sigmoid.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A social space for people researching, working with, or just interested in AI!

Server stats:

588
active users

#elmstreet

0 posts0 participants0 posts today
Dendrobatus Azureus<p>For me reading this post took about 10 minutes since I not only read but I also processed and checked references and I tooted about it immediately</p><p>It is quite sobering to read something this horrific happening in an Open Source project of this magnitude of volume</p><p>This is something you would expect in closed source not open source; it's like a shower with 0° degrees Celsius of water flowing over you 0° in the depth of the coldest Siberian winter</p><p><a href="https://security.opensuse.org/2025/05/07/deepin-desktop-removal.html#2021-02-01-dtkcommon-filedrag-d-bus-service" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.opensuse.org/2025/05/</span><span class="invisible">07/deepin-desktop-removal.html#2021-02-01-dtkcommon-filedrag-d-bus-service</span></a></p><p><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.bsd.cafe/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>
Dendrobatus Azureus<p>This is where the depth of the deception became clear </p><p>&gt;&gt;</p><p>The review of this component was also what led us to the discovery of the deepin-feature-enable whitelisting bypass, since we installed the full Deepin desktop environment for the first time in a long time, which triggered the “license agreement” dialog described above. After finding out about this, we decided that it was time to reassess the overall topic of Deepin in openSUSE based on our long-standing experiences.</p><p>&lt;&lt;<br><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.bsd.cafe/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>
Dendrobatus Azureus<p>This part I screen capped for accentuation </p><p>&gt;&gt;</p><p>2024-08-29: deepin-api-proxy: D-Bus Service</p><p>After a longer time of standstill regarding Deepin reviews, a request for the addition of deepin-api-proxy arrived. This package greeted us with over two dozen D-Bus configuration files. Again, upstream’s description of what the component is supposed to do was very terse. From looking at the implementation we deduced that the proxy component seems to be related to the renaming of interfaces described in the previous section.</p><p>We found a design flaw in the proxy’s design which allowed a local root exploit. You can find the details in a dedicated blog post we published about this not too long ago.</p><p>It is noteworthy that the communication with upstream proved very difficult during the coordinated disclosure process we started for this finding. We did not get timely responses, which nearly led us to a one-sided publication of the report, until upstream finally expressed their wish to follow coordinated disclosure at the very last moment. </p><p>&lt;&lt;</p><p>I now have really seen it all The Good the Bad and the Ugly in Open Source programming </p><p><a href="https://security.opensuse.org/2025/05/07/deepin-desktop-removal.html#2021-02-01-dtkcommon-filedrag-d-bus-service" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.opensuse.org/2025/05/</span><span class="invisible">07/deepin-desktop-removal.html#2021-02-01-dtkcommon-filedrag-d-bus-service</span></a></p><p><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.bsd.cafe/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/WTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WTF</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>
Dendrobatus Azureus<p>More excerpts </p><p>&gt;&gt;</p><p>Sadly the review of deepin-app-services was another chaotic case, one that is actually still unfinished. Even understanding the purpose of this D-Bus service was difficult, because there wasn’t really any design documentation or purpose description of the component. From looking at the D-Bus service implementation, we judged that it is a kind of system wide configuration store for Deepin. Contrary to most other Deepin D-Bus services, this one is not running as root but as a dedicated unprivileged service user.</p><p>&lt;&lt;</p><p>This reads like a horror novel but it's actually happening! Unbelievable how this has harmed a distro with many dedicated users!</p><p><a href="https://security.opensuse.org/2025/05/07/deepin-desktop-removal.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.opensuse.org/2025/05/</span><span class="invisible">07/deepin-desktop-removal.html</span></a></p><p><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/wtf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>wtf</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>
