#til

219 posts · Last used 4d

Neuerdings bin ich Aushilfsadmin auf einem Server, der bei @hetzner@mastodon.hetzner.social steht. Nach einer Weile fiel mir auf, dass dieser Server Sicherheitsupdates erst ca. 6 Stunden später bekommt als meine anderen Linux-Server, die woanders stehen. Jetzt habe ich den Grund gefunden: In /etc/apt/sources.list.d/ liegt eine Datei, die https://mirror.hetzner.com/debian/security enthält. Dass Rechenzentrumsbetreiber Spiegel der Paket-Repositories von Gnu/Linux-Distributionen betreiben, ist sicher nicht falsch. Aber Sicherheitsupdates müssen schnell verteilt werden. Dafür sollte man ein Repository einbinden, das schnell aktualisiert wird. Jetzt habe ich diese Stelle durch https://deb.debian.org/debian-security ersetzt und denke, dass ich das Problem damit behoben habe. #hetzner #aptmirror #Sicherheitsupdates #til #sysadmin #itsecurity
34
1
16
0
When I don't have a laptop with me, I sometimes do server admin stuff using my smartphone. It's a reasonably secure phone because it runs a hardened Android distribution called #GrapheneOS. Or so I thought. Shoddy apps can of course violate your security and privacy on any operating system. As a matter of fact, I once set up a Mastodon server via SSH using my smartphone as a terminal. My terminal app of choice is @termux@fosstodon.org – it almost feels like Debian Gnu/Linux. Today I found out that the #Termux developers do not care about their users' privacy: They put Google's DNS resolvers as defaults into their app and do tell their users about it. Which means that until today, Google learnt about each hostname I resolved in Termux, although I had configured my smartphone to use a different DNS resolver. The Termux developers were alerted to this bug ten years ago by @rugk@chaos.social but chose not to do anything about it. Someone wrote a shell script to correct this. But it requires special permissions you can only grant via ADB. So I just used a text editor to replace Google's DNS resolvers with privacy-respecting ones gleaned from @kuketzblog@social.tchncs.de's recommendations in my first link: editor /data/data/com.termux/files/usr/etc/resolv.conf #TIL #dnsleak #terminal #android #app #privacy
5
0
9
0
TIL that Lose/Lose is a 2009 video game made as an art project that erases a random file from your computer for each enemy you beat and can therefore brick it by design if you're not lucky. A reviewer quipped that the game was so scary they only dared play it for 3 seconds. https://en.wikipedia.org/wiki/Lose/Lose #til #todayilearned https://www.reddit.com/r/todayilearned/comments/1wmd9ll/til_that_loselose_is_a_2009_video_game_made_as_an/
7
0
11
0
Replying to
#TIL that BackDrop CMS (a fork of Durupal 7) is working on an ActivityPub plugin; https://backdropcms.org/project/backdrop_federation The latest version is in alpha, released in March this year. If you can help the developers to test or improve it, please do! #BackDrop #ActivityPub #FediDevs @blogdiva@mastodon.social @johnnythan
2
0
5
0
Replying to
@combatwombat@hachyderm.io @diazona@techhub.social @pilum@fedi.j1nk4l.com @apLundell@timeloop.cafe @Taweret@timeloop.cafe#TIL Octaman has an entry on the CthulhuEternal wiki! But it gets a very low tentacle rating there 😆 https://yogwiki.cthulhueternal.com/wiki/Octaman_(1971_film) The Dunwich Horror does better with 3.5 tentacles https://yogwiki.cthulhueternal.com/wiki/The_Dunwich_Horror_(1970_film) #Monsterdon #ReMonsterdon
2
0
0
0
TIL that the spiciest peppers in the world all belong to the exact same species called Capsicum chinense, named because it was mistakenly thought to come from China. It includes the habanero, Scotch bonnet, ghost pepper, Trinidad scorpion, Carolina reaper, Pepper X, and others https://en.wikipedia.org/wiki/Capsicum_chinense#Common_C._chinense_varieties #til #todayilearned https://www.reddit.com/r/todayilearned/comments/1wm0xz5/til_that_the_spiciest_peppers_in_the_world_all/
2
0
2
1
Replying to
@danirabbit@mastodon.online I was curious what the related "news" item was. Searching didn't help, but – as a side effect – #til I could scare myself re #WWIII with a click of a button: https://warmonit.com/global-war-risk
1
0
0
0