Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

51–60 of 265 posts

Re: When internal hostnames are leaked to the clown

#51
post #48
post #45

Earlier quoted context omitted.

You are right, I meant paranoid. >Btw, in this case it can’t be paranoia since the belief was not irrational - the author was being watched. Yes, but I mean being overly cautious in the threat model. For example, birds may be watching through my window, it's true and I might catch a bird watching my house, but it's paranoid in the sense that it's too tight of a threat model.

I know analogies are not meant to be perfect, but birds don't mass watch, and don't systematically watch every of your moves neither.

That's what you think...

Re: When internal hostnames are leaked to the clown

#52
Reverse address lookup servers routinely see escaped attempts to resolve ULA and rfc1918. If you can tie the resolver to other valid data, you know inside state.

Public services see one way (no TCP return flow possible) from almost any source IP. If you can tie that from other corroborated data, the same: you see packets from "inside" all the time.

Darknet collection during final /8 run-down captured audio in UDP.

Firewalls? ACLs? Pah. Humbug.

Re: When internal hostnames are leaked to the clown

#53
I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing.

Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but why?

Don’t get me started with the old rsync version, lack of midnight commander and/or other utils.

I should have gone with something that runs proper Linux or BSD.

Re: When internal hostnames are leaked to the clown

#54
post #17

>Hope you didn't name it anything sensitive, like "mycorp-and-othercorp-planned-merger-storage", or something. So, no one competent is going to do this, domains are not encrypted by HTTPS, any sensitive info is pushed to the URL Path. I think being controlling of domain names is a sign of a good sysadmin, it's also a bit schizophrenic, but you gotta be a little schizophrenic to be the type of sysadmin that never gets…

TLS 1.3 has encrypted client hello which encrypts the domain name during an HTTPS connection.

Re: When internal hostnames are leaked to the clown

#56
post #19
post #15

Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Seems to me that the problem is the NAS's web interface using sentry for logging/monitoring, and part of what was logged were internal hostnames (which might be named in a way that has sensitive info, e.g, the corp-and-other-corp-merger example they gave. So it wouldn't matter that it's inaccessible in a private netw…

> Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Clown is Rachel's word for (Big Tech's) cloud.

Anyone know how she come up with the word or why she chose it?

Re: When internal hostnames are leaked to the clown

#57
post #19

Earlier quoted context omitted.

> Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Clown is Rachel's word for (Big Tech's) cloud.

She was (or is) at Facebook, and "clowntown" and "clowny" are words you see there.

[flagged]

Re: When internal hostnames are leaked to the clown

#58
post #53

I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…

(Copied from an earlier comment of mine)

There are guides on how to mainline Synology NAS's to run up-to-date debian on them: https://forum.doozan.com/list.php

Re: When internal hostnames are leaked to the clown

#60
post #19

Earlier quoted context omitted.

> Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Clown is Rachel's word for (Big Tech's) cloud.

amusingly its a term used by my co-workers to describe anyone thats not them.

Your coworkers call you a clown?
Post reply on HN