Email or username:


Forgot your password?

ugh. I picked up a shitty NUC from ewaste and it had a label on it for an AI company.
ahh, another startup that burnt out trying to build some silly AI project on crap hardware. I wonder what they did? I check their URL:
ahh. healthcare. great, great.

Diane 🕵


Scan the filesystem for crimes first?

Jeremy Stephens

@foone where do you get ewaste from? is it a local place where people dump electronics or is it like a second hand shop where you can buy old stuff?

Scott Miller 🇺🇦 🇺🇸

@viking @foone I too want to know where I can rummage through ewaste bins and take stuff home.


also I hope they wiped these hard drives


but given the state of them when they arrived at ewaste?

no they did not


when you see a gaylord stacked high with NUCs and half of them still have USB fans attached, you know these were all just yanked off a shelf.
no one wiped these.

Calyo Delphi

@jaykass @foone lmao yeah it's a common term in warehouse logistics

Someone who has delivered car parts for a living and had to unpack gaylords brought in on truck day


I have now stuck the hard drive in my imaging box

it turns out it was in service as of June.

and this one has log errors about the sensors in the bathroom and bedroom. this was used. fuck.

Fi, infosec-aspected


oh that's.......that's -reallllllll- unfortunate.

Fi, infosec-aspected


is the company still in business because this is a material breach type situation


HEY FUN FACT: this was used as part of an Alexa/google home type thing! this is the "cloud" half, as in the part sitting in a warehouse somewhere.
It turns out every time the customer asked for something from the smart assistant, the WAV file was sent to the cloud box

where it is still stored. and I now have eleven thousand wave files

Graham Spookyland🎃/Polynomial

@foone the people behind this need to be barred from operating a business ever again. I know this shit happens all the time with liquidated assets but it's fucking unacceptable.


@foone JFC this is doubleplusungood

Advanced Persistent Teapot

@foone exhibit #1473 in Why I Will Not Have Smart Home Shit, Ever


@foone this has _got_ to be some kind of crime, right? like, not you having the wav files, but the fact that someone gave them to you. a HIPAA violation at the very least


@glyph oh, most likely.
but I probably have all this shit because they are gone and bankrupt

Graham Spookyland🎃/Polynomial

@glyph @foone sadly, no. at most it's *maybe* a GDPR violation depending on the content of the WAV files, but likely not, and I'm guessing that's going to be impossible to prosecute anyway because the assets are almost certainly a result of an insolvency liquidation. I see this shit all the damn time and right now there's very little recourse for those affected.


If this is from an EU customer, it is a GDPR violation. But as you stated, there is probably no legal entity anymore that could pay the fine. Which means we need an appendix that ensures that the insolvency administrator enforces GDPR in liquidation cases (or would be personally liable if shit like this happens).

And again, this would probably not apply to the US so good look out there...
@glyph @foone

If this is from an EU customer, it is a GDPR violation. But as you stated, there is probably no legal entity anymore that could pay the fine. Which means we need an appendix that ensures that the insolvency administrator enforces GDPR in liquidation cases (or would be personally liable if shit like this happens).


god the logs are full of errors about assorted video streams failing.
so this thing was connecting to something which had cameras. like, I can tell which room of the house failed.

now I don't think there's any video stored on this device, but keep in mind: the fools that made this thing fill up with WAV files? they also designed the video streaming part. Where are those videos stored, and how safe are they?


or maybe the fools who dumped all the NUCs from their entire "AI remote healthcare" in the recycling without yanking any drives are just somehow REALLY GOOD at knowing how to secure their s3 buckets.


assuming their S3 keys aren't just saved in this harddrive somewhere


jesus christ this isn't the only time THIS MONTH I've found an IoT device and checked the filesystem contents and it's got their private git repos on it


and now I can email the lead developer.

or just commit to their git repo, I guess.

Foone🏳️‍⚧️ replied to Foone🏳️‍⚧️

okay so the good news is that they don't just have S3 keys laying around in plain text.
the other good news is that they have a secrets manager
the bad news is that they rolled their own secrets manager
the extra bad news is that I have the source for said secrets manager
and the extra extra bad news is that it has to decrypt those keys without external input, meaning I have all the parts here to pull out their s3 keys

Foone🏳️‍⚧️ replied to Foone🏳️‍⚧️

oh hey!

this thing authenticates to some of their servers (which are still up, even if the company might not be (this is unknown at the moment)) over SSH! using keys kept in the same home-rolled vault thing!

so I can SSH into their servers now!

Foone🏳️‍⚧️ replied to Foone🏳️‍⚧️

oh god this thing sends email from gmail

please tell me they didn't embed the google login into this device

Foone🏳️‍⚧️ replied to Foone🏳️‍⚧️

tempted to drive past their HQ with a megaphone "I'VE GOT YOUR MODELS, YOU AI HACKS!"

Foone🏳️‍⚧️ replied to Foone🏳️‍⚧️

wait. did they seriously stuff videos into their redis database?

Σ(i³) = (Σi)² replied to Foone🏳️‍⚧️

I heard somewhere you were low on cash? I wonder how much what you have there might fetch on some shady website...

Elfi, :verifiedtransbian: cute moth

@foone If there was a bounty for this kind of shit, you'd never have to work again. my god.

Foone🏳️‍⚧️ replied to Elfi, :verifiedtransbian: cute moth

@elfi yeah. the problem is I'd have to become a security researcher and I'm reasonably sure I'd rather die

Juliet Merida (she/they) 🚝🏳️‍⚧️🏹🎯 Based on what you've described so far I'd be surprised if you *don't* find their keys.

The Turtle

@foone some models of those NUCs run Mac OSX pretty well.


@foone this is like a horror story ohno 😭

Lars Marowsky-Brée 😷

@foone Uhm. This sounds like you can finance the rest of your life with a class action law suit.
Or, if that has data from EU/California citizens, have a noticeable impact to their shareholder value.
I think you're set.

Tod Beardsley 🤘

@larsmb @foone while Foone probably doesn’t have standing to be in the class, they can certainly try to charge a consulting fee to a law firm.

Wilfried Klaebe

@foone Someone needs to be sued to hell and back. And then to hell again.

Niko :neofox_flag_nb_256: :neofox_flag_trans_256:

@foone oh great
flashbacks to the time i discovered home assistant kept my precise location history for two weeks
at least that was on my own hardware
this is somewhat more terrifying

The Turtle


"Buying more shit from that place."


@foone oh good grief I feel like I'd fuck up that drive immediately to be rid of it, might as well be toxic waste for how much I don't want that


@foone If you're in the bay area, it's 50/50 whether they were disposed of improperly or just stolen, tbh.

Ryan Finnie

@foone I would totally get AI care from a site with the domain


@foo Glad I was not alone in parsing it that way lol

remote procedure chris

@foone ah, the "how much <bubble> company garbage is showing up at ewaste" index


@foone that sound suspiciously like my day job, you are scaring me


@foone P, that's reassuring, a bit. Also we don't have USB fan nor rack full of NUC, we have a single one per client. But we had at least two that reboot for definitively known reason? We are assuming they run out of memory at this point


@foone thanks! Your threads are like the greatest content here.


@foone wonder how everyone seems to be able to draw nice stuff from e-waste. Here it's only junk all the time :(

Go Up