Skip to content

World

Topics from outside of this forum. Views and opinions represented here may not reflect those of this forum and its members.

A world of content at your fingertips…

Think of this as your global discovery feed. It brings together interesting discussions from across the web and other communities, all in one place.

While you can browse what's trending now, the best way to use this feed is to make it your own. By creating an account, you can follow specific creators and topics to filter out the noise and see only what matters to you.

Ready to dive in? Create an account to start following others, get notified when people reply to you, and save your favorite finds.

Register Login
  • UsulU

    I'm tryin ponos instead of linkedin first, I posted this it's probably missing my resume now that I think of it.


    @usul Oui je me perds un peu je crois
  • UsulU

    For one of my blogs, I use dotclear, and wrote in french, notes when I did the installation at https://ludovic.hirlimann.net/2023/04/installer-dotclear-sur-freebsd-13.html

    #freebsd #dotclear


  • UsulU

    https://ludovic.hirlimann.net/2024/05/giving-nomadbsd-spin.html

    I was unable to have it work on my latest work laptop, but I'll retry cause it was nice with the newer 15.1 based release.

    #nomadbsd


  • UsulU

    Would it make sense to have a job section?

    Ludo


  • grahamperrinG

    https://nextbsd.org/

    https://www.reddit.com/r/BSD/comments/1u5qk0n/nextbsd_the_bsd_of_the_21st_century/

    https://www.reddit.com/r/freebsd/comments/1u5qkds/nextbsd_the_bsd_of_the_21st_century/

    … My main focus has been getting all the issues fixed with Gershwin Desktop so I can make an image include that + more kexts ASAP. Wifi kexts load but I need to port some 80211 stuff to integrate wifi into configd, etc. More to come. …

    …

    Mach IPC, launchd (replaces /sbin/init), configd/IPconfiguration (replaces netif), IOkit (replaces devmatch, devd). Resulting in automatic graphics detection, automatic networking with state change handling, service supervision, parallel startup to name a few things. I have other ideas beyond Darwin components like porting smb3 from illumos that I have been brewing about for a long time. New frameworks for jails, bhyve. The equivalent of dockerhub for jails. Management tools comparable to this https://www.hexbsd.org (an earlier creation of mine). A revived NAS appliance. A Gershwin on NextBSD image (desktop appliance).

    For people who are new to all of this:

    9febc628-3c7a-447a-844c-8ec2ef6f896e-image.jpeg


    NextBSD goal, mission and visions · nextbsd-redux · Discussion #406 The first of Joe's responses was last week. Two highlights: … one person's trash is another persons treasure. … – and: Download Server (The preview you see today, with after the superset finishes a few more touches like pkg hook to create LaunchDaemons) Download App (Cross platform management app) Download Desktop (Gershwin) I think that when these key things roll out more, is how it will better align with the rally cry. That said I've wanted to do some research excursions and deviations out of interest here and there … August 15 2026 - Linux compat work, ARM64 ISO lands, and KMS drivers for virtualization (WIP) … I want virtualization on Apple silicon to work better than any other BSD starting with UTM as a first target via QEMU and the native hypervisor working as a follow up stretch goal if it can be done. …
  • grahamperrinG

    https://littlefedi.org/

    a small ActivityPub server written in Go. It ships as a single static executable with a server-rendered web interface, a Mastodon-compatible client API, a durable federation queue, moderation tools, and optional PostgreSQL and S3 support. No runtime to install, no services to wire together.

    Via https://littleone.littlefedi.social/@stefano/08d20839-b21b-47bc-a1b6-800d1137f36e | https://mastodon.bsd.cafe/@stefano@littleone.littlefedi.social/117076101948770274 @stefano@littleone.littlefedi.social


  • CiotBSDC

    (06/10)

    ⇒ A Final Return for OpenBSD Anti-Return-Oriented Programming Mitigations

    Return-Oriented Programming (ROP) continues to be a serious attack taking advantage of flaws in memory unsafe languages, particularly buffer overflows, to launch arbitrary code execution attacks by chaining together pieces of already existing code in loaded binaries and shared libraries, called gadgets. With the continued reliance on x86_64 CPUs in cloud and personal servers, mitigations that can meaningfully reduce the success of ROP attacks without significant overhead continue to be attractive. We propose the porting of one such software-based anti-ROP mitigation proposed by OpenBSD: compile-time instruction rewriting to avoid opportunities for ROP exploitation. We bring this mitigation, originally developed for the custom OpenBSD implementation of the LLVM compiler suite, to GCC by way of a standalone utility that sits in between the compiler and the assembler and rewrites potential gadget instructions before assembly into object code. Our utility provides a minimal reduction in gadgets with some penalties in binary sizes and performance impacts. We compare our GCC-ported standalone utility to the original OpenBSD LLVM mitigation and discovered that our standalone utility is weaker compared to the original LLVM-based mitigation. However, due to the overall weak reduction in gadgets for both the LLVM-based and GCC-based implementations, we conclude that seemingly obvious mitigations may prove to be anything but, and caution providing security improvements without significant testing and evaluation.


