Earlier quoted context omitted.
Certainly in Texas I would be extra careful. Either way, have someone standing outside to advise the homeowner or cops what is going on. Also call the police ahead of time and tell them what you intend to do. Maybe even ask for an officer to assist.
Better get a friend with a firearm to stand guard at the door if you must take that kind of measure. US police are ill-disciplined, trigger-happy and uninformed about the law.
A mysterious grey-hat is patching people's outdated MikroTik routers
161–170 of 220 posts
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#162Earlier quoted context omitted.
A lot of Mikrotik's are installed at WISP's and other ISP's... making unplanned reboots very disruptive. Those of us using them on our corporate networks might be inconvenienced by a temporary outage, but that's unlikely at 3am... however, scheduling and doing these manually is still the best way for enterprise gear.
I doubt that most ISPs who can't be bothered to apply security updates are going to notice a 5 minute reboot. Split the difference - email the user that an update will apply on $date unless they do it first, or if they delay it (and don't let them delay it indefinitely).
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#163Earlier quoted context omitted.
This is not at all negative. Imagine parent telling some underground rebel group that their revolution would be more successful if they organized it with Jira. Meanwhile, this concern is so far away from the rebels, who are doing just fine with pen and paper, and are more concerned with basic needs like surviving undetected. People are of course excited by this initiative, and wish to contribute how they know. Except…
Not true, you are wrong. Better organization leads to a focus that can solve problems at a greater scale and with easier access to solutions. Your metaphor sucks as well.
You can't optimize what's not there.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#164>But despite adjusting firewall settings for over 100,000 users, Alexey says that only 50 users reached out via Telegram. A few said "thanks," but most were outraged. Have to wonder if those "outraged" users are ones who would have proactively fixed it themselves, or if they would've let their router happily continue to chug away as part of a botnet.
Security issues are tricky. Often making people aware of an issue is indistinguishable from having caused the issue.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#165Not sure what they mean by "mysterious". He isn't hiding and never was. He posted his photo, name and other personal details in articles about MikroTik on Russian IT blogging platform[1]. His name is Alexey Sopov, 34, from Novosibirsk. Quick search revealed his social network accounts: https://fb.com/100005153643926 https://vk.com/lmonoceros [1] https://habr.com/post/353530/
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#166Earlier quoted context omitted.
As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…
>with the authority and means to shut down domains for exactly this How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#167Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#168Earlier quoted context omitted.
As someone with the authority and means to shut down domains for exactly this, the truth is, most people have either used email addresses they never check, or, just ignore all warnings. I'd argue >75% of people contacted never reply. Their entire domain gets shut down, and then, probably 75% of those do finally contact asking why their domain is down. It's probably most likely that since WHOIS data is public, people…
>with the authority and means to shut down domains for exactly this How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#169Earlier quoted context omitted.
I think you have a point, but unfortunately I didn't get it from your first comment as well. It read as a pretty negative comment. It sounds like the point that you are making is reasonable, though, and unfortunately one that I see play out with a lot of FOSS projects as well. I remember a talk one time where a project lead essentially made the point that every new talk is met with a lot of "I'll setup CI for you" an…
Note: I was not the original poster: his comment simply rang very true to me; "lean" is being a motif in my work, as the complexity of precious time and resource management increases. Contributions are all well-intentioned, but they cost resources, especially if you're not great at ruthlessly filtering out, or don't want to, for any reason; they generate a lot of heat where this energy can't be used. Also well-intent…
It is very easy for software contributions to create lots of friction and your analogy to heat and energy loss is really great, IMO.
Re: A mysterious grey-hat is patching people's outdated MikroTik routers
#170Earlier quoted context omitted.
I've heard that in US you could be shot for trespassing. It might be very dangerous to try fixing it.
Similarly, unsolicited help with computer infrastructure can land you in jail under CFAA. No good deed goes unpunished.