The curious case of the Raspberry Pi in the network closet (2019)
blog.haschek.at
blog.haschek.at
Sadly it's pretty anticlimactic as the owner of the place had a meeting with the guy who put the Pi there (without me as he didn't want the Pi-dropper to feel ambushed) and in the end decided not to escalate it to legal and just basically told him to pack his things and get out.
So no legal after play and just a slap on the wrist
edit: Thanks for the write-up btw. Was a nice read, although a bit short (which is the story's fault I guess)
But by trying to mitigate the risk of toxicity you can go too far in the other direction and end up not pushing smart kids to reach their full potential, which is also bad. Striking the right balance is hard.
Someone I know was called gifted at some point, he didn't end up in any accelerated programs but he did end up in higher education... which he only finished after many years, meanwhile he was eating, drinking and smoking his student loans + job income away, he ended up broke and in debt, and to date - 10, 15 years later - is still unemployed.
The poster seems to have confused top-tier private schools and gifted programs. Read enough politician and C-suite and such bios and it's very clear what's going on. You practically never see "attended a pretty decent public high school—but was in the gifted program!" Private college prep secondary schools (at the very least—often it's private schools all the way) on the other hand are overwhelmingly the norm in that set.
It's kinda depressing as a parent. If you haven't scraped together 25+k/yr for elite prep school tuition (and, probably, boarding) all your "you can be anything you want if you try really hard!" is kinda a lie. Like, that's still much better than not trying hard and will likely improve your life outcomes, but, looking at the actual world, realistically... nah, sorry, you're probably locked out of a lot of options. There are de facto requirements, and we couldn't afford them. Sorry kid.
Similar story with The Arts. You start looking at the backgrounds of very high-paid artists of all kinds (actors, musicians, even authors a lot of the time if they're considered good and not "merely" popular) and you're likely screwed if you weren't at least one of: 1) born to a family that's already successful at that, or 2) had an expensive and very focused education starting before college. Lots of the successful folks had both of those things. Again: there are counter examples, and it's technically possible to get in if your parents weren't in the arts and you didn't start gigging/acting/attending-an-artsy-private-school by the time you were 12, but realistically you're looking at a serious uphill battle.
The complexity of art and math doesn't change depending on how you learn or how rich is your father. Even with support a kid has to gain the same useful skills. What matters is ability, not how the kid got there. They are just kids, everything that shaped society into what it is happened before they were grown enough to have any say in it.
To which data set are you referring? Data from 2019 found that 80% of Fortune 100 CEOs hold undergraduate degrees from public institutions[0].
[0]: https://www.forbes.com/sites/kimberlywhitler/2019/09/07/a-ne...
FYI, $25K/year won't get you an elite prep school these days. For that, you'll need at least $60K+.
Once I got to college after graduating from a boarding school for gifted teens it was like a culture shock back to the world of horrible professors. I nearly failed out of college due to being completely uninterested with the lack of engaging materials in first semester classes.
Ended up with a degree in broadcast journalism because it was an easy path to graduating in less than 3 years. Especially because I was graduating during the 2008 financial crisis and just wanted to be done with school and find whatever job I could to get a start in the real world.
It's a nice piece of paper for HR to nod at and let me pass the degree hurdle.
My favorite moment was working a shit retail job in 2010 and running into another graduate of the same gifted high school working a fast food job just to survive.
EDIT// I did have some classmates go to found companies, work for NASA, etc. They were driven people who could have prospered in any scenario honestly.
It got me some interesting opportunities here and there but I am fundamentally kind of a slacker :)
The problem with this is you have no idea what harm the guy actually may have caused; nor what other RPis he may have set up around the company or around town. Next time he may be more careful with his username, set up the disk to be encrypted w/ a network key, &c, making future exploits more difficult to track down.
There is a systematic issue at the heart of the way we do network security.
You can by a lighting / usb cable that can do all of these things and more for $120 if he'd used that he'd never have gotten caught.
We treat network security like physical security at our peril.
I think they are talking about this particular, singular, bad apple and the other companies that bad apple is also attacking right now and stopping that harm as opposed to "sending a message" to other bad apples.
If after the business owner sat down with the perpetrator they decided it is just some script kiddie playing at being a spy then that's up to them.
The wider issue remains that some script kiddie with $120 could have done this and got away with it for ever.
