news.volyx.in

The curious case of the Raspberry Pi in the network closet (2019) (blog.haschek.at)

799 points by BayAreaEscapee · 1705 days ago · 262 comments on HN

Article summary

A Raspberry Pi was found in a network closet, and after analysis, it was discovered to be a malicious device with a WiFi and Bluetooth connection. The device was found to be connected to a paid IoT service and had a nodejs app that collected data, but its exact purpose was unclear. The owner of the device was identified through a username and WiFi credentials, and it was found to be an ex-employee who had been given a key to the building. The incident was handled internally, and the ex-employee was told to leave without further action.

Main themes

  • Network Security
  • Malicious Devices
  • Incident Response
  • Gifted Programs
  • IoT Security
  • Corporate Security Measures

What commenters say

  • The handling of the incident was too lenient and may have allowed the perpetrator to continue malicious activities elsewhere.
  • The use of 802.1x certificate-based network security could have prevented the incident.
  • Gifted programs in schools can be beneficial but also have drawbacks, such as creating undue pressure on students.
  • The incident highlights the need for better network security measures, such as periodic security reviews and SIEM alerts.
  • The effectiveness of gifted programs in predicting future success is unclear.
  • Punishing the perpetrator may not be enough to prevent similar incidents in the future.
  • The incident was likely not an isolated event, and similar attacks may have occurred or will occur at other companies.