Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Hey so how's ActiveDirectory going to implement that OS-based age-flag horseshit?

Hey so how's ActiveDirectory going to implement that OS-based age-flag horseshit?

Scheduled Pinned Locked Moved Uncategorized
17 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

    @munin fwiw, its not entirely by adults, we have the odd minor on an internship/trainee - rare but still enough the assumption doesn't hold.

    The entire thing is ... technically conceptually easy, good luck implementing it: Add another field to users, then adapt all your automations to pull/maintain that field. Chances are you already have an information flow from your HR system (as the employment single source of truth) to your AD re: account creation & disabling. Same with admins: I sure hope you can track temporary accounts to their instantiators/initiators, "just" gotta update those tools now

    It's all so fucking stupid & unnecessary. It's such a bad law, even just technically, feels like not a single person who has ever used anything other than an IPad was involved in writing it.

    nyanbinary@infosec.exchangeN This user is from outside of this forum
    nyanbinary@infosec.exchangeN This user is from outside of this forum
    nyanbinary@infosec.exchange
    wrote last edited by
    #5

    @munin it's so fucking useless, istg, we should just pull out of CA, chances are any changes to implement this thing would cost us more than we make in the state...

    nyanbinary@infosec.exchangeN 1 Reply Last reply
    0
    • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

      @munin it's so fucking useless, istg, we should just pull out of CA, chances are any changes to implement this thing would cost us more than we make in the state...

      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchangeN This user is from outside of this forum
      nyanbinary@infosec.exchange
      wrote last edited by
      #6

      @munin oh lol, I just realized... local accounts on firewalls and shit...

      munin@infosec.exchangeM 1 Reply Last reply
      0
      • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

        @munin oh lol, I just realized... local accounts on firewalls and shit...

        munin@infosec.exchangeM This user is from outside of this forum
        munin@infosec.exchangeM This user is from outside of this forum
        munin@infosec.exchange
        wrote last edited by
        #7

        @nyanbinary

        Y u p .

        munin@infosec.exchangeM 1 Reply Last reply
        0
        • munin@infosec.exchangeM munin@infosec.exchange

          @nyanbinary

          Y u p .

          munin@infosec.exchangeM This user is from outside of this forum
          munin@infosec.exchangeM This user is from outside of this forum
          munin@infosec.exchange
          wrote last edited by
          #8

          @nyanbinary

          hey how much you wanna bet some kind of admin tool's auth check ends up being bypassable if you set your age to 6?

          nyanbinary@infosec.exchangeN 1 Reply Last reply
          0
          • munin@infosec.exchangeM munin@infosec.exchange

            @nyanbinary

            hey how much you wanna bet some kind of admin tool's auth check ends up being bypassable if you set your age to 6?

            nyanbinary@infosec.exchangeN This user is from outside of this forum
            nyanbinary@infosec.exchangeN This user is from outside of this forum
            nyanbinary@infosec.exchange
            wrote last edited by
            #9

            @munin istg, if this is just a ploy to force everyone to replace their EOL appliances I am all here for it

            nyanbinary@infosec.exchangeN 1 Reply Last reply
            0
            • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

              @munin istg, if this is just a ploy to force everyone to replace their EOL appliances I am all here for it

              nyanbinary@infosec.exchangeN This user is from outside of this forum
              nyanbinary@infosec.exchangeN This user is from outside of this forum
              nyanbinary@infosec.exchange
              wrote last edited by
              #10

              @munin also: absolutely racing you to the first ../ in the birthdate field

              1 Reply Last reply
              0
              • munin@infosec.exchangeM munin@infosec.exchange

                @nyanbinary

                afaik the law makes no exemptions for business systems used, presumably, entirely by adults.

                So now, everyone's AD installs have to attest to their age; It's The Law after all.

                So your temporarily instantiated admin account you're using to modify a service - that's going to need to attest you're over 18.

                Is it going to pull that information from HR? is it going to make you answer a dialogue when you login? How is this going to be implemented in business systems that are, again, almost guaranteed to be only used by adults?

                kluthulhu@infosec.exchangeK This user is from outside of this forum
                kluthulhu@infosec.exchangeK This user is from outside of this forum
                kluthulhu@infosec.exchange
                wrote last edited by
                #11

                @munin @nyanbinary For some reason this reminded me of company profiles on social media.
                There was a period where these profiles would get locked because they were "under 13" (i.e. company age = person age).

