Showing posts with label SystemAdmin. Show all posts
Showing posts with label SystemAdmin. Show all posts

Thursday, August 27, 2026

Wednesday, August 12, 2026

Authenticators, Passkeys, and more - Oh my

Most major online sites  (Google, Microsoft, Banks, etc.) are now requiring some sort of multi-factor authentication (MFA) due to the number of compromised accounts.  MFA basically means you need two things to login in such as a password and something else like a code from a SMS text.  MFA comes in several flavors such as:

  • A code sent to you via email, SMS text, or voice
  • An authenticator app that generates a code such as Proton, Microsoft, or Google Authenticators
  • A passkey which uses asymmetric authentication where you store the private key on your device and the vendor stores your public key.  They have to match for it to work

Microsoft has already disabled email MFA and, as of February 1st, 2027, Microsoft will disable SMS text and voice for MFA for their enterprise accounts (consumer accounts are not affected).  This is because it is just too easy for these methods to be hacked as they require a remote system to send you a code in plaintext which provides many opportunities for someone to intercept the code (e.g. social engineering, SIM cloning, forwarding all emails to the bad guy, etc.).

So why are passkeys better? There are several:

  • They are based on asymmetric encryption so you hold the private key and the vendor has the public key.  If the vendor is broken into, the bad guys cannot get a bunch of passwords to hack  and the cannot get your private key part as that is on your device (see next item)
  • The private key part is stored on your device or in a secure password keeper such as Bitwarden.  What this means is that a bad guy cannot remotely try to break into your account at the vendor; they need your device or access to your secure password keeper.
  • You have no idea what the private key part is and it is very long so social engineering attacks will not work easily.
  • The passkey is different for each account and site you visit.  So no more reusing passwords across multiple sites.
  • Fake phishing websites will not work as they do not have the public key so you will not be able to login.  Also since you do not enter a password, they cannot get your passwords.
  • You do not need to use an account id or password to login, just click on the passkey.  So it is much easier.
But like most things, there are some downsides:
  • They are typically stored in a secure store on the device.  This means you have to set up separate passkeys on each device to access a single service (e.g. a bank account).
  • In some cases, local devices (looking at you Windows 11) only allow you to store one passkey per service (e.g. Office.com) instead of a passkey for each account you have on the service.  So if you have work and personal Office.com accounts, you can only use a passkey with one of them. Sigh.
  • To access a passkey, they typically use a short PIN (not good - looking at you Windows Hello) or some sort of biometric (e.g. finger or face id - good).
  • If you loose a device or if fails, you loose all your passkeys and will have to regenerate them.  So always, always, set up an authenticator app as a back up MFA option.
  • To get around the above issues, Microsoft, Apple, Google, and most major secure password keepers allow you to store the private key part with them instead of on the device which means you have to login to their services just to access the passkeys.  Frankly, I do not trust Microsoft and Google with my private key parts and I do not want them knowing whenever I use a passkey to access my bank account.  Instead I use Bitwarden secure password keeper.  If you do this, then the first 4 issues disappear (although in the case of item 4 you can log in with the passkey on a different device to regenerate the passkeys).
  • Passkeys are implemented very differently by the different vendors.  Some like a Bank I use, do not ask for a PIN code so if someone gets my computer, they have full access to that bank account - oh boy.  Others use a passkey with SMS. Some, like Microsoft Windows 11,  only allow 1 passkey per service so no multiple accounts.  Some still require you to enter a login id, some do not.  Until this  gets sorted out and standardized, passkeys are a bit of challenge to set up and use.
  • The worst thing though is if a bad guy gets your phone or computer and you are using a short, easily guessable PIN to access your passkeys, they can guess it and get access to all your accounts.
Even with that last problem, passkeys are better than Passwords with Email/SMS/Voice MFA as you really cannot do remote attacks with passkeys.  The bad guys have to get your device which is a much lower probability than a remote attack or vendor compromise.

So how to make passkeys work best for you:
  • Use a secure passsword keeper such as Bitwarden (not LastPass as they get hacked almost every year).  This allows you to share passkeys between devices.
  • Use a biometric ID of some sort such as Face or Fingerprint ID to unlock passkeys or, in the case of a secure password keeper a very long password that you use no where else.  Do not use a simple pin code because it is too easy to guess if a bad guy gets your device.
  • Always set up authenticators such as Proton Authenticator as backups to passkeys in case you loose one of your devices and have to redo all your passkeys.

Tuesday, June 2, 2026

Task list and personal knowledge base

Over the last several months I have moved to Obsidian to track tasks and act as a personal knowledge base. 

