Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jdamato
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
jdamato
8y ago
Thanks for commenting this! I've seen this website before and it's really unfortunate how much attention it gets. APT's use of plain text HTTP (even with GPG) is vulnerable to several attacks outlined in this paper: https:&#
2.
▲
by
jdamato
9y ago
APT will not reject it on replay if the 'Valid-Until' date has not been met yet. Imagine a version of, say, libEXAMPLE has a vulnerability allowing remote code execution. The `Valid-Until` date is some time in the future, maybe a
3.
▲
by
jdamato
9y ago
Yes, plain text APT repositories (signed with GPG or not) are vulnerable to freeze attacks.
4.
▲
by
jdamato
9y ago
We never suggest that you turn security off -- several versions of APT come with various settings defaulted to off, as described in the article. All of the attacks presented (replay attacks, freeze attacks, and downgrade attacks) affect GPG
5.
▲
by
jdamato
9y ago
Hi! I'm the author of the article. We never suggest turning off GPG and checksum verification. The bugs may be in APT, but they allow several attack vectors against APT, as explained throughout. Let me know if you have any specific que
6.
▲
by
jdamato
9y ago
The website you linked to has several factual errors, as explained in the article.
7.
▲
by
jdamato
9y ago
Yep, and the information is still relevant! The article explains how it applies to recent versions of APT in the current Ubuntu LTS releases.
8.
▲
by
jdamato
10y ago
We don't really know what EC2 does or precisely the type of hardware your VM will be spun up on. I've erred on the side of being cautious due to the vast amount of work being invested in timekeeping in various hypervisors. If EC2
9.
▲
by
jdamato
10y ago
Not quite. The vDSO provides a general syscall-wrapper mechanism for certain types of system call interfaces. It also provides implementations of gettimeofday clock_gettime and 2 other system calls completely in userland and acts precisel
10.
▲
by
jdamato
10y ago
This is precisely what the vDSO does. The clocksources mentioned explicitly list themselves as not supporting this action, hence the fallback to a regular system call.
11.
▲
by
jdamato
10y ago
Author here, greetings. Anyone who finds this interesting may also enjoy our writeup describing every Linux system call method in detail [1]. [1]: https://blog.packagecloud.io/eng/2016/04/05/the-definitiv
12.
▲
by
jdamato
10y ago
Thanks for reading and I'm glad to hear you loved my post!
13.
▲
by
jdamato
10y ago
Hi, both are answered in the article: First: > What’s going on here is that the first call to localtime in glibc opens and reads the contents of /etc/localtime. All subsequent calls to localtime internally call stat, but they d
14.
▲
by
jdamato
10y ago
Author of the post here: greetings. If you enjoyed this post, you may also enjoy our deep dive explaining exactly how system calls work on Linux[1]. [1]: https://blog.packagecloud.io/eng/2016/04/05/the-de
15.
▲
by
jdamato
10y ago
Check out the post linked from the article: https://blog.packagecloud.io/eng/2016/04/05/the-definitive-g... to learn more about how system calls work on x86 Linux.
16.
▲
by
jdamato
10y ago
If you enjoy this post, you may also enjoy the companion post which dives into the same level of detail, but for the receive side[1]. I set out to write all this up because so much of the existing documentation (including the man pages) is
17.
▲
Monitoring and Tuning the Linux Networking Stack: Sending Data
(blog.packagecloud.io)
119 points
by
jdamato
10y ago
|
6 comments
18.
▲
by
jdamato
10y ago
Thanks for this! I recently wrote a deep dive in to both strace [1] and Linux system calls [2] which may be interesting to folks reading this great article. [1]: https://blog.packagecloud.io/eng/2016/02/29
19.
▲
by
jdamato
10y ago
Great introductory article, thanks for writing and sharing this! I wrote an article explaining the inner workings of strace [1], and a detailed article about Linux system calls [2] which others interested in this article may find relevant.
20.
▲
by
jdamato
10y ago
I wrote an article explaining how ptrace works, which may interest you: https://blog.packagecloud.io/eng/2016/02/29/how-does-strace-...
21.
▲
More than you ever wanted to know about Linux system calls
(blog.packagecloud.io)
6 points
by
jdamato
10y ago
|
0 comments
22.
▲
How does ltrace work?
(blog.packagecloud.io)
2 points
by
jdamato
11y ago
|
0 comments
23.
▲
How to extract and disassemble a Linux kernel image (vmlinuz)
(blog.packagecloud.io)
2 points
by
jdamato
11y ago
|
0 comments
24.
▲
How does strace work?
(blog.packagecloud.io)
2 points
by
jdamato
11y ago
|
0 comments
25.
▲
by
jdamato
11y ago
Hi: I built packagecloud, which is what GitLab uses for hosting packages. Getting a package repository installed securely is quite a bit more difficult than it seems, but I agree that our Manual install instructions should be simplified and
26.
▲
Infrastructure as code might be literally impossible
(blog.packagecloud.io)
9 points
by
jdamato
11y ago
|
0 comments
27.
▲
HOWTO: GPG sign and verify RPM packages and yum repositories
(blog.packagecloud.io)
1 points
by
jdamato
12y ago
|
0 comments
28.
▲
Debugging an MRI Ruby GC Segfault Caused by a Buggy RubyGem
(blog.packagecloud.io)
7 points
by
jdamato
12y ago
|
0 comments
29.
▲
HOWTO: GPG sign and verify deb packages and APT repositories
(blog.packagecloud.io)
2 points
by
jdamato
12y ago
|
0 comments
30.
▲
Yum and createrepo generate incorrect metadata
(blog.packagecloud.io)
4 points
by
jdamato
12y ago
|
0 comments
More ›