Is that a pickup line? Lol
RedFox
Husband, Father, IT Pro, service.
If I ask a lot of questions, I might understand why.
- 5 Posts
- 78 Comments
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
1·2 years agoI have the older Sophos utm, which doesn’t use the Sophos cloud central manager.
I think their new firewall utm can work disconnected, but I don’t know.
Sophos has a home use license that’s free for non business use.
I love companies that do community edition or free home use.
Sophos, Veeam has nfr, Elastiflow has community edition, which is a netflow.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
2·2 years agoSorry for confusion. I use Sophos utm as a WAF for exchange. Basically reverse proxy that is specifically programmed for exchange attacks. It allows OWA to keep working.
I put the exchange admin URL behind authentication, so you try to go to /ecp, it Sophos intercepts and make you authenticate to Sophos utm first, which is passing to ad with radius.
MS got rid of intune on prem. It’s only Azure service now. I think.
My router is my biggest vuln. Oddly the most important. It’s an enterprise ISR. It’s updated as far as possible. My paranoia ends with the US gov/NSA. I don’t care if they want back door oddly. I don’t want China using me for attack relay however.
Loads of monitoring. You do a span/mirror port to your IDS like security Onion. Let it analyze all your traffic. Apparently there are some state sponsored exploits that allow them to owe a router at kernel level and hide their activities from you and monitoring, but that’s a level I can’t deal with.
As far as lock out, you create a break glass on everything. Emergency account with non rememberable ridiculous password, saved in a safe place.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
1·2 years ago- Exchange on prem 😳
- Both mdm,.Ms intune, and just installing the root cert manually in trusted store. You don’t have to root Android for that. It presents some warnings, appropriate.
- My Sophos is self contained. It does radius against active directory. It wants IPS and other updates though.
I guess the firmware is as good as possible. All network devices are just computers and can be exploited. I use a Cisco router as my actual gateway. Sophos is inline after that.
Privacy. 🤔
Not much. I have certain traffic go through a VPN to the Internet, but that’s split tunneled.
I use incognito? That doesn’t really do anything, ha.
I’m slowly killing web browser tracking and cookie stuff that group policy allows.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
2·2 years agoYour working environment sounds gross :)
IT is hard. Finding good IT people is harder in my opinion. Working for a company that is not super squared away with good security and great usability sucks. At least you found some work arounds and are trying to do it well.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
2·2 years agoHa, probably. It’s fun to learn stuff though.
Working in this field, almost every company has been beached, IP stolen, etc.
Sometimes your home IP gets hit in an automated scan for a vulnerability and then auto exploited by automation. I’m hoping not to get random chance added to a botnet.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
6·2 years agoAlso laughing because that’s how some companies get owned, IP stolen, etc.
There has to be balance, if your life using their system sucks so hard you can’t do your job or meet production marks, you get creative.
My industry has to prioritize security over productivity. It’s almost impossible to get work done.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
1·2 years agoHa yeah.
Id say the same for trellix.
You should try doing things with installs or updating apps when the edr product blocks write access to all temp locations. You have to do an exclusion for every installer, signing cert, or turn it off to install programs.
RedFox@infosec.pubto
Selfhosted@lemmy.world•What are the most paranoid network/OS security measures you've implemented in your homelab?English
121·2 years agoI’m an enterprise guy, so that’s the explanation for non home use things.
- VPN for anything not my web or certificate revocation distribution point
- Sophos IPS
- sophos utm for web application firewall
- transparent inline web proxy, sophos is doing https inspection. I have internal CA and all clients trust it. I don’t inspect medical or banking, other common sense stuff.
- heavily vlan segmented with firewall between
- my windows clients are managed by active directory with heavy handed GPOs.
- least priv accounts, different accounts for workstation admin, server, domain, network devices
- security Onion IDS
- separate red forest that has admin accounts for my management access and accounts on devices
- trellix antivirus and global reputation based file monitoring
- I’ve started applying disa STIGs on servers
- site to site VPN with other family member household. They get managed trellix av also.
- my public identity accounts like MS,.Google, etc all need 2fa, token, etc.
I bet this can still get exploited, just would take effort hopefully none does for a home network.
I’m still one shitty windows zero day click away from getting my workstation or browser tokens owned though, I can feel it.
RedFox@infosec.pubto
Technology@lemmy.world•The U.S. economy is booming. So why are tech companies laying off workers?English
71·2 years agoThis corporate cycle isn’t likely to change anytime soon right?
Top tier corps, boards, Cs, ultimately care about share price and growth right?
Isn’t it tied to their pay incentives? To keep their contracts and incentives, they have to grow or reduce costs.
They make bad choices or bets among the way, no problem, just reduce costs and still meet the metrics. Only people who pay seem to be the workforce, right?
Or am I oversimplifying?
RedFox@infosec.pubto
Technology@lemmy.world•The U.S. economy is booming. So why are tech companies laying off workers?English
11·2 years agoI think that’s synonymous with “all hail the shareholder”
RedFox@infosec.pubto
Selfhosted@lemmy.world•How to properly setup local certificate authorities for sub domains?English
1·2 years agoOne of the keys to selecting the solution from the provided answers is if you need this to be publicly trusted.
I use an internal openssl ca root, created intermediate ca for each active directory domain or Forest. Also, I wanted to create internal PKI smart cards with yubikeys and his c1150 cards. For you know, fun.
I didn’t care that other hosts don’t trust my stuff because all my hosts are configured with root ca, and I only use VPN for access.
You want external trust, must do some of the other suggestions. Setting up internal CA is a chore with understanding AIA, CDP points, line of sight to PKI urls for renovation checking, more…
RedFox@infosec.pubto
Selfhosted@lemmy.world•Feedback on Design and Firewall OptionsEnglish
5·2 years agoI recommend look into managed, vlan capable switches after you get your firewall figured out. That will allow you to put hosts on different vlans and separate lab stuff from the rest of your home network stuff.
There’s a million videos.
RedFox@infosec.pubto
World News@lemmy.ml•Palestinians accuse Israeli forces of executing 19 civilians in Gaza
14·2 years agoWhat makes you believe one side’s propaganda over another? Both entities have incentive to illicit sympathy?
RedFox@infosec.pubto
World News@lemmy.ml•Palestinians accuse Israeli forces of executing 19 civilians in Gaza
25·2 years agoRemoved by mod
RedFox@infosec.pubto
World News@lemmy.ml•A Louisiana teen traveled to the West Bank to learn about his roots. He was shot dead.
211·2 years agoI can’t imagine the pain and bottomless hatred I’d have if my son was killed in a war, but the name thing keeps me from wanting him to travel anywhere that might be a war zone.
Well, anymore than random places in the US already is…
RedFox@infosec.pubto
World News@lemmy.ml•A Louisiana teen traveled to the West Bank to learn about his roots. He was shot dead.
91·2 years agoGenerically, sure. Seems like some highly complex social issues, religion, and hate might have complicated things…
RedFox@infosec.pubto
World News@lemmy.ml•US forces strike Houthi sites in Yemen as Biden says allied action hasn’t yet stopped ship attacks
189·2 years agoHey, the navy needs to keep their button pushing skills sharp /s



I know this isn’t what you’re looking for, but I got a family plan from Google for music and split it with 6 family members, which is probably the same as apple music I assume.
I don’t have to mess with download anymore.
Lidarr is only one I know.