HN user

sslalready

498 karma

Telecom. Berlin, Germany.

Posts7
Comments82
View on HN

And then there’s Banksy’s “in the future, everyone will be anonymous for 15 minutes“. For pretty much the same reasons you stated above, I assume.

ESPHome 2 years ago

ESPHome is awesome. Any chance you can get MQTT running on RP2040W?

Kudos to Spotify for supporting libspotify and its use-cases for so many years. I'm sure it hasn't been easy and that copyright owners haven't been very fond of it.

Anecdata: I’ve found USB powered external drives to be unreliable on the Pi, even when powering the Pi with an official power adapter. I’d recommend using an external drive that comes with its own power adapter.

Reasons for self-hosting: GitLab.com's not-so-great availability [1], slow code searches (compared to self-hosted with GitLab Advanced Search) and the fact that you can keep your code and resources off the public Internet.

The fact that you do need to upgrade it yourself regularly is indeed a drawback. On the other hand, an Omnibus upgrade has only failed me twice in the last five years or so, so there's little reason to not do automatic upgrades at night and fire off an alert in case something doesn't work as expected afterwards. Their releases are typically solid, so kudos to the team.

[1] https://status.gitlab.com/pages/history/5b36dc6502d06804c083...

I too found this after reading about it here. I contacted them and received the following reply.

Exposure notifications cannot be enabled without user consent, so if you have not turned MassNotify on, then it is not active on your phone. However, a recent Google update, which makes MassNotify available as an option in your phone's settings, is causing some users to see MassNotify in their app list. Apologies if this caused any confusion.

The appearance of MassNotify in the app list does not mean that MassNotify is enabled on your phone. The presence of the app merely means that MassNotify has been made available as an option in your phone's settings if you wish to enable it. For more information about this, please see this help center article from Google: https://support.google.com/android/answer/10775533

You can see whether MassNotify is active by going to Settings -> Google -> COVID-19 Exposure Notifications. The “Use Exposure Notifications” toggle at the top of the page will show you whether MassNotify is active or not. From this screen, you can also enable or disable MassNotify at any time.

I’ve reflected on the fact that some makers on YouTube wear gloves and wondered if this is for privacy reasons. I see globes being worn even when they’re not obviously doing anything that risk getting their fingers dirty.

Not that I'm aware of, but I wish. Memory is getting hazy these days. AFAIK the kernel.org breaches were made by the kind of hackers doing it for fun and games (if you get that thing) and not the kind working for nation states. I'm sure you can (or at least, at some point could) find others who know more details at your favorite compsec conf.

If memory serves me right the CVS bug was originally discovered and exploited by a member of an infamous file sharing site. After descriptions(?) of that bug were leaked in underground circles, an east European hacker wrote up his own exploit for it. This second exploit was eventually traded for hatorihanzo.c, a kernel exploit, which was also a 0-day at the time.

The recipient of the hatorihanzo.c then tried to backdoor the kernel after first owning the CVS server and subsequently getting root on it.

The hatorihanzo exploit was left on the kernel.org server, but encrypted with an (at the time) popular ELF encrypting tool. Ironically the author of that same tool was on the forensic team and managed to crack the password, which turned out to be a really lame throwaway password.

And that's the story of how two fine 0-days were killed in the blink of an eye.

I remember ftp.openbsd.org being owned around 2002. Possibly this hostname was pointed to the www.openbsd.org machine, which was running Solaris. I have a vague memory that this machine also hosted something else in addition to the OpenBSD site, and that people managed to get root on it via two (chained) 0day exploits of which at least one involved a Solaris daemon related to printing services. (Feel free to correct me if I got it wrong.)

I also recall cvs.openbsd.org being owned but I no longer remember how that happened. There's a high chance it was made possible thanks to a remote CVS exploit that was making rounds in some hacker circles[1]. FWIW, cvs.openbsd.org is mentioned under "memorable places I've been" in the Phrack #65 prophile of the UNIX terrorist.

2002 was a particular bad year for OpenSSH and OpenBSD. In March, 2002, it was found that OpenSSH 2.x/3.0.1/3.0.2 had an exploitable (post-auth IIRC) integer overflow in its channels handling. In June, 2002 that preauth Challenge-Response vulnerability was made public and shortly afterwards GOBBLES Security made public an exploit (sshutuptheo) for the vulnerability that among other things targeted OpenBSD 3.1 default installations. Early August, 2002 it was discovered that several OpenSSH packages had been backdoored on ftp.openbsd.org on June 30th, 2002 (google: "openssh 3.4p1 trojan").

Incidently the sshutuptheo exploit was written by the Australia division of GOBBLES Security. Later postings on public mailing lists suggests that this division fell off the earth shortly afterwards (can't link).

Some of these things had ties to the community around #phrack and the autonomous Phrack High Council "movement". PHC had nothing to do with the official Phrack magazine and instead was similar (in actions) to the Global Hell (gH) movement that happened earlier (around 2000, I think). PHC kind of spun out of the anti-sec movement that existed at the time, but really it was just a setup to trick kids into thinking they have a common purpose and do damage for the lulz; think early "anonymous" or lulzsec and you'll get the idea.

I know FBI had at least one informant in the #phrack and PHC circles at the time: soupnazi a.k.a segvec a.k.a [2]. So perhaps those contacts mentioned in a child post aren't OpenBSD developers but.. other people?

The nickname of the Hungarian wasn't pipops but I'll leave it out since you got the reference right the first time: "PaX Team" ;) Regarding the feud, you can find some pointers in this poster defacement[3] attributed to the Micke Mouse Hacking Squadron. The picture is from the OpenBSD tent at the Chaos Communication Camp in Berlin, Germany in August of 2003. MMHS was one of several GOBBLES Security copycats. They generally lacked the effort but MMHS was the only one that, like GOBBLES, produced a few (arguably funny) comic strips.

Grsecurity/PaX team did a hell of a job identifying vulnerabilities and working around them or hardening code long before anyone else. It's not surprising that they would've mingled with others interested in that sort of things, possibly sharing hints of vulnerable code paths or having discussions around the vulnerabilities and/or workarounds.

[1] https://news.ycombinator.com/item?id=18179805

[2] https://en.wikipedia.org/wiki/Albert_Gonzalez

[3] https://web.archive.org/web/20060512113602/http://www.grsecu...

Second this. It’s super hard to imagine in what ways things can go wrong before you have seen or experienced them.

Kick-backs would never even have been on my radar, even though I’m seeing myself as a careful person, if it wasn’t for YouTube and people like him taking their time to educate the rest of us.