Zero Trust Architecture
Zero Trust Architecture

Zero Trust Architecture

Guys a madman, didn't even ask for a ticket.
Allowing children on roblox is negligence at this point so I think this is unironically in the right
Deleting Roblox and installing Factorio
You'll thank me when you're older, kid.
The factory must grow.
Older? Poor kid might forget to eat or drink water if you get him hooked on Factorio
Paying for Factorio and letting their engineering career pay for your retirement home is way cheaper than saving for retirement!
I refuse to allow my own child on it. It takes zero effort to see all the super shady shit happening there. I wont have my child exposed to that crap.
I played Roblox with my kids for years and didn't find any shady shit. Not saying there is no shady stuff on there, but after 100s of hours either it's suddenly gotten worse, we somehow dodged all the shady shit or the media have exaggerated the issue. Take your pick.
I played with my kids because they desperately wanted to join in on the fun but the reports of it being pedo land made me create a rule of "you only play when we play together". We had great fun, have many fond memories of our time on there.
My sister-in-law let her 10 year old daughter play it with zero supervision. When we found out we told her she should be watching what her daughter’s doing so she went in to check and found the kid talking to some grown man from Azerbaijan.
The American use "ironically" is probably the only difference between our dialects that I'll stand firm on.
My friends, we already have a use for the word, and it's not this!
I'm all about linguistic innovation, but using "unironically" in place of "seriously" and "ironically" in place of "sarcastically"/”not seriously" is not happy times for me.
Unless you give me a new word for irony.
I quite like y'all, I use that all the time, not against Americanisms in general, just this one.
To me, the original post was riddled with "verbal" irony - they were saying things whose words meant one thing but the overall post was actually making fun of the ideas the words were presenting.
My comment serves to state that I agree with the point the words are making and not the meaning through the lens of irony. Ie, unironically.
I respect the pushback though. I have similar gripes with "sarcasm" being used when "irony" is correct and vice versa.
hey don't blame us, we learned it from the brits
The real question is : Why did you invite anyone over, before having a guest VLAN set up ? Classic beginner mistake.
I have two seperate guest VLANs, one for my family, and one for the people I love.
Whatever happened to just talking to each other? I'm glued to my devices all day every day, yet even I ignore the phone during holiday family gatherings.
Nobody's forcing you to go; if you prefer be on the internet rather than interacting with your family, please just stay home.
Edit: Downvotes be damned, I stand by what I said. If this asocial shut-in who hasn't had a friend since 2014 (because people annoy me) can come out of my shell a few times a year, and spend some time with the people I grew up, so can you. No excuses.
One day they will all be dead or estranged, and you will regret not looking up from your phone for two hours to spend quality time with them when they were alive and in your life, as you die alone in your nursing home (assuming you're rich enough to afford assisted living, that is). Don't say you aren't warned.
Sounds like the network people at my company. They are asking us to spend more time in the office, but they don't provide enough desks, they don't provide working wired LAN and they only provide semi-working Wifi. All with proxies that don't work and filters that don't let me access the webapp I am supposed to maintain, which is blocked for "being a commercial website". Thanks, I know, I have to program that crap.
I've only ever met two types of IT professional. Either:
Or:
“Everything I do at work, I try out at home first.”
Absolutely no fucking way! And anything that touches work is isolated, their opsec sucks so much they didn't even realized they mandate "security solutions" with known backdoors.
I think it means they setup new tech on their homelab to learn how everything works and how to break it. Then when a problem arises where one of these solutions is needed at work, you can implement it without any large issues. It makes sense if your hobby is close to or adjacent your day job, and you are on Salary, and your boss treats you right.
Our opsec is pretty well managed, but I try to squeeze anything I'd need at home to work tasks. I get paid to learn the stuff at work and then I can just implement it on my own environment.
Isn't this basically just rich IT guy vs poor IT guy?
