Live data from Hacker News

The curious case of the Raspberry Pi in the network closet (2019)

blog.haschek.at

261–269 of 269 posts

Re: The curious case of the Raspberry Pi in the network closet (2019)

#261

That one really felt like a written-version of a Mr. Robot episode. Lovely!

This[0] is probably what you had in mind: [0] https://youtu.be/XTN_-pRZjoU?t=415

Yup. Exactly this scene. Thanks for reminding the great memories.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#262

Earlier quoted context omitted.

>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…

> Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I once worked at a place where one of the founders would too often get the shits with someone or some team, and become a micro managing asshole for a few weeks. I wrote a python script to run on the wifi router to monitor for…

That's pretty cool and funny too, but AFAIK, tracking people at work without their explicit consent is illegal in most of the EU even before GDPR.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#263

Earlier quoted context omitted.

For a while the easiest and fastest way to identify a 1U server in a rack of 40 was to SSH in and type: eject

Wait, was it common for 1U servers to have optical drives back in the day?

Yes, the thin laptop style usually.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#264
post #26

Earlier quoted context omitted.

I've also had this problem once, on a university campus though. "net send 'If you can read this, please call IT SUPPORT at ... and tell us'". It worked :)

This should really only ever happen with wireless connections. You should always be able to tell what switchport a computer is connected to and work from there.

This was roughly 19 years ago and my department was not in any way involved with the networking.

Sure, in an ideal world that would be possible - but we didn't even have access to the switches. So either it's trying to hunt down the other department in another building who /might/ solve that riddle in an unspecified amount of time... or just do it :)

Re: The curious case of the Raspberry Pi in the network closet (2019)

#265

Earlier quoted context omitted.

> Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I once worked at a place where one of the founders would too often get the shits with someone or some team, and become a micro managing asshole for a few weeks. I wrote a python script to run on the wifi router to monitor for…

That's pretty cool and funny too, but AFAIK, tracking people at work without their explicit consent is illegal in most of the EU even before GDPR.

Realistically, how is this different from logging login attempts? If the device is configured to attach to the company network isn't it within the company's rights to know that a device is logged on at any given time even under GDPR? Or would it be the publication of that information - even internally - that would be the issue?

Re: The curious case of the Raspberry Pi in the network closet (2019)

#266
post #51

Earlier quoted context omitted.

As I was reading this I was hoping for modern day Cuckoo's Egg. But it was not to be. Great write up. Thanks for sharing.

For anybody wondering, the Cuckoo's Egg (written in 1989 by Cliff Stoll) is a wonderful read about tracking an early hacker. I highly recommend it.

Thanks for the recommendation

Re: The curious case of the Raspberry Pi in the network closet (2019)

#267

Earlier quoted context omitted.

Doesn't anxiety tend to not make you want to sprinkle boxes of malware in network closets? Like, I would be absolutely terrified to even accidentally overhear someone talking about this and possibly be dragged into it that way.

The author of this piece didn't work at the company. It sounds like the company wasn't really full of technical people. The perpetrator probably thought they were so much smarter than everyone else that they'd never be caught.

I think this is probably a fair assessment.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#268
post #265

Earlier quoted context omitted.

That's pretty cool and funny too, but AFAIK, tracking people at work without their explicit consent is illegal in most of the EU even before GDPR.

Realistically, how is this different from logging login attempts? If the device is configured to attach to the company network isn't it within the company's rights to know that a device is logged on at any given time even under GDPR? Or would it be the publication of that information - even internally - that would be the issue?

>If the device is configured to attach to the company network isn't it within the company's rights to know that a device is logged on at any given time even under GDPR? Or would it be the publication of that information - even internally - that would be the issue?

Logging anonymized MAC addresses is one thing, but converting the MAC addresses to employee names, revealing their location on premises that is shared with everyone in the organization without their consent is a completely different thing and is illegal under most EU privacy laws (at least in Austria and Germany).

Sure, in theory the company could already know when I come it at work from the logs of me swiping my access badge at the main security entrance door but any such logs are kept private and can only accessed by security and upper management if some act of theft or gross misconduct has occurred which warrants an investigation.

Sharing this information publicly with everyone in the org would be a privacy breach. If you want to know if I'm "at work" just look at my Slack/$CHAT_APP notification color.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#269

Earlier quoted context omitted.

For a while the easiest and fastest way to identify a 1U server in a rack of 40 was to SSH in and type: eject

Wait, was it common for 1U servers to have optical drives back in the day?

Back in the day? Mine still do!
Post reply on HN