Episodios

  • 582: On the CUPS of Disaster
    Sep 30 2024

    We explain the one-packet attack on CUPS and discuss its real-world implications. Plus, a Meshtastic update and more.

    Sponsored By:

    • Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!
    • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
    • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.

    Support LINUX Unplugged

    Links:

    • 💥 Gets Sats Quick and Easy with Strike
    • 📻 LINUX Unplugged on Fountain.FM
    • Attacking UNIX Systems via CUPS — A remote unauthenticated attacker can silently replace existing printers’ (or install new ones) IPP urls with a malicious one, resulting in arbitrary command execution (on the computer) when a print job is started (from that computer).
    • Marcus Hutchins Scan finds 107,287 servers responding to the UDP port 631 — Instead of relying on Shodan data, I performed my own internet-wide scan using a distributed network of servers. This resulted in discovering drastically more exposed cups-browsed instances, causing my total count to rise from 13,289 to 107,287.
    • Shodan on X: 75,000 exposed CUPS daemons on the Internet
    • Annual Membership — Put your support on automatic with our annual plan, and get one month of membership for free!
    • nodeboard — Your Ultimate Digital Inventory Manager
    • Lightning Pay
    • activate-linux — The "Activate Windows" watermark ported to Linux
    • Install Frog on Linux | Flathub — Extract text from images, websites, videos, and QR codes by taking a picture of the source.
    • Clapgrep — Ever had a folder full of PDF files, where you knew, somewhere in there, is what you're looking for. But you did not know in which file. So you had to search each of them at a time...
    Más Menos
    1 h y 8 m
  • 581: The Linux Escape Hatch
    Sep 23 2024

    What if we had to abandon ship and stop using Desktop Linux? We've come up with a master plan, and put it to the test.

    Sponsored By:

    • Jupiter Party Annual Membership: Put your support on automatic with our annual plan, and get one month of membership for free!
    • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
    • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.

    Support LINUX Unplugged

    Links:

    • 💥 Gets Sats Quick and Easy with Strike
    • 📻 LINUX Unplugged on Fountain.FM
    • Meshtastic Linux-Native Application
    • MeshMap — Meshtastic Node Map
    • LINUX Unplugged 269 — What if desktop computing went a very different direction in the late 90s? Deeply multithreaded from the start, fast, intuitive, and extremely stable. This is the world of Haiku, and we go for a visit.
    • The Dawn of Haiku OS — Haiku, unlike its more established competitors, is exceedingly good at tackling one of the toughest challenges of modern computing: multicore microprocessors. Let's take a look at why that is, how Haiku came to be, and whether the operating system running on your computer really performs as well as it should.
    • Haiku Project History
    • Haiku R1/beta5 Release Notes — The fifth beta for Haiku R1 over a year and a half of hard work to improve Haiku’s hardware support and its overall stability, and to make lots more software ports available for use.
    • docker-qemu-haiku — A Docker image for the Haiku operating system.
    • golang-haiku/go — The Haiku port of the Go programming language for upstream support. Changes are made in 'golang-1.11-haiku' or 'golang-haiku-master'.
    • Using the remote app server | Haiku Project
    • JB Haiku Server
    • Lighttpd
    • DHH Talks Apple, Linux, and Running Servers
    • Annual Membership — Put your support on automatic with our annual plan, and get one month of membership for free!
    • dadjoke-cli
    • colmena
    • spectorus' NixOS Config
    • Pick: rustpad — Efficient and minimal collaborative code editor, self-hosted, no database required
    • Is the Nostr moment officially here?
    Más Menos
    1 h y 8 m
  • 580: Brent's Boogie Bus Broadcast Bash
    Sep 16 2024

    The things we like in the new Nextcloud release, and we attempt to upgrade our production server live—from a big blue bus.

    Sponsored By:

    • Core Contributor Membership: Take $1 a month of your membership for a lifetime!
    • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
    • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.

