Esa Jokinen

14 Followers
21 Following
39 Posts
Please consider direct messages on Mastodon as public; use email & PGP for important stuff.
Webhttps://esajokinen.net
GitHubhttps://github.com/oh2fih
🇫🇮​ As of today, it is mandatory to validate the caller IDs of all Finnish (+358) phone numbers between Finnish operators, as Traficom's regulation 28 J/2022 became fully effective. This pretty much ends the called ID spoofing here. 🙌​
Many people still read their email in plain text, but even larger operators sometimes forget to proofread the unformatted versions of their newsletters. A funny residue of a placeholder text was found at the beginning of an announcement from @valimail 📬​

I noticed a slight overreaction over a vulnerability, CVE-2023-38408. They suggested building the latest OpenSSH server [sic] from sources over the one packaged in your distribution, although the vulnerability in the ssh-agent affects the OpenSSH client & only if agent forwarding (`-A` / `ForwardAgent`) is enabled.

Vulnerabilities in security critical utilities easily get high CVSS score as they could have severe implications for confidentiality, integrity and availability. However, this one is rather easy to mitigate by correct configuration, and does not affect typical nor default configurations.