Elektrine lite

← Feed

@m0xEE@breloma.m0xee.net

2026-05-02 14:41 UTC

@phnt@fluffytail.org @icon_of_computational_sin@mstdn.starnix.network @mangeurdenuage@shitposter.world To me CopyFail revealed what a complete and utter clusterfuck modern Linux systems are — and it's not about the fact that vulnerabilities exists or how they are disclosed. Cryptographic routines running in kernel space exported to user space via a socket, what the fuck for? For a 0.1% performance gain?! And kernel module getting loaded when a user — any user at all, creates a socket of a particular type? For real?! This is the shit a ni~ ehm… user gets to deal with now?! And in RHEL AFAIK they went even further and built that module right into the kernel — so there is nothing to unload or prevent from getting loaded. Neither of these things should be possible in a system that is considered even remotely secure! :marseytabletired2: While security folk insist on putting everything in a container — these things exist!

Replies (1)

  • @phnt@fluffytail.org 2026-05-02 15:04

    @m0xEE@breloma.m0xee.net @icon_of_computational_sin@mstdn.starnix.network @mangeurdenuage@shitposter.world >To me CopyFail revealed what a complete and utter clusterfuck modern Linux systems are Have been for a very long time now. >And in RHEL AFAIK they went even further and built that module right into the kernel — so there is nothing to unload or prevent from getting loaded. initcall_blacklist=af_alg_init kills it.

    Open ##2686522