GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Billy O'Neal (malwareminigun@infosec.exchange), page 2

  1. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:18:32 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault
    • werdahias

    @drewdevault @werdahias I did. I don’t see how it changed this equation. Saying “Don’t worry about how long it takes distros to ship you” does not solve the problem. I can’t tell customers “sorry, I fixed that bug last year, but your system runs Ubuntu 20.04 or RHEL8 and we haven’t waited around long enough for the unpaid voulentrers that maintain those to ship our update so there’s just nothing I can do for you”.

    In conversation Thursday, 02-Nov-2023 04:18:32 JST from gnusocial.jp permalink
  2. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:17:44 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault
    • werdahias

    @werdahias @drewdevault Great, that means 2 groups of people have to be convinced to ship anything before one can ship anything.

    The amount of folks I deal with who want to ship to Windows, Linux and Mac but drop Linux when they realize it’s actually like supporting at least 5 different platforms (RHEL, Fedora, Debian, Ubuntu, Arch, Alpine, …) is depressing.

    Reinventing another package manager just makes N+1 package managers one has to support. This is why we explicitly refuse requests to make vcpkg into an application deployment system, as we don’t want to make the fragmentation of that universe even worse.

    In conversation Thursday, 02-Nov-2023 04:17:44 JST from gnusocial.jp permalink
  3. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:53 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault @marcan if the server is exploited whether you put the exploiting script in a file first means nothing. This is running code. The user needs to trust where they get that code.

    In conversation Thursday, 02-Nov-2023 04:16:53 JST from gnusocial.jp permalink
  4. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:52 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault @marcan 1. Ok but who really checks the sig in these scenarios? (Do 99% of users even know how?)
    2. If I owned the distributor I probably can get something signed too?

    In conversation Thursday, 02-Nov-2023 04:16:52 JST from gnusocial.jp permalink
  5. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:50 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault great, so to ship software you want the distributor to go through approval processes at all N distros.

    Oh wait there isn’t such a package manager that does that on macos.

    Wait, wasn’t this discussion about curl | sh?

    In conversation Thursday, 02-Nov-2023 04:16:50 JST from gnusocial.jp permalink
  6. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:48 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault homebrew’s installer does curl | sh. 🤷

    In conversation Thursday, 02-Nov-2023 04:16:48 JST from gnusocial.jp permalink
  7. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:46 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault I don’t see how this is specific to macOS. The only solution presented is “all software must come from the distro” which is a terrible answer.

    In conversation Thursday, 02-Nov-2023 04:16:46 JST from gnusocial.jp permalink
  8. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 02-Nov-2023 04:16:44 JST Billy O'Neal Billy O'Neal
    in reply to
    • Drew DeVault

    @drewdevault all bow to our RedHat and Canonical overlords. No thanks.

    In conversation Thursday, 02-Nov-2023 04:16:44 JST from gnusocial.jp permalink
  9. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Friday, 08-Sep-2023 22:08:07 JST Billy O'Neal Billy O'Neal
    in reply to
    • Paul Cantrell

    @inthehands I doubt it. It's a contract between his private company and the military, that behavior isn't setting US policy

    In conversation Friday, 08-Sep-2023 22:08:07 JST from infosec.exchange permalink
  10. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 24-Aug-2023 15:49:58 JST Billy O'Neal Billy O'Neal
    in reply to
    • Aral Balkan

    @aral I'm referring to Google the search engine, not Google the company, in my post.

    In conversation Thursday, 24-Aug-2023 15:49:58 JST from infosec.exchange permalink
  11. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 24-Aug-2023 15:25:05 JST Billy O'Neal Billy O'Neal
    in reply to
    • Aral Balkan

    @aral I don't agree.

    1. There are lots of things where there is benefit in aggregate usage statistics etc. where there's no reason a user would go looking to turn it on because it doesn't affect immediate product function, but which will make the product better over time when designers can see how and what gets used.

    2. In the 'advertising' cases which are what tend to make people angry, the opt out is functionally the price of the product. Which makes the statement "if you're making something that wouldn't exist if nobody was willing to pay for it, maybe the thing you're making shouldn't exist". By which logic we would have none of the modern commercial internet. The world is better for things like Google existing than not.

    In conversation Thursday, 24-Aug-2023 15:25:05 JST from infosec.exchange permalink
  12. Embed this notice
    Billy O'Neal (malwareminigun@infosec.exchange)'s status on Thursday, 29-Jun-2023 13:38:38 JST Billy O'Neal Billy O'Neal
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller SolarWinds? Seems misugided. Equifax? Now we talkin

    In conversation Thursday, 29-Jun-2023 13:38:38 JST from infosec.exchange permalink
  • After

User actions

    Billy O'Neal

    Billy O'Neal

    Dev at Microsoft on the vcpkg team. Former @VisualC STL maintainer. He/Him (Although I don’t care much)

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          136729
          Member since
          15 Jun 2023
          Notices
          32
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.