good lord. I pulled a microSD card out of a Raspi inside an IoT product and it appears they had some developer use a raspi to develop/test some software, and then they just yanked the SD card out of that machine and duped it on to all of their deployed products.

it's got .bash_history of the development process! there's git checkouts of private repos! WHY WOULD YOU DO THIS?

I've also been able to de-stealth a "stealth startup" on linked in.
because this has commits from different users, and I can just look up on linkedin what stealth-startup all those people work/worked at and then look at the name on the IoT box I'm holding

also, you punks are writing python 2 code in 2021? come on, who does that?

I mean, I do all the time, but I'm a known retrocomputerist. I run Windows 95 and MS-DOS regularly. of course I'm using a wildly outdated programming language. I'm not making a product I sell to customers!

oh cool you can pull the GPS history of a truck from azure without any login, you just need to know the device ID.
this might be UPS trucks. I should probably not query any of these GPS histories

also they're spamming 9 lines to syslog every minute.

this is a microsd card in a raspi, guys! you are going to fry your fucking card by running out of write cycles. That's not a good idea in any raspi application, especially not an IoT one

oh sweet jesus they logged into slack from this machine('s image)

I have their chrome profile, with history and cookies and shit!

@foone do you need an OVE?
@cadey a what?
@foone diet CVE
@cadey nah. I didn't get this device legitimately, so I can't really report any security holes in it.
@foone you could go anonymous through a disclosure intermediary like ZDI…
@aardvark They already posted publicly about it though... better to not have "someone else" suddenly report that right now. (But I hope that some people get tipped off by this, shouldn't be too hard to find what it is by the clues)
@the_moep elliptically tooting on Mastodon isn’t really disclosure to the vendor (no matter how entertaining).