    ping: https://bsd.network/@bcallah/116725877009964245


    It seems to be my 200th post here… 😉


    26/08/11 ⇒ Cleaning costs, or, examining the OpenBSD -fret-clean flag I start with apologies to williewillus, calvin, and reezer on Lobste.rs. Prior to July 9, I would have agreed with you all. But it appears I was wrong. There is no need to further engage; it is clear that critique-from-within is undesirable. Which is perfectly OK, because I stepped away from being on the inside. So let's just keep evaluating OpenBSD's mitigations and we'll continue to learn interesting things along the way. https://briancallahan.net/blog/20260811.html
  • R

    A semi-active web forum for DOS users and developers


    Always great to see active DOS communities!
  • CiotBSDC

    26/08/03

    ⇒ Show memory information on OpenBSD

    Finding memory information and usage on OpenBSD requires a few commands and the right places to look. If you are used to Linux, then commands like free are no longer available. Let’s have a look at memory details on OpenBSD.


    26/08/05

    ⇒ Running your own mail server with OpenBSD and OpenSMTPD

    Self-hosting your own services such as a blog, website, or email is a valuable skill. It gives you a better understanding in the technology and usually also fun to do. With privacy under pressure and Big Tech continuing to store our data, this might be a good time to host your own mail server.


  • ptribbleP

    Tribblix and OmniTribblix m41 released

    http://tribblix.org/download.html

    This doesn't have any significant breaking changes on the application side, just a lot of normal version updates, but does pick up the handful of illumos CVEs we've had recently.


  • D

    No idea what happened to that tomato, but it grew into the FreeBSD logo.


    Hey, thanks! Now I know to keep them cooler.
  • CiotBSDC

    Setup a simple web server with bozohttpd on NetBSD.


  • UsulU

    If not any idea how much work that would represent?


    NomadBSD based on FreeBSD 15.1-RELEASE from @pfriedma@pfedi.pfriedma.org : r/NomadBSD cross-posted to r/freebsd.
  • Y

    Gentlefolk,

    I am trying to set up a wireguard client inside a Bastille jail - both the host and the jail are on FreeBSD 15.1.

    I have encountered an error (SIOCIFCREATE2 (wg0): Invalid argument) when I try to bring up the interface.

    Apparently this is because, while the host system has access to the kernel module that enables wireguard, the jail does not.

    After a bit of research, it seems that the way to handle this is to put the declaration
    if_wg_load="YES"
    into /boot/loader.conf, or perhaps into a file inside /boot/loader.conf.d.

    However, Bastille sets up /boot as a read-only filesystem.

    Hence the only way I can see to fix this is to edit the fstab for this jail and change the flags for /boot to rw from ro, restart the jail, edit the necessary files, and then go back out to the host and reset the flags in fstab.

    Now, call me an optimist, but I suspect the good folks behind Bastille will already have seen this problem and worked out a less awkward solution - I just can't find it anywhere. Am I missing something?

    Many thanks as ever,

    ---WBTD.


    ...and it was an idiot error. I had to enable wg in the host kernel. I knew it was built into the kernel these days...I just hadn't realised I needed to enable it. -->facepalm<--
  • CiotBSDC

    26/08/01 ⇒ MidnightBSD 4.0.7 RELEASE MidnightBSD 4.0.7 RELEASE is uploading right now. It contains a number of security updates and is recommended for all users. https://bsdsec.net/articles/midnightbsd-security-midnightbsd-4-0-7-release
  • grahamperrinG

    @grahamperrin Optimus is a trademark of NVIDIA for their implementation of hybrid graphics.And other manufacturers like AMD calls almost the same thing differently.From the CPU-side of the view, PRIME is the underlying interface for iGPU and dGPU (not limited with NVIDIA) to offload heavy graphics tasks to mighty dGPU, mainly using efficient (but poor in performance) iGPU.Before Austin's port of nvidia-drm.ko appears, the only "working" way to achieve hybrid graphics was to use VirtualGL, with configuring individual "screen" for iGPU and dGPU respectively, and screen rendered by dGPU was needed to be transferred to another (for iGPU) with software BitBlt, as physical framebuffer cannot be shared with this method.And current implementation of nvidia-drm.ko relies on PRIME to work. Without PRIME, there's no way (arbitrations) for dGPU to access (part of) physical framebuffer of iGPU.See detailed and precise info by Austin here. https://badland.io/prime-configuration.md
  • UsulU

    I'm in my 50s, been using computers since the beginning or the 80s, been on the internet since the beginning of the 90s. I'm a computer professional, I've been

    • consultant
    • QA lead
    • SRE / Sysadmin
    • lately more support engineer.