I have been tracking Obsidian for years as it added features, but it never had a task manager until recently. Before I use Remember the Milk for taska and Joplin as a knowledge base.  The problem was I had information in two locations and would often look in the wrong location. In addition, these systems required yearly payments to get syncing between my phone and computer to work. 

With Obsidian, all my data is in one place so a global search finds what I am looking for. Using various plugins, I can customize the notes and tasks to my workflow.  For syncing between my phone and laptop, I use Syncthing.  Whenever my phone and laptop are on the same wireless network, the Obsidian data is synced. And best of all - it just plain works. 

The primary Obsidian plugins I use are:

  • Edit history: so I can recover things when I delete them accidentially. This works great across the phone and laptop (e. g. if I delete parts of a note on the phone and notice it on the laptop a few hours later, I can restore the information)
  • TaskNotes: this is my task list where each task is a note.  That way I can have lots of information about the task. 
  • Hidden  folder: hides the folders with the tasks in them as I only want to modify these notes via the TaskNotes interface. 
  • Templater: allows me custom templates for my daily notes. 
  • Omnisearch: true global search across notes and attachments
  • Text extractor: extracts text for omnisearch from attachments
  • Open tab settings: makes sure the tabs I want to see are opened on startup - the daily note and task list
If you are looking for a free, very good tool that just works to manage your task list and personal knowledge base; I highly recommend Obsidian.  Using Syncthing, you can get all the data on your phone and laptop in complete sync. 

Saturday, January 10, 2026

Microsoft Support - The long and winding road

So for one of the non-profits I support we use Microsoft Teams for voice calls.  This works very well and is less expensive than all the other options.  At the start of 2025, Microsoft said they were adding SMS texting to teams which would be very nice for the non-profit to communicate with volunteers and for MFA for services that work with VOIP phone numbers.  So in Feb I signed up through the teams support portal and was added to the wait list.  In October they enabled SMS and I had to do 3 things to make it go live:

  • Fill out a form that allows PSTN operators to validate your company. This was easy and approved quickly
  • Create a 'brand' that is used to verify you with other SMS providers.  Again, pretty easy and approved quickly
  • Create a campaign.  This defines the use cases for SMS.  This is where things fell apart.
The problems started with the fact that Microsoft has multiple different service centers and the one you get when you click on the '?' on the main teams page cannot help with SMS.  However in trying to be helpful, they will waste weeks of your time trying to help until you finally reach a manager type who has enough knowledge to say they cannot help. They even wrote back one time that the screen shots I sent them were "from a third-party application. To better understand the situation, could you please clarify the following..."  See this post for more information.  The main helpdesk folks tried for 2 months to find me help and the best they could do was to give me this email pstn@microsoft.com which 


bounced.  Sigh.

The way it works is you fill out the forms and some automated system looks at them, approves or denies it.  The errors the system said I had made no sense such as CallToActionMissingOrInaccessible, but when I look at it all the links are good and the text is just like their example. Back in Feb, I was able to fill out the help form asking for SMS to be enabled.  In Oct this I get these options:

Notice that there is no case type for SMS.  When I pick General Inquiry I get this:

This is what I get when I interact with the chatbot:    
🤖 said:
If there is no specific case type for SMS campaigns, you can still open a new case by following these steps and providing detailed information about your issue:

Navigate to the Phone Number Service CenterFrom the Phone Number Service Center home page, you can find options to create a new case at the top of the page or at the bottom tile. Alternatively, you can go to the "View my existing cases" page or the "View my company cases" page.
Select Create a New Case: Choose the option to create a new case.
Provide Case Details:
Case Category: Select "Submit a new request" if you want to submit a new request related to your SMS campaign.
Country or Region: Select the country or region for which the phone number you are submitting this case for.
Case Type: If there is no specific case type for SMS campaigns, you can select a general case type that closely matches your issue or select "General inquiry".
Enter Case Title: Provide a title that summarizes your issue with the SMS campaign.
Notification Emails: Enter the list of people who will receive automated status notifications from Microsoft. This is optional.
Description: Describe the issue you are facing with your SMS campaign in detail. Include any error messages you have received and any steps you have already taken to try to resolve the issue.
Additional Supporting DocumentsUpload any additional documents that might help in resolving your case.
Submit the CaseAfter entering all the required information, select "Submit". You will then see a new screen where you can view your case number.
If you need further assistance, you can contact the TNS Service Desk directly.                                    

The major issue is that you cannot follow the instructions as most of the case options such as General Inquiry above go directly to the chatbot which does not allow you to enter data into a form like the instructions (whoops infinite loop).  The other issue options are for porting numbers which I do not want to do. Hmm, perhaps re-open a previous ticket - nope that is not an option either.

