home.social

#hardening — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hardening, aggregated by home.social.

fetched live
  1. 🤖🔧 Behold the thrilling saga of #C++26 "hardening" experiments: where programmers #debate if wrapping your #code in Kevlar will actually prevent #runtime #bugs, or just make it uncomfortable. 🥱🔒 Witness the riveting "real-world" examples that could potentially save you milliseconds, assuming you haven't fallen asleep first. 📚💤
    cppstories.com/2026/hardening- #Hardening #Programming #Optimization #HackerNews #ngated

  2. 🤖🔧 Behold the thrilling saga of #C++26 "hardening" experiments: where programmers #debate if wrapping your #code in Kevlar will actually prevent #runtime #bugs, or just make it uncomfortable. 🥱🔒 Witness the riveting "real-world" examples that could potentially save you milliseconds, assuming you haven't fallen asleep first. 📚💤
    cppstories.com/2026/hardening- #Hardening #Programming #Optimization #HackerNews #ngated

  3. 🤖🔧 Behold the thrilling saga of #C++26 "hardening" experiments: where programmers #debate if wrapping your #code in Kevlar will actually prevent #runtime #bugs, or just make it uncomfortable. 🥱🔒 Witness the riveting "real-world" examples that could potentially save you milliseconds, assuming you haven't fallen asleep first. 📚💤
    cppstories.com/2026/hardening- #Hardening #Programming #Optimization #HackerNews #ngated

  4. 🤖🔧 Behold the thrilling saga of #C++26 "hardening" experiments: where programmers #debate if wrapping your #code in Kevlar will actually prevent #runtime #bugs, or just make it uncomfortable. 🥱🔒 Witness the riveting "real-world" examples that could potentially save you milliseconds, assuming you haven't fallen asleep first. 📚💤
    cppstories.com/2026/hardening- #Hardening #Programming #Optimization #HackerNews #ngated

  5. 🤖🔧 Behold the thrilling saga of #C++26 "hardening" experiments: where programmers #debate if wrapping your #code in Kevlar will actually prevent #runtime #bugs, or just make it uncomfortable. 🥱🔒 Witness the riveting "real-world" examples that could potentially save you milliseconds, assuming you haven't fallen asleep first. 📚💤
    cppstories.com/2026/hardening- #Hardening #Programming #Optimization #HackerNews #ngated

  6. Audit active OpenSSH runtime settings via `sshd -T`. Extract effective ciphers, MACs, KEX algorithms, and root login flags to harden Enterprise Linux hosts. #ssh #hardening #ValtersIT

    valtersit.com/vault/ssh-config

  7. Audit active OpenSSH runtime settings via `sshd -T`. Extract effective ciphers, MACs, KEX algorithms, and root login flags to harden Enterprise Linux hosts. #ssh #hardening #ValtersIT

    valtersit.com/vault/ssh-config

  8. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

    #email #mail #css #hacking #exfiltration #security #hardening #software #hack

  9. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

  10. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

    #email #mail #css #hacking #exfiltration #security #hardening #software #hack

  11. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

    #email #mail #css #hacking #exfiltration #security #hardening #software #hack

  12. Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!

    Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.

    github.com/nekromoff/mailove

    #email #mail #css #hacking #exfiltration #security #hardening #software #hack

  13. ECH aktivieren: Encrypted Client Hello in nginx mit OpenSSL 4.0, sechs Domains und ein gemeinsamer Deckname

    Der Servername im TLS-Handshake bleibt für jeden Netzwerkbeobachter sichtbar, selbst wenn DNS-Anfragen längst verschlüsselt laufen. Mit OpenSSL 4.0 und einem gemeinsamen Deckname über mehrere unabhängige Domains hinweg lässt sich das schließen, wenn eine Entscheidung nicht falsch getroffen wird: der öffentliche Name.

    kernel-error.de/2026/08/17/enc

  14. ECH aktivieren: Encrypted Client Hello in nginx mit OpenSSL 4.0, sechs Domains und ein gemeinsamer Deckname

    Der Servername im TLS-Handshake bleibt für jeden Netzwerkbeobachter sichtbar, selbst wenn DNS-Anfragen längst verschlüsselt laufen. Mit OpenSSL 4.0 und einem gemeinsamen Deckname über mehrere unabhängige Domains hinweg lässt sich das schließen, wenn eine Entscheidung nicht falsch getroffen wird: der öffentliche Name.

