HNHacker News
TopNewBestAskShowJobs

yrro

2,593 karma · joined August 10, 2013

submissionscomments
yrro··on Self hosted email continues to steeply decline
Can you formulate that question more precisely if this doesn't answer you?

* I am still using the same domains that I've always hosted mail for * Since I am sending from new IP addresses, but want to retain the ability to send from the old MTA until it is decomissioned, the new MTA uses a different HELO identifier, and the dependencies for that are all in place (forward and reverse DNS addresses and updated SPF records) * The new DNS records are still in the same administrative domain as the old ones

yrro··on Self hosted email continues to steeply decline
Thank you for this perspective. I've been hosting my own email for about 25 years and have never had significant problems delivering to any of the large providers. A couple of months ago I migrated from one VPS host to another. I'd been putting this off for a long time, in part because of what I've read on HN about how difficult it is to self-host your mail. I finally took the plunge a couple of months ago, expecting to find the new provider's IP space unusable & having to relay via the old MTA/start relaying via a commercial MTA; but to my surprise, it's been completely smooth sailing! Maybe I've just been lucky with the nature of my setup: a small number of mailboxes and domains used for personal/small business use. Certainly if I was sending bulk mail or significant amounts of transactional mail then I'd use someone else's service.
yrro··on Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim
Debian builds Exim against GnuTLS because OpenSSL used to use a license with an advertising clause, making it incompatible with the GPLd Exim.

Since OpenSSL 3 is now available under a GPL-compatible license, I think it's long past time to switch. But judging by the sorry state of https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446036 I don't think it's going to happen any time soon.

yrro··on Let’s Encrypt: Stopping Issuance for Potential Incident – Resolved
Ask the CA/Browser forum what they will insist upon
yrro··on Copy Fail
FYI RHEL's SELinux policy blocks AF_ALG socket creation for confined services out of the box. But disabling via RestrictAddressFamilies= unit option, or initcall_blacklist= kernel parameter, seems to be a good mitigation for unconfined services, users and containers.
yrro··on Copy Fail
They've bumped the severity and 8/9/10 are now 'affected'. Hope a patch comes soon!
yrro··on Copy Fail
Have you got any info about this. 'seinfo -c' shows there is an alg_socket class. I presume this permission is required to be able to create an AF_ALG socket:

    $ sesearch -A -c alg_socket -p createallow bluetooth_t bluetooth_t:alg_socket { accept append bind connect create getattr getopt ioctl listen lock read setattr setopt shutdown write };
    allow container_device_plugin_init_t container_device_plugin_init_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_device_plugin_t container_device_plugin_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_device_t container_device_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_engine_t container_engine_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_init_t container_init_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_kvm_t container_kvm_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_logreader_t container_logreader_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_logwriter_t container_logwriter_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_t container_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow container_userns_t container_userns_t:alg_socket { accept append bind connect create getattr getopt ioctl lock map read setattr setopt shutdown write };
    allow openshift_app_t openshift_app_t:alg_socket { append bind connect create getattr getopt ioctl lock read setattr setopt shutdown write };
    allow openshift_t openshift_t:alg_socket { append bind connect create getattr getopt ioctl lock read setattr setopt shutdown write };
    allow spc_t unlabeled_t:alg_socket { append bind connect create getattr getopt ioctl lock read setattr setopt shutdown write };
    allow staff_t staff_t:alg_socket { append bind connect create getopt ioctl lock read setattr setopt shutdown write };
    allow sysadm_t sysadm_t:alg_socket { accept append bind connect create getopt ioctl listen lock read setattr setopt shutdown write };
    allow unconfined_domain_type domain:alg_socket { accept append bind connect create getattr getopt ioctl listen lock map name_bind read recv_msg recvfrom relabelfrom relabelto send_msg sendto setattr setopt shutdown write };
    allow user_t user_t:alg_socket { append bind connect create getopt ioctl lock read setattr setopt shutdown write };
... that's a lot of domains, including container_t and user_t; and obviously anything unconfined_t can't be expected to be restricted.

(Maybe you & others are specifically thinking of Android's policy?)

yrro··on A deep dive into Apple's .car file format
... and that is why all 'modern' software is incredibly memory and CPU intensive...
yrro··on Babylon 5 is now free to watch on YouTube
Take it from someone who saw it when it first aired on standard definition analogue TV: it doesn't really matter all that much. The performance of the actors and the story is what's important!
yrro··on Babylon 5 is now free to watch on YouTube
A _real_ web site!