No, it's 'my life is IT and i never stop working" guy, and "IT is just my job" guy.
I just order a new router on Black Friday to replace my 10 year old one. I also only console game now because PC gaming is too much of a headache. I spend my money on outdoor gear and pets, not technology. My new router is $90 bucks. I can't fathom why I'd ever need a wifi 7 quad band router with 9Gbps of throughput for a home network, other than pure bragging rights. All my devices are like 5-10 years old and barely support wifi 6 anyway.
A couple of my co-workers are the former. They will be doing penetration testing at 2am form their home lab in the morning because they their default mode is work work work. If i'm up at 2 am i'm watching TV and snacking.
I monitor security updates, but my co-workers like get excited and ramble on anytime a new patch/attack is documented. I don't get it. They revel in doing updates and rebuilding their VMs fresh every few weeks, I groan and clone.
Nah, I could afford nice shit but I'm still using a ubiquity edge router 8 from 10 years ago.
There is probably something to be said that there is an in between to those two extremes. The "my network is made of a Hodgepodge of shit my employer threw out that still seems to work and brand new things I replaced because I had to"
The guy she tells you not to worry about VS you.
I'm in the meme. In the shitty paragraph.
Are you my boyfriend/roommate?
Edit: he and I are both IT folks, but he handles all the Windows issues in the house. I handle Linux issues. He handles the router because it's closer to his desk so it's easier for him to threaten.
I want to be the first, but I am definitely closer to the second. I'm trying to find a reasonable middle ground.
Like, I want to have a nice home network with a proper NAS, Pihole DNS, Plex/Emby/Jellyfin media server, all my music properly tagged, little mediaplayer/emulation/game streaming endpoint boxes on each TV, etc. But I don't have the time or money to do it right at the moment.
So I have my desktop set up to share out my media folders as SMB shares when it's powered on, and I've used a few tools to get my video content organized right for Kodi. I've got Kodi installed as an app on the Xbox Series X plugged into the family room TV. The other TV has a Chromecast dongle with VLC sideloaded and set up to connect to the SMB shares, because I'm too lazy to get my Kodi setup on it. Every room in the house has an ethernet port, and most rooms have a dumb switch so as much hardware can have ethernet connection as possible. I've run my music collection through MusicBrainz Picard, and separated it into a properly tagged and organized folder, and one for stuff that isn't.
I used to be the first, but because of a shitty landlord I was forced to move, and I only had 30 days to find a place. I bought a house because no one would rent to me with a large dog and she’s been with us for 10 years now.’my homelab is sitting disassembled in the basement with nowhere to even plug it in, because in order to get an outlet wired I’d have to replace my entire breaker box which is probably hanging on by a thread. I’m too house poor to even consider getting the work done over paying the bills I need to and providing my kid with food and clothing.
The place is nice enough and my family lives well, but I was the first guy and now I have to be the second guy for who knows how long.
In other words; fuck landlords
Well I sit kind of between these
Like I'm not getting a dedicated router and have no server room in my apartment, and my consumer router only supports two VLANs (main and guest). But I'd say the rest is rather sophisticated with all machines defined in my NixOS config, including automated generation of firewall and reverse proxy rules for which I wrote custom modules.
Media server isn't super full but connected to jellyseer and the rest of the stack, accessible over TLS (Let's Encrypt certificates) only, with the option to have users managed via IDM.
However, I only have devices on my network that I somewhat trust, with an Android TV box being the worst offender. The smart TV was never connected to my network.
Would be cool to isolate my work PCs somewhat (I work from home with company provided equipment) but it's just not worth the trouble in my opinion. Not switching out a low power device that does most for two different devices that both use more power (since you usually need a router and a modem).
I'm in the middle. At work, I play it fairly conservative, applying well established solutions to well-known problems.
I have friends whom I advise and assist with their networks that absolutely fall into the first category.
