hayden aiken ๐Ÿ‡บ๐Ÿ‡ฒ

140 Followers
136 Following
610 Posts
Jesus follower. wife guy. proud marylander but recovering floridian.
infosec๐Ÿคnatsec.
ops and open source lover.
b.s. cybersecurity.
highly mistrustful security enthusiast.
bloghttps://debug.openaiken.net
email[email protected]
githttps://codeberg.org/openaiken
whiskeyneat

RE: https://techhub.social/@rayckeith/116762201282703808

A screenshot of a Mastodon post, posted on Tumblr, screenshotted, and shared as an image and a post on mastodon again. Evidence at this platform deserves a seat at the internet table

(And, re: my previous comments about LLMs being an effective way to have non-coders make local changes they want anyway - if you don't care about upstreaming your code, that seems entirely fine, there's no need for it to be maintainable or extensible)

RE: https://debug.openaiken.net/2026/stig-checklist-generator-for-rhel/

I published a write-up on how I designed and assembled by automated STIG validation tool for RHEL.
I found that it was a nearly ideal use case for Claude Code because the benchmark is written in human-speak and the rules can be categorized by control group.

I've got Pi-KVM running in a podman container, rootless, on RHEL, x86 hardware.

https://codeberg.org/openaiken/pikvm-podman

I've made this work before, with a native installation and manually building dependencies, writing scripts to automate steps, etc. I hadn't done a good enough job and it broke badly after trying to upgrade. And unrelatedly I'm pretty experienced now with podman containerization.

So this is a heavily vibe-coded project that builds and runs the software in a custom image, ready to access behind a reverse proxy, and it has support for the web terminal and kvm switching for multi-input.

pikvm-podman

A build and run system on x86 64-bit Enterprise Linux.

Codeberg.org
I applied for a "trump account" for my infant daughter when I filed my 2025 taxes. The Treasury has started notifying people about it, and the email comes from a subdomain of treasury.gov but it really wants you to download an app, and it also directs you to a dot com domain. After skimming fine print and hovering links in the privacy policy it becomes clear that this service (?) is being offered via Robinhood. The website is branded thoroughly with the "national design studio" that I learned about from the blog recently from The Drey Dossier.
interesting to see that Linux might be making a new way to create processes instead of fork/exec https://lwn.net/SubscriberLink/1076018/16f01bbbb8e0d1f0/
Moving beyond fork() + exec()

Since the earliest days of Unix, two of the core process-oriented system calls have been fork() [...]

LWN.net

Two quotes by Robert Louis Stevenson I found while looking for something else:

"Marriage: A friendship recognized by the police."

"Marriage is the process of finding out what kind of man your wife would have preferred.โ€

No other experiment has a lower false negative rate.
https://xkcd.com/3254/

Dozens of Red Hat packages backdoored through its offical NPM channel

Anyone who has downloaded affected Red Hat packages should investigate immediately.
https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social