Probably something like "hey, my nephew is a computer nerd, why not hire him instead of $EXPENSIVE_CONSULTING_COMPANY?"
Followed a couple months by: "Why is our internet so slow?" and "why aren't out customers getting our emails?"
Microsoft has just recently made SMB safe for the Internet (Azure File Shares), but that's just one of many protocols on a Domain Controller...
The enterprise world have a huge problem with it's addiction to legacy Microsoft technology that Microsoft is both aware of but also unable to fully address as their modern stuff just aren't all that competitive without the legacy compatibility. And the "domain controllers" it's at the very core of this problem.
In the unix ecosystem most of the old vulnerable legacy(which was never as bad as windowsNT) is actually dying out but for some reason most of the traditional wintel ecosystem seems to be partying like it's still 1999.
Really and truly the problem is executives not seeing the value in hiring for their actual IT problem space. Too many companies, especially ones that are more physical and have people who like to proudly claim computer ignorance, refuse to admit that with advances in technology that IT is an integral and vital part of the business.
Instead they don't even hire for positions they really need, or if they do, they hire for peanuts and get subpar gui-ninjas... and that's how you end up with a bunch of AD servers on the internet.
> Microsoft has just recently made SMB safe for the Internet
cifs anyone?
Azure Active Directory has almost nothing in common with Active Directory, other than the name. Amongst other things, it uses HTTPS almost exclusively.
CIFS is an older protocol that Linux admins use incorrectly to refer to SMB, which is the file sharing protocol used by Windows.
Is Linux UNIX?
I have not done network administration in a very long time, so my suspicion is that many of these domain controllers were set up by not very experienced people with not very intelligent bosses thinking that "it was done once, therefore it is done forever".
If you are talking about how the DC itself gets updates then it has outbound access normally via a proxy server or something like that.
You wouldn't put the DC on the internet that would be really insane.
if you cannot expose the AD server to the public internet, can you then actually use windows in remote first organization?
Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication.
I work in this exact type of environment. Your laptop is joined to the domain in office before being sent to you. You can of course logon to the laptop even though it cannot connect to the domain. You just have to connect to the VPN and domain periodically to get gp updates if there is some mandatory software it'll install when you connect. So you connect to the VPN after you logon locally.
You also have to connect to the domain to change your password.
> Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication.
No you can logon to a computer with your domain credentials even when it's not connected to the domain.
The internet facing deployment means you have to set up ADFS Web Application Proxy in DMZ that is NOT domain joined and can communicate with domain-joined ADFS service.
ADFS allows plenty of stuff, including 2FA, for example for trusted devices only, which has been registered with ADFS and uses certificate based auth. It allows SSO with online services like Azure, Google Workspace and more.
Edit: Ahh, sorry, the story is about not logging into web apps, but domain joined computer. Credentials are cached on user laptop, so you can login without network (you can prevent credential caching if you will. You should for domain admin accounts). Or you setup always on VPN (DirectAccess or wireguard) so that you always have the connectivity.
They don't. MOre so - they don't even know what they are doing.
NB there are people on the other side of the spectrum - I've met enough Linux fanboys who insisted what they don't need a firewall running on their public machines, because... Linux is safe.
Obviously in a more involved (enterprise) setup a firewall will make sense for several reasons, but on a small server you rent for yourself to run an httpd and let's say an ircd plus ssh, what exactly do you think a firewall does for you?
> but on a small server you rent for yourself
Bwahaha!
But what if I WANT to install software that opens it? Like MongoDB for example? What could be wrong if I just install some MongoDB to run $softwarename, right? Nothing wrong could happen, yes?
Read my comment at [0], I don't want to repeat it here.
Why would it need a firewall running?
Today you setup you shiny new host and you know exactly what is running on it and what ports are open. Some months/years later?
Yes, a single purpose mail server can get by with tcp/22 and tcp/25 for all it's useful life but something more complex?
Or when you don't even know for sure what are defaults are and you 'move fast and break things'? Should I remind you about MongoDB fiasco? [0] Are you sure all your 'internal' services (DBs and whatever) are bound to localhost and not to 0.0.0.0?
Running a firewall in the default drop/whitelist mode (at least for the inbound traffic) protects you against your own mistakes.
Add to this what while you can be an exceptional localhost admin, as soon as you have more than 5 hosts and/or work with other people you can never be sure what every host is properly configured, secured, don't have anything unnecessary running.
[0] https://krebsonsecurity.com/2017/01/extortionists-wipe-thous...
>> If installed on a server with the default settings, for example, MongoDB allows anyone to browse the databases, download them, or even write over them and delete them.
Edit: with a 'deemed safe enough by Gordonjcp@HN' column of course.
Your argument is "software might have unsafe defaults, so you should rely on a piece of software that might have unsafe defaults".
My argument is having an additional layer of protection just in case. Do you wear a helmet only on the days you fall off from your bicycle?
> you should rely on a piece of software that might have unsafe defaults
Well, if you just took the helmet with you but never bothered to wear it...
If you cannot install a server without ensuring you're running what you expect to be running, you've no business running it at all.
The other way in which the analogy is flawed is that I might very well consider myself a perfect cyclist, but that still doesn't protect me from that drunk driver in a SUV shooting out a side alley where I have no chance to react.
A firewall does nothing useful if there's nothing to firewall.
It's a skill that everyone should know, if they want to run servers. It's a skill you can acquire by reading some very simple instructions.
Imagine if bridges were designed and built by the fuckwits that created (or indeed use) MongoDB.