Introduction
Introduction Statistics Contact Development Disclaimer Help
Post AvCFSiEVGId50VIXM8 by [email protected]
More posts by [email protected]
Post #AvBlQDYhL8YifVddNw by [email protected]
0 likes, 8 repeats
https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjrWhen a u…
Post #AvBloOTCQJq9SXauQa by [email protected]
0 likes, 1 repeats
@cR0w There’s TOFU and there’s TOFU
Post #AvBloOYs5ENRk8FRGi by [email protected]
0 likes, 1 repeats
@jimfl Yeah, this is a whole new level to me. Yikes.
Post #AvBltTY2yDswenHjDU by [email protected]
0 likes, 0 repeats
@cR0w but Mark Shuttleworth only hires the finest high school valedictorians af…
Post #AvBltTe4bohoxU6Xbs by [email protected]
0 likes, 1 repeats
@rootwyrm I've heard nothing but the worst about that process and shit like…
Post #AvBmC2RRyXVq5e3DEW by [email protected]
0 likes, 1 repeats
@cR0w I love how they're downplaying this. It's obviously C:H/I:H/A:H, …
Post #AvBmH3AAilTxm7MIym by [email protected]
0 likes, 1 repeats
@kallisti That's why I didn't put severity or CVSS string in the toot. …
Post #AvBpYgLia3Gw5urIGW by [email protected]
0 likes, 1 repeats
@cR0w lol. Lmao even.
Post #AvBpuqcD5ms4Ix8rjM by [email protected]
0 likes, 1 repeats
@ckure Look, it's not like Canonical has been doing vulnerable systems for …
Post #AvBqSZWV99jx8lYKdU by [email protected]
0 likes, 0 repeats
@cR0w I like the workaround, "do not use this software". A beautiful …
Post #AvBqSZcslQqPSYXQa8 by [email protected]
0 likes, 1 repeats
@noratrieb Mitigation: sudo init 0
Post #AvBqVsHLs0QgB92cz2 by [email protected]
0 likes, 0 repeats
@cR0w I love a disposable root shell
Post #AvBqVsNjUHX8Uw1ivg by [email protected]
0 likes, 1 repeats
@Dio9sys Happy Monday. It's just so... Canonical.
Post #AvBqZMIuh41QAXQvPE by [email protected]
0 likes, 1 repeats
@cR0w Canonical is truly a gift that keeps on giving
Post #AvBqbgZuHnB3cwUWsy by [email protected]
0 likes, 1 repeats
@redsakana Unless you're a customer, that is.
Post #AvBqcgcXc67k34CVbE by [email protected]
0 likes, 1 repeats
@cR0w if only the CVSS v4.0 example guide had thought to include an SSHD exampl…
Post #AvBqmEdOWKYw999Y7U by [email protected]
0 likes, 0 repeats
@cR0w No way this is "moderate" lmao, how is an LPE C:L/I:L/A:N?
Post #AvBqmEjQ9vNoRpyMVs by [email protected]
0 likes, 0 repeats
@fre That's why I didn't put severity or CVSS string in the toot. I thi…
Post #AvBqmNfquYsOBNN8hU by [email protected]
0 likes, 0 repeats
@cR0w good move
Post #AvBqmRnRaHKEy4xG5Y by [email protected]
0 likes, 1 repeats
@ckure I do honestly hope this wasn't some poor intern that will get thrown…
Post #AvBqnGDO85mtL1TgTA by [email protected]
0 likes, 0 repeats
@cR0w PAM - 1001 ways to shoot yourselves into the foot.
Post #AvBqq80R6fBwkOmqzg by [email protected]
0 likes, 0 repeats
@cR0w
Post #AvBqsLB96MA4BHqqCu by [email protected]
0 likes, 0 repeats
@cR0w Yup good call, imo this is blatantly just engineering the score to stay b…
Post #AvBqsm2DFg3hTOsaX2 by [email protected]
0 likes, 0 repeats
@cR0w W-H-A-T?
