kuijsten
bonked
original: Roelmaalderink@mastodon.social
Stand back... I'm going to write some code.
kuijsten
bonked
original: Roelmaalderink@mastodon.social
kuijsten
bonked
original: Roelmaalderink@mastodon.social
kuijsten
bonked
original: OpenBSDAms@mastodon.bsd.cafe
Ori Bernstein - GEFS: The File Shredder of the Future. https://exquisite.tube/w/3QQimMdswWJxrsPaJtak2u \o/
kuijsten
bonked
original: lattera@bsd.network
Reverse engineered #Stuxnet from 2010 samples released on GitHub: https://github.com/Sadpainy/Stuxnet I have mirrored it on #Radicle :
rad:z27MwjFvi6GvAPKX5tPeJPuvETYpR
Just released filter-dmarc v0.3.0. It now supports non-UTF-8 mail bodies and does stricter filter protocol parsing. If you are interested in #DMARC with #OpenSMTPD you should definitely give it a try. https://netsend.nl/opensmtpd-filter-dmarc/ TODO:
Currently on OpenBSD "stdio rpath inet" is pledged and everything, that is DMARC, DKIM and SPF verification including DNS resolving, is done by Stalwart's mail-auth (written in Rust). I want to only pledge "stdio" to this huge amount of Rust code and do DNS resolving using OpenBSD native asr(3) in a separate process.
I'm happy to share my #DMARC filter for #OpenSMTPD with a wider audience. I've been running it for several weeks myself and so far DMARC is being enforced successfully while no legitimate mail has been blocked. This is just a thin wrapper around @stalwartlabs's DMARC, DKIM and SPF implementations. It supports an
--spf-only-domains argument so that you can easily bypass DMARC for mailing lists like openbsd.org or lists.openwall.com.
Just released an update to my spf and spamtrap filters for #OpenSMTPD. If you are using them on a listener with auth enabled (i.e. Fixed in filter-spf v1.0.2 and filter-spamtrap v1.0.0, both released today.
listen on ... auth filter spf) you should update immediately because otherwise an attacker can bypass the filter.
kuijsten
honked back
in reply to: https://exquisite.social/users/mischa/statuses/117086601866046112
@mischa i know i know, but i don't think it ever (or at least not up till a couple of years ago) really had the blessing of Martijn for production. You have production experience with it? I mean, I'm not in a hurry, my Go version is working well as well :)
kuijsten
honked back
in reply to: https://exquisite.social/users/mischa/statuses/117081466720098905
@mischa no filter-spf is mine, written in Go: https://netsend.nl/opensmtpd-filter-spf/ based on some skeleton from Gilles :)
Just released a fix for #OpenSMTPD filter-spf on OpenBSD 7.9. Apparently pledge dns needs to be accompanied with rpath /etc/resolv.conf.
In case you like to do DNS lookups using #Go on #OpenBSD with pledge you have to set I.e. to make my honk resolve hostnames again without recompiling I have set the following:
GODEBUG=netdns=cgo or compile using go build -tags netcgo ...$ cat /etc/login.conf.d/honk
honk:\
:setenv=GODEBUG=netdns=cgo:\
:tc=daemon:
Happy to see symon v2.91 is released and available in #openbsd current! 🎉 mbuf: smart:
- model after systat(1) mbufs
- add missing cluster mcl2k2
- big performance improvements
- stricter sysctl error handling
- remove ifdef KERN_MBSTAT (defined since OpenBSD 3.2)
- support running unpriviledged
- support disklabel UIDs using opendev(3)
- use xreallocarray instead of xrealloc
- stricter ioctl error checkpkg_add symon symux
kuijsten
bonked
original: openbsdjournal@mastodon.social
Call for testing: OpenBSD vmm(4)/vmd(8) fd-ification #openbsd
https://undeadly.org/cgi?action=article;sid=20260804054218
kuijsten
bonked
original: damienmiller@hachyderm.io
A few people have asked me recently about how OpenSSH sshd implements privilege separation after the changes of the last couple of years, such as splitting sshd into multiple binaries. I finally got around to writing it up - please take a look if you're curious. https://github.com/openssh/openssh-portable/blob/master/README.privsep
@damienmiller is there a place I can read or watch about the rationale of openssh replacing sntrup761x25519-sha51 with mlkem768x25519-sha256 as the default kem?
kuijsten
bonked
original: libreleah@mas.to
update regarding my librewolf port for OpenBSD: it works perfectly. i screwed up the branding, so the menu icons (e.g. lxqt menu) say firefox. easy fix (just have to enable librewolf branding in the build process; accidentally removed it earlier) https://codeberg.org/vimuser/librewolf-openbsd-port will update for openbsd 7.9 soon (current package is 7.8) and then also for CURRENT. debating whether or not to maintain a temporary package repo, until openbsd merges it. i plan on sending to the openbsd ports team for review.
kuijsten
bonked
original: eanakashima@hachyderm.io
My greatest professional accomplishment of the year: I got my exec & manager teammates saying "point positive," a term from whitewater rafting and kayaking. Meaning: when facing hazards, point people toward where to go/what to do, rather than drawing attention to everything to avoid.