Live data from Hacker News

Remove “This incident will be reported.” from user warnings

github.com

171–180 of 302 posts

Re: Remove “This incident will be reported.” from user warnings

#171

Earlier quoted context omitted.

I got a chiding lecture like that from some skinny UUG-type security admins, by manually shutting down my HP-UX workstation in a university CS lab. I had reached behind it and flipped the power switch. I tried to flip it back on just afterward, to resume my business (lol) but found that my login was blocked with a message...come up to security in room 300-something and talk to us to get your account un-suspended. The…

What does UUG stand for? That's the only acronym that ChatGPT didn't give me a guess for from your comment. The other guesses were: CDE - Common Desktop Environment, MTC - Missionary Training Center. GPT is much better than web search for this, I'll say that. It's ability to use context is invaluable.

This is an interesting example of the Clever Hans Phenomenon. You think you're comparing GPT and Google equally but you're actually giving GPT much more manual help. A search as simple as "UUG acronym" gives me the answer in a box at the top: "Unix Users Group" (tested in incognito).

GPT is useful, but there's an annoying tendency of it's proponents to promote it with examples they haven't validated.

Re: Remove “This incident will be reported.” from user warnings

#172
Alright, did I tell my college sysadmin story already? This is the perfect place to drop it.

1990, freshman in college, Pascal class on AT&T Unix SVR3 3B2 cluster named "earth", "wind", and "fire". We'd just learned our way around "vi" and how to "uvapc" our Pascal source into a.out.

I discovered anonymous ftp, and "make", and I quickly rose to become the gaming king of Pascal class. I had ularn, nethack, megs and megs of games crammed in my no-quota $HOME, and I'd opened permissions for everyone else to access and play them. I often chit-chatted with a classmate or two over "write" or "ytalk".

Not content to merely play games, I became mischievous with the system and its inner workings. I created a .profile and a .plan, the latter of which used VT100 cursor escape sequences to self-modify the screen, such as changing my $HOME to "/" and I also made a boastful comment about having root access.

It was all in good fun, and then came the day that I discovered /etc/passwd and I attempted to "su" to every single system account I found listed. I mean some of their passwords were just "*" so they must've been wide open!!1

I soon received ominous, chilling email from the unseen sysadmin of the whole cluster. He described to me everything I'd done up to this point, and he informed me that saying I have root access is like telling airport officials that I have a bomb. That point definitely drove it home to me as a young and dumb hacker.

So, for the rest of my short college career, while I did some silly "extra-curricular" things with my own compute resources, I was careful to not try and break system security, or even say that I had, for fear of the wrath of the unseen sysadmin.

Re: Remove “This incident will be reported.” from user warnings

#173
post #143

Earlier quoted context omitted.

There's the talk command on Unix. We used to do a 'who' to find out who're on the system and 'talk' to them.

That was such a mind blowing experience coming from a DOS background. It would split your terminal horizontally and you could see each other type in real time. Before the days of SMS, and even before the days of instant messengers like ICQ and AIM, I taught the split-screen `talk` command to my girlfriend so we could chat while I was working. We've been married for 20 years now.

"talk" was often bugged (and IIRC, used UDP) so it was soon updated by xtalk and then ytalk. ytalk was like the kitchen sink of talk, with a huge feature set and compatibility with everything that went before. Everyone had to get ytalk for sure.

Re: Remove “This incident will be reported.” from user warnings

#174

Earlier quoted context omitted.

I got a chiding lecture like that from some skinny UUG-type security admins, by manually shutting down my HP-UX workstation in a university CS lab. I had reached behind it and flipped the power switch. I tried to flip it back on just afterward, to resume my business (lol) but found that my login was blocked with a message...come up to security in room 300-something and talk to us to get your account un-suspended. The…

> the married student housing computer labs. This is a good garden-path sentence.

Learned something new today!

https://en.wikipedia.org/wiki/Garden-path_sentence

Re: Remove “This incident will be reported.” from user warnings

#175
post #137

Earlier quoted context omitted.

I once entered 'sudo echo hi" or something similar on a large HPCC and received an email back from a sysadmin that just said "hello".

That's an amusing anecdote, though I find it bothersome the sysadmin failed to correctly implement the echo command

[deleted]

Re: Remove “This incident will be reported.” from user warnings

#176

Earlier quoted context omitted.

Yes. More or less the first time I used Linux was on a fedora workstation at my desk at MIT. The very nice sysadmin down the hall sent me an email just a bit later saying "We see you were trying to install x program. We installed it for you." I understand that this is a very rare experience but the first time I saw that message, a helpful person was actually looking at these reports.

Does this kind of sysadmin still exists? (or do they even still have the freedom to be so kind?) I cannot really imagine that happening today, at least not in "professional" context.

Yes....?

If I see info in logs and it could help a user (my userbase is internal), I reach out to them. I've coached a number of them through improving something on their end, even if it's not a critical change.

And I'm by no means some sysadmin wizard.

