Debian — The Universal Operating System

linuxmagazine,
@linuxmagazine@fosstodon.org avatar
RL_Dane,
@RL_Dane@fosstodon.org avatar

@amin, have you gotten scli to work in ?

I gave up because pipx refuses to install urwid, and I think Debian's version is drumroll way too old. ;)
I wish pipx just had scli. There's an scli package in PyPI, but it's literally an empty placeholder for nothing.
Infuriating.

tripplehelix,
@tripplehelix@fosstodon.org avatar

@RL_Dane @amin I can't see it in Sid, so F

eugenialoli,
@eugenialoli@mastodon.social avatar

The funny part about the removal of networking from the default package on , is that they did it for "security" reasons, without thinking that the MOST INSECURE way to transfer a to your is via the CLIPBOARD. Absolutely every running app or service can read the clipboard! And yet, that's the default way they expect users to do it now!

That maintainer didn't think it through at all.

jbzfn,
@jbzfn@mastodon.social avatar

🌀 16 years of CVE-2008-0166 - Debian OpenSSL Bug
— 16years.secvuln.info

"A patch in Debian's and Ubuntu's OpenSSL packages broke the random number generator, effectively limiting the number of possible keys to a few ten thousand plausible variations"

https://16years.secvuln.info/

9to5linux,
@9to5linux@floss.social avatar

Endless OS 6 Is Here Based on GNU/Linux 12 “Bookworm”, Here's What's New https://9to5linux.com/endless-os-6-is-here-based-on-debian-gnu-linux-12-bookworm

gnulinux, German
@gnulinux@social.anoxinon.de avatar

Gaming auf Debian und Derivaten Teil 2: Lutris

Der zweite Teil einer Serie, die sich damit befasst, wie man auf Debian/Ubuntu spielt und am besten Probleme schon im Voraus vermeidet.

https://gnulinux.ch/gaming-auf-debian-und-derivaten-teil-2-lutris

tripplehelix, (edited )
@tripplehelix@fosstodon.org avatar

How "unstable" is Experimental? I've been thinking of adding to Sid.

hrakaroozorn,
@hrakaroozorn@fosstodon.org avatar

@tripplehelix uncertain if joking, and if not, i apologize, but Sid is unstable https://wiki.debian.org/DebianUnstable

tripplehelix,
@tripplehelix@fosstodon.org avatar

@hrakaroozorn Oops, I meant Experimental/RC-Buggy

jschauma,
@jschauma@mstdn.social avatar

On the topic of "key rotation, it's not just for HTTPS", @hanno finds hundreds of DKIM keys apparently generated using the predictable PRNG vulenrability from 2008 (CVE-2008-0166):

https://16years.secvuln.info/

(And yes, is still stupid.)

isotopp,
@isotopp@chaos.social avatar

@jschauma

The question is, for whom that is a problem. DKIM signing mails is mostly to get Google to accept the mail, and not for anything useful.

bluelupo, German
@bluelupo@social.tchncs.de avatar

Debian spaltet KeePassXC auf - LinuxNews.de

Schade das der Maintainer des Debian-Paketes nicht ansatzweise die Funktionalität eines Passwortmanagers verstanden hat. Meiner Meinung nach missbraucht hier ein Paketbetreuer seine Kompetenzen. Letzlich schadet er mit seiner Vorgehensweise Debian insgesamt als Linuxdistribution.

https://linuxnews.de/debian-spaltet-keepassxc-auf/

gischpelino,
@gischpelino@mastodon.online avatar

@goebbe @bluelupo aber anders herum wäre es besser und Debian konform. KeepassXC mit vollem Funktionsumfang, wie gewohnt und erwartbar, und daneben eine KeepassXC-tiny ohne die Netzwerk- und Browserfunktionen anbieten.

allo,
@allo@chaos.social avatar

@gischpelino
vim-full ist auch nicht das default. Glücklicherweise, denn die meisten brauchen gar nicht alle Funktionen.

@goebbe @bluelupo

debacle,
@debacle@framapiaf.org avatar
thepaffy, German
@thepaffy@osna.social avatar

Wenn der Package-Maintainer die Software die er packertiert selber nicht nutzt... Ich hab schon wieder massive Kopfschmerzen...