Dendrobatus Azureus<p>The Deepin frightmare </p><p>Excerpt from linked site<br>&gt;&gt;<br>After reviewing the main D-Bus service, we could not help ourselves but call it a security nightmare. The service methods were not only unauthenticated and thus accessible to all users in the system, but the D-Bus configuration file also allowed anybody to own the D-Bus service path on the system bus, which could lead to impersonation of the daemon. Among other issues, the D-Bus service allowed anybody in the system to create arbitrary new UNIX groups, add arbitrary users to arbitrary groups, set arbitrary users’ Samba passwords or overwrite almost any file on the system by invoking mkfs on them as root, leading to data loss and denial-of-service. The daemon did contain some Polkit authentication code, but it was all found in unused code paths; to top it all off, this code used the deprecated UnixProcess Polkit subject in an unsafe way, which would make it vulnerable to race conditions allowing authentication bypass, if it had been used.<br>&lt;&lt;</p><p>¿WTF?</p><p><a href="https://security.opensuse.org/2025/05/07/deepin-desktop-removal.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.opensuse.org/2025/05/</span><span class="invisible">07/deepin-desktop-removal.html</span></a></p><p><a href="https://mastodon.bsd.cafe/tags/openSUSE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSUSE</span></a> <a href="https://mastodon.bsd.cafe/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.bsd.cafe/tags/POSIX" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>POSIX</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <br><a href="https://mastodon.bsd.cafe/tags/Deepin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deepin</span></a> <a href="https://mastodon.bsd.cafe/tags/frightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>frightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/elmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmStreet</span></a></p>
Dendrobatus Azureus<p>Politics had totally changed, instead of having politicians, you only had puppets for the big tech companies: all those puppets did, was make sure that it's companies kept getting more financially powerful, and kept getting even more invasive, as if that were even possible</p><p>I mean they were a literally up your digestive track already, all the way to your spinkster.</p><p>Don't let me talk about flying; it takes you literally 72 hours to book a ticke; 8 hours a day you have to follow those dreadful procedures of which 90% is just ads, to finally get the seat booked with six screens pointed at you only bombarding you with advertisements.</p><p>Trains were even worse; Walls of screens, almost no place to sit, let alone sit comfortably.<br>In busses they left you alone, but what they did, is make the bus almost totally transparent and make sure that all the of the massive screens at the buildings were pointing at you, giving out all your personal information for everyone else to see, including your menstrual cycle, the size of your prostate, and everything else that's supposed to be medically sealed, just to show you walls and walls of advertisements regarding those medical status parameters.</p><p>And do not think that when you're finally at home sleeping, away from your dreadful job, and asleep that you sleep cycle was normal<br>Remember those devices that implanted in you at Birth? Those devices injected at advertisements in your dreams making your sleep horrific and tiring.</p><p>Suicide rates were skyrocketing; it was normal to lose a friend every month who succumbed to suicide because of the horrific carpet bombing advertisements raids. There were more psychiatrists than regular physicians. Funeral parlors were the only places where business was booming for the private sector, owned by fairly regular people. </p><p>Mercedes-Benz almost exclusively made funeral cars because that's what's sold the most and the best and asked for the most, by those who could still afford cars</p><p>/2</p><p><a href="https://mastodon.bsd.cafe/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> <a href="https://mastodon.bsd.cafe/tags/Alphabet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Alphabet</span></a> <a href="https://mastodon.bsd.cafe/tags/Chrome" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Chrome</span></a> <a href="https://mastodon.bsd.cafe/tags/AdBlock" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AdBlock</span></a> <a href="https://mastodon.bsd.cafe/tags/uBlockOrigin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>uBlockOrigin</span></a> <a href="https://mastodon.bsd.cafe/tags/terrible" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>terrible</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Elmstreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Elmstreet</span></a> <a href="https://mastodon.bsd.cafe/tags/WTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WTF</span></a> <a href="https://mastodon.bsd.cafe/tags/replacement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>replacement</span></a> <a href="https://mastodon.bsd.cafe/tags/aftermath" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aftermath</span></a></p>
