@corbet it's the confusion of who gets to decide what ownership means and what the business and service relationship requires that doesn't generate informed consent.
@corbet For a tech it's clear that if the app is talking to a hosted config manager that the vendor has remote admin access to your equipment, and may be presumed to be accountable for changes. It's also in both interests to disallow access to unknown third parties, but there is little incentive to identify the customer as a first party admin when the automation "just works" and most users would have difficulty with credential/key management, so this is skipped leading to this kind of hack
@corbet All I get from that link is a "Sorry, you have been blocked" page from Cloudflare; others on HN (https://news.ycombinator.com/item?id=40840367) have the same issue.
@corbet Nice read. Unfortunately the web server placed by the author allows unauthenticated execution of arbitrary code using path traversal. This is definitely something that should be appropriately firewalled.
@corbet There's a sticker going around which says "don't connect me to the Internet, no matter how hard I beg". I want to put it on most of my newer appliances.