@rgacogne@mamot.fr
@rgacogne@mamot.fr avatar

rgacogne

@rgacogne@mamot.fr

Member of the ArchLinux Security Team and package maintainer, PowerDNS dev, TLS, fuzzing, software engineering, Linux stuff.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

gabrielesvelto, to linux
@gabrielesvelto@fosstodon.org avatar

I've updated my tutorial on how to monitor memory on to include information about the kernel_lockdown LSM, and how to make it work when it's enabled.

Long story short, you can still monitor corrected & uncorrected memory errors with kernel lock-down enabled, but only using integrity mode. rasdaemon is incompatible with kernel lock-down confidentiality mode, as it deliberately hides kernel information from userspace applications.

https://www.setphaserstostun.org/posts/monitoring-ecc-memory-on-linux-with-rasdaemon/

rgacogne,
@rgacogne@mamot.fr avatar

@gabrielesvelto Unless I'm mistaken there is a typo in the troubleshooting section: "lockdown=ingerity"

GrapheneOS, to random
@GrapheneOS@grapheneos.social avatar

There's a site impersonating the GrapheneOS project for scamming people (grapheneos dot fr). GrapheneOS does not currently sell phones or work with any company/individual selling phones.

We strongly recommend using the very easy to use web installer: https://grapheneos.org/install/web.

rgacogne,
@rgacogne@mamot.fr avatar
rgacogne, to random
@rgacogne@mamot.fr avatar

Do I have a great #Go developer looking for a job in my contacts?

We at PowerDNS are hiring, remote is not a problem (most of us are remotely working from various places in the EU at the moment): https://careers.open-xchange.com/job/The-Hague-Senior-Software-Developer-PowerDNS-%28Go%29-%28mfd%29/973784855/

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Good morning, Brisbane! First "real" day of #IETF119. https://www.ietf.org/how/meetings/119/

We start with the new "all dispatch" session: new job which does not know where it fits and has to be dispatched somewhere in the large IETF.

rgacogne,
@rgacogne@mamot.fr avatar

@jpmens @bortzmeyer You are not supposed to state the secret end goal out loud!

bagder, to random
@bagder@mastodon.social avatar

c-ares 1.27.0 is here! https://c-ares.org/

Fixes CVE-2024-25629, adds two new functions and fixes a few bugs.

rgacogne,
@rgacogne@mamot.fr avatar

@bagder Is it my own lack of coffee or is the https://github.com/c-ares/c-ares/security/advisories/GHSA-mg26-v6qh-x48q link in the Change Log yielding a 404 error? Or perhaps it's expected because it's not public yet?

rgacogne, to random
@rgacogne@mamot.fr avatar

As you can see, #fosdem is going well!

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Collection of emails received by a free software maintainer. There are many strange people on the Internet. https://github.com/bagder/emails

But some emails are quite nice such as https://github.com/bagder/emails/blob/main/2023/2023-04-14.md

rgacogne,
@rgacogne@mamot.fr avatar

@bortzmeyer This week I personally received several death threats by email from someone who was very unhappy about being subscribed to the dnsdist mailing list. Strange people indeed.

Brevesdepresse, to random French
@Brevesdepresse@mastodon.social avatar

🔴🇨🇵INFO -Derrière la chute d'#Anticor, on retrouve notamment Me Thiriez, un avocat proche de la macronie. À l'Élysée, le retrait de l'agrément de l’association anticorruption, qui lui permettait d’agir en justice, n’a attristé personne, écrit Le Monde... lemonde.fr/m-le-mag/artic…https://www.lemonde.fr/m-le-mag/article/2023/09/17/anticor-un-improbable-trio-derriere-la-perte-de-l-agrement-ministeriel_6189741_4500055.html

rgacogne,
@rgacogne@mamot.fr avatar
bagder, to random
@bagder@mastodon.social avatar

"CVE-2020-19909 is everything that is wrong with CVEs"

A claimed "9.8 CRITICAL" flaw in #curl that does not exist.

https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/

rgacogne,
@rgacogne@mamot.fr avatar

@bagder @Shortfinga Yes, it does. Only Mitre could then decide to allocate a CVE after hearing all parties.

rgacogne, to random
@rgacogne@mamot.fr avatar

"Surprisingly, by chaining four common side effects of shared libraries from official distribution packages, we were able to transform this very limited primitive (the dlopen() and dlclose() of shared libraries from
/usr/lib*) into a reliable, one-shot remote code execution in ssh-agent (despite ASLR, PIE, and NX)."

Qualys continues to deliver, wow! #CVE-2023-38408

https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt

mattblaze, (edited ) to photography
@mattblaze@federate.social avatar

Irritated that Capture One (basically a raw image processor bundled with a better version of Lightroom) has moved to an Adobe-style subscription model. At least they still let you buy a permanent copy (and basically give you the current version for free after 5 years as a subscriber).

Having to buy an annual subscription to manage and edit my own work reminds me how vulnerable we are to the business-model-du-jour of proprietary platforms we rely on.

#photography

rgacogne,
@rgacogne@mamot.fr avatar

@mattblaze I used to like Corel AfterShot Pro, but it might be very light for what you need.

jpmens, to random
@jpmens@mastodon.social avatar

deleted_by_author

  • Loading...
  • rgacogne,
    @rgacogne@mamot.fr avatar

    @jpmens I have one of these, or very close, in front of my house. As far as I know not a single visitor managed to use it, so I usually pay for them using the mobile app which is much easier to use..

    bagder, to random
    @bagder@mastodon.social avatar

    CVE as JSON https://daniel.haxx.se/blog/2023/05/05/cve-as-json/

    My latest thing on the #curl site.

    rgacogne,
    @rgacogne@mamot.fr avatar

    @bagder That's very cool, thank you!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines