{"author":"heresie-dabord","children":[{"author":"FloatArtifact","children":[{"author":"chrisjj","children":[{"author":"crimsonnoodle58","children":[{"author":"chrisjj","children":[],"created_at":"2026-01-31T10:15:24.000Z","created_at_i":1769854524,"id":46835234,"options":[],"parent_id":46832410,"points":null,"story_id":46831784,"text":"Ouch. Thanks.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:35:25.000Z","created_at_i":1769823325,"id":46832410,"options":[],"parent_id":46831889,"points":null,"story_id":46831784,"text":"Not true for their docker instructions which specify -p 11434:11434 instead of -p 127.0.0.1:11434:11434. [1]<p>Combine that with rootful docker&#x27;s famous bypass of ufw and you have a publicly exposed ollama, even with a firewall. [2]<p>[1] <a href=\"https:&#x2F;&#x2F;docs.ollama.com&#x2F;docker\">https:&#x2F;&#x2F;docs.ollama.com&#x2F;docker</a><p>[2] <a href=\"https:&#x2F;&#x2F;github.com&#x2F;moby&#x2F;moby&#x2F;issues&#x2F;4737\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;moby&#x2F;moby&#x2F;issues&#x2F;4737</a>","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T00:28:06.000Z","created_at_i":1769819286,"id":46831889,"options":[],"parent_id":46831833,"points":null,"story_id":46831784,"text":"The article says no, the default is listening to just localhost. Given the instances in question have been deliberately configured to listen on public ports, calling this <i>misconfiguration</i> seems somewhat unjustified.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T00:21:33.000Z","created_at_i":1769818893,"id":46831833,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"This is a combination problem poor default (listening to all interfaces?) and also IPv6 can be publicly accessible. It&#x27;s a bit dependent on how this is configured upstream by default, but this is a gotcha compared to IPv4.","title":null,"type":"comment","url":null},{"author":"rvz","children":[],"created_at":"2026-01-31T00:27:46.000Z","created_at_i":1769819266,"id":46831884,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"Nevermind. [0] Nothing to see here.<p>[0] <a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=45116322\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=45116322</a>","title":null,"type":"comment","url":null},{"author":"dfajgljsldkjag","children":[{"author":"rvz","children":[],"created_at":"2026-01-31T03:08:23.000Z","created_at_i":1769828903,"id":46832966,"options":[],"parent_id":46832127,"points":null,"story_id":46831784,"text":"Even better.<p>We have those who are openly admitting that they have never written &#x2F; read a line of code and have no idea on what it does and using AI to deploy &quot;AI tools&quot; without knowing how to secure them.<p>Infosec experts are going to have a great time with collecting lots of money out of this.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T00:57:44.000Z","created_at_i":1769821064,"id":46832127,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"I see this happen all the time when people just want their new toys to work right away. They copy and paste commands from the internet to open up the connection but they forget to put a lock on the door. It is dangerous that so many people run these programs without understanding the basics of how networks work.","title":null,"type":"comment","url":null},{"author":"meltyness","children":[{"author":"threecheese","children":[{"author":"meltyness","children":[{"author":"threecheese","children":[],"created_at":"2026-01-31T21:01:51.000Z","created_at_i":1769893311,"id":46840809,"options":[],"parent_id":46832376,"points":null,"story_id":46831784,"text":"Makes sense, thank you!","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:31:33.000Z","created_at_i":1769823093,"id":46832376,"options":[],"parent_id":46832337,"points":null,"story_id":46831784,"text":"It&#x27;s more of a distribution thing for me really. I&#x27;m basically using docker as a package manager since they otherwise distribute through one of those ad-hoc shell scripts that I&#x27;d prefer to avoid accidentally breaking Debian with somehow.<p>I&#x27;ve built ollama before too, but, I like that I can cleanly rip it out of my system or upgrade it without handing root off to some shell script somewhere I guess.<p>If anyone&#x27;s gonna bash up my system it oughta be me","title":null,"type":"comment","url":null},{"author":"cyberax","children":[{"author":"throw20251220","children":[],"created_at":"2026-01-31T16:12:30.000Z","created_at_i":1769875950,"id":46837893,"options":[],"parent_id":46834886,"points":null,"story_id":46831784,"text":"You work with Linux. On a mac, you run ollama on the host because the gpu is not available in the container.