Replies

This profile is from a federated server and may be incomplete. Browse more on the original instance.

uncanny_static, to random
@uncanny_static@chaos.social avatar

Going home now. Exhausted, but super sad that the GPN is over.

uncanny_static,
@uncanny_static@chaos.social avatar

This has been my first chaos event. I had expected a bunch of interesting and nerdy stuff, but I was not expecting to meet so many queer folks and such a colorful event. So wholesome vibes everywhere. ❤️🧡💛💚💙💜

uncanny_static,
@uncanny_static@chaos.social avatar

I would say that the quiet hackcenter was a big success. It was filled most of the time. So I guess even neurotypical folks enjoy a quiet space to retreat for a while. I wish, more events would offer those.

uncanny_static,
@uncanny_static@chaos.social avatar

@ljrk ❤️

uncanny_static,
@uncanny_static@chaos.social avatar

@ljrk Here too. For a train that was announced to have an "exceptionally high demand" it is surprisingly empty. Like, only half the seats taken.

grueproof, to random
@grueproof@fosstodon.org avatar

If you can’t get to it without an app or account, it’s not a podcast.

uncanny_static,
@uncanny_static@chaos.social avatar

@grueproof Yes! 👏 And on top of that: if it does not have an RSS feed, it is not a podcast. 🙃

PixelPerfectEngine, to gamedev
@PixelPerfectEngine@peoplemaking.games avatar

Can someone help me in middleware development?

How do I stop my own windows (the one with the giant X) from looking like they're out from the early 2010's? I really want to throw out SDL from my engine ASAP.

uncanny_static,
@uncanny_static@chaos.social avatar

@PixelPerfectEngine What do you mean? What is the issue?

scy, to random
@scy@chaos.social avatar

What's the first music video you remember seeing?

For me, it's Eurythmics' "Here Comes the Rain Again", must've been something like 1988.

uncanny_static,
@uncanny_static@chaos.social avatar

@scy Well... Must have been some sort of Euro Dance on Viva. People dancing in front of 90s flashing backgrounds. The first one that really stuck with me, tough, was Linkin Park's "In the End".

jacqueline, to random
@jacqueline@chaos.social avatar

is there any easy way on mastodon to find out if i've already asked someone about something in a dm?

uncanny_static,
@uncanny_static@chaos.social avatar

@jacqueline Ask them and if they complain that you have already asked that question you probably did. 😉

uncanny_static,
@uncanny_static@chaos.social avatar

@jacqueline 😂 🤷‍♀️

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

#liblzma #xz #lzma #backdoor #ITsecurity #OpenSSH #SSH

uncanny_static,
@uncanny_static@chaos.social avatar

@scy Sorry, I am not buying this argument. Instead of using the official systemd library, developers should default to implementing their own version of a systemd-specific lowlevel socket protocol?

uncanny_static,
@uncanny_static@chaos.social avatar

@scy But why do you expect people to know that? The page you linked lists a bunch of C functions at the top. And people should know that they should ignore those and rather lookup the protocol and implement it themselves?

uncanny_static,
@uncanny_static@chaos.social avatar

@scy I am not saying that this attack has been solely enabled by systemd. Far from that.

However, I think it was a contributing factor. When you are interfacing with another piece of software the standard approach is to look for the official libraries and use them, if they exist. In this case, however, this drastically increased the attack surface. 1/3

uncanny_static,
@uncanny_static@chaos.social avatar

@scy Developers, in general, are not systemd experts and I do not think that they should be expected to know the inner workings of a systemd-specific protocol, even if it is that simple. Using the official library that implements such a basic functionality should not create a large attack surface. 2/3

uncanny_static,
@uncanny_static@chaos.social avatar

@scy IMHO, one of the lessons to be learned here is that such a functionality should be provided by a library that is as simple and small as possible, and not expect people to implement the functionality themselves despite there being officially supported libraries for that. That is just not how people work and "roll your own" is usually considered bad practice. 3/3

uncanny_static, to openSUSE
@uncanny_static@chaos.social avatar

Unfortunately, openSUSE Tumbleweed already includes version 5.6.1 of liblzma. Hence, if you are using Tumbleweed, your system might already be affected.
https://www.openwall.com/lists/oss-security/2024/03/29/4
#openSUSE #Linux #liblzma #lzma #xz #ssh #infosec

uncanny_static,
@uncanny_static@chaos.social avatar

OpenSSH in openSUSE also seems to be patched to link to libsystemd, thus linking to liblzma. Hence, Tumbleweed should be affected. 😔

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • kavyap
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • magazineikmin
  • modclub
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • Durango
  • tacticalgear
  • JUstTest
  • ngwrru68w68
  • everett
  • normalnudes
  • cubers
  • tester
  • thenastyranch
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • megavids
  • anitta
  • Leos
  • lostlight
  • All magazines