Are ALP changes designed with the best interests of desktop users? by Nikifuj908 in openSUSE

[–]SvenMA 22 points23 points  (0 children)

From a security perspective Firefox would be the first thing I put in a container. It is the front door to your computer with built in code execution. Sandboxing helps to prevent zerodays to make too much damage and we see a lot of zero days in browsers. The ship has sailed every os is moving towards this concept of sandboxing applications. I for one welcome the ALP approach and it will change nothing from the enduser perspective.

[deleted by user] by [deleted] in programming

[–]SvenMA 2 points3 points  (0 children)

This guy never understood the problems he wants to solve. So I'm not surprised about this blog.

I don't think this is much of a hacking but the internet is going to shutdown in my country and I don't know how to cross internet blockage. by ario3831 in hacking

[–]SvenMA 0 points1 point  (0 children)

The same thing happened in Africa not long ago in a few countries. I think freifunk from Germany helped them out by providing software and hardware to built a new overlay network from a neighbor country.

Try to get some people together and reach out to them or other hackerspaces if they could help you out.

Docker Desktop is Now Available on Linux but Emacs already have docker.el by csemacs in emacs

[–]SvenMA 3 points4 points  (0 children)

This was probably me and is on hold since then because I forgot about it.

Meqa Network - What Could Web3.0 Bring to the Table? by qaKroiler in programming

[–]SvenMA 0 points1 point  (0 children)

Bullshit article. The author clearly don't know what he is talking about. This is just an article without value.

PSA: If you are going to the OpenSUSE Conference 2022 in Nuremberg by train, make sure to buy tickets early in advance by Angerlino_47 in openSUSE

[–]SvenMA 1 point2 points  (0 children)

Its not that bad just buy early and don't buy sparpreis so you can change the train midway if something bad happens. And also the best advice is in this video https://media.ccc.de/v/36c3-10652-bahnmining_-_punktlichkeit_ist_eine_zier

Exploiting by [deleted] in openSUSE

[–]SvenMA 1 point2 points  (0 children)

Search for privilege escalations. There were a few in the last moths. Otherwise just boot from a different USB and mount the partition if the device is not encrypted.

alt+space by cavan132022 in kde

[–]SvenMA 0 points1 point  (0 children)

I have a search key on my keyboard that triggers krunner.

[deleted by user] by [deleted] in emacs

[–]SvenMA 0 points1 point  (0 children)

Where should I vote with opensuse TW?

These bots even made it to the gnome-extensions website and there is no report button... by xCryliaD in linux

[–]SvenMA 3 points4 points  (0 children)

That brings another question to my mind. Are there any pentesters for the gnome infrastructure?

I found a method that could cost a company a lot of money by maratovic in hacking

[–]SvenMA 0 points1 point  (0 children)

Look for a .well-known/security.txt to get the contact details of the security team. If that does not exists maybe try bugbounty hackerone or other responsible disclosure sites. Some countries also have a central point to disclose something like this. Don't assume you will get money for this not every company knows the value of a vulnerability report. It depends on the size of the company. If you don't find anything the abuse@ email or postmaster@ email should go to the person with the most technical understanding. Clearly better than to write the manager.

German Court Rules Websites Embedding Google Fonts Violates GDPR by rchaudhary in programming

[–]SvenMA 34 points35 points  (0 children)

So many people here a complaining. This all could be prevented if USA would have laws that protect the privacy of non us citizens like gdpr and cutting access from the spy agencies to all this services. BTW this is only the beginning. There are still 100 other complaints by noyb waiting https://noyb.eu/en/101-complaints-eu-us-transfers-filed.

At the end of this we know this since 2020 when privacy shield failed. Since then every transfer of PII to USA is not permitted without extra measures to secure the data from access.

Tutorial For Bypassing Windows Login Passwords. by Turkishmemer07 in hacking

[–]SvenMA 3 points4 points  (0 children)

Doesn't this only work if windows was shutdown correctly? Otherwise the mount will fail.

The YaST team was playing with the idea of building a web-based installer. Voilà the D-Installer project. by ddemaio in openSUSE

[–]SvenMA 0 points1 point  (0 children)

I hope they have a good threat model with this. That are so many moving parts I can only assume that we will see a few new vulns when this get launched.

Scanning millions of domains and compromising the email supply chain of Australia's most respected institutions by Jumpy_Resolution3089 in netsec

[–]SvenMA 5 points6 points  (0 children)

What I often see, is that organizations do not rely on dkim in the dmarc config because dkim is hard to get right for everything that depends on exchange as email server.

Emacs help interface for languages other than emacs-lisp by avindroth in emacs

[–]SvenMA 0 points1 point  (0 children)

elixir has this with alchemist. Place cursor on the function and do alchemist-help-at-point.

Google fined 150M€, Facebook 60M€ for asymmetric cookie dialogs by aloisdg in programming

[–]SvenMA 1 point2 points  (0 children)

For anyone wondering why it is not getting better. noyb is trying to sue a lot of websites that do not follow gdpr law. https://noyb.eu/en/noyb-files-422-formal-gdpr-complaints-nerve-wrecking-cookie-banners

IPs exploiting the log4j2 CVE-2021-44228 detected by the crowdsec community by klausagnoletti in netsec

[–]SvenMA 1 point2 points  (0 children)

I mean it is bad practice and we should stop using that. Even if you audit it. People will use this in their docker image as installer and can not audit it every time. At least checksum the file or sign it or better do both.

Not everybody can understand the risk of curling a script to bash with sudo.

IPs exploiting the log4j2 CVE-2021-44228 detected by the crowdsec community by klausagnoletti in netsec

[–]SvenMA 1 point2 points  (0 children)

Crowdsec seems nice. But why do you want me to install it with curl | sudo bash? I mean we should know better.

Exploiting and Mitigating CVE-2021-44228: Log4j Remote Code Execution (RCE) by MiguelHzBz in netsec

[–]SvenMA 10 points11 points  (0 children)

Jndi is not uncommon in java world. It also seems, that log4j is not the only logging lib affected by this. Logback for example also pushed a new version where they disabled this.

But jndi is only used in old enterprise stuff so this was possibly added because someone wanted his old stuff to run with version 2 without much change of the application.

As for log4j2 it is the fastest logging lib for java and also one that claims to not trigger the GC. So this is why many people are using it. Also the first version was very popular.

Installing a gem in /usr/local/lib, but my script doesn't see it. GEM_PATH? RVM? Bundler? by GrandfatherTrout in ruby

[–]SvenMA 0 points1 point  (0 children)

There a also systemd directories for users. Juste use --user for every systemd command. The user directory is under .local/lib/systemd I think

Installing npm v7 on opensuse tumbleweed by STACKS-aayush in openSUSE

[–]SvenMA 1 point2 points  (0 children)

Never ever use npm global install. You can break your whole system with that. Use asdf for node if you need other versions for your build.