-
ketas
-
cpet
Ketas that's chrome it has some security crap that uses its own dns stuffs
-
ketas
cpet: might be chrome component embedded yes but i busted it
-
ketas
:p
-
cpet
Bastard
-
cpet
Most of my security sits in the hands of a netgate appliance
-
cpet
It used to be a firewalla
-
cpet
Now a netgate 4200S
-
cpet
I did not like the old software atleast the netgate runs a jan 15 current
-
luser
-
luser
Also does other formats like bind.
-
badkat
cpet: you love backd00rs
-
cpet
I guess
-
cpet
They said the same about open bsd
-
badkat
that is some legendary plain sight back door
-
luser
Netgate and OpenBSD have backdoors?
-
cpet
Who.knows
-
cpet
What you read online isn't always true
-
badkat
>:)
-
cpet
Especially coming from a bad kat
-
badkat
nice point
-
cpet
Cause bad Kats are bad
-
badkat
as cigarettes
-
cpet
I smoke cigars
-
badkat
i prefer to smoke asm
-
cpet
Can't smoke 0 and 1's
-
thedaemon
hello
-
cpet
Hi
-
ketas
luser: it's in that thing i use, one of lists
-
ketas
i haven't updated it but meh no ads appear so
-
ketas
10M Jun 30 2024 ad
-
ketas
also bind wastes memory for every view?
-
ketas
actually i have one view with that
-
ketas
but i acl it to 2 /24's & 2 /64's
-
luser
ketas: I have a weekly cron to update it. Works great. I do strip out a couple of domains which break sites I use but that is a part of my script so simple as.
-
luser
Also, I use unbound for DNS caching and forwarding (to NSD for my local domain and DoT for external).
-
ketas
hmm
-
ketas
i could try that chain of dns servers maybe
-
luser
I used BIND for 20 years and I think unbound/nsd is better. You can use unbound to set static host entries much like /etc/hosts if you have a small enough network.
-
ketas
but it gets awfully complex i think
-
luser
Not really. I used NSD for with replication but I could just as easily use unbound. The only down fall I would say is dynamic DNS for DHCP doesn't exist (at least the last time I checked).
-
ketas
like i have ad filter, recursive and auth dns, and different views, all in one bind
-
ketas
how do i split it up?
-
ketas
it's also kind of past /etc/hosts
-
luser
unbound will have your ad filter, views and recursion; nsd for authority dns.
-
ketas
i include static and dynamic parts in my zones and i autogenerate them from ips, making it my own dynamic dns too
-
luser
No, I'm not saying using /etc/hosts, I'm saying you can use unbound much like /etc/hosts was used to set static DNS entries.
-
ketas
i include same content in two different zones and in two different levels eh
-
ketas
fancy setup
-
luser
Does BIND implement DoT yet? Last I read it was a work in progress but required an external process to achieve.
-
ketas
that would maybe good idea indeed
-
ketas
to have
-
ketas
bind has it
-
luser
Nice. Do you use it?
-
luser
Just stumbled on this if anyone is interested. 2025 FreeBSD Community Survey:
freebsdfoundation.org/blog/the-2025-freebsd-community-survey-is-here
-
ketas
no, unless it does it hiddenly
-
ketas
:p
-
ketas
i filled that survey up
-
ketas
was better than last time
-
luser
No, it will be an explict configuration.
-
ketas
i don't even gave dnssec yet :/
-
ketas
granted, personal domains eh
-
ketas
s/g /h /
-
luser
I wouldn't say it's a necessary on your own network, but you should encrypt your DNS traffic for external requests.
-
ketas
s/ g/ h/
-
ketas
:p
-
ketas
how many servers do it?
-
badkat
dnscrypt-proxy full featured is great :))
-
badkat
you can put a recursive resolver on top ofc
-
ketas
in reality i should indeed split it up to 3 parts maybe
-
luser
ketas: I use quad9.net
-
badkat
g0v9? roflma0
-
ketas
if you have own dns server, why bother using public recursors?
-
badkat
ketas: i meant to have your own RR with dnscrypt-proxy as upstream
-
badkat
unbound/bind/any you line
-
badkat
like*
-
luser
ketas: how else am I going to resolve external DNS that I don't manage?
-
luser
badkat: you seem to think everything is a backdoor.