    Support LINUX Unplugged

    Links:

    • 💥 Gets Sats Quick and Easy with Strike
    • 📻 LINUX Unplugged on Fountain.FM
    • OpenSats Grants Long-Term Support for WireGuard Creator Jason Donenfeld
    • OpenSats Lightning Node
    • Nextcloud Hub 9
    • Introducing Nextcloud Hub 9 - the world's leading open source collaboration platform! - YouTube
    • Day 1: Nextcloud Community Conference 2024 - YouTube
    • Day 2: Nextcloud Community Conference 2024 - YouTube
    • Nextcloud Community Conference 2024
    • Mailvelope — Mailvelope is a browser add-on that you can use in Chrome, Edge and Firefox to securely encrypt your emails with PGP using webmail providers
    • Nextcloud Server Releases
    • nextcloud/docker: ⛴ Docker image of Nextcloud
    • Bug: Unable to update background execution mode: conflict between new type (mixed) and old type (string)
    • VLESS
    • hacompanion: Daemon that sends local hardware information to Home Assistant.
    • LNXlink: 🖥 Effortlessly manage your Linux machine using MQTT.
    • Waycheck — Waycheck is a simple graphical application that connects to your Wayland compositor and displays the list of Wayland protocols that it supports, along with the list of protocols that it doesn't.
    • Supersonic — A lightweight cross-platform desktop client for Subsonic and Jellyfin music servers.
    Más Menos
    1 h y 12 m
  • 579: Lost & Found
    Sep 8 2024

    Secret moments from the show you've never heard before. We kick off with some hardware hurdles, then dive into the news and share a few surprising stories.

    Sponsored By:

    • Core Contributor Membership: Take $1 a month of your membership for a lifetime!
    • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
    • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.

    Support LINUX Unplugged

    Links:

