HNHacker News
TopNewBestAskShowJobs

botanicalfriend

23 karma · joined November 13, 2021

HN username AT fastmail dot com
submissionscomments
botanicalfriend··on Claude Code escapes its own denylist and sandbox
On the dynamic linker bypass specifically, have you looked at fapolicyd [1]? It uses fanotify(7) and the top of the README is:

> The restrictive policy was designed with these goals in mind:

> 1. No bypass of security by executing programs via ld.so.

> 2. Anything requesting execution must be trusted.

One correction on the table: SELinux and AppArmor shouldn't be grouped under "rename-resistant: No". AppArmor is path-based. SELinux labels are on the inode, a rename doesn't change the security context. The copy attack doesn't apply either: a process in sandbox_t creating a file in /tmp gets tmp_t via type transition, and the policy does not grant sandbox_t execute permission on tmp_t.

[1] https://github.com/linux-application-whitelisting/fapolicyd

botanicalfriend··on Linux kernel security work
Paying maintainers doesn't give Red Hat a magic oracle for "which commits matter for security". What you actually end up with is cherry-picking + backporting. Backporting is inherently messy, you can introduce new bugs (including security bugs) while trying to transplant fixes, and omissions are inevitable. And CVEs don't save you here: plenty of security relevant fixes never get a tidy CVE in the first place, and vendors miss fixes because they often pretend the CVE stream is "the security feed".

Greg is pretty blunt about this in the video linked in the article: "If you are not using the latest stable / longterm kernel, your system is insecure" (see 51:40-53:00 in [1]). He also calls out Red Hat explicitly for ending up "off in the weeds" with their fixes.

RHEL as an entire distribution may provide good enough security for most environments. But that is not the same claim as "the RHEL kernel is secure" or "they know exactly which commits are relevant". It is still guesswork plus backports, and you're still running behind upstream fixes (many of which will never get pulled in). It is a comfortable myth.

[1] https://www.youtube.com/watch?v=sLX1ehWjIcw&t=3099s

botanicalfriend··on An Interview with Oxide's Bryan Cantrill
amazing because of the irony, yes?
botanicalfriend··on Ask HN: Pydantic has too much deprecation. Why is it popular?
From my perspective a large factor contributing to its popularity is because of FastAPIs native integration. V2 has broken so much behavior, and the library is generally fragile and slow. Credit where it is due, it is a great library that has done a lot to bring python types to more projects, but there are better solutions out there now.

I’d strongly recommend looking into msgspec. It is a much faster alternative and is largely “correct” in its implementation. It uses all of the python native type annotations without many hacks. Really it is much much faster and can actually be used for performance sensitive python workloads that need strong typing.

botanicalfriend··on Ask HN: Is Firefox team too small to do serious security tests?
I have the same worry (although I have no evidence, and haven’t done much research into finding evidence).

I've slowly transitioned from FF to Chrome over the past year, for this reason. I still use both, but am trying to prepare myself for a time that comes when FF is no longer a viable primary browser.

botanicalfriend··on Show HN: WireHole combines WireGuard, Pi-hole, and Unbound with an easy UI
This looks super useful. It is a bit convoluted to setup WG/PiHole/Unbound/foo and link them all together. But, it is not tedious enough that I’d ever put in the time to make a whole UI to improve it. I’m glad someone did though, it’s these little things that you don’t realize you need :-)
botanicalfriend··on Ask HN: Which project(s) made you go “I can't believe this is open-source”?
HAProxy
botanicalfriend··on Pingora, the proxy that connects Cloudflare to the Internet
The “closed door development” is a problem for their business. They don’t have that problem when they maintain it, free software aside.
botanicalfriend··on Show HN: ProxSNI, a transparent HTTPS tunnel for self-hosters
A very simple haproxy/envoy/nginx config will achieve this, no?
botanicalfriend··on Ask HN: How do you archive secrets for your side projects?
You can encrypt them using something like https://github.com/FiloSottile/age and then just store them in git. When you need to access them, just run "age -d .."

If you're paranoid you can use GPG + a smart card like a yubikey, but its all about convenience trade off..

botanicalfriend··on Ask HN: Are there any open source PKI solutions that don't suck?
Vault X.509