294 karma · joined June 25, 2020
There was only one type of sign but it did come in various different cases.
You are correct that with domain control I am able to serve content to any sign but the content will only be loaded once at boot time. Any future updates would have needed to come from their defunct AWS IoT connection (ignoring full restarts).
Using the exploit I remove the connection to AWS IoT and update some of the code to better connect it to the recreated API so users can update their signs in mostly real time.
> Good question! No signs connected to the server until I reached out to some other sign owners to try out my instructions.
I do not know how many signs are out there. I imagine most people would have just unplugged their sign after the company's API vanished since any data would be stale and useless.
The sign did use AWS IoT for real time configuration updates however initial configuration was pulled from their HTTP server. Using the vulnerability I describe in the article I just remove the connection to AWS IoT.
EDIT: Here is the specific tweet: https://twitter.com/NYCTRAINSIGN/status/926106932573810688
[0] https://hackaday.com/2023/01/09/iot-archaeology-leads-to-api...
My apologies for the downtime, I wasn't expecting much traffic today since I submitted the post to HN yesterday but I've started scaling my server now!
While I don't think the berries are worth the price tag, I'd definitely be interested in trying some of the new products they mention in the article (tomatoes, melons).
Here's another one posted about a week ago: https://github.com/gogs/gogs/issues/6536
Recently I was looking for a way to sanitize user generated HTML of malicious things like JavaScript.
Solutions like bleach, html_sanitizer, and lxml's Cleaner all work but I found that their performance on complicated HTML snippets were lacking because they needed to rely on html5lib for parsing HTML5. And completely normal content would get mangled without using html5lib.
I ended up writing these Python bindings to the bluemonday library. It seems to perform much better than existing Python solutions for the same problem[2]. I suspect because more of the work can be done in native code instead of having to pass an XML tree around.
Hoping that this is useful to someone else but also looking for any feedback. Especially about how the bindings were written.
I did come up with ways to assemble the chips faster but I couldn't optimize it enough so that I could remove myself from the equation. I ended up selling enough to get rid of all of the inventory I purchased and making enough profit to cover any tool/equipment purchases.
If anyone knows how I could streamline the whole modchip creation process I would be very interested!
I think burned discs are probably one factor but I think general hardware failure or dirty lenses are a more common cause.
https://www.digitalocean.com/docs/spaces/#bandwidth
Digital Ocean may not be the best cloud platform but it's fairly cost effective.
> Aggregate and anonymous data is exempt from the CCPA, unless it is in any way re-identifiable. https://www.cookiebot.com/en/what-is-ccpa/
IP to country is fairly easy and I open sourced all the scripts and the database itself [0].
But IP to city is much harder, I'm not actually sure it's viable for anyone to do that without relying on some other 3rd party service.
I'd be very interested to hear if anyone knows how to pull that off in an open sourceable manner.
I've been meaning to make automatic Github releases for it.