Hyperbola switches from GNU/Linux to OpenBSD
Hyperbola planned to switch from GNU/Linux to an independent operating system derived from OpenBSD.
Read the full post20 posts
Projects, Linux, networks, systems, finds and internet standards from 2019.
Hyperbola planned to switch from GNU/Linux to an independent operating system derived from OpenBSD.
Read the full postKG compares stellar engines that use solar radiation or a directed fusion jet to move the entire solar system over the long term. Very small forces become powerful when they act without interruption over astronomical periods of time. Propulsion can change a frame of reference without driving each object in it individually.
Read the full postAl Williams shows SSH configuration, file transfer, port forwarding, a SOCKS proxy and remote file systems as versatile tools for secure networks. SSH encrypts login and data traffic. scp and sftp transfer files over SSH.
Read the full postAl Williams shows tracing, strict shell options and a real Bash debugger as better tools than scattered echo output. Bash has built-in tracing functions. External debuggers can run scripts step by step.
Read the full postManuel Schmitt notes down a short ip command that renames a network interface without triggering udev again. The documented command is ip link set OLDNAME name NEWNAME. Manuel explicitly calls the entry a reminder to himself.
Read the full postJohannes describes a post-receive hook that mirrors a self-hosted Git repository to GitHub after every push. The hook runs after a successful push. As downstream services, Johannes names Travis CI and Docker Hub.
Read the full postFranck Courchamp and Clément Morin set human intelligence, inventions and importance against the scales of evolution, biodiversity, Earth’s history and the universe. ARTE produced the French series in 2018. The German TV premiere began on 14 October 2019.
Read the full postLennart Poettering presents systemd-homed, which combines Linux home directories with encryption, portable identities, modern authentication and structured user records. A decades-old directory model now carries authentication, encryption and mobility at the same time. Convenient encryption comes about when key management is integrated into the normal login process.
Read the full postStallman’s resignation sparked a debate about Stallman as a person and the lasting value of the GNU project.
Read the full postIn 2019 the German Federal Office for Information Security (BSI) presented the results of a funded project that improved the Mailvelope browser extension for PGP-encrypted email. New features included the ability for website operators to encrypt contact forms end to end, with keys retrieved via the Web Key Directory. An audit by SEC Consult found and closed four holes in Mailvelope and three in the OpenPGP.js library.
Read the full postIn August 2019 CERT-Bund warned of four unpatched holes in Cisco’s Firepower firewall software through which attackers could bypass the filter rules without logging in. While CERT-Bund rated the risk as high, Cisco rated all four holes only as “Medium” with CVSS 5.8. At the time of the report there were neither updates nor workarounds.
Read the full postIn 2019 researchers from vpnMentor found the “Biostar 2” biometric database of the manufacturer Suprema largely unprotected on the net. Using a normal browser, they reached 27.8 million entries totalling 23 gigabytes, including unencrypted user names and passwords, more than a million fingerprints and facial images. The system controlled access control, including via Nedap’s AEOS platform at more than 5,700 organisations in 83 countries.
Read the full postThe complete computer disappears into a folding desk that plans work surface, cooling and cable routing together. The original video has the ID QaoFh1DH51U. Furniture and computer are better designed together than one after the other.
Read the full postConnections to my EUserv server and to the provider’s website lost about ten percent of their packets; the problem became visible from the network node 149.14.211.218 onwards. The measurement showed roughly ten percent packet loss. Both my own EUserv server and the website euserv.de were affected.
Read the full postProxmox VE and Ceph combine virtualisation, distributed storage and high availability on the same nodes.
Read the full postRFC 8555 standardises ACME for the automated issuance, validation and renewal of certificates. Automation made short certificate lifetimes manageable in practice. PKI reliability increasingly depends on secure renewal processes.
Read the full postBrian Krebs reconstructs an espionage campaign that manipulated registrar accounts and DNS records to intercept the email and VPN access of numerous organisations. Netnod confirmed that its registrar account had been compromised. The attackers obtained certificates for manipulated mail destinations.
Read the full postIn 2019 kernel developers discussed a dedicated subsystem for AI accelerators, whose drivers had until then been scattered across various areas of the kernel. Olof Johansson proposed patches and wanted to maintain the subsystem together with Greg Kroah-Hartman. Developers of the graphics drivers considered the idea wrong because the differences from GPUs were minimal.
Read the full postIn January 2019 SUSE developer Andreas Färber published an experimental Linux driver for the home automation protocol Z-Wave. Färber called it a proof of concept, tested with the Pine64 Z-Wave module and written without documentation of the UART protocol. Drivers for the LoRa radio protocol had also been in the works for some months.
Read the full postIn January 2019 Harry Sintonen of F-Secure found five holes in the SCP implementations of OpenSSH, PuTTY and WinSCP. SCP does not check whether received files correspond to the requested ones, so a malicious server can swap files or place additional ones unnoticed. This could be used, for example, to replace .bashrc and execute malicious code the next time a program is called.
Read the full post