    kernel-error.de/2026/08/17/enc

  15. ECH aktivieren: Encrypted Client Hello in nginx mit OpenSSL 4.0, sechs Domains und ein gemeinsamer Deckname

    Der Servername im TLS-Handshake bleibt für jeden Netzwerkbeobachter sichtbar, selbst wenn DNS-Anfragen längst verschlüsselt laufen. Mit OpenSSL 4.0 und einem gemeinsamen Deckname über mehrere unabhängige Domains hinweg lässt sich das schließen, wenn eine Entscheidung nicht falsch getroffen wird: der öffentliche Name.

    kernel-error.de/2026/08/17/enc

  16. ECH aktivieren: Encrypted Client Hello in nginx mit OpenSSL 4.0, sechs Domains und ein gemeinsamer Deckname

    Der Servername im TLS-Handshake bleibt für jeden Netzwerkbeobachter sichtbar, selbst wenn DNS-Anfragen längst verschlüsselt laufen. Mit OpenSSL 4.0 und einem gemeinsamen Deckname über mehrere unabhängige Domains hinweg lässt sich das schließen, wenn eine Entscheidung nicht falsch getroffen wird: der öffentliche Name.

    kernel-error.de/2026/08/17/enc

  17. OpenPGP-Karte eingerichtet: Curve 25519 scheitert am Kartenlimit, die Unterschlüssel landen trotzdem in Hardware

    Kann eine OpenPGP-Karte den Primärschlüssel aus dem Ed25519-Beitrag offline vorhalten? Kurz: nein, es fehlt der Zertifizierungsslot dafür. Aber sie bindet die drei täglich genutzten Unterschlüssel hardwaregebunden, inklusive Kartenlimit bei Curve 25519 und einem gemessenen PIN-Timeout am Pinpad.

    kernel-error.de/2026/08/16/ope

  18. OpenPGP-Karte eingerichtet: Curve 25519 scheitert am Kartenlimit, die Unterschlüssel landen trotzdem in Hardware

    Kann eine OpenPGP-Karte den Primärschlüssel aus dem Ed25519-Beitrag offline vorhalten? Kurz: nein, es fehlt der Zertifizierungsslot dafür. Aber sie bindet die drei täglich genutzten Unterschlüssel hardwaregebunden, inklusive Kartenlimit bei Curve 25519 und einem gemessenen PIN-Timeout am Pinpad.

    kernel-error.de/2026/08/16/ope

  19. OpenPGP-Karte eingerichtet: Curve 25519 scheitert am Kartenlimit, die Unterschlüssel landen trotzdem in Hardware

    Kann eine OpenPGP-Karte den Primärschlüssel aus dem Ed25519-Beitrag offline vorhalten? Kurz: nein, es fehlt der Zertifizierungsslot dafür. Aber sie bindet die drei täglich genutzten Unterschlüssel hardwaregebunden, inklusive Kartenlimit bei Curve 25519 und einem gemessenen PIN-Timeout am Pinpad.

    kernel-error.de/2026/08/16/ope

  20. OpenPGP-Karte eingerichtet: Curve 25519 scheitert am Kartenlimit, die Unterschlüssel landen trotzdem in Hardware

    Kann eine OpenPGP-Karte den Primärschlüssel aus dem Ed25519-Beitrag offline vorhalten? Kurz: nein, es fehlt der Zertifizierungsslot dafür. Aber sie bindet die drei täglich genutzten Unterschlüssel hardwaregebunden, inklusive Kartenlimit bei Curve 25519 und einem gemessenen PIN-Timeout am Pinpad.

    kernel-error.de/2026/08/16/ope

  21. systemd is now 16 years old - and still I dislike it and everything around it. Heavily.

    Recent events forced me to dig waaay deeper into it than I wanted to.

    To make this story short:

    `systemd-analyze security [name].service` is a neat tool which has shown me quite a bit of effort there is in systemd (and yes, I still dislike all of it!)

    And one shouldn't set `ProtectHome=true` and try to start a service in ~/[service].

    Of course, if the error had been something different than `203/EXEC` I probably wouldn't have had this "wonderful" journey...

