Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cpach
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
by
cpach
3mo ago
See also https://news.ycombinator.com/item?id=48660159 (1 comment so far)
32.
▲
by
cpach
3mo ago
Why is this on the front page? :)
33.
▲
by
cpach
3mo ago
Feel free to launch your own CA.
34.
▲
by
cpach
3mo ago
Interesting!
35.
▲
by
cpach
4mo ago
Reading, writing, cooking, child-rearing.
36.
▲
by
cpach
4mo ago
What’s the performance when you do that?
37.
▲
by
cpach
4mo ago
Dupe: https://news.ycombinator.com/item?id=48265498
38.
▲
by
cpach
4mo ago
Uhm… cryptography or cryptocurrency?
39.
▲
by
cpach
4mo ago
For those who can I would recommend upgrading to Wireguard.
40.
▲
by
cpach
5mo ago
If it was for personal use, surely there would be some kind of consumer organization or ombudsman one could contact for advice? For B2B, I guess the local chamber of commerce might be able to advice.
41.
▲
by
cpach
5mo ago
Same here, zero plugins for me.
42.
▲
by
cpach
5mo ago
Regarding su… su - might yield better results.
43.
▲
by
cpach
5mo ago
Does anyone know how to mitigate this one? Is it sufficient to disable the esp4/esp6/rxrpc modules?
44.
▲
by
cpach
5mo ago
Main discussion here: https://news.ycombinator.com/item?id=48058393
45.
▲
by
cpach
5mo ago
Welcome to Hacker News! Please write in English here. Thank you in advance from a long-time member :)
46.
▲
by
cpach
5mo ago
No, I haven’t. My concern is to try to understand the mechanisms of the exploit. Copy Fail is not simply ”hey, kernel, give me root”. I would say it’s more general than that. It’s rather: ”Hey, kernel, when you present file /foo to a p
47.
▲
by
cpach
5mo ago
Many? No, I don’t agree.
48.
▲
by
cpach
5mo ago
Sure. But it would probably still be a good thing if the kernel maintainers could tear out AF_ALG.
49.
▲
by
cpach
5mo ago
That might make Copy Fail harder to exploit, but I still wouldn’t bet money on CF being impossible to use in that scenario.
50.
▲
by
cpach
5mo ago
How does allowPrivilegeEscalation=False help?
51.
▲
by
cpach
5mo ago
If so, I would look into applying a decent seccomp profile. Other hardening solutions could be to run the workloads inside of a VM such as Firecracker, or gVisor. But that might be more work to implement compared to seccomp.
52.
▲
by
cpach
5mo ago
How?
53.
▲
by
cpach
5mo ago
I would say any sanely written application would fall back to doing the requested operations in userspace if it cannot use the AF_ALG socket. It could fail though. But I have not yet heard of anyone noticing big problems due to disabling
54.
▲
by
cpach
5mo ago
Good enough for what? I could be wrong, but I’m not sure those settings are enough to mitigate Copy Fail. If your distro offers a patched kernel, it’s best to upgrade to that one and reboot. You can also disable the vulnerable module (how t
55.
▲
by
cpach
5mo ago
Well at least if it’s crufty stuff like AF_ALG that barely no-one is using and is kind of a forgotten place of the kernel. I don’t oppose reasonable crypto in the kernel, like WireGuard.
56.
▲
by
cpach
5mo ago
What is the false premise in the article?
57.
▲
by
cpach
5mo ago
We had lectures on Frame Relay and stuff like that in uni, but I’ve never ever touched that stuff (:
58.
▲
by
cpach
5mo ago
?
59.
▲
by
cpach
6mo ago
If you happen to use Vim, I think it has a built-in spellchecker.
60.
▲
by
cpach
6mo ago
“Has anyone else had a similar experience?” Yes. Same here. The owner has never replied to my emails. I have also had contact with vendors who received the same treatment. To be honest I’m disappointed. I have seen multiple persons linkin
More ›