Tumgik
#update: all of my questions have been answered I now ship them :DD
violinist-rachel · 7 months
Text
Tumblr media Tumblr media Tumblr media
Pick me up!
199 notes · View notes
rainbowsky · 3 years
Note
Hello! Fellow not-so-new turtle here. I have a question that may sound dumb but still I have to get it out of my head.
It's about x/z studio statement about x/z and w/z/c rumor (about them dating). I've read the translation of the statement and there's something that caught my eyes.
"There are others who are spreading rumors on staff's identities, making up false stories on relationships between Mr. X/Z and his friends." The statement didn't specifically state about who's this x/z's friend is. I know that it was updated after the rumor, but I still have another mind that think 'maybe it was for both rumor of w/z/c and bjyx (hitting two birds with one stone, maybe)'.
Since everyone is saying that x/z refuted the rumor betwen him and w/z/c and leaving bjyx alone, I wonder if they came to that conclusion only because the statement was updated after the rumor or did x/z or x/z studio personally took down the cp supertopic (if there was the supertopic in the first place). I would really appreciate your opinion or answer on this.
Sorry that it got kind of long and if there's any mistake in my English (it's not my first language). Thanks beforehand..
Fake, fan fiction, CPN.
I could answer your question simply and quickly by saying that if the statement applied to both DD and WZC, why was the WZC CP topic taken down and the one with DD left up? But brevity has never been my strong point, and this is a subject I’ve been thinking about a lot for my ‘what makes you believe BJYXSZD’ post (still in my drafts, not done yet sorry guys).
I double-checked the translation of the statement (thanks @peekbackstage for help with that), and the line pertaining to relationships/shipping is as follows:
“There are fans who constantly appear at the hotel stopping his way, some others are spreading rumors on the identity of staff, making up unreasonable speculation about Mr. XZ and his friends relationship in the entertainment circle."
The full statement:
Tumblr media
By its very nature, the statement would include DD, as DD is ‘a friend in the entertainment circle.’
At the time GG was being shipped with multiple ‘friends from the entertainment circle’ including WZC, XL, LQ, WYB, and others. It all seems to have been tolerated until GG’s birthday on 5 October, 2019, when he celebrated with his Lotus Pier siblings.
Tumblr media
Shortly after that, the WZC/XZ CP supertopic started blowing up and causing controversy among fans, and it was then that
The statement was issued
The supertopic was shut down
Now, we have no proof that the supertopic was shut down because of this, or that the statement was in reference to the supertopic, but I think it’s a pretty reasonable assumption given the circumstances and sequence of events. He’s getting heavily shipped with WZC and the supertopic starts getting traction and fan wars raging, and then suddenly it’s taken down and a statement is issued.
Meanwhile, there are 3 huge CP supertopics shipping GG with DD, and they persist to this day - the biggest one is nearly 3 million strong.
Now, some people might say that the BXG supertopics are ‘safe’ to leave up because GG and DD have appeared in a TV series together as a romantic pairing whereas WZC was cast as a sibling and any shipping with GG is riskier to GG - and there might be some truth to that. But the show officially wasn’t a romance, it was a bromance, and there are other notable factors at play here:
The Untamed has long since finished airing and there is no longer any marketing purpose for continuing to allow the CP to persist.
GG’s scandal last year began via solos reporting a fictional story involving GG and DD in a sexual/romantic relationship. That is the spark that nearly destroyed GG’s entire career.
Untamed BTS continue to be leaked and continue to fuel the rumors about a relationship between them. Some of the BTS have trended on C social media.
There are serious fan wars and slanderous rumors between GG and DD’s solo fans and CP fans, which have caused a lot of disruption. Some of the rumors have actually led to legal action.
They are both promoting multiple dramas, either upcoming or currently airing, which involve romantic pairings with women.
Even though the size of the CP fandom is in the millions, CP fans make up only a small fraction of the fan bases for GG and DD, and an even tinier fraction of their potential fan bases.
Yet the supertopics are still up there and are growing rapidly.
AFAIAC, there is simply no other rational explanation for why the GGDD-related CP supertopics have not been taken down by their studios or agencies, except that they don’t want them taken down, and that heavily implies a real relationship.
The supertopics/CP represent fans that support a relationship.
The supertopics/CP provide cover for such a relationship, if it exists.
Edit: More on that here and here.
82 notes · View notes
libermachinae · 3 years
Text
Fault Lines Under the Living Room
Part II: Breathe - Chapter 6: Just Another One
Also available on AO3! Chapter Summary: Ratchet and Rodimus embark. Word Count: 5096
---
They could have left the last stage of planetbreak to autopilot, but Ratchet kept his hands wrapped around the yoke. If there was damage the shuttle’s sensors had missed, he said, better to have someone sentient piloting. Rodimus nodded along with his logic, like he hadn’t been aware the moment Ratchet decided he would do everything in his power to distract himself from… all this.
Rodimus had little room to feel offended. He was trying to dd the same, exploring the shuttle’s interface while background threads worked through anything he might have forgotten in their haste to leave. He hadn’t gotten around to telling the engineers about the ominous blinking panel in engine room 3, and he’d neglected to pick a replacement judge for the upcoming karaoke contest. His consciousness slipped between these background thoughts and exploration and Ratchet’s piloting, both of them trying so hard not to acknowledge the other than they jumped when the alarm went off.
“Frag.”
Rodimus grabbed for controls that failed to materialize in front of him.
“What?” he demanded, looking to the monitors for an incoming projectile despite the answer pooling in his mind.
“Haven’t reached exit velocity,” Ratchet said, punching commands into the console with one hand firm on the yoke. “Forgot how much power it takes to get these old war rigs moving. I’m adjusting the flightpath to buy us time to build momentum.” The alarm stopped. “There.”
Ratchet’s words were echoes of his thoughts, old knowledge by the time they reached Rodimus’ audials. Ratchet didn’t know how to fix that problem. Rodimus hadn’t realized it was a problem. Conversations between them were already a challenge, to add this new dimension was—
They were thinking about each other’s thoughts again. Rodimus rapidly shifted between menu options until the flashing light dragged him back out of his head.
“This sucks,” he said.
Ratchet grunted. He couldn’t keep up with all of Rodimus’ thoughts at once, and even hanging onto one was a strain, so he was trying to create hard divides between them. Right now, he was generating a list of all the medical supplies one could expect to find on a ship this size, basing it on a combination of Autobot guidelines and the kinds of repairs he had seen on POWs. Rodimus’ processor tried to latch on, but the thick jargon kept him slipping off, back to exploring the workings of their new home.
No, was home not the right word? The place they were living? Where they were captive? Their cosmic questing raft? The Decepticraft? The Drifter?
Ratchet withdrew the tracker from his subspace, ignoring the way plinking ideas sunk into his thoughts like lead nuggets into molten cadmium. Autobot and Decepticon tech was not designed to be compatible, but he had performed enough surgeries with parts scavenged from the battlefield to know how to jury rig the connection. As he pulled out a small utility knife, he thought sadly of the universal adapter he had stashed with the rest of his medical supplies, all of it now sailing away to parts unknown. Though he would knock a dent into Arcee if they ever caught up to her, he did hope his kit was getting put to use.
Rodimus wondered how long Ratchet had been preparing for his trip, when the planning had started (at the vote? Overlord?), how he could have missed it. Ratchet recoiled from the blunt curiosity and his list fell apart, dumped out of short term memory as his processor scrambled to pull up the answers to Rodimus’ questions.
Mistake, mistake, mistake.
“Just—stop,” Ratchet said, waving at Rodimus like he could dispel the corrosive thoughts with a gesture.
How do I stop? Does it hurt? You’re so quiet? Are you okay? Does it hurt? What do I do? Rodimus had never had reason to stop his processor before, and the effort of trying to now was making it worse.
Ratchet, though, had a lifetime’s experience forcing himself to focus in stressful situations. He stopped responding to Rodimus’ questions, and the thoughts that did come through were focused entirely on his hands as he stripped down the tracker’s cable. Once a physical connection had been established, he would need to register the tracker as a pilot in the navicomp, then reroute the transceivers in the shuttle’s communications array to increase their range.
