HN user

evilDagmar

397 karma
Posts0
Comments193
View on HN
No posts found.

It's not inconceivable to suggest that the people claiming that the CSAM hadn't been removed knew it was still there not only because they'd never actually sent the request for removal, but because they themselves put up the original site and requested the CSAM be indexed in the first place.

It's amusing how the article says it's "potentially" in violations of US hacking laws.

That practice is _definitely_ a violation of the Computer Fraud and Abuse Act. No employer's IT is going to have it not be a violation for a user to share their password with someone else, which even in the weakest boilerplate immediately revokes their rights to the account. At that point _any_ use of those credentials is very much a violation of the CFAA.

Oh that app did a huge thing just by showing how far the administration is willing to go with its delusional fascist nonsense. The app was _barely_ functional and available on a minority of the smart phones, and yet there the White House was, making hyperbolic claims on a regular basis about the massive "dangers" it posed. They even went so far as to go after the guy's wife since they didn't have any legal means to oppose him.

Things which take minimal effort but produce a massive response are what Trump's fire hose of duplicitous social media posts are all about. It's perfectly fine work to leverage that same asymmetry in response.

The "disclosure" was a big waste of time. It was vague and ill-informed, nothing that came after seems to give the impression that they actually knew what they were talking about.

The only serious vulnerability that might have applied would have required the man to be using Apache as a reverse proxy to another server, which is just _extremely unlikely_ considering where it was hosted and what it was being used to do.

Truth. A stripped down configuration of that running nothing but personally-written code on the backend would pretty much render those issues moot (as in "completely mitigated").

Considering how lacking in detail the reports were, I'd probably have just dismissed this man's claims as "AI slop". That he was relying on nmap to tell him the version of something that is easily discovered using openssl s_client (because those HTTP response headers are perfectly human-readable) is kind of telling in and of itself.

These larger power-generation systems tend to be more efficient than smaller power-generation systems, not less, which should result in a cost decrease, not an increase.

Tennessee (for example) has fairly cheap electricity because the TVA uses a lot of hydroelectric, and since we have a ridiculous amount of rain and violent thunderstorms each year, every decade or two they build another hydroelectric dam and create a new lake, which generates more hydroelectric power (and a moderate increase in tourism/recreation). We don't have buried power lines (excepting in a very few places) but we've got a ton of redundant power substations and multiple transmission paths (because storms). The TVA and Corps of Engineers are kinda hardcore here otherwise the valley would flood about a quarter of the year and be sitting around in the dark for another quarter of the year.

Maintenance of the power transmission lines is paid for by the electrical customer as a part of paying for the electricity itself. This actually scales just fine. If your local electrical utility is not doing it this way, someone needs to explain to them how proper accounting works.

Calling a "hidden cost" is just a convenient way to say "We're making this up because we feel like it's right and we don't intend to show any proof."

This is completely missing the point.

Until there's a substantial number of driverless cars on the roads, LPR systems will always equate to tracking people. You might as well argue that exposing geospatial data about cell phone movements is fine because cell phones aren't people.

These systems, when abused, amount to warrantless monitoring of civilians over long periods of time. A judge can not and will not order someone's movements to be tracked over the last six months. They can facilitate someone's movements going forward to be monitored for a specific period of time.

...and these systems are always abused. To the degree that if you've put an RFP out there for a LPR system that disposes of the scan data after 30 days, suddenly no one wants to submit a proposal.

Abuse is pretty much the default state unless there are hard guardrails against it. That knucklehead in Millersville was pretty obviously using FINCEN data to go looking up the life details of people his political party didn't like, probably because the only safeguard was that someone had to enter a relevant case number to show that the search was legal. Lo and behold a regular audit being performed by the TBI resulted in a near immediate lockout of Millersville from their system and a warranted search of said knucklehead's residence because of "irregularities". It's not hard to figure out what was going on there.

It took months to get the LPR system in Mt. Juliet, TN to actually start disposing of the scanned data, and we've already seen reports of LPR systems being abused by ICE/CBP to search for people all over the nation. What's currently holding up Nashville getting such a system? I'm pretty sure it's the data destruction policy, because the state-level government is being run by people who think such Orwellian surveillance is just dandy.

