<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: mmstr</title><link>https://news.ycombinator.com/user?id=mmstr</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 19 Sep 2026 20:22:31 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=mmstr" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by mmstr in "Remote Access Backdoor Discovered in Chinese Robot Dog Unitree Go1"]]></title><description><![CDATA[
<p>From the article:<p>"The discovery of the backdoor was made by cybersecurity specialists Andreas Makris (aka Bin4ry) and Kevin Finisterre (aka d0tslash), who published their findings in a detailed technical report late last week. The duo reverse-engineered firmware and conducted a hands-on analysis of the Unitree Go1 robot dog, revealing that each device ships with a preconfigured tunnel client that initiates a connection to CloudSail — a remote access platform developed by Zhexi Technology, based in China.<p>The researchers demonstrated that upon gaining access to the CloudSail API, which they did using a recovered API key, they could:<p><pre><code>    List all connected devices and their IP addresses
    Establish remote tunnels to those devices
    Access the robot dog’s web interface with no authentication
    Use the robot’s cameras for live surveillance
    Log in via SSH using default credentials (pi/123)
    Move laterally within internal networks to which the robot is connected
</code></pre>
Makris and Finisterre identified a total of 1,919 unique Unitree Go1 units that had connected to the CloudSail network. While most connections originated from Chinese IP addresses, a significant number were traced to academic and corporate networks abroad. Notable institutions included MIT, Princeton, Carnegie Mellon, and the University of Waterloo, among others. The researchers even observed some units connecting via Starlink, suggesting use in mobile or remote environments."</p>
]]></description><pubDate>Sun, 06 Apr 2025 20:33:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=43604739</link><dc:creator>mmstr</dc:creator><comments>https://news.ycombinator.com/item?id=43604739</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43604739</guid></item><item><title><![CDATA[New comment by mmstr in "The Shepherd 1.0.0 released"]]></title><description><![CDATA[
<p>For those that don't know, GNU Shepherd is an init system (like systemd) written in Guile (a LISP), the unit files are written with Guile too.</p>
]]></description><pubDate>Tue, 14 Jan 2025 17:55:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=42701000</link><dc:creator>mmstr</dc:creator><comments>https://news.ycombinator.com/item?id=42701000</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42701000</guid></item><item><title><![CDATA[Pros and Cons of Suns (1987)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.dourish.com/goodies/suns-boot-fast.html">https://www.dourish.com/goodies/suns-boot-fast.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37715000">https://news.ycombinator.com/item?id=37715000</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 30 Sep 2023 13:02:11 +0000</pubDate><link>https://www.dourish.com/goodies/suns-boot-fast.html</link><dc:creator>mmstr</dc:creator><comments>https://news.ycombinator.com/item?id=37715000</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37715000</guid></item><item><title><![CDATA[New comment by mmstr in "Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475"]]></title><description><![CDATA[
<p>Context for people reading the comments:<p>CVE-2022-47966 is a Zoho vulnerability, while the other is a fortigate one, both are RCEs
Both have had public PoCs published at least early this year, there's a bunch more of publicly known RCEs that are still unpatched and used by some tens of thousands of machines, according to Shodan</p>
]]></description><pubDate>Thu, 07 Sep 2023 19:28:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=37424339</link><dc:creator>mmstr</dc:creator><comments>https://news.ycombinator.com/item?id=37424339</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37424339</guid></item><item><title><![CDATA[New comment by mmstr in "USENET rises again?"]]></title><description><![CDATA[
<p>If you want to read more about USENET through a criticism written while it was still used, I suggest to you the wonderfully anachronistic Unix Haters Handbook (<a href="https://web.mit.edu/~simsong/www/ugh.pdf" rel="nofollow noreferrer">https://web.mit.edu/~simsong/www/ugh.pdf</a>), it starts to talk about USENET at page 131</p>
]]></description><pubDate>Thu, 31 Aug 2023 15:06:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=37338336</link><dc:creator>mmstr</dc:creator><comments>https://news.ycombinator.com/item?id=37338336</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37338336</guid></item></channel></rss>