cybre:uranther #012.018 is a user on cybre.space. You can follow them or interact with them if you have an account anywhere in the fediverse.

What's good today? I need a distraction.

@ajroach42 I've been lurking in Freenode -hardened, , , and #-hardened just trying to soak in the knowledge about security and mitigation techniques.

@ajroach42 glibc and the software that depends on it rely on a lot of undefined, non-standard, and undocumented behavior.

I think we knew this already but it can be painful to get into the grit of it when trying to provide standards conformance in .

Also, had (has?) some strange 'alternative' behavior that would do sketchy entropy collection instead of returning an error when /dev/urandom is not available.

@uranther IIRC, that SSL problem has been mitigated??? Dunno, I don't spend enough time in security right now.

glibc honestly scares me though.

@ajroach42 That article was from 2015 so I think it's been mended since then. It just surprised me because I thought the OpenBSD wizards were infallible. 🙂