Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

kpcyrd 🏳️‍🌈🏴

@kpcyrd@chaos.social
mastodon 4.6.9
  • Open on chaos.social

Rust Developer 🦀, {Arch Linux,Debian,Alpine} Package Maintainer 📦, Reproducible Builds Enthusiast ⛓, Security Researcher 🦝, Anarcho Communist 🏴

0 Followers
0 Following
20 Posts
Joined December 30, 2022
Github:
https://github.com/kpcyrd
Blog:
https://vulns.xyz/
Arch Linux:
https://archlinux.org/people/package-maintainers/#kpcyrd
Pronouns:
they/them
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago

This took me quite a bit of time, but I managed to boot postmarketOS on a currently unsupported devboard (commonly available for €25-30 where I live).

Little bit proud, but it's not a proper port yet, I ripped the kernel and other parts of the pre-init bootchain (fip.bin, u-boot, ...) from a pre-made Debian image for that device. I have a (mostly working) APKBUILD for that device's userland though. :)

#postmarketos #linux #milkv #riscv64

chaos.social

chaos.social

59
2
11
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 3mo ago
Something to consider for the current #aur incident, if you don't want to engage with the javascript ecosystem anyway - add this to your /etc/pacman.conf: IgnorePkg = npm IgnorePkg = bun Also make sure both packages aren't installed already and uninstall if necessary. #archlinux
7
0
4
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to
@YaLTeR@mastodon.online @zimward@chaos.social @alerque@mastodon.social 😺
2
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to

@G33KatWork@infosec.exchange @dmnk@infosec.exchange a few years ago somebody added document.addEventListener('paste', ...); to their website, sending the contents to their server, and noticed people would randomly paste passwords while reading their blog. It was later suspected this is because many laptop users, especially thinkpads during that time, scroll websites with their paste button, aka middle mouse.

So from a security point of view it's very sensible this is not the default anymore.

1
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 13mo ago
Replying to
@prefec2 @StaticR jayloading
5
1
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 6mo ago
Replying to
@yossarian @andrewnez I have the opposite experience, my specific niche feels desolate, like a lot of people left. Which is understandable after years of layoffs, the promise of a bright future in tech fading, and the "easy money by copy-pasting from stackoverflow"-meme being pretty much dead at this point. Understandably that makes it less attractive for new people to pursue.
1
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 7mo ago
Replying to
@michalfita@mastodon.social @preslavrachev@mastodon.social that would definitely be an improvement, the rest of it might be due to somebody going bonkers with generics (i.e. some kind of complicated callback signature). I have mixed feelings when people don't put in effort to keep their Rust code simple, for people from the outside it's not possible to tell if the language is bad or if the author of the code just has terrible taste.
1
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 7mo ago
Replying to
@GossiTheDog what was the vulnerability you found in those search results over and over? I only get html and css stuff when I click that link.
1
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 9mo ago
Replying to
@JessTheUnstill@infosec.exchange I spent some time with embedded Rust recently, I wrote a savegame library that's optimized for low-level flash storage, with power-fail safety and wear leveling: https://github.com/kpcyrd/embedded-savegame I specifically designed it to work with the ch32v003 (2kb ram, 16kb flash) by implementing djb2 for embedded Rust too, instead of using crc32. I also wrote some documentation for programming the microcontroller itself: https://github.com/kpcyrd/ch32v003-demo
GitHub

GitHub - kpcyrd/embedded-savegame: Savegame library for embedded with powerfail-safety and wear leveling

Savegame library for embedded with powerfail-safety and wear leveling - kpcyrd/embedded-savegame

1
0
1
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 6mo ago
Replying to
Note the https:// may not be visible in your fediverse client, if the copy-pasted command doesn't work for you, make sure both urls (--doh-url and the last argument) start with https://
0
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 6mo ago
Replying to
@tekkie it's not really "supply chain", it's just a "normal" vulnerability ✌️
0
2
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 10mo ago
Replying to
@luj@chaos.social @raboof@merveilles.town very cool to see this progress! :3 Since it mentions 'decentralized', I'm not sure how to read the interface: Are all builds/attestations done by the reproducibility.nixos.social entity, or a collection from multiple groups/entities? Would another instance host their results on their own domain, like with rebuilderd and reproducible.archlinux.org/reproduce.debian.net, and decentralized means you can run your own instance?
0
5
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 10mo ago
Replying to
@luj@chaos.social @raboof@merveilles.town in that case I'd probably want to know who submitted e.g. https://reproducibility.nixos.social/evaluations/2/adaa24fbf467 so I can decide if I trust those results. :) If it's from somebody with a good reputation -> yes, if it's "somebody on the internet said [...]" it'd take that with a healthy amount of salt. :)
reproducibility.nixos.social
0
3
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 6mo ago
Replying to
@jas@fosstodon.org It looks like there have been rustsec advisories (RUSTSEC-2026-00{23,24,25,26}), but only one of them has a severity of 'high', the other ones have a severity of 'none'. Anybody can send pull requests to the advisory-db, maybe the author of the blogpost could add to them and adjust the impact/severity/description/title. Note also (by @djc@hachyderm.io): https://github.com/cryspen/libcrux/issues/1335
github.com
0
4
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to
@cpu@hachyderm.io as the author of an acme integration, what would be a good time to renew in advance? :) I think I currently have this set to 7 days. Also curious to learn more about ARI.
0
1
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to

@jbz@indieweb.social That's more an opinion post instead of a fact based one. Evidently the gold standard for crypto primitives on the lowest level is not C but assembly, and there is no reason why you would have to use C to call into your assembly instead of using Rust directly.

unsafe means "turn off the compiler guardrails", and while this is inherently necessary to call into your assembly, it's a bad reason to conclude "might as well rawdog ASN.1 and all of TLS with guardrails off too".

0
0
1
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 7mo ago
Replying to
@sharlatan@mastodon.social @nmeum@chaos.social as far as I know it's a bug in gcc's LTO streamer, the #line macro is causing a temporary path to be included in a way that isn't normalized by prefix-strip (Foxboron did research/work on this): https://gcc.gnu.org/pipermail/gcc-patches/2024-March/647303.html https://github.com/golang/go/pull/53528
gcc.gnu.org

[PATCH] lto-streamer: Ensure src_pwd is remapped

0
0
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to
@Pol@mathstodon.xyz Nice, congrats! I noticed there's some json parsing code in there, you might be able to use serde_json::from_str and serde_json::Value. When you enable the indexmap feature the dict/map variant should retain the original key order. :)
0
2
0
0
Open post
kpcyrd 🏳️‍🌈🏴 @kpcyrd@chaos.social
· 5mo ago
Replying to
@sam@shonk.sam.ax @ariadne@social.treehouse.systems @jvoisin@infosec.exchange as much as I want forgejo to be the good folks, the optics ain't great: https://codeberg.org/forgejo/forgejo/pulls/12288 You may ASK unpaid security research volunteers to participate in some coordinated disclosure, but you can't demand they surrender their free time beyond the report. The maintainers are NLnet funded, the security researcher is operating on goodwill. The bugs are still sitting unaddressed in the open, although there's a recent commit fixing token expiry.
Codeberg.org

fix(markup): don't trust user-supplied strings

The fix removes the `strings.NewReplacer` substitution that injected user-influenced SrcLink()/RawLink() values (containing repo name, branch name, etc.) into the command string before `strings.Fields()` splitting. The values are already safely passed as environment variables `GITEA_PREFIX_SRC...

0
3
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:52:06 UTC