shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

257
active users

#grsec

0 posts0 participants0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://possum.city/@tauon" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tauon</span></a></span> <span class="h-card" translate="no"><a href="https://limepeeps.perchinup.top/@radmin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>radmin</span></a></span> granted <a href="https://infosec.space/tags/SystemD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SystemD</span></a> is a suite of utilities and like the <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> patches &amp; tools they work best together.</p><ul><li>OFC the criticism <em>is valid</em> and I don't deny the problems that occur not just to you...</li></ul><p>All I'm saying is that what came before was <em>objectively worse!</em></p><ul><li>Personally <a href="https://possum.city/notes/a7vl18qge7x200ez" rel="nofollow noopener noreferrer" target="_blank">I had the opposite experience</a> cuz once you want to find a mistake, <a href="https://infosec.space/tags/journalctl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>journalctl</span></a> actually prints useful error messages with <code>journalctl -xe $ServiceName</code> …</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@carlwgeorge" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>carlwgeorge</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.bsd.cafe/@vermaden" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>vermaden</span></a></span> <span class="h-card" translate="no"><a href="https://fosstodon.org/@samurro" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>samurro</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.bsd.cafe/@tara" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tara</span></a></span> Well, that confirms you went <a href="https://infosec.space/tags/ReplyGuy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReplyGuy</span></a> on me in the most disingenious way possible, wasting everyones' time and patience in the process.</p><ul><li>Gues what: Good luck with that sales.pitch, cuz I'd rather give <span class="h-card" translate="no"><a href="https://ubuntu.social/@ubuntu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ubuntu</span></a></span> or <span class="h-card" translate="no"><a href="https://fosstodon.org/@opensuse" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>opensuse</span></a></span> my money cuz that nonchalant attitude is insulting.</li></ul><p>If you (or <a href="https://infosec.space/tags/RedHat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedHat</span></a> / <a href="https://infosec.space/tags/IBM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IBM</span></a>) don't want to support <a href="https://infosec.space/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> or anyone using anything they made for <a href="https://infosec.space/tags/RHEL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RHEL</span></a> without paying, then shure you can do that but then don't expect people to like you.</p><ul><li><a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> already did that and I'm shure it resulted in 0 extra customers.</li></ul><p><a href="https://infosec.space/tags/CentOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CentOS</span></a> was <em>in fact</em> a <em>"gateway distro"</em> and had Red Hat not axed it I would've convinced my (fmr.) boss to consider paying for an RHCSA, but alas I've invested time and effort migrating from CentOS to <a href="https://infosec.space/tags/UbuntuLTS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UbuntuLTS</span></a> and even negotiated commercial support from <a href="https://infosec.space/tags/Canonical" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Canonical</span></a> instead, because they were more friendly and welcoming.</p><ul><li>Personally, I think that Red Hat should just be honest and just stop any <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> contributions, instead try to upsell their customers to <a href="https://infosec.space/tags/zOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>zOS</span></a> on z/Architecture <a href="https://infosec.space/tags/Mainframe" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mainframe</span></a>|s instead cuz that was <em>such a great business</em>...</li></ul><p>Even <em>"Source Available"</em> like <a href="https://infosec.space/tags/Tarsnap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tarsnap</span></a> is better - espechally in <a href="https://infosec.space/tags/finance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>finance</span></a> - because having actual <a href="https://infosec.space/tags/SourceCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourceCode</span></a> available is a matter of <a href="https://infosec.space/tags/trust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trust</span></a>.</p><ul><li>And <a href="https://infosec.space/tags/transparency" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>transparency</span></a> is the reason people choose <a href="https://infosec.space/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> over <a href="https://infosec.space/tags/Solaris" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Solaris</span></a> and other <a href="https://infosec.space/tags/Unix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Unix</span></a>-esque OSes.</li></ul><p>But I'm not getting paid to prevent Red Hat from continuing to shoot itself in the foot...</p><ul><li>In fact, I'd love to short it into the ground!