Just a regular Joe.

  • 0 Posts
  • 57 Comments
Joined 1 year ago
cake
Cake day: July 7th, 2023

help-circle



  • I have two apparmor profiles targeting shell scripts, which can run other programs. One is “audit” (permissive with logging) and the other is “safe” (enforcing).

    The safe profile still has a lot of read access, but not to any directories or files with secrets or private data. Write access is only to the paths and files it needs, and I regularly extend it.

    For a specific program that should have very restricted network access, I have some iptables (& ip6tables) rules that only apply to a particular gid, and I have a setgid wrapper script.

    Note: This is all better than nothing, but proper segregation would be better. Running things on separate PCs, VMs or even unpriviliged containers.


  • Temporal is MIT licensed and comes with multi-tenant security features and its durable execution model is solid and scalability is phenomenal. They upsell to the cloud offering and the default OSS auth plugin is intentionally limited (you might want to develop your own if you self-host). You’d probably only look at the Temporal UI when debugging.

    Windmill is very cool, but it is only suitable for trusted teams due to its security model. If you want to be able to develop scripts and workflows in the web browser and run them together with trusted colleagues, on a schedule etc., then windmill might just be for you!



  • https://opensource.stackexchange.com/questions/8367/is-the-term-open-source-a-trademark has a discussion about this.

    The short story is that the OSI failed to obtain a legal trademark in the US for the term “open source” (software), resulting in many opportunistic companies and individuals adopting the term popularized by the OSI (which was founded by Eric Raymond, Michael Tiemann and Bruce Perens).

    There was controversy at the time due to it being a business-friendly spin on the ideological “free software”, and I personally avoided using the term for many years as a result. Even without a trademark on the now generic term of Open Source, there is still value in the OSI brand and its stamp of approval on a license.

    Those who want to be crystal clear, should probably always say OSI Approved Open Source License.

    Now, I’m off to have a Nescafé Approved Coffee.






  • It is possible to wrap something like python into a single file, which is extracted (using standard shell tools) into a tmpdir at runtime.

    You might also consider languages that can compile to static binaries - something like nim (python like syntax), although you could also make use of nimscript. Imagine nimscript as your own extensible interpreter.

    Similarly, golang has some extensible scripting languages like https://github.com/traefik/yaegi - go has the advantage of easy cross compiling if you need to support different machine architectures.



  • Joe@discuss.tchncs.detoMemes@lemmy.mlGlory!
    link
    fedilink
    arrow-up
    13
    arrow-down
    43
    ·
    edit-2
    4 months ago

    It’s the Y chromosome that triggers them.

    edit: alleged/unpublished … she failed some gender verification tests of IBA that disqualified her there, but met the IOC’s criteria. It is what it is. They might keep or change the eligibility rules in the future, and that will continue to be IOC’s decision, much as it is IBA’s.






  • Joe@discuss.tchncs.detoMemes@lemmy.mlCapitalism and fascism
    link
    fedilink
    arrow-up
    1
    arrow-down
    3
    ·
    edit-2
    5 months ago

    The world economy is huge and growing, and the US economy is damn strong with a significant share of it. It also owns the world as far as raw military power and power projection goes. The US would absolutely use its huge military and economic advantages to keep its position as top dog if necessary. It is fine that the world’s economy is growing (inevitable after the devastation of ww2, which barely touched the US; also industrialization in countries like china), but it doesn’t mean the US is any weaker for it. And anyone who thinks the US won’t keep its rivals in check (no doubt leaving a trail of bloody corpses behind) has not been paying attention.


  • Joe@discuss.tchncs.detoMemes@lemmy.mlCapitalism and fascism
    link
    fedilink
    arrow-up
    1
    arrow-down
    3
    ·
    edit-2
    5 months ago

    There’s a lot of people pinning their hopes on the global south and the decline of the dollar. I just don’t see it, and it seems like wishful thinking. If there were a real risk to US supremecy, we’d see serious chaos unfold, setting them (edit: not the US) back significantly. The gloves are still on just now.

    The US chooses when and how to intervene. With Israel vs Iran, it was clear. With NATO, it is clear. With Ukraine, it is still wishy washy - Ukraine can’t lose, but it doesn’t need to win for the US’ strategic goal of a weakened russia to be met. One can easily argue that it helps. Russia and its allies will continue to shit stir in “minor” ways elsewhere as a result, distracting but not really hurting the US.