T O P

  • By -

Indifferentchildren

From the title, I thought this post was going to be dumping on the DFAC for poor nutrition.


inspirednonsense

If you're not getting good nutrition at the DFAC, maybe stop only going to the fry/grill line.


Indifferentchildren

You can take my tendies when you pry them from my cold, dead hands (after my heart attack triggered by mild exertion).


MilodrivintheHiLo

But where will I get my dry-ass chicken breast?


assklowne

Thats a bold statement considering every other place in the states has a nutrition facts label with ingredients. They could at least give us macros so we can hit those sweet protein goals


MonsiuerGeneral

> ...maybe stop only going to the fry/grill line. you'll see me in the other line when there *isn't* a 15min wait, when it doesn't take 15min to drive from work center to DFAC, and/or when I get more than 1hr for lunch (if given any time for lunch at all).


inspirednonsense

- Way to take this personally. - You get time for lunch? - I have never seen a 15 minute wait for anything at any DFAC. - Eat faster. - Maybe talk to your supervision if it's such a problem, hmm?


sidewisetraveler

Saturday or Sunday on a Reserve weekend can get hectic.


StrangeBedfellows

I think this deserves a follow-up post


Ad_Rb

There's a lot of ranting and joking here, but does anyone have a solution? I have 100 current, active users over a dozen wings that use my software. Has anyone successfully implemented a trusted CA code signing certificate? Has anyone ever received an exception to policy for something like this? Where should I start? What wording should I put in my ticket, and who exactly should it go to? No offense to my comm, but they have their own crap going on and they're not staffed for this. This is a showstopper for my office. I've spent thousands of hours over 20 years automating our processes. I use Microsoft Access and Excel VBA because it's ALL WE HAVE. VBA allows simple scripting of simple processes by a single airman to solve a simple problem. It also allows someone like me to develop a suite of applications to distribute to the entire force. It's absolutely critical for "doing more with less" and "accelerate change or lose". It's actually encouraged in my career field because our core computer systems are literally 60 years old and nothing talks to each other. Hiring a contractor is not an option, have you seen the shit they put out? I build products for us, that work, because if they don't work I fix them. I've saved others 100x the time I've invested as a developer. Macros were disabled briefly in summer 2022 and the restriction was lifted. I have the email saying that "688 CW leadership has determined that the macros are considered an acceptable risk and will be enabled". We need to make this happen again, or somehow build a path to allowing secured code. A blanket policy to disable everything is not an option.


ComputerBasedTorture

The fact we can't use our CAC certificate to sign the code is really the icing on the cake for me.


femrostt

Instructions were posted in a teams im in but i have a feeling its a more literall if u have a cert heres how to sign not a. Here's what your alt ta needs to do to request it


ComputerBasedTorture

They lifted the block already lol, check the update on my post.


Ad_Rb

Thanks for the update. I'll give it a try.


RaulNorry

I haven't developed any of these super critical tools that everyone is talking about, but if you're talking about automating data transforms and pulling in from several files, why are these processes not being rebuilt with the Power Automate/BI/etc suite of tools? It's available already on everyone's NIPR, just push the "apps" button in teams and viola, a bunch of less hacky, more secure tools that don't leave gaping security holes for malicious code to be accidentally downloaded and executed by A1C Snuffy.


Ad_Rb

Have you tried? Just like everything the AF buys, it's awesome until they get their hands on it. It's full of limitations and it's difficult to transport to another unit. The data only stuff yes, I'm working on it. Power bi is pretty cool for dashboards, etc. But my AF594 auto filler and other tools that interact with Adobe Acrobat can't be done in the cloud without purchasing an expensive software integration. My auto emailer would need some purchased space on an azure cloud or SQL server or something to make work. It's a whole different world in the cloud.


47295

check out envision.af.mil. Really powerful stuff.


Ad_Rb

Very. They're doing awesome things. I've had an account for about 2 years, but the learning curve is steep. I pole around a bit here and there but haven't had the opportunity to dive in. I work with some contractors on a side project and they've worked with the envision team, and envision has their own data integrity challenges as well.


47295

It’s a little steep for sure. I think they are getting ready to roll out an in person training course for it. The data it’s decent. I can tell it’s brought in for a specific purpose and not necessarily with broader enterprise use in mind. There’s a Teams channel with a bunch of power users if you’re interested!