I used to live in an apartment that was within high gain antenna range of the local McDonalds Free WiFi. I had a antenna/wifi adaptor set up in promiscuous mode to listen to all traffic on their network, looking for MAC addresses that connected for a while, then stopped connecting. It'd then switch to that MAC address and BitTorrent until the 500MB daily cap per device ran out, then go back to monitoring mode looking for someone else who'd agreed to the captive portal T&Cs had their MAC address whitelisted and then left. I think I got pretty much all of Game Of Thrones that way...
For a little while, I was monitoring my own home network, and one thing I tried was running map against any reconnection of a known/allowed MAC address, to try and confirm it at least looked like the same device. A RaspberryPi connecting using the MAC address of a phone or a MacBook stood out like a sore thumb. That never turned out useful enough for me to bother wrapping it up into a project I kept running or would have shared.
Probably by actually connecting it to the internet. Since the idea that you can keep people out of your network is probably more dangerous in the long term.
Unless people are manually verifying GPG keys in person all the time, you're gonna need to trust someone. Even with a two man rule you need some degree of trust. Trust is easier when people know they might go to jail if they break it.
Most private and embarrassing stuff rarely ever matters anyways. This isn't a movie
As someone who has done security research for over 15 years, I take the ethics of this sort of thing seriously. I fully expect repercussions of the legal sort if I did something like this without permission. The key detail being that this was done secretively in a private office.
But in this case.... the motive seems to be unknown.
There is actually a solution for that (shameless plug): https://www.recompile.se/mandos
Is this something you created yourself, or was it a community project?
The level of understanding required is something I would think that all system administrators worth their salt had at the time. I would think that the best way to acquire such knowledge is doing the Linux From Scratch⁴ exercise, even though I have not done it myself.
1. RFC 6091
2. http://www.dns-sd.org/, RFC 6763
3. RFC 7250
I still recall how to build a Linux system from go. Coding what you're working on up in Python/C would take a large unrelated amount of knowledge.
The first version of the program used a simple UDP broadcasting method to a hard-coded port to find servers, which required some rudimentary networking knowledge, but only basic TCP/IP stuff.
Later, both the server and client parts have gone through numerous refactorings which brought in many features (like a plugin system on the client side, and a D-Bus interface on the server side), but those were manageable chunks to add to an already mature and working system.
But sure, in addition to the knowledge one could acquire from LFS, I also had some high-level knowledge of how TLS and its handshake worked, I knew that there was some way to use OpenPGP keys instead of X.509 certificates in TLS, and I knew a little about how DNS-SD worked. The rest I needed I read up on as I wrote the code.
Also, I don’t really see any discussion of availability concerns. This is a system with a pretty gnarly fail-closed kill switch that could happen with a simple network outage. That doesn’t really seem to be acknowledged and there’s no discussion of the inherent balance between security and availability. You really need to be able to guarantee a certain level of availability or things basically self-destruct. Presumably there’s a mechanism that allows a self-destructed pair or cluster of these mandros’d servers to go back to a normal operating mode?
Anyway, I don’t mean to be too critical. It’s a really cool project. A little Byzantine but with a stated reason for that. Would just like to see more focus on the weaknesses and potential critical operational issues. A section called “reasons you may not want to use this” that is very up front about those seems appropriate.
Yes, that is a weakness, which is openly addressed in the FAQ: https://www.recompile.se/mandos/man/intro.8mandos#quick TLDR: It only works if an attacker is pretty quick about it. See also here: https://www.recompile.se/mandos/man/intro.8mandos#security
> And what about the vector where someone attacks the CA that issued the certs?
There is no CA involved, nor any X.509 keys. The keys used in TLS are ed25519 raw keys, and the server has a list of, and checks, individual key fingerprints.
> This may be moot if you are using self-signed certs, but of course those introduce their own management issues.
Yes, you have to generate and transport keys out-of-band (i.e. by hand) as part of the initial setup. The instructions on exactly how to do this are shown as part of installation and configuration.
> a pretty gnarly fail-closed kill switch
That’s a feature. A security system should fail closed.
> Presumably there’s a mechanism that allows a self-destructed pair or cluster of these [mandos]’d servers to go back to a normal operating mode?
Yes. You either type in a password on the console on one of the servers, or use a dropbear to ssh in remotely to do it.