</li></ul><p><a href="https://infosec.space/@kkarhan/113065846313541796" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.space/@kkarhan/1130658</span><span class="invisible">46313541796</span></a></p><p><a href="https://infosec.space/tags/thxbye" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>thxbye</span></a> <a href="https://infosec.space/tags/next" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>next</span></a> <a href="https://infosec.space/tags/EOD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EOD</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://social.treehouse.systems/@marcan" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>marcan</span></a></span> <span class="h-card" translate="no"><a href="https://oxytodon.com/@fuchsiii" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fuchsiii</span></a></span> kinda gives me <a href="https://infosec.space/tags/grsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsecurity</span></a> &amp; <a href="https://infosec.space/tags/RHEL" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RHEL</span></a> - flashbacks:<br>cuz <a href="https://infosec.space/tags/paywalling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywalling</span></a> <a href="https://infosec.space/tags/SourcecodeAccess" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourcecodeAccess</span></a> to paying <a href="https://infosec.space/tags/subscribers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>subscribers</span></a> and penalizing them aka. firing them as clients for exercising their right to share/modify/redistribute the <a href="https://infosec.space/tags/SourceCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourceCode</span></a> is inherently an asshole move but apparently legal.</p><ul><li>Since <a href="https://infosec.space/tags/BrucePerens" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BrucePerens</span></a> failed to sue <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> into not doing that and <a href="https://infosec.space/tags/IBM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IBM</span></a> took notice when they bought <a href="https://infosec.space/tags/RedHat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedHat</span></a>.</li></ul> <p>Not shure if a <a href="https://infosec.space/tags/license" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>license</span></a> that governs things beyond the useage rights of a <a href="https://infosec.space/tags/Software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Software</span></a> is even legally enforceable in Germany amd many other juristictions... </p><ul><li>I'd certainly rather blow €€€€ on a lawyer instead of playing <em>"<a href="https://infosec.space/tags/FuckAroundAndFindOit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FuckAroundAndFindOit</span></a>"</em> and facing insolvency-inducing <em>"cease and decist letters"</em> from competitiors by having flatout-illegal terms...</li></ul><p><a href="https://infosec.space/tags/WhatYouAllowIsWhatWillContinue" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatYouAllowIsWhatWillContinue</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> but then again, <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> <a href="https://lkml.iu.edu/hypermail/linux/kernel/1706.2/06228.html" rel="nofollow noopener noreferrer" target="_blank">really didn't cooperate</a> and I know why most people didn't bother to <a href="https://www.linux-magazin.de/news/kernel-security-linus-disst-grsecurity/" rel="nofollow noopener noreferrer" target="_blank">even consider them</a>.</p>
Kevin Karhan :verified:<p>Sadly the <a href="https://infosec.space/tags/paywalling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywalling</span></a> of <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> / <a href="https://infosec.space/tags/grsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsecurity</span></a> also killed more <a href="https://infosec.space/tags/downstream" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>downstream</span></a> projects like <a href="https://web.archive.org/web/20191230091137/https://en.wikipedia.org/wiki/Tor-ramdisk" rel="nofollow noopener noreferrer" target="_blank">tor-ramdisk</a> which was a minimalist <a href="https://infosec.space/tags/busybox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>busybox</span></a> / <a href="https://infosec.space/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://infosec.space/tags/distro" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>distro</span></a> <a href="https://blogs.gentoo.org/blueness/2014/05/23/tor-ramdisk-a-tiny-embedded-image-to-host-a-tor-relay-or-exit/" rel="nofollow noopener noreferrer" target="_blank">designed</a> to host <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OnionServices</span></a>. It was <a href="https://tor-talk.torproject.narkive.com/jgOoi0bN/tor-ramdisk-20160810-released" rel="nofollow noopener noreferrer" target="_blank">pretty nifty</a> and the <a href="https://infosec.space/tags/SourceCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourceCode</span></a> is <a href="https://gitlab.torproject.org/legacy/gitolite/tor-ramdisk/" rel="nofollow noopener noreferrer" target="_blank">still</a> <a href="https://web.archive.org/web/20200329155520/https://gitweb.torproject.org/tor-ramdisk.git" rel="nofollow noopener noreferrer" target="_blank">online</a> and hosted by <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>torproject</span></a></span> on their <a href="https://infosec.space/tags/gitlab" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gitlab</span></a>, abeit seemingly abandoned since 2018...</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://musician.social/@soulexpress" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>soulexpress</span></a></span> <em>nodds in agreement</em> </p><ul><li>EVERY SINGLE ONE OF THEM!</li></ul><p>Like there's a reason I only got a copy of <a href="https://infosec.space/tags/SubgraphOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SubgraphOS</span></a> as <em>non-public alpha</em> under the precondition to <em>not redistribute</em> and was allowed to <a href="https://www.youtube.com/watch?v=AAdzyCQdxvE" rel="nofollow noopener noreferrer" target="_blank">preview it</a> because that thing was unstable and had a lot of <em>known issues</em> the devs were working on to get fixed.</p><ul><li>It's not as if they weren't aware of those, but they also didn't want <em>"<a href="https://infosec.space/tags/TechIlliterates" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechIlliterates</span></a>"</em> using it with a false belief in it being ready to use and trust in.</li></ul><p>Not shure how <a href="https://infosec.space/tags/Subgraph" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Subgraph</span></a> evolved after <a href="https://infosec.space/tags/grsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsecurity</span></a> decided to <a href="https://infosec.space/tags/paywall" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywall</span></a> access to the <a href="https://infosec.space/tags/sourcecodes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sourcecodes</span></a> of said <a href="https://infosec.space/tags/patches" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>patches</span></a> and <a href="https://infosec.space/tags/tools" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tools</span></a> cuz those were used in said distro as a means to harden it.