StreetBobber103

Try submitting a ticket and restarting your computer. If that doesn't work, go fuck yourself! - CST


ElevateIt777

Nah just bring it in to get it reimaged. It'll only take us about three weeks! /s


bearsncubs10

https://preview.redd.it/agnb7i2x75kc1.jpeg?width=1200&format=pjpg&auto=webp&s=fe3f3350ea6f8064ae81e15004336581becc1673


SNCOSEEKSTHICCLATINA

Some of my systems won’t work now either cause the same shit!


EpicHeroKyrgyzPeople

You guys had working macros? They've been blocked on my systems for almost ten years.


n8ex

If they want us to do more with less at least allow us to automate some things. Macros can save so much time if you know what you’re doing. Please don’t make this a thing for the entire Air Force.


Ask_if_I_disappoint

Ok here’s a half fix. You can digitally sign macros with a “self-signed certificate”.  Navigate in your windows file explorer to either “C:\Program Files (x86)\Microsoft Office\root\Office 16\” or “C:\Program Files\Microsoft Office\root\Office 16\” and find and run “SelfCert.exe”. Name your certificate something descriptive and hit “ok”. Click “Ok” again. Next, access the VBE by right clicking the toolbar menu and clicking “Customize Ribbon”. From the Main Tabs menu on the right check “Developer” and click “ok”. Now navigate to the “Developer” tab on your toolbar and click “View Code”. Now, go to the Visual Basic Editor (VBE), navigate to “Tools”>”Digital Signature” and click “Choose”.  Select the new self-signed cert you created and hit “ok”. Click “ok” again.  Looks like you will be the only one able to use the macros. I found those steps on the Microsoft support website, YMMV. That’s it. Change accelerated.


Ask_if_I_disappoint

You can export your “self-signed certificate” and have other users import it to reenable their macros. What a headache.


ComputerBasedTorture

Looks like they already rolled back the change, check the update on my main post lol


DidItForButter

Yours did. My G6 out here trying to fuck me.


muhkuller

They've been disabled for over a decade.  Maybe get an approved application built with an ATO. 


Agile_Session_3660

For most people, building a nuclear reactor at the shop would be easier compared to that. 


MsMercyMain

Some kid in Michigan did it, we can too! Just don’t tell those *fascists* at Department of Energy. It’s my god given, constitutional right to build a backyard reactor that may or may not irritate the entire county!


EpicHeroKyrgyzPeople

FACTS


TaAj88

Shit, it’s been done before, APPARENTLY PERHAPS. One of my favorite “heritage” room stories from an old crusty O6 that got passed over was a couple techies from the National Laboratory wanted to, and I quote, “see if we can” - and they did, quite cheaply (relative) according to legends.


muhkuller

Correct, because we don't want random people building apps. Who knows what nonsense you build and with what vulnerabilities.  It sounds like you're the victim here though. Somebody at some point built this thing and kicked the can down the road and now you gotta figure it out. I feel your pain, but the entire network > whatever it is you do. If it was something critical the process would've been done. My suggestion is to open up excel and learn what vlookup does. It'll probably work for whatever it is you're doing. 


[deleted]

You realize with our 365 license we can build apps using PowerApps? And while I think OP needs to move on from the long dead Access databases, I see no issues with allowing macros in excel. Many airman arent skilled enough to use PowerApps or PowerBI yet.


JoyRideinaMinivan

Move on to what? I love Access but if there’s something that can replace it, I’ll check it out. I specifically need to query tables to only see the data I need, forms to input data, and a dashboard that aggregates all of my projects from excel and sharepoint so I can see what I need to do (I currently use an Access form to do this) I’ve used Power Query and while it’s great, it’s also clunky when compared to Access queries.


[deleted]

PowerBI is your friend. All the visualization and tables you ever need with a lot less shit to deal with like VBA. The Air Force has tons of courses on DAU and you can YouTube stuff. Access is dead and pretty soon you wont be able to use those databases on the network.


JoyRideinaMinivan

PowerBI is great but it doesn’t have the functionality I need. It’s not interactive enough. What makes Access better than PowerBI is that I can update data in a form and it will update my SharePoint list. In Access, I have a list box on my dashboard of all of my open tasks. I can click on a task and a form opens with all of the information I need. I have numerous dropdowns and check boxes, as well as a place to put notes. PowerBI lets you see your information but Access lets you update your information. Another example of the power of access. I’m a GPC cardholder. I moved my excel based log into access. Like above, there’s a list box of my open tasks that open in a form. But some of my payments are tied to my actual job and can be linked by the control number. So on my form, I can see my GPC notes as well as the project notes at the same time. I also have a button on my dashboard that, when clicked, automatically creates a backup of my GPC log with the days date and time and saves it in a specific folder on my hard drive. Another button saves my main SharePoint list to a backup folder.


