@h3artbl33d@exquisite.social
@h3artbl33d@exquisite.social avatar

h3artbl33d

@h3artbl33d@exquisite.social

Hacker | OpenBSD | InfoSec | Coffee addict | Todays paranoia is tomorrows truth

This profile is from a federated server and may be incomplete. Browse more on the original instance.

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

@delta

I run into the issue that deltachat-rpc-server doesn't build on OpenBSD, due to the quinn crate (in particular, quinn-udp). The fix isn't trivial.

Should I file a bug report as an issue in deltachat-core-rust repo or as a feature request / support issue on the forum?

GrapheneOS, to random
@GrapheneOS@grapheneos.social avatar

We've pre-ordered a Pixel 8a for our official device testing farm. They push the Android Open Source Project tags and stock OS factory images on the official release day. Should take us a couple hours to add support for it. We'll build, test and make an official release quickly.

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@GrapheneOS

I assume that the Pixel 8a will support MTE as well?

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@GrapheneOS

Yeah, makes sense - seen how modern chip vendors segment their products. Thank you for the answer! Likely will be upgrading to the 8a (with GOS) to gain MTE.

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@chat

Memory Tagging Extension - in this case in ARM, a hardware feature that helps mitigate use-after-free and buffer overflow bugs. In comparison to stock, GrapheneOS has a much more complete (...and enabled by default) implementation and enforcement of it.

@GrapheneOS

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

OpenBSD was right

Newsflash: is always right.

helma, (edited ) to infosec
@helma@mastodon.social avatar

If I were to do a talk at the information security conference #WICCON this October in NL, what topic would you want to hear more about? Other suggestions welcome in reply.

@wicca
#InfoSec #WICCON2024 #Security #Privacy

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@helma

I took the liberty if voting for the surveillance state through the CSAM excuse. If I were to visit a talk, that would have my preference.

I feel like I should mention, within this context, that I am a cisgender male.

@wicca

stux, to random
@stux@mstdn.social avatar

Hm, hmmm! :blobhappy:

I can enjoy it so much when I can overtake cars with my electric bike since they have to wait and I can Keep ridin'n :nkoCool:

Esp stupids brands like BMW and Mercedes, I often put on a HUGE smile when I go past them with my cheap bike :flan_laugh:

"Look at you now with your stupid big car being stuck muwhaha"

Sorry not sorry 🤷

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@RL_Dane @stux

Public transportation in the Netherlands is pretty decent. Especially in comparison to other countries.

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar
h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

We become what we behold
We shape our tools and then
our tools shape us
~ Marshall McLuhan

That quote struck me :flan_aww: I have been using #OpenBSD for little over two decades. Back then, it wasn't love at first sight as documented on a blog. It did grow on me, right to the point where I could say that I truly loved it. I still remember socially engineering my mother for permission to get a Puffy tattoo (which was a requirement before turning 18). Much to my surprise, she was not only okay with it, but offered to give it as my birthday present :flan_heart:

Over the years, OpenBSD and the community have been shaping my views on computing, security and privacy. I am incredibly grateful to Theo, to OpenBSD, to the developers, to the contributors and community at large.

You - collectively and without exception - have been a bless. It has been (and continues to be) an honor. I am forever grateful to you all :heartcyber:

(soon to be continued)

geerlingguy, to opensource
@geerlingguy@mastodon.social avatar

As free money dries up and profits slow, companies slash headcount almost as fast as community trust.

My thoughts on IBM's HashiCorp buyout: https://www.youtube.com/watch?v=hNcBk6cwim8

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@geerlingguy

Almost sounded like "the OpenBSD license", only to realize it was "the open BSD license" :flan_laugh:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Oh my :flan_ooh: A big Youtuber with 20M subscribers (Mrwhosetheboss) talks about Enshittification, features @pluralistic right in the intro.

Now that there is some momentum, it might be a good time to help your loved ones move away from big tech and reclaim their privacy. Please help, you all, increase the awareness!

The video in question:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Eleventy is a simpler static site generator

Have you even met ssg?

$ doas pkg_add lowdown<br></br>$ mkdir -p bin<br></br>$ ftp -Vo bin/ssg https://romanzolotarev.com/bin/ssg<br></br>$ chmod +x bin/ssh<br></br>

Way simpler and doesn't require the bizarre nodejs kitchensink.

Thank you @romanzolotarev

stux, to random
@stux@mstdn.social avatar

What's in my daily toolbelt?

Well, Visual Code Studio, Terminus, Photoshop, FileZilla, Atom and some other utilities ⚒️

Oh, and a saw

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@stux

You have the saw to sever the ties to other Adobe bloat?

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@stux

"Here, another creative cloud tool for you!"

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

A map of Europe drawn from memory

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

From what I gather, from the very limited information available: the signedness folks are being vocal about an NFS exploit and dubbing it as an OpenBSD RCE.

I have no reason to assume that this is misinformation, given the track record of these folks. However: NFS is disabled by default.

If you are running nfsd, especially exposed publicly, you might want to disable it until this vulnerability is patched.