His calm confidence guided Rodimus’ focus. The stream of questions would not abate, but they were no longer provoked from panic, nor did they interrupt Ratchet’s process.
Will it accept an Autobot ident?
Some even turned out to be helpful.
“Probably not,” Ratchet said, their connection helping Rodimus pinpoint which of his thoughts Ratchet was responding to. “Not a problem, I can just program a new one… dammit.”
The computer flashed red: outdated codes.
“Who was stationed on this ship they would bother updating their security?” Ratchet wondered aloud, his processor trying to piece together a workaround simpler than taking apart the entire navigation system.
Rodimus hesitated, but Ratchet caught it, so there was no point to staying quiet.
“Prowl passed me some intel before we left,” he said.
“Hm.” Ratchet’s thoughts turned sharp, a phantom pain that caused Rodimus to wince.
“Codes,” he said. “Just in case.”
He hadn’t asked where Prowl had gotten them, though Ratchet’s imagination filled in the gaps. Instead, Rodimus had been doing his best to appear professional and capable before Optimus’ infamous adviser. Prowl’s optics could not bother to emote for how unimpressed he was. That Rodimus had assumed this meeting concerning “galactic relations” would be about culture clash with their closest neighbors had not helped his image.
He had nearly run out of the office when Ultra Magnus commed to say he was actually late for another meeting, stopped only by the datapad forced his way.
“A few precautions,” Prowl had called it. Rodimus downloaded the files and stored them among the events on Kimia, tech specs for the waste disposal system, and other things he could willingly not think about.
Ratchet’s hand, poised over the keyboard, clenched and shook itself out.
“I hope you ran a virus scan on that thing before you plugged it into yourself,” he said, doing a commendable job not bringing up everything this subject of conversation was making him think about.
“No, but I passed it through my antivirals.” And it didn’t feel like Prowl was remote controlling him from the opposite side of the galaxy. He doubted Prowl had the processing capacity to pilot him through multiple rounds of volcanic derby racing, for one.
“Here.” Ratchet retrieved his portable med kit from his subspace and set it on his lap. The lists were moving back in: everything he’d lost versus what he had to work with now. Rodimus found himself sobered and accepted the antiviral chip when it was passed to him. “Load this and run another scan. You might experience a few seconds lag or disorientation; just ride it out and let the chip do its job.” A few very rare cases experienced sensory inversion, but longterm effects were uncommon enough Ratchet wouldn’t bother to mention them.
Rodimus cracked a grin as he popped open a port cover and inserted the chip. He grimaced as he installed the program—invasive medical programs were rarely comfortable to integrate—then ran Prowl’s files through it.
So, there had been a tracking signal that Rodimus’ programs had failed to uncover, but once that had been snipped out the rest were deemed safe. Rodimus tightbeamed the data to Ratchet who used it to finish building their fake Decepticon and finally got through. ‘Galeforce’ finished integrating the tracker and set the system to start searching for Drift’s signal.
“Thanks,” Ratchet said, a longer pause than normal between thinking the word and saying it out loud. Internal distractions compounded and inevitably led them to crashing into each other, so maybe talking would redirect enough of their attention to stop the spiraling before it could start.
Rodimus chanced a glance at him but could not catch his optic; he was still focused on the controls.
“No problem,” he said. Drift had once wasted a full off-shift failing to teach him how to meditate. The problem had not been Drift’s teaching: it was all Rodimus and his inability to let a thought go once it manifested. It was like they stuck him, coils of barbed wire wrapped round and around, each pinprick demanding his attention and—”How far is it to the outer rim?”
“Depends where we’re going, and if Drift’s on the move,” Ratchet said. The screen of the navicomp blinked, a pinwheel replacing the previous screen. “Might find somewhere to get comfortable. This part’s been known to go for a few hours.”
“Hours?” Rodimus repeated. Anything that could have once been considered comfortable was covered in junk. The captain’s chair had belonged to Ratchet before they had taken off, and the flight deck chairs were too abandoned to feel secure.
“The transceiver on Drift’s speeder isn’t strong enough to send a direct signal,” Ratchet said. “It’s going to have to bounce between Galactic Council transmission planets a bit before it makes it back here.” Assuming Drift had strayed close enough for one to grab his signal. From what Ratchet understood, though, they were almost impossible to avoid these days. “Whatever we get’s going to be a few days old, but it’s a start.”
Rodimus’ processor drew up a cartoonish map, a dotted line zigzagging between planets to show the path Drift’s signal would take. He recoiled from under Ratchet’s scrutiny, but all his haste could add was a backdrop of randomized stars.
“While we’re waiting, I’ve got us on course to slingshot around Scarvix’s star,” Ratchet went on. A note of surprise: Rodimus’ stress had caused his own cables to tense. “By the time the tracker gets us some coordinates, we should be ready to… This isn’t helping.”
Rodimus was distressed and Ratchet was spiraling. How were they going to make it all the way to the outer rim? What would they do if Drift had nothing for them? Refused to help? Rodimus couldn’t keep tying himself in knots, nor could he endure the sting every time Ratchet anguished over a possible future trapped together.
“I distract myself.” Rodimus forced his voice through the fog.
“How?” Ratchet was gripping the edge of the captain’s seat, squeezing until the hard edge reminded him which body was his.
“A lot of things work: racing, fight,” Rodimus said. “Anything that could get me out of my head for a few minutes.”
Meteor surfing, free all skydiving, asteroid spelunking. Any activity that teased the edge of mortality (crafting a spectacle was a bonus) was fair game. The rush of knowing he was solely responsible for the continued light of his spark never failed to wipe his mind of the stress of everything else.
Ratchet could not relate. Nor could he imagine how they were going to fit a racetrack into a ship just a bit larger than Swerve’s. Sparring might have been an option, were it not for the fact that every step risked tripping and landing face first on something volatile.
The idea hit Rodimus and he groaned.
“What about—cleaning?” Ratchet gestured around them. “I don’t want to put up with this chaos for longer than I have to.”
And there was something nostalgic about it. After the destruction of his Rodion clinic, Ratchet started practicing performative minimalism; anything of purely sentimental value had to be kept on his person, out of harm’s way. Prior to that, his offices had been littered with evidence of a life lived mostly within their walls: chickenscratch notes immediately forgotten, used energon cubes, and fond mementos from old friends he would get around to calling one of these days, for sure. Over days and weeks it would pile up, until he was using his lap as a desk and had no choice but to sweep it all back into a configuration resembling tidiness.
Rodimus balked at Ratchet’s fondness of those memories. Cleaning for him was performed on hands and knees, tips of steel wool sticking into his finish as he worked rust out of wash rack corners. Back and forth over the same spot, over and over and over, until boredom pressed down like it intended him to become one with the floor.
“Punishment detail,” he said, though Ratchet had already guessed.
During the war he had bounced between barracks and military vessels, plugging into recharge docks still warm from their last occupant. How could he ever take pride over a cleaned room when neither the space nor the mess belonged to him? He had tried to improve his habits upon moving into the Lost Light, but there were reasons Ultra Magnus refused to meet him at his hab suite.
“It’s not just about the space,” Ratchet said. “It’s an emotional reset. When you have time to clean, it means the fighting’s over for now.” Ratchet’s memories had lost hold of entire days stationed in field hospitals, brought back only as he had wiped down his instruments and organized his remaining supplies. Rubbing cleanser deep into his joints to free them of the day’s residue was one small kindness he could afford himself.
Rodimus shrugged and twisted in the seat so he could rest his chin on the back of it. He scanned the room. It certainly looked like a fight had gone through.
“Right.” Ratchet did one better than him and stood up. “You’ve got decent knees, so you can start by hauling those shelves back into place.”
“Decent knees?” Rodimus repeated, allowing himself to crack a grin. He shoved himself from the chair and wandered out into the swamp, tripping once as he felt something snap under his heel. “Old joint all worn out, doc?”
