HN user

imduffy15

132 karma
Posts28
Comments25
View on HN
www.youtube.com 1y ago

Pulling images from private registries with KEP-4412

imduffy15
3pts1
ianduffy.ie 1y ago

Troubleshooting the Engineer's Brain

imduffy15
1pts0
news.ycombinator.com 2y ago

Ask HN: How do I get my ISP's IPs out of PerimeterX's block list?

imduffy15
3pts3
pansift.com 2y ago

Apple, an Airport, 802.11 Channel Flags, and Some Binary

imduffy15
2pts1
github.com 5y ago

Help unlock Tuya IoT devices – new PSK encryption

imduffy15
1pts0
twitter.com 5y ago

House alarm controlled by an OralB toothbrush

imduffy15
1pts0
twitter.com 5y ago

House Alarm system armed from a toothbrush

imduffy15
2pts1
www.scrapinghub.com 6y ago

Turn article web pages into structured data

imduffy15
2pts1
github.com 6y ago

OAuth2/JWT CLI Swiss Army knife – generate tokens easily

imduffy15
3pts0
twitter.com 6y ago

Spotify on a vacuum cleaner (rockrobo S5) via librespotify

imduffy15
2pts0
twitter.com 6y ago

Lighting controlled by a OralB Bluetooth toothbrush

imduffy15
77pts25
growremote.ie 6y ago

Year of Working Remote – 10 top tips

imduffy15
2pts0
ianduffy.ie 6y ago

First 6 months of working remotely

imduffy15
3pts0
github.com 6y ago

Show HN: CLI for Generating OpenID or OAuth2 Tokens

imduffy15
1pts0
www.confluent.io 6y ago

Why Scrapinghub’s AutoExtract Chose Confluent Cloud for Their Apache Kafka Needs

imduffy15
2pts0
ianduffy.ie 6y ago

6 months of working remotely at scrapinghub.com

imduffy15
3pts0
github.com 7y ago

Build HTTP Forwarding Proxies with Go

imduffy15
5pts0
ianduffy.ie 7y ago

Local Development with Virtual Hosts and HTTPS

imduffy15
2pts0
ianduffy.ie 7y ago

Managing Access to Multiple AWS Accounts with OpenID

imduffy15
3pts0
github.com 8y ago

Provides Different Google Service Accounts and Scopes for Pods Running on K8S

imduffy15
1pts0
www.confluent.io 8y ago

Experience of Running Kafka Streams on AWS

imduffy15
3pts0
github.com 9y ago

Service for exposing Apache Kafka Consumer group lag information over HTTP

imduffy15
1pts0
www.monkeylittle.com 9y ago

Kubernetes Fundamentals

imduffy15
4pts0
ianduffy.ie 9y ago

Elevating from a root user on an Azure VM to storage account administrator

imduffy15
2pts0
ianduffy.ie 9y ago

Acquiring administrative access to Azure's RedHat Update infrastructure

imduffy15
93pts18
github.com 9y ago

Packer post processor for uploading vagrant boxes with metadata to azure storage

imduffy15
1pts0
github.com 10y ago

A JVM contract tool for testing HTTP interactions based on contracts

imduffy15
1pts0
www.monkeylittle.com 11y ago

JPA Inheritance Strategies Explained

imduffy15
2pts0

Not a solution for shared multi factor auth but maybe some ideas…

- the root account should not be used. Disable it from being able to do anything with an SCP

- new accounts created with aws organisations by default have a random password and no mfa. Access is granted by going through the password reset process. Switch to this process for existing accounts, randomise all the passwords, grant break glass access via password resetting (ensure your contact details are valid). The password reset typically requires access to the email account (make it accessible via SSO) and potentially a phone call, ensure a virtual phone number is used and root holders can point it at their phone.

- use the likes of azure ad, keycloak or okta to store your organisations identities. Require MFA on them via yubikey. Enable access to multiple aws accounts via aws sso.

- for ssh access switch to using aws ssm.

Sad, frustrated, bitter & angry to have been apart of this. Started the job on April 4th, casual 1:1 with my manager on May 26th turned into HR stating it’s over. Not even one months severance as a good will gesture.

Why does bad planning on your part need to result in stress, anxiety, and financial concern for me?

The market is thankfully in a good place and I’m good at what I do. Did atleast one interview activity with 20+ places, it was hell, busier than a average work day. To get to final around it took 6-8 hours of interview activities.

It would be amazing to see companies that are struggling to hire to create a fast tracked interview process for those laid off.

My bet is you could remove the user. Do some DNS messing about either on your router or hosts file to drop all communications to goguardian and then resign into your sons account.

The end result will be that the school management scripts will still run but they’ll be unable to fetch and install goguardian.

The demod used case is a silly one that makes zero sense, but instead of asking why, think, what else is possible.

For most peoeple the act of brushing their teeth marks waking up or going to bed.

With such data exposed and combined with timing data you could trigger morning or night time routines. For example, the toothbrush transitioning from running -> idle after 8pm and before 4am could cause the bedroom to go into sleep lighting (gold at 40% fading out over 15 minutes), all other lights to be turned off, all smart plugs turned off, house alarm set to armed, heating turned off and so on..... or I could just continue to be silly and turn it into a TV controller https://twitter.com/imduffy15/status/1256954852996939777

Can help fill in some of the blanks for you. The toothbrush has bluetooth. Its bluetooth advertisement contains information about its operating state (running, idle, etc.), mode (brush, daily clean, etc.), pressure and some other things. The ESP32 chip scans bluetooth, detectes these advertisements, parses them and extras the data. It then sends it over to home-assistant.io which can use the data to trigger actions on any other connected device.

Debatable @shshhdhs, I can confirm they locked down access but I'm not confident the certificates were actually rotated. It would have meant they would have needed to push new SSL client certs out to every customer Red Hat Enterprise Linux Virtual Machine.

I'm confident that duplicating the virtual disk, certificates or installing the documented RPMs will result in repository access without being billed accordingly. It is considered fraud and I would imagine if one took large advantage of one would be disciplined accordingly.