Tootfinder

Opt-in global Mastodon full text search. Join the index!

@kubikpixel@chaos.social
2026-05-15 05:35:04

Oh no, please don't tell me again that Linux is now insecure on the net?!
«Linux's Latest Vulnerability Allows Reading Root-Owned Files By Unprivileged Users»
⛓️‍💥 phoronix.com/news/Linux-ssh-ke
⛓️‍💥

@keithp@fosstodon.org
2026-03-18 22:50:38

Today, I learned that emacs can access remote files:
/ssh:<host>:<path>
Why do I feel like I should have known this like thirty years ago?

@grahamperrin@bsd.cafe
2026-02-19 02:10:40

Exosphere:
― aggregated patch and security update reporting
― basic system status across multiple Unix-like hosts via SSH
<exosphere.readthedocs.io/> | <

@ruario@vivaldi.net
2026-05-15 05:46:49

Linux fans, please tell me you have updated your machine for "ssh-keysign-pwn", right… right!?
github.com/0xdeadbeefnetwork/s

@simon_brooke@mastodon.scot
2026-05-05 11:56:46
Content warning: SSH problem!?

Houston, I have a problem.
Today, I cannot connect to anywhere with my desktop machine. #ssh fails with:
Load key "/home/simon/.ssh/id_rsa.pub": error in libcrypto
simon@notary.journeyman.cc: Permission denied (publickey).
It worked fine last night. Nothing has changed in my ~/.ssh directory. `apt update` was run yesterday, but the log does not show any update to ssh o…

@denkbeteiligung@digitalcourage.social
2026-03-14 17:17:28

An alle #Linux #Admins 2-Faktor-Authentifizierung ist ja ein Ding. Macht man das auch für #ssh?

@niqdanger@social.linux.pizza
2026-04-16 22:27:23

Just to add to my insane home networking difficulties, right now I am online, all clients are working / routing to the internet. Can I connect to OPNsense via HTTP or SSH? Nope. The box just ignores me. I can log in locally and all is fine. WTF? I started a radio stream as a "test" and now poking around, some stuff loads, some doesn't, like 1/2 the internet is out. WTF? (again)

@sean@scoat.es
2026-03-14 16:29:03

#Swift Concurrency as a call-out feature makes my inner engineer happy.
(Also, super interesting idea; shared with me by @… )

@ruari@velocipederider.com
2026-05-15 06:03:12

After Copy Fail, Dirty Frag, Fragnesia and now ssh-keysign-pwn in short succession, even I am feeling a little overwhelmed. And I just have a few personal machines.
I cannot for the life of me understand how annoying and draining this must be for sysadmins. You have my sympathies.

@fanf@mendeddrum.org
2026-05-09 14:42:04

from my link log —
Stop MITM on the first SSH connection with cloud-init.
joachimschipper.nl/Stop MITM

@grahamperrin@bsd.cafe
2026-04-16 23:12:51

Connected via ssh?

@nebucatnetzer@social.linux.pizza
2026-04-13 19:33:27

Well that was fun.
I managed to lock myself out of my fileserver (QNAP NAS) after I misconfigured the #Wireguard client.
Luckily there is a short window after reboot where the client isn't connected and I was able to SSH into the server and remove the broken config.
Took me three attempts however.

@thomasfuchs@hachyderm.io
2026-05-09 13:34:18

RE: mastodon.social/@glynmoody/116
FWIW I'm using multiple different VPNs daily for work, for reasons that have nothing to do either age verification or anything else "illegal":
1. My main ISP's connection is brittle and causes dropped data transfers on larger files; a VPN solves this completely
2. I'm using a VPN to manage servers securely (allows me to not have open ports for SSH etc. on the public Internet)
3. When I'm out of the office, a VPN allows me to access my desktop computer, my file server and even to quickly print something.
If they wanted to establish a police state they could just say so.

