Why I quit this battle
61–70 of 126 posts
Re: Why I quit this battle
#62Earlier quoted context omitted.
Copper needs to die. The Australian NBN is a mess because of it. Sigh, what could've been...
FTTx systems make copper almost non-existent. All copper in my city is replaced by fiber, and only copper is from the FTTx box in front of my apartment to my flat. Eeerything (landline, internet, IPTV, etc.) runs from a single, dark fiber. With cabling already in place and VDSL can reliably provide 5 units of bandwidth (where 4 units is used for download and 1 unit is used for upload, e.g. 32/8 mbps), with a theoreti…
I can't wait until my HFC NBN service here goes the way of the dodo.
While I have 1000mbps down, the 50mbps upload is just miserable. And the cost is painful, $130 AUD a month.
Re: Why I quit this battle
#63I ended up making a big stink elsewhere and they got the repo down. Funny enough, their heads of security told me they'd use my disclosure to push the execs into building a big bounty program. Long story short, their CISO told me on the phone that what I found wasn't a "bug", and that if they did a bug bounty program, they'd go bankrupt.
Re: Why I quit this battle
#64His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up maki…
Re: Why I quit this battle
#65Earlier quoted context omitted.
Me too. Not sure why artifact_44's comment is dead so I vouched for it, I don't see what is gained by throwing around psychiatric terms, used pejoratively, for no good reason (could there be a good reason on HN? I doubt it but I don't see one here).
So I think it's wrong of the author to flame other people publicly. I really denounce that. I shouldn't have gone for the jugular, using a word for a real illness. I apologise for that. That was wrong. The reason I wrote that was to convey my feeling that the author is doing something bad, writing an unstructured misspelled text bullying people with allegations that are also not verifiable. I should have thought abou…
Re: Why I quit this battle
#66You might think "that only moves the attack surface" , you are both right and wrong. Technically it is moved but you eliminate LAN based, wireless (think wpa) and untrusted network devices from the equation and reduce them to one attack surface. Not only that, the threat actors most relevant to most people's threat models are not able to operate or operate with reduced capability to the most part when the attack surface is not a home network/device managed by individuals (and crappy vendors,isps,etc...).
It can pay for itself, don't worry about network device security, just get the cheapest yet fastest stack amd VPN through it.
Re: Why I quit this battle
#67The code that makes these devices fail uses up lots of UDP ports which suggests that the issue may be with the NAT implementation. I have done some searching online but haven't got a definitive answer on what exactly the issue is (other than it causes latency and hitter under certain conditions).
I'm slightly sceptical these modems (really modem routers) are as bad as this site previously suggested. It seems like the only use case that breaks them is some specific games where there is a huge amount of latency critical UDP traffic.
Re: Why I quit this battle
#68"Flounce, v. To leave an internet group or thread with exaggerated drama; deleting posts, notifying mods and or group users, and cross-posting on other groups to draw attention to the drama. Comes from the original use of gathering up skirts and petticoats and leaving in dramatic, impatient and exaggerated movements." - https://www.urbandictionary.com/define.php?term=Flounce
Re: Why I quit this battle
#69His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up maki…
I appreciate the honesty! I do think that any company that offers a bug bounty program already has their security in order, to the point where they can no longer find any obvious issues themselves anymore. Not having a bug bounty program implies they don't really trust themselves yet, or haven't reached that level of maturity yet. That probably covers most companies though. I know the codebase I inherited at my current employer wouldn't pass even the most superficial security check. Its only line of defense is that it's only on private networks. Until it isn't. I wonder if I should do a google to look for any public instances... just did, I'm only finding a lot of search engine spam thankfully.
Re: Why I quit this battle
#70His experience is similar to one I had a long while back when trying to report to Comcast that I found one of their sysadmin's home directory on GitHub. It had ssh keys, passwords, configs, scripts, etc etc. When I reported it on their support forum, some random dude responded basically saying I found nothing, insulting me, etc. It's wild to me how quickly people will go to insult in these situations. I ended up maki…
Comcast is the worst! Seriously, just a terrible company all around. How long ago was this BTW? I think they've had an undisclosed security breach, but this may help prove it.