xt-data.ixsystems.com (64.71.187.13) upload

Status
Not open for further replies.
Joined
Dec 7, 2015
Messages
3
Hey Team,

I can see my freenas mini device uploading about 5M every day to xt-data.ixsystems.com (64.71.187.13) over HTTPS.

Does anyone know what this could be and how to disable it?

I suspect some analytics from the system but I see no option to disable this via the UI.

I have since firewalled off that IP and sinkholed the domain but still would like some insight into what it is and why its happening.

Thanks,

Chris
 

Attachments

  • freenas.png
    freenas.png
    9.9 KB · Views: 321
D

dlavigne

Guest
Is System -> Advanced -> Enable automatic upload of kernel crash dumps and daily telemetry checked?
 
D

dlavigne

Guest
If it does, it sounds like you found a bug. If so, please create a bug report at bugs.freenas.org and post the issue number here.
 

titan_rw

Guru
Joined
Sep 1, 2012
Messages
586
Wow. I just looked at what it calls home with. I didn't realize it was sending things like 'zfs list', or 'zfs get'.

I can totally understand calling home with stuff like the motherboard models, and memory size, etc. Even arc_stats. But serial numbers too? And then there's sending 'zfs list/get', which includes the users poolnames, and datasets. To me, this is not just anonymous information. This is a small amount of user data. Think about this pool/dataset: tank/corporate-takeovers/in-progress/XYZ-corp. Some people would probably rather not have their pool layouts sent back to the mothership.

I'll be disabling this now. And I'm contemplating adding a firewall block to stop any outbound access. I can deal with OS updates manually.

I think gathering anonymous information like MB /CPU model / memory size, and arcstats should default to ON.

I think gathering anything further like pool layout / serial numbers, etc, should default to OFF. If the user wants to turn it on, let them.
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,525
@titan_rw

Did you put in bug ticket requesting that this be changed or anything?
 

cyberjock

Inactive Account
Joined
Mar 25, 2012
Messages
19,525
Do you remember what file had all the commands that are retrieved? I'd like to look at the list for curiosity.
 

titan_rw

Guru
Joined
Sep 1, 2012
Messages
586
It looks like cron calls:

/usr/local/bin/telemetry-cron.sh

And that calls:

/usr/local/bin/telemetry-gather.py

Looks like /var/log/messages is included as well as the RRD graphs.
 
Status
Not open for further replies.
Top