@ruario@vivaldi.net
2026-05-15 05:47:16

@… Sorry
github.com/0xdeadbeefnetwork/s

@UP8@mastodon.social
2026-03-27 04:29:43

🐍 snakes.run, massively multiplayer Snake over SSH
#programming #software

@jdrm@social.linux.pizza
2026-03-06 13:04:07

I can't see my problem trying to connect from my #9front laptop to an #openSUSE PC via ssh. The ssh command returns a "read1: eof" error.
I regenerate the RSA key with a 4096 bytes size and that isn't the problem. 😞
I can connect from other OS to that computer. …

@ripienaar@devco.social
2026-05-08 09:30:28

This is looks really great boxd.sh

@gwire@mastodon.social
2026-05-11 10:34:05

One of the side-effects of a choice I made more than a decade ago, is that I get informed of new networks that are performing ssh scanning/guessing on one of my servers - because I naively assumed there were a limited number of networks involved (not realising it's mostly hijacked machines, rather than hackers renting VPSes).
Anyway, there's been an uptick in the last few weeks of new networks originating this traffic.

@fanf@mendeddrum.org
2026-02-27 12:42:03

from my link log —
snakes.run: rendering 100M pixels a second over ssh.
eieio.games/blog//blog/secure-
saved 2026-02-26

@gideonstar@mastodon.gideonstar.de
2026-04-26 21:46:36

„Hallo, hier ist der Matrix-Support. Bitte geben Sie ihr SSH-Passwort und/oder ihren SSH-Public-Key sowie ihre IBAN Pin und eine Kopie ihres Personalausweis hier ein, damit Sie weiterhin unseren sicheren Messenger betreiben können.“
Könnte funktionieren.

@azonenberg@ioc.exchange
2026-03-02 06:03:44

Just ran a successful non-interactive build and test cycle of ngscopeclient in a Debian VM with a PCIe passthrough GPU.
Just start the VM from the snapshot, paste a handful of shell commands into a SSH session, and I get this.
Still need to work out how to actually spawn the VM, specify the hash I want to build, shut it down and revert when done, etc.
Took only three and a half minutes on this instance (16GB RAM, 16 vCPU, GTX 1630) which is pretty decent considering there w…

CDash build dashboard showing zero errors and 49 warnings
@thomasfuchs@hachyderm.io
2026-05-06 13:25:34

PSA you can get rid of the annoying OpenSSH "post-quantum" cryptography warning by adding:
WarnWeakCrypto no-pq-kex
to your SSH config (you can do this per host).
Important: the best way is to upgrade server OpenSSH version but that's not always feasible like on servers using LTS Ubuntu etc.

@veit@mastodon.social
2026-04-30 14:10:02

Now elementary-data has also been hit: for just under half a day, a malicious version 0.23.3 was available on PyPI, which had stolen credentials such as SSH keys, AWS login details, API tokens and wallet files. The attack was carried out via a script injection vulnerability in one of the GitHub Actions workflows. Cooldown helps protect against such attacks, as we have described here:

@schachjugend@schach.social
2026-04-01 08:16:35
Content warning: April, April :)

🌍♟️ DEM 2031 goes international!
Zur Feier von 10 Jahren Deutsche Schachjugend e.V. gehen wir neue Wege:
👉 Die DEM 2031 findet erstmals in Ägypten statt!
🏨 Austragungsort: Sweet-Star-Hotel (SSH), Alexandria
🌊 Schach direkt am Meer – mit Pool & (fast) Blick auf die Pyramiden
💸 Das Beste:
👉 Teilnahme ab nur 45€ pro Tag inkl. Vollpension
🛏️ 2000 Betten – keine Ausquartierungen mehr
♟️ Bis zu 700 Teilnehmende im Open
Was sagt ihr – seid ihr dabei…

Fotomontage mit einem Hotel, Pyramiden, Schachbrett und Kamel (KI-generiert)
@michabbb@social.vivaldi.net
2026-03-01 06:40:25

🖥️ Less relevant for server environments using SSH keys – primarily affects desktop users
heise.de/en/news/sudo-rs-shows

@dawid@social.craftknight.com
2026-03-01 22:17:25

Poszło od ręki - niesamowity ten nixos-anywhere... Cały system przekonwertowany od tak, zero USB, żadnego piKVM, nic. Cała konwersja po SSH z partycjonowaniem i postawieniem dosłownie wszystkich serwisów 1-1 co miałem przetestowane na vmce. Jedna komenda, kilka minut i wszystko od A-Z od filesystemu, użytkowników, wszystkich narzędzi, wszystkie serwisy, dosłownie wszystko postawione ot, tak...

