eb, to security
@eb@social.coop avatar

Unfolding now: https://news.ycombinator.com/item?id=39865810

An incredibly technically complex in xz (potentially also in libarchive and elsewhere) was just discovered. This backdoor has been quietly implemented over years, with the assistance of a wide array of subtly interconnected accounts:

The timeline on this is going to take so long to unravel

eb,
@eb@social.coop avatar

https://boehs.org/node/everything-i-know-about-the-xz-backdoor

I have begun a post explaining this situation in a more detailed writeup. This is updating in realtime, and there is a lot still missing.

nixCraft, to random
@nixCraft@mastodon.social avatar
nixCraft, to random
@nixCraft@mastodon.social avatar
davidrevoy, to linux
@davidrevoy@framapiaf.org avatar
ikkeT, to linux
@ikkeT@mementomori.social avatar

Fun and heart warming #Linux #kernel contrib from 4-year old about "s" letter feeling sad and lonely at the end of line, missing header hilight as the all other letters have. ❤️

Copy from https://twitter.com/linux_deepin/status/1691396817039314945

Image describing the mentioned sd s at the end of line.

archlinux, (edited ) to random
@archlinux@fosstodon.org avatar

Upgrade your systems now!

The xz package has been backdoored

https://archlinux.org/news/the-xz-package-has-been-backdoored/

fedora, to fedora
@fedora@fosstodon.org avatar

🚨 ⚠️ Emergency PSA: A critical security exploit was discovered in the xz package recently, used for compression and decompression on nearly all Linux distributions.

Rawhide users ARE impacted and should immediately STOP using Rawhide until the package update is fully rolled back. (1/3)

Security Advisory: https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users

nixCraft, to linux
@nixCraft@mastodon.social avatar
sonny, to linux
@sonny@floss.social avatar

Orca the Linux screen reader now has a website!

https://orca.gnome.org/

Thanks to @snwh

And thank you Joannie, @igalia and the community for all the ongoing work and support.

sesivany, to linux
@sesivany@floss.social avatar

shitposting

davidrevoy, to linux
@davidrevoy@framapiaf.org avatar

:neko_cats_eye: Today I'm going to show you how I turned a cheap USB numeric keypad into a pad that I use for my digital painting shortcuts under GNU/Linux.
→ Tutorial: https://www.davidrevoy.com/article989/how-to-customise-a-usb-numeric-keypad-under-gnulinux

#Keypad #Linux #NailPolish
#diy #Krita #MastoArt

EncoreUneMarie, to windows French
@EncoreUneMarie@diaspodon.fr avatar

Si quelqu'un a un job d'amin cybersecurité dans le sud de Paris avec télétravail (par pitié) n'hésitez pas à me faire signe. J'suis sympa, je m'intègre bien et je suis moins bête que je n'en ai l'air.
J'ai bossé sur #cyberark
Je suis très bonne en systèmes #windows et cherche à me former sur #linux
Je parle couramment l'anglais
J'ai travaillé sur le #SOC #checkpoint
Je fais du #powershell à mes heures perdues

fedora, to fedora
@fedora@fosstodon.org avatar

Fedora Linux 40 is HERE! Check out all our latest variants for desktop, server, and more.

New features include:

  • @kde Plasma 6
  • @gnome 46
  • Fedora Atomic Desktops (rebrand for Silverblue et al)
  • PyTorch / ROCm
  • And more!

Learn more and try Fedora 40 today! https://fedoramagazine.org/announcing-fedora-linux-40/

#Fedora #Linux #OpenSource #Gnome #KDE

nixCraft, to linux
@nixCraft@mastodon.social avatar

Two types of users. which one are you?

davidrevoy, to linux
@davidrevoy@framapiaf.org avatar

Here is my new GNU/Linux distribution guide about Debian KDE 12, the right GNU/Linux distribution for professional digital painting in 2024! Also about three major problems with GNU/Linux distros that will drive away all professional artists, IMO, and how I got kicked out of the Fedora KDE ecosystem with F40, which imposed Plasma6 and Wayland. I hope it helps other artists here!

Blog post: https://www.davidrevoy.com/article1030/debian-12-kde-plasma-2024-install-guide

ricci, to Kubernetes
@ricci@discuss.systems avatar

Okay, so let me tell you about my doorbell, from a perspective.

When you push the button by the door, it sends a message over the wireless mesh network in my house. It probably goes through a few hops, getting relayed along the way by the various Zigbee light switches and "smart outlets" I have.

Once it makes it to my utility closet, it's received by a Zigbee-to-USB dongle, through a USB hub (a simple tree network) plugged into an SFF PC. From there, it gets fed into zigbee2mqtt, which, as the name implies, publishes it to my local broker.

The mqtt broker is in the small cluster of nodes I run in my utility closet. To get in (via a couple of switch hops), it goes through , which is basically a proxy-ARP type service that advertises the IP address for the mqtt endpoint to the rest of my network, then passes the traffic to the appropriate container via a veth device.