-
ketas
which external dns?
-
luser
I don't doubt for a second the .gov isn't implementing honey traps though.
-
luser
how do you resolve google.com, ketas?
-
ketas
bind does it locally along the path
-
badkat
luser: they can issue certificates trusted by your root CA just in seconds, no vulnerabilities or such involved :)))
-
ketas
it has copy of . so it don't need to go ask roots wherr com is
-
ketas
then it caches it and next time it's fast
-
luser
ketas: right, and it queries external DNS servers in plain text unless you encrypt it.
-
ketas
yeah should fix it :p
-
luser
badkat: no they can't.
-
badkat
luser: maybe you dont know HOW that works, you could tho.
-
luser
I understand very well how it works and they can't.
-
ketas
dot can be used towards auths as well?
-
badkat
before this internet that is a leftover of the original fenomenom is over, in 10 years you will no have any access to information like today.
-
badkat
luser: r0flma0
-
ketas
internet is not same before and after 2013
-
badkat
next checkpoint 2033
-
badkat
after that 2045
-
badkat
buy some top grade storage devices, LTO should be fine
-
luser
I don't doubt that govs are trying to restrict info, but they aren't seemlessly issuing fake digital certificates to MitM traffic to snoop on everyone.
-
badkat
luser: not everyone lol, i never meant that.
-
luser
ketas: do you mean your own authoritive DNS?
-
badkat
those certs are not fake lol, are real, trusted certs.
-
ketas
luser: no, others
-
luser
And the private keys accossiated to those certs?
-
badkat
luser: they have private programs with the owners, big companies of the north, $$$$$$$$$$$
-
luser
ketas: in BIND, you will set your forwarders to an external DNS provider that supports DoT and then enable DoT. Who do you currently use?
-
luser
badkat: without private keys, they can't generate trusted certificates to anyone 3rd party.
-
ketas
no forwarders at all
-
badkat
luser: they have the private keys r0flma0 its just a file, did you even read?
-
ketas
i took forwarders off since govt mandated filtering started
-
ketas
was isp before
-
luser
badkat: you have no idea what you're talking about. FIN.
-
badkat
luser: 0k, l00ser.
-
badkat
SYN SYN SYN
-
luser
ketas: you must have forwarders somewhere to resolve external DNS (like google.com).
-
ketas
no it's direct outside conns now
-
luser
Ok. So set up forwarders to quad9 with DoT and your DNS will be encrypted.
-
luser
Cloudflare also offers DoT I believe.
-
ketas
seems like more trouble to me
-
ketas
extra resolvers in the way
-
badkat
ketas: $(just resolve the entire internet once a week) > /etc/hosts
-
luser
not at all. Instead of recursing from TLD down, you forward to resolvers and utilise their cache (if already resolved) or make them recurse. The difference is your DNS requests are now encrypted and can't be snooped or interfered with on the line.
-
ketas
badkat: hahaha
-
ketas
why don't we encrypt them in the way there then?
-
ketas
i read that dot/doh is only for clients to recursive resolvers
-
ketas
what protects traffic going outside of quad9
-
ketas
nothing hides it iirc, dnssec only signs it
-
luser
DNSSEC would provide integrity for quad9 requests however there is no attribution to you for the those requests. Encrypting is about protecting your DNS requests: both integrity and from snooping.
-
ketas
well that's correct, can't correlate them to me, well, easily
-
ketas
but i would like dns to have full ssl
-
ketas
:p
-
ketas
when do we get there?
-
luser
That would be great but that would require every authoritative DNS server to implement TLS in some way to encrypt requests.
-
ketas
some do?
-
ketas
i never looked
-
luser
You'e using recursive resolution so the best you have is DNSSEC but that's still in the clear.
-
ketas
at that paranoid level, what are chances my sim would get remotely owned?
-
luser
sim?
-
ketas
yeah like in my phone
-
luser
phones are completely insecure and, as badkat would attest to, completely backdoored.
-
ketas
or yeah baseband too
-
ketas
it's all fuckup
-
badkat
ketas: by who? build a threat model first
-
badkat
all CPU's have a out of band processor, in mobile communications its worse because it have a pretty damn good antenna xD
-
ketas
who would even sniff in actual internet backbone or isp access network
-
ketas
law enforcement?
