258 karma · joined December 27, 2019
clickhouse-local - https://news.ycombinator.com/item?id=22457767
q - https://news.ycombinator.com/item?id=27423276
textql - https://news.ycombinator.com/item?id=16781294
simpql- https://news.ycombinator.com/item?id=25791207
We need a benchmark i think..;)
After that, it's just the matter of putting a crontab job to run archive job every night. Note that i have no way yet to know when the mouse move in macosx as xdotool no longer work with mac so right now it takes screenshot of every monitor and resize it down... it might be too much and could eat up your HDD. i like the nix version since I did a dirty job with mouse location so whenever i take a break from incident or walk away from my desk, the screenshot script stops.
I have used these 2 on my machines for the last 4 years and writing tons of script for myself, here are a few:
- Displaying internet/internal ip and allow me to click it to put in clipboard
- taskwarrior
- Simple conversion script that take my clipboard & encode/decode in base64, hex, url encoding, convert epoch to UTC,
- "auto type" my clipboard by simulating keystrokes- particular useful for pasting text into terminal that disable clipboard
- An incident response switch that would trigger a script to take screenshot every 5 seconds when my mouse moves, reduce image quality and save it to a folder in my homedrive. Another script will GPG encrypt it at the end of the day so i can go back and get screenshot or look back at incident if needed.
Unfortunately i only see the old version here with flameshot taking screenshot at full resolution.. my few later versions turn screenshot to black and white and applied a few imagemagick tweaks to make screenshot file incredibly smaller to store but you get the idea :): https://gist.github.com/santrancisco/9d14e0105316cfa15f98f0f...
I then write another small bash script that use consolemd and surge(probably will move to github page at some point) to generate a simple webpage with simple markdown JavaScript library to serve it up along with all the files generated by consolemd so i can use curl in terminal and have it colorfully displayed.
The cheatsheet site is here https://ch.ebfe.pw/.
And you can try it in terminal: curl https://ch.ebfe.pw/intel/splunk
And my code can be found here if you are interested:
https://canarytokens.org/generate#
Like any other tools though, i recommend to have a script to trigger it every now and then to make sure it works (and alert you about it so you dont go into panic mode)... for personal stuff, I usually have a specific day in the month i expect to see some canary tokens fire :)
I wonder how/where they got this data? Did some third party phone app(messenger, whatsapp) dump our contact list somewhere and map those information out? This site is cheap to sign up for an account and it's a sweet honey pot for mass sending CEO phishing campaign.
The way it works is super simple: the anchortag is base on the tunnel name (first round of sha256 if my memory serves me well) and the actual "tunnel id" is a few first characters of the second round of sha256. This way by enter the same "tunnel" both devices can share file without the need to share long complicated urls. The files in tunnel only lives up to a day.
Unlike sendlight though, it is not peer2peer webrtc and it is using the same lambda backend to create signed urls for s3 and encryption done in browser like before, just a neat little trick to have a simple way to setup "room" between devices ;)
Note that the anchor tag part does not leave the browser so it is one of the clever thing firefox send used to share some id/key. You can double check it in the network tab ;) If you are worry about that key being leaked somehow, adding a password ontop is a good measure.
You can roll your own too with the terraform code in it. It costs me barely anything (never go over free tier limit) to run it because files never live more than 10 days (there is a catchall lifecycle rule on the bucket) and when users select durations, i also put them in bucket prefix that has lifecycle rule place on objects under them for that duration. Note that we can't rely on lifecycle rule all the time so i also make sure when lambda is called to access the object, it checks the time-stamp, the duration and if it is meant to expire and not yet cleaned up by s3 - lambda function deletes it.
I learnt a ton of cool things about s3 after this neat little project and really dig the API, the lifecycle rule, signing url etc...
Ps: for these type of tool, you should definitely mitm it to see if plaintext file or password ever leave the browser... Relaysecret does leave one item unencrypted and that is the file name. You can change it upon upload but i like to leave it there so people know what they are downloading. I have simple idea of encrypting that with just the anchor key but haven't gotten around to put that in yet.
having a quick glance, it does remind me a lot of que-go (https://github.com/bgentry/que-go) that is inspired by similar project written in ruby which use postgresql lock cleverly to take tasks from queue, work on it and release lock.
I liked the implementation so much and how easy it was to write worker for it, i ended up modifying it to use go channel (https://github.com/santrancisco/cque) as queue for worker task.. i used it in several personal projects over the years for cli tools that can leverage from having async tasks/jobs handle by workers.
For example, when we have tools that need to be deployed across 10+ AWS accounts managed by different Ops team, I hand them a CloudFormation template and they could run it, plug in the right parameters, pulling lambda code from the same S3 bucket we have etc... Totally agree with Writing Cloudformation is a pain but when you have it done once, it works consistently and we don't have to worry about terraform version, the tfstate etc... It just works.
I use terraform for more complicated setup, an environment that we keep adding ontop, share & manage among our team and need rebuild/redeploy often/quickly or an environment we need to spin up for various tasks (eg incident handling VPC, interview challenges, CTF events...) ... Terraform and its powerful reusable terraform modules/module registry make spinning up these environments in minutes make it extremely attractive.
Managing terraform version and tfstate is still a pain with terraform even with the help of remote S3 bucket & dynamodb lock but it is definitely better than when i first started and we had gpg encrypted tfstate.
With that said, I work in security and only very occasionally I need a big deployment like scalable spark cluster or multi-zone elasticsearch cluster etc... so perhaps I don't have enough indepth knowledge about each tools.
I'm sure there are plenty of flaws here but perhaps having Ads for good causes will at least make it more pleasant to the eyes than the current state...
Nice work regardless!
Shameless plug: I made a similar tool base off another project after FirefoxSend shuts down but deploy on AWS instead of GCP :) It is hosted here if anyone wanna take a look or roll their own https://www.relaysecret.com/. The design philosophy is the same (everything is encrypted on clientside, no plaintext or password leave clients browser, minimal backend).