
Tristan Ross 😺❄️
13.3K posts

Tristan Ross 😺❄️
@RossComputerGuy
I like computers and cats. ちょっと日本語上手。にゃー Ko-fi: https://t.co/X2dKfIm2kf
San Diego, California, USA Katılım Ocak 2015
476 Takip Edilen1.6K Takipçiler
Sabitlenmiş Tweet

I write posts and try to do them daily or at least weekly. Check out my site (tristanxr.com) for my latest posts. I often write about topics like ARM, RISC-V, NixOS, and things I am interested in or involved in.
English

@anthrofract @hetmehtaa 1. Roll back is easy with generations
2. Reproducible builds
3. Declarative setups makes replicating things easy
English

@RossComputerGuy @hetmehtaa Because you can roll back versions on failure, or is there some sort of way to hot swap the kernel?
English

there's a zero-day being actively exploited
i need to patch the system
the patch requires a reboot
the system hasn't been rebooted since 2019
nobody is sure it will come back up
it has achieved a kind of digital immortality that we are all afraid to disturb
we decided to leave the zero-day unpatched
the system is both the most vulnerable and most resilient thing in our network
English
Tristan Ross 😺❄️ retweetledi

Determinate Nix 3.19.1 fixes the latest round of Nix CVEs and is fully available through all channels. status.determinate.systems/incidents/41b9…
Determinate Systems@DeterminateSys
We are tracking two vulnerabilities (one high and one moderate) in Nix, and a coordinated Determinate Nix 3.19.1 release is in progress. More details on our status page: status.determinate.systems/incidents/41b9…
English

@MaxKorbel1 It is hard, it's going well. The parser was failing with ROHD but it seems to be happy now. Sema is failing to pick up on the types correctly. That should be fixed soon. I've been having a lot of time waiting for tapeout & DRC of Aegis.
English

Working on making Quart work with ROHD. Hoping it can reduce the amount of memory needed to generate the RTL for Aegis.
Tristan Ross 😺❄️@RossComputerGuy
Cross compiled Dart to x86 from aarch64 without the Dart AOT runtime.
English

@MaxKorbel1 It's an implementation of Dart I'm working on that's written in Rust. It uses Cranelift and compiles down straight to an ELF. It skips things like the AOT runtime because it can be truly native.
English
Tristan Ross 😺❄️ retweetledi

🚨ALERT‼️ There are over 100,000 Flock Cameras In the United States as of today.
BTW each one contains 3 g of gold, almost $100 worth of silver, and enough copper wire to choke a horse. 🤔🤔
Learn everything you can about them: deflock.org

English

Do they just kill someone if the 10M+1 person is born ?
Polymarket@Polymarket
JUST IN: Switzerland to vote on capping its population at 10 million.
English

@rywiggs That's what it was like when I got my first debit card in like high school. Mercury made is so easy, literally less than 20 minutes to have an account and everything.
English

Remember when you had to drive to a bank branch?
Tristan Ross 😺❄️@RossComputerGuy
@mercury's profile says "apply in 10 minutes" but they need to also say that you can be verified in 5. I set up Mercury for @MidstallSW today, it literally took them 5 minutes to verify me. I've never seen anyone verify that quickly.
English
Tristan Ross 😺❄️ retweetledi

DetSys is announcing long-term support for Determinate Secure Packages 25.11 through May 2028 🎉🛡️📦
Based on the nixos-25.11 branch of Nixpkgs but with an SLA for CVEs, SBOMs, all covered packages built on SOC 2 Type II infra and cached in FlakeHub Cache, and all with a one-line change in your flakes. Read today's blog post for more at the link in thread 👇🧵🔗
English

@mercury's profile says "apply in 10 minutes" but they need to also say that you can be verified in 5.
I set up Mercury for @MidstallSW today, it literally took them 5 minutes to verify me. I've never seen anyone verify that quickly.

English

@RossComputerGuy Fixes this but also somehow makes it worse at the exact same time
English

@GrapheneOS SELinux certainly helps but having more layers of security doesn't hurt. And when 1 vulnerability exists, multiple can still exist. There's always the chance of there being a vulnerability. Exploits could always use multiple vulnerabilities until they take over a system.
English

GrapheneOS is immune to the Copy Fail vulnerability due to the deep integration of SELinux in the Android Open Source Project (AOSP). AOSP only permits using specific types of sockets throughout the OS. It only permits the dumpstate process used to create bug report zips to access AF_ALG sockets.
SELinux is based on explicitly listing out everything that's permitted and anything not listed isn't allowed. AOSP uses strict, fine-grained SELinux policies for the whole OS. Instead of simply permitting everything that's used in a fine-grained way, the rest of the OS is developed with it in mind.
English
Tristan Ross 😺❄️ retweetledi

Tracking: CVE-2026-31431 "Copy Fail", a local privilege escalation in the kernel that is exploitable from within the Nix sandbox.
We're preparing to ship the patch via Determinate Secure Packages channels shortly.
Subscribe for details: rootly.com/teams/determin…
English

@ludwigABAP lol yeah, I saw this yesterday and imo it's a bad sign
English








