Weekly Shaarli
Week 15 (April 12, 2021)
In-depth comparison of files, archives, and directories.
Only some of the highlights:
- ZFS now provided by OpenZFS
- in-kernel framing and encryption of TLS
- arm64 is promoted to Tier-1 status
- rewritten routing stack
- clang, lld, llvm, libc++ update to 11.0.1
- bhyve improvements
- removed obsolete GDB
In this statement, the DNS root server operators explain why they don't feel comfortable being the early adopters of authoritative DNS encryption.

Element Matrix Services is now bridging to Microsoft Teams.

The article demonstrates with practical examples how insufficient user input validation leads to code execution vulnerabilities.
Interesting read about the shortcomings of using fail-fast for achieving fault tolerance in modern distributed systems.
Blog post on how Nix can help to solve DevOps problems.
»BleedingTooth is a set of zero-click vulnerabilities in the Linux Bluetooth subsystem that can allow an unauthenticated remote attacker in short distance to execute arbitrary code with kernel privileges on vulnerable devices.«
With the free support ending for Qt5, KDE is now maintaining security and functional fixes for it.
Page with a comprehensive list of various text to diagram tools.
Version 12 of the LLVM compiler toolchain was released.

The FBI actively removes backdoors from the hacked Microsoft Exchange servers.
»Dell Technologies to Spin-off 81% Equity Ownership of VMware.«
In this multi-part article, the author covers access methods to multi-screen spice consoles.
In this post, the author shows that replacing C/C++ with safer languages is not an all-or-nothing task and suggests prioritizing systematically.
New release of OSBuild, the project providing tools for building operating system images.
»Tahoe-LAFS is a Free and Open decentralized cloud storage system.«
»The DebOps project is a set of Free and Open Source tools that let users bootstrap and manage an IT infrastructure based on Debian or Ubuntu operating systems.«

Yes, running unsupported, unpatched servers on the Internet is a bad idea.

Article about Microsofts first production-environment deployment of two-phase liquid immersion cooling in a data center.

»Upptime is the open-source uptime monitor and status page, powered entirely by GitHub Actions and Issues.«
The Epic Games Reliability Engineering team did a post-mortem on a certificate expiration issue they recently experienced.

The short instructions on this post show how to set the Permissions-Policy: interest-cohort=()
header in popular HTTP/S servers.
The Codecov supply chain hack gets investigated.
»Some of you have noticed the past few weeks and months that
a serious attempt to bring a second language to the kernel was
being forged. We are finally here, with an RFC that adds support
for Rust to the Linux kernel.«
This short post explains why, strictly speaking, the term DNS propagation is misused.

Post by Percona about different multi-master replication solutions for Postgres.

Pointed comment by Corey Quinn on why the operating system does not matter that much anymore.