-- Leo's gemini proxy

-- Connecting to gemini.tuxmachines.org:1965...

-- Connected

-- Sending request

-- Meta line: 20 text/gemini;lang=en-GB

Tux Machines


Security: Reproducible Builds, FUD, and more


Posted by Roy Schestowitz on Apr 18, 2023


Raspberry Pi Pico W and Arduino

TLA+, Mozilla, and Raku



More on Differential Reproducible Builds: Devuan is 46% reproducible!


↺ More on Differential Reproducible Builds: Devuan is 46% reproducible!


> After fixing some quirks, building Devuan GNU+Linux 4.0 Chimaera was fairly quick since they do not modify that many packages, and I’m now able to reproduce 46% of the packages that Devuan Chimaera add/modify on amd64. I have more work in progress here (hint: reproduce/pureos), but PureOS is considerably larger than both Trisquel and Devuan together. I’m not sure how interested Devuan or PureOS are in reproducible builds though.



This Bay Area prosecutor wants to help police nationwide take on ‘pig butchering’ scams


↺ This Bay Area prosecutor wants to help police nationwide take on ‘pig butchering’ scams


> Santa Clara County Deputy District Attorney Erin West's "Operation Shamrock" isn't relying on luck to take down the worst criminals.



Matthew Garrett: PSA: upgrade your LUKS key derivation function


↺ Matthew Garrett: PSA: upgrade your LUKS key derivation function


> Here's an article from a French anarchist describing how his (encrypted) laptop was seized after he was arrested, and material from the encrypted partition has since been entered as evidence against him. His encryption password was supposedly greater than 20 characters and included a mixture of cases, numbers, and punctuation, so in the absence of any sort of opsec failures this implies that even relatively complex passwords can now be brute


↺ Here's an article



Report finds software supply chains are being compromised by popular open-source products [Ed: Distracting from vastly worse problems in proprietary software]


↺ Report finds software supply chains are being compromised by popular open-source products


> A new report from software supply chain management startup Lineaje finds an inherent risk of software supply chains being compromised when using the most popular open-source products and dependencies.




gemini.tuxmachines.org

-- Response ended

-- Page fetched on Sat Jun 1 07:23:43 2024