> A section called “reasons you may not want to use this” that is very up front about those seems appropriate.
The project is mostly intended for those people who have already decided that full-disk encryption is a requirement, and Mandos is meant to alleviate some of the pain which they have already accepted. But sure, I see your point.
Of course, but there should at least be a mention of the fact that you need to tune the fail-closed parameters to take your availability into consideration. I appreciate that the various attacks would have to be done "pretty quick" according to the FAQ but the definition of "pretty quick" is necessarily countered by what kind of guarantees you can make about your availability (of the server(s) and the client), and this isn't mentioned. If a 30 second network failure causes the server to refuse keys to the client from that point on, but you can't guarantee that level of network availability (taking into account things like replacement of network switches and other types of maintenance), the definition of "pretty quick" may be too quick. It's a very direct and explicit tradeoff between security and availability and that concept is absent from the intro/FAQ. As a mental exercise, consider how you'd answer the FAQ "So I should set my timeouts super low for better security?"
Again, I'm not trying to be a picky ass, and I think the project is cool. I just think this is a topic that non-security-folks don't necessarily think about automatically, and this is the opportunity to make them think about it. The entire doc sounds like "faster timeout == better" and it would be very unfortunate for someone to configure and deploy this based on that understanding.
PS your other responses to my nitpicks were great, and somehow I missed the entry about stealing the client key being possible but having to be done very quickly. Thumbs up. I'm curious about what you mean by saying you aren't using "x509 keys" though. You must be generating a self-signed x509 cert containing the client's pubkey in order to do TLS. The packaging of the key itself isn't really relevant, is it? The "cert validation" on either side doesn't really care much about the contents of the cert other than the pubkey encoded therein, but you still do actually have to create x509 certs using those keys unless you've completely butchered the TLS stack. Right?
Also, you could add the Mandos server status to your alerting system, and if anything goes wrong with your network and the Mandos server times out for a client, you can be alerted to this fact, so you can fix it before the next time that client happens to reboot.
> consider how you'd answer the FAQ "So I should set my timeouts super low for better security?"
Fair; the text could be clearer about this.
> I'm curious about what you mean by saying you aren't using "x509 keys" though.
Well, we aren’t using TLS with X.509 keys. We are using TLS with Raw Public Keys, as specified by RFC 7250 (https://www.rfc-editor.org/rfc/rfc7250.html) and supported by GnuTLS: https://www.gnutls.org/manual/gnutls.html#Raw-public_002dkey...
Teddyh's answer describes some of the technical aspects, through I would like to add the security scenarios that Mandos works to address. Any security measure is in one way or another designed with known threats, assets and costs/outcomes.
If one operates a bunch of servers with FDE in a server room, getting there every time there is a need to reboot is a significant problem. To mention a few causes, redundant nodes going up and down in the middle of the night, updates to the operating system and kernel, and misbehaving hardware. At the same time, those servers are likely to hold a lot of sensitive data to companies or persons, especially email, which puts the administrator at conflict between using full disk encryption or not using it. In my experience, unless there are regulations that dictate otherwise, servers are not encrypted because of the hassle and downsides of manual or needing to attend reboots in person. This was the initial case as to why Mandos was created many years ago. If the server hall loses both primary and backup power, there is a real risk that the administrator does need to travel there to bring the machines back up. That would be one of the major trade offs, through I would still recommend administrators to do that, compared to the risk of an unencrypted disk getting lost, stolen, or cases where someone comes in and takes all the servers.
There are naturally other scenarios that one can use Mandos for, but like any tool it's good to know whats it is designed for. It is not intended to replace setups where one is already using FDE where one types in the passwords manually at the terminal and is happy with it. If one does not need the unattended aspect but want to remotely reboot the server, there are things like Dropbear or IPMI/remote KVMs, in which case the security will rely on those components' security. In my experience, IPMI's security should not be exposed to the internet which means one first needs a security entry point to the local network. Dropbear uses ssh which mean one should use client certificates and verify the signature before use. Depending on the use case and what risks one wants to take there are benefits and drawbacks, but the key point I do want to come back to is that people really should use full disk encryption and Mandos alleviates the primary reason people don't use FDE.
Yeah, I agree with all of this. My nitpick is just basically requesting the doc talk about this being a conscious tradeoff where your infra availability and your lack of tolerance for frequent fail-closed events might lead you to intentionally weaken the security guarantees by lengthening the timeouts. In other words, you set the timeouts as short as you can tolerate, based on your infra.
