Live data from Hacker News

Tor is a great sysadmin tool (2020)

jamieweb.net

81–90 of 125 posts

Re: Tor is a great sysadmin tool (2020)

#81
I can confirm that Tor is very useful for exposing services when you cannot port forward!

Specifically, I've used Tor for connecting to GitHub Actions virtual machines over SSH. This is great for debugging Actions without running them over and over again. I also used this for a project that sets up an ephemeral, collaborative environment in one of the GitHub Actions VMs.

https://github.com/jstrieb/ctf-collab

Re: Tor is a great sysadmin tool (2020)

#82
post #20

In many ways I think this blog post really makes quite compelling arguments and honestly opened my eyes a bit. One (perhaps mad) idea for more secure access to a machine deep behind many levels of NAT where you, the sysadmin, have lawful access but are fed up with having to have a 12 KB ~/.ssh/config file in order to access it because of your university's overbearing IT department^W^W^W^W network topology, would be t…

Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…

Especially when, since it's Tor, potential attackers cannot be traced

Re: Tor is a great sysadmin tool (2020)

#84
post #79
post #45

Earlier quoted context omitted.

IT departments make choices that benefit their own needs and for their own convience, often forgetting that the entire point of their department is to make the rest of the organization more effective. Sadly, it often goes the other way. Shadow IT is a signal that the IT organization is doing things wrong. People use shadow IT because the IT department is not doing it's job properly, serving it's customer base based o…

“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…

If the IT department can't do its job because of resource constraints likely the whole organization is a failure.

If you find something like that, run…

If you can't run, do whatever makes your live better. The org is doomed anyway.

Re: Tor is a great sysadmin tool (2020)

#85
post #79
post #45

Earlier quoted context omitted.

IT departments make choices that benefit their own needs and for their own convience, often forgetting that the entire point of their department is to make the rest of the organization more effective. Sadly, it often goes the other way. Shadow IT is a signal that the IT organization is doing things wrong. People use shadow IT because the IT department is not doing it's job properly, serving it's customer base based o…

“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…

I'm working in an organization where we have one laptop from work, and another laptop to do work on. Because the one sized fits all IT policy doesn't work for our org, but it's forced on us because of the IP security needs of another parallel org.

We went from an organization moving towards BYOD, to, now the exact opposite.

Re: Tor is a great sysadmin tool (2020)

#86
post #66

Earlier quoted context omitted.

building a new computer. want to be able to trust it 100% for at least a moment. i can't figure out how to "buy" a trusted copy of any linux and don't have any machines i have 100% trust in (who does), so can't burn it. current plan is to buy a chromebook solely for the purpose of downloading and burning ubuntu. alternatively, buy MSWindows, install on the new machine, burn, and then replace but this mental exercise…

One thing that helps a lot in this situation is to plan based on threat model. There’s no such thing as 100% trust, but you can have a computer which is safe for e.g. . It’s pretty crucial to pick one or two specific s and focus only on those. If you just want to browse the darknet and see what the markets are like, for example, Tor on your current computers is fine. If you’re wanting to make a purchase and you’re wo…

> If you’re literally dodging the NSA, you need to...

Or just make friends with an developing-world advance-fee scammer, and then pay them to have one of their cash mules buy and send you (that is, an empty house somewhere in your city) a laptop.

Re: Tor is a great sysadmin tool (2020)

#87
post #79

Earlier quoted context omitted.

“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…

If the IT department can't do its job because of resource constraints likely the whole organization is a failure. If you find something like that, run… If you can't run, do whatever makes your live better. The org is doomed anyway.

A recent example from me -- one VPN client of mine suddenly refused to connect one day for no discernible reason when they made a configuration change to their cisco vpn "concentrator" without documenting it or announcing it. Cisco AnyConnect GUI clients were fine and some magic happened behind the scenes to push the configuration change and, in typical Cisco style, avoid saying what exactly it was.

