HN user

gnufx

1,725 karma
Posts100
Comments1,354
View on HN
www.manchester.ac.uk 1mo ago

Largest scorpion revealed from 415M-year-old fossils

gnufx
5pts0
www.openwall.com 2mo ago

Pintheft Linux LPE

gnufx
4pts3
www.hpcwire.com 5mo ago

Brookhaven Lab's RHIC concludes 25-year run with final collisions

gnufx
100pts69
www.manchester.ac.uk 5mo ago

443M-year-old fossils reveal early vertebrate eyes

gnufx
2pts0
www.manchester.ac.uk 6mo ago

Umping giants: Fossils show giant prehistoric kangaroos could still hop

gnufx
2pts0
link.springer.com 6mo ago

The proposed design of the digital euro: A critical analysis

gnufx
4pts0
www.manchester.ac.uk 8mo ago

Stroke scientists gather more evidence for presence of 'gut-brain axis'

gnufx
2pts0
www.manchester.ac.uk 8mo ago

Why China's central bank is quietly leading the world on climate action

gnufx
1pts0
www.hpe.com 8mo ago

HPE to build two systems for Oak Ridge National: Next-generation exascale

gnufx
6pts0
news.liverpool.ac.uk 9mo ago

First evidence in the UK of breeding aegypti mosquito – main spreader of dengue

gnufx
6pts0
www.manchester.ac.uk 9mo ago

Potential new therapeutic target for asthma discovered

gnufx
2pts0
www.lightbluetouchpaper.org 10mo ago

App-Solutely Modded: Surveying Modded App Market Operators and Original App Devs

gnufx
1pts0
www.lightbluetouchpaper.org 10mo ago

Taking Down Booters: The Cat-and-Mouse Game

gnufx
5pts0
news.liverpool.ac.uk 11mo ago

Will offshore wind energy affect ocean productivity?

gnufx
2pts0
www.manchester.ac.uk 11mo ago

Scientists discover surprising language 'shortcuts' in birdsong – like humans

gnufx
50pts27
dl.acm.org 1y ago

The next 700 programming languages

gnufx
2pts2
www.lightbluetouchpaper.org 1y ago

Human HARMS: Threat modelling social harms against technical systems

gnufx
2pts0
news.liverpool.ac.uk 1y ago

Discovery of collagen in fossil bone could unlock new insights into dinosaurs

gnufx
70pts17
www.bbc.co.uk 1y ago

The rock houses of England's last cave people

gnufx
12pts2
news.liverpool.ac.uk 1y ago

The whole story of human evolution – from ancient apes via Lucy to us

gnufx
1pts0
www.lightbluetouchpaper.org 1y ago

Join Our 3-Course Series on Cybersecurity Economics

gnufx
3pts0
www.gov.uk 2y ago

Unlocking the potential of quantum: £45M investment

gnufx
1pts1
www.bbc.co.uk 2y ago

Annie Nightingale: Trailblazing BBC Radio 1 DJ Dies at 83

gnufx
3pts1
www.manchester.ac.uk 2y ago

Crop spray could lead to mass resistance in new-generation antifungal treatments

gnufx
2pts0
www.theregister.com 2y ago

What comes after open source? Bruce Perens is working on it

gnufx
137pts179
www.lightbluetouchpaper.org 2y ago

Grasping at Straw

gnufx
1pts0
www.lightbluetouchpaper.org 2y ago

Hate Sites Evade the Censor

gnufx
3pts0
news.liverpool.ac.uk 2y ago

Archaeologists discover oldest wooden structure

gnufx
188pts104
taler.net 3y ago

Practical Offline Payments Using One-Time Passcodes [pdf]

gnufx
1pts0
news.liverpool.ac.uk 3y ago

Liverpool begins first human trial of new Zika vaccine

gnufx
1pts0
Pintheft Linux LPE 2 months ago

The latest page cache-related LPE, even though it's not Thursday night (here). EL9 kernels don't have the modules enabled, and the PoC doesn't build on Debian 13 or Ubuntu 24.04, whether or not that means they're safe.

Any university or national HPC system as I'd understand the term is multi-user.

