Live data from Hacker News

The curious case of the Raspberry Pi in the network closet (2019)

blog.haschek.at

131–140 of 269 posts

Re: The curious case of the Raspberry Pi in the network closet (2019)

#131

> [...] I got a message from my dad [...] I asked him to unplug it, [...] and to make an image from the SD card [...] What a technical dad you have!

> What a technical dad you have!

Working for over 35 years for IBM and inspiring BASIC/REXX to ones child may do the trick -> https://blog.haschek.at/about/

Re: The curious case of the Raspberry Pi in the network closet (2019)

#132

Reminds me of this[1] good old quote from the IRC days hm. I've lost a machine.. literally _lost_. it responds to ping, it works completely, I just can't figure out where in my apartment it is. [1]: http://bash.org/?5273

We had a prod case where a server was being flooded with requests, and a downstream server kept falling over. We figured it was an attack of some sort and investigated, eventually traced it back to a computer inside our own network (we're a big computer, five floors of computers). It had an open file share, containing some Delphi books and from which we got the computer name too. So we walked over to the Delphi team'…

One of the issues with Knights Capital was that they forgot about a server running an old bit of code and shut down all the new ones which just sent all the data to the old server which was causing all the problems. Not keeping track of that server was very expensive.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#133
post #106

Earlier quoted context omitted.

That feels like a choice for the victim. If after the business owner sat down with the perpetrator they decided it is just some script kiddie playing at being a spy then that's up to them. The wider issue remains that some script kiddie with $120 could have done this and got away with it for ever.

Do you have a suggestion for a change to treating network security?

1) 802.1x certificate based network security (The MDM configures each approved network device with a certificate so rogue devices can't get on the network) 2) Periodic security review (look at attached network devices and determine an owner and purpose for each one). 3) Configure SIEM to alert on long-lived outbound connections.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#134

Earlier quoted context omitted.

Do kids in gifted programs go on to become intellectual elites and “captains of industry” at higher rates than their peers?

Not by much, I'd bet. If at all. The poster seems to have confused top-tier private schools and gifted programs. Read enough politician and C-suite and such bios and it's very clear what's going on. You practically never see "attended a pretty decent public high school—but was in the gifted program!" Private college prep secondary schools (at the very least—often it's private schools all the way) on the other hand ar…

I think in most cases supporting kids with money and professional experience is family merit. The family spent money and effort to help its next generation. Maybe they are not rich, just education focused and ready to sacrifice a lot to achieve it. On the other hand having too much family wealth correlates negatively with academic accomplishments.

The complexity of art and math doesn't change depending on how you learn or how rich is your father. Even with support a kid has to gain the same useful skills. What matters is ability, not how the kid got there. They are just kids, everything that shaped society into what it is happened before they were grown enough to have any say in it.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#135
post #66
post #60

Earlier quoted context omitted.

Is “gifted person” code for something? Are they from some sort of enrichment program?

“Gifted” individuals are selected at early ages to run through rigorous education programs that greatly push them ahead of their peers. It is a pipeline to create intellectual elites and captains of industry. Gifted kids are widely accepted as the most intelligent kids of a school and held up as the finest examples of the school’s educational abilities.

However, there doesn't seem to be a correlation between membership in gifted programs and success later in life.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#136
post #88

Earlier quoted context omitted.

It is completely irresponsible and without excuse for any main network operator/owner to not be completely aware of what each and every cable does which is connected to a switch/network router. If the owner refuses to determine this, they are responsible if there is a nefarious device on the network until they do. Wireless makes this much more complicated so any responsible admin will ensure the wireless network is c…

Customer site, big insurance company. The started documenting cables and labeling them to get rid of old faulty documentation. Half way through their security department forced them to stop. Why? If an attacker gains access to the documentation he would have all the information he needed. So, the had three types of cables: old ones with faulty labels, cables with right labels and unlabeled cables. And then there was…

> Half way through their security department forced them to stop. Why? If an attacker gains access to the documentation he would have all the information he needed.

Some IT security departments have very confused ideas.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#137

Reminder (from a security guy): what the author did is risky. If you are really worried about a compromised server or a suspicious device call security consultant / forensic experts.

What are the potential risks around what he did?

Malware triggered by its absence? If the device disappears, it's likely because it was found and removed, so malware that starts erasing data or otherwise causing confusion or covering their tracks is a plausible next step (though not a good one in this case, given that the device itself led straight to the person who planted it).

Re: The curious case of the Raspberry Pi in the network closet (2019)

#138

Earlier quoted context omitted.

We did get a hand written statement from him and the original evidence (hardware) is still untouched and locked away. In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena. But even though we could never decipher what the nodejs program actually did (because it was so heavily obf…

At one point you wrote "It is beyond me why a co-founder of a company would distribute these devices around town but well.." I take it, however, that the installer turned out to be someone else. Now I am curious as to whether this company advertises itself as a supplier of such things, and if so, what it claims about their capabilities. Given that the code has not been reverse engineered, can you be sure its capabili…

This is what I was thinking, except that I started wondering what weird shit this company or its owner are up to.. Maybe a slap on the wrist is just a solution to a mutually assured destruction situation. We all love conspiracy theories so if i were the author of this article id quickly quash this one and provide some more deets.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#139
post #106

Earlier quoted context omitted.

That feels like a choice for the victim. If after the business owner sat down with the perpetrator they decided it is just some script kiddie playing at being a spy then that's up to them. The wider issue remains that some script kiddie with $120 could have done this and got away with it for ever.

Do you have a suggestion for a change to treating network security?

Treat every computer like it's connected to the internet.

Probably by actually connecting it to the internet. Since the idea that you can keep people out of your network is probably more dangerous in the long term.

Re: The curious case of the Raspberry Pi in the network closet (2019)

#140

Earlier quoted context omitted.

We did get a hand written statement from him and the original evidence (hardware) is still untouched and locked away. In his statement he wrote that the pi logged to the SD card but there was no data on the SD card (well not on the data partition) and I'm pretty sure that was a lie and it just logged to Balena. But even though we could never decipher what the nodejs program actually did (because it was so heavily obf…

>he was tracking the movement data of the boss to avoid him whenever possible. Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job. I just don't get, something doesn't feel right about this being the true reason. To me it looks more like he wanted a covert backdoor in the company…

> Wow, imagine hating your boss so much you go to so much creative and illegal lengths (that can backfire against you) to track him, instead of using same skills legally to finding a better job.

I’ve mentored a lot of juniors. It’s not uncommon for young people, especially those with less developed social skills, to have an undeserved fear of their boss or anyone else with authority. It’s common with young people who have debilitating anxiety and a tendency toward rumination. They think that as long as they avoid the authority figure, they can avoid any negative social interactions (which are largely imagined).

It’s possible that the boss was bad, of course, but I kind of doubt it given that his response to this situation was to let the person off easy.

Post reply on HN