MY network is is like the lab of a mad scientist, everything tinkered with right up to the edge of breaking. My home router collapses multiple times a year due to the wonky chaos I ask it to do. Home automaton sequences that are more complex than most rube goldberg machines. Metaphorical sharp edges and loose clutter everywhere, but an unholy abomination that works better than it has any right to - until I scrap it all to rebuild it from scratch next week.
I spent way more time than I care to think about figuring out how to get my porch lights to come on at 7am and turn off 10 minutes before sunrise without breaking when sunrise happened before 7am. I tried some serious Rube Goldberg nonsense in multiple iterations, until finally I decided to just add another "turn off the lights" at 9am every day. Most of the time it doesn't do anything because the lights are already off, but on DST day it accomplishes my goal of making sure they don't run all day, since 9am is always after sunrise.
I'm almost the first (I run multiple VLANs and SSIDs using pfSense and Ubiquiti hardware) but my server is an old PC sitting under my desk and my cable management strategy is mostly "out of sight, out of mind". I'm also heavily invested in the Apple ecosystem, especially for smart home stuff, so not everything is open source. Basically I have a complex network setup because I actually make use of it, but I really don't enjoy working on it and if there's an easy solution, I'll go for it.
For the smart stuff: HomeAssistant
I work on this shit daily... it's fucking infuriating...why on God's green earth would I want to spin up a bunch of shit that's gonna give me more hassle than its worth, for free, when I can just...not, ya know?
I'll take option 2
For all the AI hate on this website y’all couldn’t figure out this was written by it? This is ChatGPT in particular.
Or, wait, are you saying that my original comment that you're replying to is ChatGPT? Because...lol, sadly, no, I'm just like this. "This" meaning pretty much everything I write is way too overwrought.
Or just copypasta.
I figured it was made up ("@it_unprofession" probably ran out of content ages ago), but it doesn't look like actual AI content to me. The sentences are too short, for one thing.
"Are you nuts kid? We don't use wifi around here. I unsoldered the antennas of my router, just in case."
Fake! The AP is separate from the router!
Imagine having a router with an AP built in. We don't use that consumer tier stuff around here. 😎
I’m very against Roblox. I know a kid who had a really hard time with online predators and a lot of it stated with Roblox. He’s 19 now. He and I were talking about it recently.
Parents think Roblox is like Minecraft bc of the aesthetics of the game. But, Roblox is not a game with a chat feature, it’s a chat room with some games. That’s a big difference.
They have 380 million users. Around 60% of the user base is under the age of 16. 40% is under the age of 12. That’s 152 million mostly unmonitored kids.
I’m sure Roblox has gotten better moderation during that time, but in our experience predators meet kids on Roblox and get them to exchange Discord or other contact info with them.
Discord is also a problem here, but that’s for another rant in another thread. If you are concerned about your kids and want to discuss it with me, feel free to message me.
TLDR: DO NOT LET YOUR KIDS PLAY ROBLOX unless you are actively monitoring the game.
I’m sure Roblox has gotten better moderation during that time
Quite the opposite.
https://en.wikipedia.org/wiki/Roblox%E2%80%93Schlep_controversy
And here too! https://consumerrights.wiki/w/Roblox
Don't forget the child labor aspect. https://www.theguardian.com/games/2022/jan/09/the-trouble-with-roblox-the-video-game-empire-built-on-child-labour
The whole company is gross. I forgot about this.
A friend's 8 year old daughter was asking to play Roblox recently and they reached out to me since it's in my current area of study and advised them against it due to the lack of responsibility that the corporation takes for their users.
I suggested that they introduce her to Vintage Story on a self hosted server instead. That way, they can control who has access and content.
I'm actually surprised at how many parents let their kids play Roblox unmonitored. I mean, why not let them go to the playground unmonitored instead?
why not let them go to the playground unmonitored instead?
That would actually be the safer option imo.
