Andreas Schneider

@cryptomilk
181 Followers
89 Following
346 Posts
FOSS Hacker (Samba, MIT Kerberos, libssh, cmocka, cwrap, darktable, etc.). Loves bicycles.
Websitehttps://cryptomilk.org
Bloghttps://blog.cryptomilk.org

@abbra and I released version 0.1.0 of the Kirmes LocalKDC today.

https://gitlab.com/kirmes/localkdc/-/releases/0.1.0

Wait, what are we needing a KDC for which only runs locally? Well, you want the details, I suggest to watch our talk at https://sambaxp.org/ next Monday (or wait till it is online).

It uses systemd-userdb via libkirmes (written in rust) and implements KDB modules for MIT Kerberos also written in Rust (kurbu5)!

#kerberos #rust #rustlang #systemd

0.1.0 · kirmes / localkdc · GitLab

Added KDC listening exclusively on a Unix socket (/run/localkdc/kdc.sock) via systemd socket activation. No TCP/UDP...

GitLab

Several years ago I packaged #Signal and #Electron for #openSUSE and #Fedora in the openSUSE Buildservice.
Bruno Pitrus helped to improve it and maintained it over many years. With Signal 8.6.0 it wont be maintained anymore. The reason is that we never got help from Upstream Signal and that it got much harder. Especially Electron is a huge pain.

https://build.opensuse.org/project/show/network:im:signal#comment-2255302

Signal Messaging Devel Project

This provides the Signal-Desktop app.

openSUSE Build Service
Mapterhorn v0.0.10 includes improved 5 m terrain data for Lombardia, Trentino, and Piemonte in Italy, 10 m in Rwanda, and fixes some artifacts in Scotland, UK.

There is finally a merge request to use QtKeyChain in plasma-nm 🥳 🎉

https://invent.kde.org/plasma/plasma-nm/-/merge_requests/551

#kde #plasma #networkmanager

I submitted a Pull Request to update MacPorts' libssh to 0.12.0 here:

https://github.com/macports/macports-ports/pull/31472

3 of 3 of GitHub Continuous Integration checks passed.

It's up to someone else with commit access to merge it.

I'm not the maintainer, nor am I really a user of libssh, so some things are not particularly tested (I did attempt to run "port -vst install" but tbh even "port -v install" was failing due to some weird kerberos defaults and I don't run kerberos locally, for good reasons. Also, I don't really use anything dependent upon libssh).

It was more that I was having dreams about OpenSSH and figured I should test a snapshot (no issues there, phew!) but noticed that libssh had been version bumped (more than one actually, there's also a 0.11.4 release) and there were security related issues, so it seemed worth at least submitting a Pull Request since it had apparently slipped under the maintainer's radar? The Portfile is also listed as openmaintainer, so I am guessing a little outside assistance is welcome.

Hopefully it helps some others! Doesn't do much of anything for me.

Hopefully it doesn't break anything for others; that I am less certain about.

#libssh #MacPorts #OpenSource #Security #OpenSSH

Internet Bug Bounty program hits pause on payouts

“AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed. The balance between findings and remediation capacity in open source has substantively shifted,”

https://www.infoworld.com/article/4154210/internet-bug-bounty-program-hits-pause-on-payouts.html

Internet Bug Bounty program hits pause on payouts

HackerOne is the latest organization to struggle with AI submissions.

InfoWorld
kurbu5: MIT Kerberos plugins in Rust

For a couple of years, Andreas Schneider and I have been working on a project we call the ‘local authentication hub’: an effort to use the Kerberos protocol ...

This is a gorgeous, gorgeous longish essay from @tg on the tech that's constantly asking for our attention. Love the beautifully subtle animations and the CSS handdrawn casio and apple watches, .

THE LAST QUIET THING:

https://www.terrygodier.com/the-last-quiet-thing

The Last Quiet Thing

Your possessions came alive. Now they won't stop talking.

Terry Godier
[Live Q&A] Neovim 0.12 Release with the Core Team

YouTube

"Internet Bug Bounty is taking a break and is not accepting new submissions."

Killed by AI Slop.

No bug bounty for #libssh anymore.