Debian — The Universal Operating System

linuxmagazine,
@linuxmagazine@fosstodon.org avatar
RL_Dane,
@RL_Dane@fosstodon.org avatar

@amin, have you gotten scli to work in ?

I gave up because pipx refuses to install urwid, and I think Debian's version is drumroll way too old. ;)
I wish pipx just had scli. There's an scli package in PyPI, but it's literally an empty placeholder for nothing.
Infuriating.

tripplehelix,
@tripplehelix@fosstodon.org avatar

@RL_Dane @amin I can't see it in Sid, so F

eugenialoli,
@eugenialoli@mastodon.social avatar

The funny part about the removal of networking from the default package on , is that they did it for "security" reasons, without thinking that the MOST INSECURE way to transfer a to your is via the CLIPBOARD. Absolutely every running app or service can read the clipboard! And yet, that's the default way they expect users to do it now!

That maintainer didn't think it through at all.

jbzfn,
@jbzfn@mastodon.social avatar

🌀 16 years of CVE-2008-0166 - Debian OpenSSL Bug
— 16years.secvuln.info

"A patch in Debian's and Ubuntu's OpenSSL packages broke the random number generator, effectively limiting the number of possible keys to a few ten thousand plausible variations"

https://16years.secvuln.info/

9to5linux,
@9to5linux@floss.social avatar

Endless OS 6 Is Here Based on GNU/Linux 12 “Bookworm”, Here's What's New https://9to5linux.com/endless-os-6-is-here-based-on-debian-gnu-linux-12-bookworm

gnulinux, German
@gnulinux@social.anoxinon.de avatar

Gaming auf Debian und Derivaten Teil 2: Lutris

Der zweite Teil einer Serie, die sich damit befasst, wie man auf Debian/Ubuntu spielt und am besten Probleme schon im Voraus vermeidet.

https://gnulinux.ch/gaming-auf-debian-und-derivaten-teil-2-lutris

tripplehelix, (edited )
@tripplehelix@fosstodon.org avatar

How "unstable" is Experimental? I've been thinking of adding to Sid.

hrakaroozorn,
@hrakaroozorn@fosstodon.org avatar

@tripplehelix uncertain if joking, and if not, i apologize, but Sid is unstable https://wiki.debian.org/DebianUnstable

tripplehelix,
@tripplehelix@fosstodon.org avatar

@hrakaroozorn Oops, I meant Experimental/RC-Buggy

jschauma,
@jschauma@mstdn.social avatar

On the topic of "key rotation, it's not just for HTTPS", @hanno finds hundreds of DKIM keys apparently generated using the predictable PRNG vulenrability from 2008 (CVE-2008-0166):

https://16years.secvuln.info/

(And yes, is still stupid.)

isotopp,
@isotopp@chaos.social avatar

@jschauma

The question is, for whom that is a problem. DKIM signing mails is mostly to get Google to accept the mail, and not for anything useful.

bluelupo, German
@bluelupo@social.tchncs.de avatar

Debian spaltet KeePassXC auf - LinuxNews.de

Schade das der Maintainer des Debian-Paketes nicht ansatzweise die Funktionalität eines Passwortmanagers verstanden hat. Meiner Meinung nach missbraucht hier ein Paketbetreuer seine Kompetenzen. Letzlich schadet er mit seiner Vorgehensweise Debian insgesamt als Linuxdistribution.

https://linuxnews.de/debian-spaltet-keepassxc-auf/

gischpelino,
@gischpelino@mastodon.online avatar

@goebbe @bluelupo aber anders herum wäre es besser und Debian konform. KeepassXC mit vollem Funktionsumfang, wie gewohnt und erwartbar, und daneben eine KeepassXC-tiny ohne die Netzwerk- und Browserfunktionen anbieten.

allo,
@allo@chaos.social avatar

@gischpelino
vim-full ist auch nicht das default. Glücklicherweise, denn die meisten brauchen gar nicht alle Funktionen.

@goebbe @bluelupo

debacle,
@debacle@framapiaf.org avatar
thepaffy, German
@thepaffy@osna.social avatar

Wenn der Package-Maintainer die Software die er packertiert selber nicht nutzt... Ich hab schon wieder massive Kopfschmerzen...

"...schreibt Klode, dass er die [...] diese Funktionen entfernt. Diese dienten vermutlich dem Nachladen eines favicon einer Webseite, meint der Maintainer. Er gehe davon aus, dass die meisten Leute nicht wollten, dass ihre Passwort-Manager irgendwohin verbinden, wovon sie nichts wüssten."

#debian #keepassxc

cybso,
@cybso@osna.social avatar

@wonka trotzdem ist das nicht der richtige Weg. Wenn der Package maintainer meint es besser zu wissen als die Entwickler, dann soll er das Programm forken und unter eigenem Namen weiterführen.

Abgesehen davon wäre es auch nicht das erste Mal, dass Sicherheitslücken erst durch unsachgemäße Patches aufgetreten sind oder ausnutzbar wurden

@thepaffy

wonka,
@wonka@chaos.social avatar

@cybso Das ist leider wahr, und gerade Debian hat da ja ein bis zwei fulminante Fälle vorzuweisen.

