@governa@fosstodon.org
@governa@fosstodon.org avatar

governa

@governa@fosstodon.org

Connoisseur. Raconteur. Globetrotter.
Linux aficionado. 🐧 FOSS evangelist. 🌱
May contain traces of nuts & the odd swear word.

•Opinions are my own•

#CyberSec #IT #HR #F1 #MMA #FOSS #Linux #E2EE #PGP #Meshtastic #LoRa #StandWithUkraine🌻

🦣 Joined 𝟵 𝗔𝗽𝗿 𝟮𝟬𝟭𝟴 (RIP mastodon.technology)

📍🇪🇺 | 🗣️ en,pt | ✔ provenb943a2

This profile is from a federated server and may be incomplete. Browse more on the original instance.

MostlyHarmless, to random
@MostlyHarmless@thecanadian.social avatar
jmwright, to space
governa, to linux
@governa@fosstodon.org avatar

12 Best Free Command Line Games for Users

https://www.tecmint.com/best-linux-terminal-console-games/

marquisdegeek,
@marquisdegeek@ohai.social avatar

@governa Let's hope my version of Pac-Man gets a mention in future versions of that list! :)

danielalbu, to random
@danielalbu@mastodon.gamedev.place avatar

Happy 27th anniversary to Winamp!

⚡🦙⚡
The first version of ⚡Winamp⚡ was released as freeware on April 21st, 1997!
⚡🦙⚡

Winamp, it really whips the llama's ass!

pafurijaz, to opensource
@pafurijaz@mstdn.social avatar
fsf, to random
@fsf@hostux.social avatar

We have recently made updates to the benefits that organizational Patrons receive, including additional donation tiers and more benefits. See all the tiers and current benefits at: https://u.fsf.org/3u2

ukscone, to random
@ukscone@fosstodon.org avatar
nergahak, to programming

Open Watcom V2 - This is the v2 fork of the Open Watcom suite of compilers and tools.
https://github.com/open-watcom/open-watcom-v2

ilumium, to Skydiving
@ilumium@eupolicy.social avatar

Holy shit, I thought I knew how evil the industry was but here we are:

Two-thirds of European websites just ignore your choice and track you anyways, researchers from found. 🤯

https://www.usenix.org/system/files/sec23winter-prepub-107-bouhoula.pdf

The_Whore_of_Blahbylon, to random
@The_Whore_of_Blahbylon@mastodon.social avatar
jsr, to random
@jsr@social.jsr.com avatar

You would be surprised at how much I would pay for this, if it actually existed.

thunderbird, to android
@thunderbird@mastodon.online avatar

When Thunderbird for Android is ready for release, what will the upgrade path from K-9 Mail look like? Will both apps co-exist? Where does Mozilla Sync fit in?

Alex answers some of your burning questions about our Android plans in this short clip from our recent Community Office Hours session.

https://tilvids.com/w/wGoySntAhuVxpnniETxaJG

#Android #Thunderbird #K9Mail

mina, to random
@mina@berlin.social avatar

Still need inspiration for Easter decoration?

Look no further than towards this super cute steampunk bunny by artist Sue Beatrice:

jwildeboer, to random
@jwildeboer@social.wildeboer.net avatar

I know the next 3-7 days will be filled with exaggeration and doomsday talk, but IMHO the backdoor, though seemingly meticulously planned for a long time, failed miserably as it was caught at a stage where it wasn't widely deployed but only in testing/prerelease distros. Yes, it made it quite far in the supply chain but it ultimately failed. The mess is being cleaned up, no cases of actual use of the exploit in the wild are known thus far. The immune system of FOSS has worked. Again.

MikeTelahun, to random

To everyone losing their shit over the xz/liblzma debacle: This is how Open Source is supposed to work: many eyes looking over work-in-progress to make sure it works as intended. Sometimes it’s reviewing source code commits and other times it’s looking over the behavior of pre-release software, noticing anomalous behavior and chasing down the commit that caused it. This is preciselywhy we have debian-testing and FreeBSD-Current. If anything this is validation that Open Source works

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

HT to @wdormann here - somebody has backdoored the open source project XZ which has downstream impacts.

For example, although OpenSSH doesn’t use XZ, Debian patch OpenSSH and introduced a dependency which translates as the XZ changes introducing a sshd authentication bypass backdoor it appears.

One dude bothered to investigate in his free time about why ssh was running slow, so it was caught fairly early - i.e. hopefully before distros started bundling it.

https://www.openwall.com/lists/oss-security/2024/03/29/4

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Back in 2022 a host of characters appeared and basically bullied the creator of the XZ project to hand it over to somebody else - at the time the guy cited mental health issues around not updating the project quickly.

At the time he was already talking about maybe handing over to the account who years later introduced the backdoor.

In mid 2023 said account introduced a change to Google’s OSS Fuzzer to weaken detection for XZ.

Somebody played a years long game of Jenga and lost.

GossiTheDog, (edited )
@GossiTheDog@cyberplace.social avatar

Postgres developer @AndresFreundTec saving Linux security from backdoors as a side of desk activity

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

Original maintainer of XZ repos has posted a short update:

https://tukaani.org/xz-backdoor/

HT @SamantazFox

governa, to linux
@governa@fosstodon.org avatar

Easy-to-use make-me-root exploit lands for recent kernels. Get patching.

https://www.theregister.com/AMP/2024/03/29/linux_kernel_flaw/

  • This exploit need local access to the machine.
  • "It was patched at the end of January, updates have been rolling out since then", straight from the article.
jwildeboer,
@jwildeboer@social.wildeboer.net avatar

deleted_by_author

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

#liblzma #xz #lzma #backdoor #ITsecurity #OpenSSH #SSH

scy, (edited )
@scy@chaos.social avatar

Meanwhile, #Debian is considering rolling #xz back not only to the point before the backdoor was added, but to where the person who wrote the backdoor hadn't contributed any code to xz yet.

Which means considering creating patches to fix ABI breakage such a rollback would cause.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024

For all the trash talk Debian gets for being "pedantic" and slow to change: They put in the work to do things right. I respect that.

via https://hachyderm.io/@joeyh/112181512951127467

(Edit: English is hard.)

per_sonne, to random Portuguese
@per_sonne@ciberlandia.pt avatar

Quick reminder that the XZ backdoor discovery and patching would take a lot longer and make many more victims along the way, if the code was proprietary and closed-source.

  • slapping the laptop with an open hand *
muzej, to Slovenia
@muzej@mastodon.social avatar

In 1983, Atari Corporation unveiled the Atari 800XL, a home computer boasting enhanced graphics and memory capacities. Renowned for its versatility, expandability, and an extensive array of software 🎮, it swiftly became a darling among enthusiasts and gamers alike during the golden era of home computing in the 1980s. What fond memories do you associate with this iconic machine?

brunomiguel, to random
@brunomiguel@masto.pt avatar

the xz repo on github was disabled by the platform

hackaday, to random
@hackaday@hackaday.social avatar

The recently discovered backdoor in the Linux xz package shows a remarkable level of sophistication. While the number of known compromised systems is relatively low right now, this may only be the tip of the iceberg.

https://hackaday.com/2024/03/29/security-alert-potential-ssh-backdoor-via-liblzma/

LinuxActual, to linux

Cuando me dice ¿Alguien realmente usa 😂

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines