Sensitive content
Head to squarespace.com/thelinuxexperi… to save 10% off your first purchase of a website or domain using code thelinuxexperiment
Grab a brand new laptop or desktop running Linux: tuxedocomputers.com/en#
👏 SUPPORT THE CHANNEL:
Get access to:
- a Daily Linux News show
- a weekly patroncast for more personal thoughts
- polls on the next topics I cover,
- your name in the credits
YouTube: youtube.com/@thelinuxexp/join
Patreon: patreon.com/thelinuxexperiment
Or, you can donate whatever you want:
paypal.me/thelinuxexp
Liberapay: liberapay.com/TheLinuxExperime…
👕 GET TLE MERCH
Support the channel AND get cool new gear: the-linux-experiment.creator-s…
🎙️ LINUX AND OPEN SOURCE NEWS PODCAST:
Listen to the latest Linux and open source news, with more in depth coverage, and ad-free! podcast.thelinuxexp.com
🏆 FOLLOW ME ELSEWHERE:
Website: thelinuxexp.com
Mastodon: mastodon.social/web/@thelinuxE…
Pixelfed: pixelfed.social/TLENick
PeerTube: tilvids.com/c/thelinuxexperime…
Discord: discord.gg/mdnHftjkja
Timecodes:
0:00 Intro
0:41 Sponsor: SquareSpace
01:45 App Verification and security
04:36 Distro packages aren't really safer
06:46 Sandboxing: no silver bullet
09:07 Distro dependencies are better?
13:07 It's your responsibility to check
14:50 Sponsor: Tuxedo Computers
15:43 Support the channel
Verified apps are an implicit guarantee that this thing is as the developer intended. What app verification isn't, is a guarantee that the package you're downloading is safe, or has no security problems.
If the repo has been hacked, if one of the maintainers for the app is malicious, then the official package will also contain that code.
The security argument will often be used to push people towards distro packages instead of flatpaks and snaps, but this is also not really how things work.
The general view of distro packages is that they can be safer, because there's a trusted maintainer that will create the package, and thus can detect any unwanted change, backdoor, or problem, and prevent you from getting the infected or buggy version of the package.
This is not really the case though.
Log4J, the recent SSH vulnerability, the XZ backdoor, and basically every CVE ever discovered points to the fact that maintainers DO NOT do security reviews on most packages they build. That's not what is expected of them either. A lot of maintainers aren't developers and couldn't conduct these audits in the first place.
unixdigest.com/articles/how-se…
flameeyes.blog/2022/02/15/on-t…
Another big misconception is around the sandbox for Flatpaks and snaps. A sandbox basically just means that the app you're running has a system of permissions that limits what the app can do, and how it can interact with the system. It CAN be more secure than not having a sandbox, but it doesn't mean it IS always more secure.
Another example of the sandbox not doing anything to protect the user is with the recent scam crypto apps on the snap store: these WERE sandboxed, because they scammed you through a web view, a website basically.
Another common misconception around packages is how dependencies work. You'll often read that distro packages use the system dependencies, and thus use less disk space, and are more secure, because you know that the library the app relies upon is updated by your distro, compared to a flatpak, snap or AppImage, where the dev might have bundled a dependency on their own, and never bothered to update it.
First, you CAN check which versions of dependencies the package comes with. A flatpak is open, you can see how it's built. Second, distro packages aren't always up to date either: just because it's a shared library doesn't mean it has all the latest security fixes.
This example will be clearer: MariaDB got a security update in 2021 in November. While Arch and Artix updated things the same day, Debian took 3 months to apply it, and Alpine took 4. Same goes for fixed linux kernel versions: when your distro is locked to a specific kernel version, it's been factually proven that this version becomes more and more buggy and vulnerable over time, as maintainers simply don't apply every fix, and don't backport everything. For example, the current RHEL 8.8 kernel had more then 4500 bugs open that have fixes in later kernel releases.
unixdigest.com/articles/how-se…
ciq.com/blog/new-research-the-…
debian.org/devel/wnpp/orphaned…
The older a Linux vendor kernel gets, the more unfixed bugs and security vulnerabilities it is likely to have. New research by CIQ engineers Ronnie Sahlberg, Jonathan Maple, and Jeremy Allison shows…CIQ
Last week at the U.N. General Assembly, before Israel attacked Iran, the U.K. ambassador's written explanation of her vote on a Gaza ceasefire suggested Starmer and Lammy are terrified. By Craig Murray CraigMurray.org.Consortium News
“…taking them out is LONG overdue. There should be no US "nation building" after it's done.”
