Monthly Shaarli
July, 2021
The national agency for the digitalization of the healthcare system in Germany will use Matrix as an instant messaging standard.

»While cynics are probably correct (for now) that we probably can't shut down every avenue for compromise, there's good reason to believe we can close down a vector for 0-interaction compromise. And we should try to do that.«
rpm-ostree is a hybrid image/package system allowing atomic upgrades/rollbacks.
»Learn how identifiable you are on the Internet.«
Among other improvements, mitmproxy now supports TLS-over-TLS, HTTP/2 - HTTP/1 interopatibility, and host header-based proxying.
With dynamic CPU scaling, the time a CPU took to complete a task and how much work the CPU did have to do, are two different things.

Microsoft introduces Windows 365, its virtual desktop product.

For data protected by the GDPR, encryption is not sufficient for processing data.
»Writing a SQLite clone from scratch in C.«

»Rustpad is an efficient and minimal open-source collaborative text editor based on the operational transformation algorithm.«

In this post, the author gives a short introduction to using virt-backup
for KVM backups.

TCP Fast Open allows the initial SYN packet to contain data. This post shows what practical challenges TFO is currently facing.
This paper is analyzing the geographical distribution of OSS contributions from GitHub.

This site and the related paper focuses on same-site attacks on the modern web through the takeover of insufficiently secured subdomains.
lnav
is a command-line log file viewer.
Rhit is an Nginx log analyzer.

Eternal Terminal (ET) is a remote shell that automatically reconnects. Inspired by autossh
and mosh
.
This article summarizes a size_t-to-int conversion vulnerability in Linux's files system layer exploited by creating, mounting, and deleting a deep directory structure.

This blog post gives insights into how Facebook migrated from MySQL 5.6 to 8.0.
Webserver on a calculator.

Like Proxmox VE, the new release of Proxmox Backup Server is based on the upcoming Debian Bullseye and includes Kernel 5.11 as well as ZFS 2.0.
Two-part blog series on installing SCO UNIX.

Percona finds that MySQL on ZFS is now on par with ext4 performance-wise for their test use case.

The Sovereign Cloud Stack (SCS) is the open-source base for the federated data infrastructure project Gaia-X.
»OpenVAS is a full-featured vulnerability scanner.«
Harvester is a bare metal HCI solution by SUSE.

This week, version 7 of the Proxmox Virtualization Environment landed. It is already based on the upcoming Debian 11, and among other improvements, it supports using BTRFS and Ceph version 16.2.
In his LISA21 talk, Brendan Gregg gives an overview and makes some predictions on server performance.
This blog post gives a brief introduction to the Border Gateway Protocol (BGP).
Post-Mortem über einen Incident mit dem Ceph-Cluster bei Uberspace, verursacht durch eine Spannungsschwankung.

In this blog post, the author introduces his custom build 25 Gbit/s Internet router.
»Internet-in-a-Box brings the power of a free Digital Library of Alexandria into the hands of any school, hospital, or community worldwide.«
In his talk, Evan Smith gives practical tips on how to become a kinder engineer.
The blog presents some practical Nginx features, e.g., rate-limiting, caching, and the split-client module.

»fd is a program to find entries in your filesystem. It is a simple, fast and user-friendly alternative to find. While it does not aim to support all of find's powerful functionality, it provides sensible (opinionated) defaults for a majority of use cases.«

»…roundtable for a dynamic and open discussion around the meaning and implications of the notion of European sovereignty in today's digital world.«
MITRE 2021 Common Weakness Enumeration (CWE) Top 25 list.
VGA PCI Pass-through KVM optimized for low latency and performance.
OpenSearch, Amazon's fork of Elasicsearch and Kibana, is now generally available.
Virtuozzo Linux is another alternative to RHEL/CentOS 8.4.

»A team at the Technische Universität Dresden has developed the first implementation of a complementary, vertical organic transistor technology.«
Poul-Henning Kamp on why it's time for governments to establish IT accident investigation boards.
XCP-ng is an open-souce Hypervisor based on XenServer.

Version 22 of Nextcloud Hub is now available. Some of the improvements: User-defined groups, integrated chat and task management, PDF document signing, and integrated knowledge management.
Dan Langille on upgrading jails with mkjail
without a jail manager being involved.
The author explains how Postgres out-of-memory situations are handled differently on cloud instances.

This podcast episode from The Changelog gives Insights into the release process of RabbitMQ and FreeBSD.
The Open Voice Network is a Voice assistance project funded by the Linux Foundation.

»A massive REvil ransomware attack affects multiple managed service providers and over a thousand of their customers through a reported Kaseya supply-chain attack.«
The Google Project Zero team explains how AMD-specific led to KVM virtual machine escape.