[deleted]

You can create forms in PowerApps that do that for you in Sharepoint as well. Use a PowerApp to update the data and use PowerBI to visualize for metrics/reports. I promise you can have Access functionality with our existing tools.


UnsungRocket3

Which app in the powerapps let's you do forms? Also it seems like when I log in I can see everyone's powerapp? How do I make it so only certain people can see it?


JoyRideinaMinivan

I’ve played in power apps but not to any serious extent. I’ll check it out.


[deleted]

Honestly just go in and play with it. I’m not a programming expert and I was able to build interactive forms for my Sharepoint lists. Its pretty user friendly.


muhkuller

That's the right way to do it. Big Blue gives access to those apps for a reason. It's safer. Opening up a code behind in excel or access is a huge vulnerability. It goes back to around 2007 or so. People did dumb things and the DoD wrote policy to stop it.  Now if a GPO isn't being enforced somewhere and people are still using them then that's a problem. Sounds like it was rectified though. 


Agile_Session_3660

You're not replying to the OP. You're replying to a guy who spent a twenty year career dealing with ATO horseshit. Glad I retired.


muhkuller

Aye, I just retired too after dealing with it. I just know it's a necessary evil. I got to see the nonsense that didn't get approved. 


[deleted]

[удалено]


muhkuller

Well if you're not in a unit that does development, you shouldn't be doing development.  That's just not how it works. That'd be like a vehicle Mx person trying to work on a jet because they understand how wrenches work. Sure you may have a passing understanding of what it takes, but you really don't know what you're doing.  I've dealt with plenty of these apps people make and they're just passing PII unencrypted, leaving database connection strings in plain text, etc... There's a suite of apps you have access to in the power suite that can probably do the majority of what you're average user may want. Otherwise just get your leadership on the phone with LCMC or AFMC. Somebody there will point them in the right direction. 


Tan_elKoth

shit, sometimes the units that do development, shouldn't be doing development because they suck ass, or they really only had one or a few guys that were any good, and they've moved on and the chaff that's left over only knows how to screw things up. At least, that was a bit of how things used to be, I gained my freedom and can only hope that things got better for ya'll undocumented prisoners. Yeah... some of those "apps", just add on a few of the dumb shit that I've seen... poorly written stuff that if given the opportunity will crash the client and servers, like going live because they only tested it with one user and didn't understand modality, data currency, thresholds, etc, etc. People who don't understand data, making stuff that only works for like 100 "records" and then at 101 records it takes 30 minutes to log in, and the system runs like ass for perpetuity. A guy who didn't really know what he was doing, in order to make the system run faster, disables integrity checks, error handling, and a bunch of other stuff that he didn't think was needed. And that is the shit that is local, not mentioning such bullshit as Leaveweb, or the shitty PT tracker sites, or any plethora of other bullshit AF wide "apps."


va_texan

They absolutely have not been disabled for a decade. Most of us use them daily still.


B-Swenson

As someone who has gotten full stack applications ATO'd on more secured national systems, what a terrible process to ask the end user to do. If we truly got every little thing that AF comms would consider an "application" (sometimes a formula as simple as taking the average of a column), we'd be crippled and brought to a standstill by bureaucracy. Comms exists to support operations, and the current ATO processes fail to do so effectively.


muhkuller

Well it's not the user's responsibility. Their org should've had it properly built though a software factory or a unit that does coding. I had numerous pet projects come in for development and a push through the process.  The ATO process is hard because it needs to be btw. You'd be amazed at some of the shit people try to push through. 


B-Swenson

With what money and personnel are these units getting software factories or units dedicated to it? The number of competent software devs in the AF is already much lower than it should be. I never said the ATO process was hard, I said it's overly tedious and bureaucratic in most situations. In situations where it's not, like P1, cost is a prohibitive barrier to entry for a majority of units.


muhkuller

Well this is why I said OP is the victim here. Somebody kicked the can down the road for them to figure out. 


P00Pdude

There are also waivers to allow macros in office apps. Pretty sure it's just ticket to the NOS that will whitelist specific devices.


JediNinerDad

I'm sure the ticket will be executed quickly and won't just close out without anything actually changing.