Dendrobatus Azureus<p>I've just woken up from a horrific IT Nightmare.</p><p>Only commercial companies were providing services on the internet, Open Source did not exist, Linus Torvalds was never born, Netscape has never come into fruition.</p><p>Every website you went to you have to go through 12 pages of advertisements bombarding you with all the flashes all the sounds and even even HTML5 did not exist everything was Flash!</p><p>There are only two browsers available Google Chrome and Microsoft Internet Explorer. Browser extensions were non-existent; everybody went on the internet like a drone and endured the horrific bombardment of advertisements like carpet bombs falling on your mind, as if you were in Vietnam, getting bombarded by The Enemy Flying B-52 fortresses.</p><p>All the Services constantly changed their end-user license agreement, your mobile devices had eight cameras pointed at you and none to the outside world. Those devices also had seven microphones of which the worst was used for you to talk into with your people and Friends, the six others were used to listen to you environment and sent everything outside.</p><p>Tracking devices were planted in your body at Birth, you are constantly itching because of all those devices in your system, giving you skin irritation and making your complexion like that of sandpaper.</p><p>Even going outside in your garden was horrific, micro drones were constantly following you, listening and looking at everything you do, even if you don't have any mobile devices on you.</p><p>Stores were even worse, everything you bought had tracking and tracing, even The Food you ate had tracking, and traces were going to your digestive track all the way to the toilet.</p><p>And while you were sitting there you had to endure advertisements for every time you use the toilet.</p><p>There were 12 financially Rich families on the planet everyone else was economic slave.</p><p>All religions were converted to advertisement bombardment Systems and to subjugation of people to Ads</p><p>^Z</p><p>/1</p><p><a href="https://mastodon.bsd.cafe/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> <a href="https://mastodon.bsd.cafe/tags/Alphabet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Alphabet</span></a> <a href="https://mastodon.bsd.cafe/tags/Chrome" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Chrome</span></a> <a href="https://mastodon.bsd.cafe/tags/AdBlock" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AdBlock</span></a> <a href="https://mastodon.bsd.cafe/tags/uBlockOrigin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>uBlockOrigin</span></a> <a href="https://mastodon.bsd.cafe/tags/terrible" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>terrible</span></a> <a href="https://mastodon.bsd.cafe/tags/nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nightmare</span></a> <a href="https://mastodon.bsd.cafe/tags/Elmstreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Elmstreet</span></a> <a href="https://mastodon.bsd.cafe/tags/WTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WTF</span></a> <a href="https://mastodon.bsd.cafe/tags/replacement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>replacement</span></a> <a href="https://mastodon.bsd.cafe/tags/aftermath" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aftermath</span></a></p>
Juan Lobo<p>Me estoy viendo toda la saga de películas de "Pesadilla en Elm Street" y esta tercera entrega es la que más me ha gustado por ahora, se aprecia un salto en espectacularidad de escenas y calidad de efectos especiales. La escena de la alfombra es lo mejor de la saga (por ahora).</p><p>Y bueno, al igual que en la primera me sorprendió ver a un adolescente Johnny Depp, en esta ha sido curioso toparme con un jovencito Laurence Fishburne, aunque en los créditos aparece como Larry Fishburne.</p><p><a href="https://masto.es/tags/cinemastodon" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cinemastodon</span></a> <a href="https://masto.es/tags/cine" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cine</span></a> <a href="https://masto.es/tags/pelis" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pelis</span></a> <a href="https://masto.es/tags/terror" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>terror</span></a> <a href="https://masto.es/tags/elmstreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>elmstreet</span></a></p>
Radio Azureus<p><span class="h-card" translate="no"><a href="https://mastodon.social/@Polynomial_C" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Polynomial_C</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@madeindex" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>madeindex</span></a></span> a genuine LOL 😂 emmited here</p><p><a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/Clippy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Clippy</span></a> <a href="https://mastodon.social/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> <a href="https://mastodon.social/tags/Nightmare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nightmare</span></a> on <a href="https://mastodon.social/tags/ElmStreet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ElmStreet</span></a> <a href="https://mastodon.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://mastodon.social/tags/ArtificialIntelligence" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ArtificialIntelligence</span></a></p>