“Just got them replaced,” Ratchet corrected, “and I’d rather not break them in on a mess that wasn’t even my fault.” First Aid would let him have it, and he was already due for a tongue lashing whenever they got back to the Lost Light. “This can be your penance.”
“Penance.” Rodimus laughed through the word, though he was already maneuvering around the shelves in question, trying to guess which end would be easiest to lift from given the state of the floor around them. “Right, because I’m the one who put you on this ship in the first place.” Neither would have been out here if Ratchet had just asked to go get Drift.
Nor if Rodimus had gone first—not sent him away—prevented Overlord—
“Here,” Ratchet said, clearing some of the space Rodimus had been tiptoeing around. “Let’s start with this.”
They started together, Ratchet picking through whatever was in Rodimus’ way as he heaved the shelves upright, but their tasks caused them to drift apart, Ratchet sorting through his findings while Rodimus shoved the room back into a semblance of order. He drifted into a rhythm of lifting and pushing, occasionally grunting with the effort of returning the room to its previous state. This plan was derailed almost immediately: he’d had other things on his mind when he first rushed onto the bridge, and the placement of the various shelves and crates had missed his attention entirely. Even Ratchet’s memory of the layout was imperfect.
So, he got creative with it, using the shelves to form a divider between the cockpit and what would have been the command zone. He used the crates to fill in the gaps and form uneven benches along the walls, and as he took to shoving the broken pieces and miscellaneous ends into piles, the bridge started to take the shape of a living space. Ratchet, glancing up from his work only to remind Rodimus not to lift with his back, had no complaints about the design choices.
He spoke up again when Rodimus paused before one of the larger crates, considering it carefully.
“It’s not a bad idea,” he said, “but I doubt you’re the first to have it. Why would the Cons waste space with chairs when they’re already tripping over storage cubes?”
“You can’t relax sitting on a block,” Rodimus said, although, he reflected, that was likely the point.
In the end, he settled for placing a couple smaller cubes on either side of the makeshift table, almost adding a third before he thought better of it and slotted it into a space on the wall, finally covering up the loosened panel from which red light continued to trickle. His cables relaxed and he became aware that he had been hearing a buzz (a melody?) in the back of his processor ever since the flare. The silence that swept in to fill the space was just as loud, but slightly less grating.
His optics swept the room; still chaotic, according to Ratchet, but Rodimus thought it was gaining a shape. Noticing that he had accidentally blocked the door at the back of the bridge, he went to clear it, and was surprised when it didn’t open automatically for him, nor did he see a control pad.
“Ident sensor,” Ratchet said. He had noticed it built into the upper frame of the door.
“What, more secret tech stashed back there?” Rodimus asked. Both their minds bloomed with possibilities, but Ratchet shut them down.
“Recharge docks, more likely,” he said. “We had similar systems on some of the larger warships. Kept bots to their assigned off-shifts.” On one occasion, a superior officer had tried to use the same tactic to lock Ratchet out of his medbay when he was supposed to be recharging. After the public fallout settled, no one else dared to try it. “I can rig up our transceivers with a couple more facsimiles, soon as I’m finished here.”
Rodimus grinned and waved up at the sensor. He thought he could feel a brush of radiation as it scanned him, but Ratchet rebuffed the notion; it wasn’t nearly that powerful.
If that was true, what was to stop the Decepticons from lacing their ships with invisible observation devices? What if it had already discovered the intruders and was sending alerts straight to the DJD who were—
Fifteen pounds titanium alloys, ten pounds compressed carbon, eighty pounds halogen…
Ratchet’s thoughts were calm, regular, and purposeful enough for Rodimus to latch on. He glanced around again. He could start clearing the stairs. Or sweeping up glass. He could create a designated pile of useful equipment, or check that all the navigation terminals were in working order, or perform a quick security sweep. So many options. So many ways to prove that he was taking this seriously and was ready to work to stay out of Ratchet’s way.
“Come here, Rodimus.”
Of course, thinking about his options accomplished none of them. Aware he would continue wasting time if left to his own devices, he complied, plopping down in front of Ratchet. He landed in a relaxed sprawl, his position calculated down to the bend of his fingers.
Ratchet glanced up to him, thoughts of energon stock briefly set aside.
“Maybe you should’ve paid more attention to those meditation lessons,” he said.
“Told you, it didn’t work.” Never mind that he hadn’t said that part out loud; it was the defining feature of that memory. Drift had tried so hard, patiently explaining each step and troubleshooting when Rodimus struggled. They had tried different techniques, positions, even locations, and at every one, Rodimus’ thoughts had caught up to him and refused to be ignored. And every time, Drift had nodded with gentle understanding and suggested something new to try.
Because that was who Drift was: patient, calm, nonjudgmental. A forged mentor.
Ratchet’s thoughts hit him like acid rain.
“Did you know your ‘best friend’ at all?”
Of course he did, he wanted to say. All the important bits! Like that he was more regimented than Magnus when it came to his refueling schedule: one cube at the start of duty shift, and one at off-shift, every single cycle. That with his years brought experience untold, solutions and advice always at the ready. That Drift had been, and still was, extremely dangerous.
But when he dove inward to find these answers, he discovered something else: another Drift, sharp, with tattered, ill-defined edges that nonetheless drew and intimidating silhouette. This Drift was cloaked not in radiant light, but wrapped himself in darkness like a shawl, and when he tried to speak it was in many voices, none of which Rodimus recognized.
“Real friends don’t worship the ground you walk on,” Ratchet was saying. “I know your perception’s skewed since you think you have to live up to the very scratches in Optimus’ finish, but that behavior’s not healthy and it’s not normal. Drift is a real person, not some sort of—of fantasy fulfillment for you to drain until your hero complex is satisfied.”
Impatient, masking over constant stress, deeply critical of everyone but wrestling with his own failings: the other Drift’s hand appeared not with a sword, but a gun.
“I’m sorry.”
And vanished.
Ratchet released his death grip on an energon cube and set it aside.
“Not me you need to apologize to.”
“I know,” Rodimus said. “But you’re here, and it means something to you.”
“It doesn’t.” Ratchet’s lie was scratchy, like a frayed wire. “Drift’s made plenty of bad decisions in his life.” You’re just another one.
That’s not any of your business.
Habit kept them civil on the outside, but nothing, least of all self control, could stop them from thinking their truths. Drift had taken his post-war freedom and handed it straight to Rodimus, his dripping optimism like a fresh protoform faith. He had taken every dirty, demeaning job the Lost Light required of him, because he was good at them, because he wanted to help, because it was the only thing he knew how to do, because Rodimus had asked. Rodimus had taken advantage of, given an opportunity to, betrayed, saved, sacrificed—trying his best and couldn’t help that—
“Cleaning,” Ratchet said. “Cleaning.”
It took Rodimus a second just to find his body, then remember the piles of cubes stacked between them.
“What?” he asked. Even with a mental warning, he startled at the cleaning rag that landed on him.
“Some of the cubes were damaged in the crash, but it’s impossible to tell which when they’re piled together like this,” Ratchet said. He picked one from the pile and nested it in his own rag, diligently wiping away the loose energon before he unwrapped it and held it to the light. “Clean ‘em and check for damage. Get a leaker, pour it into the can with the rest. We can feed them to the ship’s reserve cells.”
The flight time bought by even a full crate’s worth of cubes would be negligible, but that wasn’t the point. Rodimus took a cube off the top of the nearest pile, feeling along the buckled edges. Were it just his own head to deal with, it might have been enough, but Ratchet’s still burning fury would not be so easily shut off.
“He volunteered,” Rodimus said.
Had he? Ratchet hadn’t known that. Rather than calm him, though, the new information made the fire in his spark burn hotter.
“I’m not having this conversation,” he said.
The cube hit the floor with an unsatisfying thud and Rodimus stood up.
“Whatever.” He had a taste of grim satisfaction watching Ratchet freeze.
“Don’t—” Ratchet started, but Rodimus cut him off.