    (perhaps this helps somebody someone. Most presumably via some AI.....)

    #linux #systemd #hardening

  22. systemd is now 16 years old - and still I dislike it and everything around it. Heavily.

    Recent events forced me to dig waaay deeper into it than I wanted to.

    To make this story short:

    `systemd-analyze security [name].service` is a neat tool which has shown me quite a bit of effort there is in systemd (and yes, I still dislike all of it!)

    And one shouldn't set `ProtectHome=true` and try to start a service in ~/[service].

    Of course, if the error had been something different than `203/EXEC` I probably wouldn't have had this "wonderful" journey...

    (perhaps this helps somebody someone. Most presumably via some AI.....)

    #linux #systemd #hardening

  23. systemd is now 16 years old - and still I dislike it and everything around it. Heavily.

    Recent events forced me to dig waaay deeper into it than I wanted to.

    To make this story short:

    `systemd-analyze security [name].service` is a neat tool which has shown me quite a bit of effort there is in systemd (and yes, I still dislike all of it!)

    And one shouldn't set `ProtectHome=true` and try to start a service in ~/[service].

    Of course, if the error had been something different than `203/EXEC` I probably wouldn't have had this "wonderful" journey...

    (perhaps this helps somebody someone. Most presumably via some AI.....)

    #linux #systemd #hardening

  24. systemd is now 16 years old - and still I dislike it and everything around it. Heavily.

    Recent events forced me to dig waaay deeper into it than I wanted to.

    To make this story short:

    `systemd-analyze security [name].service` is a neat tool which has shown me quite a bit of effort there is in systemd (and yes, I still dislike all of it!)

    And one shouldn't set `ProtectHome=true` and try to start a service in ~/[service].

    Of course, if the error had been something different than `203/EXEC` I probably wouldn't have had this "wonderful" journey...

    (perhaps this helps somebody someone. Most presumably via some AI.....)

    #linux #systemd #hardening

  25. systemd is now 16 years old - and still I dislike it and everything around it. Heavily.

    Recent events forced me to dig waaay deeper into it than I wanted to.

    To make this story short:

    `systemd-analyze security [name].service` is a neat tool which has shown me quite a bit of effort there is in systemd (and yes, I still dislike all of it!)

    And one shouldn't set `ProtectHome=true` and try to start a service in ~/[service].

    Of course, if the error had been something different than `203/EXEC` I probably wouldn't have had this "wonderful" journey...

    (perhaps this helps somebody someone. Most presumably via some AI.....)

    #linux #systemd #hardening

  26. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  27. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  28. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  29. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  30. Neunzehn Sekunden für einen Schlüssel: was der TPM-Chip unter Linux wirklich kann

    Ein Infineon SLB 9670 im Notebook, tpm2-tools 5.6 und die Frage, was der Chip wirklich bringt. Von der Suche im sysfs über ein versiegeltes Geheimnis und einen SSH-Schlüssel ohne Datei bis zur Fernattestierung, mit gemessenen Zahlen und den Angriffen, die es wirklich gibt. Dazu die Geschichte vom Fritz-Chip und den Patenten von 2001.

    kernel-error.de/2026/08/10/tpm

  31. "This Quarter in KDE #DigitalSovereignty" brings the news that...

    Automated testing for #Plasma, #KDELinux and KDE's suite of PIM apps (email, calendars, contacts, etc.) has been boosted; the work that will automatically configure accounts is under way; users will be able to restore data from Btrfs snapshots from apps like Dolphin; and much more.

    blogs.kde.org/2026/08/06/this-

    @sovtechfund

    #Linux #groupware #hardening

  32. "This Quarter in KDE #DigitalSovereignty" brings the news that...

    Automated testing for #Plasma, #KDELinux and KDE's suite of PIM apps (email, calendars, contacts, etc.) has been boosted; the work that will automatically configure accounts is under way; users will be able to restore data from Btrfs snapshots from apps like Dolphin; and much more.

    blogs.kde.org/2026/08/06/this-

    @sovtechfund

    #Linux #groupware #hardening

  33. "This Quarter in KDE #DigitalSovereignty" brings the news that...

