Post ASuUQvcfa2PERdTW5Y by leftpaddotpy@queer.af
 (DIR) More posts by leftpaddotpy@queer.af
 (DIR) Post #ASuUQvcfa2PERdTW5Y by leftpaddotpy@queer.af
       2023-02-19T17:27:37Z
       
       1 likes, 0 repeats
       
       giving a catgirl a Linux image of an undocumented device from China is like giving a cat a ball of yarn
       
 (DIR) Post #ASuUQxPGwosTyfDqU4 by leftpaddotpy@queer.af
       2023-02-19T19:10:04Z
       
       0 likes, 0 repeats
       
       so far we have found (from the manufacturer, not a user):- ssh key, private, with a description of the qq address of one of the authors- a gitconfig file- browser history- the encryption keys for the ecryptfs for the ruby code- lots of funny binaries to run the hardware- a /bin/rm http endpoint with arbitrary paths- logs and logs and logs from development time- frustratingly hashed known_hosts- frustratingly nontrivial to crack glibc password hashing (salt plus 5k rounds of sha512 isn't nothing, that's still a 5k divisor on your cracking speed)