bk99.de entertain the web since 1997

Blog 2020

26 posts

Projects, Linux, networks, systems, finds and internet standards from 2020.

The Egg: One life from every perspective

KG animates Andy Weir’s short story about a dead man who learns that every human life is an incarnation of the same maturing consciousness. Andy Weir wrote the short story “The Egg”. Stefan Zisting translated the German version published on Andy Weir’s website.

Read the full post

SolarWinds: Trusted updates as a way in

Brian Krebs describes how manipulated Orion updates carried a supply chain compromise to up to 18,000 customers and enabled prioritised follow-up attacks. SolarWinds named fewer than 18,000 Orion customers that might be affected. According to the analysis at the time, manipulated updates had been distributed since March 2020.

Read the full post

Running your own Matrix server on Arch Linux

Brendan Abolivier explains Matrix as a federated communication standard and shows how your own homeserver on Arch Linux becomes part of the network. Decentralisation distributes control but increases the demands on operations and moderation. Self-hosting only creates sovereignty with reliable updates, backups and key protection.

Read the full post

Network storage: Amazon cloud cuts off API for backups from NAS

In 2020 Amazon discontinued the programming interfaces for Amazon Drive and Amazon Photos, so that from 1 November NAS systems such as Synology could no longer write backups there. Synology’s Cloud Sync and Hyper Backup were affected, and by the nature of the change other manufacturers such as QNAP as well. Amazon recommended its own apps, which, however, offered no encryption and did not exist for NAS; S3 remained unaffected.

Read the full post

Wi-Fi routers targeted by hackers

According to Trend Micro, unauthorised login attempts on home routers rose from 23 to 249 million between September and December 2019. Attackers want to take over the devices by brute force and integrate them into botnets for DDoS attacks, especially as more company data moved into home offices. An analysis of 127 routers by Fraunhofer FKIE also showed that many had not received updates for years and ran on very old Linux kernels.

Read the full post

KDE Linux desktop: security hole in Ark allowed remote attacks

In 2020 the KDE archive manager Ark contained a path traversal hole (CVE-2020-16116) through which prepared archives could write files to arbitrary locations in the home directory. This could be used, for example, to place a manipulated .bashrc or a script in the autostart folder, but the user had to extract the archive. Ark 20.08.0 prevented this and also issued a warning.

Read the full post

Reformer for long sequences

Reformer reduces the memory and computing requirements of classic transformers through locality-sensitive hashing and reversible layers. This makes much longer inputs possible on limited hardware. Reformer replaces full attention with locality-sensitive hashing.

Read the full post

How solar storms can hit a technical civilisation

KG explains solar flares and coronal mass ejections and their possible consequences for satellites, radio, navigation and power grids. Space weather becomes an infrastructure risk because technical networks are coupled over large areas. Early warning time only helps if operators have prepared coordinated protective measures beforehand.

Read the full post

How decoding changes the text output

The article compares greedy search, beam search, sampling, top-k and nucleus sampling. It shows that the same model weights produce completely different texts depending on the decoding strategy. Beam search keeps several continuations in parallel and compares their overall probability.

Read the full post

Training a language model from scratch

Using Esperanto as an example, Hugging Face shows how the tokenizer, data set and transformer are built up from scratch together. The experiment makes visible which decisions finished models usually hide. The example model has six transformer layers and around 84 million parameters.

Read the full post

WireGuard merged into the main branch of the Linux kernel

In January 2020 Linus Torvalds merged the net-next branch, and with it the WireGuard VPN, into the main branch of the Linux kernel. This set WireGuard for Linux 5.6 in April, after Jason Donenfeld had proposed it for inclusion the previous summer. The network code comprises only around 7,000 lines, whereas OpenVPN and IPsec run to several hundred thousand.

Read the full post

L1DES and VRS make Intel chips vulnerable

In January 2020 Intel disclosed two further variants of Microarchitectural Data Sampling, found by the University of Michigan and VU Amsterdam. With L1DES, alias CacheOut (CVE-2020-0549), data is evicted from the L1 data cache into the fill buffer and can be read there; with VRS, vector registers are affected. Kaby Lake, Coffee Lake, Whiskey Lake and Cascade Lake, among others, were affected, and Intel announced microcode updates.

Read the full post

The tricks with the Google security hole

In early 2020 Trend Micro found malicious apps in the Google Play Store that exploited an Android hole previously used by customers of the spyware maker NSO. Google itself had discovered the hole around a year and a half earlier. The apps Camero and Filecrypt Manager served as droppers and secretly installed the spy app Callcam.

Read the full post