    Automated testing for #Plasma, #KDELinux and KDE's suite of PIM apps (email, calendars, contacts, etc.) has been boosted; the work that will automatically configure accounts is under way; users will be able to restore data from Btrfs snapshots from apps like Dolphin; and much more.

    blogs.kde.org/2026/08/06/this-

    @sovtechfund

    #Linux #groupware #hardening

  34. "This Quarter in KDE #DigitalSovereignty" brings the news that...

    Automated testing for #Plasma, #KDELinux and KDE's suite of PIM apps (email, calendars, contacts, etc.) has been boosted; the work that will automatically configure accounts is under way; users will be able to restore data from Btrfs snapshots from apps like Dolphin; and much more.

    blogs.kde.org/2026/08/06/this-

    @sovtechfund

    #Linux #groupware #hardening

  35. "This Quarter in KDE #DigitalSovereignty" brings the news that...

    Automated testing for #Plasma, #KDELinux and KDE's suite of PIM apps (email, calendars, contacts, etc.) has been boosted; the work that will automatically configure accounts is under way; users will be able to restore data from Btrfs snapshots from apps like Dolphin; and much more.

    blogs.kde.org/2026/08/06/this-

    @sovtechfund

    #Linux #groupware #hardening

  36. Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

    Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat.

    kernel-error.de/2026/08/02/ope

  37. Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

    Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat.

    kernel-error.de/2026/08/02/ope

  38. Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

    Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat.

    kernel-error.de/2026/08/02/ope

  39. Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

    Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat.

    kernel-error.de/2026/08/02/ope

  40. Einen modernen OpenPGP-Schlüssel bauen: Ed25519, drei Unterschlüssel und die Härtung, die ihn geschwächt hat

    Ein Schlüssel kann modern sein und trotzdem falsch konfiguriert. Teil A ist das Rezept: Ed25519, zertifizierender Hauptschlüssel, drei Unterschlüssel, gpg.conf, vier Exportformate, sieben Kanäle. Teil B erklärt, warum eine einzige Härtungszeile mir AES-128 statt AES-256 eingebrockt hat.

    kernel-error.de/2026/08/02/ope

  41. 🔒 HomeSecExplorer/Proxmox-Hardening-Guide

    Provides actionable security configurations for Proxmox Virtual Environment and Backup Server following CIS benchmarks and virtualization standards.

    ⭐ Stars: 529
    📅 Last Update: Jul 30, 2026

    github.com/HomeSecExplorer/Pro

    #selfhosted #homelab #selfhost #selfhosting #opensource #security #hardening

  42. 🔒 HomeSecExplorer/Proxmox-Hardening-Guide

    Provides actionable security configurations for Proxmox Virtual Environment and Backup Server following CIS benchmarks and virtualization standards.

    ⭐ Stars: 529
    📅 Last Update: Jul 30, 2026

    github.com/HomeSecExplorer/Pro

    #selfhosted #homelab #selfhost #selfhosting #opensource #security #hardening

  43. 🔒 HomeSecExplorer/Proxmox-Hardening-Guide

    Provides actionable security configurations for Proxmox Virtual Environment and Backup Server following CIS benchmarks and virtualization standards.

    ⭐ Stars: 529
    📅 Last Update: Jul 30, 2026

    github.com/HomeSecExplorer/Pro

    #selfhosted #homelab #selfhost #selfhosting #opensource #security #hardening

  44. FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

    klarasystems.com/webinars/free

    ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

    2026-09-02 15:00 UTC

    timee.io/e/freebsd-security-20

    #FreeBSD #security #hardening #vulnerability @allanjude

  45. FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

    klarasystems.com/webinars/free

    ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

    2026-09-02 15:00 UTC

    timee.io/e/freebsd-security-20

    #FreeBSD #security #hardening #vulnerability @allanjude

  46. FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

    klarasystems.com/webinars/free

    ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

    2026-09-02 15:00 UTC

    timee.io/e/freebsd-security-20

    #FreeBSD #security #hardening #vulnerability @allanjude

  47. FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

    klarasystems.com/webinars/free

    ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

    2026-09-02 15:00 UTC

    timee.io/e/freebsd-security-20

    #FreeBSD #security #hardening #vulnerability @allanjude

  48. FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

    klarasystems.com/webinars/free

    ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

    2026-09-02 15:00 UTC

    timee.io/e/freebsd-security-20

    #FreeBSD #security #hardening #vulnerability @allanjude