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T09:17:07.000Z","created_at_i":1769851027,"id":46834886,"options":[],"parent_id":46832337,"points":null,"story_id":46831784,"text":"I&#x27;m using open-webui project to host a Web UI for Ollama, and Ollama itself in Docker containers. It&#x27;s super-useful, because I don&#x27;t have to worry about it blowing up stuff on my system with automatic installations.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:25:12.000Z","created_at_i":1769822712,"id":46832337,"options":[],"parent_id":46832246,"points":null,"story_id":46831784,"text":"Out of curiosity, why would you need to wrap the call to an Ollama modelfile in docker? Does the dockerized ollama client provide some benefit, when it\u2019s shelling down to local Ollama instance anyway?\n(Wrt tax-pal)","title":null,"type":"comment","url":null},{"author":"crimsonnoodle58","children":[{"author":"meltyness","children":[{"author":"xhcuvuvyc","children":[],"created_at":"2026-01-31T06:40:15.000Z","created_at_i":1769841615,"id":46834082,"options":[],"parent_id":46832731,"points":null,"story_id":46831784,"text":"Docker has a lot of lazy hacks to make it work well on MacOS that had to have it running in a VM for any of the linux containers to work.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T02:27:07.000Z","created_at_i":1769826427,"id":46832731,"options":[],"parent_id":46832550,"points":null,"story_id":46831784,"text":"Apparently been that way for a while haha<p><a href=\"https:&#x2F;&#x2F;github.com&#x2F;moby&#x2F;moby&#x2F;commit&#x2F;1cbdaebaa1c2326e57945333420d25d6f77011d5\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;moby&#x2F;moby&#x2F;commit&#x2F;1cbdaebaa1c2326e57945333...</a>","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:55:22.000Z","created_at_i":1769824522,"id":46832550,"options":[],"parent_id":46832246,"points":null,"story_id":46831784,"text":"Yes the binding interface can be specified, but the default for -p 11434:11434 is 0.0.0.0.<p>IMO the default should be 127.0.0.1 and the user should have to explicitly bind to all via -p 0.0.0.0:11434:11434.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:10:19.000Z","created_at_i":1769821819,"id":46832246,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"This is a weakness of docker, a bit, I think.<p>I was rigging this up, myself, and conciscious of the fact that basic docker is &quot;all or none&quot; for container port forwarding because it&#x27;s for presenting network services, had to dig around with iptables so it&#x27;d be similar to binding on localhost.<p>The use case <a href=\"https:&#x2F;&#x2F;github.com&#x2F;meltyness&#x2F;tax-pal\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;meltyness&#x2F;tax-pal</a><p>The ollama container is fairly easy to deploy, and supports GPU inference through container toolkit. I&#x27;d imagine many of these are docker containers.<p>e: i stand corrected, apparently -p of `docker run` can have a binding interface stipulated<p>e2: <a href=\"https:&#x2F;&#x2F;docs.docker.com&#x2F;engine&#x2F;containers&#x2F;run&#x2F;#exposed-ports\" rel=\"nofollow\">https:&#x2F;&#x2F;docs.docker.com&#x2F;engine&#x2F;containers&#x2F;run&#x2F;#exposed-ports</a> which is not in some docs<p>e3: but it&#x27;s in the man page ofc","title":null,"type":"comment","url":null},{"author":"cyberax","children":[{"author":"throwaway314155","children":[{"author":"Zambyte","children":[{"author":"throwaway314155","children":[],"created_at":"2026-01-31T20:00:47.000Z","created_at_i":1769889647,"id":46840206,"options":[],"parent_id":46833289,"points":null,"story_id":46831784,"text":"That bit hadn\u2019t been edited in when I wrote my comment.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T03:58:03.000Z","created_at_i":1769831883,"id":46833289,"options":[],"parent_id":46832479,"points":null,"story_id":46831784,"text":"Binding to 0.0.0.0 means binding to every interface.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:44:25.000Z","created_at_i":1769823865,"id":46832479,"options":[],"parent_id":46832422,"points":null,"story_id":46831784,"text":"How exactly are the ports &quot;exposed&quot; if they can&#x27;t be bound to an interface?","title":null,"type":"comment","url":null},{"author":"vxxzy","children":[],"created_at":"2026-01-31T02:01:10.000Z","created_at_i":1769824870,"id":46832581,"options":[],"parent_id":46832422,"points":null,"story_id":46831784,"text":"A feature! Not a bug!  Bugs can be undisovered features.","title":null,"type":"comment","url":null},{"author":"kristopolous","children":[{"author":"Zambyte","children":[],"created_at":"2026-01-31T04:03:23.000Z","created_at_i":1769832203,"id":46833326,"options":[],"parent_id":46832707,"points":null,"story_id":46831784,"text":"<a href=\"https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18302380\">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18302380</a>","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T02:23:36.000Z","created_at_i":1769826216,"id":46832707,"options":[],"parent_id":46832422,"points":null,"story_id":46831784,"text":"it&#x27;s called a privileged port and it&#x27;s been like this for decades, on every system, ever.