9to5linux, to linux
@9to5linux@floss.social avatar

Weekly Roundup for April 14th, 2024: 24.04 LTS enters public beta testing, devs need branch maintainer, explicit sync merged in and KWin, Live patched against XZ backdoor, 3.3, Ubuntu Pro for devices, new Gear and Frameworks releases, new all Linux laptop, updated installer, and more https://9to5linux.com/9to5linux-weekly-roundup-april-14th-2024

ricci, to security
@ricci@discuss.systems avatar

Hey! Let's talk about and !

If you've ever looked at SSH server logs you know what I'm about to say: Any SSH server connected to the public Internet is getting bombarded by constant attempts to log in. Not just a few of them. A lot of them. Sometimes even dozens per second. And this problem is not going away; it is, in fact, getting worse. And attackers' behavior is changing.

The graph attached to this post shows the number of attempted SSH logins per day to one of @cloudlab s clusters over a four-year period. It peaks at about 3.4 million login attempts per day.

This is part of a study we did on our production system, using logs of more than 640 million login attempts, covering more than 1,500 hosts on our side and observing more than 840 thousand incoming IP addresses.

A paper presenting our analysis and a new, highly effective means to block SSH brute force attacks ("Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them") will be presented next week at by @sachindhke . The full paper is at https://www.flux.utah.edu/paper/singh-nsdi24

Let's dive in. 🧵

ricci,
@ricci@discuss.systems avatar

First things first: everyone "knows" that most brute force attacks are against the "root" account, right? This is certainly what earlier studies have found.

As it turns out, this used to be true, but it's not anymore. This graph shows that the fraction of brute force attacks using the username root was nearly 100% back in 2017, but it's been falling - by mid-2021, only around 20% off the attacks we saw were against root.

So, why? Well, we don't have a hotline to the attackers, but we have an educated guess from our own data and from many others' reporting: a lot of the usernames we see correspond to default usernames for , specific distributions, specific server software, and devices. Basically, as we connect ever more stuff to the Internet (and generally try to protect the "root" account), attackers seem to be diversifying the accounts they are going after.

(There's a table of the top 100 usernames in the paper.)

9to5linux, to ubuntu
@9to5linux@floss.social avatar
Edent, to fediverse
@Edent@mastodon.social avatar

🆕 blog! “The Fediverse of Things”

One of the most frustrating things in modern technology is the effort spent trying to artificially restrict abundance. Take, for example, this tale from museum-worker Aaron Cope: I was out with a friend who worked for Twitter and I asked them whether it would be possible for the museum to “create 200,000 Twitter accounts, one […]

👀 Read more: https://shkspr.mobi/blog/2024/04/the-fediverse-of-things/

steve,
@steve@social.technoetic.com avatar

Inspired by the article written by @Edent on the Fediverse of Things (, ), I experimented with using an LLM to interpret home automation requests that could be sent using and convert them to JSON device commands. I documented the results in the following blog article:
https://www.stevebate.net/fediverse-of-things-and-llms/

blog, to fediverse
@blog@shkspr.mobi avatar

The Fediverse of Things
https://shkspr.mobi/blog/2024/04/the-fediverse-of-things/

One of the most frustrating things in modern technology is the effort spent trying to artificially restrict abundance.

Take, for example, this tale from museum-worker Aaron Cope:

I was out with a friend who worked for Twitter and I asked them whether it would be possible for the museum to “create 200,000 Twitter accounts, one for each object in the Cooper Hewitt’s collection”. My friend looked at me for a moment, laughed, and then simply said: No.

In that blog post, Aaron reveals that the San Francisco International Airport Museum is using ActivityPub to create automated social-media bot accounts for all its exhibits and, possibly, every object it hold.

And why not! That would be close to impossible to do on a centralised service. But on a decentralised service under your own control, it is relatively simple. Perhaps I only want to follow the museum's canteen, or I just want to engage with a specific artefact. The Fediverse makes that possible.

This reminds me of the Melbourne "treemail" phenomenon. Every tree in the city had an email address, ostensibly so residents could email maintenance issues for a specific tree. Instead, people started interacting with the trees and sending them little love notes!

Dearest Golden Elm Tree, I finally found you! As in I see you everyday on my way to uni, but I had no idea of what kind of tree you are. You are the most beautiful tree in the city and I love you

A few weeks ago, I read about Ben Smith inventing Tweeting trains. With a bit of code, every train line in the UK was suddenly represented on the web in a convenient format. Well… Convenient if you were on Twitter.

Museums, trees, and trains naturally brings me on to the Internet of Things. I think it is fair to say that IoT is in a bit of an odd place right now. Matter is a confusing mishmash of standards. Security and privacy issues dog the simplest devices. Many people don't even want their toaster online!