Can’t have one without the other ¯\_(ツ)_/¯
as night follows day, first regime change, then (occupied) nation-building.
Same predictable results. Same inevitable blowback.
Tale as old as time.
8658; Ungarische Justiz besteht auf Fortsetzung des Prozesses gegen Maja T.
8658; „Wir finden immer eine Lösung": Putin erzählte, wie im Unionsstaat Probleme gelöst werden
8658; Irans Außenministerium bestellt Schweizer Botschafter wegen Trumps Drohungen ein
Der Unionsstaat wird alles hinkriegen. So antwortete der russische Präsident Wladimir Putin auf die Frage der Generaldirektorin der Belarussischen Telegraphenagentur Irina Akulowitsch, die zum Gespräch mit den Leitern führender Massenmedien in Sankt …Belarussische Telegraphenagentur
Palestinians in Gaza are watching the skies as missiles fall on Tel Aviv instead of them. While many think Israel can be defeated, others are left frustrated that Iran did not intervene and come to Gaza’s aid sooner.Tareq S. Hajjaj (Mondoweiss)
over_clox likes this.
rumble.com/v6uzrs9-how-the-eu-…
Content managed by ContentSafe.co
SHOW NOTES AND COMMENTS: https://corbettreport.com/how-the-eu-manufactures-misinformation/ Dr Norman Lewis is a writer, speaker and consultant on innovation and technology and a visiting research fellRumble
Iran’s supreme leader rejected Trump’s demands for “unconditional surrender” and warned that direct involvement from the US would result in “irreparable damage”Rachel Blevins
pal likes this.
The United States has intervened in 128 elections since 1946 to shape political outcomes in their own interests.
"NO WAR WITH IRAN: US veteran Josephine Guilbeau bravely calls on active duty members to push back against war with Iran and expresses how this war is for ..."
Ça sonne québecois, Guilbeau... (trouvé ça sur FB)
Nanook likes this.
reshared this
Don't know if this is legit, but if it is, it will come out sooner or later so I'm not going to try to figure it out. Just thought it was interesting. If it is real, it's a bombshell, but with AI voice mimicry you just never know.
EXCLUSIVE: Virginia Giuffre’s ‘Deadman’s Switch’ Released: “I Have Been Murdered - This is the REAL Epstein List”
x.com/PastorBobJ11071/status/1…
everything is fake and gay reshared this.
By: Andrew S FENWAY PARK – Concessions workers at the world’s oldest baseball stadium have decided resoundingly to strike for the first time in their 113-year history.Deputy Managing Editor (Working Mass)
A court has ruled Ontario must pay for a penis-sparing vaginoplasty for a person who identifies as neither fully female nor fully maleSharon Kirkey (National Post)
The swift interrogation of the MTA by the newly formed Special Commission on Antisemitism marked an escalation of deceitful, manipulative tactics and state repression.Deputy Managing Editor (Working Mass)
Not a criminal? A fighter for Democracy in Hong Kong? Holder of a Master's Degree? Legally and faithfully following the asylum process?
Doesn't matter. No one - not Chao Zhou, not even citizens - are safe from Trump's masked Gestapo, just filling up the boxcars any way they can to meet Stephen Miller's quotas.
blockclubchicago.org/2025/06/1…
Chao Zhou was arrested after a hearing in his asylum case, said his roommate, Liam Kincaid. "He got taken for doing the right thing," Kincaid said.Molly DeVore (Block Club Chicago)
A new kind of war has just been normalised through global responses to Israeli aggression: threshold war, in which nuclear states conduct wars of aggression against almost-nuclear opponents out of fear that the latter will obtain weapons that reshape geopolitical power balances, while the potential targets of such aggression are incentivised to rush towards acquiring these weapons to avoid the very threat of such aggressive actions.
Also being normalised: attacks on nuclear facilities.
theconversation.com/iran-israe…
Strikes on nuclear facilities in Iran may increase Tehran’s belief that attaining nuclear weapons is key to establishing a deterrence to regime change.The Conversation
Nanook likes this.
reshared this
BEIRUT — In condemnation of the Zionist regime’s aggression against Iran, and in solidarity with its people, armed forces, and leaders, the “Civil Campaign to Support Palestine and the Issues of the Nation” held its weekly meeting at the Iranian emba…Tehran Times
Websites Are Tracking You via Browser Fingerprinting
Link: engineering.tamu.edu/news/2025…
Discussion: news.ycombinator.com/item?id=4…
New research provides first evidence of the use of browser fingerprints for online tracking.engineering.tamu.edu
i am so embarrassed that i didn't know tons of our corporations got #reparations from #iraq no joke, at the 10-minute mark. but the whole video is good even though you've probably already the 1,000,000 reasons why this premise of this war is absurd.