And at one company they were worried about the devices getting stolen, so they could had HSMs and still couldn’t reboot unattended (though most of the signing keys were with humans rather that automated)
I though the suspects were an ex-employee, and some guy that didn't work there (the part-owner), so was an actual current employee implicated in the end?
> It was registered (or first deployed or set up?) on May 13th 2018
and the post itself is dated 2019-01-16
Since it says:
> he could still have a key for a few months
I assumed that by then the employee had given back the key, but I guess I was making a few assumptions about when this happened, and when the device had been installed - they don't actually say what date the RADIUS logs revealed they had accessed the network.
I think he got off way to easy.
Great write up. Thanks for sharing.
Just to have a thread to pull on, in the future, when something might go wrong.
In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena.
But even though we could never decipher what the nodejs program actually did (because it was so heavily obfuscated) our internal working theory is that he was tracking the movement data of the boss to avoid him whenever possible.
Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job.
I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company network for IP-theft, black-mail or other such data exfiltration purposes.
If only he knew that in a year he could avoid his boss all the time thanks to covid-WFH.
I’ve mentored a lot of juniors. It’s not uncommon for young people, especially those with less developed social skills, to have an undeserved fear of their boss or anyone else with authority. It’s common with young people who have debilitating anxiety and a tendency toward rumination. They think that as long as they avoid the authority figure, they can avoid any negative social interactions (which are largely imagined).
It’s possible that the boss was bad, of course, but I kind of doubt it given that his response to this situation was to let the person off easy.
Sure, but even as a junior employee, we're still talking about mature adults here, not kindergarten kiddies, who can vote, pay taxes and are held accountable for their actions in front of the law, so they should be aware that deliberately backdooring their employer so that they can surveillance their boss, not only most likely violates their employment contract they signed and can have serious legal backlash against then both from the company and from the person who's privacy they were trying to break.
>It’s common with young people who have debilitating anxiety and a tendency toward rumination.
Yeah, I get that, but how is this in excuse for hacking your employer/boss? Why not seek therapy from professionals for that and try to either quit toxic workplaces or report abusive bosses and find a workplace that accommodates your personality and emotional type, not try to hack and backdoor your employer's network to keep tabs on your boss.
There is no workplace in the world and no work colleagues that will tolerate you hacking their network and invading their privacy because you have anxiety and a tendency toward rumination.
No disagreement here, but to answer your question: If someone is struggling with social anxiety, they actually have to somehow overcome their anxiety enough to seek that help. It can be a real catch-22. (Not a justification for this person's actions by any means. Just explaining motivation.)
It’s a wider range than you’d think. Juniors range from seasoned employees who have had various jobs over the years to completely green employees who have never had to work a day in their lives. The latter group can allow a lot of people to avoid dealing with their problems and maturing for a long time.
> Yeah, I get that, but how is this in excuse for hacking your employer/boss?
It’s not, and I never said it was. I was only replying to the insistence that the boss must be a terrible person.
This behavior is never acceptable.
Like, I would be absolutely terrified to even accidentally overhear someone talking about this and possibly be dragged into it that way.
But within the theme of this thread, I strongly doubt the optimum solution is “full punishment in every case for everyone the moment they cross the age of majority.”
The day before your 18th birthday, you're a kid, the day after you're an adult. Makes perfect sense.
Clearly someone who looks at the world this way must be under 18.
https://www.tindie.com/products/dekuNukem/daytripper-hide-my...
I once worked at a place where one of the founders would too often get the shits with someone or some team, and become a micro managing asshole for a few weeks. I wrote a python script to run on the wifi router to monitor for MAC addresses connecting and disconnecting, ostensibly this was to publish a webpage with a "Is manager X in the building?" dashboard. Which also just happened to have filterable notification subscriptions and a Slack integration. Pretty soon, everybody he was micromanaging ended up getting 90 seconds or so notice of him arriving, as his phone connected to the wifi while he walked in from the car park.
The other managers and PMs all loved the dashboard, and I got a bonus for it at performance review time.
And what did the employees do with the information? Leave the building?