Post #AvBqvkbh15ljuitWNc by [email protected]
0 likes, 0 repeats
@cR0w ... :cirnoshock:
Post #AvBqwYdX0Wwt4u8hBg by [email protected]
0 likes, 0 repeats
@cR0w "moderate" :neocat_laugh_sweat:
Post #AvBqzfP0JF0OvjpJq4 by [email protected]
0 likes, 0 repeats
@cR0w
Post #AvBr0e72adsjDgtKoC by [email protected]
0 likes, 0 repeats
@cR0w The hivis and clipboard of invisibility aren't meant to get you C-sui…
Post #AvBr0eFY50gfe4s84O by [email protected]
0 likes, 1 repeats
@patcharcana When the unlocked door isn't actually a trap but just easy mod…
Post #AvBr0iY85rvWyrb1aS by [email protected]
0 likes, 1 repeats
LMAO when it turns out the patch for this is behind the subscription like
Post #AvBrAaje0AmFdngrVA by [email protected]
0 likes, 1 repeats
@cR0w
Post #AvBrHpOZtTiL8UHsVE by [email protected]
0 likes, 0 repeats
@f4grx @cR0w but remember! Everyone saying systemd and snaps and authd are all …
Post #AvBrHpUbX4XDRB6gtc by [email protected]
0 likes, 1 repeats
@rootwyrm @f4grx inb4 "you get what you pay for"
Post #AvBrKHFHJqai5f6b6u by [email protected]
0 likes, 1 repeats
@da_667 Happy Monday
Post #AvBrOx8ZVZXVAqCKv2 by [email protected]
0 likes, 0 repeats
@cR0w "Knock knock.""Who's there?""God."&quot…
Post #AvBrOxEb9AMNTX19JQ by [email protected]
0 likes, 1 repeats
@patcharcana We need a new version of the sudo make me a sandwich that's ev…
Post #AvBrWgXd5xCG1Gbbyi by [email protected]
0 likes, 0 repeats
@cR0w @f4grx the fucking *irony* is that sssd and systemd are both Red Hat proj…
Post #AvBrWgdejY18JxQQN6 by [email protected]
0 likes, 1 repeats
@rootwyrm @f4grx Right. Good call.
Post #AvBrqqDIqNfJoCi1q4 by [email protected]
0 likes, 1 repeats
@cR0w "boy, if only there was a solution to the problem we created 👉�…
Post #AvBruzvqeX0D6mWjS4 by [email protected]
0 likes, 1 repeats
@kevinmirsky In their imaginary defense, everyone else puts security behind pai…
Post #AvBs8g53G0ENatM3Wq by [email protected]
0 likes, 0 repeats
@cR0w if only there was a better systems programming language that this stuff c…
Post #AvBs8gB4tb3FtaArvE by [email protected]
0 likes, 1 repeats
@srtcd424 This one does not appear to be a language issue. Programmer socks wou…
Post #AvBsiD1KmLF1tJYh5U by [email protected]
0 likes, 0 repeats
@cR0w oh, I'm not golang proficient, but it looked like go was defaulting a…
Post #AvBsiD7MPw3uC0NVTs by [email protected]
0 likes, 1 repeats
@srtcd424 It defaulted to 0 but because it was programmed to do so, right?
Post #AvBsx8E4t23PMhdQsC by [email protected]
0 likes, 0 repeats
@cR0w nobody knows that “failures happen” more than incident response teams…
Post #AvBsx8KoTzRRhamoN6 by [email protected]
0 likes, 1 repeats
@ckure Fully agree. But these days it seems like nothing is working as designed…
Post #AvBtMSbmF7sToqnWme by [email protected]
0 likes, 1 repeats
@cR0w @patcharcana
Post #AvBtP9eNBYBNtGISW0 by [email protected]
0 likes, 0 repeats
@cR0w @yomimono Luckily, there's a simple fix for this. Just give all users…
Post #AvBtP9kknpHqD3HYSe by [email protected]
0 likes, 1 repeats
@angusm @yomimono When everyone is root, no one is root.