</p><ul><li>But then again the <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> devs seem to be so toxic, their entire Wikipedia Article got nuked and only an old <a href="https://web.archive.org/web/20200201055409/https://en.wikipedia.org/wiki/grsecurity" rel="nofollow noopener noreferrer" target="_blank">archive version</a> exists.</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://equestria.social/@SweetAIBelle" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>SweetAIBelle</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.space/@OS1337" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>OS1337</span></a></span> shure.</p><p>I'm convinced that a fully-fledged image of that would be similar to <a href="https://infosec.space/tags/toybox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>toybox</span></a>'s <a href="https://infosec.space/tags/mkroot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mkroot</span></a>, which is <span class="h-card" translate="no"><a href="https://mstdn.jp/@landley" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>landley</span></a></span> 's reference implementation for a toxbox + <a href="https://infosec.space/tags/musl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>musl</span></a> / <a href="https://infosec.space/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> system.</p><ul><li>Last time I checked it came out just below 4 MB, but that was the premade image using only the stuff <a href="https://youtu.be/MkJkyMuBm3g" rel="nofollow noopener noreferrer" target="_blank">toybox included</a> [and linux &amp; being statically compiled against musl] like <a href="https://infosec.space/tags/gzip" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gzip</span></a> instead of <a href="https://infosec.space/tags/xz" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>xz</span></a> for compression, so there already is room to shave a few hundred kB without reducing functionality out of the get-go as I've seen with my build tests of <a href="https://infosec.space/tags/kernel666" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>kernel666</span></a>...</li></ul><p>Either way, we're close to <a href="https://youtu.be/cz6iGrhnMKs" rel="nofollow noopener noreferrer" target="_blank">his reference matterial</a> AFAICT and I do think that OS/1337 can become a good and solid foundation for <a href="https://infosec.space/tags/minimalist" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>minimalist</span></a> &amp; <a href="https://infosec.space/tags/embedded" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>embedded</span></a> systems.</p> <p>For comparison:</p><ul><li><p><a href="https://infosec.space/tags/YoctoLinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>YoctoLinux</span></a> is <a href="https://www.yoctoproject.org/" rel="nofollow noopener noreferrer" target="_blank">quite</a> <a href="https://infosec.space/tags/THICC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>THICC</span></a> in comparison (using LSB &amp; <a href="https://infosec.space/tags/GNUtils" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GNUtils</span></a> for the most part!) and stuff like <a href="https://infosec.space/tags/OpenADK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenADK</span></a> seems to be overly complex...</p><ul><li>tho <a href="https://infosec.space/tags/Viprinet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Viprinet</span></a> <a href="https://www.viprinet.com/en/support/downloads#viprinux" rel="nofollow noopener noreferrer" target="_blank">hasn't updated their stuff in like 8 years</a> and I sincerely hope that's just them loginwalling access to <a href="https://infosec.space/tags/SourceCode" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SourceCode</span></a> like <a href="https://infosec.space/tags/grsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsecurity</span></a> to paying customers only and not them such old Kernels.</li></ul></li></ul> <p>Speaking of <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a>, I wounder if Bruce Perens actually sued them for <em>allegedly violating <a href="https://infosec.space/tags/GPLv2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GPLv2</span></a></em> when in fact said license allows <a href="https://infosec.space/tags/paywalling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywalling</span></a> aka. restricting access to buyers of the product it contains.</p><p><a href="https://infosec.space/tags/OS1337" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OS1337</span></a></p>
OS/1337<p>Similarly, a lot of decisions are mostly done out of necessity <br>[i.e. <a href="https://infosec.space/tags/SystemD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SystemD</span></a> doesn't fit into 1440kB] </p><p>or due to licensing conflicts <br>[i.e. <a href="https://infosec.space/tags/grsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grsec</span></a> /#grsecurity is <a href="https://infosec.space/tags/paywalling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>paywalling</span></a> access to it's sources so we won't even consider it as <a href="https://infosec.space/tags/FLOSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FLOSS</span></a>... ]<br><a href="https://grsecurity.net" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">grsecurity.net</span><span class="invisible"></span></a></p><p>Also apparently grsec managed to get their [ <a href="https://infosec.space/tags/Wikipedia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wikipedia</span></a> article wiped ](<br><a href="https://en.wikipedia.org/wiki/Grsecurity" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">en.wikipedia.org/wiki/Grsecuri</span><span class="invisible">ty</span></a> ) so [WaybackMachine to the rescue]( <a href="https://web.archive.org/web/20190429055854/https://en.wikipedia.org/wiki/Grsecurity" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">web.archive.org/web/2019042905</span><span class="invisible">5854/https://en.wikipedia.org/wiki/Grsecurity</span></a> )...</p><p>So yeah...<br>I hope that answers the question...</p>