Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

141–150 of 265 posts

Re: When internal hostnames are leaked to the clown

#141
post #53

I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…

You wanted a server and complain NAS is not just a server.

NAS is the primary function. But yes, I want full linux server that I can decide what to install and which protocol to use to upload and/or download files.

Re: When internal hostnames are leaked to the clown

#142

Earlier quoted context omitted.

My employer uses Sentry for (backend) metrics collection so I had to unblock it to do my job. I wish Sentry would have separate infra for "operating on data collected by Sentry" and "submit every mouse click to Sentry" so I could block their mass surveillance and still do my job, but I suppose that would cut into their profit margins. My current solution is a massive hack that breaks down every now and then.

Most organizations I've set Sentry up for tunnel the traffic through their own domain, since many blocking extensions block sentry requeats by default. Their own docs recommend it as well. All that to say, it's not trivial to fully block it and you were probably sending telemetry anyway even with the domain blocked.

With the right tricks (CNAME detection, URL matching) a bunch of ad blocking tools still pick up the first-party proxies, but that only works when directly communicating with the Sentry servers.

Quite a pain that companies refuse to take no for an answer :/

Re: When internal hostnames are leaked to the clown

#144
post #97

Earlier quoted context omitted.

wtf are you allowing plex to initiate outbound connections to begin with? and why is plex not in it's own VLAN with a egress FW rules to second with? lastly, why aren't you running snort/suricata to inspect the packets originating at plex? let me solve this problem for you - it probably doesn't bother you at all. otherwise, you'd scratched your itch a long time ago. > Clueless lol. It's ok to be clueless. And, it's o…

Its great to be clueless, thats how you learn! Just dont flex and demean other people like "Coming from someone who worked at FAANG, this is sub par post." if you're clueless. Again everything you've said does not really apply here or is impractical.

> [ ... ] if you're clueless.

Done it. Therefore, I flex. I was talking about clueless folks like yourself.

> Again everything you've said does not really apply here or is impractical.

YMMV. Always.

Re: When internal hostnames are leaked to the clown

#145
post #53

I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…

I bought Synology RS217 for $100 last year and it's the best tech purchase I made in years. The software it comes with is the best web interface I experienced in years. The simplicity, stability and attention to detail reminds me of old macs. I have macmini as application server and did not expect to use Synology for anything but file storage / replication. However it comes with a great torrent client that I use all the time now. We also use Synology Office instead of google docs now. It exceeded all my expectations and when it dies, I will immediately buy one of the new rack stations they offer.

Re: When internal hostnames are leaked to the clown

#147

Earlier quoted context omitted.

She was (or is) at Facebook, and "clowntown" and "clowny" are words you see there.

[flagged]

No it's because lots of stuff is duct taped together and then you have tons of scripts or tooling that was someone's weekend project (to make their oncall burden easier) that they shared around. Usually there'll be a flag like --clowntown or --clowny-xyz when it's obvious to all parties involved that it's destined to destroy everything one day but YOLO (also a common one).

Re: When internal hostnames are leaked to the clown

#148
Stuff like this is why I consider uBlock Origin to be the bare minimum security software for going on the web. The amount of 3rd party scripts running on most pages, constantly leaking data to everybody listening, is just mind boggling.

It's treating a symptom rather than a disease, but what else can we do?

Re: When internal hostnames are leaked to the clown

#149
post #15

Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Seems to me that the problem is the NAS's web interface using sentry for logging/monitoring, and part of what was logged were internal hostnames (which might be named in a way that has sensitive info, e.g, the corp-and-other-corp-merger example they gave. So it wouldn't matter that it's inaccessible in a private netw…

The circus left town, but the clowns are still here.

Re: When internal hostnames are leaked to the clown

#150
post #34

Earlier quoted context omitted.

Sounds like a great way to get sentry to fire off arbitrary requests to IPs you don’t own. sure hope nobody does that targeting ips (like that blacklist in masscan) that will auto report you to your isp/ans/whatever for your abusive traffic. Repeatedly.

Obligatory Bruce Scneier: https://www.schneier.com/blog/archives/2008/03/the_security_...

Hehe, just reading that.

> The poster described how she was able to retrieve her car after service just by giving the attendant her last name. Now any normal car owner would be happy about how easy it was to get her car back, but someone with a security mindset immediately thinks: “Can I really get a car just by knowing the last name of someone whose car is being serviced?”

Just a couple of hours ago, I picked my car up from having its obligatory annual vehicle check. I walked past it and went into their office, saying "I'm here to pick up my car". "Which one is it?" "The Golf" "Oh, the $MODEL?" (it was the only Golf in their car park) "Yeah". And then after payment of £30, the keys were handed over without checking of anything, not even a confirmation of my surname. This was a different guy to the one who was in there an hour earlier when I dropped the car off.

Post reply on HN