Live data from Hacker News

When internal hostnames are leaked to the clown

rachelbythebay.com

71–80 of 265 posts

Re: When internal hostnames are leaked to the clown

#71
post #59

[flagged]

Wow, just skip the "bad post", "took me 30 seconds", "Basic stuff" parts already, especially when you are completely missing the point and don't seem to realize it even after several people point it out.

Show some humility.

What's more, one doesn't really read Rachel for her potential technical solutions but because one likes her story telling.

Re: When internal hostnames are leaked to the clown

#72
post #59

[flagged]

From the article: > Around this time, you realize that the web interface for this thing has some stuff that phones home, and part of what it does is to send stack traces back to sentry.io. Yep, your browser is calling back to them, and it's telling them the hostname you use for your internal storage box. Then for some reason, they're making a TLS connection back to it, but they don't ever request anything. Curious, r…

[flagged]

Re: When internal hostnames are leaked to the clown

#73
post #28

Earlier quoted context omitted.

amusingly its a term used by my co-workers to describe anyone thats not them.

Oh well... I suppose humility is your coworker's defining quality? :-)

oh the answer to this is definitive. :-P

Re: When internal hostnames are leaked to the clown

#75
post #71
post #59

[flagged]

Wow, just skip the "bad post", "took me 30 seconds", "Basic stuff" parts already, especially when you are completely missing the point and don't seem to realize it even after several people point it out. Show some humility. What's more, one doesn't really read Rachel for her potential technical solutions but because one likes her story telling.

[flagged]

Re: When internal hostnames are leaked to the clown

#76

This highlights a huge problem with LetsEncrypt and CT logs. Which is that the Internet is a bad place, with bad people looking to take advantage of you. If you use LetsEncrypt for ssl certs (which you should), that hostname gets published to the world, and that server immediately gets pummeled by requests for all sorts of fresh install pages, like wp-admin or phpmyadmin, from attackers.

It's not just Let's Encrypt, right? CT is a requirement for all Certificate Authorities nowadays. You can just look at the certificate of www.google.com and see that it has been published to two CT logs (Google's and Sectigo's)

Re: When internal hostnames are leaked to the clown

#77

Oh god this sucks, i've been setting up lots of services on my NAS pointing to my own domains recently. Can't even name the domains on my own damn server with an expectation of privacy now.

The (somewhat affordable) productized NASes all suffer from big tech diseases.

I think a lot of people underestimate how easy a "NAS" can be made if you take a standard PC, install some form of desktop Linux, and hit "share" on a folder. Something like TrueNAS or one of its forks may also be an option if you're into that kind of stuff.

If you want the fancy docker management web UI stuff with as little maintenance as possible, you may still be in the NAS market, but for a lot of people NAS just means "a big hard drive all of my devices can access". From what I can tell the best middle point between "what the box from the store offers" and "how do build one yourself" is a (paid-for) NAS OS like HexOS where analytics, tracking, and data sales are not used to cover for race-to-the-bottom pricing.

Re: When internal hostnames are leaked to the clown

#78
post #30

Is this a Chrome/Edge thing? Or do privacy respecting browsers also do this? If so, it's unexpected. If Firefox also leaks this, I wonder if this is something mass-surveillance related. (Judging from the down votes I misunderstood something)

From what I understand, sentry.io is like a tracing and logging service, used by many organizations. This helps you (=NAS developer) to centralize logs and trace a request through all your application layers (client->server->db and back), so you can identify performance bottlenecks and measure usage patterns. This is what you can find behind the 'anonymized diagnostics' and 'telemetry' settings you are asked to enabl…

My employer uses Sentry for (backend) metrics collection so I had to unblock it to do my job. I wish Sentry would have separate infra for "operating on data collected by Sentry" and "submit every mouse click to Sentry" so I could block their mass surveillance and still do my job, but I suppose that would cut into their profit margins.

My current solution is a massive hack that breaks down every now and then.

Re: When internal hostnames are leaked to the clown

#79
post #50

Oh god this sucks, i've been setting up lots of services on my NAS pointing to my own domains recently. Can't even name the domains on my own damn server with an expectation of privacy now.

> Can't even name the domains on my own damn server with an expectation of privacy now. You never could. A host name or a domain is bound to leave your box, it's meant to. It takes sending an email with a local email client. (Not saying, the NAS leak still sucks)

I don't know much about email, but how would some random service send an email from my domain if I've never given it any auth tokens?

Re: When internal hostnames are leaked to the clown

#80

Earlier quoted context omitted.

Your coworkers call you a clown?

I didnt call them workmates.

Hire somebody to make balloon animals in the office for a couple hours, pay in cash, tell the balloonist that your name is [coworker’s name]
Post reply on HN