gyptazy.ch is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
contact@gyptazy.ch
Admin account
@gyptazy@gyptazy.ch

Search results for #hardenedbsd

Shawn Webb boosted

HardenedBSD »
@HardenedBSD@bsd.network

Shawn Webb »
@lattera@bsd.network

@paco provides a public instance of : vaultwarden.hardenedbsd.org/

It's incredibly easy to self-host your own Vaultwarden instance, too. It's compatible with the mobile and desktop apps.

Vaultwarden is incredibly easy to self-host. Backing up the stored data is simple: just create a tar archive of the data directory (or, in my case, a zfs send of a snapshot.)

Shawn Webb »
@lattera@bsd.network

@unixviking This masochist runs . ;-)

Shawn Webb »
@lattera@bsd.network

Here we see two seed nodes, running behind my fully Tor-fied network.

This is a test of exposing a Radicle seed node as a Tor Onion Service endpoint.

These two Radicle nodes are deployed on a 14-STABLE VM.

Huge step forward for .

For more information on Radicle (a sovereign {code forge} built on Git): radicle.xyz/

Huge shout-out to the Radicle dev team for this collaboration. It has been a blast working with them.

Screenshot showing two Radicle seed nodes on HardenedBSD communicating with each other.Screenshot showing `rad clone` working.

Shawn Webb »
@lattera@bsd.network

One bug running on this Dell Precision 7680: the keyboard becomes unresponsive sometimes.

I mostly use external keyboards, anyways. I'm not even sure what steps to take to debug this kind of thing.

Shawn Webb »
@lattera@bsd.network

14-STABLE running flawlessly on a Dell Precision 7680.

It's a 24-core Intel Raptor Lake laptop with a discrete NVIDIA GPU. Using the nvidia-drm-kmod graphics driver.

64GB RAM, 1TB NVMe.

Screenshot showing various technical details about the system.

Shawn Webb »
@lattera@bsd.network

Current status: Replacing on my ${DAYJOB} laptop with 14-STABLE.

Shawn Webb »
@lattera@bsd.network

Whenever my laptop wakes up from sleep mode, the trackpad becomes nonfunctional. Mouse cursor doesn't move, tap-to-click does nothing, etc.

I miss you, .

Shawn Webb »
@lattera@bsd.network

Current status: Deploying a test node on behind my Tor-ified network.

Gonna see if I can get two Onion Service endpoints for Radicle seeds. I want to see if they will talk to each other and seed each other's repos.

Shawn Webb »
@lattera@bsd.network

That moment when you expose an NFS mount over HTTP as a Tor Onion Service website. :-)

I fixed our nginx web server to properly expose /pub on our onion site. I had accidentally forgotten to set the server_name directive.

Shawn Webb »
@lattera@bsd.network

@Ryan Ideally the mesh nodes themselves would not be desktop systems. They would be network appliances running .

I have some options in mind for network appliance vendors that could bundle the right wireless chipset(s).

Shawn Webb »
@lattera@bsd.network

This is what I'm hoping we can achieve in the next decade: at least one deployment of a censorship- and surveillance-resistant wireless mesh network.

We would run these nodes (and supsernodes) on .

There is work in to support wireless mesh networking. There's even a presentation on it coming up at 2024: indico.bsdcan.org/event/1/cont

The work we're doing in HardenedBSD would pair very well with this.

Diagram showing the overall design/architecture of a simple censorship- and surveillance-resistant wireless mesh network.
0 ★ 0 ↺

gyptazy »
@gyptazy@gyptazy.ch

Long post

wow, we already have almost 50 people interested into a weekly meeting. In the BSDCafe we already thought about possible dates and additional organization.

Different timezones make it really hard to just have a single meeting and it might end up in two or even three ones but also trying to avoid fragmentation. But this will probably work out more in an iterative way…

The current idea is to start Thursdays, 7pm GMT+2 in an unmoderated public jitsi session where everyone can join. I think the targeted user group is able to handle it in that way, like we always do.

The question is also, do we want to have an agenda or only open minded jump in and see how it works out?! My experience is, that people might be shy to start talking, it’ll be silent and people start to drop’s drop. An agenda might be helpful for an initial start but I also want to avoid having an introduction round where everyone tells something about himself. I mean, this can be done optionally, but I’m also aware of it that some may feel uncomfortable with this. This round should just make fun and not make any pressure or someone feeling uncomfortable.

So, agenda or open minded and free to talk for the first sessions?



h3artbl33d »
@h3artbl33d@exquisite.social

Do you do anything interesting with any of the *BSDs ? If so, please consider giving a talk at EuroBSDCon, which is held in Dublin, September 19-22. More info on submitting your paper can be found here.

Shawn Webb »
@lattera@bsd.network

Shawn Webb »
@lattera@bsd.network

From the crunchgen(1) manual page:

The main reason to crunch programs together is for fitting as many programs as possible onto an installation or system recovery floppy.

The /rescue binaries on are 17MB in size.

I wonder if crunchgen, with all its hackiness, is really worth it in 2024.

I'm wondering if we should just build the various /rescue binaries as normal, statically-linked applications rather than use crunchgen(1).

