I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…
You wanted a server and complain NAS is not just a server.
When internal hostnames are leaked to the clown
141–150 of 265 posts
Re: When internal hostnames are leaked to the clown
#142Earlier quoted context omitted.
My employer uses Sentry for (backend) metrics collection so I had to unblock it to do my job. I wish Sentry would have separate infra for "operating on data collected by Sentry" and "submit every mouse click to Sentry" so I could block their mass surveillance and still do my job, but I suppose that would cut into their profit margins. My current solution is a massive hack that breaks down every now and then.
Most organizations I've set Sentry up for tunnel the traffic through their own domain, since many blocking extensions block sentry requeats by default. Their own docs recommend it as well. All that to say, it's not trivial to fully block it and you were probably sending telemetry anyway even with the domain blocked.
Quite a pain that companies refuse to take no for an answer :/
Re: When internal hostnames are leaked to the clown
#143Re: When internal hostnames are leaked to the clown
#144Earlier quoted context omitted.
wtf are you allowing plex to initiate outbound connections to begin with? and why is plex not in it's own VLAN with a egress FW rules to second with? lastly, why aren't you running snort/suricata to inspect the packets originating at plex? let me solve this problem for you - it probably doesn't bother you at all. otherwise, you'd scratched your itch a long time ago. > Clueless lol. It's ok to be clueless. And, it's o…
Its great to be clueless, thats how you learn! Just dont flex and demean other people like "Coming from someone who worked at FAANG, this is sub par post." if you're clueless. Again everything you've said does not really apply here or is impractical.
Done it. Therefore, I flex. I was talking about clueless folks like yourself.
> Again everything you've said does not really apply here or is impractical.
YMMV. Always.
Re: When internal hostnames are leaked to the clown
#145I bought a SynologyNAS and I have regretted already 3-4 times. Apart from the software made available from the community, there is very little one can do with this thing. Using LE to apply SSL to services? Complicated. Non standard paths, custom distro, everything hidden (you can’t figure out where to place the ssl cert of how to restart the service, etc). Of course you will figure it out if you spent 50 hours… but w…
Re: When internal hostnames are leaked to the clown
#146Re: When internal hostnames are leaked to the clown
#147Earlier quoted context omitted.
She was (or is) at Facebook, and "clowntown" and "clowny" are words you see there.
[flagged]
Re: When internal hostnames are leaked to the clown
#148It's treating a symptom rather than a disease, but what else can we do?
Re: When internal hostnames are leaked to the clown
#149Is "clown GCP Host" a technical term I am unaware of, or is the author just voicing their discontent? Seems to me that the problem is the NAS's web interface using sentry for logging/monitoring, and part of what was logged were internal hostnames (which might be named in a way that has sensitive info, e.g, the corp-and-other-corp-merger example they gave. So it wouldn't matter that it's inaccessible in a private netw…
Re: When internal hostnames are leaked to the clown
#150Earlier quoted context omitted.
Sounds like a great way to get sentry to fire off arbitrary requests to IPs you don’t own. sure hope nobody does that targeting ips (like that blacklist in masscan) that will auto report you to your isp/ans/whatever for your abusive traffic. Repeatedly.
Obligatory Bruce Scneier: https://www.schneier.com/blog/archives/2008/03/the_security_...
> The poster described how she was able to retrieve her car after service just by giving the attendant her last name. Now any normal car owner would be happy about how easy it was to get her car back, but someone with a security mindset immediately thinks: “Can I really get a car just by knowing the last name of someone whose car is being serviced?”
Just a couple of hours ago, I picked my car up from having its obligatory annual vehicle check. I walked past it and went into their office, saying "I'm here to pick up my car". "Which one is it?" "The Golf" "Oh, the $MODEL?" (it was the only Golf in their car park) "Yeah". And then after payment of £30, the keys were handed over without checking of anything, not even a confirmation of my surname. This was a different guy to the one who was in there an hour earlier when I dropped the car off.