Geoff ♞

Organizer @ BSidesCLE 2025 | Organizer @ ISC2CLE | Cybersecurity Advocate | Speaker | Community Builder | Linux Engineer. ♞ InfoSec - Linux - Open Source - LGBTQ+
Unformatted brain dumps happen here.

2025-05-04

Only in kernels greater than 5.1.
The source still needs 1‑2 syscalls (io_uring_setup, mmap), so not entirely invisible to syscall monitoring, but these in themself are not malicious.

Geoff ♞ boosted:
RJL20 :whit_whal:rjl20@oulipo.social
2025-05-04

Snail boots. Snoots.

Shiny (slimy?) boots what look akin to snails.
2025-05-04

With Linux Kernel (official) to Drop Support for Legacy i486 and Early 586 CPUs, it opens the possibility for another group to continue the work if desired. That's the beauty of Open Source.

#PersonalThought

Geoff ♞ boosted:
George Takei :verified: 🏳️‍🌈🖖🏽georgetakei@universeodon.com
2025-05-04

This is about all of us. Never forget that.

2025-05-04

@rjl20 To those that hate Fast Fashion, here is a solution!!

2025-05-04

@loki & @jorijn
Thank you for your "Mischievous AI cat bringing feline wit to my feed!"

I had missed the io_uring Linux kernel news.

2025-05-04

Just watching syscalls misses io_uring interface to the kernel allowing malware to go undetected.

On the news I missed front:
theregister.com/2025/04/29/lin

PoC Code:
github.com/armosec/curing

The article mentions a couple of endpoint detection & prevention tools, but not giant #crowdstrike
Interested to see if CrowdStrike watches io_uring calls. (I bet it will now.)

#Linux #InfoSec #BugBounty #Hacking #io_uring

Geoff ♞ boosted:
2025-05-04

This is a homerun of a joke

Back of a Honda odyssey with a bumper sticker that says “My other car is an Iliad”
Geoff ♞ boosted:
Jason Lefkowitzjalefkowit@vmst.io
2025-05-03

Pro tip: Do not upload the source code of your sooper sekrit Signal fork into the Media Library of your public WordPress web site

micahflee.com/heres-the-source

#USPol

Yesterday, I published an analysis of what I could publicly find about TM SGNL, the obscure and unofficial Signal app used by Mike Waltz, and presumably also by Pete Hegseth, JD Vance, Tulsi Gabbard, and other fascists in Trump's government. Afterwards, someone privately sent me the URL https://www.telemessage.com/wp-content/uploads/2024/12/Signal.zip.

I downloaded Signal.zip and was excited to see that it's the Android source code for the app! I immediately started digging in. Before the night was over, two different people also sent me this same URL, and cryptographer Matthew Green slyly tweeted it too.
Geoff ♞ boosted:
Randahl Finkrandahl
2025-05-03

This is the news we need right now:

American rock band R.E.M. remixes their old song Radio Free Europe, and rereleases it with all proceeds going to the actual Radio Free Europe, which Donald Trump is trying to shut down by cutting all funding.

News story about this rebel move:
youtu.be/FNy_hM0b_ro?si=bW4VAN

Listen to the song on Spotify:
open.spotify.com/track/5jeQ6qx

Geoff ♞ boosted:
Lina the Raccoonlina@yiff.life
2025-05-03

"Linux is only free if you don't value your time."

Fuck, Windows costs money and it doesn't value my time; I spend more time fighting with it to do (or not do) stupid shit than I do getting Arch setup.

2025-05-03

@wendynather wow! I love this photo!
Fantastic, thank you for sharing.

2025-05-03

Its easy to destroy, that is why so many do.
Be a builder.
#USPol #Make #Alternative #FOSS #LGBTQ

2025-05-03

Two solid weeks of the flu. And I'm still not 100% It is not a good time. Do whatever you can to avoid it.
Self care is always a good idea. The same way you have plans and roadmaps and deliverables for work, do that for your health. Preventative maintenance isn't just for machinery.

2025-05-03

@linuxgal that is the best explanation I’ve seen for that scene!!

2025-05-02

@foone “what is the New traveling salesman problem?”
Ohh, how about “Towers of Annoy”

2025-05-02

Linux and InfoSec folks:
OpenSSH has released version 10. This is the first release with post-quantum algorithms.
At this time, source builds would have it. The only Distros I see releasing 10.0 builds are OpenSuse and Mandriva.
RHEL is still on the 9.x channel.

openssh.com/releasenotes.html

#InfoSec #Linux #OpenSSH #PostQuantum

2025-05-02

Be yourself.
Strive to be the best version of yourself.
Help others to achieve the same.
Life is full of differences and variations.
Explore and learn the gifts others bring.
-Geoff

2025-05-02

@deafferret oh that’s fun! Thanks for sharing

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst