Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The irony here is that your comment is a random HN comment from an account less than 10 days old :D

In reality, I think random answers on HN (or any answer/advice anywhere) shouldn't be trusted, but rather taken with a grain of salt and think about whether the answer really helps you.

>Touching the disks can expose you to the risk of being accused of tampering evidence

I don't understand this. What do you say touching the disks is? Like physical touch, or logging in and looking at the logs? I don't think both of those can be attributed to tampering of evidence, like criminal tampering since you use the word 'accused'

On a lighter note, do you always end your sentences with 'talk to a professional'?



> I don't understand this. What do you say touching the disks is? Like physical touch, or logging in and looking at the logs?

Is this sarcasm?

If not, hypothetical situation for you:

OP works at a company that processes card information of customers. A hacker demonstrated gaining unauthorized access to production servers. Hacker pulls a db dump as well as any keys used in encryption of data (some bad practices here, but this is common). Hacker does not tell OP of his additional actions, only demonstrates unauthorized SSH entry.

OP does the logically correct thing of wiping his db servers, and "cleaning" the machine, because, well, mitigation of future damage.

Hacker pissed he/she was not given reward for demonstrating his proof of vulnerability, uses this production data for ill will. A third party audit (which will happen) finds that OP has done a full wipe of the server - logs for who pulled vulnerable information is now unknown.

With no finger to point (the hacker contacted him "anonymously", remember) OP is then implicated.


>Is this sarcasm?

Yep. I was going for pointing out the fact that he obviously logged in so he 'touched' it and the OP is not so stupid as to wipe the whole drive when 90%~ of the comments of this post say no to. And I really doubt the 'logical' decision of anyone who manages to post to HN for advice will be to wipe the drive without getting a snapshot. And since it is a prod server, the same server has to be used unless they use AWS or some other cloud service.


Thanks for clarifying.

I believe the point the parent was getting at is that there could be other unintended consequences to taking relatively good advice.

Honestly, I'd even argue there is some better advice on server fault/HN than some professionals - but the difference is getting the professional has a paper trail that you can't say "well, some DBA on server fault told me!"


> The irony here is that your comment is a random HN comment from an account less than 10 days old :D

10 days old and a throwaway. No irony here: I'm recommending the reader not to trust random HN comments including my own.


> What do you say touching the disks is? Like physical touch, or logging in and looking at the logs?

There is a reason why foresics data capture devices are so expensive and certified never to touch a bit.

> I don't think both of those can be attributed to tampering of evidence, like criminal tampering since you use the word 'accused'

There has been various cases of people accused of destruction of evidence for wiping (allegedly) compromised hosts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: