Main Menu

Recent posts

#61
Forum Lobby / CrowdStrike Outage 19 July 202...
Last post by deanwebb - July 19, 2024, 07:58:48 AM
A gut-punch of a story. CrowdStrike pushes an update to its agent globally, wrecks tons of systems because it's broken.

Yes, I want security updates fast and furious to keep ahead of the baddies.

BUT

I also want my mission-critical servers in banks, airlines, and health care to not crash because of a security update.

 :-\
#62
Forum Lobby / Quiet Vacationing
Last post by deanwebb - July 17, 2024, 02:27:37 PM
https://www.independent.co.uk/life-style/quiet-vacation-work-remote-jobs-b2580849.html

Like "quiet quitting", but you still like your job. You just don't disclose where you are when remote...  ::)
#63
Everything Else in the Data Center / Re: AWS Fun Times
Last post by deanwebb - July 12, 2024, 02:40:23 PM
Indeed. We need documentation about what works, but if updating docs isn't a sprint activity for the devs, then it's good-bye docs, casualties of the sprint cycle.
#64
Everything Else in the Data Center / Re: AWS Fun Times
Last post by Otanx - July 11, 2024, 06:40:20 PM
Sounds like there is a misconfiguration in the IAM system. I can see valid use cases for someone that can create or write to S3 not being allowed to delete. However, I will agree with you on the lack of support from AWS. I never get responses to emails. I had two users locked out of training. Emailed support, and never heard back. Luckily it wasn't important training, and a few weeks later it just started working. If you are not big enough to have a named point of contact the team monitoring the generic email addresses seem to not exist. Same with their documentation which is what the AI support is using. They change things so fast that the documentation is always outdated.

-Otanx


#65
Everything Else in the Data Center / AWS Fun Times
Last post by deanwebb - July 11, 2024, 04:17:39 PM
"Could you please delete this S3 instance I created by mistake?"

***

THREE HOURS LATER

***

Finally found the guy that has root access with his email and he was able to log in and delete the S3 bucket.

ZERO help from Amazon's automated AI-augmented help system. It offered up code that had been deprecated and would do things bit by bit, instead of calling out a full solution. At the end of the day, none of those things worked and we had to get someone to log on as root, which was another ordeal in and of itself.

Amazon Web Services I now consider to have poor support and self-defeating security mechanisms. When the creator of an object, let alone a full admin, can't delete a simple S3 bucket that was created by mistake, there is a serious flaw in their processes and policies.
#66
Security / Re: Dave work fun
Last post by icecream-guy - July 11, 2024, 09:25:10 AM
Yes FTD coming down the PIPE
#67
Forum Lobby / Re: Beryl
Last post by Otanx - July 10, 2024, 03:16:57 PM
Forgot you were down that way. Glad you guys got skipped. I did see an article that people were tracking the power outages using the Whataburger app. Apparently the power company does not have an outage map, but the Whataburger app shows which stores are open or closed and because they are normally 24x7 they could track where the power outages were.

-Otanx
#68
Security / Re: Dave work fun
Last post by Otanx - July 10, 2024, 03:10:10 PM
My old place is finishing up their migrations. They have to do STIG instead of CIS, and they are doing ASA to Palo, but it is all the same at the end of the day. If it wasn't for those details I would guess you worked there. They had a window to do a big cut over on Saturday after the 4th. It took them a little longer than expected, but it was successful. I think they only have two HA pairs left to migrate which will close out a 2 year plus migration. Then they get to move on to the switching refresh. Both data center and access are hitting at EOL near the same time so it will be a lot of work.

Are you planning to migrate to FTD at some point? We looked at it when it first came out as the obvious replacement for ASA and it was missing a lot of features, but I heard it is much more feature complete now.

-Otanx
#69
Security / Re: Dave work fun
Last post by deanwebb - July 10, 2024, 11:53:19 AM
Oof, migrating configs is tedious stuff. Best of luck with that, hate to have to see you do it all again because of a stupid missed detail somewhere!
#70
Forum Lobby / Re: Beryl
Last post by deanwebb - July 10, 2024, 11:51:58 AM
We only had some passing showers, no storming at all. Most of it passed to the east of us.

Houston got hit hard - lots of power outages there.