Ok, lets try to find contact information for the TNS Service Desk.  Searching Microsoft public documentation gets this:

Sigh.  But, but, Google to the rescue.  I was able to find a phone number (800-416-3882).  The people there could not help, but gave me an email communications@tnsi.com.

So tried it and they had no clue what I was talking about.  Eventually I filled in a ticket for New TN Acquisition with fake data and finally got a hold of someone who could help.  Why they make it so hard to get help is beyond me.

Tuesday, December 30, 2025

Sending emails on new Blogger posts - version 2

In this post, I talked about using Make.com to send emails whenever I made a new blog post.  Unfortunately, that turned out to have many problems of which the main issue was that gmail required authentication every three days and you have to use the desktop browser version to re-authenticate.  In other words, it was not usable, especially from a phone.  I am now trying Zapier.com to see if it works any better.  It works a bit differently by using the RSS feed from blogger instead of logging into blogger to see if there is a new post.  Also it seems to be better about only getting a new post, not an older post and it checks every 15 minutes so I can post multiple times a day and people should get emails.  We will see how it works.

Monday, November 17, 2025

Sending emails on new Blogger posts

I have been using follow.it to allow people to get emails whenever I post something to the blog, but did now like it as it never led people to the blog.  Instead they just copied the blog posting to their site and the person would view it there.  So after looking around at all the other services that have the same sorts of issues, I cobbled together a solution that will work for me and may be even better.

I created a free Make.com account and used their tools to connect Blogger to Gmail.  Now a new post will trigger a Make scenario which will then send an email to all the folks who have signed up.  I put people's emails in the BCC field of the Gmail app for privacy.  The Make scenario runs once a day and will only pick up the most recent blog post which is fine with me.

Next, I had to create an easy way for people to let me know they wanted to sign up.  Blogger is pretty limited on this, but as a workaround, I set up their Contact Me widget and then hid it with a custom style "#ContactForm1{display: none !important}" in the theme.  I can then copied over the widget code into my own HTML/Javascript widget and modified it to remove the name and message fields. Now I have a simple form with email field and a subscribe button.  As an aside, I also use the fields in the custom widget to create a Contact Me page on the site.

So now what happens is I get an email when someone wants to get emailed on new postings which I then add to the Make scenario.  For me this works fine as I am very low volume.

Wednesday, May 14, 2025

Sunday, May 11, 2025

Microsoft Fun - MFA

As mentioned previously, I run O365 domains for a few non-profits.  One of them has volunteers come into the office to screen videos from a camera before posting them on the website.  The volunteers log in on a shared account. 

Due to phishing and hacking issues, Microsoft has been gradually forcing people to use MFA. While this is a good idea in general, as usual there are edge cases where it doesn't make sense AND Microsoft's own documentation and web UI are all over the map concerning MFA.  So there are multiple locations in their web UI where you can manage MFA for users - both per user, by policy, and by setting defaults in at least 2 different places (notice that all my settings are to disable MFA):


Friday, May 9, 2025

Wednesday, May 7, 2025

Microsoft Fun - Support for support

I maintain Microsoft O365 domains for two different local non-profits.  These are a good deal for non-profits as they get 10 Business Premium and 300 Business Basic licenses for free plus nice discounts on other products.  As such I get to deal with the quirks of a large company.  O365 has a nice option to get support when you have problems.  It has a AI assistant (not useful for the questions I have) and then open up tickets with options for phone or email callbacks (although it seems they always want to use the phone).  The support folks try hard, but are often not able to help much.  A few annoying quirks are:

  • They often want to see you screen and start up a screen sharing session.  They like to do this via teh quick assist app that only runs on windows and mac machines.  If I say I am on a linux machine, they go 'huh', talk with their manager, and, depending on if the manager is experienced or not, will then switch to teams which does run on linux. 
  • Microsoft has multiple support groups for their different products, but links to access these support teams is either in the left side menus (Identity) or scattered around on various screens (Teams) instead of being accessible via the nice ? icon. O365 support cannot transfer tickets to other support groups and, unless you do a lot of poking around menus, you have no idea they even exist. 
So, for example, I have a question about MFA and open a O365 support ticket.  They contact me, start up a quickassist screen sharing session, and walk me through opening up a support ticket with the Identity support group.  Good thing they did as the options they had me pick to open up the ticket had nothing to do with MFA - it was more with dealing with how to create applications.

So now I need support just to access support - way to go Microsoft.  Seems like an immense waste of time and resources.

Monday, February 17, 2025

System Admin Maxim #4: Monitor your systems

 As a system admin you are responsible for the infrastructure that the rest of the organization depends on for their jobs.  To assure that this infrastructure does not break and inopportune times, you need to monitor it.  This means that you set up systems, scripts, processes, etc. so when something starts to get out of whack; the infrastructure will alert you that there is something going wrong and perhaps you may want to do something about it.

