Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

81–90 of 265 posts

Re: When internal hostnames are leaked to the clown

#81
post #40

Earlier quoted context omitted.

If you're on an apple device, disable private relay. It appears the blog has tar pitted private relay traffic.

It's tar pitting my normal unproxied residential traffic too

Same, plus my VPN connection.

Re: When internal hostnames are leaked to the clown

#82
post #53

I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…

I'm so happy I didn't buy a NAS, Synology or not. I think a proper computer running Linux gives me so much more flexibility.

Re: When internal hostnames are leaked to the clown

#83
post #56
post #19

Earlier quoted context omitted.

> Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Clown is Rachel's word for (Big Tech's) cloud.

Anyone know how she come up with the word or why she chose it?

Probably just because it looks/sounds a little like cloud and has the connotations she wants.

It feels pretty hacker jargon-ish, it has some "hysterical raisins" type wordplay vibes.

Re: When internal hostnames are leaked to the clown

#84

Isn't the article over emphasising a little bit on leakage of internal urls ? Internal hostnames leaking is real, but in practice it’s just one tiny slice of a much larger problem: names and metadata leak everywhere - logs, traces, code, monitoring tools etc etc.

In other words: never put sensitive information in names and metadata.

Re: When internal hostnames are leaked to the clown

#85
post #59

[flagged]

Clueless lol. This is not about any of that. I run Plex on my local network at plex.domain.com. Plex sends logs to the internet with its local domain in the string. Leak. There is no easy way to solve this without deeply inspecting each packet a service sends outside your network, and even that doesn't work when services use SSL certificates and certificate pinning preventing MITMs.

Re: When internal hostnames are leaked to the clown

#86
post #50

Earlier quoted context omitted.

> Can't even name the domains on my own damn server with an expectation of privacy now. You never could. A host name or a domain is bound to leave your box, it's meant to. It takes sending an email with a local email client. (Not saying, the NAS leak still sucks)

I don't know much about email, but how would some random service send an email from my domain if I've never given it any auth tokens?

It should not, but it's usual to configure random services to send mails to users, for instance for password resets, or for random notifications.

Another thing usually sending mails is cron, but that should only go to the admin(s).

Some services might also display the host name somewhere in their UI.

Re: When internal hostnames are leaked to the clown

#87

Oh god this sucks, i've been setting up lots of services on my NAS pointing to my own domains recently. Can't even name the domains on my own damn server with an expectation of privacy now.

The (somewhat affordable) productized NASes all suffer from big tech diseases. I think a lot of people underestimate how easy a "NAS" can be made if you take a standard PC, install some form of desktop Linux, and hit "share" on a folder. Something like TrueNAS or one of its forks may also be an option if you're into that kind of stuff. If you want the fancy docker management web UI stuff with as little maintenance as…

Actually I host everything on a linux PC/server, but a different box runs PFSense and a local DNS resolver so I was talking about setting up a split-brain DNS there. So I don't have to manually edit the hosts file on every machine and keep it up to date with IP changes. Personally I really like docker compose, its made running the little homeserver very easy.

Re: When internal hostnames are leaked to the clown

#90
post #56
post #19

Earlier quoted context omitted.

> Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Clown is Rachel's word for (Big Tech's) cloud.

Anyone know how she come up with the word or why she chose it?

Maybe she's a juggalo.
Post reply on HN