Nanook likes this.
Middle East Monitor
Warning: Undefined variable $sm_desc in /www/wwwroot/middleeastmonitor.com/wp-content/themes/memouk/header.php on line 159
...
Show HN: Unregistry – "docker push" directly to servers without a registry
Link: github.com/psviderski/unregist…
Discussion: news.ycombinator.com/item?id=4…
Push docker images directly to remote servers without an external registry - psviderski/unregistryGitHub
We are joined by Francesca Albanese to talk about the genocide and efforts to end it.An international lawyer, Albanese has served since May 2022 as the Unite...YouTube
The immigrant from El Salvador, who built a mass following on social media through his work documenting ICE raids, will now have to fight in immigration court for his right to remain in the country and ward off deportation.
amren.com/news/2025/06/hispani…
If all of the third world died tomorrow, (a) nothing would be worse and (b) no one would notice.
The law applies even to journalists.Henry Wolff (American Renaissance)
Thursday, 12 June 2025. The Economic Freedom Fighters (EFF) extends our condolences and sympathies to the families and nations affected by the tragic crash ofeffonline.org
Aleksandr Ivanov, head of the Officers Union for International Security, believes it's all about putting pressure on sovereign African nationsOdysee
A former National Intelligence Officer for Cyber under President Trump and Joe Biden has come forward with explosive allegations: the CIA and Office of the Director of National Intelligence (ODNI) deliberately buried evidence of Chinese Com…Jim Hᴏft (Where Hope Finally Made a Comeback)
HeyLiberty 🗽🇺🇸 MAGA Bloodbath🩸 reshared this.
This story originally appeared on VigilantFox.com and was republished with permission.Vigilant Fox (Where Hope Finally Made a Comeback)
HeyLiberty 🗽🇺🇸 MAGA Bloodbath🩸 reshared this.
The plaintiffs' goal in forum shopping is to launch their suit in a district where they are more likely to draw a sympathetic judge.Ben Weingarten (The Federalist)
TEHRAN (Tasnim) – Israeli authorities are actively suppressing reports of mounting casualties from ongoing Iranian missile attacks, as independent and foreign sources estimate the number of injured and dead to be in the hundreds.Tasnim News Agency
Llevo unas semanas usando la IA como herramienta de programación en mis proyectos, he aprendido a manejar los agentes de IA que son un paso más en la evolución de la inteligencia artificial; parecidos al agente Smith de Matrix, los agentes son modelos de IA que pueden tomar decisiones por ellos mismos, evaluar resultados y actuar en consecuencia, llegando incluso a autocorregirse.
Con ayuda de los agentes se pueden crear proyectos de software desde cero con unas simples órdenes, basándonos en un código con buenas prácticas y/o seguridad. Algo a lo que creo que ningún programador llegará por muchos años de experiencia que tenga. El discurso negacionista de la IA se irá diluyendo conforme se adapten los trabajos a esta herramienta, o se corre el riesgo de ser un parado digital más.
Hoy han cambiado las políticas de uso de GitHub Copilot, y ya no será ilimitado como hasta ahora, todo lo bueno se acaba. Mientras tanto me ha dado tiempo a refactorizar proyectos, crear temas y plugins de wordpress, empezar nuevos proyectos como ringnet.cloud o comenzar a implementar un kernel desde cero en rust basado en Linux. Las posibilidades son infinitas si esta herramienta sabe usarse correctamente, no solo ahorrará trabajo sino que lo potenciará con una alta calidad y eso depende de nosotros. Saludos 👋
AI agents are software systems that use AI to pursue goals and complete tasks on behalf of users. Learn more with Google Cloud.Google Cloud
Latvia's Rihards Kols strives to make George W. Bush fashionable again.The Electronic Intifada
The intifada in Los Angeles, Austin, Philadelphia, New York, Boston, and even Omaha is the sequel to the summer of George Floyd.Nathan Stone (The Federalist)
Fitting song for today’s war-like climate.
