Posts
3036
Following
701
Followers
1550
"I'm interested in all kinds of astronomy."

stalld: unpatched fixed temporary file use and other issues

https://security.opensuse.org/2024/11/29/stalld-fixed-tmp-file.html

0
1
2
Edited 1 year ago
@hajovonta @amszmidt I can mess up the same thing multiple times a day...
0
0
2

Linux: Race can lead to UAF in net/bluetooth/sco.c: sco_sock_connect()

https://seclists.org/oss-sec/2024/q4/130

What a mess:

“the reporter also did not reply to any of linux-distros’ members questions, most notably ‘have you contacted either security () kernel org or the bluetooth maintainers about this issue?’”

“the issue may be the same as CVE-2024-27398”

0
2
4

tuned: local root exploit in D-Bus method instance_create and other issues in tuned >= 2.23 (CVE-2024-52336, CVE-2024-52337)

https://seclists.org/oss-sec/2024/q4/127

0
3
5
@timb_machine Glad to hear that :) On my side that rendered as a very sad little blob.
1
0
0

⛧ SLEIGHER ⛧

2
0
3
repeated

NEW: The phones of the new NATO Secretary General Mark Rutte (including a hotline with the White House):
https://www.electrospaces.net/2024/12/the-phones-of-new-nato-secretary.html

1
2
0
@jann @freddy I've heard that bug bounty submissions definitely correlate with the summer break
0
1
1
@todb @zmanion Based on the post I'm afraid including error detection in new ID's would cause a Hell of a mess at the consumers side :(
0
0
1
repeated

The Archive has definitely hit the phase of "it works unless it doesn't, and then it will suddenly work". This is where the urge to just throw open what's left just to drop bug reports or complaints is high, but you just need to keep tracking things down. This was a quarter century codebase! It's beyond amazing it got this far, this fast. But every time I go back to work at my interfaces, the team has made them run better and better.

0
1
0
repeated

This was my tenth(!) year building 25 days of puzzles for . You can solve them all for free! Most people write code to solve them, but you can solve them however you like. I hope they help people become better programmers. 🌟

The first puzzle comes out in two hours: https://adventofcode.com/

6
4
0
repeated

The 2024 Economist Word of the Year:

“kakistocracy” - Government by the least qualified or most unprincipled citizens.

https://www.economist.com/culture/2024/11/29/the-economists-word-of-the-year-for-2024

0
4
0
Edited 1 year ago
test
Show content

This is a #test of frequency instruments.

Bass

Drums

Distortion

Artifacts

0
0
0
re: The computing I would like
Show content
@cynicalsecurity Thanks I'll look that up!
0
0
1
@brewsterkahle Sorry, not a native speaker here! What I mean (half-jokingly) is these days we - as in users and developers - just accept that our software is bad. We create higher layers of abstractions so ppl with minimal training can produce more sw, because we always need more sw somehow. Then ofc the abstractions leak, and the design doesn't make sense and UX is horrible. Then - if the lawyers and salesppl were smart enough - the producer can charge even more money for the fixes. And the buyers don't have alternatives and they just accept their faith because sw has always been buggy. And this is how you boil a frog.
0
1
8
@astralia @pancake @joxean @radareorg I like the warm fuzzy feeling of running NSA code (financed by US taxpayers) on my machine :)
1
0
1
re: The computing I would like
Show content
@cynicalsecurity I think "some form of NFS" deserves some focus. I haven't thought about this but seen enough NFS induced vulns to say NFS probably won't be it. You ruled out SMB. What are the alternatives?

(We have some nice setups with MinIO, but wrapping everything with HTTP doesn't feel right either)
1
0
0
Show older