I had some esoteric monitoring machine that couldn't run anyconnect (for reasons I forget but almost certainly relating to it not having a linux arm64 client at that time) and naturally couldn't connect randomly one day with openconnect (which previously had worked perfectly). I asked what the configuration change was to prevent me having to reverse-engineer it. The response was "if you want to use unsupported clients we cannot offer any assistance [...] we are currently operating two heads down and we simply do not have the resources [...]." It took me about four or five hours to work out what change they had made, change the (122 line long) configuration file for openconnect, and then, boom, everything good again. A friendly "Hey, sorry about that -- we just $FLICKED_THIS_SWITCH because $REASON" would have been massively helpful and arguably take less words than their original response. (Edit: For context, approximately 10-20k people use that specific VPN. And their team is such that losing two members of staff temporarily is a major inconvenience.)

I totally understand it from the other side. IT departments have everything from state-sponsored ransomware attacks to important people loudly going "why doesn't the printer work any more". It's a different set of skills to being a C-junkie, a programming wizard, or, in my case, a young academic with one big grant and three PhD students trying to both do work, publish work, and get money to do more work where "work" is poorly defined and highly flexible. Over time I've noticed universities get far more corporate and many academics absolutely hate this, of which I am one. The "we control the network, bug off" may be technically true but at times it does feel a bit like an imposition of some sort of academic freedom, to be honest. At the very least, it's a nice little "dog egg" to find added to the pile of administrative crap to do for that day.

Re: Tor is a great sysadmin tool (2020)

#88
post #77

Earlier quoted context omitted.

> you'd get an unpleasant phone call or visit to your office and be warned sometimes I wonder why IT departments and security in general get a bad wrap, then I see things like this.

When someone just does whatever they feel like and violates policy, what do you think should happen? Should someone send them a sternly worded email for them to ignore? Or maybe they should be allowed to do whatever they want regardless of what risk it poses to the organization?

Why do people break rules? In that situation, I'd argue that education and understanding is the appropriate response -- for people on both sides of the table.

Re: Tor is a great sysadmin tool (2020)

#89
post #79

Earlier quoted context omitted.

“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…

If the IT department can't do its job because of resource constraints likely the whole organization is a failure. If you find something like that, run… If you can't run, do whatever makes your live better. The org is doomed anyway.

What you’ve just described is most post secondary institutions, public utilities, government, etc.

Re: Tor is a great sysadmin tool (2020)

#90
post #86

Earlier quoted context omitted.

One thing that helps a lot in this situation is to plan based on threat model. There’s no such thing as 100% trust, but you can have a computer which is safe for e.g. . It’s pretty crucial to pick one or two specific s and focus only on those. If you just want to browse the darknet and see what the markets are like, for example, Tor on your current computers is fine. If you’re wanting to make a purchase and you’re wo…

> If you’re literally dodging the NSA, you need to... Or just make friends with an developing-world advance-fee scammer, and then pay them to have one of their cash mules buy and send you (that is, an empty house somewhere in your city) a laptop.

That's an interesting idea I hadn't considered. But it involves a lot of the same problems: you need to get from where you are to where the laptop is, and back, without popping up on any sensors.

There are a lot of sensors. Gait detection + god eye is what convinced me this is probably impossible.

In my case, I was using NSA as a threat model for added security against the actual threat (cartels), so I wasn't as paranoid as I needed to be for NSA dodging. But in your case, you have quite a chicken-and-egg problem of getting that laptop to your doorstep in an untraceable way.

One optional step that I took, which is probably useless, is to live close to a wifi source that you can tap into from long range. I used a directional wifi antenna to a local restaurant. That way, if you do screw up and blow your opsec, it's traced to somewhere close but not equal to you.

(It's probably useless because once your physical location is traced, you're basically doomed – all they'd have to do is realize that someone's using the restaurant as a proxy. It's also quite unethical, since you're illegally using someone's equipment in a way that could very well land them in prison, depending on what you're doing. "Reasons not to fight the cartels" could fill up several notebooks, which is what ultimately persuaded me to stop trying.)

Post reply on HN