• picnic@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 days ago

    We have done this, and it took years.

    We audited every exe and whitelisted like majority with over 50 users. Some occasional victims here and there (I lost access to my self compiled ones, too) but overall no THAT signigicant rise in ticketing

    • IrateAnteater@sh.itjust.works
      link
      fedilink
      arrow-up
      8
      ·
      6 days ago

      I do industrial controls. The software we are forced to use is usually proprietary, sometimes old, and always very poorly written. Plus there’s the networking issues. A huge amount of stuff is just statically addressed, so I might be switching the ethernet port on my laptop from an 89.89.x.y subnet, to a 10.10.i.j subnet, to a 192.168.a.b subnet, and back again multiple times a day. When IT first took admin rights off our laptops, it took away our ability to change IP addresses. There may have been some small amount of malicious compliance.

      • mojofrododojo@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 days ago

        approximately how many windows XP instances running CNC shit do you support?

        seeing these in the wild blew my mind

        • IrateAnteater@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          ·
          5 days ago

          Haven’t come across many of those, since we tend to do small to medium sized production line type machines, as opposed to individual CNC stuff. That being said, it is wild how hilariously insecure everything is.

          • mojofrododojo@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 days ago

            it is wild how hilariously insecure everything is.

            yerp. I get it, who wants to throw away a machine that costs $120k because there’s no modern software to run it, but holy hell…