-
badkat
they dont need to.
-
ketas
and mitming
-
badkat
they get netflow traffic exported from every IXP
-
badkat
so when you setup your tricky dns circus they can just correlate with a few params
-
ketas
i don't think they actually do?
-
badkat
no mitm, broke ass hoodie techniques
-
ketas
who the hell filters that also
-
ketas
remember they also like have to use same hw as everyone else
-
badkat
depends, blues are at the same level as civs
-
badkat
i mean those systems are not for massive surv, no need to get a shiton of useless data every sec
-
badkat
V.I.Ps make use of those systems to get private monitoring for example, they pay to be protected in real time
-
ketas
i wonder if dns is such a big target anyway
-
badkat
not really
-
ketas
because what happens after dns
-
badkat
if i can get a traffic export even without layer 7 data of the communications
-
badkat
i could simple do a TLS SNI resolution and know which site did you went to
-
badkat
who cares about dns roflma0
-
ketas
first who would even get targeted like thst
-
ketas
in first place
-
badkat
thats a good question
-
ketas
i mean past coffee shop open wifi, it gets hard
-
badkat
but thats the political logic of the issue, im just heading the technical part ;)
-
badkat
we are talkin about companies/countries capacities, not random n00bs using kali linux
-
ketas
of course i would love end to end encrypted channels
-
ketas
in anything
-
ketas
then it gets harder and harder even if you want
-
ketas
fun, even nsa 2013 docs said
-
ketas
we can't
-
ketas
which is like
-
ketas
good
-
badkat
in disney land, sure
-
badkat
look, thing is not the encryption mathematical-theorical power
-
badkat
is about *implementations* of such
-
badkat
did you ever check out how DES encryption works in consumer-grade devices?
-
ketas
i mean if it's faultless implementation with pfs and you can't downgrade, or correlate ot do thise things
-
ketas
yesh
-
ketas
implementations suck
-
badkat
start with DES then research about AES, then RSA
-
ketas
oh it's difficulg
-
ketas
t
-
badkat
the CPU makes the dirty job with the specialized crypto instructions
-
ketas
i like to think it's math
-
ketas
cpu crypto instructions are fun
-
badkat
yep, thats the problem with non-engineers they just believe internet posts, cant have a critical thinking because they are 100% blind on the production process
-
ketas
they could be backdoored :)
-
ketas
but has anyone proven it?
-
badkat
is not backdored actually: degraded performance
-
ketas
well i have to believe since i can't check all
-
badkat
the CPUs are beautiful black boxes
-
ketas
cpu bugs are fun too
-
badkat
yeah :D
-
ketas
there have been several
-
ketas
but you'd bet people look into them
-
badkat
cool micros to play with are the ones with goldmont platform, you can patch/modify microcode :D
-
badkat
after that series, intel enforced a really pain in the ass encryption method that makes it pretty difficult to accomplish
-
ketas
difficult
-
ketas
i once had cpu arch teaching gf, but she ran away
-
ketas
she took that in uni
-
ketas
i haven't
-
badkat
ketas: lucky you :), i never had a techy girl on my life :((((
-
la_mettrie
you can still have a techy granny
-
luser
a granny that uses the latest technology to clean her dentures.
-
badkat
la_mettrie: i hope so, common girls dont like my retro-computers/consoles room they think is total trash hoarding i dont give tours there anymore
-
ketas
where are uncommons?
-
luser
grannies.
-
badkat
Margaret Hamilton is such a hottie tho
-
badkat
w00f w00f
-
ketas
i mean they do exist
-
ketas
even younger ones
-
ketas
somewhere
-
luser
lol @ margaret hamilton. puke.
-
badkat
luser: actually, puke on your damn ass-tracked pinpointed face
-
luser
lol
-
ketas
-
ketas
her?
-
badkat
who else, ofc <3
-
ketas
photo of room btw
-
ketas
i have like unorganized rooms
-
badkat
CRTs are the biggest problem
-
badkat
along JAMMA boards
-
badkat
and the fact that some ICs wont be working in 10-20 years makes me even more anxious :((
-
badkat
they will just die :(
-
ketas
had to google jamma
-
badkat
japanese arcade systems
-
ketas
i only have some weird soviet nes clone
-
ketas
:p
-
badkat
great!
