Jan 'Duchy' Neduchal
1.6K posts

Jan 'Duchy' Neduchal
@DuchyRE
Stuff at @sentinelone. Ex @vxunderground staff. Opinions are my own and not of my employer.
Prague, Czech Republic Katılım Nisan 2017
766 Takip Edilen2.7K Takipçiler
Sabitlenmiş Tweet

FUCK. I might as well just let my homelab chill offline for a bit
V12@v12sec
0e11c4aa285dffe95d2d7e90d974ad0e72336549b0dd2161dec606ba4955e2e1 qemu.c
English

@PetrBenes Lets just have it code in F* and have all the code it produces formally verified against a spec we feed it (one can dream)
English

@vysecurity I think that's because these are meant to be sleek and connected to the outlet 24/7 at home. Thus by integrating the PSU into the body you get rid of the brick tied to the cable. I'm not a macbook user, but I have a 100w+ dock at home and the giant PSU brick is really annoying.
English

@isabelrosesss Waah wahh, this distro is not dependency bloatmaxxing.
English

@allisx86 Maturing is realising piracy is now automated: yams.media
English

@roddux I never understood why the LKMs are not an opt-in thing is major distros. If I really need PoopenFartenFS from 1984 I will install a package with a LKM that was compiled against the exact dist kernel I have. Loading it at runtime capability should also be an opt-in thing.
English

@DuchyRE Distro kernels have an *unbelievable* amount of crap stuffed in, which attempts to have the system be ready for a large variety of hardware it could be installed on.
After using your box for a week you can probably delete 80% of modules you haven't loaded and be way safer for it
English

Turns out that my schizo kernel config that turns off damn near all of the useless Linux kernel features paid off. I really should invest some time into setting up SELinux/AppArmor properly as I might not get this lucky again.

V4bel@v4bel
💥 Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io
English

@DuchyRE it doesn't work on mine just because of zfs, probably
English

@honkinwaffle What good will it do? Its tailored for my hardware and my usecase. You should roll your own :)
English

@Svaghost Oh I agree, but you gotta maintain standards across all your devices! (brb installing Gentoo on all the devices at home)
English

@x509dot I wouldn't say impossible, just really damn difficult. SELinux policy setup and tuning makes me want to, as kids say these days, unalive myself.
English

@m1ru1 I think the better question is: which ones do you actually need?
English













