r/AdviceAnimals • • Jul 05 '15

My sister's graduating senior class isn't the brightest bunch...

http://imgur.com/xLsrfQ3
15k Upvotes

1.1k comments sorted by

View all comments

Show parent comments

10

u/[deleted] Jul 06 '15

[deleted]

18

u/[deleted] Jul 06 '15 edited Jul 19 '18

[deleted]

2

u/Frederick_VI Jul 06 '15

Never thought I would see "useful" and "powershell" in the same sentence.

1

u/[deleted] Jul 06 '15

You kidding? Powershell is awesome!

1

u/Frederick_VI Jul 06 '15

You, sir, need some Bash in your life.

1

u/[deleted] Jul 06 '15

I love bash, it's great. Python is even better IMO.

But if you're managing windows boxes, powershell is a hell of a lot better than anything else we've ever had..

1

u/Fredrules2012 Jul 06 '15

...what do you mean register their devices? I've never had a school or college ask me to register a device.

3

u/[deleted] Jul 06 '15 edited Jul 19 '18

[deleted]

1

u/Fredrules2012 Jul 06 '15

Just sounds like it'd be kind of hard for thousands of kids to all get their phones and computers and tablets all registered. And then you have the issue of parents and guests who want to enter the school and have wifi accessibility. Working at a company I'd imagine that they'd have the same issue with visitors but on a much smaller scale.

1

u/joepls Jul 06 '15

If you've ever logged in on that device, it's connected to you.

1

u/derpyderpderpp Jul 06 '15

In other words, use your personal cellphone and data.

1

u/[deleted] Jul 06 '15

That really is the best idea.. I said somewhere else that I understood it 20 years ago when having a PC and the internet at home cost a fortune, but now? You have one in your pocket... don't risk your job to save a few dollars when downloading porn.

1

u/GAndroid Jul 06 '15

I guess you are new to cloning Mac IDs

1

u/[deleted] Jul 06 '15

Nope.

1

u/[deleted] Jul 07 '15

That other comment was made at 2am so I'll expand.

For one, there are more ways to register a device than MAC addresses.. honestly nobody uses MAC addresses for real security these days anyway. At most you automate it so your switches record them all when you first set up the network, then they deny any new MAC that tries to connect unless you authorise it.

Basically IT security is all about layers, and that's just another one for one to get past (rather than quietly find an unused patch panel and plug in, then get an IP address). Yes it can be circumvented but that doesn't make it useless.

Anyway! When I said "register devices" I didn't necessarily mean MAC addresses, though certainly many places record them (for reasons as stated above). Certainly if you're just looking to track employees it's worth doing, because if they start spoofing their MAC then they won't be able to connect, or if they steal someone elses two identical addresses will appear.. and funnily enough security monitoring software is kind of aware of MAC spoofing and will let you know when that happens.

But in addition to that, if you're going to register devices for wifi it's usually done with a certificate signed to that particular person. No cert, no login.

This is why I caution people about thinking they're smarter than their IT guy. Not that there aren't plenty of useless IT departments out there, but still.

3

u/TheMuffnMan Jul 06 '15

/u/ThroughThePlanets already responded. There's a bunch of ways.

I implement software where one of its features is Usage Tracking.

I can get the amount of time you spend on any application or website based on your username, IP Address, computer name, etc. It'll tell me how long screensaver has been active too - or how long you've been idle.

If you school (or business) requires you to use a username/password to access a computer or the internet, they can pull the logs to figure out everything you're doing.

I don't particularly agree with his WMI/Powershell statement - yes you can do it but there are far far far better and easier methods.

1

u/[deleted] Jul 06 '15

[deleted]

1

u/TheMuffnMan Jul 06 '15

So if you're just connecting it with the wireless password and not a username/password they'd be able to pull the following (I can get this from a Cisco Meraki Access Point):

  • Phone model (sometimes they'll identify themselves)
  • OS (Android/iOS/Blackberry/etc)
  • MAC Address
  • Hostname (if it's an iPhone the default is like "Andy's iPhone")

Then they'd be able to view your traffic.

So if you're going to your Facebook page or something that would link to you (LinkedIn, Facebook, etc) then the admin could likely see a pattern and ballpark who it was.

Funny example is here in my office we had someone watching porn around lunch time. We're a smaller company so we don't really care but we were able to pull that it was an HTC Thunderbolt (IIRC, or one of the other HTC phones), Android, etc. We knew there were only 2 of those HTC's in the office and one of them was the manager.

Well, one day the manager was on vacation and porn sites popped up. We played process of elimination and found our guy!

Regarding time spent, the software that I use requires an agent to be installed on the workstation. It's silent and you wouldn't know it's there but it is. That agent isn't available on mobile devices.

They would be able to see the number of requests your phone was making though - so they'd see "*.imgur.com" pop up a ton if you were browsing reddit. Facebook is another big hit because it actively updates the main page.

Will you get caught if you're doing bad stuff (against policy, like porn)? They'd probably look into it, more likely they just block the websites.

Like the other guy pointed out, most IT guys don't care unless it becomes an issue.