GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Damien Miller (djm@cybervillains.com)

  1. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Monday, 01-Apr-2024 11:54:13 JST Damien Miller Damien Miller
    in reply to

    Few of the mooted software-supply chain defences would have prevented this, as the attacker was a (relatively) long-term maintainer, was not averse to using sockpuppet accounts and was careful to hide their exploit from automated tools.

    Worse, many of the solutions being offered increase the workload on maintainers. But maintainer burnout was a key factor in this incident. We need to find a way to support maintainers while being proscriptive or parentalistic.

    3/n

    In conversation about a year ago from cybervillains.com permalink
  2. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Monday, 01-Apr-2024 11:54:13 JST Damien Miller Damien Miller
    in reply to

    One factor in this incident was deep, unexpected dependency chains. I wish distributions would start taking a more minimalist approach to the options they enable in the default packages they ship.

    What fraction of the sshd userbase actually needs Kerberos or SELinux (which also depends on liblzma) enabled? Put that stuff in an alternate package and reduce the exposure for the rest of your users. Fewer dependencies means less attack surface and less supply-chain risk

    2/n

    In conversation about a year ago from cybervillains.com permalink
  3. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Monday, 01-Apr-2024 10:04:44 JST Damien Miller Damien Miller

    Here's my 2c on the xz incident.

    This is the nearest of near-misses. Anyone who suggests this was any kind of success is a fool. No system caught this, it was luck and individual heroics. That's not acceptable when unauthorised access to ~every server on the internet is on the table. We need to find a way to do better.

    1/n

    In conversation about a year ago from cybervillains.com permalink
  4. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Monday, 25-Mar-2024 10:27:33 JST Damien Miller Damien Miller
    in reply to
    • Rich Felker

    @dalias we've received a few that haven't been terrible

    In conversation about a year ago from cybervillains.com permalink
  5. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Monday, 15-Jan-2024 19:34:49 JST Damien Miller Damien Miller
    in reply to
    • Rob Pike

    @robpike the year is 34157 (reformed epoch calendar). The final living human reaches out, with their last remaining energy, to add another debugging printf

    In conversation Monday, 15-Jan-2024 19:34:49 JST from cybervillains.com permalink
  6. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Friday, 22-Dec-2023 03:06:25 JST Damien Miller Damien Miller

    The "robustness principle" is the most destructive concept in protocol design and implementation of all time. We should be embracing its inverse: strict, explicit state-machines with model-checked proofs

    In conversation Friday, 22-Dec-2023 03:06:25 JST from cybervillains.com permalink
  7. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Thursday, 09-Nov-2023 07:23:14 JST Damien Miller Damien Miller
    in reply to
    • Annika Backstrom

    @annika First, this is amazing.

    At the risk of being the one guy who doesn't understand the joke: why is the third Buffalo capitalised and not the fourth?

    If the Buffalo buffalo are buffaloing the Buffalo buffalo, then shouldn't the sentence be "Buffalo buffalo buffalo Buffalo buffalo"?

    In conversation Thursday, 09-Nov-2023 07:23:14 JST from cybervillains.com permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      amazing.at
  8. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Sunday, 17-Sep-2023 16:40:47 JST Damien Miller Damien Miller

    We quietly released the code a little while ago but this is the official announcement of Capslock, our contribution to the supply-chain security conversation.

    https://security.googleblog.com/2023/09/capslock-what-is-your-code-really.html

    Capslock is a tool for understanding at high level what a given piece of (Golang) code is capable of and for detecting when an update to a library changes this capability set, to give users a chance to catch supply-chain attacks in progress.

    1/2

    In conversation Sunday, 17-Sep-2023 16:40:47 JST from cybervillains.com permalink
  9. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Thursday, 10-Aug-2023 22:47:37 JST Damien Miller Damien Miller

    I'm happy to announce that #OpenSSH 9.4 has been released.

    This release fixes a few bugs and adds a few small features. Full release notes at https://www.openssh.com/releasenotes.html#9.4p1

    In conversation Thursday, 10-Aug-2023 22:47:37 JST from cybervillains.com permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      OpenSSH: Release Notes
      OpenSSH release notes
  10. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Thursday, 10-Aug-2023 22:44:42 JST Damien Miller Damien Miller
    in reply to
    • Tony “Abolish ICE”Arcieri 🌹🦀

    @bascule here I am perpetually terrified that I'm going to make some subtle crypto fuckup and along comes these clowns

    In conversation Thursday, 10-Aug-2023 22:44:42 JST from cybervillains.com permalink
  11. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Thursday, 20-Jul-2023 03:34:39 JST Damien Miller Damien Miller

    We've just made an OpenSSH release to fix a remotely exploitable RCE vulnerability in ssh-agent's PKCS#11 support (CVE-2023-38408). Details at https://openssh.com/releasenotes.html#9.3p2

    Thanks to the Qualys Security Advisory Team for finding and reporting this bug.

    In conversation Thursday, 20-Jul-2023 03:34:39 JST from cybervillains.com permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      OpenSSH: Release Notes
      OpenSSH release notes
  12. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Tuesday, 18-Jul-2023 15:30:50 JST Damien Miller Damien Miller

    did hell freeze over too? https://sourceware.org/git/?p=glibc.git;a=commit;h=454a20c8756c9c1d55419153255fc7692b3d2199

    In conversation Tuesday, 18-Jul-2023 15:30:50 JST from cybervillains.com permalink

    Attachments


  13. Embed this notice
    Damien Miller (djm@cybervillains.com)'s status on Tuesday, 21-Mar-2023 02:36:28 JST Damien Miller Damien Miller

    Trying to run a short-arc xenon globe from a TIG welder. It didn't work.

    Apart from the wiring mistake (negative/TIG electrode should go to the pointy electrode in the globe), the HF start on my unit wasn't enough to strike the arc.

    I wasn't optimistic going in - the HF start spark on my welder is only about as long as the electrode spacing, but AFAIK these lamps run at several ATM pressure so more voltage is needed to get started.

    Looks like I'll have to make my own power supply...

    In conversation Tuesday, 21-Mar-2023 02:36:28 JST from cybervillains.com permalink

    Attachments


    1. https://files.cybervillains.com/media_attachments/files/110/053/824/640/080/767/original/4eaa0e18dac76b0b.jpeg

User actions

    Damien Miller

    Damien Miller

    debugging, v: the process of inserting printf statements into code until one's errors reveal themselves

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          108699
          Member since
          20 Mar 2023
          Notices
          13
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.