libera/#devuan/ Saturday, 2024-03-30

onefangFirst take, this xz / lzma backdoor doesn't worry me, coz the Devuan versions I'm using / upgrading to are too old.00:07
onefangSecond take.  The sudden depth of this rabbit hole does worry me.00:07
* gnarface sigh00:12
gnarfaceyea, it's probably about time to fork everything00:13
onefangI'm reading an article and a though occurs to me.  It seems to be targeting ssh sessions that have been run by systemd.  Maybe someone wants to break into systemd systems and remove systemd?  But that's OT.00:14
brocashelmall i know is testing and unstable versions reverted to 5.4.5, so it's probably safe to "upgrade" with the "really" version tag00:18
ted-iousHow do we know how far back this particular infiltration goes?01:25
fsmithredDebian says it's not in the stable version.01:28
fsmithredwhich I think is 5.201:28
fsmithrednope. 5.4 in daedalus01:29
ted-iousI don't mean which is the newest version that doesn't have the suspicious code that people are talking about.01:29
ted-iousI mean how do we know that the bad guy only got these specific updates into the code?01:29
ted-iousPeople are saying that this was a 2 year attack.01:30
onefangThat'll be why people are investigating these things now.01:31
ted-iousI'm a bit impatient to get more information.01:31
ted-iousBecause this sounds like it was a major operation and we might only be seeing the tip of the iceberg.01:32
onefangEnough of this rabbit hole.  Time to chase the Easter Bunny instead.  B-)01:43
masonOh, alright, https://lists.debian.org/debian-security-announce/2024/msg00057.html has already come up here.02:24
gast0nHi, the util-linux package has not yet been patched in Debian, to fix the vulnerability in the wall command02:45
djphyou mean the vulnerability that relies on (a) another local user as the attacker, (b) the non-default suggestion application when you misspell a command ... ?02:48
gast0nhttps://www.bleepingcomputer.com/news/security/decade-old-linux-wall-bug-helps-make-fake-sudo-prompts-steal-passwords/02:49
djphyes, that one02:50
djphthe one where the guy who has the proof of concept attack says that Debian is technically immune by default, since it doesn't ship with command-not-found ?02:52
gast0nah ok, thanks :) Also I was seeing that util-linux is a forked package in Devuan02:53
fluffywolfwaaaaaaay back when, I had fun creating filenames on a sunos server that sent terminal escapes to anyone who "ls"ed them...03:57
fluffywolfleave them in /tmp and wait...03:58
joerglol04:00
fluffywolfit's basically the exact same thing as that wall issue...  ls had absolutely no filtering, and filenames could contain anything except a null and a /.  so if you could create a file that someone else would ls, you could send any arbitrary stream to their terminal, including things that made them do bad things.04:02
joergthat issue changed?04:03
ted-iousYes nobody uses sunos anymor. :)04:03
fluffywolfls has filtered things for a while now.  heh.04:03
joerg:-D04:03
fluffywolfhell, now ls even provides fully escaped/quoted output.04:04
joergyes :-)04:06
joerglet's take it to *offtopic though :-)04:07
systemdlete2gnarface sigh04:09
systemdlete2<gnarface> yea, it's probably about time to fork everything04:09
ted-iousFork what?04:09
systemdlete2funny, when I suggested this several years ago, it was met with groans and repudiation04:09
systemdlete2I think gnarface meant the entire linux/gnu base04:10
systemdlete2(I hope that's what he meant)04:10
ted-iousSince devuan is already a partial fork what else does it need besides a few more bugs fixed here and there?04:10
systemdlete2entire vs partial04:10
ted-iousOh.04:10
joergnothing changed04:10
systemdlete2so maybe this could spell the end (finally!) of this sytemd insanity?04:11
ted-iousWhy can't a bunch of determined people take over the debian board and reverse the systemd decision?04:14
systemdlete2same reason, probably, that a bunch of determined people haven't taken over the board at boeing04:15
systemdlete2the engineers were replaced by marketing bots04:15
ted-iousFor boeing you would need lots of money but for debian I think it's just finding a few people to serve on the board and then a campaign to get support.04:16
golinuxPlease take to OT. Thanks.04:17
systemdlete2sorry04:17
majeklaHello everyone.11:51
majeklaI wanted to congratulate and warmly thank the entire Devuan team for this clean and intelligent distribution!11:51
majeklaComing from the BSD world (FreeBSD, Solaris, Illumos, etc.) and being somewhat of a "conservative" computer scientist at heart (although I am young), I was genuinely surprised by Devuan and its optimization.11:51
majeklaBeing anything but a fan of Debian, and that for several years (especially because of systemd, which I really do not like), I found in your distribution a very good alternative, with which I feel "right" on Linux again. Although there are many distributions (and I must have tried a good fifty of them), some of which also have not yielded to systemd, Devuan seems to me a truly unique case.11:51
majeklaIt's very pleasant to work with your distribution.11:51
majeklaThank you again for all your efforts!11:51
* joerg prints and hands out posters with ^^^ :-)13:16
sfoxmajekla: why is devuan unique out of the non systemd distros?18:55
majeklaTEKHonestly, on an IRC chat, the list is likely to be long. First off, I prefer the separation of tools for administration. And above all, I prefer things to be simple. I have a problem with systemd in that sense. And if I limit myself to purely system aspects, the few trials I've done (various overloads, network requests, heavy writing on disks, etc.) have revealed greater stability than Debian. I'm sorry if I don't seem nice about Debian19:24