-
badkat
6052 cpu clones?
-
luser
I think we should be fearful of solder. It's linked to 5G technology. They're playing the long game.
-
ketas
actually china maybe
-
ketas
but same thing
-
ketas
i don't know what's inside yet
-
ketas
i know it works
-
badkat
there was some interesting CPU/MCUs made in the URSS
-
badkat
prolly not chinese
-
ketas
yeah they cloned
-
ketas
actually i only later found what else did they clone
-
ketas
many things
-
ketas
just like china noe
-
ketas
now
-
badkat
luser: did you ever considered join the ch1n4 military?
-
ketas
china is now curseword :p
-
luser
no point. they hacked our brains and now control us via their satellites. We're all chinese soldiers now.
-
luser
they cloned the us satellites using space-based 3d rpinters. don't ya know?
-
badkat
我們製造您的裝置,所以我們管理網際網路,您的屁股屬於深圳的霸主。
-
badkat
luser: not really, but you should join them, they will put a 5g 發射器 in your butt so you can report to the HQ over a encrypted dns tunnel
-
luser
but it's all hacked bro, so it's pointless, right?
-
badkat
yep, prolly i could get access to your butt remotely if its running linux kernel :)
-
luser
I'm confident my private keys are private, btw, and have zero concern my digital certificates are safe and secure.
-
badkat
Neat, certified l0o0s3r
-
ketas
We build your device, so we manage the Internet, and you
-
ketas
The butt belongs to the overlord of Shenzhen.
-
ketas
hahaha
-
badkat
x)
-
ketas
hmm, according to google translate, the second one is transmitter, or hair shoot device in separate
-
badkat
hahah yes transceiver
-
ketas
that language is fun
-
ketas
are you khinese kat
-
ketas
:p
-
badkat
imagine having your butt connected to quad9, security is a must!
-
badkat
no lma0, im not.
-
ketas
badapple
-
badkat
nice song :)
-
ketas
:)
-
ketas
how's the desktop failing?
-
ketas
now
-
badkat
thanks for remind me that, by now its ok because i was not using much the desktop today
-
badkat
i think the problem maybe is not be related to ZFS in special
-
badkat
but some virtual memory allocator is doing nasty stuff while using firefox
-
badkat
allocating 14GB for 2 damn tabs is total stupid in my opinion
-
badkat
3G in use and 14GB in INACTIVE state from virtual memory reports
-
badkat
those 14g are from ff process, i dont like that
-
badkat
if i completly close firefox, the desktop stills feels a bit laggy, tried to rest a bit of computers today, tomorrow i will go deep with the kernel i built yesterday to discard some assumptions
-
ketas
14g for 2 tabs?
-
ketas
what do they run
-
ketas
i used to run ff/tb on 2g ram ufs
-
ketas
ff&tb
-
ketas
often 300 tabs etc
-
ketas
i bet 14g is leak tho
-
beastie
badkat: give your system more swap and you will not have that problem.
-
ketas
swap wouldn't help
-
ketas
if you want to use it
-
luser
In Firefox navigate to "about:memory" in the URL bar and it'll show the breakdown of memory allocation.
-
ketas
it has also tuning there
-
ketas
swap is for god knows what... 100 jails with idle dhclients?
-
ketas
active swapping is bad
-
ketas
and he already has relatively high ram
-
ketas
i mean i can build rust here and llvm
-
ketas
takes most of 4g ram and also allocates 10g swap
-
ketas
takes a day and it does complete
-
ketas
and the huge cost of time
-
ketas
s/and/at/
-
ketas
oh hw is fun, what was that demo, some game console iirc, the color palette was meh but they found some hack to put full color photo there
-
antranigv
do we even use the /development directory on the FreeBSD downloads page anymore? it has CSRG and CVS/SVN files. too old to sync now, right?
-
dvl
From base, how can I create a password hash on the command line? e.g. $2a$12$UkMrEMMQocdYI4yj4VBPs.69yAtPne3D2MT3KpuMAfg48ZbetzZvq
-
dvl
I know passwd can do that, but that would modify my password, I just want the hash.
-
dvl
htpasswd would also work, but that's not in base.
