GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 06:41:59 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️

    ugh. I picked up a shitty NUC from ewaste and it had a label on it for an AI company.
    ahh, another startup that burnt out trying to build some silly AI project on crap hardware. I wonder what they did? I check their URL:
    ahh. healthcare. great, great.

    In conversation about 9 months ago from digipres.club permalink
    • clacke likes this.
    • Embed this notice
      Fish of Rage (sun@shitposter.world)'s status on Tuesday, 20-Aug-2024 10:58:22 JST Fish of Rage Fish of Rage
      in reply to
      @foone this is basically everything that uses S3 I've ever worked on, every single thing that didn't pull a short term key from an EC2 instance.
      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:23 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      okay so the good news is that they don't just have S3 keys laying around in plain text.
      the other good news is that they have a secrets manager
      the bad news is that they rolled their own secrets manager
      the extra bad news is that I have the source for said secrets manager
      and the extra extra bad news is that it has to decrypt those keys without external input, meaning I have all the parts here to pull out their s3 keys

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:24 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      and now I can email the lead developer.

      or just commit to their git repo, I guess.

      In conversation about 9 months ago permalink
      clacke likes this.
      clacke repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:25 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      jesus christ this isn't the only time THIS MONTH I've found an IoT device and checked the filesystem contents and it's got their private git repos on it

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:26 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      assuming their S3 keys aren't just saved in this harddrive somewhere

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:27 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      or maybe the fools who dumped all the NUCs from their entire "AI remote healthcare" in the recycling without yanking any drives are just somehow REALLY GOOD at knowing how to secure their s3 buckets.

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:28 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      god the logs are full of errors about assorted video streams failing.
      so this thing was connecting to something which had cameras. like, I can tell which room of the house failed.

      now I don't think there's any video stored on this device, but keep in mind: the fools that made this thing fill up with WAV files? they also designed the video streaming part. Where are those videos stored, and how safe are they?

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
      clacke repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:29 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      HEY FUN FACT: this was used as part of an Alexa/google home type thing! this is the "cloud" half, as in the part sitting in a warehouse somewhere.
      It turns out every time the customer asked for something from the smart assistant, the WAV file was sent to the cloud box

      where it is still stored. and I now have eleven thousand wave files

      In conversation about 9 months ago permalink
      clacke likes this.
      clacke repeated this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:30 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      when you see a gaylord stacked high with NUCs and half of them still have USB fans attached, you know these were all just yanked off a shelf.
      no one wiped these.

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:30 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      I have now stuck the hard drive in my imaging box

      it turns out it was in service as of June.

      and this one has log errors about the sensors in the bathroom and bedroom. this was used. fuck.

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:31 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      but given the state of them when they arrived at ewaste?

      no they did not

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 10:58:32 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      also I hope they wiped these hard drives

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 12:08:09 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      wait. did they seriously stuff videos into their redis database?

      In conversation about 9 months ago permalink
      iced depresso and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 12:08:10 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      tempted to drive past their HQ with a megaphone "I'VE GOT YOUR MODELS, YOU AI HACKS!"

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 12:08:11 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      oh god this thing sends email from gmail

      please tell me they didn't embed the google login into this device

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 12:08:13 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      oh hey!

      this thing authenticates to some of their servers (which are still up, even if the company might not be (this is unknown at the moment)) over SSH! using keys kept in the same home-rolled vault thing!

      so I can SSH into their servers now!

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:53:31 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      they sure did! I have a video of someone picking something up from outside a door.

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:53:40 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      okay found their S3 creds. they hardcoded them in a Jenkinsfile.

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:53:58 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      and in case anyone is getting deja-vu:

      This is a completely different company than the other one I found like 3 weeks ago:

      https://digipres.club/@foone/112817523308786223

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:53:59 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      not a good sign to see a bash case statement for environment, and prod sets the server to FOOBAR.EGG
      and test sets the server to... FOOBAR.EGG

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:53:59 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      anyway I'm gonna be near their HQ on thursday. Maybe I'll stop by and ask if they're still in business, and if they are, do they know where their NUCs are?

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Tuesday, 20-Aug-2024 21:54:12 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      I'm really not the right person to work in computer security research, but it'd be nice to have a sort of consulting job with a local one where I can just point them at some really broken shit and they investigate it and maybe give me a commission

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: and clacke like this.
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Tuesday, 20-Aug-2024 21:54:49 JST Viss Viss
      in reply to
      • Graham Sutherland / Polynomial

      @gsuberland @foone my brain just fell out

      In conversation about 9 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Graham Sutherland / Polynomial (gsuberland@chaos.social)'s status on Tuesday, 20-Aug-2024 21:54:51 JST Graham Sutherland / Polynomial Graham Sutherland / Polynomial
      in reply to
      • Viss

      @Viss @foone this is more of a thing than you might expect. I've seen a few high-volume realtime media distribution backends that use Redis as a rolling video stream cache.

      I'm particularly unsurprised to see it here because there are published tools for realtime ML media analytics using redis:

      https://github.com/RedisGears/EdgeRealtimeVideoAnalytics

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Viss (viss@mastodon.social)'s status on Tuesday, 20-Aug-2024 21:54:52 JST Viss Viss
      in reply to

      @foone ffffffffffucking what? they stuffed entire videos INTO REDIS?

