Live data from Hacker News

Pi-hole Remote Code Execution

natedotred.wordpress.com

41–46 of 46 posts

Re: Pi-hole Remote Code Execution

#41
post #22

Why the sudden use of the "Black Jack ni Yoroshiku" manga comic art? I know the author released the entire thing with permissions to freely use the art anywhere, but still.

A family member of mine was the original author of pi-hope. He sold the company to his partner last year, so any changes in aesthetics would be due to the change in ownership.

One of the Pi-hole dev's here. The comment you are replying to is talking about the blog post about this CVE, not Pi-hole's aesthetics. (Which haven't changed, btw)

Say hi to J from me.

Re: Pi-hole Remote Code Execution

#42

Earlier quoted context omitted.

I'd be happy to help you with this. My rate is $235/hr, minimum 30 hours. When can I expect your deposit so we can get started?

Yes, how dare he ask you to donate some of your time to contribute back to the open source community, tsk.

Wow you created a brand new account just to post that one comment? I'm honored.

On to the response. First, doing something I don't want to do that someone else told me to do and not getting paid for it is slavery. Slavery is bad.

Second, I don't use their solution. I have my own custom DNS intercept system I wrote myself which is much better and also enjoys security by obscurity. With a single user it's hardly worth the time to mess with.

Third, I already donated to their project, above. I reviewed their code, agreed it was complete shit, and concurred with the consensus that they need a complete security audit. That is extremely valuable advice which is worth $3000. So I donated $3000 and all you've done is sit and whine and create anonymous coward accounts to troll people. Tsk.

Re: Pi-hole Remote Code Execution

#43

Earlier quoted context omitted.

AFAIK Pi-holes are almost always going to be sitting inside a LAN and owned by whoever owns the other devices on the network too, so the risk is quite low.

In general, yes, but this is how real issues start. Look at all the bmc software written in the world. It's utter horseshit. You are supposed to use a dedicated vlan for accessing the bmc. Everyone is still fighting the bmc software and it is routinely accessed over the open internet.

What is bmc software?

Re: Pi-hole Remote Code Execution

#44
post #43

Earlier quoted context omitted.

In general, yes, but this is how real issues start. Look at all the bmc software written in the world. It's utter horseshit. You are supposed to use a dedicated vlan for accessing the bmc. Everyone is still fighting the bmc software and it is routinely accessed over the open internet.

What is bmc software?

idrac, ilo, etc.

Re: Pi-hole Remote Code Execution

#45

Earlier quoted context omitted.

Yes, how dare he ask you to donate some of your time to contribute back to the open source community, tsk.

Wow you created a brand new account just to post that one comment? I'm honored. On to the response. First, doing something I don't want to do that someone else told me to do and not getting paid for it is slavery. Slavery is bad. Second, I don't use their solution. I have my own custom DNS intercept system I wrote myself which is much better and also enjoys security by obscurity. With a single user it's hardly worth…

It's funny that I'm apparently the troll here, your comment just made me consider finally making an account.

If somebody prompts you to do something on the internet do you give it any concern? You must be swimming in free iPhone X's then. He suggested you donate time to an open source project which is about as equivalent to slavery as a cashier at Burger King trying to upsell you a large whopper menu.

You've donated absolutely nothing to the project by commenting here if you didn't provide the feedback directly via the projects public tools.

I actively contribute to many open source projects. Writing a shell script to generate dnsmasq hosts files isn't exactly rocket science. It doesn't matter if you don't use the project, lesser informed people do, by improving it you improve a large amount of people's security. Call it virtual herd immunity, it affects you too indirectly.

Re: Pi-hole Remote Code Execution

#46

Earlier quoted context omitted.

A family member of mine was the original author of pi-hope. He sold the company to his partner last year, so any changes in aesthetics would be due to the change in ownership.

One of the Pi-hole dev's here. The comment you are replying to is talking about the blog post about this CVE, not Pi-hole's aesthetics. (Which haven't changed, btw) Say hi to J from me.

Ahh, my mistake. I will say hi for you :)
Post reply on HN