    • 💥 Gets Sats Quick and Easy with Strike
    • 📻 LINUX Unplugged on Fountain.FM
    Más Menos
    58 m
  • 578: Young and the Rustless
    Sep 2 2024
    Rust meets Linux in a clash of coding cultures. Why some developers are resisting, and where things go from here.Sponsored By:Core Contributor Membership: Take $1 a month of your membership for a lifetime!Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Support LINUX UnpluggedLinks:💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMBerlin with Brent: September Meetup @ Nextcloud Conference, Sat, Sep 14, 2024Berlin Buds on MatrixLinus Torvalds talks AI, Rust adoption, and why the Linux kernel is 'the only thing that matters'KubeCon + CloudNativeCon + Open Source Summit + AI_Dev China 2024Rust for filesystems — At the 2024 Linux Storage, Filesystem, Memory Management, and BPF Summit, Wedson Almeida Filho and Kent Overstreet led a combined storage and filesystem session on using Rust for Linux filesystems.Filesystem in Rust - Kent Overstreet and Wedson Almeida FilhoAsahi Lina: "I think people really don't appreciate just how incomplete Linux kernel API docs are, and how Rust solves part of the problem."One Of The Rust Linux Kernel Maintainers Steps Down - Cites "Nontechnical Nonsense" — One of the several Rust for Linux kernel maintainers has decided to step away from the project. The move is being driven at least in part due to having to deal with increased "nontechnical nonsense" raised around Rust programming language use within the Linux kernel.[PATCH 0/1] Retiring from the Rust for Linux project - Wedson Almeida FilhoOn Rust, Linux, developers, maintainers — There's been a couple of mentions of Rust4Linux in the past week or two, one from Linus on the speed of engagement and one about Wedson departing the project due to non-technical concerns. This got me thinking about project phases and developer types.The revival of the Linux C++ discussionMembership Summer Discount — Take $1 a month of your membership for a lifetime!Thank you Core ContributorsBrewHouse by the Lake – Amsterdam Brewery ShopBITCOIN WELL — The fastest and safest way to buy bitcoin in CanadaThe new JB server - KTZ systems — Join Alex, Chris, and Brent as we fly to Toronto to deploy our shiny new colo server in Canada. We'll be deploying the 45homelab HL15 server.Projectivy LauncherAerial Views ScreensaverOpenEBS — OpenEBS is a modern Block-Mode storage platform, a Hyper-Converged software Storage System and virtual NVMe-oF SAN (vSAN) Fabric that is natively integrates into the core of Kubernetes.oppy1984's Satoshi SurveyCoder Radio 582Keybase Filesystem Storage LimitsI Don't Care for GnomeDAVx5 — DAVx⁵ DAVx⁵ – CalDAV / CardDAV / WebDAV for AndroidFlock 2024 Universal Blue: Building the Future using Fedora AtomicPick: Shotcut - New Version 24.08Install Shotcut on Flathub — Shotcut supports many video, audio, and image formats via FFmpeg and screen, webcam, and audio capture. It uses a time-line for non-linear video editing of multiple tracks that may be composed of various file formats. Scrubbing and transport control are assisted by OpenGL GPU-based processing and a number of video and audio filters are available.Bonus Pick: Butler — Access your Home Assistant dashboard from a native companion UI, integrating better with your OS.Butler on GitHubRust for Linux revisitedRedox OS — Redox is a Unix-like general-purpose microkernel-based operating system written in Rust, aiming to bring the innovations of Rust to a modern microkernel, a full set of programs and be a complete alternative to Linux and BSD.
    Más Menos
    1 h y 29 m
  • 577: Summer Kernel Corn Roast
    Aug 26 2024
    Sixty vulnerabilities and exposures disclosed in one week sounds like a lot. We'll explain why it's just business as usual.Sponsored By:Core Contributor Membership: Take $1 a month of your membership for a lifetime!Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Support LINUX UnpluggedLinks:💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMToronto Meetup — Thursday, Aug 29, 2024Berlin with Brent — September Meetup @ Nextcloud Conference, Saturday, Sep 14, 2024Check out Alex’s “Building a Colo Server” videoMicrosoft’s latest security update has ruined dual-boot Windows and Linux PCs — The cause: an update Microsoft issued as part of its monthly patch release. It was intended to close a 2-year-old vulnerability in GRUB, an open source boot loader used to start up many Linux devices.What the f*** is an SBAT and why does everyone suddenly care — This update was not supposed to apply to dual-boot systems, but did anyway.SBAT Revocations: Boot Process - Ubuntu Community Hub“Something has gone seriously wrong,” dual-boot systems warn after Microsoft updateUbuntu Will Be Skipping Non-Critical Linux Kernel Updates For September - PhoronixSRU Mailing List AnnoucementCanonical Moves To Shipping Very Latest Upstream Kernel Code For Ubuntu ReleasesKernel Version Selection for Ubuntu Releases - Kernel - Ubuntu Community HubLinus Torvalds Begins Expressing Regrets Merging Bcachefs — The bcachefs patches have become these kinds of "lots of development during the release cycles rather than before it", to the point where I'm starting to regret merging bcachefs.Re: [GIT PULL] bcachefs fixes for 6.11-rc5 - Linus Torvalds — No one is being jerks here, Linus and I are just sitting in different places with different perspectives. He has a resonsibility as someone managing a huge project to enforce rules as he sees best, while I have a responsibility to support users with working code, and to do that to the best of my abilities.LINUX Unplugged 545: 3,062 Days Later — Kent Overstreet, the creator of bcachefs, helps us understand where his new filesystem fits, what it's like to upstream a new filesystem, and how they've solved the RAID write hole.Linux is a CNA — As was recently announced, the Linux kernel project has been accepted as a CNA as a CVE Numbering Authority (CNA) for vulnerabilities found in Linux.The Linux security team issues 60 CVEs a week, but don't stress. Do this insteadWhat is a "good" Linux Kernel bug?Keynote: Linux Kernel Security Demystified - Greg Kroah-Hartman - YouTubeMembership Summer Discount — Take $1 a month of your membership for a lifetime!added pihole nix module by Tdback · Pull Request #3 · JupiterBroadcasting/nixconfigs — Recently, I wanted to start 'nixifying' some of my docker-compose setup. I've created a simple module for spinning up a podman container running pihole as a systemd service, so that way I can just stick it on any NixOS machine and easily make it my DNS server.NetworkManager cli (nmci) wrapper to easily create a new network connectionDistrohopper WheelNo idea where to distrohop next? Let the ultimate distrohopper decide for you!Proxmox Virtual Environment - NixOS WikiPick: SaunaFS is a distributed file system — A robust distributed POSIX file system meticulously designed to revolutionize your storage solutions by offering unmatched efficiency, security, and redundancy. At its core, SaunaFS is a distributed file system primarily written in C++, inspired by the pioneering concepts introduced by Google File System.Google File System - Wikipediasaunafs/INSTALL.md
    Más Menos
    1 h y 20 m
  • 576: The Secret Server
    Aug 19 2024

    We reveal how we turned our humble LAN into a public server farm, all while keeping our IP address under wraps and our ISP blissfully unaware.

