/srv/irclogs.ubuntu.com/2021/05/12/#ubuntu-discuss.txt

lotuspsychjegood morning01:17
marcoagpintoHeya!04:13
ducassegood morning06:09
lordievaderGood morning06:11
Deano59morning.09:50
Deano59let's change this channel to14:41
Deano59#morninggreeting14:41
Deano59:)14:41
Ussatum...suree14:41
Deano59(:14:42
Deano59Maik: you can run but you can't hide. no need to swear.14:45
Maikstop bothering me stop trolling and stay off of whatever you're high from14:46
Deano59I'm not trolling and I'm not high. but thanks for your concern. :)14:47
Maikftard14:47
Deano59swearing again, that's not following the CoC.14:48
Maiklong live ingnore, permanent this time14:48
Deano59yay. :D14:48
Ussatum...ok14:50
Maikreported too by the way, enough is enough14:51
Deano59reported? you're the one breaking the CoC.14:51
Deano59I'm *not* swearing at you.14:52
hggdhDeano59: please stop14:56
Deano59hggdh: ?14:58
Deano59hggdh: so it's okay for him to call me a troll/ftard?14:59
hggdhno, it is not. As it is not okay for you to act the way you are acting. One error does not justify another14:59
Ussatsigh.....15:00
tomreynso, i did what no normal human wants to do. but $boss wants me to comply, and complying means running a virus scanner. so i set up clamav with on-access scanning,on 20.04. and... it works.19:16
tomreyni didn't actually need on-access scanning for compliance, but wanted to give it a try. i'm positively surprised there.19:17
tomreynsure, clamav's detection is still as terrible as it alwayws was. but the eicar test file is detected and access is prevented.19:19
sarnoldfunny, another channel was just discussing the PCI requirements and a phrase that was added along the lines of "on any platforms where malware is common" or similar :)19:19
tomreynoh, that was recently added?19:19
sarnoldI think 1.119:19
tomreyn1.1 is old, isnt it19:19
tomreynhttps://security.stackexchange.com/questions/58345/how-to-pass-pci-dss-2-0-anti-virus-requirement-5-1-on-linux19:20
tomreynif this article is correct, you quoted well19:21
tomreynwow, that's an old article19:22
tomreynDSS 3.2.1 (May 018) is current, i think19:22
tomreyn*May 201819:22
tomreyn"5.1 Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers)." https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf?agreement=true&time=162084741293419:24
tomreynit's still in there19:24
TJ-tomreyn: I told them to go jump off a high building on that, due to them conflating 'virus' (something that can spread itself) with 'malware'19:25
tomreyn:)19:26
tomreynactually something that can spread itself would be a worm, though19:27
TJ-We have firewalls IN and OUT on each system to guard against network vectors, on top of wireguard links on VLANs. On systems they are read-only immutable file-systems with tmpfs overlays to prevent persistent threats19:27
UssatWe use clamav on all LInux servers here, it lightweight, is very tuneable19:27
Ussatand if youre gonna pass a PCI audit, you need to19:27
tomreyn"firewalls IN and OUT on each system"?! how do you manage those?19:28
TJ-Everything except the minimal host OS is unprivileged systemd-nspawn container and we use cgroups v219:28
TJ-Also, our networks are IPv6 only19:28
UssatRight, because IPV6 makes everythging instrantly secure.....19:28
TJ-tomreyn: management tooling we've created (rules that bind/map to each application container). Containers have network namespaces with only wireguard interfaces imported from the host (so no access to keys)19:29
TJ-Ussat: nothing to do with secure, it is to do with being able to use simple routing across large estates and make the probe space massive if some scanner did get a toe-hold19:30
tomreynthis must be a very homogenic infrastructure, i guess?19:30
tomreyn* homogenous19:32
tomreynthis sounds like a very nice design, but i'm not sure this would work well with BYOD scenarios19:34
TJ-tomreyn: BYOD are on isolated VLANs with very controlled hairpin access through gateway containers20:02

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!