Vintage Story
Bro threw them straight into the deep end lmao
I encourage parents to talk to their kids about online safety but specifically come up with a plan. I’ve written this in a few comments, but u really believe it helps.
Ask them what they do if a stranger says something that makes them scared or uncomfortable. Ask them what they would do if it’s someone they know like a friend or a family member. Help them come up with a plan and identify a person who is a safe person to tell. Someone parents and kids trust, often it’s an aunt or uncle.
A parent is fine too, but at a certain age, I find kids seem to be afraid of getting in trouble or maybe just uncomfortable talking to their parents about sex, so having a 3rd party that the kids and parents trust is a good back up option.
why not let them go to the playground unmonitored instead?
It's highly likely there is no playground.
Do you have any idea how many removed about you NOT letting them go to the playground unmonitired
The younger kid's chat is disabled. not allowed to friend anyone.
The older kid has chat enabled, but is only allowed to friend people we vet.
Computers are in an open area, chats have been keylogged, we check occasionally.
If friends show up unanounced, or they chat where they're not supposed to, they lose internet access long enough to regret it
When they get old enough to have friends online, we contact the parents, make sure they're compatible politically, theologogically, just generally not extremists and their kids have some base level of dicipline and are safety minded.
We also semi-regularly play with them and set rules about the appropriateness of the games in relation to the kids ages. The younger one's don't get to play the violent ones.
Crazy, but it's almost like parenting can make the environment safer!
Lemmy likes to portray Roblox the same way the 10pm news portrayed the Internet when I was in my preteens and teen years, like it was the wild west, everyone was a predator, etc. I let my kids hop on. Their friends include me, their mom (who has an account for some reason), each other, and the kids who live across the street. They like to play the platformers, and they invite me sometimes and we play them.
They'll get older and they'll go explore the internet the same way I did. I spent my adolescence and teen years eventually in AIM chat rooms, then forums, and thn Skyping random people, and somehow didn't become a terrorist, didn't get predated. I also am of the school of thought that you need to learn things on your own, rather than have no exposure to things that could potentially be bad.
Making sure the parents of your kids friends are compatible politically and theologically sounds incredibly dodgy to me.
I will say this as well: strict parents raise sneaky children
Bc of what I went through with my ex’s kid, I talk help parents talk to kids about online safety. It’s good that you are so proactive!
The #1 thing I see parents miss in those safety talks is coming up with a plan when something bad happens so kids know what to do.
I spoke to my 14 year old niece last weekend. She wants to use Snapchat but her parents said no. I asked her what she would do if she got a dick pick from a stranger. I asked her what she would do if her boyfriend sent her one. Various situations like that.
She didn’t know what to do, so together, we came up with a plan and identified an adult in her life that she would feel comfortable talking to that isn’t her parents. A third part adult that you and your kid can trust is helpful for kids that are afraid to talk to their parents and get grounded.
For example: if your kid is online after they got grounded and something bad happened, they might be afraid to tell you since they weren’t suppose to be online, but maybe they’ll be okay speaking to an aunt or uncle.
Every situation is different
we contact the parents, make sure they're compatible politically, theologogically
This is insane. You call that kid’s mom to ask who she votes for and what name she uses for god, and if it doesn’t match yours, kids can’t have fun?
Simple solution: log the kid into your neighbor's wifi.
As an early teen my parents turned off the WiFi router at night and when not in use. I eventually found the neighbor had an exploitable WEP router from an Android app, and I used it to continue watching Minecraft and Happy Wheels videos on Youtube.
My son did this...
Yeah, there’s the old “strict parents make sneaky kids” saying that is often very true. Parents who try to lock down their tech often find that kids will just bypass the tech entirely. Nothing is more singularly motivated than a 14 year old who wants to look at tits, and locking it down only encourages them to do shady shit like get a secret prepaid phone, or hack the neighbor’s WiFi.
Not possible, neighbor implemented Negative Trust.