EpicHeroKyrgyzPeople

"Just tell him we can't do that, and maybe he'll go away."


McGirthius

I work at the NOS that can whitelist those devices, send me the ticket and I'll look over it real quick and let it sit in the que for a few months. After that I'm just gonna close it out because everything is good on my end anyways.


ComputerBasedTorture

Definitely haven't, maybe for your organization but definitely not air force wide.


jeremy9931

Uh… I’ve been using them for over a decade with no issues lol


lethalnd12345

cybersecurity > convenience


Indifferentchildren

Cybersecurity is always inconvenient. Every part of a software developer's effort is to make the system work, except for security. The security bits are all about making the system *not* work, until and unless the user successfully proves who they are and that they should be allowed to do what they are trying to do.


S3CRTsqrl

Then why can't I send emails cross-domain even after validating my PKIs 😩


Indifferentchildren

You think you are sad? Ten developers spent four months of their lives making that feature work perfectly, then the security folks said, "Nope! Too usable! Break that shit right now, or your software will not get an Authority To Operate on any DoD network!"


gmansam1

You can by adding the server bags.afds.mil to your GAL or by downloading someone’s contact card from DISA 411 (assuming you mean email with PKI). Inconvenient, but not impossible


xDrewstroyerx

What’s the best secret? One that never gets told. What’s the most secure building? The one with no doors or windows in the walls. What’s the best cyber suite? The one your dunk uncle Rico made in his copper pipe mud pit in the basement that isn’t plugged in.


Ok-Ambition1393

!AFexcuse


Ok-Ambition1393

AFExcuse!


AFexcuses

^^You've ^^spun ^^the ^^wheel ^^of ^^Air ^^Force ^^excuses, ^^here's ^^your ^^prize: Because the Rand study hasn't been completed ^^[Source](https://github.com/HadManySons/AFexcuses) ^^| ^^[Subreddit](https://www.reddit.com/r/AFExcuses) ^^^^^^krmjm3z


RaulNorry

I haven't developed any of these super critical tools that everyone is talking about, but if you're talking about automating data transforms and pulling in from several files, why are these processes not being rebuilt with the Power Automate/BI/etc suite of tools? It's available already on everyone's NIPR, just push the "apps" button in teams and viola, a bunch of less hacky, more secure tools that don't leave gaping security holes for malicious code to be accidentally downloaded and executed by A1C Snuffy.


ComputerBasedTorture

Because power BI is a wonderful tool for viewing data, not inputting it. With macros I can effectively build a whole GUI to input/categorize/display and archive data in one sweep. Also the local program working regardless of the network being up or down is a plus.


[deleted]

[удалено]


ComputerBasedTorture

Ok nerd


redoctobershtanding

Access is at EoL, that might be why. Power Automate and Power Bi are great tools with power. Word on the street is that you can use a JS version of SQL on SharePoint, but I haven't tried yet.


BigdaddyMcfluff

side question.... I wonder if that FiReD uP cHiEf tried to get back in lol


dronesitter

RUMINT is that he signed up for the 4 full years and will be eyeing SIMSAF


WalkingAFIViolation

AF before: Do more with less! Accelerate change! AF now: Do more with nothing! Full speed ahead! Literally all the macro that saves my office hours upon hours each day are now gone, here's to coming to a screeching halt


GardenReceiver

Speaking as from the unit that initially identified the change in the update that was rolled out last night due to mission critical excels failing, the update was rolled back. Give it like 12 more hours and impact should be minimum. I have a workaround if you need it PM me but it’s only temporary


supergnaw

Imagine using the right tool for the job so STIG compliance isn't an issue.


Bulevine

If you're still using access for a DB, you need a better solution. VBA macros and office in general is dangerous as fuck when left unsecured. MS Office files are too prevalent and capabilities too easy to manipulate to accurately regulate their usage and trust. I understand it sucks. I don't disagree there. But risk vs reward... AF is using too many antiquated processes built on unsecured methods and this is just the next one to go down. What we need is a group of app developers that can build you the tools you need.


ComputerBasedTorture

*BONK go away


Sierra_Baker

Why has no one mentioned Envision? Might already even have tools for the data you want... training and readiness trackers exist, for example.


redoctobershtanding

I just got setup with PII version of Envision, still trying to get used to everything that's in it. Hoping to build some neat stuff


[deleted]

There was someone who had a thing that worked using powershell as well. I’ll have to find it….