-
luser
echo -n "password" | openssl passwd -6 stdin
-
luser
man openssl-passwd for more details
-
dvl
luser: Works, thanks. Seems that AdGuard can't use that 'advanced' hashing algorithm. Also tried -1 etc. Seems only a password, so far, starting with $2.. works
-
luser
No proebs. I got that from
search.brave.com in the AI response and it got that from FreeBSD forums, so there might be additional information from there.
-
dch
ivy: yes I saw that comments, I think its great somebody(tm) is putting more thought into it. Once we hit 15.0-RELEASE we'll be largely stuck with it for quite a while.
-
dch
benjamino: I suspect you can't use syscons & drm-kmod together, got to pick either 1990s tech or 2010s tech
-
dch
but I would like to know for sure
-
benjamino
dch: yeah, i figured it out in the morning, i opted for vt in the end, it works fine i suppose, especially because man pages say that syscons will be removed in newer versions of freebsd
-
dch
we keep saying things like that in manpages but it might take a decade :D
-
benjamino
oh
-
benjamino
why did you have to tell me this... now i'm reconsidering syscons again
-
dch
unless vt is broken for your use case may as well stick with it
-
benjamino
dch: well, it's alright... for now. thanks!
-
badkat
beastie: my system doesnt even reachs swap, wtf?
-
beastie
what do you mean?
-
beastie
that's not true...
-
badkat
?
-
badkat
O_o
-
beastie
how can't your system reach swap if you have virtual memory?
-
beastie
you add swap for the irregular case that you have more memory in use than your actual physical memory. that simply allows your system to continue, instead of start spitting a lot of out of memory errors.
-
badkat
my swap device is never used
-
badkat
i have 2G swap, always 2048 unused, what do you mean
-
badkat
i have like 10G free memory also
-
badkat
what do you mean?
-
beastie
my system has 8Gb of memory and normally has over triple that quantity of swap in use, by several users using google chrome simultaneously.
-
badkat
i have 32gb + 2gb swap
-
badkat
i never reach to write the swap device
-
badkat
also vm.overcommit=0
-
beastie
actuallyy have 8 gigas of ram and 48Gb of swap distributed in 4 mechanical disks... this allows me to hold several users with a desktop each, and running theyr own chrome browser without having out of memory messages.
-
badkat
i never get out of memory issues
-
badkat
dont know what you talk about
-
badkat
thanks tho
-
beastie
i dont either... but I did.
-
beastie
I did my acocunting and the issue revealed.
-
beastie
I have four hard disks actually dedicated exclusivelly to swap.
-
badkat
im sure we are talking about different issues beastie
-
beastie
probably... but I was mentioned, like now...
-
badkat
i have weird freezing problems, outside of firefox too, with even 30gb free of ram
-
badkat
started to happen after upgrade to 14.2 from .1
-
beastie
I have not even read the discussion... probably the mention was for you, and the tab key intervened to change the nicks.
-
beastie
I'm running 14.2
-
beastie
have you upgraded recently, 14 has a change of abi, so you should upgrade probably many packages.
-
beastie
I have had freezes after an update that have repaired with that.... not a swap problem.
-
beastie
almost anything (any kernel loaded module... video driver... etc. can trigger a halt)
-
badkat
i did pkg upgrade -f as i do every time i do minor/major base-upgrades
-
badkat
yes i suspect about 3 modules, openzfs/drm61-kmod and ethernet-kmod from pkg
-
badkat
realtek-re-kmod
-
mage
anyone is using Gitlab? I'm wondering how do you turn off logging for api_json.log
-
badkat
mage: check the gitlab-rails configuration, use a symlink to /dev/null in the output file for api_json
-
mage
gitlab-rails ..?
-
mage
I don't have such thing .. it's gitlab-ce compiled from poudriere
-
badkat
mage: is a component of it
-
badkat
gitlab.rb should have the logging subsystem configuration
-
badkat
should be in /usr/local/www/gitlab-ce/...
-
badkat
each "rail" is the logging channel iirc
-
mage
-
mage
I'm wondering why it is simply not configurable in the config/gitlab.yml file
-
badkat
gitlab is complex, i would choose cgit/gitea/forgejo if im managing a git service for small-medium organization
-
rtprio
gitlab is a hog, i switched to gitea and haven't been happier
-
mage
yep but switching is currently not an option .. maybe on the mid/long term ..