People in his firing line would mostly use it to make sure that they were at their desk and had Jira open while waiting for something to compile, instead of HN or Reddit…
The managers-in-the-building website dashboard stayed running for at least several years after that, when I left, and it was still in regular use. People liked being able to do things like go “Hey, we’ve got the PM, Account Manager, and the CEO all in the office right now, let’s grab the tech lead security guys, and set up a 3 minute corridor meeting to make this decision.”
Logging anonymized MAC addresses is one thing, but converting the MAC addresses to employee names, revealing their location on premises that is shared with everyone in the organization without their consent is a completely different thing and is illegal under most EU privacy laws (at least in Austria and Germany).
Sure, in theory the company could already know when I come it at work from the logs of me swiping my access badge at the main security entrance door but any such logs are kept private and can only accessed by security and upper management if some act of theft or gross misconduct has occurred which warrants an investigation.
Sharing this information publicly with everyone in the org would be a privacy breach. If you want to know if I'm "at work" just look at my Slack/$CHAT_APP notification color.
Don't plug shit into private networks unless you want it reverse engineered. This falls under the fair use exceptions (learning what software is doing / was doing to your network).
The copyright holder can take it up with whoever they licensed it to, there is a reason a lot of them read "not to be used in the commission of a crime".
You might even be able to find someone local. Maybe wander over to the next in-person security conference vaguely nearby?
Sadly you have no contact info in your profile so I can't even suggest to people seeing this to cold-email you.
(I objectively don't think I would be very successful myself, given that you've mentioned everyone in the office looked at it; I don't have a lot of relevant experience, which sounds reasonably necessary to be successful here.)
cries in UUoC
<erno> hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is.
"net send <host> 'If you can read this, please call IT SUPPORT at ... and tell us'".
It worked :)
The whole system falls apart when you have no idea where in the building the end device is, if you are lucky there may be a managed switch on the network route somewhere that may help you narrow down the location somewhat.
So yes, it did happen sometimes that the only way to find a box was to send a desktop alert and hope the admin of that box contacted you.
Network documentation in this case? No way. The only option is to pull it all out for recycling, and start over.
Some IT security departments have very confused ideas.
It’s often the case that somebody slapped something together in an area that wasn’t their expertise, it’s been noticed that it’s a real problem, and someone has been hired to fix that problem. The “not knowing” is often the reason they’ve been hired. Trying to sort out a real world scenario (while also handling other needs of the org) is almost definitionally Taking Responsibility. So let’s not shit on people trying to cleanup a bad situation by calling them irresponsible for not knowing.
The more senior I get, the more I realize there are often a multitude of reasons things are the way they are, and many times those are valid reasons, when seeing something that is broken.
Taking a beat before pontificating and making a fool of yourself will save a ton of heartache in your career.
When you see something so broken, ask yourself why? Then ask somebody else. Some highlights from my career:
1) Last guy got cancer in the middle of a build.
2) Last guy worked his way up from one man help desk to Linux guru over 15 years all on his own, but was so busy putting out fires, he never had the chance to improve things.
3) Project started out as a proof of concept and was intended to be torn down.
4) Due to government contracts, the system has to be maintained exactly as delivered, no labels even allowed, and obviously no IT staff(?!) To make spreadsheets. Everything was paper notes by operators.
5) Pure laziness and incompetence as you alluded to.
All this to say, more often than not there is a good reason something is fucked up, finding out why may help you fix it (like in the case of politics, budget issues, firefighting, priorities, etc..)
If you’re hired because the old person didn’t follow basic maintenance procedures, you’re still ignorant until you rewire or trace the whole company’s network.
A Physical keystroke logger if you want to think of it that way.
[1] https://www.theverge.com/2019/7/14/20692471/logitech-mouseja...
Even if the data stream itself is encrypted there's still a little bit of data leakage. Your keyboard isn't constantly sending data, it really only chirps when there's an actual keypress event. So if you look at the actual physical RF, you 'll notice patterns related to the user's typing. There is some research in trying to guess key presses based on typing cadence, although I'm not sure exactly how effective it really is.
I say all of this typing on a Logitech Unifi keyboard amd routinely use bluetooth keyboards. As others have mentioned it really depends on your threat profile, and in the case of wireless keyboards you probably aren't near the level where this paranoia is justified. Are you typing state secrets that a foreign government body really wants in a public place? Probably want to have a wired keyboard...or maybe just not type such things in such places. Are you typing out a comment on Hacker News in a private space? Probably have nothing to worry about with a wireless keyboard.
