Posts
1542
Following
216
Followers
1956
Director of Linux Foundation IT. Currently in charge of kernel.org infra.

This account is for Linux/Kernel/FOSS topics in general: #linux, #kernel, #foss, #git, #sysadmin, #infrastructure.

For my personal account, please follow @monsieuricon@castoranxieux.ca.

Montréal, Québec, Canada 🇨🇦🇺🇦
Edited 8 months ago

This year has been godawful on service operators on the net, the level of malicious garbage being slung is off the charts

In addition to The Big DDoS, SourceHut has seen about one layer 7 DDoS per week, and in any given week this year between 40 and 70% of all new accounts are spam. Our IP and email blocklists grew by several thousand entries this year.

I've spent basically all of my time in 2024 dealing with bullshit and none of my time doing anything useful for the platform or its users.

2
3
2
Edited 1 year ago

You know how young children will see some toy or shiny object on a store shelf, and somehow — by design! Marketers know what they’re doing! — they instantly •have• to have it, and are obsessed, and all sense and proportion go out they window and they need it now now NOW, but if they get it they soon abandon it because it’s junk that only looked good on the shelf?

It’s like that with CEOs and AI right now.

2
8
2
I just marked my linux kernel mails management tool as v1 (https://sjp38.github.io/post/hackermail_v1/). I hope it answers the questions on my mails management workflow, better than I did in the past.

#linux #kernel #hackermail
2
4
11
To help clear up some confusion:

DKIM and DMARC were not created to combat email spam, they were created to combat phishing. In fact, it is very easy for spammers to send DMARC-compliant mail via a spammer botnet, with a valid DKIM signature from Gmail (or any other large provider):

1. a spammer registers an account at gmail.com and sends a single spammy message to another Gmail account they control

2. they download that message, with all the headers, from their other account

3. they then send this same unaltered message to thousands of addresses via their spam botnet using a different envelope-from domain that has valid SPF entries matching the botnet

4. The spam email arrives 100% DMARC-compliant, because the SPF records matched the envelope-from domain and the DKIM signature matched gmail.com in the From: header

Google is fully aware of this, but they can't do anything to stop spammers from using this scheme -- at least not yet. They are pushing for "Replay-Resistant ARC" (https://datatracker.ietf.org/doc/draft-chuang-replay-resistant-arc/), which is why you will see a "darn=" header in the DKIM signature you get from gmail. However, even if they succeed in getting it adopted, we're still easily years away from it making any kind of impact on spam.
1
10
17
To paraphrase: "we reinvented the usenet not because it was easy, but because we thought it would be easy."
0
4
29
FYI, the Fedi spam problem is only starting out. It won't take much effort for someone to write a payload running on random compromised webservers to send copious amounts of spam via activitypub, making blocklists ineffective.

We will basically need to implement all the same anti-abuse stuff we're already doing for email in order to cope with it on the fediverse -- greylisting, dnsbl, domain authentication, etc.

Sadly, the only way this won't happen is if ActivityPub stays sufficiently niche to make other targets more popular for spammers.
16
117
181
In the face of hundreds of thousands murdered in Ukraine, and millions more displaced fleeing Russian military aggression, it is hard to focus on the death of one man. And yet, Navalny meant a lot to the Russian opposition and his death is just another proof that Putin's regime is criminal to the core and cannot be dealt with by appeasement or backroom deals. Ukrainians are the only force actively fighting the Kremlin mafia regime and we should continue to give them all they need to achieve a swift and decisive victory.
0
18
27
b4-0.13.0 is now available!

This is a quality-of-life release that improves on many features but doesn't add any new major functionality (yet).

https://lore.kernel.org/tools/20240215-refreshing-spotted-kiwi-ae2e99@lemur/T/#u
0
6
14

[$] A turning point for CVE numbers https://lwn.net/Articles/961978/

0
5
3

So what does the world do to stop russia from killing civilians and destroying cities and villages by bombing and shelling?
What does the world do to stop the genocide, forced re-education of children, deportation, torture in detention, starvation of people?
Why is this the new norm?

0
3
1
Linux is now a CNA: http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/

This has taken a long time, I'd like to thank all the groups that helped, and especially the CVE group themselves. Our application was a bit different than other groups, but they understood that this is important for security overall.
7
83
127
#Russia #NATO
Show content

General (Ret.) Wesley K. Clark, Former NATO Supreme Allied Commander on Donald Trump’s remarks

“On 9/11, when America was under attack, NATO nations all mobilized to come to our defense and fought alongside us to crush al Qaeda. They didn’t ask us for money. They didn’t put strings on it. That is the kind of iron-clad commitment that has kept Western democracies — including our own — alive for 75 years.

“For Donald to publicly signal to Vladimir that he can take as much of Europe as he wants, and we will sit by and cheer him on, isn’t just breaking the promise the United States has made, and it isn’t just threatening Europe. It is encouraging World War III, which will hit our shores and cost American lives.

“It is the kind of statement that can only come from a deranged and twisted mind. I do not say this lightly: The lives of every American, both in uniform and civilian, are at severe risk if Donald Trump wins this election.”

http://tinyurl.com/mrx9m2p6

6
7
4

The leader of the GOP encouraging Russia to attack our NATO allies seems like the comment from a presidential candidate that everyone should be talking about this weekend.

Let’s end Trump’s political career in November: https://act.indivisible.org/survey/defeat_trump_2024_survey?source=mastodon&medium=directpost

4
2
2

1923: Hitler’s failed coup.

No real consequences.
No fundamental changes.

1933: Hitler takes power.

I wish I could implant this into everyone’s brain.

1
8
3

A Light Shining in Darkness

It makes me sad at how accurate this is.

4
5
3
Watch Putin's interview if you want more proof that the world would be *so* much better off if macho old men would just go to therapy.
0
3
25
Edited 8 months ago

CFP for LPC 2024 is out!

Please mark your calendar:

Deadline to propose a microconference: April 4, 2024
Deadline to submit talks to LPC Refereed and Kernel Summit track: June 16, 2024

https://lpc.events/event/18/abstracts/

1
13
5
CEO: I want a promotional pic that would make every Kerbal player go "lol, actually, you're just going to fall back down."
Graphics dept: how's this?
CEO: Perfect.
3
11
34
Show older