@thepaffy

nixCraft,
@nixCraft@mastodon.social avatar

DNSCrypt-proxy is an open-source and free software designed to encrypt DNS traffic, thus protecting it from eavesdropping and manipulation. Let us see how to install DNSCrypt-proxy on a 11/12 with Adblocker or Malware blocker https://www.cyberciti.biz/faq/installing-dnscrypt-proxy-on-debian-linux/

tbroyer,
@tbroyer@piaille.fr avatar

@nixCraft Using it with Pi-Hole for a couple years or so, works like a charm!
Didn't know it has built-in support for blocking, but Pi-Hole at least has a great Web UI with stats et al. 😉

mort,
@mort@fosstodon.org avatar

The whole thing is kinda giving me second thoughts wrt. the whole distro and packaging thing in general. My understanding of the implied agreement between me as a dev and a distro's package maintainer is: the maintainer, to the best of their ability, tries to make my software work "as intended". In return, they get to publish it under my software's name.

That's clearly not how Debian views things. And I can't accept distros publishing broken sw w/ my name.

mort,
@mort@fosstodon.org avatar

@deshipu Yeah, I get that. But the "threat model" here isn't really "someone else writes different software and releases it under the same name as my software", but "Debian takes my source code, breaks it in key ways, and releases it under the same name"

deshipu,
@deshipu@fosstodon.org avatar

@mort Yeah, using a modified license is a very good way of ensuring that Debian will never package it.

triskelion,
@triskelion@floss.social avatar

I see some people are really disappointed about Debian packaging a stripped-down version of KeePassXC. But hey, I actually wish there was also a minimal @thunderbird package without integrations of IRC or Matrix etc, just with core email functionality.

#Debian #Thunderbird #Email #Neomutt

triskelion,
@triskelion@floss.social avatar

@thunderbird I joined Mozilla Connect just to submit this proposal. From what I've seen, submissions on there tend to be lengthy paragraphs lacking in clarity. I've written it in the structured style of Fedora changes, thanks to @Conan_Kudo :P

thunderbird,
@thunderbird@mastodon.online avatar

@triskelion @Conan_Kudo Okay, thanks not only for posting the submission AND for doing it with such an awesome template! (We're sort of a fan of Neal's here!)

nixCraft,
@nixCraft@mastodon.social avatar

How to enable 12 Backports repository https://www.cyberciti.biz/faq/install-enable-debian-linux-12-backports-repository/ Learn how to enable, install, and search for packages from the Debian Linux 12 "bookworm" Backports repository in this quick tutorial.

CodingThunder,
@CodingThunder@mastodon.social avatar

@nixCraft Your "/faq/" pages aren't shown on the homepage and in the RSS feeds. I'd love to be able to subscribe to them with my RSS client

nekohayo,
@nekohayo@mastodon.social avatar

The attitude shown by the packager who insists on going against the will of @keepassxc devs, in this comment: https://github.com/keepassxreboot/keepassxc/issues/10725#issuecomment-2104401817 is… wow 🤦

This "packagers thinking they know better than the developers, and unilaterally patching things" mentality, along with distros often shipping outdated versions, is why many upstream software developers dislike dealing with Debian (& any LTS distro), and now ask users to test/run versions of their applications first and foremost.

matk,
@matk@mastodon.social avatar

@nekohayo @keepassxc Honestly, that sounds like a reasonable take, especially considering the reply of the former maintainer below.
Still, a compromise in providing both the full and a hardened minimal version could surely be done to make everyone happy with it, that's what is done with Nginx and many other packages as well.

alxlg,
@alxlg@mastodon.social avatar

@nekohayo @keepassxc

Flatpak is indeed a platform for third-party apps while distros never were, they are called "distributions" for a reason. Distros' packages serve a different purpose that is: reconfiguring an OS (sometimes to include more apps) so of course a distro modifies upstream projects to integrate them.

That said, does Flatpak platform already provide the API needed by those KeepassXC features? When the needed API are (yet) not available the distro's manual integration is needed

elainefs, Portuguese
@elainefs@mastodon.social avatar

Saiu a correção da lib que estava ocasionando erro de acentuação no

Kiloku,
@Kiloku@burnthis.town avatar

@elainefs Era isso q quebrava a digitação no whatsapp?

scy,
@scy@chaos.social avatar

Well I'm not sure I agree with your decision to automatically set up systemd-boot as my UEFI boot manager just because I'm installing the systemd-boot package.

I literally just wanted to read the manpage and play around with bootctl.

I especially disagree with your decision to first fuck with my existing, working GRUB2 installation and then copy kernel and initrd to /boot/efi, which turns out to be not large enough on my system, leading to a somewhat broken boot setup.

iameru,
@iameru@leipzig.town avatar

@scy that sucks. Sounds like one of the reasons why I am so happy about hourly btrfs snapshots of everything under the sun including /boot, / or even /etc as a subvolume.. I can roll back with a few commands.
Good luck with the clean up 😬

scy,
@scy@chaos.social avatar

@iameru It's not so bad, grub is still working, but it broke secure boot for some reason.

