/Cinny
jesus christ the LLM independently developed scat fetish from first principles
/Cinny
what if you are a demigod but that god is the god of executive dysfunction
/Cinny
/Cinny
@whitequark i don’t know but probably the best use of them i have seen is with the mining flotation chemical “sodium ethyl xanthate”
/Cinny
/Cinny
/Cinny
@ariadne by the time the vuln was published i was already running a fixed version on all my regular linux systems running community-maintained linux distros.
i am not convinced that red hat, a corporate provider of a paid distribution, was unable to provide a patch in a reasonable time frame despite employing one of the maintainers of the kernel crypto/ tree specifically credited in the af_alg.c file.
/Cinny
I wonder if this could be a potential mitigation too
find /usr \( -perm -u=s \) -o \( -perm -g=s \) -type f -exec chmod go-r {} \+
this removes the read bit from suid and sgid binaries so that the vuln can simply not open these files
/Cinny
the fix has been part of mainline for over a month at this point btw :)
/Cinny
@deetwenty i think you can disable it through boot args but yeah
the mitigation outlined on copy.fail doesn’t work
/Cinny
special shoutouts to red hat who sells vulnerable binaries for money
i can understand if community run projects don’t have the best response times but they are literally getting paid for this what is going on
/Cinny
apparently some distros still haven’t patched copyfail
love obsession with version number stability
/Cinny
the vetting process is just getting tested for rabies, raccanine distemper, and raccoon roundworms at the vet