-
rtprio
mage: is gitlab-ce in ports the omnibus? does it run their ansible scripts when you do stuff?
-
badkat
no
-
rtprio
is the api_log from rails or from nginx?
-
badkat
rails ofc
-
rtprio
(also how is this a problem?)
-
badkat
xD, maybe is running out of space in the logs partition
-
rtprio
so logrotate the shit out of it, with minimal retention
-
mage
the problem is that it grows to multiple gigabytes in some days
-
mage
same for sidekiq.log
-
badkat
logrotate, check gitlab community edition docs
-
rtprio
er, sorry,
-
mage
yeah.. I could manage it with newsyslog
-
rtprio
yes, i meant newsyslog.. working the wrong OS for too long
-
mage
but it's crazy that you can't configure that in config/gitlab.yml or config/another.yml file
-
badkat
you can, doesnt seem like you want to read the docs
-
badkat
so.. rftm :)
-
rtprio
the number of times i've had to grep the source to understand how to set something in the config file is nonzero
-
mage
I'd like to be happy to see where in the doc
-
badkat
the gitlab docs website? lol
-
mage
apparenlty it doesn't apply to the "version" which is in the ports
-
badkat
it does, the files are layered a bit different, thats all
-
rtprio
that was the other thing that tested my patience with gitlab, the six or so versions from free to enterprise
-
rtprio
and varying features in each
-
badkat
i managed gitlab over freebsd for years
-
badkat
everything is there, you should not bother with ruby code
-
badkat
just learn where is everything and how to use rake
-
rtprio
i also got tired that every rake operation took a nontrivial amount of time
-
rtprio
likewise for mastodon, how does `tootctl help` take 20 seconds to run
-
badkat
:P
-
mage
I have to use rake to configure logging?
-
badkat
no, i mean is part of the administrator must-know
-
badkat
my last bit of sand to help you, google: log rotation gitlab community docs
-
badkat
get into the website, read.
-
mage
badkat: I'm FreeBSD admin for years.. I don't need doc to configure newsyslog
-
mage
I have read the doc several times, nothing works (their GITLAB_LOG_LEVEL, etc)
-
mage
-
rtprio
have you asked in a gitlab channel?
-
badkat
i had explained you about the gitlab rails first, is gitlab.rb inexistent?
-
badkat
i dont have an gitlab installation on freebsd at hand now, but check in config directory if not and grep for logrotate_size
-
mage
-
mage
and logrotate_size is unknown
-
mage
but I don't care about logrotate
-
mage
I just want to change log level from DEBUG to WARN or ERROR that's all
-
mage
anyway, I've ln -s to /dev/null ; thank anyway
-
mtll
and even if I tried, I'd get nothing done, I get too scatterbrained
-
mtll
wrong channel
-
luser
wi 2
-
rwp
/
-
hernan604
alt+2
-
rwp
M-a
-
» rwp enjoys that we know exactly what we are talking about while most people walking by looking over our screen would have no idea what we are talking about. Fun! :-)
-
wsky
i've spent three days on rebuilding my blog
-
wsky
anyone wanna see?
-
wsky
\i mean few hours a day but still
-
cpet
What's the backend wordpress
-
cpet
I like gravcms or Hugo
-
wsky
i used eleventy
-
wsky
it's a js markdown chewer
-
wsky
that's the link anyway, if you care
wskyx.github.io
-
cpet
Node
-
wsky
maybe few more touches but more or less it's done
-
wsky
yes, node
-
cpet
I always used ghost until they made it hard to install using some cli
-
cpet
I personally don't like node but to each there own my current beer blog is hugo
-
wsky
works for me
-
wsky
i don't even know js :D
-
wsky
most of work i did was html/css editing. work on files, and bash scripting
-
wsky
i am tired now >:(
-
wsky
also, two nicks i just pinged :DD
-
wsky
oh yeah, and markdown editing obviously
-
wsky
the most fun part of it was when my bash script fired off and converted almost 400 markdown files :D
-
wsky
however some file editing i had to do manually, iit wasn't possible to get it done by a script
-
badkat
wsky: nice store, how do you print the canvas?
-
wsky
i order that online :D
-
wsky
no one ever ordered one from me yet tho :DD
-
wsky
my previous site had a poor theme (
vlepy.github.io )