For the majority of domestic uses, people want an Intranet of Things. There's little need to have your light-bulbs controlled when you're outside of WiFi range. Similarly, it is probably a really bad idea to have your hydroelectric dam connected to the Internet.

Which brings me back to the Fediverse.

On the one hand, it would be nice to be able to follow @Yellow_Line@Transit_Authority.gov - or even @Bus_Stop_1234@bus_company.biz - that would allow for hyperfocused data getting to the right people. It seems feasible that every civic object could have a Fediverse account. From the individual streetlights to the municipal sewerage system. Perhaps people won't send love letters to overflowing drains - but a social-dashboard of your civic environment could be both practical and delightful.

And, as for your domestic gadgets? Why not give every room, or every light-bulb, in your home a private Fediverse account? You could send a message like:

Hey @thermostat, please set the temperature to 19°C. Thanks!

That might be a bit much! But I like the idea of a private social network which consists of all my IoT gadgets talking to me and each other.

https://shkspr.mobi/blog/2024/04/the-fediverse-of-things/

attacus, to accessibility
@attacus@aus.social avatar

This piece is worth reading if you’re in tech criticism or infosec/cybersecurity and are being asked for commentary on IoT and smart home devices.

People aren’t foolish for using IoT or for wanting things to be easier in their homes. This tech makes positive and meaningful change for people of all kinds of abilities. It’s valid to worry about the privacy or security issues that IoT is riddled with, but don’t draw a direct line from there to blaming the user - some people have no alternatives that don’t involve giving up independent access to their own homes and lives. Everyone deserves to live in ways that fit their needs.

Instead, join the push to hold manufacturers and providers to account for poor security and privacy practices. Advocate for better, more respectful and accessible default configurations. Help people understand how to anticipate and mitigate the worst of these issues when they’re setting things up, and give them power and agency over their home systems.

We all deserve to have tech that works for us, in all the ways that matters.




https://www.theverge.com/24080201/smart-home-accessibility-apple-nest-alexa

jbzfn, to sbc
@jbzfn@mastodon.social avatar

🤖 Duo S RISC-V/Arm SBC features Sophgo SG2000 SoC, Ethernet, WiFi 6, and Bluetooth 5 connectivity - CNX Software

「 Linux and RTOS are said to be supported on the Duo S, and you’ll find buildroot-built OS images on GitHub to boot from either the microSD card or the eMMC flash. As of the current v1.0.9 image, Duo S does not yet support wiringX (C) and pinpong (Python) GPIO libraries, and Arduino support is not implemented either 」

https://www.cnx-software.com/2024/03/25/duo-s-risc-v-arm-sbc-features-sophgo-sg2000-soc-ethernet-wifi-6-and-bluetooth-5-connectivity/

Edent, to homeassistant
@Edent@mastodon.social avatar

🆕 blog! “Receive push notifications from your rice cooker”

I have a lovely, and reasonably priced, Mini Panda Rice Cooker. It does not have any SmartHome features. You put in water and rice, press a button, it cooks rice. Nice! The only problem is - I don't know how long the rice will take to cook. It uses "Fuzzy Logic" to work out exactly […]

👀 Read more: https://shkspr.mobi/blog/2024/03/receive-push-notifications-from-your-rice-cooker/

ResearchLux, to Futurology
@ResearchLux@mastodon.opencloud.lu avatar

Turning 🔬 into 🚀

🛗In the 4th episode of video series, discover DataThings, company of the Interdisciplinary Centre for Security, Reliability and Trust (SnT) of the University of Luxembourg.

The company offers customised digital twin solutions to help solve complex industrial problems and support sustainable operational decisions.

https://www.youtube.com/watch?v=4Jp3dFvh3-o&ab_channel=SiliconLuxembourg

orhun, to rust
@orhun@fosstodon.org avatar

Today I found a TUI for handling message queues! 🚀

📨 mqttui: Subscribe to a MQTT Topic or publish something quickly from the terminal.

🌐 Perfect for managing IoT applications! 💡
🦀 Written in Rust & built with @ratatui_rs

⭐ GitHub: https://github.com/EdJoPaTo/mqttui

asymptotic, to linux
@asymptotic@floss.social avatar

A long pending post from @sanchayan on how we implemented ALSA compress offload support in @pipewire

https://asymptotic.io/blog/pipewire-compressed-offload/

thejapantimes, to business
@thejapantimes@mastodon.social avatar
mysk, to security
@mysk@mastodon.social avatar

Connected devices offer great convenience, but often at the expense of and . Pressured by the competition, teams fail to thoroughly test their systems. The following is a great example of convenience vs. security:

https://youtu.be/7IBg5uNB7is

hl, to RaspberryPi
@hl@social.lol avatar

It lives! Now my home sensor network has a way to see the data, thanks to a locally hosted website: https://www.henryleach.com/2024/02/home-sensor-network-part-7-visualisation-website

#projects #raspberrypi #iot #flask #python #plotly

pseudonym, to infosec
@pseudonym@mastodon.online avatar

The "S" in "IoT" is for "security".

rkaramandi, to Podcast
@rkaramandi@techhub.social avatar

Another month means another @homeassistant release!

