Posts
347
Following
95
Followers
3725
repeated

Unpopular opinion: a vulnerability that was disclosed privately by researchers and had a coordinated response from vendors and service operators under an (albeit short) embargo is not a β€œ0-day”.

1
1
0
repeated
Edited 20 hours ago

Next week I'll have a talk at Open Source Summit Japan πŸ‡―πŸ‡΅:

"We need an open source phone OS - postmarketOS!"

If you are there in-person, say hello, and otherwise a live stream (December 10th, 11:40 UTC+9) should be available, and the recording will appear also at some point!

https://ossjapan2025.sched.com/event/29Fpa/

1
5
0
The European Union has now published a great page about the Cyber Resilience Act that contains a 66 page FAQ about lots of things in "plain english": https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation
0
19
38
The last 5.4.y kernel release has now happened: https://lore.kernel.org/all/2025120319-blip-grime-93e8@gregkh/

Please don't use this branch anymore, it's really old, and pretty obsolete, and has over 1500 unfixed CVEs in it:
https://lore.kernel.org/all/2025120358-skating-outage-7c61@gregkh/

And if you are stuck with that kernel version for some reason, go ask your vendor to fix those 1500+ CVEs, otherwise you are paying for support that doesn't actually do anything for you...
5
27
35
repeated
As pointed out on an irc channel, yet another example of kernel developers having to do crazy things to paper over hardware bugs: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f076ef44a44d02ed91543f820c14c2c7dff53716
5
40
40
It has now been 0 days since a AI-hallucinated "security report" was sent to the kernel security team.

Right now we seem to be averaging about 1 per week, not bad overall probably compared to other projects.

To be fair, a real security bug was recently found with an "ai tool", but the authors of that at least took the time to verify it was real before sending it to us, and they provided a patch, so not all is doom and gloom.
3
42
102
repeated

The European Union Agency for Cybersecurity (ENISA) is now a Root in the CVE Program

https://www.cve.org/PartnerInformation/ListofPartners/partner/ENISA

0
3
0
repeated

"If you're not using the stable kernel, your system is insecure. [...]
I'll call out Debian: Debian tracks our kernels very well. Debian runs the world. Over 70% of all servers in the world run Debian. Everything else is a rounding error [...]
πŸ‘‰ Debian: really, really good. I work with the Debian developers all the time. I can't recommend them enough. Their systems are good.
πŸ‘‰ RedHat, SUSE: they have their own weird systems -- talk to them, you're paying them."

@gregkh at https://youtu.be/dhu8HSOzxd8?t=1226

1
4
1
repeated

K. Ryabitsev-Prime 🍁

How big is lore.kernel.org? I counted 17,154,017 unique message-ids.

I think that's roughly how many emails @gregkh replies to every day.
0
7
26
repeated

Thorsten Leemhuis (acct. 1/4)

Edited 21 days ago
0
3
1
repeated
Edited 12 days ago

First time in South Korea. Three talks in two days. Over 200 minutes of public speaking. Two packed rooms. Made new connections. (My luggage arrived four days after me. πŸ˜…)

This week was very intense, and I’ll never forget this first visit to Seoul. I’m a bit exhausted right now, but really grateful.

Thanks, Korea! πŸ™πŸΌπŸ‡°πŸ‡·β™₯️

Abstracts, slides and videos: https://embeddedor.com/blog/2025/11/08/presenting-at-open-source-summit-korea-2025/

Linux Kernel Self-Protection Project πŸ›‘βš”οΈπŸ§

0
3
2
As seen in the Seoul Lablup office (https://www.lablup.com/) when visiting the other day right before the OSS Korea conference. Many thanks to them for the good conversations, and food and beer!
3
12
37
repeated

Jarkko Sakkinen

I sometimes wish that I'd see more "Skilled Skateboarders" than "Skilled Board Members" at LinkedIn. World would probably be a better place if that would ever happen.
2
4
12
repeated

A Halloween Horror Story:

"We're in and we've broken containment - we really are living in a virtual universe"
"That near endless string of symbols is our universe"
"Yes"
"But why one giant string of noise ?"
"Is that a regexp... ?"
"Oh my god, we're living in a perl one liner!"

1
3
0
repeated

I'm always hyping perfetto, because it's *really really* cool! Lalit does amazing work and has been super helpful sharing his knowledge on both how to do things in perfetto and even how to add features to the code for things I found missing. So it's great to see his post about his presentation from the Tracing Summit.

One neat thing in the talk is the examples show how perfetto can also ingest and visualize perf and trace-cmd output if those tools for capturing data are more familiar then perfetto's own!

https://lalitm.com/perfetto-swiss-army-knife/

1
10
2
repeated
Edited 1 month ago

** Speaker announcement ** Our first speaker is @gregkh, Linux kernel developer and Fellow at
 @linuxfoundation.

Info & tickets:
https://2026.rustweek.org

Ahead of our CFP we will be announcing our invited speakers. Also want to speak at RustWeek? Our CFP opens Nov 1st.

1
3
1
repeated

K. Ryabitsev-Prime 🍁

"This makes me 20% more productive!"
"So does cocaine."
4
23
39
repeated

X is where you find the people who think they run the Internet.

Bluesky is where you find the people who think they ought to run the Internet.

Mastodon is where you find the people who actually do run the Internet, and kind of wish they didn't.

(WIth apologies to Yes, Minister)

2
48
4
repeated

So, this is what you meant, Arch Linux, right?

10
23
3
Show older