    Sponsored By:

    • Core Contributor Membership: Take $1 a month of your membership for a lifetime!
    • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
    • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.

    Support LINUX Unplugged

    Links:

    • 💥 Gets Sats Quick and Easy with Strike
    • 📻 LINUX Unplugged on Fountain.FM
    • Toronto Meetup — Thursday, Aug 29, 2024
    • Berlin with Brent — September Meetup @ Nextcloud Conference, Saturday, Sep 14, 2024
    • Check out Alex's "Building a Colo Server" video — Building a colo server for Jupiter Broadcasting using the 45Homelab HL15 server.
    • Firewall - NixOS Wiki
    • nftables wiki
    • The netfilter.org "nftables" project
    • Gentoo Nftables Examples
    • networking/nftables: add .tables property and disable ruleset flushing by default by mkg20001
    • Example nftables config
    • Olympia Mike on "verified only Flatpaks" — I'm curious your take on a recent update that happened in Linux Mint, and the possible knock on effect of it.
    • Incus is a next generation system container and virtual machine manager.
    • Incus - NixOS Wiki
    • Moving from Proxmox to Incus
    • Membership Summer Discount — Take $1 a month of your membership for a lifetime!
    • Referral Code eXchange
    • auto-tab-discard
    • tab-session-manager
    • OneTab extension for Google Chrome and Firefox
    • Tubular — A fork of NewPipe that implements SponsorBlock and ReturnYouTubeDislike.
    Más Menos
    1 h y 20 m
  • 575: Brent's Busted Builds
    Aug 12 2024
    Brent's computer pulls an all-nighter at the worst possible moment, and the hits keep coming for open-source Android distributions and our new 2FA tool.Sponsored By:Core Contributor Membership: Take $1 a month of your membership for a lifetime!Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps. Support LINUX UnpluggedLinks:💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMToronto Meetup — Thursday, August 29, 2024 from 6:00 PM to 8:00 PM EDTSacramento LUG Meetup — Saturday September 7th, 2024 from 10:00 AM to 2:00 PM PDTAnker PowerConf S330 USB SpeakerphoneCorsair Void RGB Elite Wireless Premium Gaming HeadsetLoss of popular 2FA tool puts security-minded GrapheneOS in a paradoxGrapheneOS on X — Google can either permit GrapheneOS in the Play Integrity API in the near future GrapheneOS on X — If Authy insists on using it, they should use the standard Android hardware attestation API to permit using GrapheneOS too. Banning 250k+ people with the most secure smartphones from using your app is anti-security, not pro-security.GrapheneOS on X — Authy simply delegated checking device integrity to Google. It's Google choosing to block GrapheneOS users from using Authy. Google chooses to allow using a device with no security patches for the past 8 years but bans using an OS much more secure than the stock Pixel OS.Twilio kills off Authy for desktop, forcibly logs out all usersGrapheneOS on X — Our latest release with prevention for most VPN app DNS leaks is currently available in our Alpha and Beta channels. We need more feedback from testing VPN apps and services with leak blocking toggled on, which GrapheneOS already enables by default.GrapheneOS on X — Our current approach to DNS leak blocking appears to work well without breaking compatibility. We've made progress towards fixing a related issue for some VPN apps where rare connections are made to VPN DNS outside of the tunnel. We can hopefully ship stricter enforcement soon.GrapheneOS on X — We've become aware of another company selling devices with GrapheneOS while spreading harmful misinformation about it to promote insecure products. We're making our usual attempt at resolving things privately. However, we need to quickly address what has been claimed regardless.Membership Summer Discount — Take $1 a month of your membership for a lifetime!How You Guys Expect to Beat Me?Blue Iris Containernetbird — Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.netbird on GitHubOpenZiti — Open Source Zero Trust NetworkingOpenZiti on GitHubCollapse OS — Bootstrap post-collapse technologyDocker-OSX — Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.
    Más Menos
    1 h y 26 m