Re: [DNG] Devuan ASCII Live USB security issue

2018-09-26 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, On 27/09/18 06:01, Jaromil wrote: > On Thu, 27 Sep 2018, Andrew McGlashan wrote: > >> I've been using a live USB of Devuan with XFCE, I boot it to RAM >> and then setup my temporary environment from a different LUKS >> encrypted USB. > > have

Re: [DNG] Devuan ASCII Live USB security issue

2018-09-26 Thread fsmithred
On 09/26/2018 01:03 PM, Andrew McGlashan wrote: > > Adding to this problem is the fact that the "devuan" user has, by > default, full SUDO rights without needing any password as well; the > latter is probably easily fixed with an adjusted sudoers file, but the > auto-login is a major security risk

Re: [DNG] Devuan ASCII Live USB security issue

2018-09-26 Thread Jaromil
dear Andrew, On Thu, 27 Sep 2018, Andrew McGlashan wrote: > I've been using a live USB of Devuan with XFCE, I boot it to RAM and > then setup my temporary environment from a different LUKS encrypted USB. have you tried https://heads.dyne.org? is a Devuan derivative based on Beowulf (current te

[DNG] Devuan ASCII Live USB security issue

2018-09-26 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I've been using a live USB of Devuan with XFCE, I boot it to RAM and then setup my temporary environment from a different LUKS encrypted USB. This allows me to keep my data secure and the setup as simple as possible without actually installing

[DNG] Devuan security-tracker update

2018-09-26 Thread leloft
Hi, I am still working towards a Devuanized security-tracker but I have come up against a problem which is blocking further development. One section of the process involves nested loops to update the database with current packages in the devuan repos. However, some of the architectures do not exi

[DNG] Debian Sid -> Devuan Ceres attempt: some issues

2018-09-26 Thread m712
Hi, I recently tried to move my debian sid laptop to devuan ceres. Here's what I did: apt install sysvinit-core reboot apt purge systemd nvim /etc/apt/sources.list (changed to ceres repos with [ allow-insecure=yes ]) apt update apt install devuan-keyring nvim /etc/apt/sources.list

[DNG] DSA Sep26

2018-09-26 Thread leloft
Mon, 24 Sep 2018 15:10:07 +0200 [SECURITY] [DSA 4305-1] strongswan security update Sze Yiu Chau and his team from Purdue University and The University of Iowa found several issues in the gmp plugin for strongSwan, an IKE/IPsec suite. Problems in the parsing and verification of RSA signatures could