A PR to be able to use a relative timestamp in pip was merged just last week
601 karma · joined March 24, 2011
A PR to be able to use a relative timestamp in pip was merged just last week
The standalone makedepend(1) that does the work is available in package xutils-dev on Ubuntu.
The spec (RFC 7250, "Using Raw Public Keys in Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS)") suggests DANE/DNSSEC as a mechanism to bind identities to public keys (section 6).
https://datatracker.ietf.org/doc/html/rfc7250
Will this really be simpler?
I suspect the bureaucratic overhead of needing to go to IANA to reserve a new port might have had a chilling effect. See:
https://www.iana.org/protocols/apply
https://www.iana.org/form/ports-servicesWhich standard? RFC 3207 (for STARTTLS over SMTP), 2002, says: "If the client receives the 454 response [TLS not available], the client must decide whether or not to continue the SMTP session".
def execute(f)
f.call "test response"
end
perform = TOPLEVEL_BINDING.method(:execute)
perform.call Kernel.method(:puts)A sprinkling of grep/perl (awk/sed/ruby/...) is mostly good enough eg:
strace -e trace=%file cat /etc/passwd 2>&1 >/dev/null | grep ^open | grep -Po '(?<=").*(?=")'
Alternatively "-e trace=%file" to get all file-related system calls (will catch eg failing pre-emptive checks using access(3) -> stat(2)).
I think this is from the j2ssh/maverick SSH server, used in a bunch of enterprisey Java products.
https://jadaptive.com/en/products/java-ssh-server
https://github.com/sshtools/j2ssh-maverick/blob/ce11ceaf0aa0...
RTLD_NODELETE (since glibc 2.2)
Do not unload the shared object during dlclose().
Consequently, the object's static and global variables
are not reinitialized if the object is reloaded with
dlopen() at a later time.
Are there any other times when it's beneficial to use NODELETE?(Reference [12] is from Usenix July 2022. See "Prior work" in the introduction).
sqlite-utils create-table ~/commands.db commands id integer text text --pk id
PROMPT_COMMAND="( fc -n -l -1 | perl -p -e 's/^\s+//; chomp if eof' | sqlite-utils insert --text ~/commands.db commands - & )"
It's slow, has perl & python external deps, needs a timestamp column, call subshell to avoid job control messages, ...A nicer single "prompt command" wrapper is certainly possible though.
See http://www.ruby-lang.org/en/news/2021/04/05/xml-round-trip-v...
See top right: https://upload.wikimedia.org/wikipedia/commons/d/d8/Trn_cons...
<internal:/usr/local/lib/ruby/3.2.0/rubygems/core_ext/kernel_require.rb>:85:in `require': cannot load such file -- socket (LoadError)
"HMS carabiner" is also common amongst anglophone climbers (for the "Halbmastwurfsicherung" knot you might use as an alternative to your sticht plate).
"We will encourage you to develop the three great virtues of a programmer: laziness, impatience, and hubris.", "Programming Perl", 1ed
2ed says:
"Laziness
The quality that makes you go to great effort to reduce overall energy expenditure. It makes you write labor-saving programs that other people will find useful, and document what you wrote so you don't have to answer so many questions about it. Hence, the first great virtue of a programmer. Also hence, this book."
Some discussion at https://wiki.c2.com/?LazinessImpatienceHubris
https://www.legrand.fr/catalogue/interrupteurs-et-prises/mos...
It's a cute idea but Mosaic is quite expensive. Also, you still must take into account safety regulations eg adequately separating low and high voltage wiring behind the faceplate.
Can anyone recommend a hackable alternative? I found https://alternativeto.net/software/pocket/?license=opensourc...
The poor thermal insulation and condensation were predictable. I hadn't predicted the shifting wind which chose to balloon my orange cocoon with cold air every 20 mins no matter which orientation I chose to lie in. I finished the night with a bungie cord around the sack, under my armpits. That of course left my head, shoulders and arms exposed but kept the wind out. Not recommended.
After this experience I upgraded to reflective mylar survival bags. NB "bag". These are a little harder to find than survival blankets but if a bag can be so badly affected by moderate wind, a blanket would be so much worse.
I'm hopefully preaching to the choir here but please beware that high-visibility flaws often attract fake PoCs. Malicious in the sense "might [also] attack the user" (you!).
Often these will surf on work done by valid PoCs to look credible. GitHub was stuffed with them for the Hafnium Exchange bug, before Microsoft brought down the ban hammer. (At the time there was lots of mewing about "Microsoft protecting their own" and "Microsoft killing free speech" but I wonder if they weren't also interested in stopping the pwnage from these fake exploits, too).
I'm not saying this repo is malicious. This github user looks legitimate and doesn't look like the obviously-created-by-a-bot profiles I've previously seen. Even so I wouldn't necessarily trust ~5000 vendored class files. Play carefully.
Picking two potentially high impact announcements from the last month or so:
1. There is a severe flaw in the RSA cryptosystem. 2. There is a remote code exec vulnerability in Microsoft Exchange.
One of these was a sketch of an incremental improvement to an attack that remains mostly of theoretical interest. The other was being actively exploited, was tragically simple for 3rd parties to replicate post-announcement and resulted in widespread pain.
There is some (non-linear) scale here (theoretical flaw/poc/weaponized poc/public poc/public weaponized poc/exploited, but limited actors or targets/widely exploited/HAVOC). MS for example uses just "less likely to be exploited", "more likely to be exploited" "being exploited". It's coarse and somewhat subjective but there is value even so.
"This flaw is being actively exploited in the wild" is the best line I can take upstairs. I don't want that to go away just because some parties might misuse it.