Dennis Giese and DanielAW examine connected robot vacuums, expose their data collection and internal Linux systems and show ways to run your own IoT cloud. A household appliance becomes a privacy risk as soon as its sensors are tied to someone else’s infrastructure. Owning a device remains incomplete if essential functions only work with a manufacturer cloud.
Hackaday explains token-based Gmail login so that scripts and microcontrollers can send email without a stored account password. Gmail documents its OAuth2 interface. The approach runs on Linux and the ESP8266.
A Linux user finds a wrongly selected audio path and corrects the codec configuration for the headphone output. The bug removed low frequencies at the headphone jack. Under Windows, the same hardware sounded correct.
Al Williams compares two browser-based management tools for Linux and assesses ease of use, range of functions and security risks. Webmin and Cockpit are browser-based tools. Cockpit integrates closely with systemd.
In 2017 Kaspersky discovered the “ShadowPad” backdoor, which for 17 days was hidden in admin tools such as Xshell, Xmanager and Xftp from the Korean vendor NetSarang. The trojanised DLL was signed with valid NetSarang certificates and distributed via the regular update channel to banks, pharmaceutical and energy companies. The malicious code consisted of encrypted modules that only became active after a signal from the command server.
In 2017 GitLab contained a critical hole (CVE-2017-12426) through which attackers could execute commands on the server when importing a repository by URL. An option flag injected into the URL caused the rest of the address to be interpreted as a command. Versions 7.9.0 to 9.4.3 were affected; Recurity Labs had previously found similar bugs in Git, Mercurial and other version control systems.
In 2017 Linux 4.13 was able to take over the encryption and decryption of a TLS connection itself for the first time. This was meant to improve performance and open up new uses. The complex connection setup, however, is still handled by libraries such as OpenSSL in user space.
RFC 8200 replaces the original IPv6 specification and consolidates the matured base standard. An Internet Standard can become more precise through operational experience without changing its architecture. Deploying IPv6 requires full support in security and monitoring.
KG examines how learning software is increasingly taking over cognitive routines alongside physical work and changing entire professions. Automation becomes a problem of distribution as soon as productivity grows faster than new participation. Professions look stable, although their individual tasks carry very different automation risks.
In the lab, Lutz Donnerhacke shows how DirectAccess, DNS64 and policy-based name resolution can prevent valid DNSSEC checks. DNSSEC initially recognised the answer altered by DNS64 as insecure. The test distributed trust anchors and validation policies via group policy.
The guide builds a custom PC case from inexpensive panels, profiles and templates without an industrial workshop. The original video has the ID K8hLXJUQFoc. In many case projects, precise planning replaces expensive manufacturing machines.
At customers’ request, Manuel Schmitt adds the CAA resource record type to his hosting company’s DNS zone editor. The CAA type was enabled in the zone editor on 27 January 2017. According to the article, the extension came about at the request of many customers.
In January 2017 the BSI warned of a hole in around 60 Netgear router models through which attackers could read out the password of the web interface. It could be exploited if password recovery was disabled and the attacker was on the same network or remote management was active. The BSI rated the risk at level 5 without clearly explaining what that means.
At linux.conf.au 2017, Intel developer Daniel Vetter proposed a manifesto for kernel maintainers because maintainers are increasingly overloaded. A single maintainer does not scale, and the kernel lacks people responsible for many areas of code. Vetter drew on experience as a maintainer in the Linux graphics stack.
Brian Krebs links source code, forum profiles, chats, business relationships and DDoS motives into a detailed attribution of the Mirai author. Mirai’s source code was published on 30 September 2016. The command system was written in Go and the device software in C.
In January 2017 a free bootcode firmware for the Raspberry Pi was able to boot the Linux kernel directly for the first time. On the Pi, hard-wired code loads the proprietary Broadcom firmware onto the graphics unit, which then initialises the hardware. The free alternative was created mainly by reverse engineering, but still had gaps in USB, eMMC and power and clock management.