                1 Reply Last reply
                0
                • munin@infosec.exchangeM munin@infosec.exchange

                  @nyanbinary

                  afaik the law makes no exemptions for business systems used, presumably, entirely by adults.

                  So now, everyone's AD installs have to attest to their age; It's The Law after all.

                  So your temporarily instantiated admin account you're using to modify a service - that's going to need to attest you're over 18.

                  Is it going to pull that information from HR? is it going to make you answer a dialogue when you login? How is this going to be implemented in business systems that are, again, almost guaranteed to be only used by adults?

                  adamshostack@infosec.exchangeA This user is from outside of this forum
                  adamshostack@infosec.exchangeA This user is from outside of this forum
                  adamshostack@infosec.exchange
                  wrote last edited by
                  #12

                  @munin @tychotithonus @nyanbinary Yes, and I’ve had interns who were under 18

                  kluthulhu@infosec.exchangeK 1 Reply Last reply
                  0
                  • munin@infosec.exchangeM munin@infosec.exchange

                    @nyanbinary

                    afaik the law makes no exemptions for business systems used, presumably, entirely by adults.

                    So now, everyone's AD installs have to attest to their age; It's The Law after all.

                    So your temporarily instantiated admin account you're using to modify a service - that's going to need to attest you're over 18.

                    Is it going to pull that information from HR? is it going to make you answer a dialogue when you login? How is this going to be implemented in business systems that are, again, almost guaranteed to be only used by adults?

                    maswan@mastodon.acc.sunet.seM This user is from outside of this forum
                    maswan@mastodon.acc.sunet.seM This user is from outside of this forum
                    maswan@mastodon.acc.sunet.se
                    wrote last edited by
                    #13

                    @munin @nyanbinary What about accounts that are not tied to a single person but has a group of individuals logging in to it?

                    nyanbinary@infosec.exchangeN 1 Reply Last reply
                    0
                    • munin@infosec.exchangeM munin@infosec.exchange

                      Hey so how's ActiveDirectory going to implement that OS-based age-flag horseshit?

                      cynicalsecurity@bsd.networkC This user is from outside of this forum
                      cynicalsecurity@bsd.networkC This user is from outside of this forum
                      cynicalsecurity@bsd.network
                      wrote last edited by
                      #14

                      @munin mmh, so, they have abused LDAP and Kerberos… perhaps they can integrate YP for that?

                      1 Reply Last reply
                      0
                      • munin@infosec.exchangeM munin@infosec.exchange

                        Hey so how's ActiveDirectory going to implement that OS-based age-flag horseshit?

                        khoos@infosec.exchangeK This user is from outside of this forum
                        khoos@infosec.exchangeK This user is from outside of this forum
                        khoos@infosec.exchange
                        wrote last edited by
                        #15

                        @munin something with Azure and linking it to a government-issued ID.
                        And we'll be waiting for the first world-wide outage.

                        1 Reply Last reply
                        0
                        • maswan@mastodon.acc.sunet.seM maswan@mastodon.acc.sunet.se

                          @munin @nyanbinary What about accounts that are not tied to a single person but has a group of individuals logging in to it?

                          nyanbinary@infosec.exchangeN This user is from outside of this forum
                          nyanbinary@infosec.exchangeN This user is from outside of this forum
                          nyanbinary@infosec.exchange
                          wrote last edited by
                          #16

                          @maswan @munin finally we can enforce gmsas by law

                          1 Reply Last reply
                          0
                          • adamshostack@infosec.exchangeA adamshostack@infosec.exchange

                            @munin @tychotithonus @nyanbinary Yes, and I’ve had interns who were under 18

                            kluthulhu@infosec.exchangeK This user is from outside of this forum
                            kluthulhu@infosec.exchangeK This user is from outside of this forum
                            kluthulhu@infosec.exchange
                            wrote last edited by
                            #17

                            @adamshostack @munin @tychotithonus @nyanbinary The average apprenticeship im most of Europe starts when you're under 18...

                            1 Reply Last reply
                            0
                            • R relay@relay.an.exchange shared this topic
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups