<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail]]></title><description><![CDATA[<p>Today I have spent way too much time handling the <a href="https://copy.fail" rel="nofollow noopener"><span>https://</span><span>copy.fail</span><span></span></a> situation <a href="https://mastodon.social/tags/copyfail" rel="tag">#<span>copyfail</span></a></p><p>The persons who discovered it didn't notify the distribution security list, so no patched kernels was available for people to install when they released it.</p><p>But they did have time to write an exploit, and thought it was a good idea to distribute that on day one, before vendors had time to provide patches.</p><p>I'm not very impressed with xint.io, I guess it's the marketing department that runs the show.</p>]]></description><link>https://board.circlewithadot.net/topic/1c00fa65-dd1e-4d2b-b0bb-49624acf7e0a/today-i-have-spent-way-too-much-time-handling-the-https-copy.fail-situation-copyfail</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 01:49:21 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/1c00fa65-dd1e-4d2b-b0bb-49624acf7e0a.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Apr 2026 14:35:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 11:40:47 GMT]]></title><description><![CDATA[<span><a href="/user/eloy%40hsnl.social" rel="ugc">@<span>eloy</span></a></span> <span><a href="/user/alexanderkjall%40mastodon.social" rel="ugc">@<span>alexanderkjall</span></a></span> <span><a href="/user/noisytoot%40berkeley.edu.pl" rel="ugc">@<span>noisytoot</span></a></span> but oh boy the coding style is much worse than literal amlogic kernel BSP]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/1d1bca91-a10c-491b-a0f2-992dae6cb9cf</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/1d1bca91-a10c-491b-a0f2-992dae6cb9cf</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Sat, 02 May 2026 11:40:47 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 11:40:09 GMT]]></title><description><![CDATA[<span><a href="/user/eloy%40hsnl.social" rel="ugc">@<span>eloy</span></a></span> <span><a href="/user/noisytoot%40berkeley.edu.pl" rel="ugc">@<span>noisytoot</span></a></span> <span><a href="/user/alexanderkjall%40mastodon.social" rel="ugc">@<span>alexanderkjall</span></a></span> The only reason I can think of to use this for marketing is .. yeah, what you said, and maybe also "hey our AI is so good!!!"]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/23711783-9a4c-4bfa-8f27-b95cefa5326c</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/23711783-9a4c-4bfa-8f27-b95cefa5326c</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Sat, 02 May 2026 11:40:09 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 06:50:56 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> you can't expect that guy to notify everybody. He notified the kernel security list, but they didn't communicate downstream.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/BasieP/statuses/116503652342230953</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/BasieP/statuses/116503652342230953</guid><dc:creator><![CDATA[basiep@fosstodon.org]]></dc:creator><pubDate>Sat, 02 May 2026 06:50:56 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 04:09:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/raven667%40hachyderm.io">@<span>raven667</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> Isn't the stance rather that all bugs are security bugs?</p><p>I mean it doesn't change much in practice, but it's a better argument IMO.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/Arcaik/statuses/116503017838125893</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/Arcaik/statuses/116503017838125893</guid><dc:creator><![CDATA[arcaik@hachyderm.io]]></dc:creator><pubDate>Sat, 02 May 2026 04:09:34 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 03:22:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/fun%40berkeley.edu.pl">@<span>fun</span></a></span> <span><a href="/user/noisytoot%40berkeley.edu.pl">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> It is not serious, but OTOH the exploit is simple enough that it's still relatively easy to decipher.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.librem.one/users/dos/statuses/116502831263332154</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.librem.one/users/dos/statuses/116502831263332154</guid><dc:creator><![CDATA[dos@social.librem.one]]></dc:creator><pubDate>Sat, 02 May 2026 03:22:07 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:52:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/orca%40nya.one">@<span>Orca</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> Not anymore.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502713181805770</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502713181805770</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:52:05 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:51:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/fun%40berkeley.edu.pl">@<span>fun</span></a></span> <span><a href="/user/noisytoot%40berkeley.edu.pl">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> It totally is.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502710360436240</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502710360436240</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:51:22 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:51:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/noisytoot%40berkeley.edu.pl">@<span>noisytoot</span></a></span> <span><a href="/user/fun%40berkeley.edu.pl">@<span>fun</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> I was wondering about that (haven't had to deal with actual Redhat since 2013)...</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502709391373056</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502709391373056</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:51:07 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:49:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/omegapolice%40hachyderm.io">@<span>OmegaPolice</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> It is /not/ just you.