“I get it,” he said. “You hate me. I’m used to it. I get people hating me for who I am way before they find out all the slagged choices I’ve made. But when you’re—you—”
Ratchet was treating Drift like a drone, unable to make any choice beyond its core programming, and Rodimus the cruel engineer who delighted in watching it shock itself. Rodimus could take lashing Ratchet delivered, but objectifying Drift and calling it righteous was a step too far.
“Except that’s not what I’m saying,” Ratchet said. His voice was steady and he stayed seated; he did not try to chase Rodimus. “Of course Drift is self-sufficient. I’ve never doubted that. And I believe you that he volunteered, because it’s the exact kind of glitched plan he would come up with. But the world is bigger than you, Rodimus.”
He knew—
Drift pledging life and spark to a leader whose words struck a thousand furnaces. Cast through self-revolutions of building and breaking himself, each new face patterned after what the last one lacked. Fighting his way up an eroding cliff face of rejection, reaching out…
“It’s more than you,” Ratchet said. “Drift might have volunteered. But I’ve got to check your conductors for rust if you think he wanted to go.”
“I know, but…” If Drift wanted salvation, who was Rodimus to deny him?
“His friend, allegedly.” Though Ratchet seethed with the word, there was a hidden gentleness behind it. Drift needed friends.
Rodimus had never considered that. He knew Drift was not well liked among some Autobots, a target of suspicion if not outright hostility, but Rodimus had always seen him rise above it. Strong and steadfast and as confident in himself as he was, isolation seemed no weight on his struts.
“He’s just a bot like any other,” Ratchet said. Well. Not any other. Neither knew anyone quite like Drift. “He gets slagged ideas, too, and as you’re friend, you’re supposed to tell him that.”
Ratchet had never hesitated to tell Optimus when he was being an idiot. Not much good it had done them all in the end, but memories of yelling at the Prime while elbow-deep in his wiring helped break the tension that had crystallized between them.
“I messed up,” Rodimus said quietly.
Ratchet gestured to the floor on the other side of the cube pile.
“You did,” he said, shaking his head at Rodimus’ ripe disappointment. “What do you want me to do? Say you tried your best and forgive you? You’re right, Rodimus. Whatever your reasons for not acting sooner, Drift’s the one who has to deal with your consequences.”
“I’m scared,” Rodimus admitted as he took a seat again. He picked up the cube he had been checking before and looked it over: no leaks. He put it in the intact pile and retrieved the next. “I liked what we had before, and I’m scared Drift’s going to hate me now that his big sacrifice turned out to be for nothing.”
“What you had before wasn’t sustainable,” Ratchet said. He had moved back into his own rhythm, optics on his hands while he spoke to Rodimus. “Want to talk about objectifying? You treated Drift like a personal worshiper.”
Rodimus ducked his helm. It sucked to feel Ratchet’s scrutiny even without those fierce optics on him, but he knew it was deserved. It had just been so nice to feel appreciated for once. To have someone tell him, without disclaimer or exception, that he was good at something and could help people. Everyone else was always searching for his flaw; Drift had been the first to explore Rodimus with the intention to find his virtues. It was the praise Rodimus missed most, second only to the camaraderie, and even while acknowledging it was for the best, it still stung to know he couldn’t have that back.
Ratchet set down a cube and did not immediately reach for another one.
“I can’t make any guarantees about what Drift will do, but I think you would actually find friendship without aftkissing to be more rewarding,” he said.
But I liked that, Rodimus thought, to his horror. Ratchet rolled his optics.
I’m sure you did.
“Of course,” he said out loud. “And you never doubted it? Never once thought, ‘Hey, this level of devotion from a bot I haven’t shared three words with is a little weird’?”
No. But a few moments slipped in from Rodimus’ memories. When Drift told him about his affiliation ceremony, there were embers of a once blazing inferno glowing behind his optics, a side of the ex-Decepticon that Rodimus told himself was but a lingering echo. Drift had given up that kind of passion on his road to atonement. At least, Rodimus had convinced himself as much.
“He told you exactly what you wanted to hear, knowing you would fill in the gaps,” Ratchet said. “He is a survivalist.” And to have survived so much, only to once more find himself without a home or support was a mockery of justice and everything Ratchet had believed the Autobots stood for.
That was why he needed to leave.
“And you’re getting your new chance because of it,” he said. “You didn’t earn it, but you’re getting one anyway. And if you really meant that apology, you’ll do something different this time.”
Rodimus knew that, could internalize the idea, but when so much of what he did felt like an externally sourced script running of its own volition, he struggled to make it a guarantee. He could intend, with every fiber of every cable, to do better the second time around. But so often the pressure of potential disappointment became its own self-fulfilling prophecy.
“Well, so long as we’re stuck together, you won’t be alone,” Ratchet said. “I’ll be there. I won’t let you do that to him.”
“Okay,” Rodimus said. He had heard promises like that before, from bot who promised to support him only to turn tailpipe once they learned what that meant.
But now he could feel Ratchet’s resolve. Not to Rodimus, to whom his emotions were turbulent and untrustworthy, but to Drift and giving him what life would otherwise conspire to keep away. He thought Drift a fool for the role he had assigned himself at Rodimus’ side, but he would not deny him his agency if that was something he wanted to regain.
The navicomp beeped. They stood simultaneously and Ratchet moved back to the captain’s chair to inspect the screen.
“We’ve got a hit,” he said. “Vitreous.” An organic planet, according to the report. Neither of their databanks could produce any further information.
“A week?” Rodimus’ voice was tight as Ratchet scanned the details.
“Give or take,” he said. “If we need to refuel, that will add a couple days.”
“Sure.” Rodimus was trying very hard not to think about what a week of this would be like.
Ratchet was doing it enough for both of them.
4 notes · View notes
history-rover · 6 years
Text
Fic Writers Week (Day One): Words of Validation
Day 1: Words Of Validation - Fic Readers, take some time to leave new comments / Fic Writers, share some of the comments that stuck with you the most.
First and foremost, every single comment that has ever been left behind on any one of my fics means a great deal to me, and I can’t even describe how happy they all make me! Seriously, you all make my day! I’d like to put every single one of them into this post, but I don’t want to clog up peoples’ dashes, so even if you don’t see your comment here, just know that it is in this post in spirit.
One Available Copy
aaaaaaAAAAAAAA this is amazing??? i love this so so much asdfghjkl. Your characterization was on point and I literally laughed out loud a bunch of times. Thank you so much for sharing with us!! 
This was so lovely, sweet, funny and i can't really cope right now :D Your characterisation was spot on and this au in general was so good! And the thought of Kirishima and Bakugou sharing their assigned reading is doing funny things to my heart! 
This is so so so so cute!! I just love the progression of their relationship from emailed library notifications to post its to face to face talking and texts.... it's just so so adorable. Plus the idea itself is genius! And I've never seen a college AY that talks about library stuff like this and it's just a really cool concept and a really good idea...!Also, all the tiny details you wove into this really made it as good as it was: the inclusion of so many characters, Tsuyu's livestreams, Endeavor and Monoma's humiliation, the humour, the tododeku making out between the shelves and literally not giving a single fuck.... everything was funny and cute and the ENDING!! The ending was super well executed and wonderful and cute and I absolutely loved it. All of it. Thank you so much for writing this because it's seriously hecking amazing <3 Oh my gosh this is my favorite college AU fic! I really love everything about it. Your characterization of Bakugou especially was on point, very good, A+ LOVED IT 
Oh my goodness this was so freaking cute? Bakugou's attempts at flirting going right over kirishima's head is so in line with these two boys I'm yellinggggg thank u sm for writing this fic!!! u really made their college feel like a real living breathing place especially with the addition of all the meme pages!! 
I wrote One Available Copy (OAC) with the goal of making people laugh and smile, and to hear that I had done that made more happy than I could have imagined! I’m always second-guessing myself on characterisation as well, so these comments meant a lot to me, and I can’t thank people enough for them! Also, to hear that I had made the world feel alive and real...thank you all so much!
Wedlock
WHAT. A. FIRST. CHAPTER!!!
