151 Followers
137 Following
2.5K Posts

Just another Linux hacker

Constantly struggling to hide my affection of hacker subculture and memes behind the veil of corporate professionalism.
Father of 2, master of none.

Interested in #MotorSport, #F1, #VintageCars, #VideoGames, #InfoSec, #OpenHAB, #HomeAutomation, #Linux, #OSS.

Thoughts and opinions are my own.
I am not a bot (that I'm aware of).

Be compassionate when your users get phished. If it can happen to the Director of the FBI, it can happen to anyone.

> builds a GRUB replacement in 2016
> spends 5 years breaking GRUB piece by piece
> strips LUKS encryption from /boot "for security"
> proposes to remove: btrfs, xfs, zfs
> keeps SquashFS, two CVEs, one rated 7.8 HIGH
> controls the signing keys for all of it
> Canonical promoted him.

https://www.sambent.com/canonicals-grub-saboteur-has-a-10-year-plan

@joshbressers yeps. When we do too much trusting and too little verifying, we open up for badness to strike.

@bagder I love this message. Open source was never about trust and will never be about trust

It’s always been about the ability to verify

Childhood is idolizing Batman. Adolescence is when Joker starts to make sense. Adulthood is realizing Commissioner Gordon doesn’t get paid enough to deal with their crap.

@yifanlu Cool find 😎.

I learned about your disclosure this morning when it made it onto this week's #SecurityNow Ep1071 and then saw it go by here on mastodon not long after.

And yes, why are commercial bug reporting platforms such a PITA to deal with trying to get someone to actually listen. Having a public reporting mechanism feels like such a "box ticking exercise" from their end.