Guest vlan? Smart.
Blocking 80/443 knowing all to well everything depends on those: evil.
Throttling to 56k: the original original poster just being a dick.
Took 45 minutes: Maybe find another job. You're not good at it.
Conclusion: The sister was right. Evil incompetent dick.
Took 45 minutes: Maybe find another job. You’re not good at it.
Bit harsh.
The OpenWRT guest wifi guide isn't a simple switch like you would get on your OEM router, but involves manually setting up a bridge device, a new firewall zone, and a new AP on one of your radios.
This can take some time if you want to do things the right way. 10 minutes to setup with no extra config steps. Add another 10 if you need to move around your firewall rules, and another 20 for random debugging.
https://openwrt.org/docs/guide-user/network/wifi/guestwifi/configuration_webinterface
Although, you set it up once. After that it's just a checkbox.
and of course you need to tag the new network on all your switches, routers, APs... not to forget testing and integration in your monitoring system. 45 minutes is absolutely fine.
I have a feeling this is satire, and I'm usually the type of person to miss the joke and think it's genuine
Even if it is satire, doesn't mean we can do a full breakdown, especially for comedic value.
I mean fuck me, i can build an entire bespoke DDU from bare metal to cool down in less time than that.
45 minutes setting up an alt vlan?
Was he getting paid by the hour?
The experience of managing a consumer-grade LAN appliance:
Open web browser
Start typing 192.168.0.1
It auto-inserts 192.168.0.12 because that's the IP address of your NAS, and you've logged into it to adjust something at some point in the last six months. You register it has done this as you're releasing the Enter key.
click Back.
Type the IP address again, this time carefully deleting the 2 it oh so helpfully inserted.
Wait 3 to 5 business weeks while the 16-bit ARM microcontroller they put in these things serves a web page like old people fuck. It loads to a completely useless stats page that has no information that anyone has ever needed to know.
Click LAN Setup.
Wait 3 to 5 business weeks while the 16-bit ARM microcontroller they put in these things serves a web page like old people fuck.
Parse the wall of acronyms before you, click the link that says DHCP.
Wait 3 to 5 business weeks while the 16-bit ARM microcontroller they put in these things serves a web page like old people fuck.
It continues in that fashion until you get what you need done or your network stops working and you have to get a pen and press the Reset button on the back of the device.
IT professional doesn't have local DNS? LOL
Imagine not having an opnsense firewall deployed as an IT professional
Wait 3 to 5 business weeks while the 16-bit ARM microcontroller they put in these things serves a web page like old people fuck.
This also goes for some NAS appliances and the in-dash console of newer cars. Underpowered ARM implementations are the scourge of this decade.
It auto-inserts 192.168.0.12 because that's the IP address of your NAS, and you've logged into it to adjust something at some point in the last six months. You register it has done this as you're releasing the Enter key.
I avoid this by having my router interface on 1) a double digit IP. And 2) a non-standard port
What idiot IT specialist does not run a segregated VLAN for guest wifi access? That is just rude.
A broke one.
And separate wifi networks that are connected to different vpns from around the world.
Probably because it was Roblox and an iPad
If it was a Nintendo DS and Pokemon Black 2 you could have never been able to deny peak
The DS would not be able to connect to OP's network to begin with.
DSi and 3DS support WPA 2, but games must be DSi Enanched to go online on WPA/WPA2. DS and DS-only games support only WEP.
To play online my DS games I have a guest network with not broadcasted SSID and no password, but only allows my DSLite, DSi and 3DS's MAC addresses to connect one at a time and has its very own subnet. Not too secure, yeah, but it's all I could do on my home router.
What's the issue with the security posture of iPads you are implying?
I like the Nintendo DS and 3DS systems of consoles
Gotta have the GTS access
Ok but 56kbps is just evil
It's only considered evil if it doesn't also produce dial-up noises.
