6 ms·
Apparently his servers keep getting hacked, which doesn’t reflect well on his security practices: https://twitter.com/LukeDashjr/status/1606885577843957762 http
by phphphphp 4y ago
Apparently his servers keep getting hacked, which doesn’t reflect well on his security practices: https://twitter.com/LukeDashjr/status/1606885577843957762 https://twitter.com/LukeDashjr/status/1606885577843957762
- technion 4y agoAssuming this physical access claim is truthful (and i have doubts), I would feel at this point its budget letting him down. If your threat model includes "targeted attacks from people with physical access", it's time to run a vm on aws or azure and use the tooling they make available to secure it further. If you want tonnes of resourcing at a quite low budget, there's only a certain amount of "calling out" the group that supplied it that's reasonable.
- tinus_hn 4y agoIf he has enough Bitcoins for it to be possible for ‘many of them’ to be stolen, he doesn’t have a small budget.
- technion 4y agoJust makes this thread stranger. I know if I had over $3m in btc and was working professionally with them I wouldn't state my top budget was $55. Edit: his tweets specifically talk about not using "cloud nonsense " and states getting your own key to a rack is too expensive for him.
- johnklos 4y agoMy goodness. Really? He refers to "cloud nonsense", then uses a "dedicated server"? That's a new kind of special.
- pshirshov 4y agoFrom his tweets: he was renting a physical server for $55/m. So, a total joke.
- r1ch 4y agoI believe most of these "physical attacks" are datacenter support teams being socially engineered and not state-level actors. They hook up a USB rescue drive to "help" you back into your server, using full disk encryption or locking down the BIOS can thwart such attacks.
- technion 4y agoYou know as much as I'm generally unhappy with what MS is doing with forcing TPMs on Windows 11, I have to say Bitlocker on Windows is basically single click and a perfect solution, and I'm a bit disappointed in the scale of every comparable Linux guide I just Googled up. I can see why the average company doesn't have it deployed.
- distantsounds 4y agoLUKS isn't rocket science, you're looking at the wrong guides. using the TPM to encrypt a partition is a few commands on the shell.
- bbbbb5 4y agoNot necessarily SE, there's been tons of 0days exploited against stuff like WHMCS, Hostbill, Kayako and many other systems used by hosting companies to manage this kind of thing. Colocation and epoxy in any relevant ports is the obvious way to avoid this.
- petesergeant 4y agoSure, perhaps, but parent’s point still stands that AWS techs are not plugging USB drives into servers, because their threat-model already includes state-sponsored attacks.
- sureglymop 4y agoProbably bad security practices. Maybe he has accessed a compromised server over ssh and used agent forwarding or something. Anyhow, looks like a pretty bizarre profile...
- blibble 4y agoit's even more amazing, he's posted: > So... Any trustworthy companies offering affordable dedicated servers? > > Currently paying $55/mo for: so if you offer him some crappy free dedi appearing to be in an IP block of a reputable company all you have to do is wait a bit and presumably he'll upload his wallet.dat for you!
- hnarn 4y agoI wonder if this is the same server that “wasn’t fully rebooted in years”. https://bitcoinhackers.org/@lukedashjr/107769287522154866 https://bitcoinhackers.org/@lukedashjr/107769287522154866
- resonious 4y ago> Evidence suggests the attacker installed 2-3 remote shell backdoors, but didn't touch anything else. Well, I guess he now has evidence that maybe they touched something else.
- seba_dos1 4y agoJust a few days ago he popped into friend's Twitter thread about similarities between Freenode and Twitter situations, and announced that it was Libera Chat that conducted a hostile takeover against Freenode. Somewhat I'm not surprised at all.