majeklaTEK(which I've been using in a corporate environment for a long time) but every time I test a Debian-based distribution in depth, I regularly encounter strange bugs that appear. This ranges from file system corruption, to shells and PATHs disappearing, regardless of the medium (VM, real hardware, etc.). That's why I prefer FreeBSD or distributions coming from RHEL for heavy loads. I haven't seen anything like this on Devuan so far. I've19:24
majeklaTEKwitnessed temporary shell lock-ups of a few seconds, but nothing broke... I can't say the same for Debian, for which I've lost count of the countless bugs that occurred during overloads, updates, etc. I haven't had the time to look in detail at everything that's been done on this distribution, but just on that point (stability), I'm really surprised.19:24
cousin_luigiWhat's the story with the xz vulnerability on devuan?19:41
majeklaTEKdon't know, but xz version is not the bad one.19:49
gnarfacecousin_luigi: the vulnerability seems to be in libsystemd0, which devuan doesn't have. it has a drop-in placeholder slug which doesn't link to the compromised library19:52
gnarfaceand yea, supposedly the xz version in current stable isn't the bad one anyway19:55
gnarfacei think debian has already rolled back the ones in testing and unstable19:55
majeklaTEKTo conclude and put it succinctly, I also find the user experience to be particularly appealing on Devuan compared to other distributions. There has been a special care taken in the choice of the desktop theme (those shades of blue) which is very pleasant and calming. (not to mention that, on a personal note, I prefer xfce). Lastly, there's the choice between the init systems... and it's really important for me to maintain this traditional20:02
majeklaTEKand modular approach. Having the choice. Well done.20:02
CueXXIIIgnarface: no, the vulnerability is in xz, which is dynamically linked into libsystemd20:15
majeklaTEKin liblzma20:15
CueXXIIIyeah, that's part of xz-utils20:16
majeklaTEKyes20:16
CueXXIIIit takes a long path to arrive in sshd, by design20:16
golinuxThanks for the kind words about the theming. All the previous custom themes are still available throuuge Daedalud21:09
golinuxDaedalus21:09
gnarfacethree cheers for golinux!21:12
* golinux blushes21:20
golinuxSadly since I have "retired" there may not be any new ones going forward . . .21:21
majeklaTEKyou're welcome (go linux). It's a very good job.22:09
BoscoHello22:56
BoscoSomeone else?22:56
nemoBosco: hm?22:59
Bosconemo: 💻😅22:59
BoscoDoes anyone know if anyone has a problem with version 5 of Netinstall?23:00
nemohaven't done an install in a long while, but my recollection is netinstall was never a good idea unless you really needed it23:01
nemofsmithred here is the expert though23:01
nemoif they are active on a weekend23:01
fsmithredsure, there are always people who have problems installing, regadless of what iso they use.23:02
fsmithredwhat problem are you having?23:02
Bosconemo: Version 5 netinstall gave me problems when trying to boot it from a USB23:03
fsmithredall the isos in the "installer iso" directories will install packages from the network (a netinstall) unless you specify not to use a mirror.23:03
fsmithredhow did you prepare the usb?23:03
fsmithredand which iso, and are you booting uefi or legacy?23:04
nemofsmithred: ok. I just remember being told here on #devuan to use the full image after having run into some setup issues, but maybe it was specific to an issue at that time23:04
Boscofsmithred: Hello, when you start the boot of version 5 of netinstall it does not boot via USB23:04
nemoBosco: huh. that sounds more like a bios config issue on your computer23:05
Boscofsmithred: UEFI23:05
nemolike "press F2 to choose alternate boot device"23:05
BoscoThe screen goes black when it starts and does nothing else in netinstall 523:07
fsmithreddid you check the sha256sum to make sure the download was good?23:07
fsmithredagain, how did the iso get from your download directory onto the usb?23:07
Boscofsmithred: I downloaded it from a torrent and posted it there from the official torrent and the official link and in both cases I got a black screen23:09
fsmithredAfter you downloaded it, you had to do something to get it onto the usb.23:10
fsmithredHow did you do that? dd? ventoy? something else?23:10
Boscofsmithred: ventoy but, the netinstall 4 run well, but not the 5 one23:11
fsmithredIf you have a spare usb, use dd or cat to image that with the single iso.23:12
fsmithredIf you check on the forum, there might be instructions for getting that version to work on ventoy. I don't know wny details on that.23:13
Boscofsmithred: OK thanks23:14
fsmithredBut the bootloader on the daedalus isos is not the same as on chimaera.23:14
fsmithredBosco, do you get some kind of boot menu from ventoy before it goes black?23:14
Boscofsmithred: yes I have the graphical menu to choose one23:15
fsmithredok, so the computer is seeing the usb and letting it do its thing.23:16
fsmithredOnly other thing you could do is use one of the live isos, but those don't have the same installer.23:17
Boscofsmithred: Live's go well, no problems white these ones23:19
fsmithreddesktop-live will give you xfce as if you took the defaults on the installer isos.23:20
fsmithredbut you'll need to do apt update and apt upgrade after the install to get all the latest versions.23:21
fsmithredare you used to using the debian installer?23:21
gnarfaceBosco: if version 4 of the netinstaller works, you can just do a minimal install and update it to version 523:25
gnarfacethe desktop and stuff can be installed after just as easily23:26
Boscognarface: In fact that's what I did and it went well.23:28

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!