But since op didn't clarify, let's just assume evil.
eh, when the landlord moved a business into their house and expected me to keep providing IT for free, but also for the business: I rate limited them to 5kbps. just enough to say it has internet, not fast enough to use the internet without timing out on every page. I got paid the next day.
We're missing the most important rule here. Did the nephew open a ticket?
Lol wtf? Why even spend 45 minutes doing that if you're going to completely block those ports?
Just tell him "no".
"oh I'm trying to fix it just give me a few more minutes away from everyone" lights joint
It's about sending a message.
Throtting and port blocking is for housemates who pissed you off, not nephews.
Wouldn't it be enough to just create a seperate subnet?
Yeah that's where it turned from story to joke for me
They’re specifically talking about Zero Trust though and treating it like a corporate device as the joke. This means authenticate at every layer, RBAC, and endpoint security compliance before allowing access to a service. Putting the device into an isolated guest VLAN works too of course.
Thats all I do.
Separate SSID, goes right into its own little hellscape with no access to anything but the internet.
And a small 8 port switch for a hardwired guest option. But thats not lit until its needed.
Yeah, he did that...and then kept going for some reason. A separate subnet in a separate firewall zone that doesn't forward anywhere but the internet should be sufficiently safe
Not for the kid.
Which actual IT guy supports antivirus?
Ohh fuck yes, I support antivirus, but only on Windows, maybe, possibly OSX. If you give bare Windows to a kid, they'll have viruses as soon as they learn to use Google.
TBF, Fam gets my guest network. It's not allowed to touch anything in my house, they can only route through. DHCP sends their DNS to 4.2.2.2 and 8.8.8.8, They can't even touch my DNS, they can't see any of my home automation and they can't see each other. They can push the connection as hard as they want, the QOS won't let them take priority.
For my son I just used APLs in group policy. Only approved apps could run. I encouraged him to be better than me and he has definitely kept me on my toes. Now he is in college for cyber security and loving it.
So far he hasn't broken anything major on his computer or the network, well, aside from messing up his BIOS a couple times... But then he got to teach me how to program EEPROM (like I said, he has kept me learning stuff I normally wouldn't).
Lol generally I'll refer to the OS builtin tooling (XProtect/MS Defender) and EDRs as "Antivirus" otherwise the non-techies will freak OmG wE hAVe NO aV! And then the "anti"-viruses like mcafee and Kaspersky mysteriously spawns
And also on-demand AV software can be good for spot checks or if you're sus of something.
It's the "Real-time" shit that hooks into the kernel that needs to be avoided like the plague
When i was a windows person many moons ago i ran into viruses once or twice. Kaspersky was the only av in those days that effectively cleaned them from my system.
Now i am a linux dude. Where there doesnt really seem to be an effective antivirus solution because, even though malware exists, it's so fucking sophisticated and stealthy you may never know it.
I legitimately can't tell if this is a joke or some dude trying to do a humble brag post on LinkedIn. So many 'look what I can do' posts on that damn site.
No one that serious about network security wouldn't already have a network dedicated to untrusted devices relatives could use. Definite joke, still entertaining 😂
LinkedIn is Poe's Law for corporatism made into a lifestyle.
I'll admit it. I can feel that vibe and I don't totally disagree.
Kid should be learning social skills at a family party.
As a former kid struggling with social skills, I think that would've done me some good. It's easy and convenient to fall into avoidance behaviour, but overcoddling did me no favours.
I was told overcoddling reduces resiliency. Parents always coming in to fix things without letting their kids try to solve it on their own. The kid may fail but the act of trying and figuring out why it failed helps greatly. Most parents just "don't want to see their kids upset" though.
Take it with a grain of salt, as I don't have any kids.
Same, my parents pushed me into socializing, which i HATED at the time. I know it helped.
This reads like a classic LinkedinLunatics post and I love it. Great parody!
He is doing the right thing if only because he is preventing a child from playing Roblox.
