Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Can root verify user is secure?
Date: Sat, 29 Aug 2020 21:24:06
Message-Id: fe181347-8be1-17ab-bfd3-ad423d000cf1@gmail.com
In Reply to: Re: [gentoo-user] Re: Can root verify user is secure? by Grant
1 Grant wrote:
2 >>> Any tips here guys? Is there some kind of an audit process I can go
3 >>> through periodically to help ensure I'm safe?
4 >>>
5 >>>
6 >>> On Fri, Aug 28, 2020 at 8:52 AM Grant <emailgrant@×××××.com> wrote:
7 >>>> I noticed some strange behavior recently which has since gone away.
8 >>>> From a security standpoint, if root is hacked I suppose there's no
9 >>> way
10 >>>> to know, but if not can I use root to determine whether my user is
11 >>>> still secure?
12 >> I think there are some rootkit checks and other things, but other than going through all the settings files, it will be difficult.
13 >> What was thebstrange behaviour?
14 > The strange behavior was a critically slow internet connection first
15 > thing in the morning that wasn't fixed by a reboot or modem power
16 > cycle. My net0 monitor didn't show any traffic but I still wonder if
17 > the upstream pipe could have been clogged with data. My problem
18 > seemed to be the downstream but I think a full upstream pipe can slow
19 > the downstream? No ISP reports online and it cleared up after a short
20 > while. I haven't seen that before. Would you be concerned?
21 >
22 > Is there a separate device I can put on the network to monitor traffic
23 > so I can review it later on?
24 >
25 >
26
27
28 This may be related but it may not.  I notice things like this at times
29 and I watch the light on my modem.  If the light is blinking, something
30 is using the internet.  If not, it is upstream.  One thing I check, my
31 cell phone.  It is set to ask but for some updates, it doesn't.  At
32 times here, I can see my download stream reduced by half at least.  It
33 could be my ISP being overloaded, it could be the server I'm connected
34 too.  I think with the bug going around and a lot of people working from
35 home, it's slowing the internet a bit at times depending on how your
36 traffic is being routed or what sites you connect too.  I read somewhere
37 that youtube actually stopped high resolution videos for a while to help
38 reduce this problem.  I think it was in Europe somewhere but that
39 doesn't mean it hasn't happened in a lot of places. 
40
41 Could someone have hacked you, possible.  If you have something that is
42 worth hacking that makes you a target, very possible.  Could it just be
43 that the internet is being heavily loaded and struggling to keep up,
44 could be.  One thing I did once.  I had a video site that was really
45 slow.  It's was about like dial-up slow.  What should take a hour or
46 less was showing 6 or 8 hours.  I went to another video site and tried
47 it.  While not a max speed data transfer, it was pretty close to
48 normal.  My thinking, a lot of other people were using that site and it
49 was heavily loaded but the systems between me and it was a little slower
50 as well, although barely noticeable. 
51
52 Just some things to ponder and maybe watch for or test.  May help, may
53 not.  ;-)
54
55 Dale
56
57 :-)  :-)