I am so excited for this AU omg?? I love that they're in an established relationship already and omg the playfulness? Flirting?? YES, MY BOYS, GO OFF AND START A SCANDAL. I AM ROOTING FOR YOU!
And magic!! Oh my gosh I love the incorporation of magic in this era and the fighting--the fighting. It's amazing. Intense. I love it.
Thank you as well for the superb attention to detail. I can tell a lot of research went into representing the era accurately and it makes your world all the more vivid and fascinating! (the sweets, i am remembering the sweets hahahaha)
I'm definitely looking forward to more of this AU! Great job!!!
Special shoutout first of all to @todorokishouts for this giant comment, after having to deal with my sobbing of research woes for this fic, and cheering me on through it, and consistently being the first person to comment on every new update along with @dystopiansushi! And yes, never forget #sweetgate2k17
I really loved how many cool elements of the time you included, it shows such an amazing deal of research!
Holy shit I'm loving this fic already!! Their established relationship is so playful and sweet, I'm really looking forward to seeing what comes next in their schemes!Also, your attention to detail in the setting while still managing to seamlessly infuse magical elements is really impressive! You've got me wanting to learn more about this world :DI hope to see more soon!! Thank you so much for this great fic :DD
Wow this is great so far! :D. I thinks it's really cool how much research you've done too, the accuracy of everything is awesome :0. Can't wait for the next chapter
I already love this and I can't wait to read more! I love how much research and knowledge you put into this au because it just shows how much you care about writing and the characters. A truly incredible first chapter with all the romance, humour and action any good story has. I loved it!
Did I mention that Wedlock is the most research-intensive fic that I’ve ever done? I swear I did the same amount of research (and still am doing research) for this story, as I did for my thesis, and to know that it wasn’t for nothing, and that people appreciated it, made me weep with joy. 
So this is fantastic. Like, excellent start. Established Tododeku? Awesome magical period romance? Actual Magic Frog Tsuyu? Appearances from numerous lovable minor characters? You are on a roll, my good sir. So I've noticed this trend in most fantasy and royalty AUs that feature Tododeku, and that is the trend of Commoner/Servant!Izuku being shipped with Royalty!Shouto. In light of that, can i just say that it is SO refreshing to see a story where they don't have to get around a weird societal imbalance of power in order to properly fall in love? It's beautiful and wonderfully uncomplicated, while still having the court politics that make stories like these so delightfully intriguing.But yeah, you've started really strong and I went back through your stuff to realize that I also read and loved your college AU, so needless to say, I'm super excited for this fic! Izuku and Shouto's dynamic is so wonderful in this, and I can't wait to see where it goes!
THIS IS BEAUTIFUL OML THIS IS ONLY CHAPTER 1 AND I CAN'T STOP SCREAMING ALREADY!!! THIS IS SO REFRESHING IN SO MANY WAYS LIKE: TODODEKU (all of it) FANTASY AU (it is always refreshing in a way) DAD MIGHT (ADOPTED IZUKU) CLASS 1-A & EVERYONES COMMENTS (they are easily the best) URARAKA AND TSU FIGHTS!!!AND LAST BUT NOT LEAST: THE WAY YOU WRITE EVERYTHING FROM THE CHARACTERS TO THE ENVIRONMENT IS BEAUTIFUL. I'M HYPED!!!
PitViperofDoom messaged me yesterday with a link and one word- "READ"And boy howdy am I glad I did! This was fantastic! I love the historical aspect of it mixed with magic and quirks and the romance was just. So good. I died with the cord thing very nice 11/10, perfection! I think you really stayed true to characters while giving them interesting influence from the setting and your writing skills are just amazing. I could really see every moment playing out. And the plot! Scheming boys and scandals, oh my! Great job. I can't wait to read more!
These three comment made me collectively die of happiness on the spot, to the point where my mother actually ran into my room asking me what I was screaming about. I think that pretty much sums up why these comment stood out to me.
Path of the Wind
I love this. I'm so happy I got to be the first to read through it; I love the premise, I love your Izuku, I love your Inko and your cryptid All Might, I think the whole thing is a fantastic and original idea and I absolutely can't wait to see how you continue it <3
None of this would have been possible without my beta reader @dystopiansushi, so thank you so much!
All aboard the hype train - whoop whoop! I'm an absolute sucker for fantasy/mystery/supernatural-esque AU content, with a side serving of Tododeku, so here I am! I'm excited to see how this plays out!
I’ve never written anything in the realm of the supernatural/fantast type before PotW, so to hear this was a big boost in confidence for me!
Whoah, I love your attention to detail here. The potholes especially caught my attention. It's something people think about, but most wouldn't think to describe distance like that. I'm excited for this!
I’ve always been a sucker for big detailed scenes, and I was so happy to find out that people enjoyed them as well, and that they didn’t take away from the story like I had been worried about.
Todo sure left an impression, poor boy Also I'm SO ON for how supportative and cute momma Inko is? Fuck, I love everything about your writring and I don't know how to describe what I like more and susbsusbsjs You're amazing
holy shit i cannot get enough of this story. it’s so well written, and extremely intriguing.i love how amazing the characters are?? just their mannerisms, midoriya’s mumbling, kirishima’s touchiness, and todoroki’s bluntness are so on-spot. also your Iida is perfect i love him!!im hardcore relating to midoriya right now, just itching to know the town’s secrets haha (as well as todoroki’s cause damn that kid is mysterious)
This is such a good update! You have such a soft way to write, I like it so, so much 
*crying emoji* thank you so much for complimenting my writing, and my writing style, and for validating me!
My Neighbour Totoro? I think you mean My Neighbour Todoroki (I'll walk myself out). Hums loudly at the mention of glinting eyes watching Midoriya enter Yuuei Academy. Who could that have been? All Might isn't really size appropriate to be slinking around there after all. And just what is Todoroki up to? Midoriya has a lot of interesting questions, thats for sure. I hope he gets the answers to all of them, because they're making me wonder too. Having the Todoroki's as the fire department will certainly link Shouto to finding the necessary evidence Midoriya's searching for in regards to the old Yuuei fires where All might was spotted, and I bet Endeavour has a huge role to play in that too. I wouldn't be surprised if the fire was instigated in an attempt to successfully lure All might out, although I may be stretching the theory bar a little on that one. I just hope Endeavour hasn't forced Todoroki the impossible task for trying to track All Might down once and for all. But, he seems genuinely scared of Midoriya's "haunted" place, or maybe he's just scared of Midoriya? What's going on Todoroki, communicate with us here. I hope Midoriya doesn't get lost trying to track shouto home. Good luck boys! Until next time!
'Somewhere in the distance, there's the sharp trill of birdsong, followed closely by the frantic flapping of wings, the sounds a concert accompanied by the occasional whisper of a breeze rattling the leaves and branches of the forest, and his own discrete pants for air.' Okay just gotta say that line is absolutely gorgeous and I can picture it perfectly in my head. There are so many descriptions throughout this chapter that are just SO PRETTY!!! FIRST CONTACT WITH THE CRYPTID AAAAAAAAAAAAAAAAH!! This was adorable?!?! All Might is a sweetheart through and through! And Izuku fanboying? Oh my dear boy. (Izuku concerned for Shouto? oh my aching heart. BUT IZUKU THINKING ABOUT HOW PRETTY SHOUTO IS IS THE BEST THING EVER OKAY) Inko! Please take care;;;;;; don't worry your mother too much Izuku!Now, onto Aizawa. He cares a lot about his students, yeah........ but is that all? Hmmm? Do you know more than you let on, Aizawa? *eyes emoji* Could there be more teachers behind the scenes, helping All Might out? The plot thickens.
That would require finding said clearing, Shouto, and all things considered that sounds like quite the challenge. People often don’t remember directions well when rushing around.I wonder why Shouto wants to meet All Might so badly. Is his home life anywhere near as bad as it is in canon? Perhaps hopes All Might will help rescue his mom from wherever Enji stashed her.