    I have a thing for old Unix systems and workstations. I've been involved a lot into the Mozilla project and have been employee. I have a sweet spot for Apple ][s and old Unix workstation. I love SMP when it means more than one processor in the box.

    When I'm not toying with computer or spending time with the family, I like to read and I maintain a BookWyrm profile.
    I take pictures with a trusted Canon DSLR who's starting to show it's age. I post both on pixelfed and Flickr.
    I play historical miniatures war games, which means I build and paint minis.

    I'm present on two mastodon instances. And I 'maintain' 3 blogs. I've a love affair with various BSD since I got myself involved in OpenDarwin a few years back. My gaming blog runs on FreeBSD. I wish I'd run a BSD system on a daily basis but running a Fedora machine for work is complcated enough.

    Ludo


    @stefano Thank you.
  • UsulU

    There's usually booths and a room dedicated to BSD at Fosdem, seem interesting to me to add it, no?

    Ludo


  • grahamperrinG

    A follow-up to https://mastodon.bsd.cafe/@82mhz/117002938483503805 @82mhz

    The linked article (June 2026) began:

    The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). ..

    – 18–23 minutes, according to Firefox Reader.

    I used AI to get a concise timeline. The text below is taken from Claude's response.


    …

    The general practice: 2015

    The root of it all is Hola VPN / Luminati (Bright Data's predecessor). In May 2015, it was discovered that Hola — a free "VPN" — was quietly turning users' devices into paid exit nodes sold through a sibling brand, Luminati, at up to $20/GB. The discovery came after 8chan's admin, Frederick Brennan, traced a wave of DDoS/spam attacks against his site back to Hola users being abused as a botnet, and outlets like The Register, Fortune/Motherboard, and TechRadar covered it within days. Hola's Luminati brand was described as "the world's largest VPN network," routing HTTP, HTTPS, or TLS requests through millions of idling end-user devices. Luminati (founded 2014) was Hola's mechanism for selling access to its userbase as exit nodes, charging $20 per gigabyte for bandwidth from its free VPN users, and it later rebranded as Bright Data. So the general "your free app is secretly selling your connection as a proxy" pattern is a 2015 story, not a 2026 one.

    The smart-TV-specific angle: February 2026

    The TV angle specifically is much newer, and predates the IncludeSecurity teardown by about three and a half months. Independent tech journalist Janko Roettgers broke it in his Lowpass newsletter (syndicated by The Verge) in late February 2026: with Bright's SDK, a viewer's smart TV becomes part of a massive global proxy network that crawls and scrapes the web, alongside apps on desktop PCs and mobile devices, with the company claiming roughly 150 million such residential proxies worldwide, gathering data later resold to train AI models. Multiple later write-ups explicitly credit this as the origin point: "Lowpass, syndicated by The Verge, first surfaced the smart-TV angle in February, and this is the technical teardown."

    The AI-scraping tie-in and platform response: 2025–early 2026

    Around the same period, the broader AI-scraping-via-residential-proxy story was already building: Krebs reported in October 2025 on botnets like Aisuru fueling large-scale AI data harvesting, and Google dismantled the criminal IPIDEA proxy network in January 2026. By April 2026, FlatpanelsHD was reporting that Amazon, Google and Roku had restricted Bright Data and similar residential proxy networks from their app SDKs (Fire TV, Google TV, Roku OS), while Bright Data continued listing LG's webOS and Samsung's Tizen as partners, with over 200 apps on webOS alone.

    Your June 2026 post: the deep technical teardown

    The IncludeSecurity/Buchodi post you linked was the first to actually reverse-engineer the SDK rather than just report on the business model — documenting the peer channel's weak authentication and the iOS VPN bypass — which is why it got picked up so widely (Hacker News, Krebs, CyberSecurityNews, etc.) even though the underlying phenomenon was already known.

    Aftermath

    A follow-up Spur.us platform scan in June 2026 quantified the scale: Bright Data, Bright Data Ltd, and Bright SDK accounted for 367 proxy-flagged apps in their dataset, with residential proxy SDKs found in nearly half of scanned LG webOS apps and over a quarter of Samsung Tizen apps. And just last week, Krebs on Security reported LG moving to ban these SDKs from its smart TV apps entirely.

    So the short answer: the general practice (apps quietly monetizing users' devices as residential proxy exit nodes) was first exposed in 2015 with Hola/Luminati; the smart-TV-specific version of that story broke in February 2026 via Lowpass/The Verge; and your June 2026 link is the deep technical forensic follow-up, not the original discovery.


  • grahamperrinG

    @tomaoki

    Perhaps the title is difficult to perceive when, for example, the screen is busy.

    I had this difficulty more than once in the past.

    An example:

    407fd625-b6a2-44a6-a5d2-d75ec3807994-image.jpeg


    Here's the title: [image: 1785202914963-dad79b73-5dbc-4b83-ac05-c3326b52f602-image.jpeg] above the editing toolbar. The position is unexpected.