Such features could alleviate some of the parent poster's concerns.
Sure, in an ideal world that would be possible - but we didn't even have access to the switches. So either it's trying to hunt down the other department in another building who /might/ solve that riddle in an unspecified amount of time... or just do it :)
ejectHe sent one to “*” saying something about the FBI or some such, and evidently it ended up reaching computers across the entire local school system (not just our public school).
He was called out of class days later after they looked up the IP and library computer access logs.
I had to use my firewall to monitor the network traffic of the IP to determine what the device was. It turned out to be a long-forgotten smartwatch collecting dust on a charger tucked away somewhere.
It had an open file share, containing some Delphi books and from which we got the computer name too. So we walked over to the Delphi team's side, and kept yelling the computer name until some dude said "Hey, that's me!"
Turns out he was running a test-case, in an infinite loop until it worked (because that's how test cases worked), and he thought he was pointed at QA, but he somehow had it set up to target Prod.
Our job was done at that point, we left the rest to management (who made sure he didn't get fired but didn't do it again).
I try to tell people: "You don't need AI security, you need a checklist." Colonial Pipeline reused passwords, shared passwords, used the same password for all VPN users, failed to rotate it when people left. (that's 4 insanely basic violations of password security). ANY human who did a security review would have caught that. Even an intern who knew nothing and furiously googled "information security review" on the bus on the way in to kick off the review. (no disrespect to interns in over their heads, my point is they didn't prioritize security so they didn't get security)
Capital One used an admin privileged instance profile attached to a publicly accessible admin interface for a security tool (which tool, by the way, had no need of admin credentials). They were hit by an SSRF vuln and leaked their admin credentials. They also failed to alert of unexpected use of those credentials (try it, use of admin credentials is rare enough you won't have a lot of noise) failed to alert on large outbound connection (this one is subtle, but worth doing if you can figure it out)
Equifax failed to apply security updates regularly (just turn on automatic security updates. People suck at chores) Failed to deploy a SIEM, failed to conduct periodic security reviews, failed to put capable security people in place.
The above are not my clients, just public reports to illustrate that everyone can benefit from a security review to catch the obvious errors.
We now have a process that routinely scans our entire IP space for machines that somehow get lost from our inventory system.
I have something that sends me an occasional email. I haven't needed it in years, but it's not in any of the AWS regions I remember ever using. Nor in the obvious places I might have put it playing around with azure or google cloud or whatever. I'm sure I could find it if I really tried but t only emails me once or twice a year so I just let it be.
Well, its more like an order of magnitude slower than the Pi (and with a lot less RAM as well)
> A very powerful wifi, bluetooth and RFID reader.
It's 2.4GHz, but only BLE and custom protocols (2 Mbit max, GFSK modulation). The SoC can do RFID, but you have to connect a transmitter coil to use it, which doesn't seem to be the case from the photo.
I'd guess this was just used as a remote control backup connection if LAN is not working?
I think the dongle might just be Nordic's cheap evaluation board.
> Not the actual site but a similar one
Looks like the article, when speaking of tracing down a wrongdoing suspect, used a screenshot of a Web page of an uninvolved Web site. The screenshot included photos of actual people presumably uninvolved, and a name, phone number, and email address also presumably uninvolved.
While I'd guess this probably reduces Internet vigilantism and accusations of libel (at least involving the actual suspect), I suspect that a journalism professor, editor, or lawyer would advise not to do it that way.
Anyway the long and the short of it was one of their technicians was caught with the previous vendor's SMS-C prized open and some USB device insert into it. Similar response to this, a lot of hollering and hair pulling, but ultimately no contractual or legal implications.
I guess it happens higher up the food chain too.
I have personally identified more than a handful of employees who'd use their work computers for... let's say "access to inappropriate content". All of them where invited by HR & legal and let go with a more then decent deal.
Absolutely everything was done to prevent the company being associated with anything nasty.
In entirely unrelated news, this guide details how to set up an encrypted boot process on a raspberry pi, with it waiting for you(r forked login agent) to ssh in and provide the LUKS password: https://github.com/ViRb3/pi-encrypted-boot-ssh
Turns out that one of our sysadmins was running a porn server in the DMZ
I've always enjoyed having unique/personal SSIDs, but had never seriously considered this consequence. I wonder what the worlds generic SSIDs are.
