<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://sobac.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Network_Security%2FMeeting_Notes_2019-03-11</id>
	<title>Network Security/Meeting Notes 2019-03-11 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://sobac.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Network_Security%2FMeeting_Notes_2019-03-11"/>
	<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;action=history"/>
	<updated>2026-04-12T04:51:48Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.0</generator>
	<entry>
		<id>https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2322&amp;oldid=prev</id>
		<title>BobJonkman: Link to pfSense</title>
		<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2322&amp;oldid=prev"/>
		<updated>2019-03-25T10:08:23Z</updated>

		<summary type="html">&lt;p&gt;Link to pfSense&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revision as of 10:08, 25 March 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l67&quot; &gt;Line 67:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 67:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* [https://www.pfsense.org/ pfSense® - &amp;quot;World's Most Trusted Open Source Firewall&amp;quot;]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>BobJonkman</name></author>
		
	</entry>
	<entry>
		<id>https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2321&amp;oldid=prev</id>
		<title>BobJonkman: New Page</title>
		<link rel="alternate" type="text/html" href="https://sobac.com/mediawiki/index.php?title=Network_Security/Meeting_Notes_2019-03-11&amp;diff=2321&amp;oldid=prev"/>
		<updated>2019-03-25T09:59:45Z</updated>

		<summary type="html">&lt;p&gt;New Page&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{:Network Security}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Resources ====&lt;br /&gt;
* Firewalls&lt;br /&gt;
** The most secure firewall: [[File:Nipper for Electronic Wire (Old).png|150px]]&lt;br /&gt;
** Another secure firewall: [https://www.pfsense.org/ pfSense]&lt;br /&gt;
* Intrusion Detection Software&lt;br /&gt;
* Pen Testing apps&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* [https://www.techsoupcanada.ca/en/directory/361 TechSoup Canada Catalogue: Server and Network Management]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Claim: The greatest threat in Network Security is NetAdmin or User Error&lt;br /&gt;
** [[File:Network Security Dave.jpg|640px]]&lt;br /&gt;
** Another e-mail breach caused by human error:&lt;br /&gt;
*** [https://www.cbc.ca/news/canada/kitchener-waterloo/university-waterloo-data-email-breach-information-quest-1.5048814 Names, banking information accidentally shared in emails to University of Waterloo students | CBC News]&lt;br /&gt;
** Data exfiltration due to user error:&lt;br /&gt;
*** [https://www.thestar.com/politics/provincial/2019/01/21/privacy-breach-hits-45000-recipients-of-ontarios-disability-support-program.html Privacy breach hits 45,000 recipients of Ontario’s disability support program | The Star]&lt;br /&gt;
** NetAdmin failed to renew expired domain names:&lt;br /&gt;
*** [https://arstechnica.com/information-technology/2019/01/godaddy-weakness-let-bomb-threat-scammers-hijack-thousands-of-big-name-domains/ GoDaddy weakness let bomb threat scammers hijack thousands of big-name domains | Ars Technica]&lt;br /&gt;
** Vulnerability not acknowledged by vendor:&lt;br /&gt;
*** [https://www.cbc.ca/news/canada/new-brunswick/cyber-malware-breach-dark-web-municipal-parking-servier-click2gov-centralsquare-1.5043818 City knew of massive cyber breach days before admitting it | CBC News]&lt;br /&gt;
*** &amp;lt;blockquote&amp;gt;On Dec.19, the day following Solomon's exchange with Caissie, the city received notice from CentralSquare Technologies, the Florida company providing the Click2Gov parking server software, that there was no problem with the system. &amp;quot;Resolution: Checked Click2Gov server for evidence of malware/possible breach, no evidence found of breach/malware,&amp;quot; says the statement signed only &amp;quot;Customer Support.&amp;quot;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
** Pre-emptive shutdown of mail system to prevent a virus attack that might shut down the mail system.&lt;br /&gt;
&lt;br /&gt;
==== Meeting Notes ====&lt;br /&gt;
Spoke about resources, war stories&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Proprietary mail systems&lt;br /&gt;
** Errors in implementation, makes mail inaccessible, or sends mail when unwanted.&lt;br /&gt;
** Corporate culture prevents people from speaking of security flaws&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Bugs in the software&lt;br /&gt;
* Errors in procedures&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== The Cloud =====&lt;br /&gt;
* &amp;quot;If the data was in the cloud it would have been safe&amp;quot;&lt;br /&gt;
* What is The Cloud?&lt;br /&gt;
** Somebody manages the servers, still subject to human error&lt;br /&gt;
** But reduces the human interaction that is needed&lt;br /&gt;
** Maybe if '''everything''' is run by robots...&lt;br /&gt;
*** But that's not the way Nonprofits operate, engaging people to be more involved&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Open Source groups want more interaction, so still room for error&lt;br /&gt;
** eg. LibreOffice: Get a professional to manage website? Or keep local group involvement?  No to robots&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Robots have programmers too&lt;br /&gt;
** One more level of abstraction&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Problems solved?&lt;br /&gt;
** Email spoofing, phishing schemes: Joe Jobs, third-party addressbooks breached&lt;br /&gt;
** Could contact the apparent sender, but that person may not be involved in the message at all&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Tour of pfSense ====&lt;br /&gt;
&lt;br /&gt;
Bob Jonkman logged into his live pfSense installation and stepped through each of the menu items.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===== Multiple connections to isolate traffic =====&lt;br /&gt;
* While Bob's installation has only two connections (WAN, LAN), it is possible to isolate Internet-facing servers on their own network connection (DMZ) to isolate that traffic from the internal LAN. &lt;br /&gt;
* pfSense supports many network connections, useful for separate campus sites&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Back to: [[Network Security]]&lt;br /&gt;
&lt;br /&gt;
[[Category:KWNPSA Meeting Notes]]&lt;/div&gt;</summary>
		<author><name>BobJonkman</name></author>
		
	</entry>
</feed>