He'd be a hero if he gave him a copy of Minecraft (or really almost any non-F2P game) to play instead.
Vintage story!
wth is the point of a guest network if you have 443 blocked lmao.
Even my VPN port is 443 so it gets past basic port filtering because HTTPS is usually the only one allowed compared to other protocols.
My guest network is restricted to TFTP only if you know what I mean.
This reads like a parody greentext except you know OP is a sysad so there's no fucking way he's that self-aware
I'm 95% sure this is parody because if it was real there's no way this person's family would ask them to host Thanksgiving. And nobody blocks 443 on a guest wifi.. that'd block everything they'd even need the guest wifi for.
45 minutes to setup a guest wifi?
First time had to google the manual for the router he doesnt know the model # or how to access
This is very easy on a consumer router and more difficult on an enterprise router.
It does seem to imply the person has some experience with those though so 45 minutes still seems like a lot.
Yeah, that's where the 'IT professional' lost me.
\
(They might have a complicated setup with everything overly managed ... but this is just a new vlan, unrelated to anything ...)
Not to mention you might want to have one for test purposes anyway.
Also there are alternativnes, like mobile data via phone hotspot.
Or giving a kid to play some horror game on your gaming rig.
Or saying you don't have wifi, wired net only, why didn't they bring an ethernet dongle??
what a dick move tbh. i get ya wanna be secure, but why not just let him do his thing on that alternate network?
guess this is satire. zero trust and byod mix well, just isolate from your shit and you are done. block port 25 outgoing and known c2 IPs to not taint your IP.
But zero trust means you don't have to have a perimeter
This is just Uncle BOFH.
Fuck you with your ISO 27001 compliance!
Also, fuck that kid.
Also, fuck that kid's mother.
She's the enabler here.
What, this bish doesn't even have a wifi hotspot?
The unprotected device on his hotspot!? Sure if you want to throw caution to the wind.
How about running guest WLAN?
At a time I didn't have wifi, I would not share connection with younger guests. There was no way I would use my phone to connect to internet the bloody smart tv in the heart of our share living room. Never done it in my life, so I was not lying when I saied I didn't knew how to do it. If you Come to visit me, visit me not my game console or my streaming service.
I wonder if this was the same person who was on asklemmy or whatever saying "what can I do to convince my loved ones of the importance of data privacy"
Classic BOFH.
I couldn't imagine bringing a gaming device to a family Thanksgiving celebration and insisting on being able to use it instead of socializing with the people physically there.
It was either that or sit in a corner dissociating to survive holidays with my family.
Very boomer answer.
Most kids don't want to socialize with family more than they have to. Even before the gameboy, they would bring coloring books and puzzles to get through the day on their own.
first misake was giving him the wifi password.
Are guest networks not secure enough?
I feel like when 'Zero Trust' first became a thing, the theme was 'you should have every endpoint under your control hardened so it need not feer untrusted peers being able to connect'. E.g. if you think you absolutely need VPN to a 'private network' for security, then you are failing to be hardened in a 'zero trust' way, because you implicitly fear that your systems would fall to untrusted peers.
I feel like it's evolved to 'don't let anything be able to connect to anything under your control unless you have admin privilege over it as well'. Which is particularly a nightmare when you try to collaborate between two companies, each balking at the other's hard requirement to have admin access to all network peers of interest.
Compliance <<<< Security
Does the concept of Zero Trust also include Management? Asking for a friend.
Is this the It equivalent of the unhinged LinkedIn post?
Beautiful
this is why he has a nephew and not a son.
Spends 45 minutes creating a vlan when he could have turned on the guest wifi and walled that off from the main network in about 3 minutes.
The blocking ports and QoS move was just funny as hell though.
Best post on Lemmy. Fuck bloodlines.
Don't do that ...
\
Does that mean the Habsburg wasn't inbred enough?
The kid started crying for not being able to play roblox?