GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Billy O'Neal (malwareminigun@infosec.exchange)

  1. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Saturday, 24-May-2025 23:08:44 JST Billy O'Neal Billy O'Neal
    in reply to
    • ✧✦Catherine✦✧

    @whitequark Please tell me it’s “Bull Shit Definition Language”

    In conversation about 3 days ago from gnusocial.jp permalink
  2. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Friday, 18-Apr-2025 06:27:38 JST Billy O'Neal Billy O'Neal
    • Kevin Beaumont

    @GossiTheDog 4 day weekend? :O

    In conversation about a month ago from infosec.exchange permalink
  3. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 13-Mar-2025 03:44:29 JST Billy O'Neal Billy O'Neal
    • Kevin Beaumont

    I believe @GossiTheDog 's line here is "pass the bong"

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/150/912/160/108/469/original/2aa8880f529e94b5.png
  4. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Tuesday, 28-Jan-2025 16:14:08 JST Billy O'Neal Billy O'Neal
    • Kevin Beaumont

    @GossiTheDog of course if you just delete your profile then they can’t view it in China either

    In conversation about 4 months ago from infosec.exchange permalink
  5. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Sunday, 19-Jan-2025 02:01:36 JST Billy O'Neal Billy O'Neal
    in reply to
    • Ryan Castellucci :nonbinary_flag:

    @ryanc except it’s a firewall broken if one ever sees a packet from the target….

    In conversation about 4 months ago from infosec.exchange permalink
  6. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Tuesday, 24-Sep-2024 10:20:00 JST Billy O'Neal Billy O'Neal
    in reply to
    • mcc
    • Peter Sommerlad
    • Manu Cornet

    @mcc @PeterSommerlad obligatory @lmanul https://goomics.net/62/

    In conversation about 8 months ago from infosec.exchange permalink
  7. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 05:20:35 JST Billy O'Neal Billy O'Neal
    in reply to
    • Haelwenn /элвэн/ :triskell:

    @lanodan sorry I don’t know why I said snap, I meant flatpak.

    In conversation Thursday, 02-Nov-2023 05:20:35 JST from gnusocial.jp permalink
  8. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:54:26 JST Billy O'Neal Billy O'Neal
    in reply to
    • Haelwenn /элвэн/ :triskell:

    @lanodan If I make a snap package or similar I don't have to manage that, because my app comes with all its dependencies.

    Similarly if my app is a bash script or I can statically link everything that matters.

    Again, putting that into an rpm or deb does not fix the original argument, since that rpm or deb won't be signed by the distro. Installing malicious code through an rpm or deb is no different than installing malicious code through curl|sh.

    If you require it to be signed by the distro, you are back in 'supporting Linux actually means supporting ~10 different platforms since there are ~5 distros that matter and their different versions are different universes'. This is a big part of why there's almost no commercial software on Linux.

    In conversation Thursday, 02-Nov-2023 04:54:26 JST from gnusocial.jp permalink
  9. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:36:41 JST Billy O'Neal Billy O'Neal
    in reply to
    • Haelwenn /элвэн/ :triskell:

    @lanodan It isn't 'just deb/rpm', since any given deb/rpm often will not install unless it was produced on a matching distro, because the distros pick particular dependencies.

    In conversation Thursday, 02-Nov-2023 04:36:41 JST from gnusocial.jp permalink
  10. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:29:28 JST Billy O'Neal Billy O'Neal
    in reply to
    • Haelwenn /элвэн/ :triskell:

    @lanodan so to ship my software I now need a paid contract with every distro every one of my customers use? That’s great.

    In conversation Thursday, 02-Nov-2023 04:29:28 JST from gnusocial.jp permalink
  11. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:18:32 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault
    • werdahias

    @drewdevault @werdahias I did. I don’t see how it changed this equation. Saying “Don’t worry about how long it takes distros to ship you” does not solve the problem. I can’t tell customers “sorry, I fixed that bug last year, but your system runs Ubuntu 20.04 or RHEL8 and we haven’t waited around long enough for the unpaid voulentrers that maintain those to ship our update so there’s just nothing I can do for you”.

    In conversation Thursday, 02-Nov-2023 04:18:32 JST from gnusocial.jp permalink
  12. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:17:44 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault
    • werdahias

    @werdahias @drewdevault Great, that means 2 groups of people have to be convinced to ship anything before one can ship anything.

    The amount of folks I deal with who want to ship to Windows, Linux and Mac but drop Linux when they realize it’s actually like supporting at least 5 different platforms (RHEL, Fedora, Debian, Ubuntu, Arch, Alpine, …) is depressing.

    Reinventing another package manager just makes N+1 package managers one has to support. This is why we explicitly refuse requests to make vcpkg into an application deployment system, as we don’t want to make the fragmentation of that universe even worse.

    In conversation Thursday, 02-Nov-2023 04:17:44 JST from gnusocial.jp permalink
  13. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:53 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault @marcan if the server is exploited whether you put the exploiting script in a file first means nothing. This is running code. The user needs to trust where they get that code.

    In conversation Thursday, 02-Nov-2023 04:16:53 JST from gnusocial.jp permalink
  14. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:52 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault @marcan 1. Ok but who really checks the sig in these scenarios? (Do 99% of users even know how?)
    2. If I owned the distributor I probably can get something signed too?

    In conversation Thursday, 02-Nov-2023 04:16:52 JST from gnusocial.jp permalink
  15. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:50 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault great, so to ship software you want the distributor to go through approval processes at all N distros.

    Oh wait there isn’t such a package manager that does that on macos.

    Wait, wasn’t this discussion about curl | sh?

    In conversation Thursday, 02-Nov-2023 04:16:50 JST from gnusocial.jp permalink
  16. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:48 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault homebrew’s installer does curl | sh. 🤷

    In conversation Thursday, 02-Nov-2023 04:16:48 JST from gnusocial.jp permalink
  17. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:46 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault I don’t see how this is specific to macOS. The only solution presented is “all software must come from the distro” which is a terrible answer.

    In conversation Thursday, 02-Nov-2023 04:16:46 JST from gnusocial.jp permalink
  18. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:44 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault all bow to our RedHat and Canonical overlords. No thanks.

    In conversation Thursday, 02-Nov-2023 04:16:44 JST from gnusocial.jp permalink
  19. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Friday, 08-Sep-2023 22:08:07 JST Billy O'Neal Billy O'Neal
    in reply to
    • Paul Cantrell

    @inthehands I doubt it. It's a contract between his private company and the military, that behavior isn't setting US policy

    In conversation Friday, 08-Sep-2023 22:08:07 JST from infosec.exchange permalink
  20. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 24-Aug-2023 15:49:58 JST Billy O'Neal Billy O'Neal
    in reply to
    • Aral Balkan

    @aral I'm referring to Google the search engine, not Google the company, in my post.

    In conversation Thursday, 24-Aug-2023 15:49:58 JST from infosec.exchange permalink
  • Before

User actions

    Billy O'Neal

    Billy O'Neal

    Dev at Microsoft on the vcpkg team. Former @VisualC STL maintainer. He/Him (Although I don’t care much)

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          136729
          Member since
          15 Jun 2023
          Notices
          22
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.