Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

161–170 of 265 posts

Re: When internal hostnames are leaked to the clown

#161
Having recently set up sentry, at least one of the ways they use this is to auto-configure uptime monitoring.

Once they know what hosts you run, it'll ping that hostname periodically. If it stays up and stable for a couple days, you'll get an alert in product: "Set up uptime monitoring on ?"

Whether you think this is valid, useful, acceptable, etc. is left as an exercise to the reader.

Re: When internal hostnames are leaked to the clown

#162

Having recently set up sentry, at least one of the ways they use this is to auto-configure uptime monitoring. Once they know what hosts you run, it'll ping that hostname periodically. If it stays up and stable for a couple days, you'll get an alert in product: "Set up uptime monitoring on ?" Whether you think this is valid, useful, acceptable, etc. is left as an exercise to the reader.

Expansion opportunities

Re: When internal hostnames are leaked to the clown

#163

Earlier quoted context omitted.

> Admittedly, most residential ISPs block all SMTP traffic, and other email servers are likely to drop it or mark it as spam, but there's no strict requirement for auth. Source? I've never seen that. Nobody could use their email provider of choice if that was the case.

The 3 most common ISPs in the US are Comcast, Spectrum, and AT&T Comcast blocks port 25: https://www.xfinity.com/support/articles/email-port-25-no-lo... AT&T says "port 25 may be blocked from customers with dynamically-assigned Internet Protocol addresses", which is the majority of customers https://about.att.com/sites/broadband/network What ISP are you using that isn't blocking port 25, and have you never had the mi…

Well I am not in the USA for a start but if it is blocked it must be only inbound otherwise it would break everybody.

Re: When internal hostnames are leaked to the clown

#164
post #34

Earlier quoted context omitted.

Obligatory Bruce Scneier: https://www.schneier.com/blog/archives/2008/03/the_security_...

Good read, but: > This kind of thinking is not natural for most people. It’s not natural for engineers. Good engineering involves ... I have to disagree in the strongest terms. It doesn't matter what it is, the only way to do a good job designing something is to imagine the ways in which things could go wrong. You have to poke holes in your own design and then fix them rather than leaving it to the real world to tear…

hmmm I am 50% with you. Imho to be an amazing engineer is to see a problem and find a good(whatever good means) solution. Beeing a good scientist is asking precise questions and finding experiments validating them.

I think its more the nuanced difference between safety and security. Engineers build things so they run safe. For example building a roof that doesnt collapse is a safe roof. Is the roof secure? Maybe I can put thermites in the wood...

this is the difference. Safety is no harm done from the thing itself Engineers build and security is securing the thing from harm from outside.

Re: When internal hostnames are leaked to the clown

#168

Earlier quoted context omitted.

The 3 most common ISPs in the US are Comcast, Spectrum, and AT&T Comcast blocks port 25: https://www.xfinity.com/support/articles/email-port-25-no-lo... AT&T says "port 25 may be blocked from customers with dynamically-assigned Internet Protocol addresses", which is the majority of customers https://about.att.com/sites/broadband/network What ISP are you using that isn't blocking port 25, and have you never had the mi…

Well I am not in the USA for a start but if it is blocked it must be only inbound otherwise it would break everybody.

> if it is blocked it must be only inbound

Yep, at least in France it's like this for ISPs doing this IIRC.

Re: When internal hostnames are leaked to the clown

#169
post #34

Earlier quoted context omitted.

Obligatory Bruce Scneier: https://www.schneier.com/blog/archives/2008/03/the_security_...

Good read, but: > This kind of thinking is not natural for most people. It’s not natural for engineers. Good engineering involves ... I have to disagree in the strongest terms. It doesn't matter what it is, the only way to do a good job designing something is to imagine the ways in which things could go wrong. You have to poke holes in your own design and then fix them rather than leaving it to the real world to tear…

It wasn't typical in 2008, I think, is the upshot.

Re: When internal hostnames are leaked to the clown

#170
post #141

Earlier quoted context omitted.

NAS is the primary function. But yes, I want full linux server that I can decide what to install and which protocol to use to upload and/or download files.

Why not just leave the NAS to be a NAS and get a separate server? You're probably better off not trying to overload the NAS to be everything.

Can you provide some details about this overloading concept?
Post reply on HN