HN user

c0l0

3,619 karma

Web: https://johannes.truschnigg.info/

Posts24
Comments373
View on HN
github.com 2mo ago

Pgbackrest is no longer being maintained

c0l0
451pts232
johannes.truschnigg.info 1y ago

Colodebug: A simple way to improve bash script debugging (2021)

c0l0
12pts1
johannes.truschnigg.info 1y ago

SSH Rate Limiting with Pam and Nftables

c0l0
4pts0
www.phoronix.com 1y ago

Quantifying the AVX-512 Performance Impact with AMD Zen 5

c0l0
4pts0
johannes.truschnigg.info 2y ago

The Impending Great Famine of Our Digitized Society

c0l0
6pts2
developer.mozilla.org 2y ago

Remote Attestation is a WebAuthn first-class citizen

c0l0
5pts1
www.youtube.com 2y ago

The Agile Paradoxon [video]

c0l0
2pts0
confidentialcomputing.io 2y ago

Remote Attestation TLS (RA-TLS)

c0l0
47pts34
forum.proxmox.com 3y ago

Proxmox VE 8.0 Released

c0l0
1pts0
johannes.truschnigg.info 3y ago

Devconf 2023 (Red Hat's Linux/FOSS EU-based conference) – my favourite talks

c0l0
4pts0
futo.org 3y ago

FUTO – Bringing control of computing back to the people

c0l0
1pts0
news.ycombinator.com 3y ago

Tell HN: Google refusing Gmail login with Firefox

c0l0
50pts24
www.theregister.com 3y ago

You thought you bought software – all you bought was a lie

c0l0
24pts1
johannes.truschnigg.info 3y ago

Advanced SSH Usage

c0l0
3pts0
www.nytimes.com 3y ago

In Wealthy City, a Marxist Mayor Wins over Voters

c0l0
2pts0
johannes.truschnigg.info 4y ago

Advanced SSH Usage

c0l0
8pts1
johannes.truschnigg.info 4y ago

Steps towards debugging and resolving Android bootloops

c0l0
31pts3
wiki.gnome.org 4y ago

Vala – modern language offering high level abstractions compatible to the C ABI

c0l0
3pts1
darkimmortal.com 4y ago

Analysis of compression and encryption in LTO drives

c0l0
1pts0
johannes.truschnigg.info 4y ago

Colodebug: a simple way to improve Bash script debugging

c0l0
36pts16
www.washingtonpost.com 4y ago

In Vienna, a visionary example of dealing with urban floods

c0l0
2pts0
craphound.com 5y ago

When Sysadmins Ruled the Earth

c0l0
2pts0
github.com 5y ago

Sudo_pair – 2FA for individual `sudo` commands

c0l0
2pts0
johannes.truschnigg.info 5y ago

Fanless Pfsense Intel 3865U Industrial Mini PC (Fwbox) Review

c0l0
3pts0

I guess it is, but solar can only be part of the answer: You need a solid plan (and all the infrastructure that implementing this plan involves) for when the sun does not shine, because in the more northern parts of Europe especially, energy consumption is highest during seasons in which sunlight is (relatively) scarce.

Also, "the grid" cannot absorb any amount of solar energy - so if you choose to address (at least parts) of the above challenge with a photovoltaic build-out that results in massive excess capacity during summer, there needs to be a plan (and again, its implementation) to handle that.

Long-term, that's the smart and also necessary move. But it can't be done overnight, and the transition has its significant challenges. I hope they don't mess it up it and will address these problems rationally - but given how most EU leaders have acted over these past few years, I remain painfully unconvinced that they will.

With the 25.12 release, the luci app to use ASU for upgrades became installed by default in OpenWrt's "vanilla" images the project builds and provides for supported hardware and devices.

Previous OpenWrt releases at least as far back as 21.02 could be equipped with the same degree of ASU support by installing a single package (luci-app-attendedsysupgrade) and its dependencies.

Windows actually needs to be laid to rest forever. Win32 may live on as a legacy/stable API (via WINE) on superior free and open platforms.

Living in a city in Europe in a very decent apartment in a building that was erected in the 1880s (sic), this article made me chuckle - but also feel bad about how the throwaway society of the 21st century has extended even to things that are supposed to last.

Does Windows on ARM use VBS/Virtualization Based Security, and does ARM support nested virtualization to do so in a VM, too? Does it employ costly CPU vulnerability mitigation techniques that might hit two times in a VM (unless the Hypervisor is adequately set up, which I'd hope is the default for Hyper-V)? Those two things account for most of the common performance problems observed when putting modern Windows in a VM. I'd love to know more about it, but the article does not seem to mention either.