Post #AvBwLZf8pV09Gpdlw0 by [email protected]
0 likes, 0 repeats
@cR0w hmm, that looks like test data? Though it is explicitly 0 there before th…
Post #AvBwLZlsQSOBbin9Qu by [email protected]
0 likes, 1 repeats
@srtcd424 Bugdoor... 😏
Post #AvBy3dfXOYf8OMOwWu by [email protected]
0 likes, 0 repeats
@cR0w @redsakana yeah...
Post #AvBy6l8G6TJWPKK6am by [email protected]
0 likes, 0 repeats
@f4grx @cR0w yoooo....!
Post #AvBy6lEHk48Oi18uzA by [email protected]
0 likes, 0 repeats
@kkarhan @cR0w I have no idea who is the character on this gif, but I found her…
Post #AvBy6lJxOyfgzbnRpI by [email protected]
0 likes, 0 repeats
@f4grx @cR0w it's "Kizuna AI"
Post #AvBy6lROxIctMhHOQi by [email protected]
0 likes, 0 repeats
@kkarhan @cR0w oh noooo lol
Post #AvBy7FwHZ39Zx9xTjE by [email protected]
0 likes, 0 repeats
@rootwyrm @cR0w from the team that created the new image of WVWA, Pound Ridge, …
Post #AvBy7IcBcDrSFhZyK0 by [email protected]
0 likes, 0 repeats
@cR0w @Dio9sys I bet you #skiddies gonna go #cryptojacking #Monero tonite...
Post #AvByE4EdTgZzgHn5vM by [email protected]
0 likes, 0 repeats
@cR0w Waitwhat
Post #AvByEMAgn67NJG5CGu by [email protected]
0 likes, 0 repeats
@rootwyrm @cR0w @f4grx also this isn't a #smSystemD nor #snap issue!
Post #AvByGdAuXj4icmGrh2 by [email protected]
0 likes, 0 repeats
@rootwyrm @f4grx @cR0w what does systemd have to do with canonical's utter …
Post #AvByOHyxDmkPDFKWVE by [email protected]
0 likes, 0 repeats
@patcharcana @cR0w https://www.youtube.com/watch?v=mW9PvYYH9lA
Post #AvC289fsjzSWd8yHfE by [email protected]
0 likes, 0 repeats
@cR0w why would anyone run ubuntu over Debian, like for real?
Post #AvC289myJd88z8HwiO by [email protected]
0 likes, 1 repeats
@fabiscafe
Post #AvC2ng1rLuSsqh3BHU by [email protected]
0 likes, 0 repeats
@cR0w im fuckin losing it
Post #AvC2v93HqNiGtCHMHo by [email protected]
0 likes, 1 repeats
@somebody
Post #AvC2x0fXyxeHTA42O8 by [email protected]
0 likes, 0 repeats
@cR0w
Post #AvC2xZx8nXWCtrZ5Ae by [email protected]
0 likes, 1 repeats
@cR0w sure hope everybody has properly configured service users without login s…
Post #AvC38vBeBtpfwQl5sm by [email protected]
0 likes, 1 repeats
@farewell_ladmin
Post #AvC4K8hUO7IUzbZ7BY by [email protected]
0 likes, 1 repeats
@cR0w It's called "wheel", damn it!One has to love the push to us…
Post #AvC57SgUsPVvA4cVCC by [email protected]
0 likes, 1 repeats
Given how popular Ubuntu is, I wonder how heavily weighted code like this is wi…
Post #AvC5L21qmJImXq4vjs by [email protected]
0 likes, 0 repeats
@cR0w It was such a good quality bait, I'm a master in that class :neocat_a…
Post #AvC5L28EOaPErd41gW by [email protected]
0 likes, 1 repeats
@fabiscafe 🥂
Post #AvC5pGMC4T4Zfc0dcm by [email protected]
0 likes, 0 repeats
@cR0wI was hired basically straight out of highschool to work for Shuttleworth.…
Post #AvC5pxaBMKoPjRsutk by [email protected]
0 likes, 0 repeats
@vampirdaddy @cR0w Strange turn of words.