AND TOTORO MAKES HIS APPEARANCE - i mean All Might. He's like the local friendly bigfoot. Bless him and his accident-selfie. Midoriya had such a rough tumble - it sounded both super painful and really dangerous - I'm glad he got saved in time. Todoroki ironically lead Midoriya to the clearing by running away from him to begin with - I see you trying to benefit yourself and your goals in this invitation. I worry Midoriya won't be able to find the clearing since he woke up there and was carried away from there - without a definitive route. Todoroki might not be as patient when he realises Midoriya can't find it for him. Aizawa's behaviour concerns me. Is he in contact/affiliation with All might? I feel like he knows. Until next time!
I honestly did not expect to get this initial comment, much less speculation about PotW, so I was absolutely floored, when the speculation began to come in with later chapters, and I must say that it gave me so so much motivation to keep on writing!
Man so much of this is so Ghibli; Izuku leaning out of the window, the tiny house on the edge of a giant forest, Shouto appearing in the dusk to give an ominous message, only to retreat to his mansion home across the moor (okay the moor is Gothic lit but STILL WHAT A MOOD). He has the biggest combo of San & Haku going on and I dig it so hard.
You write EXACTLY as a Ghibli movie is animated and just Wow It’s gorgeous
This is absolutely gorgeous. You capture the atmosphere so well. I’ve always wanted a regular high school au for these kids and while it isn’t the main focus, I really enjoy that aspect of the story. The plot so far is amazing, just the right combination of Ghibli and BNHA that it creates a new story entirely its own. I love every moment of this and am excited to see how Todoroki and Midoriya’s relationship evolves.
Studio Ghibli is one of the biggest influences in my life in terms of media, and I desperately wanted to do justice to it through PotW, so these comments literally made me cry from happiness.
Wow, this got really really long, and I wholeheartedly apologise to anyone reading this on mobile, and I just wanted to say once again, to everyone who has ever read my fics, to everyone who has ever read my fics and commented, thank you so so much! Your comments, reblogs, and supports give me so much motivation, and sometimes they’re the only things that get me through a tough time!
12 notes · View notes
jennifersnyderca90 · 7 years
Text
Dahua, Hikvision IoT Devices Under Siege
Dahua, the world’s second-largest maker of “Internet of Things” devices like security cameras and digital video recorders (DVRs), has shipped a software update that closes a gaping security hole in a broad swath of its products. The vulnerability allows anyone to bypass the login process for these devices and gain remote, direct control over vulnerable systems. Adding urgency to the situation, there is now code available online that allows anyone to exploit this bug and commandeer a large number of IoT devices.
On March 5, a security researcher named Bashis posted to the Full Disclosure security mailing list exploit code for an embarrassingly simple flaw in the way many Dahua security cameras and DVRs handle authentication. These devices are designed to be controlled by a local Web server that is accessible via a Web browser.
That server requires the user to enter a username and password, but Bashis found he could force all affected devices to cough up their usernames and a simple hashed value of the password. Armed with this information, he could effectively “pass the hash” and the corresponding username right back to the Web server and be admitted access to the device settings page. From there, he could add users and install or modify the device’s software. From Full Disclosure:
“This is so simple as: 1. Remotely download the full user database with all credentials and permissions 2. Choose whatever admin user, copy the login names and password hashes 3. Use them as source to remotely login to the Dahua devices
“This is like a damn Hollywood hack, click on one button and you are in…”
Bashis said he was so appalled at the discovery that he labeled it an apparent “backdoor” — an undocumented means of accessing an electronic device that often only the vendor knows about. Enraged, Bashis decided to publish his exploit code without first notifying Dahua. Later, Bashis said he changed his mind after being contacted by the company and agreed to remove his code from the online posting.
Unfortunately, that ship may have already sailed. Bashis’s exploit code already has been copied in several other places online as of this publication.
Asked why he took down his exploit code, Bashis said in an interview with KrebsOnSecurity that “The hack is too simple, way too simple, and now I want Dahua’s users to get patched firmware’s before they will be victims to some botnet.”
In an advisory published March 6, Dahua said it has identified nearly a dozen of its products that are vulnerable, and that further review may reveal additional models also have this flaw. The company is urging users to download and install the newest firmware updates as soon as possible. Here are the models known to be affected so far:
DH-IPC-HDW23A0RN-ZS DH-IPC-HDBW23A0RN-ZS DH-IPC-HDBW13A0SN DH-IPC-HDW13A0SN DH-IPC-HFW13A0SN-W DH-IPC-HDBW13A0SN DH-IPC-HDW13A0SN DH-IPC-HFW13A0SN-W DHI-HCVR51A04HE-S3 DHI-HCVR51A08HE-S3 DHI-HCVR58A32S-S2
It’s not clear exactly how many devices worldwide may be vulnerable. Bashis says that’s a difficult question to answer, but that he “wouldn’t be surprised if 95 percent of Dahua’s product line has the same problem,” he said. “And also possible their OEM clones.”
Dahua has not yet responded to my questions or request for comment. I’ll update that here if things change on that front.
This is the second time in a week that a major Chinese IoT firm has urgently warned its customers to update the firmware on their devices. For weeks, experts have been warning that there are signs of attackers exploiting an unknown backdoor or equally serious vulnerability in cameras and DVR devices made by IoT giant Hikvision.
Writing for video surveillance publication IPVM, Brian Karas reported on March 2 that he was hearing from multiple Hikvision security camera and DVR users who suddenly were locked out of their devices and had new “system” user accounts added without their permission.
Karas said the devices in question all were set up to be remotely accessible over the Internet, and were running with the default credentials (12345). Karas noted that there don’t appear to be any Hikvision devices sought out by the Mirai worm — the now open-source malware that is being used to enslave IoT devices in a botnet for launching crippling online attacks (in contrast, Dahua’s products are hugely represented in the list of systems being sought out by the Mirai worm.)
In addition, a programmer who has long written and distributed custom firmware for Hikvision devices claims he’s found a backdoor in “many popular Hikvision products that makes it possible to gain full admin access to the device,” wrote the user “Montecrypto” on the IoT forum IPcamtalk on Mar. 5. “Hikvision gets two weeks to come forward, acknowledge, and explain why the backdoor is there and when it is going to be removed. I sent them an email. If nothing changes, I will publish all details on March 20th, along with the firmware that disables the backdoor.”
According to IPVM’s Karas, Hikvision has not acknowledged an unpatched backdoor or any other equivalent weakness in its product. But on Mar. 2, the company issued a reminder to its integrator partners about the need to be updated to the latest firmware.
A special bulletin issued Mar. 2, 2017 by Hikvision. Image: IPVM
“Hikvision has determined that there is a scripted application specifically targeting Hikvision NVRs and DVRs that meet the following conditions: they have not been updated to the latest firmware; they are set to the default port, default user name, and default password,” the company’s statement reads. “Hikvision has required secure activation since May of 2015, making it impossible for our integrator partners to install equipment with default settings. However, it was possible, before that date, for integrators to install NVRs and DVRs with default settings. Hikvision strongly recommends that our dealer base review the security levels of equipment installed prior to June 2015 to ensure the use of complex passwords and upgraded firmware to best protect their customers.”
ANALYSIS
I don’t agree with Bashis’s conclusion that the Dahua flaw was intentional; It appears that the makers of these products simply did not invest much energy, time or money in building security into the software. Rather, security is clearly an afterthought that is bolted on afterwards with these devices, which is why nobody should trust them.
The truth is that the software that runs on a whole mess of these security cameras and DVRs is very poorly written, and probably full of more security holes just like the flaw Dahua users are dealing with right now. To hope or wish otherwise given what we know about the history of these cheap electronic devices seems sheer folly.
In December, KrebsOnSecurity warned that many Sony security cameras contained a backdoor that can only be erased by updating the firmware on the devices.
Some security experts maintain that these types of flaws can’t be easily exploited when the IoT device in question is behind a firewall. But that advice just doesn’t hold water for today’s IoT cameras and DVRs. For one thing, a great many security cameras and other IoT devices will punch a hole in your firewall straight away without your permission, using a technology called Universal Plug-and-Play (UPnP).