We either have to teach crunchgen(1) how to deal with a libc that has been built with LTO or live without LTO-ified libc.

Link Time Optimization (LTO) is a prerequisite for Cross-DSO CFI. With libc being a huge target, it seems we should kick crunchgen(1) out the door.

I realize, though, that I have quite a few blind spots. Are there any reasons to continue using crunchgen(1) in 2024, sacrificing Cross-DSO CFI and LTO for libc?

🗳 0 ★ 0 ↺

gyptazy »
@gyptazy@gyptazy.ch

⚠️ The BSD Pub ⚠️

Hey Fans!

We all share the same interests - based systems like , and .

We chat all day, sharing thoughts, questions and help. We talk on Matrix across different channels, we share on the . We have @vermaden@bsd.cafe's newsletter, we have @dexter@bsd.network's and calls and many other ones I can't list here.

Wondering if there would be and interests in the , , etc., for a weekly smalltalk session like in a pub. Just a Jitsi based video/audio call where we can meet, discuss things from newsletter, trending things from the or just have off-topic and openminded discussions. This could result into the meeting.

I know, some people are shy - keep your cam off until you feel comfortable and feel free to join the discussions. Even this meetings should make fun and no pressure - so if someone is not in the mood or can't make it - no worries. No one will judge.

Would you be interested?


Yes:44
No:4

Closed

Shawn Webb »
@lattera@bsd.network

Seems like does not like larger repos. Trying to rad clone the src and ports repos is proving problematic.

Shawn Webb »
@lattera@bsd.network

Happy decade birthday, !

$ fetch -q -o - api.github.com/repos/HardenedB | jq -r .created_at
2014-04-08T10:10:24Z

Screenshot showing when the HardenedBSD repository was created at GitHub along with today's date.

Shawn Webb »
@lattera@bsd.network

Current status: Deploying a test node on . Going to seed the HardenedBSD src and ports repos.

I'm hoping to continue expanding alternative forms of access to our resources (both code and infrastructure).

If this test proves successful, we may have another official method of getting HardenedBSD-related stuffs.

HardenedBSD »
@HardenedBSD@bsd.network

The infrastructure is back online. Maintenance has completed successfully.

HardenedBSD »
@HardenedBSD@bsd.network

The infrastructure has been taken offline in preparation for electrical work.

HardenedBSD »
@HardenedBSD@bsd.network

The development/build infrastructure is back online. We will closely monitor temperature as the evening progresses.

HardenedBSD »
@HardenedBSD@bsd.network

The development/build infrastructure is currently offline due to an overheated server room.

We're letting the room cool before powering things up again.

Shawn Webb »
@lattera@bsd.network

@EdanOsborne The sadist in me recommends giving a try.

Shawn Webb »
@lattera@bsd.network

${DAYJOB} delivered a new Dell Precision laptop.

I absolutely love the Precision line. Runs very, very well.

Though, I'll be stuck on on this laptop. Customer requirements come first.

Michael Dexter »
@dexter@bsd.network

Oh look! My favorite Mastodon host is back online!

That's reason to say Hey! The @bsdcan planning team has some amazing sponsors lined up but we'd appreciate another Bronze or two, and would flip for another Silver.

The schedule is awesome and I hope to see you there.

Could you please nudge your team about a sponsorship?

Thank you!

Please RT!
(I love how that out-lasted its origin)

(in alphabetical order)

Stefano Marinelli »
@stefano@mastodon.bsd.cafe

Shawn Webb »
@lattera@bsd.network

h3artbl33d »
@h3artbl33d@exquisite.social

The fact that is still offline worries me a bit. Hope they are doing okay and that recovery is imminent.

While Exquisite requires account approval, it is more of an abuse and spam countermeasure. Should you be interested in a second fediverse account, feel free to signup. Exquisite runs on in DC1, two racks from @OpenBSDAms.

We welcome everyone from the - whether that be OpenBSD, , , , , and yes even .

Shawn Webb »
@lattera@bsd.network

The code for the program that toggles exploit mitigations and security hardening techniques in has been rewritten from scratch.

This rewritten version will land in 15-CURRENT no later than the end of this month/weekend:

groups.google.com/u/1/a/harden

This change is transparent to users. The only folks that might be affected are those who consume the libhbsdcontrol library directly. The ABI and API have both been changed.

The command-line arguments to the hbsdcontrol(8) utility are unchanged.

Shawn Webb »
@lattera@bsd.network

It would be cool to see this running on : radicle.xyz/

It would be even cooler to have it exposed as a Onion Service.

Shawn Webb »
@lattera@bsd.network

I'll be giving a presentation on today in Denver, Colorado at 6:30pm. If you're interested in , , and/or , I'd love for you to come join me.

meetu.ps/e/MNbpb/ck83q/i

Shawn Webb »
@lattera@bsd.network

@mikael The sadist in me wants to suggest . ;-)

Jay 🚩 »
@jaypatelani@bsd.network

Shawn Webb »
@lattera@bsd.network

I'll be giving a practice run of my presentation titled "HardenedBSD 2024 State of the Union: A Decade of Hardened Bits" on March 23rd, 2024 up in Denver, Colorado: meetup.com/dc303denver/events/

If you're in the greater Denver area and interested in or , I would love for you to join and give me feedback.