I have , running in the same Kubernetes cluster, subscribed to these events. Within Kubernetes, the message goes through the CNI plugin that I use, . If the message has to pass between hosts, Flannel encapsulates it in VXLAN, so that it can be directed to the correct veth on the destination host.

Because I like for automation tasks more than HomeAssistant, your press of the doorbell takes another hop within the Kubernetes cluster (via a REST call) so that NodeRed can decide whether it's within the time of day I want the doorbell to ring, etc. If we're all good, NodeRed publishes an mqtt message (more VXLANs, veths, etc.)

(Oh and it also sends a notification to my phone, which means another trip through the HomeAssistant container, and leaving my home network involves another soup of acronyms including VLANs, PoE, QoS, PPPoE, NAT or IPv6, DoH, and GPON. And maybe it goes over 5G depending on where my phone is.)

Of course something's got to actually make the "ding dong" sound, and that's another Raspberry Pi that sits on top of my grandmother clock. So to get there the message hops through a couple Ethernet switches and my home WiFi, where it gets received by a little custom daemon I wrote that plays the sound via an attached board. Oh but wait! We're not quite done with networking, because the sound gets played through PulseAudio, which is done through a UNIX domain socket.

SO ANYWAY, that's why my doorbell rarely works and why you've been standing outside in the snow for five minutes.

nixCraft, to linux
@nixCraft@mastodon.social avatar
gnome, to GNOME
@gnome@floss.social avatar

Today we're celebrating the 26th anniversary of GNOME 🎉🎉
Thank you to all our outstanding contributors and community members for helping make the #GNOME project what it is today!

#opensource #FOSS #linux

nixCraft, to linux
@nixCraft@mastodon.social avatar

#Linux is so savage 😂👇

ainmosni, to python
@ainmosni@berlin.social avatar

I'm looking to get

Are you looking for a freelance developer/architect with:

  • Over 20 years of experience in various tech roles.
  • Success in designing scalable services, both of the monolithic. and microservice variety.
  • Well versed in designing verification systems based on cryptography.
  • Expert in writing , and .
  • Experienced in writing many other languages and frameworks.
  • Expert in and based deployments.

DMs are open if you need more info.

fedora, to fedora
@fedora@fosstodon.org avatar

Fedora Linux 39 is here! Thank you for your patience as we made sure this release was as stable as you’ve come to expect.

Changes include:

  • Introduction of Fedora Onyx (immutable @buddiesofbudgie Spin)
  • @gnome 45 for Fedora Workstation
  • Fedora Cloud images available in Azure
  • And more! Check it out!

➡️ https://fedoramagazine.org/announcing-fedora-linux-39/

nixCraft, to opensource
@nixCraft@mastodon.social avatar

Germany's Sovereign Tech Fund Becomes First Governmental Sponsor of FFmpeg Project. See https://ffmpeg.org/index.html#stf24 and https://www.sovereigntechfund.de/tech/ffmpeg #opensource #unix #linux

rinidisc, to linux

She gives the best advice
#linux #xenia #art #furryart #mastoart

linuxtechmore, to firefox
@linuxtechmore@linuxrocks.online avatar

✍️ Firefox Isn't Just a Browser; It Is a Web Resistance, and It's Now at Version 119

I'm baffled as to why Google Chrome still dominates the browser market when Firefox, a faster and privacy-conscious open-source browser, is readily available!

In the previous update, Firefox introduced a long-awaited feature – an automatic and customizable built-in translation. With this addition, Firefox fills a significant gap that was once held against it.

Now, with the latest update, Firefox 119 not only surpasses Chrome (I'm confident it does) but also competes with PDF editors. With great excitement, let's explore what this latest version has in store.

https://www.linuxtechmore.com/2023/10/what-is-new-in-firefox-119.html

#Firefox #Linux #Privacy #Security

cassidy, to GNOME
@cassidy@blaede.family avatar

Do you work on GNOME or adjacent stuff? Do you want to help improve the GNOME desktop around usability, reliability, safety, digital well-being?

GET PAID TO DO IT!

The @gnome Foundation is offering a one-year contract (with potential to extend) to work on the above on behalf of the Foundation. You’d probably interact with me, the GNOME design team, and core maintainers of GNOME components.

https://foundation.gnome.org/2024/01/12/application-open-for-gnome-foundation-software-engineer/

#GNOME #Linux #OpenSource #FOSS #FLOSS #GetFediHired #OpenPosition #hiring

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • magazineikmin
  • mdbf
  • thenastyranch
  • khanakhh
  • rosin
  • Youngstown
  • ethstaker
  • slotface
  • modclub
  • kavyap
  • DreamBathrooms
  • Durango
  • provamag3
  • ngwrru68w68
  • InstantRegret
  • tacticalgear
  • GTA5RPClips
  • cubers
  • normalnudes
  • osvaldo12
  • tester
  • anitta
  • cisconetworking
  • megavids
  • Leos
  • lostlight
  • All magazines