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502701974357896</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502701974357896</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:49:14 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:47:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/penguin42%40mastodon.org.uk">@<span>penguin42</span></a></span> <span><a href="/user/fedops%40fosstodon.org">@<span>fedops</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> That's also on NIST, and the aren't doing too well right now.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502696409157132</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502696409157132</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:47:49 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:46:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/penguin42%40mastodon.org.uk">@<span>penguin42</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> No. That situation is really complicated and easy to fuck up.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502692844528746</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502692844528746</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:46:55 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 02:46:20 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@LabanSkoller">@<span>LabanSkoller</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> <span><a href="https://fosstodon.org/@jmm">@<span>jmm</span></a></span> You don't get the props for that that you used to. Giving it a cute name and marketing campaign is the thing these days.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502690552461328</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.hackers.town/users/drwho/statuses/116502690552461328</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Sat, 02 May 2026 02:46:20 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Sat, 02 May 2026 01:53:59 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@alexanderkjall" rel="nofollow noopener">@<span>alexanderkjall</span></a></span> I mean... it is normal that, as a security researcher, when you find a security bug, you contact the upstream vendor, and can expect that to result in the issue being handled appropriately (for example, because the project notifies their downstreams about the issue, or because downstreams generally pick up all patches fast, or because propagation of fixes is ensured through a mechanism like CVEs).</p><p>To my knowledge, there is no such mechanism between Linux and most distros, unless the distro just always ships the latest stable kernel; I think that is a process issue, not the security researcher's fault.</p><p>When I report Linux kernel security bugs, I, too, just send the bug report to security@kernel.org and the maintainers, not to the third-party linux-distros list.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jann/statuses/116502484744138301</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jann/statuses/116502484744138301</guid><dc:creator><![CDATA[jann@infosec.exchange]]></dc:creator><pubDate>Sat, 02 May 2026 01:53:59 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 22:44:56 GMT]]></title><description><![CDATA[<a href="https://mastodon.social/@alexanderkjall">@alexanderkjall@mastodon.social</a> They even have time to obfuscate and minimize that exploit code, which makes it very hard to understand.<br /><br />As if "732 bytes" means anything.<br /><br />Surely the best way to create a proof-of-concept exploit to share their understanding with the world? /s]]></description><link>https://board.circlewithadot.net/post/https://nya.one/notes/alr2elez2bqw1rv1</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://nya.one/notes/alr2elez2bqw1rv1</guid><dc:creator><![CDATA[orca@nya.one]]></dc:creator><pubDate>Fri, 01 May 2026 22:44:56 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 22:03:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/fun%40berkeley.edu.pl">@<span>fun</span></a></span> <span><a href="/user/noisytoot%40berkeley.edu.pl">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall">@<span>alexanderkjall</span></a></span> the reason is marketing, not technical</p><p>"we are so good because we need very few bytes to achieve this massive thing"</p>]]></description><link>https://board.circlewithadot.net/post/https://hsnl.social/users/eloy/statuses/116501577681046945</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hsnl.social/users/eloy/statuses/116501577681046945</guid><dc:creator><![CDATA[eloy@hsnl.social]]></dc:creator><pubDate>Fri, 01 May 2026 22:03:19 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:54:07 GMT]]></title><description><![CDATA[<span><a href="/user/noisytoot%40berkeley.edu.pl" rel="ugc">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> it's not like you'll be running the exploit on some microcontroller with 16K of SRAM]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/86de1c3c-a53b-46b0-b736-e0a6bcccaedc</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/86de1c3c-a53b-46b0-b736-e0a6bcccaedc</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:54:07 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:53:27 GMT]]></title><description><![CDATA[<span><a href="/user/noisytoot%40berkeley.edu.pl" rel="ugc">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> it's just not serious]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/19ebbbde-6693-4f29-bb3b-4949e1729038</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/19ebbbde-6693-4f29-bb3b-4949e1729038</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:53:27 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:41:41 GMT]]></title><description><![CDATA[<span><a href="/user/fun%40berkeley.edu.pl" rel="ugc">@<span>fun</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> both of those are for minification: if it used descriptive variable names and didn't compress the payload it would have been longer than 