libera/#devuan/ Monday, 2025-02-03

SkyforgerHaroldis anyone else having trouble connecting to the 0ad website and lobby server at wildfiregames.com ?06:05
freemSkyforgerHarold: pings passes, but website does not allows connection, neither in http nor in https. My guess: their httpd is dead. I do not know for the lobby, I don't play 0ad.06:07
freem(that probably should have been asked on their communication channels though)06:08
XenguySkyforgerHarold, wildfiregames.com resolves fine here06:09
freemto query lobby one could either know the port they use, or run nmap, but the latter may be illegal depending on the type of scan and countries involved06:11
freemwith the port one could ping, I mean.06:12
freembut if game fails at it, likely nothing would pass06:12
golinuxIsn't this off-topic? Please take it there.06:14
SkyforgerHaroldoops, I thought I was talking in #devuan_offtopic. Sorry!06:15
psionicWhat on earth happened to Kismet?09:58
psionicpackage just vanished or what09:58
rwppsionic, https://tracker.debian.org/pkg/kismet it appears to have been gone since 2020.10:07
metala@psionic interesting, it seems that the last one that has it as a package is buster. However, kismet are shipping their own Debian packages.10:08
metalaref. https://www.kismetwireless.net/packages/#debian-bookworm10:10
psionic kismet-capture-hak5-wifi-coconut : Depends: libwebsockets16 but it is not installable11:41
psionicah man this is gonna be painful11:41
psionictons of unmet deps for kismet11:41
psionicits gonna be easier if i install some hodge podge like kali linux in a docker and give it direct access to wlan013:33
AlverstoneDid you know that without polkit, elogind cannot switch tty for you?19:02
AlverstoneFor that matter, for some reason, by default, seatd only allows root to use the socket. Why is that? Are there any security implications in allowing users to access seatd?19:02
gnarfaceAlverstone: i think those are both expected functionality, but on daedalus you can still just disable seatd if you are using startx instead. you'll see complaints in the xorg log but it'll still work19:11
freemI suppose there are security implications for multi-user systems?19:19
gnarfacewell, running any graphical login daemon necessitates using permissions backends that are inherently less secure than doing without19:21
rwpWhat multi-user systems run X?  And why would they?19:21
freemas in, systems which have multiple accounts, not systems on which multiple users use the same account (i.e. family computers in my childhood, when 1 computer *and* account was used by all)19:21
gnarfacebut to a lesser degree just running X at all is also a security hazard...19:21
freemis it a network security hazard, or a physical one?19:21
rwpFor the most part by now after these decades X is understood but the concern is that there may still be unknown problems lurking there somewhere.19:22
gnarfaceeh, i think local access risks only probably, as long as you're not using nvidia drivers19:22
gnarfacebut if you have users using untrustworthy software all bets are off anyway...19:23
freemI am more concerned by wayland not implementing enough features in a standard/generalised enough way than by X11 "security problems"19:23
freemI would be curious to learn about a way in which X11 was actually usable to trigger real damages, that wayland would have prevented19:24
freemthe most important part of a disk $HOME and I don't see how wayland can protect that19:24
freems/disk/systems/19:25
rwpI am unaware of any actual attacks that wayland would have protected against but that X would have allowed.  When I read wayland articles talking smack about X they always seem to be things that no reasonable person is actually doing.19:27
gnarfaceyea, i don't either really. you don't want to be in any situation where the video card drivers are the only line of defense between users reading other users' passwords19:27
freemI believe wayland can have a performance benefit, though, since it's designed for modern harware... but then it also have, in some negligible areas, performance degradations: https://mort.coffee/home/wayland-input-latency/19:27
freemI also have a long list of bugs created in, say, SDL2, for supporting wayland19:28
freemso, wayland? To me it's nayland19:28
freemI see no benefit for my cheap hardware, really19:28
freemsecurity is how you sell bullshit to naive people19:28
freemand performance benefits... they have the mouse cursor lagging, in some conditions, in some servers (because no standard ofc) on some places. Compared to the old, slow protocol.19:29
freemI would be very curious to learn about practical and neutral analysis of performances and security, for those who dare to not junk their electronics because fashion says so19:32
Alverstone...19:47
AlverstoneThe question was, why exactly seatd chooses to be root-only by default? Is there any particular reason why access to seatd should be denied?19:47
