Posts
21172
Following
432
Followers
800
25. θΔδ*& *NIX Developer.Average Paw Enjoyer. ♿ HSD

pfp by https://www.furaffinity.net/user/wuta-tumaki

lotte adds rac- to words a lot but it doesn’t alter meaning

NSFW posts are not for minors (they will be blocked on sight).

Opinions expressed in this profile are representative of those of your employer.

“u are my favorite therianizing biohazard” — @sodiboo@gaysex.cloud
“you know, maybe i will finally learn to read the content warning before clicking 'view' [—] thanks for this lesson @charlotte” — @ariadne@social.treehouse.systems

@whitequark i don’t know but probably the best use of them i have seen is with the mining flotation chemical “sodium ethyl xanthate”

0
0
0

@fiore @ariadne fixed versions of 2 stable and 1 LTS release were already out for two weeks at that point.

disclosure was a clusterfuck but like

i don’t think red hat has much of a reason to not have it patched already

1
0
1

on lighter news

RHEL 6/7 aren’t affected by copy.fail

0
1
3

@sodiboo i think staring at a cursor is what MLers do when their loss explodes

1
0
0

@ariadne by the time the vuln was published i was already running a fixed version on all my regular linux systems running community-maintained linux distros.

i am not convinced that red hat, a corporate provider of a paid distribution, was unable to provide a patch in a reasonable time frame despite employing one of the maintainers of the kernel crypto/ tree specifically credited in the af_alg.c file.

2
0
0

I wonder if this could be a potential mitigation too

find /usr \( -perm -u=s \) -o \( -perm -g=s \) -type f -exec chmod go-r {} \+

this removes the read bit from suid and sgid binaries so that the vuln can simply not open these files

0
0
0

the fix has been part of mainline for over a month at this point btw :)

2
0
2

@deetwenty i think you can disable it through boot args but yeah

the mitigation outlined on copy.fail doesn’t work

0
0
1

special shoutouts to red hat who sells vulnerable binaries for money

i can understand if community run projects don’t have the best response times but they are literally getting paid for this what is going on

2
0
3

apparently some distros still haven’t patched copyfail

love obsession with version number stability

2
0
2

@maia don’t turn folks into unskippable raccutscenes pls

0
0
1

the vetting process is just getting tested for rabies, raccanine distemper, and raccoon roundworms at the vet

0
0
0

americans making up metric abbreviations like “kilo-pico-hours”

0
1
1

also long uptimes are not a good sign. you want to stay up to date with security updates at the very least. my servers max out at about a week of uptime

1
0
1

like you should absolutely patch it because it’s an incredibly useful stage 2

anyways my scalding sysadmin take is that if your infrastructure needs to survive a single server going down but can’t you built it wrong

2
0
1
Show older