If you self-host a Snikket server, we released a security update today that you should be aware of... for more details check our blog post: https://snikket.org/blog/snikket-jan-2021-security-release/
If you've been exposed to Moxie Marlinkspike frequent rants about how people are dumb and lazy and we should have centralized systems for their happiness, André Staltz wrote a very good counterpoint (from @makeworld )
https://staltz.com/some-people-want-to-run-their-own-servers.html
Oops, I was wrong, that only allows access from localhost and the docker subnet.
The solution comes directly from docker's documentation: there is a chain, DOCKER-USER, that can be used to filter local traffic:
iptables -I DOCKER-USER -i wlan0 ! -s 192.168.1.0/24 -j DROP
https://docs.docker.com/network/iptables/#restrict-connections-to-the-docker-host
Happy New Year!
Just a reminder: We are considering to participate the Google Summer of Code 2022! #GSoC
If you are interested as a student, mentor or as #XMPP project in general add your ideas to https://wiki.xmpp.org/web/Google_Summer_of_Code_2022 and reach out to us via xmpp:gsoc@muc.xmpp.org?join
Finally tried #pihole with #docker. Everything works flawlessly, but I realized as a nasty surprise that docker bypasses #ufw, so I could potentially open my DNS server to the world.
Even they are several and complicated lists of rules to make ufw catch this, luckily pihole developers created an option "settings→DNS→Allow only local requests" that only lets the local network query the server.
Re-encoding videos with the aid of several computers in parallel.
https://sachachua.com/blog/2021/12/re-encoding-the-emacsconf-videos-with-ffmpeg-and-gnu-parallel/
"Have you heard of our lord and saviour GNU parallel?"
Finally I got #anbox to work. I use it to try apps instead of installing them on the phone.
I revisited #k9mail after a long time, but I still very much prefer #fairemail, it has so many more features.
gnupg.org is self-sustainable now:
Dear Free Software Community, let’s raise awareness about Quicksy. We don’t have to recommend our geeky solutions to everyone. If some people switch to free software, decentralized and federated app like Quicksy, that is better compared to them finding xmpp/matrix/IRC difficult to use and not using it. We need to work to advertise this option and raise awareness about it.
December #Prosody trunk update:
No 0.12 release yet!
A new setting to easily configure TLS security and compatibly level: `tls_preset = "modern" | "intermediate" | "old"` based on #mozilla recommendations
New module and API for recurring tasks (e.g. cleanup jobs): mod_cron
New module to prevent registration of deleted accounts, as they might retain group memberships on remote instances: mod_tombstones
Many other minor tweaks and polish.
69 files changed, 2707 insertions(+), 579 deletions(-)
🎉 Happy new 2022 🎉
Have a great new year celebration everyone. We wish you all a very awesome 2022!
Special thanks to all the Disrooters that have been helping us by reporting issues, donating, hanging out on our community chat, all those who submitted patches, translations and tutorials! You are all awesome!
Disroot would not exist without the tireless work of all FLOSS developers either. We would like to thank you all for your hard work!You are the heroes!
More at: https://disroot.org/en/blog/disnews-4
As I upgraded to #debian "testing" again, my Bluetooth headset stopped connecting because some protocol issue. Turns out it was as easy to fix as deleting it from the list of paired devices and then pairing it again.
We made exciting progress in our work towards OpenPGP card support in Sequoia. Two weeks ago, we extended our CI system to run a test suite against a set of physical OpenPGP cards:
https://sequoia-pgp.org/blog/2021/12/20/202112-openpgp-card-ci/ "Towards OpenPGP Card Support in Sequoia".
(With this, our CI system now makes use of the three devices that @nitrokey donated for this purpose - thanks again!)
Today I learned the SSLKEYLOGFILE environment variable for #firefox , so you can capture #TLS traffic from #wireshark.
Nevertheless, it is disabled on #debian, but #chromium still supports it via the --ssl-key-log-file argument.
If you're a server administrator running #Synapse, please be prepared to upgrade as soon as the patched version is released.
#matrix
https://matrix.org/blog/2021/11/18/pre-disclosure-upcoming-security-release-of-synapse-1-47-1
#apple: take everything, give nothing
Free Apple support | daniel.haxx.se
https://daniel.haxx.se/blog/2021/11/18/free-apple-support/