Sounds simple, but monitoring is somewhat of an art form because:

  • The infrastructure you are monitoring is dynamic and constantly changing.  So you need to constantly be updating your monitoring system to reflect this.
  • You need to decide what is important to monitor and when the system should alert you and how it should alert you.  For critical things and email will not cut it.  You want a text or push notification to your phone.  
  • Is the alert a 'real' one or a false positive. If you get too many false positives you will start ignoring them to your own peril.
  • What happens if the system it uses to alert you fails?  How do you know the monitoring system is really working?  These are questions you need to resolve - perhaps by having it send out an 'OK message every day or so.
  • Certain failures (e.g. a switch or router) and make it look like large portions of your infrastructure failed when they did not so you get a zillion alerts when really you only needed one alert from the failed switch or router.
  • What about partial failures where people notice slowdowns, but the system is running? What about gradual failures where a disk is slowly filling up until the system completely breaks? You need to figure out how to deal with these sorts of failures.
  • What is 'normal'.  Most systems will produce lots of monitoring data, but until you work with the system for at least a year, you really do not understand what is 'normal' data and what is 'I am about the break badly' data in many cases.  I say at least a year, because most organizations have yearly, monthly, quarterly, and other cycles that may affect the system.
  • What dose it mean to be outside of normal?  Some percentage like 10%.  Perhaps 1 or 2 standard deviations. Perhaps you can compare it to previous years data AND the system had not changed too much so you can say this is really different, perhaps I should check into it.
As rule of thumb, I have found that you need to keep the monitoring systems as simple as possible, because if they are not they will not be maintained and just rot away.  Determine first which sort of events are causing your infrastructure problems, then start out small monitoring things that lead up to those events.  Then gradually add in more things while not increasing the false positives or workload on yourself.

Saturday, February 15, 2025

Tuesday, January 14, 2025

System Admin Maxim #2: Identify your infrastructure's risks to management

I have many, many examples of organizations closing the door after the horse is long gone as in Maxim #1.  The most painful one was where I warned the CEO of a small, public software firm that (1) developers were not saving all their data and code on the server, but instead keeping in on their local machines because that was much easier and faster and (2) we were only backing up the servers.  Because we were a public firm, we had to make our quarterly numbers or else the stock would tank.  I told him the cost to back up the workstations and recommended that we do so, but he decided against it. So about a week before the end of a quarter, the machine of the primary QA developer working on a new release that was expected to come out in that quarter, failed.  All the work was lost, the product was not released on time, stock tanked, lots of very, very unhappy people.  The CEO brought me into his office that same day and told me to spend whatever it took to back up all the workstations. Because I had identified the risks before hand there was not much else he could do. As a system admin you need to identify the risks to management.  They may or, as in this case, may not act on the risks.  If they choose not to act, then you must prepare as best you can to recover when the event happens.  It is more difficult these days as the risks are larger (e.g. ransomware), more insidious (e.g. attacks on supply chain vendors), and many are human related (e.g. social engineering cyberattacks) that technology really cannot solve or mitigate.

Monday, January 13, 2025

System Admin Maxim #1: Closing the door after the horse has escaped

I grew up on a small farm and we had a saying of 'closing the barn door after the horse has escaped'.  In my 40 years as a system admin, I can only think of a few times where this has NOT been true.  Most organizations I have worked for are resource constrained and cannot or will not do what is needed to protect their networks.  This is especially true today with the rise in number and costs of attacks on technology infrastructure.  I am reminded of this because I help out at a non-profit who just had their network hacked because, even though they were warned, continued using simple passwords and were sharing the password for their primary wifi.  After the attack, I segmented their network into staff, IoT, and public vlans along with using secure passwords for the network.  

I can only think of one organization during the dot com boom of the late 1990's that dedicated enough resources to protect their technology infrastructure. In this case it was when the owner decided to move to an on-prem Exchange mail server. I told him that Exchange servers were known to have many issues with cyber attacks and to defend against them we needed a multi-layered software approach of anti-virus software on the server and on all the clients connecting to the server from 2 different vendors.  This software cost was 50% of the Exchange server cost so was not cheap, but he decided to do it.  A few months after the migration, all is going well and he is off at a conference of peers; when a big cyber attack against Exchange servers happened.  His company was the only one at the conference who had no email issues because he chose to spend the money to protect the systems.  One vendor's antivirus software stopped some of the attacks and the other vendor's software stopped the rest of the attacks.  I remember him coming back and giving me a bonus because he sure did look smart at the conference.