:openbsd:

h3artbl33d,
@h3artbl33d@exquisite.social avatar

Furthermore, both me and PurpleRaiN (from @secbsd fame) went through the source tree. Seems that this is still unpatched.

From that, there is one logical conclusion: the vulnerability is not shared with #OpenBSD. Because if it were, it'll be patched faster than one can pronounce "remote code execution".

Hence, this is irresponsible behaviour. "We have a RCE exploit for NFS on OpenBSD, but we aren't disclosing any details, nah-nah".

h3artbl33d, to Signal
@h3artbl33d@exquisite.social avatar

Signal on OpenBSD

Rust-powered Signal client for the terminal. Sans Java.

Here is how you do it, pending my port:

$ doas pkg_add git protobuf rust<br></br>$ cargo install --git https://github.com/boxdot/gurk-rs gurk<br></br>$ export PATH=~/.cargo/bin:$PATH<br></br>$ gurk<br></br>

Might want to grab a coffee (or beer, wine, whatever your poison is) while cargo runs.

Enjoy - and as always HACK THE PLANET :flan_hacker:

#OpenBSD #Signal

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Apple's move to create a single ecosystem, based on the same architecture is fantastic.

One exploit to pwn them all :flan_hacker:

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Over a decade ago, I took a leap of faith and became an entrepreneur. It has somewhat escalated - as in: my company incorporated and that I have employees nowadays (still getting used to that, but that is a story for another day).

There are some key lessons that I learned, that I want to share:

  • The single most worthy 'asset' is humans. Treat them with respect. If you don't, you'll be digging your own grave. Listen, reward and pay effin attention. Nobody is perfect - nor are you and I.
  • Having an attitude can be good. The client isn't always right - and if you can explain why you don't want to work on it, it might just open their eyes.
  • Being an entrepreneur often requires taking risk. But do it at your own expense - never, ever at the expense of others.
  • Let go. You can't manage everything - even though your company feels like it is your 'child'. Micro-managing will end up hurting everyone.
  • Always be open to learn and adapt. We are human, bound to make mistakes and fuck up. Be honest and humble. Apologize if you effed up.
  • Never, ever, give tight deadlines. If your estimation is three weeks, communicate double (six weeks). It'll cut you some slack when things don't go according to plans.

1/2 🧵

h3artbl33d,
@h3artbl33d@exquisite.social avatar
  • Again: humans. Employees and workers above everything else. Don't ever throw them under the bus. If you do - I might pay you a visit and give you a deserved slap in the face.

And... Silicon Valley (...and others) should be an example of how not to conduct business. Seriously. Steer clear of VC - as it'll only end up hurting everybody.

As a business owner, you should never, ever be the first beneficiary. Because if you are, you are doing it wrong.

2/2 🧵

thomholwerda, to random

There's two ways to handle linking to someone else's work on a blog or news website.

  1. Find an interesting paragraph, quote it, and link back to the post. Add a few lines of your own, if needed. You can also not quote and only link, but that's immaterial.

  2. Take someone else's work, reword it, maybe add a link to an earlier related story you also lazily reworded, to give it a veneer of original reporting, and post it as a full 'new' news story.

@osnews has, since its inception, pretty much exclusively done 1. This is very old-fashioned and not SEO-friendly, but I am convinced it's the only correct way to link to someone else's work, and ensure as much traffic as possible is sent the source's way. I'm always very cognisant of the fact people tend to not follow links to sources, so I try to quote only a taste, a bite, a sample, ensuring people are encouraged to browse to the source and read it in full.

A lot of popular, funded, profit-driven tech news websites do 2. It makes it seem as if every story they post is original reporting, but in reality, it's just a form of theft. It's taking someone else's hard work, posted on a less well-known blog, rewording it just enough to seem original, and claim the clicks. (1/2)

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@thomholwerda

Thank you for that. As Cory Doctorow (@pluralistic) phrases it:

five giant websites, each filled with screenshots of the other four

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@pluralistic

Thank you for the reply and correction. Really appreciate it :flan_heart:

@thomholwerda @tveastman

h3artbl33d, to random
@h3artbl33d@exquisite.social avatar

Did you know that Mastodon has a nifty NSA-esque feature?

It stores all user IP addresses by default for a year :flan_nooo:

Exquisite retains the IP addresses for 4 (four) hours before being pruned completely.

Should we become the target for abuse, we can increase the retention. But one full year? That is just plain and utter madness - and a complete disregard for privacy and protecting the community :flan_molotov:

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@legume

Good question - @mastohost please elaborate on this :)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • InstantRegret
  • magazineikmin
  • modclub
  • khanakhh
  • Youngstown
  • rosin
  • mdbf
  • slotface
  • Durango
  • ngwrru68w68
  • thenastyranch
  • kavyap
  • DreamBathrooms
  • JUstTest
  • cubers
  • osvaldo12
  • Leos
  • anitta
  • everett
  • ethstaker
  • GTA5RPClips
  • tester
  • cisconetworking
  • megavids
  • tacticalgear
  • normalnudes
  • lostlight
  • All magazines