Live data from Hacker News

You might want to stop running atop

rachelbythebay.com

151–155 of 155 posts

Re: You might want to stop running atop

#151
post #66

Earlier quoted context omitted.

> it's too easy for a dictatorship to force something We really need to get rid of this mentality. Australia has laws that allow undisclosed, compelled, software updates. Verbally by ministers, but written (confidential) changes can be requested by federal agencies. Many western countries have followed to various degrees. There's no stable trusted government that doesn't want its fingers in your code.

I agree it's not good but being realistic: I'd be far less worried about the Australian government stealing/selling customer data, using my servers in a botnet, using my servers to spread malware.. etc. Mainland China, Russia, North Korea, all have proven track records of doing these things and having corporate espionage rat lines: https://www.youtube.com/watch?v=y27B-sKIUHA

strong speculation that fortigates annual SSL VPN CVE's are simply government backdoors.

Re: You might want to stop running atop

#152
post #112

Earlier quoted context omitted.

I am out of the loop. Who is Rachel, and what are they famous for?

She is a known technology blogger https://rachelbythebay.com , active for more than a decade. Her posts often make it to front page. I'd trust her enough to remove a non-essential component like atop basically.

Why should one trust her? What's her full name and the reason for deferring to her expertise?

And yes I'm aware her posts have made it to the top of HN many times in the past. That I've seen, they've all been unhelpful vague-posts like this one.

Maybe she's actually a real expert I should be listening to! But layer upon layer of vague "if you know, you know" do not make that case.

Re: You might want to stop running atop

#153
post #20

There's a lot of speculation about why, with the answer almost certainly security / exploitable (or backdoor), and I'll just throw an extra little tidbit in: atop seems to run persistently as root, which may be the reason for preventing it from running/uninstalling. the netatop part of atop installs a persistent kernel module, netatop.ko, as part of its installation. The module hooks netfilter to be able to monitor a…

When we tried deploying it we had netatop crashing kernels with a use after free on a linked list, based on the stack traces and kernel dumps. Every box we trialed it on started going down multiple times a week.

Re: You might want to stop running atop

#155
post #152
post #112

Earlier quoted context omitted.

She is a known technology blogger https://rachelbythebay.com , active for more than a decade. Her posts often make it to front page. I'd trust her enough to remove a non-essential component like atop basically.

Why should one trust her? What's her full name and the reason for deferring to her expertise? And yes I'm aware her posts have made it to the top of HN many times in the past. That I've seen, they've all been unhelpful vague-posts like this one. Maybe she's actually a real expert I should be listening to! But layer upon layer of vague "if you know, you know" do not make that case.

turns out you can Google it.
Post reply on HN