Nando Sola is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Nando Sola @mr_solo@mastodon.social

Nando Sola boosted

"Sysadmins needed to create MBR partitions and then nest disklabel partitions inside those MBR partitions.²

² In the quarter century since then, the BSD community has spent innumerable work-hours explaining and then justifying that decision. Learn from our pain. Don’t port your OS to commodity hardware."

#af3e

Nando Sola boosted
Nando Sola boosted

intel ceo resigns Show more

Nando Sola boosted

Thank you #OpenBSD for disabling HyperThreading on Intel. I could not agree more.

HyperThreading was a mis-guided attempt at improving performance of Java threads by copying the SPARC processors without having the SPARC architecture… as usual with these marketing-driven issues it is coming back to bite Intel (and us…).

I never, literally never, ran a piece of code benefitting from HyperThreading nor ever heard anyone brag about it.

Parece que Debian Stretch no es vulnerable a security-tracker.debian.org/tr

Una vez más nos salva el pompis, sin reconocimiento alguno de la comunidad GNU/Linuxera undeadly.org/cgi?action=articl

Esto no ha hecho más que empezar. Meltdown/Spectre/LazyFPU son el aperitivo. Desactiven HyperThreading *ya* (el impacto en rendimiento es significativo) phoronix.com/scan.php?page=art

Nando Sola boosted

Paper about Intel CPU flaw is out:
“LazyFP: Leaking FPU Register State using Microarchitectural Side-Channels”

blog.cyberus-technology.de/ima

Nando Sola boosted
"ps. Disable Intel Hyper-Threading where not needed, until we all know more." -Theo de Raadt

Ooooh I bet Intel is not flushing L1/L2/L3 caches for hyperthreading anymore to increase performance. So if accurate, this means you can steal keys out of it if you run your process on the same CPU core as the process you're attacking
Nando Sola boosted

More details about the Intel CPU issue. Affected OSes:
- Linux (mostly pre 4.4.y, y < 138)
- FreeBSD
- Windows
- KVM when run on affected Linux kernel versions
- All Xen versions and generally all hypervisors that employ lazy FPU switching

Affected CPUs:
- Verified on the Intel Core microarchitecture from Sandy Bridge to Skylake
- State of other processors unclear

There are also attack details, at least for one of three variants they discovered.

blog.cyberus-technology.de/pos

Nando Sola boosted

responsible disclosure Show more

Nando Sola boosted
All watched over by machines – a review of Yasha Levine’s “Surveillance Valley” | LibrarianShipwreck https://quitter.no/url/1789157
Nando Sola boosted

"Speculating about Intel" by Theo de Raadt. A lunchtime BoF at #BSDCan

Yes, it will be livestreamed.

bsdcan.org/2018/schedule/event

Nando Sola boosted
Nando Sola boosted
Nando Sola boosted

#Ruby Web Application Security Defense in Depth by Jeremy Evans. Video isn't available afaik but all slides include the speaker's notes. code.jeremyevans.net/presentat #OpenBSD

Nando Sola boosted

I've been active as a professional since the 90s. I saw at the height of their predatory practices. I saw the Ballmer years.

Even so, the reactions around their acquiring feel like hysteria and histrionics.

Run your projects where you will. I use Gitlab for my own things. But do it because you evaluate the trade-offs and choose, not because you get swept up in some meme.

You may find the alternatives aren't as stable, usable or available as you'd expect.

Nando Sola boosted

"Damn, this centralized tool with paid premium features we blindly rely on has been bought by Microsoft, so let's move to this other centralized tool with paid premium features."

See, that's why we can't have nice things on the Internet.

Nando Sola boosted

I just realized: Electron is a #github project. Microsoft now owns the software tool that many developers were counting on opening up cross-platform development (though it's open source). Any thoughts on how that plays into all this?

Nando Sola boosted

This is a note to people moving their repositories blindly to Gitlab.org: do you know Google is actually a huge investor in Gitlab?

The issue is not about Microsoft buying Github. The issue is about centralization and silos.

You do not solve that by moving your data from one silo to another.

You solve that by relying on small providers you can trust, or by becoming a provider yourself.