home.social

#patches — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #patches, aggregated by home.social.

  1. Security Patches

    InfoSec

    Regardless of which Operating System you run, it is important to keep up with the critical updates to keep your machines as safe as possible

    • Realize that by the time a critical bug has been reported, verified, patched and delivered to your distribution of choice, a significant amount of time has passed...
    • From the first day the bug has been discovered [zero day] to the day you patch your computing machine, you've had a vunurable open machine in that one respect.
    • Keep the amount of time between the availability, of patches & the update of your machines, especially your VMs (Qemu et al) & physical servers as short as possible
    • Make sure to always use manual updates on your server VM's!
    • I shall not explain why, start reading on Wikipedia and furthe, the explanation is too long for this short post

    Notes:

    • every OS can have vunurabilities
    • Security in obscurity does not work!
    • you are not secure because you run obsolete AmigaOS QNX or cool and niche *BSD as an OS
    • buffer overflows hide everywhere
    • I reguraly find them!

    #Security #patches #programming #InfoSec #AmigaOS #Amiga #QNX #Linux #feeBSD #netBSD #openBSD #technology #software #buffer #overflow #mathematics

  2. In the last week or so, #Microsoft's CEO Satya Nadella announced that they were going to pull back from doing new feature work for #Windows for a bit, and focus on bug fixes and other quality-of-life improvements for users and administrators. Windows' already shaky reputation has taken a beating over the last year as it seems that every monthly rollup #patch, and many out-of-band #patches, introduce new problems at the same rate as they fix previous ones.

    Is this giving you deja vu? It should. Remember a couple or three years ago, when the same guy announced that Microsoft was going to focus on security? They were in the middle of a long spell of brutal security holes found in all their products. Remember how they told their #engineers "If you have to choose between doing a feature and doing security, choose security"?

    Remember how you never heard about that initiative again?

    It's the same thing here. #PR garbage in service of a narrative that no, Windows' horrible security, usability, and #stability aren't actually that bad, so that MS can focus on their core competencies of buzzword promotion, stock market analyst manipulation, and monopoly abuse.

    Perhaps someone in Microsoft management actually believes these refocusing efforts are genuine - but if you don't change the incentives, they won't actually take hold.

    #PR #marketing #buzzword #MSWindows #SatyaNadella #security #WeveHeardOfIt #stability #crash #rollup #monopoly #MemoryHole

  3. Was Unternehmen aus dem CrowdStrike-Vorfall lernen können

    Am 19. Juli 2024 kam es weltweit zu einer Betriebsstörung zahlreicher Computer. Schätzungsweise 8,5 Millionen Systeme, die Windows als Betriebssystem und die Software Falcon von CrowdStrike nutzten, waren betroffen. Infolge dieser Ausfälle mussten zahlreiche Institutionen ihren Betrieb einstellen. D(...)
    dr-datenschutz.de/was-unterneh

    #IT-Sicherheit #NIS2 #Notfallmanagement #Patches #Qualitätsmanagement

  4. I am hopeful that the #yinglet and #drekir folks will head over to the Fediverse too as Twitter goes down in flames.

    The #OutofPlacers by #Valsalia and #TheLongHike by #Patches are lovely comics with fandoms that I hope can survive the current shakeups in net spaces