Actually, I think the problem here is that he's reducing it to a cost-benefit analysis that applies to a single corporation alone. Corporations are notoriously short-sighted and generally unable to plan for or see into the future more than 1-3 financial quarters.

Facilitating investment in long-term things that benefit the country or humanity as a whole is literally one of the reasons we have governments. Putting men on the moon didn't make any profit, but a whole slew of discoveries and inventions that happened before that could happen definitely made improvements to everyone's lot.

In other news, yet another website fails at understanding that a hard redirect prior to a 404--instead of just issuing a 404 in the first place--is an idiotic practice that breaks browser history.

Guess what happens when people take antihistamines... Lovely, lovely side effects. Side effects which are generally equally as annoying as the original problem.

If one can treat the symptoms just as easily as the cause and pseudoephedrine doesn't make them feel like a drugged-out zombie, just guess which drug people are going to take...

...and yes, doctors actually will write prescriptions for pseudoephidrine because they're generally pretty sure their patients aren't using it to make meth. I know three people who've gotten such prescriptions, and I've been tempted to do the same thing myself.

You're kidding, right? For people with allergies and/or chronic sinusitis, it's a thing they're taking for about a quarter of the year off and on. ...and they _will_ practically "cut you off" if you buy enough to be taking it for 45 days straight, no matter how you buy it.

That phenylephrine (which everyone with sinuses knows doesn't do a damn thing) was perpetually being touted as a substitute was just adding insult to injury.

Absolutely. I have used the heck out of this on systems since I found out about rrsync.pl and read through the code to make sure it was using a solid approach.

With a quick keypair generation one can quickly deploy read-only (and probably write-only although I've never tried that) access to select parts of a filesystem and do selective near-line backups of important files into a "history" host of sorts, and even leverage rsync's ability to use hardlinks in place of files that have not changed since the last run so no space is needlessly wasted backing up 400 copies of the same thing.

It was wonderful that I didn't have to write such a wrapper myself.

No, stereotypes aside, hackers who code diligently tend to wrap their "actual work" schedule around their external obligations, and while the morning is generally filled with distractions like dealing with "morning people", after lunch (an on into the evening) there are generally far fewer interruptions. I can honestly get much more done with an uninterrupted four hours than I can in the entire eight office hours of random phone calls and emails coming in, and I am no longer a "young person", and I'll do some stuff at night just because I know it'll take half the time if I'm not interrupted and I've had a few hours to at least intermittently mull it over. If you're having peaceful mornings, I envy you.

Frankly I think they should just take their lumps and shut up. Other bits of the article mention that apparently Heise Online was able to freely download a copy of the binaries (passwords included!) from Modern Solution's website in 2021 and I'm going to guess based on that that other people probably did know about this who were reasonably moral about it, and the company was likely ignoring the issue... ...until someone offering competing services noticed it and said something, at which point they panicked and decided it was still cheaper to shoot the messenger than to hire a couple of highly-caffienated teenagers to fix their trash architecture.

And if you went somewhere you're not supposed to and found out it's a master key by trying it in those places you're not supposed to access, you'd be accused of trespass.

Hard no. That analogy fails because all the contractor needed to type was `SHOW DATABASES` which would be the same as looking around and seeing everyone else's stuff just sitting around in piles, completely unsecured.

If you rented a storage room and the place was so lazy as to use one key for all the doors, that would be one thing, but in this case the storage facility used the same key for all the doors and also completely lacked interior walls to separate people's stuff into individual rooms.

There is _zero_ reason for you to _use_ exposed credentials if you find them. It adds nothing to the "security research" you may be doing.

Bullshit. For one thing, he wasn't doing "security research" he was trying to fix a problem his client was asking him to fix that directly involved the MySQL database in question. He literally stumbled across the security problem by accident. For the other, the vendor should be facing an investigation into exactly why they thought it was a good idea to have thousands of customers and millions of euros "protected" by one single password that was stored in plaintext on thousands of customer's machines. In a number of places that could easily result in criminal liability on their part--which is probably exactly why they contacted the authorities.

...and I'll point out that he didn't actually even have to know what these credentials were. With elevated privs on the local system, one can merrily let the application connect to the database server and then snatch that socket up and do with it whatever they wish and then the same information would have been revealed--that every one of MS's customers could quite readily access all the data of every other customer.