[-] rotopenguin@infosec.pub 2 points 1 day ago

Flatseal is the tool.

(Another benefit to using the flatpak version of Steam is that Steam leaks rather substantial chunks of /dev/shm memory. The flatpak automatically cleans that up. God knows why Valve hasn't fixed this yet.)

[-] rotopenguin@infosec.pub 5 points 4 days ago

The simplest way to opt out is to "install any other OS instead".

[-] rotopenguin@infosec.pub 6 points 5 days ago

The hard part is finding a stable identifier, instead of "this interface is know as sink 48 at this exact instant. It will be a completely different number tomorrow. It might even be a potato emoji, who knows?"

[-] rotopenguin@infosec.pub 68 points 5 months ago* (last edited 5 months ago)

How do you know there isn't a logic bug that spills server secrets through an uninitialized buffer? How do you know there isn't an enterprise login token signing key that accidentally works for any account in-or-out of that enterprise (hard mode: logging costs more than your org makes all year)? How do you know that your processor doesn't leak information across security contexts? How do you know that your NAS appliance doesn't have a master login?

This was a really, really close one that was averted by two things. A total fucking nerd looked way too hard into a trivial performance problem, and saw something a bit hinky. And, just as importantly, the systemd devs had no idea that anything was going on, but somebody got an itchy feeling about the size of systemd's dependencies and decided to clean it up. This completely blew up the attacker's timetable. Jia Tan had to ship too fast, with code that wasn't quite bulletproof (5.6.0 is what was detected, 5.6.1 would have gotten away with it).

[-] rotopenguin@infosec.pub 78 points 7 months ago* (last edited 7 months ago)

Patch notes: clause unnecessary. Refactored to cover the general case.

[-] rotopenguin@infosec.pub 76 points 8 months ago

It's an ".avi.exe".

[-] rotopenguin@infosec.pub 71 points 9 months ago

It's kinda wild that GTK's grandpappy is now the last thing to get updated to the current GTK.

[-] rotopenguin@infosec.pub 152 points 10 months ago

I use Ubuntu, which is apparently the least popular distro around.

[-] rotopenguin@infosec.pub 166 points 11 months ago

It's a shame that Valve couldn't get Steam to issue them a new AppID, so they had to delete CSGO in order to put CS2 on the store. It was the only way.

[-] rotopenguin@infosec.pub 86 points 1 year ago

But I might need 99 of every potion for the last boss!

[-] rotopenguin@infosec.pub 76 points 1 year ago

Has anybody mentioned yet that tar isn't even a "compression format"?

view more: next ›

rotopenguin

joined 1 year ago