AlverstoneA wild guess - seatd does not have the concept of active sessions, so it seizes and releases devices only in cooperation with software that uses it, so if some software grabs your input devices you'll be screwed tight. But I have absolutely no idea how it *actually* works19:49
AlverstoneI combine elogind and seatd at the same time. No real reason, but it seems I don't have this bug with X going blank with seatd, while just not so long ago I experienced such "crash" with a elogind user19:50
* Xenguy checked and seatd is not installed here ...20:46
fsmithredMaybe I don't understand correctly, but I can switch tty just fine without polkit. But maybe that's because I don't have elogind or dbus or a display manager on this build. Just seatd.22:14
fsmithredctrl-alt-Fn works22:15
leitzI have a laptop with an internal wifi, but I want to test a USB wifi adapter. How do I use the adapter?22:16
fsmithredleitz, if network-manager is installed, I think you just select that as the interface for it to use.22:19
fsmithredAssuming the firmware for it is installed. Do you know if it is or not?22:19
fsmithreddoes it show up if you run 'lspci'?22:20
leitzfsmithred, it shows up under lsusb, so it should be good.22:20
fsmithredwhat is it?22:21
fsmithredatheros, realtek, intel, broadcom?22:21
fsmithredmaybe a model number?22:21
leitzRalink mt7601u, and I'm not seeing any way to "select" it. The top bar has the wifi, and lets me choose networks, but not the devices.22:24
fsmithredright-click or left-click should have 'edit connections'22:25
fsmithredand I think you can add one there22:25
fsmithredmake sure firmware-realtek is installed (assuming this is daedalus)22:25
leitzChimera, and firmware-realtek is installed22:29
fsmithredok, it's the same package in chimaera. There used to be a separate one for ralink.22:30
fsmithredok, I just tried this on a laptop, and 'Edit connections' is not the right place. That's for adding a different wireless connection, not wireless device.22:32
leitzI think I've gotten it going.22:35
leitzWell, I used a different wifi adapter, an actual Realtek.  :)22:35
fsmithredand I'm already connected on the wireless device without doing anything. I must have used it before on this laptop.22:35
leitzYeah, I found how to add it, but when I try to connect, even given the new MAC address, it goes to the internal wifi.22:41
fsmithredmaybe you can turn it off with network-manager or else with rfkill in a terminal22:44
fsmithredyou should be able to disconnect the interneal in n-m22:44
fsmithredleft-click on the icon and it should say Disconnect under any active connection22:45
leitzI need to look at it after a decent break. It's a "plug and play for linux" that's taken up much of the afternoon. It doesn't work on another Linux varient either.  :(22:47
Alverstonefsmithred, correct, seatd works.22:47
AlverstoneBut elogind want polkit22:48
Alverstonewhy? wish I knew22:48
AlverstoneThis design is really strange. Why do they need to outsource authentication to another process? Elogind already knows whether the session is active or not, and it runs as root. Why does it need polkit at all? Maybe I don't want to know at all22:49
fsmithredunderstanding polkit is above my paygrade23:06
Alverstonefsmithred, I don't blame you. Future is only known to titans that create it, eh? On the topic, do you know which implication might turn up if I make seatd socket world writable?23:07
fsmithredno I don't, but my gut says it would be bad23:08
Alverstone:(23:08
Alverstonewhich solution you applied?23:09
fsmithredfor what?23:09
Alverstonefor seatd socket!23:09
fsmithredI can't recall a problem to solve with it.23:09
fsmithredmy "solution" for that particular build is to pin dbus to -1 priority23:10
fsmithredit's a fairly comprehensive software filter.23:10
fsmithredor malware filter, depending on your view23:11
Alverstonefsmithred, stat -c '%U:%G' /run/seatd.sock23:11
fsmithredI have to reboot a usb stick on a laptop to do that. Take me a couple minutes.23:11
fsmithredroot:video23:17
rrqAlverstone: it's fine to make the seatd socket world accessible; no reason not to really, unless you do want to separate users who can access it from users who can't.23:18
rrqthe "credentials" for vt control is with /dev/ttyN ownership23:19
rrqand seatd (like elogind) use that for device node access permission23:20
Alverstonefsmithred, thank you, understoon23:25
Alverstoneunderstood*23:26
Alverstonerrq, does seatd check which tty is currently active?23:28
rrqyes23:29
Alverstoneso if a process on another tty tried to request access to input devices, it gets rejected?23:30
rrqyes23:33
rrqthere's a bit of code in Xorg & seatd handle VT transitions (leave + enter)23:34
Alverstonethank you23:35

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!