Post #AvC5sqw0X5d3yyTNGi by [email protected]
0 likes, 0 repeats
@chillybot @rootwyrm a lot of the people at Canonical are really shitty to othe…
Post #AvC5t0CI5v0Ai5A0Om by [email protected]
0 likes, 1 repeats
@cR0w
Post #AvC5zvM2UwhhiY1Lea by [email protected]
0 likes, 0 repeats
@cR0wYUP XD@rootwyrm
Post #AvC61maY3pdn6qh3jc by [email protected]
0 likes, 1 repeats
@jerry It would explain a lot.
Post #AvC61mojD6z1opKNpw by [email protected]
0 likes, 1 repeats
@cR0w @jerry vibe coding before it was cool
Post #AvC8OnXWtECQd2Nr0a by [email protected]
0 likes, 1 repeats
@cR0w this might go back all the way to the start of systemd
Post #AvC8rMyMkExmd7YnDM by [email protected]
0 likes, 0 repeats
@cR0wExplicit is better than implicit. It's a new level of openness and tra…
Post #AvCAaQUmarU0Xcltgm by [email protected]
0 likes, 1 repeats
@cR0w Canonical QA tester: ssh login works ✅
Post #AvCBpseOIQQuA0CNLk by [email protected]
0 likes, 0 repeats
@cR0w Ah, this is another Canonical inhouse component? Wondered why I wasn'…
Post #AvCBpslpqkO6X5gJxA by [email protected]
0 likes, 0 repeats
@cR0w SuSE sponsors a project with similar goals (and hopefully less :flan_face…
Post #AvCBpssZRhm8ryphS4 by [email protected]
0 likes, 1 repeats
@galaxis Seems like it would be quite a challenge for them to introduce a more …
Post #AvCEWxG7En9SoVVlCa by [email protected]
0 likes, 0 repeats
@cR0w @fre > The stable PPA release of authd can be used today as an authent…
Post #AvCEfXK52KQayrSRF2 by [email protected]
0 likes, 0 repeats
@cR0w @chillybot @rootwyrm Like big guys get named Tiny.
Post #AvCEk2isEb2NWYCg7c by [email protected]
0 likes, 0 repeats
@yacc143 @fre 🤔
Post #AvCFSi7lfLF2fc99rE by [email protected]
0 likes, 0 repeats
@cR0w Is it a local privilege escalation when it involves a remote shell?
Post #AvCFSiEVGId50VIXM8 by [email protected]
0 likes, 1 repeats
@truh Everything is local if you wait long enough to observe it. taps temple
Post #AvCGBCAHKy0Oa4X6g4 by [email protected]
0 likes, 1 repeats
@cR0w I can't help but ask... what does this tell us about authd, if anythi…
Post #AvCGWjvb0A5XNPwFH6 by [email protected]
0 likes, 1 repeats
@adamshostack I think that pretty much nails it. It appears it's using test…
Post #AvCHzU1TJdewOpxNWC by [email protected]
0 likes, 1 repeats
@cR0w :shock_kosaki:
Post #AvCI3EWgsCTvUqLaO8 by [email protected]
0 likes, 1 repeats
@cR0w ummm, ok, and uhhhh, what happens if GID 1234 is in use? Shouldn't t…
Post #AvCI694FcoHPR3Qvgm by [email protected]
0 likes, 1 repeats
@adamshostack Yeah. And then the sandbagged CVE assessment is the cherry on top.
Post #AvCI69AHGP6HjkFk5A by [email protected]
0 likes, 1 repeats
@cR0w you mean cvss?
Post #AvCI8WksWgirTpVY2a by [email protected]
0 likes, 1 repeats
@adamshostack I would think so but maybe they're just kicking the can down …
Post #AvCIA9h9EakcXVXUkS by [email protected]
0 likes, 1 repeats
@adamshostack Yep, sorry about that.