What's more important is that you don't set your SSID to hidden: Someone needs to broadcast the SSID for the connection to work, and if it isn't the AP, it will be your mobile device broadcasting it everywhere you go!
xfinitywifi is the top, with 2% of the routers seen having that name; it's followed by XFINITY (.73%), BTWiFi-with-FON (.38%), linksys (.37%), BTWifi-X (.35%), <no ssid> (.31%). The next one is AndroidAP at .28% and that feels like a good place to stop copying data, go look at the page if you wanna see more of the world's generic SSIDs. Basically "manufacturer name" and "internet provider name" dominate.
One comes with more easily identifying you/your network while the other comes with being more easily hacked by readily available rainbow tables (I think, but am not sure, that WPA3 fixed this, but WPA1/WPA2 use the SSID as a salt for the password)
(For those OOTL, see https://blog.benjojo.co.uk/post/smart-sfp-linux-inside - it made the rounds on Twitter and HN a couple days ago)
This reminds me of a discussion I've seen... when the Pi first came out I think ? About how we could soon make whole electric kettles or even keyboards (and Pi recently did it !) with whole spying (on wireless) computers built into them, unbeknownst to people not aware of that "extra functionality".
(IIRC with the context of potential Chinese spying ? The current reality is a bit more prosaic : USA can likely just use the backdoors (they likely have) in Intel CPUs (or Windows), and the Chinese - in Huawei's networking gear.)
I’m wondering if there was an easy way for the attacker to encrypt or obfuscate some of these configuration files, so that defenders can’t extract settings even when physically connected to the device.
Ofcourse you can still defeat this if you dump the memory or reverse engineer the process to get the key yourself. Makes it a bit harder but still not impossible.
Make sure you don't have any work deadlines in the few days after you start it.
The individual stories seem to be still available on the non-archived web here: https://www.toolbox.com/user/about/ChiefMonkey/ but not, from what I can find, the convenient story index, which I linked to above.
He seems to have planned a rewrite of all the stories and put them on… Medium.com: https://medium.com/@chiefsecuritymonkey However, the last update is from May, 2020.
How frequently does IT run scans of what software is running on the server vs how often does IT physically inspect the server? Remember, one of those things means I have to get up out of this chair and the other does not.
What a technical dad you have!
Working for over 35 years for IBM and inspiring BASIC/REXX to ones child may do the trick -> https://blog.haschek.at/about/
- Losing access to forensic data by not capturing the contents of the device RAM. Pretty common.
- Becoming witness of a crime and getting personally targeted by some criminal organization in retaliation. This one should be obvious.
- Wasting the opportunity to keep the device on to monitor the activity of the intruder
I will never have enough. Amazing read!
Monitor BLE traffic, filter it to a known device (his boss') and update an IoT server with that information when it changes?
On an RPi, that's not even an afternoon of work. I mean, it's cool and I would definitely want to interview someone who did this, but it's hardly "hire this person now!!!" material.
I'm suspecting it would require for them to make a new SOC, breaking compability?
That's the problem with the entire RPi ecosystem - there's a lot of things people want "even if it only adds another few dollars". Another ethernet, proper m.2 port, better audio, so-dimm slot etc etc etc....
The Rpi is meant to be cheap. Yes it means that it might not include the feature that you want. And no, "just making it a little bit more expensive" is not the solution here. It's already gotten way too expensive for what is was meant to be originally.
And if you really want a Pi with built in flash, then the compute module has that:
https://www.raspberrypi.com/products/compute-module-4/?varia...
This is substantially simpler for beginners than using network boot, or messing around with a bootloader via serial console.
If that's not enough, the eMMC could even come preinstalled with an OS.
But AFAIK this shouldn't be an issue any more (assuming a non-counterfeit charger) with USB-C 3.0 (RPi 4+ ?) which starts at 15 W ?
Sorry these are two different distributors, but the CM4 is hard to find right now and the PiTray mini is cool, just couldn’t find them at the same place. PiTray mini is also at Digi-Key I think.
https://www.seeedstudio.com/Raspberry-Pi-Compute-Module-CM41...
It already has the USB port for power, surely they could have gotten Broadcom to include USB serial in the SoC for negligible cost by now?
Lovely!
I could be mistaken though; only over installed on a Pi 3.