Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Do a Tesla move and say that's a new service and they need to pay 10000 a month to keep using the service otherwise you reserve the right to mess up with the responses. :P of course, just a joke, but that's what they do
  • Thankfully it doesn't seem to be much traffic, but still... weird. You'd hope at somepoint the weird responses would get looked at in some log, but I won't hold my breath for that haha.

    Tangential, but I love the design of your blog. That's so freakishly accurate to old GNOME 2 Ubuntu, amazing work.

  • I'd try to contact Assetnote. Most (sadly not all) managed vuln scan companies are pretty sensitive to scanning stuff that doesn't belong to their client and could expose them to liabilities because they don't have permission.
    by kjs3
  • CNAME'ing pool-ntp.tesla.com to something they do not control is already quite risky as it would allow someone to e.g. request pool-ntp.tesla.com certificate though it might take quite a few tries.
  • I've been consistently attacked by ShadowServer who have the following sponsors,

    Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nihon Cyber Defence, Nucleus Security, Orange Polska, Precursor Security, Protect.ngo, Public Interest Registry (PIR), Red Hat, SURFcert, SWITCH, Team Cymru, Trend Micro, Trivest AG, Tucows, Verisign, VulnCheck,

    I don't care what they say they're doing, I hate how corporations can act with impunity with these types of things while everyone else would get a felony for it.

  • “You must absolutely not use the default pool.ntp.org zone names as the default configuration in your application or appliance.”

    ref: https://www.ntppool.org/en/vendors.html

  • I’m pretty sure this way they’ve hardcoded the NTPs is actually against the ToS for use of the NTP pool too.

    The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html

    On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.

  • Remember in 2003 when netgear hardcoded a university's NTP server into a ton of their products? Well....

    https://www.google.com/search?&q=university+ntp+server+netge...

    https://pages.cs.wisc.edu/~plonka/netgear-sntp/

Explore Birbla archives