<p>Here&#x27;s a reference to this &quot;macos feature&quot; from 1995: <a href=\"https:&#x2F;&#x2F;www.w3.org&#x2F;Daemon&#x2F;User&#x2F;Installation&#x2F;PrivilegedPorts.html\" rel=\"nofollow\">https:&#x2F;&#x2F;www.w3.org&#x2F;Daemon&#x2F;User&#x2F;Installation&#x2F;PrivilegedPorts....</a>","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T01:36:37.000Z","created_at_i":1769823397,"id":46832422,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"Fun fact! On macOS you can expose privileged ports (&lt;1024) using a regular user account.<p>But ONLY if you don&#x27;t bind the listening port to any interface. So you try to create a listening port on localhost (e.g. 127.0.0.1:443) under a non-root account you get a permission error.<p>Edit: the thing is, you CAN expose &quot;0.0.0.0:443&quot; without root privileges!","title":null,"type":"comment","url":null},{"author":"adw","children":[],"created_at":"2026-01-31T01:42:20.000Z","created_at_i":1769823740,"id":46832464,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"The tool-calling thing here is overblown.<p>When you do &quot;tool calling&quot; with an LLM, all you&#x27;re doing is having the LLM generate output in a particular format you can parse out of the response; it&#x27;s then your code&#x27;s responsibility to run the tools (locally) and stick the results back into the conversation.<p>So that _specific_ part isn&#x27;t RCE. It&#x27;s still bad for the nine million other obvious reasons though.","title":null,"type":"comment","url":null},{"author":"nxobject","children":[],"created_at":"2026-01-31T02:04:31.000Z","created_at_i":1769825071,"id":46832602,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"Pay for Shodan, folks!","title":null,"type":"comment","url":null},{"author":"gerdesj","children":[{"author":"reactordev","children":[],"created_at":"2026-01-31T03:50:13.000Z","created_at_i":1769831413,"id":46833238,"options":[],"parent_id":46832728,"points":null,"story_id":46831784,"text":"Fortunately there\u2019s an easy way to check\u2026","title":null,"type":"comment","url":null},{"author":"alexeiz","children":[],"created_at":"2026-02-02T22:42:12.000Z","created_at_i":1770072132,"id":46863059,"options":[],"parent_id":46832728,"points":null,"story_id":46831784,"text":"Fear not, we have Clawdbot! (openclaw whatever)  You can put your naked ass on the internet in seconds now.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T02:26:39.000Z","created_at_i":1769826399,"id":46832728,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"I&#x27;m not sure the &quot;journos&quot; from Techradar are too familiar with how networks ... work.<p>IPv4 requires an inbound NAT these days to work at all globally, unless you actually have a machine with a globally routable IP.  There will probably be a default deny firewall rule too.  I do remember the days before NAT ...<p>IPv6 doesn&#x27;t require NAT (but prefix translation is available and so is ULA) but again a default deny is likely in force.<p>You do actually have to try quite hard to expose something to the internets.  I know this because I do a lot of it.<p>The entire article is just a load of buzz words and basically bollocks.  Yes it is possible to expose  a system on the internet but it is unlikely that you do it by accident.  If I was Sead, I&#x27;d go easy on the AI generated cobblers and get a real job.","title":null,"type":"comment","url":null},{"author":"vivzkestrel","children":[{"author":"driverdan","children":[{"author":"vivzkestrel","children":[{"author":"Tiberium","children":[],"created_at":"2026-01-31T10:50:41.000Z","created_at_i":1769856641,"id":46835435,"options":[],"parent_id":46834238,"points":null,"story_id":46831784,"text":"GitHub sends those keys to Amazon which automatically quarantines them","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T07:14:59.000Z","created_at_i":1769843699,"id":46834238,"options":[],"parent_id":46833474,"points":null,"story_id":46831784,"text":"well i did not use regex earlier but found some AWS keys <a href=\"https:&#x2F;&#x2F;github.com&#x2F;search?q=%2F%22AWS_(%5Cw%2B)%22%3D%22(%5Cw%7B20%7D)%22%2F&amp;type=code\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;search?q=%2F%22AWS_(%5Cw%2B)%22%3D%22(%5C...