All things Linux

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
6,069
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
I was using Claude to go through some things I can do to optimize the webserver I have from Digital Ocean and one thing was to reboot it because it had an uptome of like 220 days.
 
Joined
Sep 19, 2018
Messages
6,769
Location
NJ suburb of Philadelphia
SL Rez
2003
SLU Posts
4494
I was using Claude to go through some things I can do to optimize the webserver I have from Digital Ocean and one thing was to reboot it because it had an uptome of like 220 days.
Then there was windows 95 which had some 32 bit counter in a device driver causing it to crash in 49.7 days. Not many people were affected since generally windows 95 crashed before then anyway.
 

Argent Stonecutter

Emergency Mustelid Hologram
Joined
Sep 20, 2018
Messages
7,507
Location
Coonspiracy Central, Noonkkot
SL Rez
2005
Joined SLU
Sep 2009
SLU Posts
20780
Microsoft keeps making that mistake:

Wikipedia said:
Microsoft

In Microsoft Windows 7, Windows Server 2003, Windows Server 2008, and Windows Vista, TCP connection start information was stored in hundredths of a second, using a 32-bit unsigned integer, which caused TCP connections to fail after 497 days.
Windows 95 and Windows 98 had a problem with rollovers in a virtual device driver, VTDAPI.VXD, which used unsigned 32-bit integers to measure system runtime in milliseconds; this value would overflow after 49.7 days, causing systems to freeze.
Until version 6.0, Microsoft's .NET platform had a bug that caused threadpool hill-climbing to fail periodically after 49.7 days due to an overflow while handling milliseconds since startup.

-- https://en.wikipedia.org/wiki/Time_formatting_and_storage_bugs
 
  • 1Thanks
Reactions: Essence Lumin

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,499
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
Servers operated by Ubuntu and its parent company Canonical were knocked offline on Thursday morning and have remained down ever since, a situation that’s preventing the OS provider from communicating normally following the botched disclosure of a major vulnerability.

Attempts to connect to most Ubuntu and Canonical webpages and download OS updates from Ubuntu servers have consistently failed over the past 24 hours. Updates from mirror sites, however, have continued to work normally. A Canonical status page said: “Canonical’s web infrastructure is under a sustained, cross-border attack and we are working to address it.” Other than that, Ubuntu and Canonical officials have maintained radio silence since the outage began.
A group sympathetic to the Iranian government has taken credit for the outage. According to posts on Telegram and other social media, the group is responsible for a DDoS attack using Beam, an operation that claims to test the ability of servers to operate under heavy loads but, like other “stressors,” are, in fact, fronts for services miscreants pay for to take down third-party sites. In recent days, the same pro-Iran group has taken credit for DDoSes on eBay.
 

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
6,069
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
Microsoft probably getting nervous about everyone dumping Windows 11.
 

Govi

Crazy woman yells at clouds
VVO Supporter 🍦🎈👾❤
Joined
Sep 20, 2018
Messages
1,577
Location
North of Surf City
SL Rez
2004
Joined SLU
27.05.2009
SLU Posts
5294
Don Tzu: "People in grass houses should be careful about flaming rocks."
 

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,499
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
I keep trying to swipe left on man pages, but then I remember grindr doesn't have that feature.
 

Free

*censored*
VVO Supporter 🍦🎈👾❤
Joined
Sep 22, 2018
Messages
42,499
Location
Moonbase Caligula
SL Rez
2008
Joined SLU
2009
SLU Posts
55565
Official Red Hat NPM accounts have been compromised and used to push a malicious worm that spreads from machine to machine, where it pilfers sensitive credentials in hopes of stealing yet more confidential data, researchers said.

The supply-chain attack began Monday and remained active at the time this post went live, according to researchers at security firm Aikido. It’s the result of the threat actor responsible for the hack taking control of @redhat-cloud-services, a legitimate channel in the npm repository that’s reserved for official Red Hat packages. As such, the channel is widely trusted by developers who rely on Red Hat cloud services.
It’s unclear precisely how the threat actor took control of the namespace, but it almost certainly involved the compromise of credentials required to access it, possibly through a previous supply-chain attack. More than 30 packages seem to be affected.