There are also things like the extensive high energy physics WLCG compute federation, which is somewhat different, but can potentially be compromised quickly at large scale. For the original copy-fail we didn't want to drain our WLCG Alma9 cluster, or just kill all the jobs like the university HPC system. We got eBPF mitigation in place within a couple of hours, relieved the exploit signature wasn't in logs from the night before. That would have been done earlier if Proofpoint hadn't bounced the forwarded oss-security article as "contains malware"; sigh.

Yes, but its authN components only act locally, and PAM is optional for sshd. It can/does call out to network services like Kerberos/LDAP given a password, of course, but I was thinking of network authN connected directly with OIDC somehow, for which I don't know a mechanism in vanilla OpenSSH. (I don't know what Authentik does for this -- I could imagine it's behind the scenes somehow.) I should probably look it up sometime.

I'm happy for anyone who doesn't have MS Windows/Active Directory -- so Kerberos -- in their organization, but I'd need (Free)IPA or similar for user/access management anyway. Certificates are an extra layer of SSH-specific complexity, which concerns me for security even if it doesn't involve some third party. MFA is needed once a day, say, for SSO to all Kerberized services. [As I understand it, "managing an OIDC IdP" includes shipping the contents of Active Directory to Entra, heaven help us.]

Setting up Kerberos in 2026 feels somewhat close to malpractice to me.

Microsoft (if that means anything, but they've done good work) and Red Hat obviously disagree, along with decades' experience. It is malpractice not to secure NFS mounts (and other network filesystems with sensitive data), and that means Kerberos.

Yes, FreeIPA is Kerberos+LDAP+X.509 CA, and GSSAPI is in OpenSSH (normally with the key exchange patch). SSSD is a local mechanism, not network authentication. I mentioned authorized keys distribution mechanisms elsewhere, but I was thinking authentication (c.f. OIDC), not authorization.

I don't want to have to get a special purpose credential when I have a TGT which can work generally, and is at least required for secure remote filesystem access.

You have to manage extra infrastructure for certificates and, as a user, have the friction of firing up a JavaScript-enabled web browser via an additional tool, assuming "real IdP" means using OIDC. Unfortunately that flow is actually needed for remote systems and something like Edugain federation, since Moonshot/IETF ABFAB failed, but at least Shibboleth can use the TGT, and it's not the Globus horror.

As far as I remember, that's just because only the find/replace was implemented, and it could have more sophisticated (semantic?) features.

I had a Fairphone 3, and after 5 years, /e/OS was outdated by 4 years w.r.t. the manufacturer updates

Mine is running /e/ and reporting Android 13, which appears to be the last one Fairphone support. /e/ said it was too difficult to support 14 with the kernel involved. It's had continual security updates apart from the Android version.

Edit: Murena make it clear which phones are officially supported and which have "community" support.

In the context of the article "collider" means intersecting particle beams, like in RHIC and LHC, which obviously involves rather low probability interactions, as opposed to accelerators which slam a beam into a dense target (like the SLAC accelerator). In a synchrotron light source you want the beam to circulate and specifically not collide with anything; they were developed from particle physics accelerators, of course.

Oh, I hadn't found that. Yes, it seems strange not to publicize something like that to give users confidence (assuming the audit/pentest isn't damning). It doesn't have to have been perfect initially, as long as appropriate fixes were made.

I've looked without success for external audit reports of either Tailscale and Netbird, like Mullvad gets. While I don't approve of the sort of auditor box-ticking we get at work, it would be reassuring to see a report from a proper security consultancy.

I'm just reading what was written, especially "the specific components we needed", and assuming they're not as incompetent as is being suggested, given they've served me well. Perhaps you haven't been tendering for server hardware recently, even bog-standard stuff, and seen the responses that even say they can't quote a fixed price currently. At least, that's in my part of the world, in an operation buying a good deal of hardware. We also have systems over ten years old running.

commodity hardware

Apart from the "someone's basement", as objected to in this thread, it also doesn't say they acquired "commodity hardware"; I took it to suggest the opposite, presumably for good reason.

Fedora, for instance, is built with LTO, except for some packages which it breaks. I've forgotten the details of where I had to turn it off.