      In conversation about 9 months ago permalink
    • Embed this notice
      JacobRPG+ 🫘 (jaykass@mastodon.online)'s status on Tuesday, 20-Aug-2024 21:54:58 JST JacobRPG+ 🫘 JacobRPG+ 🫘
      in reply to
      • clacke

      @clacke @foone like this

      In conversation about 9 months ago permalink

      Attachments


      1. https://files.mastodon.online/media_attachments/files/112/991/807/840/277/265/original/3c732cac0d745089.jpg
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      JacobRPG+ 🫘 (jaykass@mastodon.online)'s status on Tuesday, 20-Aug-2024 21:55:00 JST JacobRPG+ 🫘 JacobRPG+ 🫘
      in reply to

      @foone TIL what a gaylord is

      In conversation about 9 months ago permalink
    • Embed this notice
      clacke (clacke@libranet.de)'s status on Tuesday, 20-Aug-2024 21:55:00 JST clacke clacke
      in reply to
      • JacobRPG+ 🫘

      @jaykass @foone I hadn't heard it either. I guess it's these shelves?

      gaylord.com/c/Storage-and-Hand…

      In conversation about 9 months ago permalink
    • Embed this notice
      pettter (pettter@mastodon.acc.umu.se)'s status on Tuesday, 20-Aug-2024 23:26:53 JST pettter pettter
      in reply to

      @foone Incredible

      In conversation about 9 months ago permalink
    • Embed this notice
      Graham Sutherland / Polynomial (gsuberland@chaos.social)'s status on Wednesday, 21-Aug-2024 03:00:20 JST Graham Sutherland / Polynomial Graham Sutherland / Polynomial
      in reply to

      @foone the people behind this need to be barred from operating a business ever again. I know this shit happens all the time with liquidated assets but it's fucking unacceptable.

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Graham Sutherland / Polynomial (gsuberland@chaos.social)'s status on Wednesday, 21-Aug-2024 03:00:43 JST Graham Sutherland / Polynomial Graham Sutherland / Polynomial
      in reply to
      • Viss

      @Viss @foone there is some method in the madness. if you've got a lot of transient video data, and you need access to a rolling window of it (either for buffering/stability purposes or for realtime analytics), storing it to disk ends up costing a fortune because you'll end up running headlong into DWPD limits on drives and having to swap them out constantly. but with RAM there's no such wear. for a few hundred concurrent clients you can do it on a single consumer desktop PC worth of RAM.

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      clacke (clacke@libranet.de)'s status on Wednesday, 21-Aug-2024 03:00:58 JST clacke clacke
      in reply to
      • JacobRPG+ 🫘
      @jaykass @foone ah, ok
      In conversation about 9 months ago permalink
    • Embed this notice
      Ozzelot :anarchy: :linux: (ozzelot@mstdn.social)'s status on Wednesday, 21-Aug-2024 03:04:21 JST Ozzelot :anarchy: :linux: Ozzelot :anarchy: :linux:
      in reply to

      @foone keys through obscurity

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:12 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to
      • lp0 on fire :unverified:

      @lp0_on_fire I'll have you know if anyone is a gaylord full of computers, it is ME

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      lp0 on fire :unverified: (lp0_on_fire@social.linux.pizza)'s status on Thursday, 22-Aug-2024 17:15:13 JST lp0 on fire :unverified: lp0 on fire :unverified:
      in reply to

      @foone, yes: we all wondered why that person was full of NUCs and whether he appreciates being insulted like that.

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:14 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      BTW I want to make something clear:
      remember how I said there was a gaylord full of NUCs?
      yeah. I took one. of like, a hundred.

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:15 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      Why the fuck is this on hacker news? ugh. I'm gonna need to run my own mastodon instance, aren't I?

      If you found this on hacker news, you owe me 5$:

      https://digipres.club/@foone/112929955279707608

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:16 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      because this keeps happening

      In conversation about 9 months ago permalink
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:22 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to

      I haven't exploited their git repos.
      I haven't misused their leaked AWS credentials
      I haven't gone to the media to try and expose this company.

      but I took only one of NUCs. The same content is on all the rest of them, I assume

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      Foone🏳️‍⚧️ (foone@digipres.club)'s status on Thursday, 22-Aug-2024 17:15:28 JST Foone🏳️‍⚧️ Foone🏳️‍⚧️
      in reply to
      • overflow

      @overflow they're okay, haven't pissed me off yet

      In conversation about 9 months ago permalink
      clacke likes this.
    • Embed this notice
      overflow (overflow@shitposter.world)'s status on Thursday, 22-Aug-2024 17:15:29 JST overflow overflow
      in reply to
      @foone found on lobster.rs what do I owe you
      In conversation about 9 months ago permalink

      Attachments


      clacke likes this.
    • Embed this notice
      PhilipKing (philipking@mastodon.social)'s status on Thursday, 22-Aug-2024 17:15:35 JST PhilipKing PhilipKing
      in reply to

      @foone In British English , the word gaylord is derogatory slang (making fun of a member of the LGBT community) and would be considered offensive. (I had to look up what it also means in Canada/US). It’s true that we are divided by a common language.

      In conversation about 9 months ago permalink
    • Embed this notice
      clacke (clacke@libranet.de)'s status on Thursday, 22-Aug-2024 17:15:35 JST clacke clacke
      in reply to
      • PhilipKing
      @PhilipKing @foone Apart from a slur, it is also both a surname and a given name in the US and Canada as well as in the UK, although it is less common in this year than it was a century ago, for obvious bigoted reasons.
      In conversation about 9 months ago permalink
    • Embed this notice
      Ryan Finnie (foo@fosstodon.org)'s status on Thursday, 22-Aug-2024 17:15:36 JST Ryan Finnie Ryan Finnie
      in reply to

      @foone I would totally get AI care from a site with the domain ahh.healthcare.great.

      In conversation about 9 months ago permalink
      clacke likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.