Thanks for this (and I actually learned about PS1's handy Unblock-File this very moment! :)), but I am aware of the "mark of the web"-stuff MSFT had introduced after realizing that an "attacker-controlled" filename extension alone is a poor safeguard against making a file executable ;)

For my specific problem/situation, the executable in question gets transferred to the target machine on a read-only UDF file system burnt onto a USB thumb drive. Other Golang executables from FOSS projects on the same filesystem execute just fine (I guess they have better "reputation", due to their hashes being registered with MSFT somewhere).

"works just fine on Windows as it always has" is just not true. These days, I cannot even run my own cross-compiled Go executables of a cross-platform tool that I am developing in private on Windows 10 or 11, because some blue popup from Windows Defender/"SmartScreen" prevents me from doing so, and tells me to contact the software publisher if I'd like to be able to do something about it. Outright disabling Defender/SmartScreen works around the problem (but the popup doesn't tell me that), and, presumably, signing these executables with a "trusted" developer certificate would make this outcome less probable - that is at least what people online have been telling me.

In my book (I started using computers during ther Windows 3.0 era), this clearly does not qualify as "working just fine on Windows as it always has", no matter how you spin it.

As a wireguard user myself (even on the lone Windows machine that I still begrundingly have), I am happy that this problem could have been resolved. I am just wondering - if there had not been this kind of public outcry and outrage that Mr. Donenfeld discounts in his announcement message, would the issue have been fixed by now?

What are individual developers of "lesser" (less important, less visible, less used) software with a Windows presence to do? Wait and pray for Goliath to make the first benevolent move, like all the folks who got locked out forever from their Google accounts on a whim? Ha!

The fact of the matter is, the code signing requirements on Windows are a serious threat to Free and Open Source Software on the platform. Code signing requirements are a threat to FOSS on all platforms that support this technique, and infinitely more so where it's effectively mandatory. I firmly believe that these days, THIS is the preferred angle/vector for Microsoft to kill the software variety their C-levels once publicly bad-mouthed as "cancer", and zx2c4 is one of the poor frogs being slowly boiled alive. Just not this time - yet.

I am already donating the rough equivalent of the cheapest Microsoft 365 subscription to The Document Foundation each year, and won't stop now just because they're increasing the visibility of their donation-based funding model. I hope they succeed, and many more people start contributing financially as a result.

Thanks, but no thanks. The only winning move, long-term, is to excise everything this wretched company makes from your life as vigorously as possible. It's been true 20 years ago, and it's even more true today.

None of the missing ones have proper, official, upstream LineageOS support. If you install LineageOS on these, you install somebody's own, personal fork of LineageOS. Which might be totally fine, of course. But because of the necessarily different signing keys alone, it's a (potentially) very different thing.

LineageOS 23.2 5 months ago

I disagree. If LineageOS builds were actually unsigned, I would have no way of verifying that release N was signed by the same private-key-bearing entity that signed release N-1, which I happen to have installed. It could be construed as the effective difference between a Trust On First Use (TOFU) vs. a Certificate Authority (CA) style ecosystem. I hope you can agree that TOFU is worth MUCH more than having no assurance about (continued) authorship at all.

LineageOS 23.2 5 months ago

LineageOS isn't unsigned, it just happens to be signed by keys that are not "trusted" (i.e., allowed - thanks for the correction!) by the phone's bootloaders.

Yeah, I can see why that is a show-stopper for people. However, the thingino project has people among them who care deeply about ease of installation - so with these security issues discovered in the TP-Link device, chances are an installation method that relies on a vulnerable stock firmware will be provided in time :)

I realize this is mostly tangential to the article, but a word of warning for those who are about to mess with overcommit for the first time: In my experience, the extreme stance of "always do [thing] with overcommit" is just not defensible, because most (yes, also "server") software is just not written under the assumption that being able to deal with allocation failures in a meaningful way is a necessity. At best, there's an "malloc() or die"-like stanza in the source, and that's that.

You can and maybe even should disable overcommit this way when running postgres on the server (and only a minimum of what you would these days call sidecar processes (monitoring and backup agents, etc.) on the same host/kernel), but once you have a typical zoo of stuff using dynamic languages living there, you WILL blow someone's leg off.

Wireguard FPGA 9 months ago

Yeah that would have been great, but it's not available on our existing core switches (Dell PowerSwitch S5200 series).