</a><p>these are the same guys that later complain about a 100k$ bill on AWS<p>also this conversation never happened","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T04:25:26.000Z","created_at_i":1769833526,"id":46833474,"options":[],"parent_id":46833360,"points":null,"story_id":46831784,"text":"I just looked through 2 pages and didn&#x27;t see any keys, just empty config vars and placeholder values. How many real keys are you actually finding?","title":null,"type":"comment","url":null},{"author":"kirici","children":[],"created_at":"2026-01-31T05:11:46.000Z","created_at_i":1769836306,"id":46833697,"options":[],"parent_id":46833360,"points":null,"story_id":46831784,"text":"&gt; I wonder if github supports regex search<p>&#x2F;it does like this&#x2F;","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T04:07:29.000Z","created_at_i":1769832449,"id":46833360,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"- you ll be surprised how many OLLAMA API KEYS [you can find here](<a href=\"https:&#x2F;&#x2F;github.com&#x2F;search?q=%22OLLAMA_API_KEY%22&amp;type=code&amp;p=5\" rel=\"nofollow\">https:&#x2F;&#x2F;github.com&#x2F;search?q=%22OLLAMA_API_KEY%22&amp;type=code&amp;p...</a>) its 2026 and this technique still works. I wonder if github supports regex search","title":null,"type":"comment","url":null},{"author":"kristopolous","children":[{"author":"thehamkercat","children":[{"author":"Imustaskforhelp","children":[],"created_at":"2026-01-31T13:24:54.000Z","created_at_i":1769865894,"id":46836469,"options":[],"parent_id":46835706,"points":null,"story_id":46831784,"text":"Arcee AI is currently free on openrouter with some really great speeds and no logs&#x2F;traning from what I can tell while being completely free till end of feb and its a 500B model.<p>There are tons of free inference models. I treid to use  gemini flash in aistudio + devstral free for agentic tasks but its now deprecated but when it wasn&#x27;t, it was a really good setup imo. Now I can use arcee but personally ended up buying a 1 month cheap subscription of kimi after haggling it from 19.99 to 1.49$ for first month (could&#x27;ve haggled more too leading to 0.99$ too but yeaaa)","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T11:40:03.000Z","created_at_i":1769859603,"id":46835706,"options":[],"parent_id":46833670,"points":null,"story_id":46831784,"text":"If someone is that desperate looking for free inference, or just for fun openrouter has many free models","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T05:03:15.000Z","created_at_i":1769835795,"id":46833670,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"I tried a few these ... they are pretty slow. If you are looking for free inference you&#x27;d have to be pretty desperate.<p>example:<p>$ OLLAMA_HOST=<a href=\"http:&#x2F;&#x2F;47.101.61.248:9000&#x2F;\" rel=\"nofollow\">http:&#x2F;&#x2F;47.101.61.248:9000&#x2F;</a> ollama run gemma3:27b &quot;outline ww2&quot;<p>Many appear to be proxies. I&#x27;m familiar with some &quot;serverless&quot; architectures that do things like this <a href=\"https:&#x2F;&#x2F;www.shodan.io&#x2F;host&#x2F;34.255.41.58\" rel=\"nofollow\">https:&#x2F;&#x2F;www.shodan.io&#x2F;host&#x2F;34.255.41.58</a> ... you can see this has a bunch of ollama ports running really really old versions<p>You can pull down &quot;new&quot; manifests but very few ollamas are new enough for decent modern models like glm-4.7-flash. The free tier for the kimi-k2.5:cloud is going to be far more useful then pasting these into you OLLAMA_HOST variable.<p>I think the real headline is: &quot;thousands of slow machines running mediocre small models from last year. Totally open...&quot;<p>Anyways, if codellama:13b is your jam, go wild I guess.","title":null,"type":"comment","url":null},{"author":"Ms-J","children":[],"created_at":"2026-01-31T05:20:42.000Z","created_at_i":1769836842,"id":46833746,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"In my opinion Ollama has become so far off course with their licensing and user hostile features [1] that the only sane options I&#x27;ve come across is using llama.cpp.<p>[1] <a href=\"https:&#x2F;&#x2F;www.glukhov.org&#x2F;post&#x2F;2025&#x2F;09&#x2F;ollama-enshittification&#x2F;\" rel=\"nofollow\">https:&#x2F;&#x2F;www.glukhov.org&#x2F;post&#x2F;2025&#x2F;09&#x2F;ollama-enshittification...</a><p>To not even be able to disable data being exfiltrated with their automatic updates is terrible behavior.","title":null,"type":"comment","url":null},{"author":"ActorNightly","children":[],"created_at":"2026-01-31T05:24:03.000Z","created_at_i":1769837043,"id":46833765,"options":[],"parent_id":46831784,"points":null,"story_id":46831784,"text":"<a href=\"https:&#x2F;&#x2F;www.shodan.io&#x2F;\" rel=\"nofollow\">https:&#x2F;&#x2F;www.shodan.io&#x2F;</a><p>I ironically found out about this website from Mr Robot tv show.","title":null,"type":"comment","url":null}],"created_at":"2026-01-31T00:12:22.000Z","created_at_i":1769818342,"id":46831784,"options":[],"parent_id":null,"points":65,"story_id":46831784,"text":null,"title":"175K+ publicly-exposed Ollama AI instances discovered","type":"story","url":"https://www.techradar.com/pro/security/over-175-000-publicly-exposed-ollama-ai-servers-discovered-worldwide-so-fix-now"}
