4 April 2024

42 links · Thursday

xz backdoor - Dmitry Kudryavtsev

A malicious backdoor was discovered in xz library that implements LZMA compression. xz, among many other places, is used, indirectly, in sshd. My attempt to explain what happened.

Use OpenVPN as a proxy to more comfortably access internal Gitlab

I currently work on a project that uses a self hosted Gitlab instance for git and this Gitlab instance can be only accessed after connecting to the company’s OpenVPN. I did not want to be connected to OpenVPN all the time from my machine, especially this being…

Abstraction is much more than interfaces

When people learn about abstraction, they usually focus on the means used to achieve it: abstract classes, objects, functions, or interfaces. They read that abstraction is used to hide background details or unnecessary implementation of the data so that users …

Please return my property.

California Attorney General Rob Bonta, Please return my property – as I have asked through your official contact form, by email (with read receipts), and by phone many times, and have been in…

The Video That Inspired Me To Create Odin

[Originally from a Twitter Thread] Original Twitter Post Many people may not know this but this video by Sean Barrett @nothings is partially the reason why I made the Odin programming language. And I’ll explain what insights it gave me in this thread 🧵. A lot…

PostgreSQL and its annoying crosstab

Today, I had to pivot (pun intended) from my usual tasks to help a colleague with a query. The task is deceptively simple: Collect metadata about all columns of a table in a single query. This was to be a function in PostgreSQL that would return a table with t…

Joining Polar as an Advisor

I'm excited to share that I've joined Polar as an advisor. The opening text of the Polar website at the time of writing is "Get paid coding on your passion." This is a deeply personal mission to me. I want to share some of my personal history and how it led to…

HTTP/2 `CONTINUATION` Flood

What is the CONTINUATION Flood? It is a new class of vulnerabilities in multiple implementations of HTTP/2 protocol. The root cause is an incorrect handling of HEADERS and multiple CONTINUATION frames which ultimately leads to Denial of Service. The outcome de…

Demystifying HTTP with Telnet – Ian's notes

Established in 2020, this site serves as a memory bank of notes and guides for me to reference again down the line, made public with the knowledge that others are likely to encounter simillar situations, especially in niche environments.

Exploring Batch Caching of Trees

From my other posts it might seem that I am a bit of a React hater - not at all. React and related frameworks have introduced a very powerful concept into the web development field - the concept of materialised trees. In fact, we have been dealing with those i…

Reverse engineering Bandcamp authentication protocol

Did you know that the albums you purchase on Bandcamp can disappear from your collection without notice? This can happen for various reasons. For example, a seller might decide on a whim to remove the album from the platform. Bandcamp apparently allows this in…

XZ Backdoor: Not the End of Open Source

When I stumbled across a post that an encryption library offers a potential backdoor to SSH connectivity on Good Friday, my first thought was: why is it always on a Friday that these things drop? And then my second one: oh bugger, here goes my weekend. Now, I …

Linux shellcraft: the pipe trick

This article covers a useful shell scripting technique on Linux that allows for getting read and write handles to a pipe in a shell process's memory.

autoconf makes me think we stopped evolving too soon

I've gotten a few bits of feedback asking for my thoughts and/or reactions to the whole "xz backdoor" thing that happened over the past couple of days. Most of my thoughts on the matter apply to autoconf and friends, and they aren't great.

German state moving 30,000 PCs to LibreOffice - The Document Foundation Blog

Following a successful pilot project, the northern German federal state of Schleswig-Holstein has decided to move from Microsoft Windows and Microsoft Office to Linux and LibreOffice (and other free and open source software) on the 30,000 PCs used in the local…

A disk so full, it couldn’t be restored

My younger child’s MacBook Pro was unsalvageably full. Only a complete wipe would suffice—and then Time Machine failed us. I love my children, but they do sometimes forget what I do for a living: a…

[HOWTO] Suggest changes directly in Azure DevOps pull requests

Azure DevOps allows proposing changes directly in pull requests, simplifying the process of suggesting small alterations like translations or formatting. Users can mark the part needing a change, c…

.NET MAUI Community Standup

The topic for this month’s .NET MAUI community standup is so interesting, Testing your MAUI Apps ft. Gerald Versluis. Remember to join live on Thu, Apr 4 at 17:00 UTC. Click the link to access the …

GitHub - nilsherzig/LLocalSearch: This is a completely locally running meta search engine using LLM Agents. The user can ask a question and the system will use a chain of LLMs to find the answer. The user can see the progress of the agents and the final answer. No OpenAI or Google API keys are needed.

This is a completely locally running meta search engine using LLM Agents. The user can ask a question and the system will use a chain of LLMs to find the answer. The user can see the progress of th...

Terraform makes carbon neutral natural gas

We did it! After two years of hard work we hold in our hands hard proof that the incredible team at Terraform can make synthetic natural gas from sunlight and air, as reported in TechCrunch. Last W…

Introducing Jpegli: A New JPEG Coding Library

Jpegli, an advanced JPEG coding library that maintains high backward compatibility is faster, and more efficient, than traditional JPEG.