Live data from Hacker News

The curious case of the Raspberry Pi in the network closet (2019)

blog.haschek.at

181–190 of 269 posts

Re: The curious case of the Raspberry Pi in the network closet (2019)

#181

That's a very obvious and very obviously bad way of planting a network exploit. Very rookie and rather sad. In entirely unrelated news, this guide details how to set up an encrypted boot process on a raspberry pi, with it waiting for you(r forked login agent) to ssh in and provide the LUKS password: https://github.com/ViRb3/pi-encrypted-boot-ssh

The whole part with it being tracked back to a site for G/T kids makes it sound like this was a young person somewhere in the range between "script kiddie" and "beginner hacker", so "rookie" sounds about right. Bored teen or twentysomething with time to kill and an interest in computers.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#182

Earlier quoted context omitted.

We did get a hand written statement from him and the original evidence (hardware) is still untouched and locked away. In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena. But even though we could never decipher what the nodejs program actually did (because it was so heavily obf…

>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…

They sell laser trip-wires that act as usb keyboards and can hide windows, lock your computer, or run scripts.

https://www.tindie.com/products/dekuNukem/daytripper-hide-my...

Re: The curious case of the Raspberry Pi in the network closet (2019)

#183
post #46

>And what do we do, when we want to find out a location associated with a wifi name? We go to wigle.net, enter the SSID (=wifi name) and it tells us where on the world it is found. I've always enjoyed having unique/personal SSIDs, but had never seriously considered this consequence. I wonder what the worlds generic SSIDs are.

A little browsing around wigle.net brings me to a page listing SSIDs and manufacturers: https://wigle.net/stats#ssidstats

xfinitywifi is the top, with 2% of the routers seen having that name; it's followed by XFINITY (.73%), BTWiFi-with-FON (.38%), linksys (.37%), BTWifi-X (.35%), (.31%). The next one is AndroidAP at .28% and that feels like a good place to stop copying data, go look at the page if you wanna see more of the world's generic SSIDs. Basically "manufacturer name" and "internet provider name" dominate.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#184

Reminds me of this[1] good old quote from the IRC days hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is. [1]: http://bash.org/?5273

I work for a company with around 50k machines globally... one time we discovered a machine that was supposed to have been decommissioned five years prior still sitting on the network, just waiting to do its job. We ended up scanning our entire IP space and finding 10-20 other machines in the same state.

We now have a process that routinely scans our entire IP space for machines that somehow get lost from our inventory system.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#185
post #166

Earlier quoted context omitted.

There's a decent amount of infrastructure involved in getting 802.1x authentication up and running in an efficient manner. While it does provide very good security, it's not widely used because of that.

Any idea on a good, at-home or small network alternative?

There really isn't one. 802.1x is the wired security standard, and almost never worth the hassle for home or small business networks unless you are really interested in learning the ins and outs.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#186
post #166

Earlier quoted context omitted.

Any idea on a good, at-home or small network alternative?

Having a list of allowed MAC addresses, enforced per-port by a managed switch (or at least by the DHCP server and router), is a first step, though naturally it's easy to spoof a MAC address.

MAC address filtering isn't a first step towards 802.1x, precisely because of the reason you mentioned. It's damn near pointless for all but the most basic security scenarios.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#187
post #55

Earlier quoted context omitted.

> told him to pack his things and get out I though the suspects were an ex-employee, and some guy that didn't work there (the part-owner), so was an actual current employee implicated in the end?

An ex-employee who still had a key to the office so they could move some stuff they had there. Presumably that courtesy was immediately terminated and the key was returned.

Having a key to the office and having a key to the network closet are not the same thing. The article said only four people had access to the network closet. So did this guy break into the closet to plant the pi?

I think he got off way to easy.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#188
post #161

Earlier quoted context omitted.

what if this guy is just a hell of an introvert who is more comfortable rigging something like this up than with interacting with this boss. If this kid was in his early 20s I'd probably slap his wrist and impress on him the dangers of screwing with the company network closet. If he is an adult he really ought to know better

just came here to say that while I understand the sentiment, people in their 20s can vote, and should be considered adults, not kids.

What an intelligent way to look at the world. If the law says something that is the exact truth. No room for any nuance.

The day before your 18th birthday, you're a kid, the day after you're an adult. Makes perfect sense.

Clearly someone who looks at the world this way must be under 18.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#190

Earlier quoted context omitted.

>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…

> Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I’ve mentored a lot of juniors. It’s not uncommon for young people, especially those with less developed social skills, to have an undeserved fear of their boss or anyone else with authority. It’s common with young people who…

>I’ve mentored a lot of juniors. It’s not uncommon for young people, especially those with less developed social skills.

Sure, but even as a junior employee, we're still talking about mature adults here, not kindergarten kiddies, who can vote, pay taxes and are held accountable for their actions in front of the law, so they should be aware that deliberately backdooring their employer so that they can surveillance their boss, not only most likely violates their employment contract they signed and can have serious legal backlash against then both from the company and from the person who's privacy they were trying to break.

>It’s common with young people who have debilitating anxiety and a tendency toward rumination.

Yeah, I get that, but how is this in excuse for hacking your employer/boss? Why not seek therapy from professionals for that and try to either quit toxic workplaces or report abusive bosses and find a workplace that accommodates your personality and emotional type, not try to hack and backdoor your employer's network to keep tabs on your boss.

There is no workplace in the world and no work colleagues that will tolerate you hacking their network and invading their privacy because you have anxiety and a tendency toward rumination.

Post reply on HN