ugh. I picked up a shitty NUC from ewaste and it had a label on it for an AI company.
ahh, another startup that burnt out trying to build some silly AI project on crap hardware. I wonder what they did? I check their URL:
ahh. healthcare. great, great.

but given the state of them when they arrived at ewaste?

no they did not

when you see a gaylord stacked high with NUCs and half of them still have USB fans attached, you know these were all just yanked off a shelf.
no one wiped these.

I have now stuck the hard drive in my imaging box

it turns out it was in service as of June.

and this one has log errors about the sensors in the bathroom and bedroom. this was used. fuck.

HEY FUN FACT: this was used as part of an Alexa/google home type thing! this is the "cloud" half, as in the part sitting in a warehouse somewhere.
It turns out every time the customer asked for something from the smart assistant, the WAV file was sent to the cloud box

where it is still stored. and I now have eleven thousand wave files

god the logs are full of errors about assorted video streams failing.
so this thing was connecting to something which had cameras. like, I can tell which room of the house failed.

now I don't think there's any video stored on this device, but keep in mind: the fools that made this thing fill up with WAV files? they also designed the video streaming part. Where are those videos stored, and how safe are they?

or maybe the fools who dumped all the NUCs from their entire "AI remote healthcare" in the recycling without yanking any drives are just somehow REALLY GOOD at knowing how to secure their s3 buckets.

assuming their S3 keys aren't just saved in this harddrive somewhere

jesus christ this isn't the only time THIS MONTH I've found an IoT device and checked the filesystem contents and it's got their private git repos on it

Follow

@foone If there was a bounty for this kind of shit, you'd never have to work again. my god.

· · Web · 1 · 0 · 3

@elfi yeah. the problem is I'd have to become a security researcher and I'm reasonably sure I'd rather die

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.