When I first returned to it rewatching B5 a couple of years ago, I actaully found it difficult to navigate. It took me a while to realise that my brain was parsing the block of navigation buttons at the centre top of the screen as a banner ad and filtering it out!

yrro··on Babylon 5 is now free to watch on YouTube
The "TKO" 'A' plot is silly but it has one of the most moving and memorable 'B' plots of the series!
yrro··on Windows Notepad App Remote Code Execution Vulnerability
This is the same company that, back in the day, warned users to not click links in Internet Explorer. A web browser.
yrro··on The RCE that AMD won't fix
Doesn't this break CRL fetching and OCSP queries?
yrro··on The RCE that AMD won't fix
Of course not, the vulnerability is in "AMD’s AutoUpdate software" (i.e., vendor trash).
yrro··on How not to securely erase a NVME drive (2022)
That won't overwrite pages not allocated to a namespace (which can happen due to wear levelling/underprovisioning, or because the controller has decided to stop using that page because it's unhealthy).

Flash looks like a simple array of blocks, but under the hood there is a controller that allocates writes to different pages. You need to tell the controller to erase all pages if you want to guarantee data destruction.

yrro··on How not to securely erase a NVME drive (2022)
What's the difference between this and sanitize? Should we be doing both?

[edit] sanitize runs on the controller level while format works on the namespace level. So I suppose formatting won't touch any pages not allocated to a namespace.

I wish there was _any_ way to find out which NVME controllers supported which operation before you buy them!

yrro··on How not to securely erase a NVME drive (2022)
I suppose arguably the kernel, or at least some component of the OS, should be freezing/locking drives as they come online. The firmware doing so as one-off operation during boot is a workaround for the lack of this being done by the OS.
yrro··on How not to securely erase a NVME drive (2022)
I've lost faith that Linux distros will ever fix the problem where some PCR changes and the TPM refuses to unseal the key... the user is left with a recovery passphrase prompt & no way to verify whether they have been attacked by the 'evil maid', or whether it was just because of a kernel or kernel command line or initrd or initrd module change, etc.
yrro··on How not to securely erase a NVME drive (2022)
> So I connected it to the computer with the USB to NVME M.2 converter

> blkdiscard: /dev/nvme0n1: BLKSECDISCARD ioctl failed: Operation not supported

I've got a USB-to-NVME adapter that exposes the NVME namespaces as SCSI disks. `blkdiscard` did not work with these by default, however it worked fine after I changed the `provisioning_mode` attribute of the disk.

This can be done by identifying the SCSI device ID of the disk (lsscsi) and then changing it with:

    # echo unmap > /sys/class/scsi_disk/a:b:c:d/provisioning_mode
`lsblk -D` will show which block devices support the discard operation; run it before and after changing provisioning_mode to see the difference.

This is absolutely not to be used as an alternative to a real 'sanitize' operation directly sent to the NVME controller. If you actually need to securely erase your data, and the drive dosesn't support the sanitize operation, then you should physically shred the drive and demand a refund from the retailed (goods as sold are not fit for purpose).

Overall, I've found dealing with nvme a frustrating experience. In theory it's nice to have NVME controller firmware be responsible for executing commands from the host (sanitize! change LBA size! underprovision by 30%!) but in practice, it's complete hit or miss whether controllers support a command or will reject it, or maybe they claim to support it but it doesn't work because the controller firmware is buggy shit.

I would like to have raw NAND devices and have the kernel be in charge of everything, but sadly that wouldn't work for Windows so we're stuck in proprietary firmware hell.

yrro··on We will ban you and ridicule you in public if you waste our time on crap reports
Somehow, I knew this would be curl before finishing reading the headline. Good on them!
yrro··on An Elizabethan mansion's secrets for staying warm
In the UK it's minimum code and we don't bother to inspect. We trust the building firms to self-certify, with predictable results...
yrro··on Why is there a tiny hole in the airplane window? (2023)
How much easier would it be to design build & maintain aircraft if we did away with (passenger) windows?
yrro··on Open Infrastructure Map
https://www.electricitybills.uk/ shows a breakdown of the components of consumer energy bills. It's not as simple as saying "it's expensive because of gas", though pricing based on the marginal production cost is one component.
yrro··on IPv6 just turned 30 and still hasn't taken over the world
If only the inventors of NAT had patented it and then refused to license it!
yrro··on IPv6 just turned 30 and still hasn't taken over the world
Is it commonly used within small/medium/large businesses?
yrro··on tc-ematch(8) extended matches for use with "basic", "cgroup" or "flow" filters
Spare some context for a poor old blind beggar?
yrro··on Influential study on glyphosate safety retracted 25 years after publication
Dandelion roots are ridiculously long!

https://images.wur.nl/digital/collection/coll13/id/676/rec/3

yrro··on Self-hosting a NAT Gateway
Separating out main, guest, work, internet-of-shit, security & VPN subnets
yrro··on A day at Hetzner Online in the Falkenstein data center
There is no such thing as an 'internal' network.
yrro··on Nearly all UK drivers say headlights are too bright
It seems like no government wants to kick the hornet's nest & solve this issue, nor the issue of pavement parking. At least this government is finally working on the problem of doctored number plates that are invisible to enforcement cameras. Land a few drivers with a 15 year sentence for perverting the cause of justice & things should right themselves.
Page 1 of 34Next →