Post #AvCIWY8R2zIsi4ysz2 by [email protected]
0 likes, 0 repeats
@jerry @cR0w You are joking but: https://threadreaderapp.com/thread/19320794355…
Post #AvCIWYFAdwgv2y8GTw by [email protected]
0 likes, 1 repeats
@buherator @jerry
Post #AvCLYLsPtV9R8J2Vbk by [email protected]
0 likes, 1 repeats
@buherator @cR0w how else are we going to get companies to pay maintenance fees…
Post #AvCN7JSkxcqnjhGuHo by [email protected]
0 likes, 0 repeats
@andre @kevinmirsky Meh, I've had a good run. Just make it quick and thorou…
Post #AvCNCyt8MxVZf9JQdE by [email protected]
0 likes, 0 repeats
@cR0w like the service where they don´t release test against CIS and other ben…
Post #AvCNHoyUeg3AMe7wdU by [email protected]
0 likes, 0 repeats
@cR0w I hope they coke on a bukkit of dic^H^Hebian
Post #AvCOMeuBcWtgXJz1Fo by [email protected]
0 likes, 0 repeats
@cR0w Isn't authd currently only distributed via PPA?Do they really provide…
Post #AvCOMf0ZEo08r6y7CS by [email protected]
0 likes, 1 repeats
@Doomed_Daniel I don't think so. I was being a smartass about Canonical&#39…
Post #AvCOSSixp1pGUlV8k4 by [email protected]
0 likes, 0 repeats
@cR0w what are you talking about? the patch is not behind any kind of subscript…
Post #AvCOSSozSce8nSJx8S by [email protected]
0 likes, 1 repeats
@jxvvt I was being a smartass about Canonical's general approach of hiding …
Post #AvCOzMIEkmZy6cgbJ2 by [email protected]
0 likes, 0 repeats
@cR0w Yeah, that's a very dubious practice.But I think it should be made cl…
Post #AvCOzMOGONOqPJVPhQ by [email protected]
0 likes, 1 repeats
@Doomed_Daniel That's an exercise for the admins. I'm not going to impl…
Post #AvCP5izRHRFEEhvfLU by [email protected]
0 likes, 0 repeats
@cR0w "// TODO: Should we set the GID to something else than 0 (i.e. the G…
Post #AvCP5j56wLmWWIaCBc by [email protected]
0 likes, 1 repeats
@dotjayne It's just so funny.
Post #AvCQJiEYzJXJtqElTE by [email protected]
0 likes, 0 repeats
@cR0w And I continue to be a happy Debian user :neocat_laugh_sweat:
Post #AvCQL6hFWPaA3iJt7g by [email protected]
0 likes, 0 repeats
@rootwyrm @cR0w @f4grx What. A. Surprise.
Post #AvCQO1uzkB7m6l8vB2 by [email protected]
0 likes, 0 repeats
@yacc143especially openess@cR0w @jimfl
Post #AvCRd3OWdYy2z6gQds by [email protected]
0 likes, 0 repeats
@cR0w @Doomed_Daniel Yes, if you installed and configured authd and an authd br…
Post #AvCRd3UYH9mvHnVF2G by [email protected]
0 likes, 1 repeats
@jxvvt @Doomed_Daniel Organizational memory too though. Just because it wasn&#3…
Post #AvCSrjnNt7b0UssPPU by [email protected]
0 likes, 0 repeats
@cR0w I presume this is some kind of auto-account provisioning feature?
Post #AvCSrjtPWiPsnZhDns by [email protected]
0 likes, 1 repeats
@peribotsarah Not so much provisioning as brokering cloud auth.https://document…
Post #AvCZYYdNrQNO3f050y by [email protected]
0 likes, 0 repeats
@Doomed_Daniel that's correct. @cR0w is just wrong.
Post #AvCZYYk7SNlQOY9SVs by [email protected]
0 likes, 1 repeats
@3v1n0 @Doomed_Daniel I usually am but how so this time?