The packages execute an obfuscated payload that can run during the npm install process, which occurs before a developer imports or actually uses the package in a production environment. Security firm Socket said an analysis of the malware revealed that it’s designed to collect sensitive credentials, including GitHub action secrets, npm tokens, Kubernetes and Vault material, and credentials for other cloud services. The worm then spreads by republishing backdoored packages to third-party accounts the infected device has access to. Most, but not all, of the packages had been taken down in the hours following the incident.
 
  • 1Interesting
  • 1Wow!
Reactions: Dakota Tebaldi and Govi

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
6,069
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
This is so good and super accurate.

 
  • 1Like
Reactions: Erich Templar

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,844
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791

Spirits Rising

Quite Blunt
Joined
Sep 21, 2018
Messages
653
Location
Clinton, OH
SL Rez
2006
Joined SLU
08/24/2014
SLU Posts
1476
... Considering the horror show Snap packages are described to be by users, I am incredibly glad I no longer use Xubuntu.
 
Last edited:
  • 1Like
Reactions: Dakota Tebaldi

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
6,069
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
I forget if I dislike Snaps or Flatpacks or both. I just want to apt-get ya'll.
 

Argent Stonecutter

Emergency Mustelid Hologram
Joined
Sep 20, 2018
Messages
7,507
Location
Coonspiracy Central, Noonkkot
SL Rez
2005
Joined SLU
Sep 2009
SLU Posts
20780
I'm still pissed nobody but Apple did anything with the NextStep package model, which gives you all the packaging advantages of snaps and flatpack and the like without the security theater that make them suck so badly.
 

Noodles

The sequel will probably be better.
Joined
Sep 20, 2018
Messages
6,069
Location
Illinois
SL Rez
2006
Joined SLU
04-28-2010
SLU Posts
6947
What I don't get doesn't Linux have all the security theater built in, with SUDO and groups and crazy permissions.
 

Dakota Tebaldi

Well-known member
VVO Supporter 🍦🎈👾❤
Joined
Sep 19, 2018
Messages
9,844
Location
Ohio
Joined SLU
02-22-2008
SLU Posts
16791
If flatpak permissions are being annoying, I strongly recommend Flatseal, which lets you manage them per-package in as much detail as you want. Like, flatpaks don't normally see the /mnt directory where I have some storage drives mounted, so if I want a particular flatpak program to be able to read or write in that drive I can use Flatseal to give it access to /mnt, or just that particular drive, or even just a specific folder inside that specific drive, and from now on when I run the program and open the file save window that location will magically be there.

I'm starting to learn how to build programs from source finally, so once I get the hang of that, I suspect I'm going to start preferring it and only use Flatpaks if the source code looks like it's going to be Dependency Hell. So it'll be like, APT always first, and if it's not on APT or the Debian package is too old, then

.deb if available
Source code
Flatpak
AppImage
Snap way down here, last resort, maybe not at all
 
  • 1Agree
Reactions: Spirits Rising

Argent Stonecutter

Emergency Mustelid Hologram
Joined
Sep 20, 2018
Messages
7,507
Location
Coonspiracy Central, Noonkkot
SL Rez
2005
Joined SLU
Sep 2009
SLU Posts
20780
What I don't get doesn't Linux have all the security theater built in, with SUDO and groups and crazy permissions.
The UNIX group model if properly used (like it hasn't really been since they started adding crap like SElinux and other glued-on security models and people quit designing applications around only exposing rights through the set-group mechanism) is actually quite effective. The "turnin" program at college survived years of undergraduate CS majors trying to cheat it. I wouldn't call it "security theater".
 

Argent Stonecutter

Emergency Mustelid Hologram
Joined
Sep 20, 2018
Messages
7,507
Location
Coonspiracy Central, Noonkkot
SL Rez
2005
Joined SLU
Sep 2009
SLU Posts
20780
The NSA has a requirement for mandatory access control (Orange Book) for classified information which nobody outside the federal Governent cares about, but SElinux doesn't even do that right. It's ass all the way down.