Shawn Webb is a user on bsd.network. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Shawn Webb @lattera@bsd.network

Pinned toot

I now have a new .onion email, now with webmail access. :)

shawn@3w2s7tpb5mc7ubsjjnzp4oxvqupjeoywzwdxfvfnjn3toqbuzgkn7kqd.onion

Note that this MTA can only send email to other .onion MTAs. It cannot send emails to clearnet addresses.

If you'd like your own .onion inbox, please message me over signal with your desired username.

Note that storage is very limited. I plan to increase storage within the next week or two.

Pinned toot

If anyone needs or wants to get a hold of me, I have a burner phone with installed. It sits behind my network. Feel free to contact me at any time over Signal.

+1 443-546-8752

My wife is going to have shoulder surgery in a few months. She'll be out of work for six months to a year.

Would filing a short-term disability claim have future ramifications? Thinking 20-30 years down the road when applying for term life insurance.

Shawn Webb boosted

We've got a new Tor Browser alpha, and we need your help to test it!

Tor Browser 8.0a9 has a lot of new features, including a couple major UX changes, and we want them to be in tip-top shape before the stable release hits this September. blog.torproject.org/new-releas

From a conversation at work: "Clouds: great for sharing. With people you want. And possibly, those you don't."

is not having a good day: archives.gentoo.org/gentoo-ann

"All Gentoo code hosted on github should for the moment be considered compromised."

Every time I'm forced to use , I realize how much SIGINFO spoils me.

Such a simple, yet powerful, feature. <comment type="troll">Which is probably why Linux doesn't bother implementing it.</comment>

Shawn Webb boosted

Now that I have a PoC working, I need to add some security mechanisms so that jailed environments can't create VM instances arbitrarily. I'll probably add a new jail parameter (allow.vmm=0).

And here we see running in in a jail.

bhyve on this HBSD laptop:

1. PIE for ASLR
2. Full RELRO
3. Capsicum
4. CFI
5. SafeStack
6. Jailed

Attempting to run in a jail: vm_create: Operation not permitted

:(

Interesting commit: "Could result in plaintext being output by 'encrypt' operation"

svnweb.freebsd.org/changeset/b

Goal for this weekend: set up a jail just for , since it violates PaX ASLR and PaX NOEXEC.

Even though this shows the flexibility and power of HardenedBSD, I'm still annoyed that I have to disable exploit mitigations due to the stupidity of others.

12-CURRENT/arm64 package repo updated.

And here we see the working flawlessly with on .

Hey @akpoff, do you know how FCC rules/laws apply to Native American reservations? Or can you point me in the right spot for learning that kind of stuff?

Hey @akpoff, are your slides for the amateur radio BoF available somewhere?

Prepping my laptop for a four-day SDR training at work that starts Monday.