Live data from Hacker News

The curious case of the Raspberry Pi in the network closet (2019)

blog.haschek.at

71–80 of 269 posts

Re: The curious case of the Raspberry Pi in the network closet (2019)

#71

Earlier quoted context omitted.

This should really only ever happen with wireless connections. You should always be able to tell what switchport a computer is connected to and work from there.

One of the many reasons that I dislike the push towards wifi/wireless for everything. It makes my hair stand on end to see people using wireless keyboards (which people usually have for at least 5 years). People seem so disgusted when you even suggest that these things are inherently bad ideas which will inevitably lead to consequences and immediately push you into a naysayer/antiprogressive category verbally or sile…

Have you considered that using a wireless keyboard and other tech is OK under their threat model? I use one at home and I honestly can not see any downside to it.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#72
post #52

Earlier quoted context omitted.

And then? The cable disappears into a wall together with 100s of other cables (which most likely are not labeled or not correctly, otherwise you wouldn't have lost the machine in the first place)

It is completely irresponsible and without excuse for any main network operator/owner to not be completely aware of what each and every cable does which is connected to a switch/network router. If the owner refuses to determine this, they are responsible if there is a nefarious device on the network until they do. Wireless makes this much more complicated so any responsible admin will ensure the wireless network is c…

I've seen bundles of cat 5 cabling the girth of a 100 year old oak tree. No chance anyone knows every cable in such a data center.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#74
post #50

Earlier quoted context omitted.

An encrypted disk would be kind of useless in such a device as it would require the user to login every time the device reboots, unless they intend for it to never be rebooted. I’m not sure what you mean by network key in this case.

No, you can have the initrd boot to a dropbear sshd that allows the operator to ssh in on reboots and provide the key.

There are also options like the Zymkey[1] which is essentially an add-on TPM which can auto-decrypt the disk if it detects that the Raspberry Pi and SD card it is connected to have not changed. Not sure how difficult that would really be to defeat given enough effort though.

[1] https://www.zymbit.com/zymkey/

Re: The curious case of the Raspberry Pi in the network closet (2019)

#75

Earlier quoted context omitted.

This should really only ever happen with wireless connections. You should always be able to tell what switchport a computer is connected to and work from there.

One of the many reasons that I dislike the push towards wifi/wireless for everything. It makes my hair stand on end to see people using wireless keyboards (which people usually have for at least 5 years). People seem so disgusted when you even suggest that these things are inherently bad ideas which will inevitably lead to consequences and immediately push you into a naysayer/antiprogressive category verbally or sile…

Can you explain in clear ways how the person you're telling this to will directly be harmed?

Re: The curious case of the Raspberry Pi in the network closet (2019)

#76
post #66
post #60

Earlier quoted context omitted.

Is “gifted person” code for something? Are they from some sort of enrichment program?

“Gifted” individuals are selected at early ages to run through rigorous education programs that greatly push them ahead of their peers. It is a pipeline to create intellectual elites and captains of industry. Gifted kids are widely accepted as the most intelligent kids of a school and held up as the finest examples of the school’s educational abilities.

Do kids in gifted programs go on to become intellectual elites and “captains of industry” at higher rates than their peers?

Re: The curious case of the Raspberry Pi in the network closet (2019)

#77
post #3

Author of the article here. Since I first published this blog post I was getting messages from people asking how it ended. Sadly it's pretty anticlimactic as the owner of the place had a meeting with the guy who put the Pi there (without me as he didn't want the Pi-dropper to feel ambushed) and in the end decided not to escalate it to legal and just basically told him to pack his things and get out. So no legal after…

> told him to pack his things and get out I though the suspects were an ex-employee, and some guy that didn't work there (the part-owner), so was an actual current employee implicated in the end?

My understanding is: ex-employee bought/acquired the device from the "gifted guy"/part-owner, and deployed it in the network cabinet by using the key he still had.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#78
post #55

Earlier quoted context omitted.

An ex-employee who still had a key to the office so they could move some stuff they had there. Presumably that courtesy was immediately terminated and the key was returned.

oooh, I didn't realise they still had the key at that point. OK, I wouldn't have even said that - I'd have asked for the key back and boxed the remaining stuff myself. TBH, I'm surprised to what extend the employee would of had a bunch of stuff there - did they have furniture there or something?!

Yeah it sounds like the person was on good terms with the company and was trusted enough, must have stung for whoever made the decision to trust the ex-employee to be sorta betrayed like that. The blog author is somewhere in the comments here, I don't know if they're willing to share much more info but let's see what they say.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#79
post #21

Earlier quoted context omitted.

> So no legal after play and just a slap on the wrist The problem with this is you have no idea what harm the guy actually may have caused; nor what other RPis he may have set up around the company or around town. Next time he may be more careful with his username, set up the disk to be encrypted w/ a network key, &c, making future exploits more difficult to track down.

There is a case to be made for using the legal system as a deterrent. But there is also the case to made to not do that as in the case of Aaron Swartz.

This is a lot more localized and malicious. I do think people deserve second chances, but the context of all this rubs me the wrong way. Maybe the building owner was right to not make it a legal matter, but this feels like more than a harmless experiment. The malicious persons operational security is obviously terrible.

As someone who has done security research for over 15 years, I take the ethics of this sort of thing seriously. I fully expect repercussions of the legal sort if I did something like this without permission. The key detail being that this was done secretively in a private office.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#80
post #26

Reminds me of this[1] good old quote from the IRC days hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is. [1]: http://bash.org/?5273

I've also had this problem once, on a university campus though. "net send 'If you can read this, please call IT SUPPORT at ... and tell us'". It worked :)

Did that with a printer that came up on an audit at a hospital once. IT director told me to go to X site to find it based on its IP in the schema and I just cranked out a job to it that said to call my extension. Two minutes later the phone rang...
Post reply on HN