<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://sobac.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Network_Security%2FMeeting_Notes_2019-03-11</id>
	<title>Network Security/Meeting Notes 2019-03-11 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://sobac.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Network_Security%2FMeeting_Notes_2019-03-11"/>
	<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;action=history"/>
	<updated>2026-06-14T20:53:43Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.0</generator>
	<entry>
		<id>https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2322&amp;oldid=prev</id>
		<title>BobJonkman: Link to pfSense</title>
		<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2322&amp;oldid=prev"/>
		<updated>2019-03-25T10:08:23Z</updated>

		<summary type="html">&lt;p&gt;Link to pfSense&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 10:08, 25 March 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l67&quot; &gt;Line 67:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 67:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;/div&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* [https://www.pfsense.org/ pfSense® - &amp;quot;World&amp;#039;s Most Trusted Open Source Firewall&amp;quot;]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class=&#039;diff-marker&#039;&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>BobJonkman</name></author>
		
	</entry>
	<entry>
		<id>https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2321&amp;oldid=prev</id>
		<title>BobJonkman: New Page</title>
		<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2321&amp;oldid=prev"/>
		<updated>2019-03-25T09:59:45Z</updated>

		<summary type="html">&lt;p&gt;New Page&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{:Network Security}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Resources ====&lt;br /&gt;
* Firewalls&lt;br /&gt;
** The most secure firewall: [[File:Nipper for Electronic Wire (Old).png|150px]]&lt;br /&gt;
** Another secure firewall: [https://www.pfsense.org/ pfSense]&lt;br /&gt;
* Intrusion Detection Software&lt;br /&gt;
* Pen Testing apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* [https://www.techsoupcanada.ca/en/directory/361 TechSoup Canada Catalogue: Server and Network Management]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Claim: The greatest threat in Network Security is NetAdmin or User Error&lt;br /&gt;
** [[File:Network Security Dave.jpg|640px]]&lt;br /&gt;
** Another e-mail breach caused by human error:&lt;br /&gt;
*** [https://www.cbc.ca/news/canada/kitchener-waterloo/university-waterloo-data-email-breach-information-quest-1.5048814 Names, banking information accidentally shared in emails to University of Waterloo students | CBC News]&lt;br /&gt;
** Data exfiltration due to user error:&lt;br /&gt;
*** [https://www.thestar.com/politics/provincial/2019/01/21/privacy-breach-hits-45000-recipients-of-ontarios-disability-support-program.html Privacy breach hits 45,000 recipients of Ontario’s disability support program | The Star]&lt;br /&gt;
** NetAdmin failed to renew expired domain names:&lt;br /&gt;
*** [https://arstechnica.com/information-technology/2019/01/godaddy-weakness-let-bomb-threat-scammers-hijack-thousands-of-big-name-domains/ GoDaddy weakness let bomb threat scammers hijack thousands of big-name domains | Ars Technica]&lt;br /&gt;
** Vulnerability not acknowledged by vendor:&lt;br /&gt;
*** [https://www.cbc.ca/news/canada/new-brunswick/cyber-malware-breach-dark-web-municipal-parking-servier-click2gov-centralsquare-1.5043818 City knew of massive cyber breach days before admitting it | CBC News]&lt;br /&gt;
*** &amp;lt;blockquote&amp;gt;On Dec.19, the day following Solomon&amp;#039;s exchange with Caissie, the city received notice from CentralSquare Technologies, the Florida company providing the Click2Gov parking server software, that there was no problem with the system. &amp;quot;Resolution: Checked Click2Gov server for evidence of malware/possible breach, no evidence found of breach/malware,&amp;quot; says the statement signed only &amp;quot;Customer Support.&amp;quot;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
** Pre-emptive shutdown of mail system to prevent a virus attack that might shut down the mail system.&lt;br /&gt;
&lt;br /&gt;
==== Meeting Notes ====&lt;br /&gt;
Spoke about resources, war stories&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Proprietary mail systems&lt;br /&gt;
** Errors in implementation, makes mail inaccessible, or sends mail when unwanted.&lt;br /&gt;
** Corporate culture prevents people from speaking of security flaws&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bugs in the software&lt;br /&gt;
* Errors in procedures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== The Cloud =====&lt;br /&gt;
* &amp;quot;If the data was in the cloud it would have been safe&amp;quot;&lt;br /&gt;
* What is The Cloud?&lt;br /&gt;
** Somebody manages the servers, still subject to human error&lt;br /&gt;
** But reduces the human interaction that is needed&lt;br /&gt;
** Maybe if &amp;#039;&amp;#039;&amp;#039;everything&amp;#039;&amp;#039;&amp;#039; is run by robots...&lt;br /&gt;
*** But that&amp;#039;s not the way Nonprofits operate, engaging people to be more involved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Open Source groups want more interaction, so still room for error&lt;br /&gt;
** eg. LibreOffice: Get a professional to manage website? Or keep local group involvement?  No to robots&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Robots have programmers too&lt;br /&gt;
** One more level of abstraction&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Problems solved?&lt;br /&gt;
** Email spoofing, phishing schemes: Joe Jobs, third-party addressbooks breached&lt;br /&gt;
** Could contact the apparent sender, but that person may not be involved in the message at all&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Tour of pfSense ====&lt;br /&gt;
&lt;br /&gt;
Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Multiple connections to isolate traffic =====&lt;br /&gt;
* While Bob&amp;#039;s installation has only two connections (WAN, LAN), it is possible to isolate Internet-facing servers on their own network connection (DMZ) to isolate that traffic from the internal LAN. &lt;br /&gt;
* pfSense supports many network connections, useful for separate campus sites&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Back to: [[Network Security]]&lt;br /&gt;
&lt;br /&gt;
[[Category:KWNPSA Meeting Notes]]&lt;/div&gt;</summary>
		<author><name>BobJonkman</name></author>
		
	</entry>
</feed>