732 bytes]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/54cf2633-a177-4044-8eb1-e0c0668c19b8</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/54cf2633-a177-4044-8eb1-e0c0668c19b8</guid><dc:creator><![CDATA[noisytoot@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:41:41 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:40:31 GMT]]></title><description><![CDATA[<span><a href="https://infosec.exchange/@LabanSkoller" rel="ugc">@<span>LabanSkoller</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> they waited a month after reporting to the Linux kernel security team, they did not report to distros<br /><br />Debian at least was quite clearly unprepared given that it took a day to get fixed in trixie and only just got fixed in bookworm (between when I last checked earlier today and now)]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/664bf15c-65cc-4087-9320-b91a3259ecc4</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/664bf15c-65cc-4087-9320-b91a3259ecc4</guid><dc:creator><![CDATA[noisytoot@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:40:31 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:39:20 GMT]]></title><description><![CDATA[<span><a href="/user/noisytoot%40berkeley.edu.pl" rel="ugc">@<span>noisytoot</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> it's also obfuscated IMO. Why need to zlib.decompress ? Can't you give us the data itself without compression?<br />A bunch of variables also have quite meaningless names. It really does scream a lot like obfuscation.]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/836dada7-5e9f-4505-bd71-18543b3e30c4</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/836dada7-5e9f-4505-bd71-18543b3e30c4</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:39:20 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:37:36 GMT]]></title><description><![CDATA[<span><a href="/user/simonzerafa%40infosec.exchange" rel="ugc">@<span>simonzerafa</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> the Linux kernel security team did not tell distros]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/2a03d65a-c5c1-47c9-9fdf-90c8f8234f32</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/2a03d65a-c5c1-47c9-9fdf-90c8f8234f32</guid><dc:creator><![CDATA[noisytoot@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:37:36 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:36:51 GMT]]></title><description><![CDATA[<span><a href="/user/fun%40berkeley.edu.pl" rel="ugc">@<span>fun</span></a></span> <span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> It's minified rather than obfuscated, I think they did that just so they could say it was only 732 bytes.<br /><br />It's also likely that they just asked an LLM to minify it, given that the whole article was so obviously AI-generated and not even proofread (it originally claimed to have been tested on RHEL 14.3, which does not exist)]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/ccc7eb93-fdab-473b-ae3a-972e9f60928c</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/ccc7eb93-fdab-473b-ae3a-972e9f60928c</guid><dc:creator><![CDATA[noisytoot@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:36:51 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:32:12 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@alexanderkjall" rel="nofollow noopener">@<span>alexanderkjall</span></a></span> let's say how it is Greg didn't put it into backports and no one could be arsed to look at it by themselfes as it is, in deed, work.</p><p>Maybe get mad at Herbert (who commited the kernel fix patch) for not telling the distribution security list?</p><p>Anyways, the result is a massive PR event for Xinit/theori and a bad day for Distro security teams and IT Security people all over the world (oh well at least most of you should  be geting payed a nice premium for working at May 1st). </p><p>I guess learning from it would be better then finger pointing but who am I to tell you all how to do your jobs?</p><p>I'm retired. My local machines with public services sit fully proxied behind a BSD machine. The only person with shell access (from my LAN only) is me.</p><p>If the Hyperscaler guys don't pay people to monitor CVEs and do their own classification well <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3ff.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--skin-tone-6" style="height:23px;width:auto;vertical-align:middle" title="🏿" alt="🏿" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2640.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--female_sign" style="height:23px;width:auto;vertical-align:middle" title="♀" alt="♀" />️<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3ff.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--skin-tone-6" style="height:23px;width:auto;vertical-align:middle" title="🏿" alt="🏿" />‍<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2640.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--female_sign" style="height:23px;width:auto;vertical-align:middle" title="♀" alt="♀" />️</p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/TheOneDoc/statuses/116501455371942511</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/TheOneDoc/statuses/116501455371942511</guid><dc:creator><![CDATA[theonedoc@tech.lgbt]]></dc:creator><pubDate>Fri, 01 May 2026 21:32:12 GMT</pubDate></item><item><title><![CDATA[Reply to Today I have spent way too much time handling the https:&#x2F;&#x2F;copy.fail situation #copyfail on Fri, 01 May 2026 21:12:10 GMT]]></title><description><![CDATA[<span><a href="https://mastodon.social/@alexanderkjall" rel="ugc">@<span>alexanderkjall</span></a></span> they also had time to obfuscate their exploit.]]></description><link>https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/46dc93da-b00f-47c5-9929-0e70089d69a1</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://berkeley.edu.pl/objects/46dc93da-b00f-47c5-9929-0e70089d69a1</guid><dc:creator><![CDATA[fun@berkeley.edu.pl]]></dc:creator><pubDate>Fri, 01 May 2026 21:12:10 GMT</pubDate></item></channel></rss>