not that simple but .Net is and has been on Linux https://learn.microsoft.com/en-us/dotnet/core/install/linux

Docker images I have run dotnet in a container but the docker server host is Ubuntu. Though I really should flatten it and run it on proxmox.

However, it’s not like that would save real dollars on licensing we have Windows servers still for AD et. al. and therefore have to license all CPU cores in a hypervisor cluster so having fewer windows servers is irrelevant in our environment with regards to license costs.

permalink
report
parent
reply
3 points

I feel ya man. I spent a year arguing for the existence of a pilot environment.

Because when you test in production, it’s bad, mmmkay.

permalink
report
parent
reply
3 points

Oof that’s a rough one indeed!

permalink
report
parent
reply
30 points

permalink
report
reply
19 points

Me: “Hey whats that feature we need to implement into our software?” Boss: “Ntlm passthrough” Me: “… Hey boss about 90% of the stuff i find online is about how ntlm is insecure and should be shut off wherever you see it?” Boss: “Yeah… But everyone still uses it everywhere. Just implement it and dont think about it.”

permalink
report
reply
15 points
*

I’m an IT sub roundabout working for the US government. We’ve a multi-site contract and arrive at the one we’d been vaguely warned about: Some contractors got fired mid-job in the 90s and left some trash.

The hallway we needed to go down was filled with all sorts of shit, waist deep, for about twenty feet. My co-worker and I put on some gloves and started making a path. We found just a little had fallen on a path made by those that came before us.

About halfway through the hallway trash I see a small, solid green light reflecting off the floor. After a little digging we find a beige metal half tower complete with Pentium and Win 3.1 stickers, laying on it’s side but upside down, power and network ran into what looked like a hole in the wall made with multiple blows from a hammer. It wasn’t in the documentation that we could see.

In the confusion of a vendor fuckup someone decided taking a undocumented hammer to the rules best served society. Everyone who saw it afterwards decided to keep their mouth shut. We favored past wisdom and present uptime. We buried the twenty five year old rig again, hiding it from view while ensuring good air flow.

permalink
report
reply

Cybersecurity - Memes

!cybersecuritymemes@lemmy.world

Create post

Only the hottest memes in Cybersecurity

Community stats

  • 400

    Monthly active users

  • 79

    Posts

  • 1K

    Comments