Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dhx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
181.
▲
by
dhx
3y ago
For both JiaT75 and hansjans162 combined, the days of weeks they were active is the following (per a selection of timezones): tz mon tue wed thu fri sat sun AE_Asia/Dubai 166 232 266 275 273 107 7 AL_Europe/Tirane 167 238
182.
▲
by
dhx
3y ago
"In this way, consumers need only trust a small number of secure build platforms rather than the many thousands of developers with upload permissions across various packages."[1] Bad idea. We should instead have 1000's of peo
183.
▲
by
dhx
3y ago
An attack would look something like: 1. A new "test" is added to the xz-utils repository, and when xz is being built by a distribution such as Debian, the backdoor from the "test" is included into the xz binary. 2. The b
184.
▲
by
dhx
3y ago
As this backdoor has shown, extra unnecessary files in the source files can make it easier to hide malicious code. If you take Gentoo as an example, when a software package is built, Gentoo creates a sandboxed environment first, disallowing
185.
▲
by
dhx
3y ago
For many projects, the release tarballs only contain the files necessary to build the software, and not the following items that may be present in the same repository: - scripts used by project developers to import translations from another
186.
▲
by
dhx
3y ago
I think this analysis is more interesting if you consider these two events in particular: 2024-02-29: On GitHub, @teknoraver sends pull request to stop linking liblzma into libsystemd.[1] (not in the article) 2024-03-20: The attacker is now
187.
▲
by
dhx
3y ago
^ typo: 28 Feb 2023 is meant to be 28 Feb 2024, or almost 4 months later.
188.
▲
by
dhx
3y ago
1.5.29-rc2 was tagged on 9 Nov 2023 [1] and, as an example, did not contain "N_("CJK Unified Ideographs Extension I")," in src/ibusunicodegen.h [2]. Commit 228f0a77b2047ade54e132bab69c0c03f0f41aae from 28 Feb 2023 i
189.
▲
by
dhx
3y ago
sshd is probably the softest target on most systems. It is generally expected (and setup by default) so that people can gain a root shell that provides unrestricted access. sshd.service will typically score 9.6/10 for "systemd-ana
190.
▲
by
dhx
3y ago
sshd starts with root privileges and then proceeds to, in summary:[1] 1. Parse command line arguments 2. Setup logging 3. Load configuration files 4. Load keys/certificates into memory (notably including private keys) 5. Listen on a so
191.
▲
Xz: Can you spot the single character that disabled Linux landlock?
(git.tukaani.org)
538 points
by
dhx
3y ago
|
313 comments
192.
▲
by
dhx
3y ago
Answer: https://git.tukaani.org/?p=xz.git;a=commitdiff;h=f9cf4c05edd... Description of Linux's Landlock access control system if you are not familiar with it: https://docs.kernel.org/userspace-api/
193.
▲
by
dhx
3y ago
A mirror of the offending repository created by someone else is available at [1]. GitHub should be keeping the evidence in the open (even if just renamed or archived in a safer format) instead of deleting it/hiding it away. The offendi
194.
▲
by
dhx
3y ago
The charges currently listed are not going to age well in history books due to reasons such as: 1. Other parties are seemingly more responsible than Assange in releasing of unredacted cables, and yet these parties are seemingly not subject
195.
▲
by
dhx
3y ago
"For example, such information is critical to protecting the US Defense Industrial Base" is not an overly convincing argument for purchasing "NetFlow"[1]. The US State department Exchange Online hack is an example of whe
196.
▲
by
dhx
3y ago
Amongst the numerous reasons why (B) may not be preferred is governments in looking at macroeconomics will generally want to disincentivise buying services overseas, something which would reduce domestic GDP and strengthen the economies of
197.
▲
by
dhx
3y ago
Whilst Firefox may support hardware video decoding, Mesa since March 2022 disables patent encumbered codecs by default[1], and distributions such as Fedora and OpenSuse do not explicitly enable these patent encumbered codecs to avoid possib
198.
▲
by
dhx
3y ago
This was my first thought too because the argument is against a FSF-award-winning founder and maintainer of 25 years of one of the most important and widely used cryptographic libraries. The blog appears to be at least hosted by, and possib
199.
▲
by
dhx
3y ago
I gather this might be changing per [1] as Wikifunctions is investigating the possibility of implementing interpreters such as CPython with WebAssembly. [1] https://phabricator.wikimedia.org/T308250
200.
▲
by
dhx
3y ago
See [1] for an overview of "state of the art" metadata-protecting communications protocols. There has been much research into this problem over decades and the effectiveness of such protocols very much depends on real world use ca
201.
▲
by
dhx
3y ago
ClearURLs implemented the rule to remove the si attribute on November 5th[1]. I think a better approach though is to whitelist allowed attributes rather than blacklist disallowed attributes. For example, if you get a URL starting " htt
202.
▲
by
dhx
3y ago
Optus' official position on the events that they tabled to the Australian parliament are is at [1]. In summary: > "This unexpected overload of IP routing information occurred after a software upgrade at one of the Singtel inter
203.
▲
by
dhx
3y ago
There are a few patterns common in Australia: 1. Person directly employed on an ongoing basis. The employer pays all insurances, professional memberships and generally contributes to the professional development of the employee. 2. Person d
204.
▲
by
dhx
3y ago
Refer to the Casual Employment Information Statement (CEIS)[1] and due-to-be-released-on-6-December-2023 Fixed Term Contract Information Statement (FTCIS)[2]. [1] https://www.fairwork.gov.au/sites/default/files
205.
▲
by
dhx
3y ago
I haven't been able to find information on what part of their overall network is impacted. Per [1] they use a mixture of leased fibre and owned fibre for connectivity between Australian cities, and per [2] (note: zoom in) many point-to
206.
▲
by
dhx
3y ago
“An Optus source, who did not wish to be named because they were not authorised to speak publicly, said a BGP prefix flood from a peer was likely causing the issues on the telco’s core network.” “Our on-site technician is actively prioritis
207.
▲
by
dhx
3y ago
“An Optus source, who did not wish to be named because they were not authorised to speak publicly, said a BGP prefix flood from a peer was likely causing the issues on the telco’s core network.” “Our on-site technician is actively prioritis
208.
▲
by
dhx
3y ago
It's not quite that easy. Soil under plantations is easy to deplete at a non-renewable rate. Harvest causes soil compaction and erosion. Post-harvest, herbicides are used extensively to kill weeds that would otherwise fill the void bef
209.
▲
by
dhx
3y ago
Coming soon to the next release: > "I can't search Google easily" "Have you heard about Bing, which let's you harness the power of AI to... Click [here] to visit Bing. Otherwise click [here] to find out more abou
210.
▲
by
dhx
3y ago
What would $5bn buy? AusCERT 2023 had a few talks that hint towards a focus on "threat intelligence sharing"[1][2] amongst what would seemingly be a combination of government departments and "critical infrastructure" pri
More ›