2024.3 brings features we've wanted, and so many more we didn't know we needed. Phil and I break down this months features in the latest episode of the @homeassistant

https://youtu.be/5g2sjZ2DSOk

FlockOfCats, (edited ) to random
@FlockOfCats@famichiki.jp avatar

This video in the mansion pamphlet doesn’t work wtf

FlockOfCats,
@FlockOfCats@famichiki.jp avatar

@soycamo

I knew the Internet of Things was just empty hype!

tekkie, to Software
@tekkie@mstdn.social avatar

We’ve reached the point of having to patch the of your shoes.

jeridansky, to tech
@jeridansky@sfba.social avatar

LOL: HP wants you to rent a printer from the company via its new subscription service.
https://arstechnica.com/gadgets/2024/02/hp-wants-you-to-pay-up-to-36-month-to-rent-a-printer-that-it-monitors/

My suggestion: Just follow The Verge's advice and buy a Brother laser printer. I'm very happy with mine — something I never expected to say about a printer.
https://www.theverge.com/23642073/best-printer-2023-brother-laser-wi-fi-its-fine

BarbChamberlain,
@BarbChamberlain@toot.community avatar
AAKL, to Cybersecurity
@AAKL@noc.social avatar

Tenable launches new platform to improve visibility across attack surfaces https://betanews.com/2024/02/29/new-platform-improves-visibility-across-attack-surfaces/ @betanews @iandbarker

AAKL, to Cybersecurity
@AAKL@noc.social avatar
KathyReid, to TwitterMigration
@KathyReid@aus.social avatar

It's been a while since I did an #Introduction #Introductions #TwitterMigration #Connections post where I curate interesting accounts for you to follow in the #Fediverse :fediverse:

Firstly, a warm welcome to @russell_stuart - Russell is the Treasurer of @linuxaustralia and of this year's @everythingopen, which is happening in #Gladstone in about 6 weeks.

Russell is an unsung hero of #OpenSource in Australia - it's his diligence and hard work that has kept the books straight for Linux Aus and auspiced conferences for several years now 👋

@gombang is a tech journalist from Indonesia 🇮🇩, #Wikipedian. Posts in #bahasaIndonesia and also #BasoMinangkibau 👋

@histoftech is a #Professor and historian of #technology and you can catch them talking about their work in about 12 hours with the @WomeninAIethics presentation 👋

@iot is the monthly #IoT meeting for folks in #Brisbane #Meanjin #BNE 👋

@mikrotik is the official account for Mikrotik, who make #networking gear like routers 👋

@quinn does a lot of work with decentralized technology @fission and has an interest in #programming languages 👋

That's all for today, don't forget to share your own lists so together we can more richly connect the #Fediverse ❤️

Edent, to homeassistant
@Edent@mastodon.social avatar

🆕 blog! “Review: Matter-enabled Energy Monitoring Smart Plugs - Meross 315”
★★★★★

Matter is coming to fix all your smarthome woes! A single IoT standard, working across multiple radio protocols, bringing together different products from many different manufacturers. And… it works! Mostly These are the Meross 315 Smart Plugs. They are …

👀 Read more: https://shkspr.mobi/blog/2024/02/review-matter-enabled-energy-monitoring-smart-plugs-meross-315/

Edent, to homeassistant
@Edent@mastodon.social avatar

Has anyone here used a #Matter smart plug to detect when an electrical appliance has finished doing something?

For example, I want to plug in my rice cooker and get an alert on my phone when its electrical use drops to zero.

Ideally using something like #HomeAssistant - but I'm not fussed.

(Looking for people with direct & personal experience; I know how to use Google. Also, not looking for your criticisms of #IoT.)

Edent,
@Edent@mastodon.social avatar

Thanks to a tip from @dis I can now get alerts from when a smart-plug stops providing electricity.

https://github.com/leofabri/hassio_appliance-status-monitor

That's a good way to upgrade old appliances to .

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • modclub
  • everett
  • rosin
  • Youngstown
  • slotface
  • ethstaker
  • mdbf
  • kavyap
  • osvaldo12
  • DreamBathrooms
  • anitta
  • Durango
  • ngwrru68w68
  • tester
  • khanakhh
  • love
  • tacticalgear
  • cubers
  • GTA5RPClips
  • Leos
  • normalnudes
  • provamag3
  • cisconetworking
  • JUstTest
  • All magazines