Post #AvCZj585tmLfjiNoP2 by [email protected]
0 likes, 0 repeats
@cR0w wrong.It's just in a PPA, it's not in Ubuntu main either, being a…
Post #AvCZstE90SS1iXtEFE by [email protected]
0 likes, 0 repeats
@cR0w @Doomed_DanielThe updates are part of a PPA: https://launchpad.net/~ubunt…
Post #AvCZw3Ho3zq9mf6vAG by [email protected]
0 likes, 1 repeats
@3v1n0 @Doomed_Daniel I have linked both of those in replies as I do understand…
Post #AvCbmt5ao2eLSc9hdA by [email protected]
0 likes, 0 repeats
@lanodan @cR0w it does.There's no other way the user group can be initializ…
Post #AvCbmtByQJknmP8nZo by [email protected]
0 likes, 1 repeats
@3v1n0 @lanodan I'm not saying that I know the code any better. I'm jus…
Post #AvCcZtFuyY2GAOLqVM by [email protected]
0 likes, 0 repeats
@cR0w @Doomed_Daniel well... I replied while going through the thread.But for s…
Post #AvCcZtMIap8iUBKwS0 by [email protected]
0 likes, 1 repeats
@3v1n0 @Doomed_Daniel It wasn't false accusations. It was, at least to peop…
Post #AvCg8uY8SNgsB3GNqy by [email protected]
0 likes, 1 repeats
@lanodan @cR0w https://youtu.be/TbBdyXGZ1Gw
Post #AvCgTRPI0I0bsFunIm by [email protected]
0 likes, 0 repeats
@cR0w @fre imho the description looks more dangerous than it is...Try to get an…
Post #AvCgTRVJdspUAwjbhA by [email protected]
0 likes, 0 repeats
@3v1n0 @fre That's a downstream issue, though one I expect we also have dif…
Post #AvCgTRazInMmSXO8XI by [email protected]
0 likes, 0 repeats
@cR0w @fre it was mostly due to the SSH architecture (and happening only there)…
Post #AvCgTRh0wOBelECwvg by [email protected]
0 likes, 0 repeats
@3v1n0 @fre All I'm suggesting is that it's a hilarious bug and that I …
Post #AvCgTRnOYfI751C2sK by [email protected]
0 likes, 0 repeats
@cR0w @fre indeed nobody wants a cookie, but any behavior was criticized, while…
Post #AvCgafxUIdYf23MQnw by [email protected]
0 likes, 0 repeats
@3v1n0 @fre "Finally"LMAO. Have a nice day.
Post #AvCgatRk9SU4recHGi by [email protected]
0 likes, 0 repeats
@lanodan @cR0w well, we may have wrapped it into function helpers doing the sam…
Post #AvCjBnsc0jXcDrubAG by [email protected]
0 likes, 0 repeats
@cR0w @3v1n0 with > 500 boosts your original post clearly got a much wider a…
Post #AvCjBnyzd0e4Xeth6u by [email protected]
0 likes, 0 repeats
@Doomed_Daniel @3v1n0 500 boosts? No wonder so many people have responded.
Post #AvCjBo5NFHkWrRsn3Y by [email protected]
0 likes, 0 repeats
@cR0w @Doomed_Daniel @3v1n0 Clearly many users responsing to your post misunder…
Post #AvCjE8mFHnbZc733s8 by [email protected]
0 likes, 0 repeats
@jxvvt @Doomed_Daniel @3v1n0 If the misunderstanding is that widespread, then m…
Post #AvHi2kFF1nJGB9PepU by [email protected]
0 likes, 0 repeats
@angusm @cR0w @yomimono ah, I see you're familiar with modern DevOops.
Post #AvHi2xLOKExAnzOFii by [email protected]
0 likes, 0 repeats
@cR0w @angusm @yomimono This is the root cause.
Post #AvHi301INPf36X0kJU by [email protected]
0 likes, 0 repeats
@angusm @cR0w @yomimono I know you make a joke here but I worked at a Fortune 5…
Post #AvImUWIl3XmY19W8KO by [email protected]
0 likes, 0 repeats
@cR0w @adamshostack ohhh... How can be the analysis be so superficial?It's …
Post #Avd8v95ZYIb3zqeKrw by [email protected]
0 likes, 0 repeats
@cR0w // TODO: Should we set the GID to something else than 0 (i.e. the GID of …
Post #Avd8vKK9mPnaqGYdd2 by [email protected]
0 likes, 1 repeats
@josephholsten I saw that too. 😆 https://infosec.exchange/@cR0w/114695486788…
You are viewing proxied material from pleroma.anduin.net. The copyright of proxied material belongs to its original authors. Any comments or complaints in relation to proxied material should be directed to the original authors of the content concerned. Please see the disclaimer for more details.