🌉 bridged from ⁂ https://chaos.social/@kpcyrd, follow @ap.brid.gy to interact
Digital independence is nice and everything, but if the USA invasion of Europe starts a war, do I lose my .org domain due to not being able to renew? #diday #digitalsovereignty
Digital independence is nice and everything, but if the USA invasion of Europe starts a war, do I lose my .org domain due to not being able to renew? #diday #digitalsovereignty
https://codeberg.org/kpcyrd/ssh-keyonly
Everything else worked well. I'm also mirroring the repo to Arch Linux' Gitlab […]
https://codeberg.org/kpcyrd/ssh-keyonly
Everything else worked well. I'm also mirroring the repo to Arch Linux' Gitlab […]
haha, maybe I can finally do android development now
haha, maybe I can finally do android development now
https://github.com/seanmonstar/reqwest/releases/tag/v0.13.0-rc.1
https://github.com/seanmonstar/reqwest/releases/tag/v0.13.0-rc.1
There's multiple mainstream implementations, they all have incompatible commandline interfaces, two of them have been unmaintained for 20 years and lack ipv6 support (netcat-traditional and gnu-netcat).
Debian […]
Not in the affected versions, but ever.
#supplychainsecurity #infosec
Not in the affected versions, but ever.
#supplychainsecurity #infosec
https://lists.reproducible-builds.org/pipermail/rb-general/2025-November/003941.html
#supplychainsecurity #infosec
https://lists.reproducible-builds.org/pipermail/rb-general/2025-November/003941.html
#supplychainsecurity #infosec
It's a very cool find and I'm glad it's fixed, but it's not the unconditional local-root that people seem to think it is? Going from www-data to root with this bug seems to be almost […]
It's a very cool find and I'm glad it's fixed, but it's not the unconditional local-root that people seem to think it is? Going from www-data to root with this bug seems to be almost […]
Processing a tar stream with a vulnerable version won't execute […]
Processing a tar stream with a vulnerable version won't execute […]
The cypherpunk movement never really died, it just wasn't necessary while regulators acted mostly reasonable and there are in fact some things […]
The cypherpunk movement never really died, it just wasn't necessary while regulators acted mostly reasonable and there are in fact some things […]
The code assumes an outdated API of the library, that returned either a list of certificates, or a […]
[Original post on chaos.social]
The code assumes an outdated API of the library, that returned either a list of certificates, or a […]
[Original post on chaos.social]
38.54.71.220:16169
Joining my collection of "p2p nodes running in countries with active conflicts". https://map.apt-swarm.orca.toys/
38.54.71.220:16169
Joining my collection of "p2p nodes running in countries with active conflicts". https://map.apt-swarm.orca.toys/
1) starting the process to enable 2FA
2) saving the TOTP secret into bitwarden/vaultwarden
3) enter the confirm code and continue
4) the website askes me to "add a security question", which I didn't want to do, I cancel the setup
5) I delete the TOTP secret […]
1) starting the process to enable 2FA
2) saving the TOTP secret into bitwarden/vaultwarden
3) enter the confirm code and continue
4) the website askes me to "add a security question", which I didn't want to do, I cancel the setup
5) I delete the TOTP secret […]
https://www.debian.org/releases/trixie/release-notes/whats-new.en.html#debian-progress-towards-reproducible-builds
https://www.debian.org/releases/trixie/release-notes/whats-new.en.html#debian-progress-towards-reproducible-builds
```
progpick -e 'env GNUPGHOME=/backup/.gnupg/ gpg --batch --passphrase-fd 0 --pinentry-mode loopback --export-secret-keys YOUR_FINGERPRINT' "$(cat pattern.txt)"
```
```
progpick -e 'env GNUPGHOME=/backup/.gnupg/ gpg --batch --passphrase-fd 0 --pinentry-mode loopback --export-secret-keys YOUR_FINGERPRINT' "$(cat pattern.txt)"
```
https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack
I checked the affected versions against the whatsrc.org dataset, while most of the packages (eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core […]
https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack
I checked the affected versions against the whatsrc.org dataset, while most of the packages (eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core […]
I struggle to jump through the necessary hoops to recover the pgp key needed to renew my subkey - I chose "better […]
I struggle to jump through the necessary hoops to recover the pgp key needed to renew my subkey - I chose "better […]