In other cases, IoT products are incorporating peer-to-peer (P2P) technology that cannot be turned off and exposes users to even greater threats.  In that same December 2016 story referenced above, I cited research from security firm Cybereason, which found at least two previously unknown security flaws in dozens of IP camera families that are white-labeled under a number of different brands (and some without brands at all).
“Cybereason’s team found that they could easily exploit these devices even if they were set up behind a firewall,” that story noted. “That’s because all of these cameras ship with a factory-default peer-to-peer (P2P) communications capability that enables remote ‘cloud’ access to the devices via the manufacturer’s Web site — provided a customer visits the site and provides the unique camera ID stamped on the bottom of the devices.”
The story continued:
“Although it may seem that attackers would need physical access to the vulnerable devices in order to derive those unique camera IDs, Cybereason’s principal security researcher Amit Serper said the company figured out a simple way to enumerate all possible camera IDs using the manufacturer’s Web site.”
My advice? Avoid the P2P models like the plague. If you have security cameras or DVR devices that are connected to the Internet, make sure they are up to date with the latest firmware. Beyond that, consider completely blocking external network access to the devices and enabling a VPN if you truly need remote access to them.
Howtogeek.com has a decent tutorial on setting up your own VPN to enable remote access to your home or business network; on picking a decent router that supports VPNs; and installing custom firmware like DD-WRT on the router if available (because, as we can see, stock firmware usually is some horribly insecure and shoddy stuff).
If you’re curious about an IoT device you purchased and what it might do after you connect it to a network, the information is there if you know how and where to look. This Lifehacker post walks through some of the basic software tools and steps that even a novice can follow to learn more about what’s going on across a local network.
from https://krebsonsecurity.com/2017/03/dahua-hikvision-iot-devices-under-siege/
0 notes
amberdscott2 · 7 years
Text
Dahua, Hikvision IoT Devices Under Siege
Dahua, the world’s second-largest maker of “Internet of Things” devices like security cameras and digital video recorders (DVRs), has shipped a software update that closes a gaping security hole in a broad swath of its products. The vulnerability allows anyone to bypass the login process for these devices and gain remote, direct control over vulnerable systems. Adding urgency to the situation, there is now code available online that allows anyone to exploit this bug and commandeer a large number of IoT devices.
On March 5, a security researcher named Bashis posted to the Full Disclosure security mailing list exploit code for an embarrassingly simple flaw in the way many Dahua security cameras and DVRs handle authentication. These devices are designed to be controlled by a local Web server that is accessible via a Web browser.
That server requires the user to enter a username and password, but Bashis found he could force all affected devices to cough up their usernames and a simple hashed value of the password. Armed with this information, he could effectively “pass the hash” and the corresponding username right back to the Web server and be admitted access to the device settings page. From there, he could add users and install or modify the device’s software. From Full Disclosure:
“This is so simple as: 1. Remotely download the full user database with all credentials and permissions 2. Choose whatever admin user, copy the login names and password hashes 3. Use them as source to remotely login to the Dahua devices
“This is like a damn Hollywood hack, click on one button and you are in…”
Bashis said he was so appalled at the discovery that he labeled it an apparent “backdoor” — an undocumented means of accessing an electronic device that often only the vendor knows about. Enraged, Bashis decided to publish his exploit code without first notifying Dahua. Later, Bashis said he changed his mind after being contacted by the company and agreed to remove his code from the online posting.
Unfortunately, that ship may have already sailed. Bashis’s exploit code already has been copied in several other places online as of this publication.
Asked why he took down his exploit code, Bashis said in an interview with KrebsOnSecurity that “The hack is too simple, way too simple, and now I want Dahua’s users to get patched firmware’s before they will be victims to some botnet.”
In an advisory published March 6, Dahua said it has identified nearly a dozen of its products that are vulnerable, and that further review may reveal additional models also have this flaw. The company is urging users to download and install the newest firmware updates as soon as possible. Here are the models known to be affected so far:
DH-IPC-HDW23A0RN-ZS DH-IPC-HDBW23A0RN-ZS DH-IPC-HDBW13A0SN DH-IPC-HDW13A0SN DH-IPC-HFW13A0SN-W DH-IPC-HDBW13A0SN DH-IPC-HDW13A0SN DH-IPC-HFW13A0SN-W DHI-HCVR51A04HE-S3 DHI-HCVR51A08HE-S3 DHI-HCVR58A32S-S2
It’s not clear exactly how many devices worldwide may be vulnerable. Bashis says that’s a difficult question to answer, but that he “wouldn’t be surprised if 95 percent of Dahua’s product line has the same problem,” he said. “And also possible their OEM clones.”
Dahua has not yet responded to my questions or request for comment. I’ll update that here if things change on that front.
This is the second time in a week that a major Chinese IoT firm has urgently warned its customers to update the firmware on their devices. For weeks, experts have been warning that there are signs of attackers exploiting an unknown backdoor or equally serious vulnerability in cameras and DVR devices made by IoT giant Hikvision.
Writing for video surveillance publication IPVM, Brian Karas reported on March 2 that he was hearing from multiple Hikvision security camera and DVR users who suddenly were locked out of their devices and had new “system” user accounts added without their permission.
Karas said the devices in question all were set up to be remotely accessible over the Internet, and were running with the default credentials (12345). Karas noted that there don’t appear to be any Hikvision devices sought out by the Mirai worm — the now open-source malware that is being used to enslave IoT devices in a botnet for launching crippling online attacks (in contrast, Dahua’s products are hugely represented in the list of systems being sought out by the Mirai worm.)
In addition, a programmer who has long written and distributed custom firmware for Hikvision devices claims he’s found a backdoor in “many popular Hikvision products that makes it possible to gain full admin access to the device,” wrote the user “Montecrypto” on the IoT forum IPcamtalk on Mar. 5. “Hikvision gets two weeks to come forward, acknowledge, and explain why the backdoor is there and when it is going to be removed. I sent them an email. If nothing changes, I will publish all details on March 20th, along with the firmware that disables the backdoor.”
According to IPVM’s Karas, Hikvision has not acknowledged an unpatched backdoor or any other equivalent weakness in its product. But on Mar. 2, the company issued a reminder to its integrator partners about the need to be updated to the latest firmware.
A special bulletin issued Mar. 2, 2017 by Hikvision. Image: IPVM
“Hikvision has determined that there is a scripted application specifically targeting Hikvision NVRs and DVRs that meet the following conditions: they have not been updated to the latest firmware; they are set to the default port, default user name, and default password,” the company’s statement reads. “Hikvision has required secure activation since May of 2015, making it impossible for our integrator partners to install equipment with default settings. However, it was possible, before that date, for integrators to install NVRs and DVRs with default settings. Hikvision strongly recommends that our dealer base review the security levels of equipment installed prior to June 2015 to ensure the use of complex passwords and upgraded firmware to best protect their customers.”
ANALYSIS
I don’t agree with Bashis’s conclusion that the Dahua flaw was intentional; It appears that the makers of these products simply did not invest much energy, time or money in building security into the software. Rather, security is clearly an afterthought that is bolted on afterwards with these devices, which is why nobody should trust them.
The truth is that the software that runs on a whole mess of these security cameras and DVRs is very poorly written, and probably full of more security holes just like the flaw Dahua users are dealing with right now. To hope or wish otherwise given what we know about the history of these cheap electronic devices seems sheer folly.
In December, KrebsOnSecurity warned that many Sony security cameras contained a backdoor that can only be erased by updating the firmware on the devices.
Some security experts maintain that these types of flaws can’t be easily exploited when the IoT device in question is behind a firewall. But that advice just doesn’t hold water for today’s IoT cameras and DVRs. For one thing, a great many security cameras and other IoT devices will punch a hole in your firewall straight away without your permission, using a technology called Universal Plug-and-Play (UPnP).
In other cases, IoT products are incorporating peer-to-peer (P2P) technology that cannot be turned off and exposes users to even greater threats.  In that same December 2016 story referenced above, I cited research from security firm Cybereason, which found at least two previously unknown security flaws in dozens of IP camera families that are white-labeled under a number of different brands (and some without brands at all).