Shawn Webb »
@lattera@bsd.network

has a new code hosting partner: . The first project being hosted is : git.hardenedbsd.org/SoldierX/l

Shawn Webb »
@lattera@bsd.network

The 13-STABLE package builder ran out of disk space, causing the current package build to fail.

I'm reclaiming space now and will start a new fresh build.

Shawn Webb »
@lattera@bsd.network

The BSDCan talk committee is pleased to announce that your abstract "HardenedBSD 2024 State of the Hardened Union: A Decade of Hardened Bits" with ID #12 has been accepted (Lecture 50 min). We are delighted that you will be contributing to the 20th annual BSDCan.

HardenedBSD »
@HardenedBSD@bsd.network

Shawn Webb »
@lattera@bsd.network

Shawn Webb »
@lattera@bsd.network

TomAoki »
@TomAoki@mastodon.bsd.cafe

Shawn Webb »
@lattera@bsd.network

Lightly tested new build of released: hardenedbsd.org/~shawn/hbsdfw/

Your usual upgrade instructions:

  1. Back up your configuration
  2. Reinstall from scratch
  3. Restore configuration file

Default username/password: root/hbsdfw

hbsdfw is a 14-STABLE fork of .

edit[0]: Add usual upgrade instructions.
edit[1]: Add default username and password

TomAoki »
@TomAoki@mastodon.bsd.cafe

HardenedBSD »
@HardenedBSD@bsd.network

From @lattera at the Users mailing list:

recently introduced some changes that separate out the userspace handling of system calls to a new library, libsys. I think the change overall is good, but it does cause issues with HardenedBSD.

There is a dance between libc, libsys, libthr, and the CSU at various stages of a process's lifecycle. We compile both applications and libraries with Link-Time Optimization (LTO), which seems to be causing issues with the dance.

I'm hoping to resolve this before the next monthly OS build (01 March 2024). But there's a chance I might not fix it in time. I need to have a better understanding of the code as there are some gaps of knowledge to be filled.

I'll keep everyone informed as to my progress. If I can't fix it in time for the next monthly build cycle, I plan to disable the build of 15-CURRENT (and *ONLY* 15-CURRENT). We will still build 13-STABLE and 14-STABLE.

Reference: groups.google.com/a/hardenedbs

Shawn Webb »
@lattera@bsd.network

Two new additions to the family.

Two StarFive VisionFive2 SBCs enclosed in their powder black cases, with one of the devices having a UART USB cable attached.

Shawn Webb »
@lattera@bsd.network

FreeBSD 15.0-CURRENT-HBSD #0  hardened/current/master-n193382-7d849178809c: Mon Feb 12 19:03:14 UTC 2024                                                       
shawn@hbsd-current-01:/usr/obj/usr/src/riscv.riscv64/sys/HARDENEDBSD riscv

No description

Michael Dexter »
@dexter@bsd.network

Thank you Foundation and for your support of the 20TH ANNIVERSARY @bsdcan !

Thermometer updates to come and a lot more outreach!

Shawn Webb »
@lattera@bsd.network

Current status:

$ sudo make real-release NODOC=1 NOSRC=1 NOPORTS=1 NODOCS=1 TARGET=riscv TARGET_ARCH=riscv64

Shawn Webb »
@lattera@bsd.network

The USB prohibition work has been merged/cherry-picked to 13-STABLE and 14-STABLE.

Shawn Webb »
@lattera@bsd.network

Re-deployed my wireless access point at home today. I now have one wireless network that routes directly out to the public Internet, and another that routes all traffic via .

Shawn Webb »
@lattera@bsd.network

h3artbl33d »
@h3artbl33d@exquisite.social

Right. The Bitlocker key can be obtained in under a minute, by sniffing the TPM. This goes for the most recent build of Windows 11 and includes TPM 2.0.

Fortunately, there is a quick fix. Run or with full disk encryption . Case closed.

HardenedBSD »
@HardenedBSD@bsd.network

HardenedBSD »
@HardenedBSD@bsd.network

Major thanks to exquisite.social/@h3artbl33d for helping fix cloning our repositories over HTTPS! This command should now work: `git clone git.hardenedbsd.org/HardenedBS

Shawn Webb »
@lattera@bsd.network

Shawn Webb »
@lattera@bsd.network

Interesting new commit in :

HBSD: Provide support for prohibiting new USB device connections

This commit introduces the hardening.pax.prohibit_new_usb sysctl
tunable node. This node can be set to one of three values:

0: Disabled
1: Enabled
2: Enabled without possibility to disable

When set to 2, a reboot is required to end the prohibition on new USB
connections.

This is based on a patch by Loic F <loic.f@hardenedbsd.org>.

git.hardenedbsd.org/hardenedbs

Shawn Webb »
@lattera@bsd.network

Goal for next week: start the process on getting a new passport. My wife removed our passports from our safe, so now we can't find them--especially with moving twice in one year.

My passport was expired, anyways.

I'm really hoping to start traveling the world again this year, giving presentations on and libhijack.