Posts
1292
Following
212
Followers
1869
Director of Linux Foundation IT. Currently in charge of kernel.org infra.

This account is for Linux/Kernel/FOSS topics in general: #linux, #kernel, #foss, #git, #sysadmin, #infrastructure.

For my personal account, please follow @monsieuricon@castoranxieux.ca.

Montréal, Québec, Canada 🇨🇦🇺🇦

So we got @gregkh on the show to explain Linux Kernel security, both proactive and reactive, and why they sort of can't treat security bugs special (TL;DR: Linux is on everything, so a prenotification list to tell people secretly doesn't work when you tell thousands of people... and that's one of the easier problems), the whole thing and more on the with @joshbressers and @kurtseifried https://opensourcesecurity.io/2024/02/25/episode-417-linux-kernel-security-with-greg-k-h/ TL;DR: just run an up to date stable Kernel, the era of trying to cherry-pick and backport security fixes is coming to an end.

7
5
4
Happy to welcome two new orange mayhems into our home.

(This is Tater. His brother Wesley is roaming somewhere out of reach of the camera.)
0
0
13
akkoma 2024.02 stable has been released!

https://meta.akkoma.dev/t/akkoma-stable-2024-02-background-followbacks/655

featuring such cool stuff as user background federation!
automatic followback approval!
and the hinted-at security fix!
0
3
1

Le Castor Anxieux 🇨🇦🇺🇦

Posted with Akkoma 3.11 for Workgroups.

(Not sure anyone at Akkoma is actually old enough to get this joke.)
0
1
1

Fascinating to see the Times slowly trying to come to grips with the way they’ve been played by Moscow.

It takes them seven paragraphs to get to the fact that the allegations against Biden were (passive voice) “made up.”

Not till paragraph twelve does the real protagonist appear: Russian intelligence. It’s a Russian disinformation operation. Let’s see if we can say that out loud. https://masto.ai/@Nonilex/111984017335877297

2
3
1

Two years ago, Putin started a full-scale invasion of Ukraine.

Some predicted that it would fall in a matter of days.

Instead, the Ukrainian people have proven the power of fighting for something.

Putin made a mistake because he cannot understand what drives a human spirit when it is free to think and dream.

He cannot understand that if you give people a choice, they choose liberty. 

Ukraine chose to fight for its freedom and a better future.

And Europe will be with you.

1
7
4

North Korea has been supplying Putin with missiles to attack Ukraine. But when wreckage from one of those North Korean missiles was examined, investigators discovered it had been built primarily from smuggled American parts:

"75 percent of the components documented were linked to U.S. companies, with 16 percent linked to European ones, and nine percent connected with companies based in Asia."

https://www.twz.com/news-features/north-korean-missile-used-in-ukraine-was-packed-full-of-u-s-parts

0
1
0

this is how changelogs are going to look like from now on

1
2
2
So, this is fun, but it really chews through your ChatGPT credits. :`)

I'm working on b4 "code review" mode (grab a series, apply it to your tree, review every patch, send all your acked-by's, reviewed-by's, and individual comments as a one lump batch at the end of your review). The reason I'm playing with this is to see if we can plug in some AI pre-analysis and discussion summaries before the reviewer starts their work.
1
4
9
I look forward to not having to spend a chunk of my day adding spam instances to the MRF policy. ಠ_ಠ
1
0
3

MASSIVE - Hunter Biden “star witness” admitted to DOJ that he was getting information from the Kremlin and serving as a conduit for Russian disinfo.

That’s right.

Looks like the whole Hunter Biden “scandal” was a Russian psy-op — straight from Putin.

2
5
3
When a site forces you to register, and then tries to spam you, lovingly addressing you by that username you picked in the heat of the moment.
1
2
16
Edited 3 months ago

This year has been godawful on service operators on the net, the level of malicious garbage being slung is off the charts

In addition to The Big DDoS, SourceHut has seen about one layer 7 DDoS per week, and in any given week this year between 40 and 70% of all new accounts are spam. Our IP and email blocklists grew by several thousand entries this year.

I've spent basically all of my time in 2024 dealing with bullshit and none of my time doing anything useful for the platform or its users.

2
3
2
Edited 8 months ago

You know how young children will see some toy or shiny object on a store shelf, and somehow — by design! Marketers know what they’re doing! — they instantly •have• to have it, and are obsessed, and all sense and proportion go out they window and they need it now now NOW, but if they get it they soon abandon it because it’s junk that only looked good on the shelf?

It’s like that with CEOs and AI right now.

2
8
2
I just marked my linux kernel mails management tool as v1 (https://sjp38.github.io/post/hackermail_v1/). I hope it answers the questions on my mails management workflow, better than I did in the past.

#linux #kernel #hackermail
2
4
11
To help clear up some confusion:

DKIM and DMARC were not created to combat email spam, they were created to combat phishing. In fact, it is very easy for spammers to send DMARC-compliant mail via a spammer botnet, with a valid DKIM signature from Gmail (or any other large provider):

1. a spammer registers an account at gmail.com and sends a single spammy message to another Gmail account they control

2. they download that message, with all the headers, from their other account

3. they then send this same unaltered message to thousands of addresses via their spam botnet using a different envelope-from domain that has valid SPF entries matching the botnet

4. The spam email arrives 100% DMARC-compliant, because the SPF records matched the envelope-from domain and the DKIM signature matched gmail.com in the From: header

Google is fully aware of this, but they can't do anything to stop spammers from using this scheme -- at least not yet. They are pushing for "Replay-Resistant ARC" (https://datatracker.ietf.org/doc/draft-chuang-replay-resistant-arc/), which is why you will see a "darn=" header in the DKIM signature you get from gmail. However, even if they succeed in getting it adopted, we're still easily years away from it making any kind of impact on spam.
1
10
17
To paraphrase: "we reinvented the usenet not because it was easy, but because we thought it would be easy."
0
4
30
FYI, the Fedi spam problem is only starting out. It won't take much effort for someone to write a payload running on random compromised webservers to send copious amounts of spam via activitypub, making blocklists ineffective.

We will basically need to implement all the same anti-abuse stuff we're already doing for email in order to cope with it on the fediverse -- greylisting, dnsbl, domain authentication, etc.

Sadly, the only way this won't happen is if ActivityPub stays sufficiently niche to make other targets more popular for spammers.
17
124
182
Show older