“Cybereason’s team found that they could easily exploit these devices even if they were set up behind a firewall,” that story noted. “That’s because all of these cameras ship with a factory-default peer-to-peer (P2P) communications capability that enables remote ‘cloud’ access to the devices via the manufacturer’s Web site — provided a customer visits the site and provides the unique camera ID stamped on the bottom of the devices.”
The story continued:
“Although it may seem that attackers would need physical access to the vulnerable devices in order to derive those unique camera IDs, Cybereason’s principal security researcher Amit Serper said the company figured out a simple way to enumerate all possible camera IDs using the manufacturer’s Web site.”
My advice? Avoid the P2P models like the plague. If you have security cameras or DVR devices that are connected to the Internet, make sure they are up to date with the latest firmware. Beyond that, consider completely blocking external network access to the devices and enabling a VPN if you truly need remote access to them.
Howtogeek.com has a decent tutorial on setting up your own VPN to enable remote access to your home or business network; on picking a decent router that supports VPNs; and installing custom firmware like DD-WRT on the router if available (because, as we can see, stock firmware usually is some horribly insecure and shoddy stuff).
If you’re curious about an IoT device you purchased and what it might do after you connect it to a network, the information is there if you know how and where to look. This Lifehacker post walks through some of the basic software tools and steps that even a novice can follow to learn more about what’s going on across a local network.
from Amber Scott Technology News https://krebsonsecurity.com/2017/03/dahua-hikvision-iot-devices-under-siege/
0 notes
rainbowsky · 3 years
Text
Ask Policy
In the interest of ensuring I can answer as many asks as possible without making too many people wait too long, I’ve decided to give some guidelines for submitting asks. Some of this is just me setting healthy boundaries because I find a lot of asks I get are outside of the scope of what I feel comfortable with, but some of it is just meant to help simplify things for those wanting to submit an ask.
I am always happy to get asks from people so don't let this policy hold you back from asking a question. It's meant as guidance to help people frame their questions to increase the likelihood they'll be answered - and as an explanation for why I don't always answer every ask. Please don't feel intimidated or deterred by the policy.
This policy is subject to change and updates so feel free to check back if there's anything you are unsure about.
I do not answer every ask
I want to start by making it clear that unlike some other bloggers, I do not answer every single ask I get. It would be impossible for me to do that. I don’t have the time or the spoons, and I get a large volume of asks daily. However, I read every single one of them and I do my best to take what I read into consideration when deciding on what to post about, etc. so even if I don’t get to your ask, it will be taken into consideration.
There are also some asks I just won’t answer, some topics I won’t discuss. I will try to outline the primary ones below, to make expectations clear.
Timing of answers
Also, I do not always answer asks in the order they are received. That would not be practical. Some asks require research and thought. Some inspire ideas that take longer for me to articulate than others. Some are time-sensitive. All of these impact the timing of a response.
Someone asking me, “What makes you believe BJYXSZD?” is going to take me a long time (months, apparently) while someone asking me, “What time is the XYZ livestream happening tonight?” takes only a moment to answer. Sometimes I get fixated on tangents about DD’s hair and fashion and will answer several asks in a row about it, even though there are older asks in the inbox.
All I can say is, I try to strike the right balance between giving people what they’re asking for while ensuring that I enjoy being on Tumblr and don’t end up feeling like it’s a job I’m not getting paid for. Sometimes I will set aside my needs for the needs of the readers, and other times I will set aside the needs of the readers for my own. This is the best way I’ve found to keep that balance right.
Guidelines for submitting an ask
Please check my index post before sending an ask. Many common questions will be answered in those posts.
Please try to keep the total word count under 300 words.
If you are asking a question, please make sure it's stated clearly.
If you want me to comment on something you saw online, please include a link so that I can see what you’re referring to.
If you have submitted the same question to multiple bloggers, please be open and honest about that.
If you aren’t anon and want me to respond privately please make that clear.
Things I'm unlikely to respond to
Hateful, harassing asks are deleted without hesitation.
Asks that go beyond the word count will likely not be answered. I have frequently gotten asks in the 600-1,200 word count range, and it’s just too much. If you have a lot to say, I recommend starting a blog of your own. Now, if you have that much to say to me and you don’t care about it being replied to then feel free to send it in, but please understand that I will likely not post your ask.
Asks that speak negatively of GG and/or DD, or that frame GG or DD as rivals or in opposition to each other, will be deleted. Such messages tend to be anti messages, and I won’t let my blog be a platform for that. If you have a good-faith question relating to that topic please be careful how you frame it, and understand I might not be willing to post a response.
Asks that are obviously copy pasted to multiple bloggers I will not answer unless there's a clear reason why they want multiple perspectives, and only if that has been stated openly in the ask. Spammed asks will be deleted.
Asks that just repeat or affirm what's already been said are less likely to be posted than ones that add something new to the conversation.
Complaints about what other people are doing online are generally referred to my post about fan wars. That’s not because I don’t care how you feel. I do, and I know how frustrating the fandom can be. I tend not to respond to those asks because I don’t want to fuel those thoughts and feelings in others, or to be a platform for spreading negativity and anger about others (and that includes solos). If you really want to talk about something relating to fan wars, try to find a way to frame it that won’t violate those principles.
While I am always happy to get fic recommendations, I have a policy of not posting fic recs to my blog. I cannot be a platform for promoting anything I haven’t yet read. I have gotten some recs that fall outside the type of fic I’m comfortable with. However, if I like the fic you recommend, it might end up on my rec list.
Asks regarding other ships, other fandoms or other artists besides GGDD are outside of my purview. My focus is on GGDD and things immediately relating to them.
Asks about time-sensitive things that have passed. For example, asks that people sent me about a live event as it was happening, which referenced things that would have made sense if read at the time but make no sense now or feel out of place after the fact, are unlikely to be responded to now.
Topics I am working on at the moment
Here’s a list of some of the ask-related posts I am currently working on, in case you are wondering whether to ask about a certain topic. If your ask hasn’t been answered you might want to check back here to see if it’s on the list.
What makes you believe BJYXSZD?
An update to my timeline post.
The BTS is fake/fan service.
Oversexualization of GGDD, especially on Twitter.
Why do solos dismiss GGDD’s relationship?
Will GG and DD ever come out?
If your ask hasn’t been answered
If your ask hasn’t been answered and
It’s been longer than a few weeks
It’s a topic I haven’t already covered (refer to my index post)
It isn’t on the list of topics I am currently working on (above)
It isn’t on the list of topics I won’t respond to (also above)
then there’s a chance it’s been lost or that I just haven’t had time. If it’s a question that really matters to you then feel free to resubmit as long as your ask meets all four of the criteria above.
If you do resubmit, consider rephrasing or reframing your ask to make it clearer and easier to answer.
I can’t guarantee I will get to it any sooner, but I will do my best.
If you don’t have time to answer all asks, why not close your inbox?
Some bloggers close their inbox when they are getting a volume of asks beyond what they have time to answer. I suspect they do that because it works for them and for how they go about things. That approach would not work for me or for how I like to engage with the fandom.
To me there is a huge value in being able to respond to asks about issues and events as they arise. It’s important to me to be able to discuss things that are currently happening, with input from readers as it is contributed. Closing my inbox would prevent that.
A lot of asks can be answered quickly. Yes, I could close my inbox and limit my answers to the longer, more time consuming asks that are lurking there. If I did so, I would ironically be answering significantly fewer asks than by leaving it open.
I also try to think about it from the ‘do unto others’ perspective, and in terms of what I expect from other bloggers when I submit an ask to them. I regularly submit asks to other blogs and when I do so, I never expect a response. I might hope for a response, of course, but I don’t expect it. I understand that people respond if/when they are able, and there might be countless reasons they wouldn’t get to my particular ask. I hope that readers can feel the same way when submitting an ask to me.
Can I message you privately?
Yes you can, but if you are messaging me to ask me a question or tell me something that might be of interest to other readers, please consider sending it as an ask so that it can be shared with everyone.
27 notes · View notes