Teraz tylko skopiowanie ~7.5TB danych przez pewnie całą noc i po sprawie.

0 Ansiblea, 0…

@jdrm@social.linux.pizza
2026-03-06 18:12:36

- ¿Y qué tal te lo has pasado esta tarde?
- Super bien, he estado depurando conexiones ssh a dos servidores y leyendo código fuente en C para encontrar un problema y lo he arreglado
- ....
- Ke?

@epiceric@mastodon.xyz
2026-04-08 21:29:03

You don't have to leave your Zellij session, or install anything, to share it across CGNAT! All you need to do is run:
```
ssh -R 80:localhost:8082 demo.sandhole.com.br
```
And thanks to Sandhole (sandhole.com.br), you get your own (temporary) HTTPS subdomain with zero config!

A browser running a Zellij session over HTTPS under a subdomain of demo.sandhole.com.br. Across the different panes and tabs, you can see a Neovim editor, the Sandhole logs, and the Zellij share session window.
@azonenberg@ioc.exchange
2026-04-27 08:08:59

Progress! Sorted out a bunch of permissions issues and I'm now able to (over SSH) clone a template VM on the mac mini and launch it.
Now to set up a script to actually run the test suite.
I've written more bash than any other language the last week or so and I don't like it lol. But it had to be done...

@thomasfuchs@hachyderm.io
2026-04-28 00:56:49

Is there a really simple alternative to Teleport?
I only need to sporadically allow ssh sessions to a handful of servers for deployment and maintenance for one or two people.

@tomkalei@machteburch.social
2026-03-12 07:07:46

Ich hatte nicht auf meiner sprichwörtlichen Bingo-Karte, dass die Vermenschlichung der Maschine dadurch passiert, dass claude mich über ssh auf meinem Handy fragt, wie der Beweis weiter geht...
Das ist erschreckend ähnlich zu Nachrichten die ich mir mit Menschen so schicke.

@fanf@mendeddrum.org
2026-02-27 09:42:04

from my link log —
soft-serve: a self-hostable git ssh server for the command line.
github.com/charmbracelet/soft-
saved 2026-02-26

@dawid@social.craftknight.com
2026-03-30 17:39:47
@… I assume you want to use more than 100mb? https://docs.codeberg.org/getting-started/faq/#how-about-private-repositories?

If you have literary ANY VPS on the internet with ssh - you can just `git init --bare` and use that as remote for yo…
@azonenberg@ioc.exchange
2026-04-25 10:08:28

It's 3 in the morning on a Saturday and I'm trying to use SLURM to spawn a batch job on a Linux frontend node, which SSH's into a Windows 11 VM, spawns a msys2 UCRT64 shell, then runs a bash script in it.
Not even the KPDH soundtrack I'm blasting is enough to excise the demons here.

@grahamperrin@bsd.cafe
2026-02-24 19:41:17

sh is not a shell
SSH is not a protocol

@sean@scoat.es
2026-02-22 18:55:00

Okay, I think this thing is ready-enough to tell people about it.
I made a #BBS to watch aircraft near #YUL (#Montreal airport), through my home #ADSB

The yulbbs about screen. It reads:

YULBBS is powered by ADS-BBS
(a pun on the ADS-B system that provides data)

Both were created by Sean Coates: https://seancoates.com

ssh (or telnet): yulbbs.via.sc

It uses Swift, NIO, swift-nio-ssh, and dump1080 on the backend.
The antenna is near CYUL, in Dorval, Quebec, a borough of Montreal.
The whole thing runs on a Raspberry Pi 3 in my office networking closet.
Aircraft data comes from the air, not from the net. Be nice.

(Yes, I know that it's not a …
A screen shot of the “ANSI”/BBS style UI. The main “list” view of air traffic near YUL. It contains a list of featured aircraft, a chart of arrivals/departures, recent activity, and some stats.
The map view, which uses Unicode Braille characters. One plane is departing, another is arriving, and a third is not currently heuristically engaged with the airport but it’s nearby.