"...schreibt Klode, dass er die [...] diese Funktionen entfernt. Diese dienten vermutlich dem Nachladen eines favicon einer Webseite, meint der Maintainer. Er gehe davon aus, dass die meisten Leute nicht wollten, dass ihre Passwort-Manager irgendwohin verbinden, wovon sie nichts wüssten."

#debian #keepassxc

cybso,
@cybso@osna.social avatar

@wonka trotzdem ist das nicht der richtige Weg. Wenn der Package maintainer meint es besser zu wissen als die Entwickler, dann soll er das Programm forken und unter eigenem Namen weiterführen.

Abgesehen davon wäre es auch nicht das erste Mal, dass Sicherheitslücken erst durch unsachgemäße Patches aufgetreten sind oder ausnutzbar wurden

@thepaffy

wonka,
@wonka@chaos.social avatar

@cybso Das ist leider wahr, und gerade Debian hat da ja ein bis zwei fulminante Fälle vorzuweisen.

@thepaffy

nixCraft,
@nixCraft@mastodon.social avatar

DNSCrypt-proxy is an open-source and free software designed to encrypt DNS traffic, thus protecting it from eavesdropping and manipulation. Let us see how to install DNSCrypt-proxy on a 11/12 with Adblocker or Malware blocker https://www.cyberciti.biz/faq/installing-dnscrypt-proxy-on-debian-linux/

tbroyer,
@tbroyer@piaille.fr avatar

@nixCraft Using it with Pi-Hole for a couple years or so, works like a charm!
Didn't know it has built-in support for blocking, but Pi-Hole at least has a great Web UI with stats et al. 😉

mort,
@mort@fosstodon.org avatar

The whole thing is kinda giving me second thoughts wrt. the whole distro and packaging thing in general. My understanding of the implied agreement between me as a dev and a distro's package maintainer is: the maintainer, to the best of their ability, tries to make my software work "as intended". In return, they get to publish it under my software's name.

That's clearly not how Debian views things. And I can't accept distros publishing broken sw w/ my name.

mort,
@mort@fosstodon.org avatar

@deshipu Yeah, I get that. But the "threat model" here isn't really "someone else writes different software and releases it under the same name as my software", but "Debian takes my source code, breaks it in key ways, and releases it under the same name"

deshipu,
@deshipu@fosstodon.org avatar

@mort Yeah, using a modified license is a very good way of ensuring that Debian will never package it.

triskelion,
@triskelion@floss.social avatar

I see some people are really disappointed about Debian packaging a stripped-down version of KeePassXC. But hey, I actually wish there was also a minimal @thunderbird package without integrations of IRC or Matrix etc, just with core email functionality.

#Debian #Thunderbird #Email #Neomutt

triskelion,
@triskelion@floss.social avatar

@thunderbird I joined Mozilla Connect just to submit this proposal. From what I've seen, submissions on there tend to be lengthy paragraphs lacking in clarity. I've written it in the structured style of Fedora changes, thanks to @Conan_Kudo :P

thunderbird,
@thunderbird@mastodon.online avatar

@triskelion @Conan_Kudo Okay, thanks not only for posting the submission AND for doing it with such an awesome template! (We're sort of a fan of Neal's here!)

nixCraft,
@nixCraft@mastodon.social avatar

How to enable 12 Backports repository https://www.cyberciti.biz/faq/install-enable-debian-linux-12-backports-repository/ Learn how to enable, install, and search for packages from the Debian Linux 12 "bookworm" Backports repository in this quick tutorial.

CodingThunder,
@CodingThunder@mastodon.social avatar

@nixCraft Your "/faq/" pages aren't shown on the homepage and in the RSS feeds. I'd love to be able to subscribe to them with my RSS client

  • All
  • Subscribed
  • Moderated
  • Favorites
  • debian
  • PowerRangers
  • DreamBathrooms
  • osvaldo12
  • magazineikmin
  • InstantRegret
  • everett
  • Youngstown
  • ngwrru68w68
  • slotface
  • rosin
  • GTA5RPClips
  • tester
  • kavyap
  • thenastyranch
  • provamag3
  • mdbf
  • ethstaker
  • cisconetworking
  • Durango
  • vwfavf
  • normalnudes
  • tacticalgear
  • khanakhh
  • modclub
  • cubers
  • Leos
  • anitta
  • megavids
  • All magazines