Reinstalling grub might just fix it, but I have 100 things on my plate right now …

haploc,
@haploc@fedi.cr-net.be avatar

Fun times trying to rescue a botched grub on a 12 with btrfs as rootfs.
Made it. 💪

jan,
@jan@kcore.org avatar

@haploc cough ZFS cough

haploc,
@haploc@fedi.cr-net.be avatar

@jan it was not a btrfs problem, just how do I mount this stuff to fix grub :-P

scy,
@scy@chaos.social avatar

hmmm since I'll be using anyway, I might as well use systemd-boot instead of grub … 🤔

scy,
@scy@chaos.social avatar

@gd2 @dunkelstern Yes, according to https://wiki.debian.org/SecureBoot#Supported_architectures_and_packages Debian comes with pre-signed GRUB and kernel, shim is also available.

I'm kind of a noob when it comes to how SB works, but the way I understand it, since sd-boot only works with UKIs, I need to combine Debian's signed kernel and initramfs into a UKI and thus self-sign anyway.

gd2, (edited )
@gd2@chaos.social avatar

@scy @dunkelstern Ah sorry, then I skipped a lot of steps in my initial reply.

So from the wiki page, only shim is signed by Microsoft, the others (including GRUB) are signed by Debian, which tracks with what I know. So the Microsoft signed shim is required if you want to use SB but not roll your own keys, as most consumer hardware has only the Microsoft CA installed and not the Debian one. Instead, shim contains the Debian CA and then verifies the Debian signed GRUB, I believe. [1/3]

zwovierzwo,

Mal eine Frage in die Gemeinschaft.
Vor längerer Zeit hatte ich Mal eine Anleitung wie man in ein stable einbaut das manche (nicht alles) Pakete aus dem oder installiert werden. Mit allen Risiken ich weiß.

Leider finde ich die nicht mehr.
Hat hier jemand einen Tipp 🤔

Danke schon mal

txt_file,
@txt_file@chaos.social avatar

My #debian testing tries to install snapd.
Can I see #gentoo or #FreeBSD again? I do not want Canonical® snapd™.

Bad enough that libpipewire-0.3-modules (version 1.0.5-1) has a dependency to libsnapd-glib-2-1. :puke:

zirias,
@zirias@bsd.cafe avatar

@txt_file Didn't you know, to build software you absolutely need npm, cargo, nuget, pip, .... and MAKE SURE to always specify EXACT VERSIONS, you can easily deploy all that stuff with snap, appimage, flatpak, or better play it safe and just deploy docker images!!!!

Ladies&Gentlemen:

txt_file,
@txt_file@chaos.social avatar

@zirias dependency management ist so 1990s. Let's just ship an image of developers notebook to customer.

eugenialoli,
@eugenialoli@mastodon.social avatar

On 11, the whole system along with was taking 500 MB of RAM. On Debian 12, the system takes 850 MB of RAM. On Trixie/Sid-unstable, it takes 1.3 GB. I honestly don't know what they're shoving in it.

With and , it takes 1.6 GB on idle. Since when Cinnamon, a gnome2/gtk3 fork takes (or should take) as much RAM as Gnome4/gtk4? Something's amiss.

nekohayo,
@nekohayo@mastodon.social avatar

@eugenialoli With kernel caching etc. (i.e. "unused RAM is wasted RAM"), is it still meaningful to compare total RAM usage across DEs, vs analyzing individual RAM usage of components/applications to look for a more specific anomaly?

But even then, my observation in the past few years is that the more RAM you have available in a system, the more it tends to use it anyway.

ecadre,
@ecadre@mastodon.social avatar

@nekohayo Debian running on my "new" computer habitually uses more RAM than my old computer had in total.

I'm wondering what else this RAM is supposed to be doing if not used by my computer?

xtaran,
@xtaran@chaos.social avatar

merge request list down to a single page again. Phew!

LaKorin, French
@LaKorin@travelpandas.fr avatar

Ok, je sèche.
Je voudrais connecter mon iphone 12 mini a mon sony vaio violet trop mignon sous debian 12.
J'ai suivit pas à pas ceci : https://wiki.debian.org/fr/iPhone
et je n'arrive toujours pas a accéder à mes photos, ni même au contenu de mon iphone. Par contre il est reconnu en partage de connexion...
Des idées ?
PS : pas la peine de me proposer autre chose, c'est ça que je veux faire

Le repouet fait pouet pouet

LaKorin,
@LaKorin@travelpandas.fr avatar

@Phipe 🤣 🏏

Phipe,
@Phipe@diaspodon.fr avatar

@LaKorin 🤐

  • All
  • Subscribed
  • Moderated
  • Favorites
  • debian
  • PowerRangers
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • InstantRegret
  • ngwrru68w68
  • Youngstown
  • everett
  • slotface
  • rosin
  • khanakhh
  • GTA5RPClips
  • kavyap
  • thenastyranch
  • provamag3
  • Durango
  • cubers
  • tester
  • vwfavf
  • mdbf
  • cisconetworking
  • tacticalgear
  • modclub
  • normalnudes
  • osvaldo12
  • Leos
  • anitta
  • megavids
  • All magazines