Live data from Hacker News

Found hooked up to my router

reddit.com

351–358 of 358 posts

Re: Found hooked up to my router

#351
post #326

Earlier quoted context omitted.

This is why certificate pinning and modern web security practices are so important. On a well configured site, this attack would fail.

HSTS and Certificate Transparency, yes. Certificate Pinning is too easy to shoot yourself in the foot with, so it should only be considered for the most sensitive sites.

Dynamic pinning (HPKP header) is being rolled back from browsers because of the reasons you mention. Only a small set of static pins will remain (in Chrome, Google sites for example).

Re: Found hooked up to my router

#352
post #273

Earlier quoted context omitted.

I was at a financial software firm that dealt with USB security issues by filling the USB sockets with epoxy. The keyboard and mouse could not be removed from their USB sockets as they were held in place with a metal collar bolted to the case. Simple and effective, although it destroyed any resale value of the PCs.

Do businesses (other than super small startups) actually sell their old hardware? Genuinely curious.

In this company's case the PCs were the cheapest of the cheap. Bottom end Dell and HP stuff.

when they were life expired they were given over to a recycling company, whom I assume would take the time to pick the epoxy out of the USB sockets or probably just replace them. I think buying new USB sockets and connecting ribbons to the motherboards is probably quite cheap these days

Re: Found hooked up to my router

#353

Earlier quoted context omitted.

Are Windows 0-days really that common? I thought they were usually saved for really serious attacks, e.g. from state-sponsored actors, not scams on the level of "pay some random person $15 a month to attach a mysterious device to their router".

I can't answer your question authoritatively, but there are plenty of organised criminal enterprises in the world with state-level resources.

Not just a question of state-level-ness, but of targeted/mass. Burning a 0day on a mass scam is really, really stupid.

Re: Found hooked up to my router

#354
post #293

Is a disk image of one of these available anywhere? I find it much more likely that these are being used for what they say they are (basically a proxy so they can buy ads from a residential IP) than some crazy MITM device. The "Attacker" is basically renting an IP connection or paying a co-location fee for their little server. Plugging a device into your network doesn't make it magically see all the traffic. It would…

Unless OP is someone very special, all their private data isn't worth 15 dollars a month.

I suspect this device is far more likely a broadband speed testing agency trying to get speed test results from different consumer ISP's, taking WiFi and the customers device out of the picture.

Re: Found hooked up to my router

#355
post #293

Is a disk image of one of these available anywhere? I find it much more likely that these are being used for what they say they are (basically a proxy so they can buy ads from a residential IP) than some crazy MITM device. The "Attacker" is basically renting an IP connection or paying a co-location fee for their little server. Plugging a device into your network doesn't make it magically see all the traffic. It would…

Unless OP is someone very special, all their private data isn't worth 15 dollars a month. I suspect this device is far more likely a broadband speed testing agency trying to get speed test results from different consumer ISP's, taking WiFi and the customers device out of the picture.

I disagree; the plug-in-this-Raspberry-Pi scam is unfortunately not uncommon, and not at all related to broadband testing AFAIK. A company called rentyouraccount.com runs a similar scam, and their service explains what the Pi is doing:

>Facebook has several mechanisms in place to protect your account. We make every attempt to work within the these constraints. In order to keep your account from being locked we use a small device called a Raspberry Pi. This device allows us to connect to Facebook advertising APIs from your home network and avoids the hassle of your account being locked due to unfamiliar activity. Learn more about the Raspberry Pi below.

https://www.reddit.com/r/Scams/comments/2vd1g8/scam_rentyour...

Re: Found hooked up to my router

#356
post #305

Earlier quoted context omitted.

Chrome changes the "Not secure" in the address bar from grey to red (and displays a red explamation mark symbol there) when data is entered into the form.

Which version/OS? I have the latest Chrome (69.0.3497.100) on macOS 10.13.3, and I see no red exclamation mark. Nothing changes or warns me at all when I start entering data in the fields. https://imgur.com/a/Q0rZWOS Maybe you have a browser extension, or setting turned on that I'm missing?

This is in Version 69.0.3497.100 (Official Build) (64-bit), Windows 10.

This happens regardless of extension (i.e. in an incognito window).

Re: Found hooked up to my router

#357

Earlier quoted context omitted.

Unless OP is someone very special, all their private data isn't worth 15 dollars a month. I suspect this device is far more likely a broadband speed testing agency trying to get speed test results from different consumer ISP's, taking WiFi and the customers device out of the picture.

I disagree; the plug-in-this-Raspberry-Pi scam is unfortunately not uncommon, and not at all related to broadband testing AFAIK. A company called rentyouraccount.com runs a similar scam, and their service explains what the Pi is doing: >Facebook has several mechanisms in place to protect your account. We make every attempt to work within the these constraints. In order to keep your account from being locked we use a…

Sounds true, although I question why they don't simply install a proxy extension in the users browser. Would save them a lot of capital expenses.
Post reply on HN