World Party - Ship Of FoolsFrom the album Private RevolutionReleased: March 1987℗ 2009 Seaviewhttp://itunes.apple.com/gb/album/private-revolution/id337201421...YouTube
For the sake of urgency I’m going to talk in direct and bold terms about the targeting of Tulsi Gabbard.Sundance (The Last Refuge)
“The American people have no interest in sending service-members to fight another forever war in the Middle East", says Senator Tim Kaine.Monitoring Desk (DAWN.COM)
i switched mobile carriers and the new one has a voice AI assistant. the voice AI was actually better than the human pajeet i talked to. the jeet was completely bullshitting me and just talking out their ass, had no idea how to configure the access point manually for their mobile service and just basically pretended to do some technical bull crap on their end, put me on hold a few times, then didn't solve my problem
the AI at least got me pointed in the right direction, even though it gave me bad info.
eventually i figured it out from their web docs.
dorumon likes this.
didn't i just see any new sandman season announced though?
I feel like we have to be able to separate artists' bad behavior from our evaluation of the quality of their work.
Maybe there's a time limit? Maybe they have to be dead so they can't benefit from their work being sold.
Are there any non problematic artists/creators from 500 years ago who we nevertheless find their work product valuable to society today? What about science? Especially medicine with all the body snatching.
Neil Gaiman is almost certainly a sex pest based on all the women reporting. So I get not wanting to give him money. He hopefully gets it, too.
I like the suggestion of piracy as an approach...
I genuinely do not understand people who have deep fried opinions about Signal needing a goddamn phone number in 2025.
Many privacy nerds were outraged when you needed to give out a phone number to other people in order to talk with them. I was one of those nerds. They fixed that with the usernames rollout.
As a mobile phone app, Signal uses your phone number to bootstrap your enrollment into the protocol. This is literally the path of least resistance as an SMS replacement app, for most users.
If you want to know whether Signal can obtain enough metadata to target users that have enrolled, the answer is complicated.
The way profiles are encrypted, and how sealed sender works, makes any targeting seem infeasible. (Your profile key rotates, at mininum, when you block someone.)
Signal currently does not have IP addresses, etc. stored. If this changes in the future, it will not be retroactive. If you're worried about that, Molly boasts Tor support. Maybe that's fine. I haven't audited Molly, and won't.
more concerned about the fact that I have to have a google or apple account even to use it
the Pigeon client from Punkt worked around that, but it's constantly broken in other ways, so
until Signal gets over itself and releases a proper desktop client that doesn't required a linked corporate surveillance device, it might as well not exist
I'm on the side of the Iranians, I always side with anyone that goes up against Israel, even if it means Americans are going to get killed.
I don't care anymore about stupid brainwashed American morons, they have the internet in front of them, 24/7 and chose to look at porn and play video games instead of educating themselves. They deserve to die in the Middle Eastern meatgrinder.
Russia's northern rivers will be connected to the Northern Sea Route (NSR) to ensure easier access for commodity producers, Russian Transport Minister Roman Starovoit said on Wednesday.Sputnik International
Those who cheered on the latter murder should now be examining their consciences.
The historical record is very clear: in politics, violence begets violence. This story is only beginning and it may not end well for America.
See details about the recent shootings.
Nobody's cheering a CEO murder, they're cheering a symbolic win AGAINST the health insurance industry, which preys on poor Americans.
And nobody's cheering a Democrat politician murder, they're cheering a symbolic win FOR the party that preys on poor Americans.
Following his June 10 meetings, Chinese Foreign Minister Wang Yi met with his counterparts from South Africa, Burkina Faso, Niger, Guinea-Bissau, the Republic of the Congo, the Democratic Republic of the Congo, Ghana, Nigeria, Ethiopia and Djibouti t…Friends of Socialist China
You can follow us in other languages. Visit our website for more information wordsmith.social/protestation/…
Our socials: fediverse.blog/~/ActaPopuli/fo…
Wayne Allyn Root:
God, Trump, MAGA and Israel. Why Tucker Carlson is Dead Wrong This Time
On top of all the barbarism that #Israel is engaging in in #Gaza and now in #Iran, here's some news that you don't hear about:
english.palinfo.com/news/2025/…
"Israeli occupation forces (#IOF) demolished multiple residential buildings on Tuesday in the Syrian town of Al-Hamidiyah, located in the northern countryside of #Quneitra near the occupied Golan Heights."
The fault of the residents is that their homes are close to a newly established military base.
benda reshared this.
Kurginyan: Everything the USSR was destroyed for turned out to be a lie Rossa Primavera News from RussiaAvis Krane (Rossa Primavera International News)
Images available to use for free, with the relevant image Weapons consultancy and lobby firm, Eagle Strategic Consulting Ltd, has been permanently shut down following repeated actions by Palestine Action. […]bluehost (Palestine Action)
Nanook
in reply to The Linux Experiment • •