Re: Remove “This incident will be reported.” from user warnings

#177
post #68

Earlier quoted context omitted.

something like 99% of computers with sudo installed are single-user machines where the only effect of the warning is to scare people and it's only been the same since people started to switch to sudo in the late 90s; su never printed such a warning

Reminds me of when I was younger and my mom and my brother were using a windows computer. They got the message “an illegal error has occurred” and my mom called me to ask if they had broken the law.

I almost shit myself the first time I saw X Screensaver..

It has to take the prize for worst UX ever.

Re: Remove “This incident will be reported.” from user warnings

#178

Earlier quoted context omitted.

This is great! Now when I break into a system I can quickly verify if they've got this aspect of sudo logging setup or not! Only 1/2 /s

Checking if the alarm is set by seeing if it activates seems like it's not particularly useful.

Not to comment on this particular case, but this is a more useful tactic than it seems at first. Seeing the reaction that an alarm brings can provide lots of useful information for evading future ones.

Re: Remove “This incident will be reported.” from user warnings

#179

Earlier quoted context omitted.

That was such a mind blowing experience coming from a DOS background. It would split your terminal horizontally and you could see each other type in real time. Before the days of SMS, and even before the days of instant messengers like ICQ and AIM, I taught the split-screen `talk` command to my girlfriend so we could chat while I was working. We've been married for 20 years now.

"talk" was often bugged (and IIRC, used UDP) so it was soon updated by xtalk and then ytalk. ytalk was like the kitchen sink of talk, with a huge feature set and compatibility with everything that went before. Everyone had to get ytalk for sure.

I use ytalk on a VPS that me and a friend have ssh logins for. It's still a neat way of communicating that I don't think any modern chat apps do.

Re: Remove “This incident will be reported.” from user warnings

#180
post #12

I was always disappointed it never summoned some grumpy graybeard unix admin from a dark server room basement to give me a chiding lecture.

I got a chiding lecture like that from some skinny UUG-type security admins, by manually shutting down my HP-UX workstation in a university CS lab. I had reached behind it and flipped the power switch. I tried to flip it back on just afterward, to resume my business (lol) but found that my login was blocked with a message...come up to security in room 300-something and talk to us to get your account un-suspended. The…

Also former BYU EE major (and former Mormon), very early 2000's. I recall fondly those HP-UX boxen running CDE. I really liked that UX. For some reason it really appealed to me as an engineering student. I was very active in the UUG. At one point I lived in a married student housing unit. Some of the kids fucking incessantly in those units could have stood to make sure their windows were closed. But I digress. Story time!

This was in the early days of Napster. Out of curiosity I downloaded and unzipped it in my home directory. I think I started downloading some random file but terminated it before it finished. Several weeks later when trying to log into my account, it didn't work. When I asked the skinny kid in the admin room about it, he lectured me about having the Napster software unzipped in my home directory before telling me to delete it as he re-enabled my account.

I was generally low-trust when it came to anything administration-related at my school, so I kept my own backups of all my shit. That ended up saving my ass. The HP-UX boxen were configured to dump huge core files by default on segfaults. The predictable thing happened as random widely-ignored core files proliferated throughout student home directories. I think about 2 weeks before the end of the semester, some low-level admin kid tried writing a script that recursively walks all the students' home directories and deletes core files to free up disk space. Not wanting the script to interfere with regular workloads during the day, he had it run as a cron job in the middle of the night. The kid fucked up the script, and it instead deleted all the contents of everyone's directory for the whole goddamned department. Well, effectively. I think when the admins got into work the next morning they realized that shit was completely fucked and killed the script. But massive damage had already been done. Two weeks before the end of the semester when final class projects were all coming due. Also, the backups hadn't been working, and nobody had been giving a fuck. Until then.

I had a friend in another lab in the CS department who ran a Tor exit node from his workstation. Fast forward a few weeks, and his advisor sat him down and, with a really serious tone, asked if there's anything he wanted to talk about with respect to his usage of the lab computers. Apparently some of the shit the Tor exit nodes were accessing made some waves in the department. (Bearing in mind that BYU is a very religiously conservative institution.) He somehow survived that incident, but he went out into the Real World (there's a pun here -- you should look up the whole Julie Stoffer debacle sometime) not long after of his own accord.

Then there were the students who abused the lab laser printers to print wedding invitations. All the fucking time. IIRC, it was only 10 cents a page, so it was a steal to print really nice-looking stuff at the time. Even better were the students who fed not-safe-for-laser-printer shit into the them that would melt and gunk up the insides.

Some assholes would often lock the screen rather than log out in order to "reserve" an HP-UX workstation for themselves. That got annoying when things were busy. I'd do a hard reboot whenever I ran across an unoccupied locked workstation. Apparently there were some grad students whose work that they were distributing across several nodes as background jobs would get fucked when the workstations were hard-rebooted. Personally I think that should have been a hard lesson in a "cattle, not pets" approach to distributed systems. Especially when there is effectively no physical security for the compute nodes.

There are also UUG stories. One of my favorite is when the UUG was handing out "Software for Starving Students" CDs full of OSS software in the student quad. They ended up getting reported to the "authorities" for distributing software for free.

Post reply on HN