Show more
yt-dl.org

Access denied

Due to a ruling of the Hamburg Regional Court, access to this website is blocked.

Zugriff gesperrt

Aufgrund eines Urteils des Landgerichts Hamburg ist der Zugriff auf diese Website gesperrt.
Here is a hopefully-useful notice about Linux kernel security issues, as it seems like this knowledge isn't distributed very widely based on the number of emails I get on a weekly basis:

- The kernel security team does not have any "early notice"
announcement list for security fixes for anyone, as that would only
make things more insecure for everyone.

- The kernel community does not assign CVEs, nor do we deal with them
at all. This is documented in the kernel's security policy, yet we
still have a number of people asking for CVE numbers even after
reading that policy. See my longer "CVEs are dead..." talk for full
details about how the CVE process is broken for projects like Linux:
https://kernel-recipes.org/en/2019/talks/cves-are-dead-long-live-the-cve/

- You HAVE to take all of the stable/LTS releases in order to have a
secure and stable system. If you attempt to cherry-pick random
patches you will NOT fix all of the known, and unknown, problems,
but rather you will end up with a potentially more insecure system,
and one that contains known bugs. Reliance on an "enterprise"
distribution to provide this for your systems is up to you, discuss
it with them as to how they achieve this result as this is what you
are paying for. If you aren't paying for it, just use Debian, they
know what they are doing and track the stable kernels and have a
larger installed base than any other Linux distro. For embedded,
use Yocto, they track the stable releases, or keep your own
buildroot-based system up to date with the new releases.

- Test all stable/LTS releases on your workload and hardware before
putting the kernel into "production" as everyone runs a different %
of the kernel source code from everyone else (servers run about
1.5mil lines of code, embedded runs about 3.5mil lines of code, your
mileage will vary). If you can't test releases before moving them
into production, you might want to solve that problem first.

- A fix for a known bug is better than the potential of a fix causing a
future problem as future problems, when found, will be fixed then.

I think I need to give another talk about this issue to go into the above in more detail. So much for me giving a technical talk at Kernel
Recipes this year...

honestly surprised the balloons haven’t been replaced with just a bunch of 🖕 by now

Are we just going to ignore the fact that Biden let Hurricane Hillary hit California when he could have used a Sharpie to move it out to sea safely?

@nikodunk @nekohayo @jimmac

- Do consider the energy usage of the apps you create. Some frameworks, databases, whatever may make development easier, but they shouldn't require a lot of hardware resources / energy to work properly.

- Do consider the energy usage of your development workflows. Triggering that CI/CD needlessly is a waste of energy, and so is leaving your hardware on when you aren't using it.

Quoting Greg Kroah-Hartman:
"After Android, Debian is by far the largest Linux user, and the Debian
kernel developers do an awesome job of tracking the stable kernel
releases which have been documented to fix 99% of known security issues _BEFORE_ they are known (data produced by Google security team for 2 years straight)."

99% is probably a little over optimistic (there's certainly some fixes which land in stable trees after they are publicly known), but his core argument is spot-on.

still hanging out in front of fairydust at the marktplatz #cccamp23 where you can play with our open hardware laptops (MNT Reform and Pocket Reform)

Thanks to all who listened to my newbie impressions of #Prolog at #CCCamp23 ! I hope you learned something too. (The talk was recorded and will be available online.)

If you like the way I present, then see you at my #Rust #workshop on Friday :)

It is my pleasure to announce that I'm leading an #embedded #Rust workshop at the #CCCamp23 . Come on Friday 17:00 to #Schattenland at #ChaosZone .

I'll show you how to use #no_std Rust, aka hard mode. Bring your laptop!

Today we #celebrate the 30th birthday of #debian, one of the largest and most important cornerstones of the #OpenSourceCommunity. With its revolutionary package management system and unwavering commitment to free software, the many Debian developers have now shaped the Linux universe for over three decades. We at TUXEDO also ultimately build our TUXEDO OS on the foundation of Debian. For this we would like to thank you very much and wish you the best for the next 30 years!

#happybirthday

Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml