The end game of systemd: starting from the next version, the existence of a sysadmin is deprecated, system administration will be delegated to systemd-admind.
Just found a massive footgun if your hostname contains a . (dot), e.g. if you use FQDN directly as /etc/hostname, your gTLD may accidentally become a DNS search domain used by libc. Anyone can register a domain name under your gTLD to bypass DNSSEC. #dns#dnssec
Applied cryptography be like: I have an approved block cipher called AES out there, how can I use it to simulate a stream cipher so I can encrypt Internet traffic? I have a fast stream cipher called ChaCha20 out there, how can I use it to simulate a block cipher so I can encrypt hard drives?
"The echo Request (REQ, Kind=6) and echo Response (RES, Kind=7) Options provide UDP packet-level acknowledgments as a capability for use by upper layer protocols, e.g., user applications, libraries, operating systems, etc. Both the REQ and RES are under the control of these upper layers, i.e., UDP Option support described in this document never automatically responds to a REQ with a RES. Instead, the REQ is delivered to the upper layer, which decides whether and when to issue a RES."TIL You can officially ping someone over UDP now.
/me is copying git repos to my NFS, with the stunning speed of 3 MB/s! The client is already mounted async, but I think each copy is a sync anyway due to close() calls.
#TIL You can use GRUB's filesystem drivers in userspace, it's a huge collection of drivers without root!!!"The program grub-mount performs a read-only mount of any file system or file system image that GRUB understands, using GRUB’s file system drivers via FUSE. (It is only available if FUSE development files were present when GRUB was built.) This has a number of uses: [...]"
"FlashCP was a copy prevention technology [...] This is done through the use of Windows software [...] interfaces with proprietary software in the flash drive. SanDisk manufactured a flash drive using the FlashCP technology, the 256MB Cruzer 'Freedom Drive'".LMAO :blobcatlul:
Unix be like: you want to read a filesystem in an image file owned by you, created previously with "mkfs". You can read every byte in it, but you need a filesystem view. The sysadmin says no, and refuses to grant you "mount" permission, because a crafted file can panic or root the whole machine. But only the kernel has the best driver for it. So you build Usermode Linux, which runs the whole kernel as an userspace app, because you can't just run only the driver, the system is called Unix, not L4 for a reason. Or you run guestmount, which runs the whole kernel in a VM and forwards that mountpoint back to you.
"IPv6AcceptRA=: Note that kernel's implementation of the IPv6 RA protocol is always disabled, regardless of this setting. If this option is enabled, a userspace implementation of the IPv6 RA protocol is used, and the kernel's own implementation remains disabled, since systemd-networkd needs to know all details supplied in the advertisements, and these are not available from the kernel if the kernel's own implementation is used."#TIL systemd-networkd replaces the Linux kernel's RA protocol. It's truly "systemd".
"--no-rs-codes: Do not apply any reed-solomon codes when embedding core.img. This option is only available on x86 BIOS targets."TIL GRUB's legacy BIOS code is protected by ECC.
Programmers: Mom, can we add logical expressions in Unix shells? Mom: No, we have logical expressions at home. Logical expressions at home: An executable named [ that pretends to be an operator.
Hackers, 2000: DMA allows arbitrary memory access! Vendors: Isn't that great? Kernel debugging is so convenient!
Hackers, 2010: FBI and NSA can use ExpressCard and IEEE 1394 DMA to access memory at will and steal full-disk encryption keys from participants in movements like "Occupy Wall Street"! Vendors: How many dissidents across the US are actually going to get targeted by the FBI like that?
Hackers, 2020: USB 4 allows arbitrary memory access via DMA, any standard USB device can be used to steal data! Vendors: Physical security isn't our responsibility - you can just seal off the USB ports.
Hackers, 2025: PCIe DMA enables online game cheats that the system can't detect! Vendors: Right now! Immediately! Enable IOMMU! Anyone who doesn't enable it gets their account banned!
@lanodan@queer.hacktivis.me My computer be like, at one point: Boot up. Old Nvidia Quadro video card Option ROM (5 seconds). BIOS prepares to enter an Option ROM (3 seconds), Highpoint SATA controller RAID menu (5 seconds), BIOS prepares to enter an Option ROM (3 seconds). Intel 10 GbE NIC netboot Option ROM Port #1 menu (5 seconds). BIOS prepares to enter an Option ROM (3 seconds). Intel 10 GbE NIC netboot Option ROM Port #2 menu (5 seconds).
Previously: @niconiconi@cybre.space / Code monkey and sysadmin / No nations, no flags, no patriots. / Chaotic Neutral / Now Accelerationist / currently NEET + hikikomori / ? “Onii-chan is watching you!", use OpenPGP: FAD3EB05E88E8D6D / biologically male, self-identified as '; DROP TABLE genders;