Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #237388 > unrolled thread
| Started by | Charlie Gibbs <cgibbs@surfnaked.ca> |
|---|---|
| First post | 2021-07-14 17:40 +0200 |
| Last post | 2021-07-15 00:30 +0200 |
| Articles | 20 on this page of 63 — 23 participants |
Back to article view | Back to linux.debian.user
Re: MDs & Dentists Charlie Gibbs <cgibbs@surfnaked.ca> - 2021-07-14 17:40 +0200
Re: MDs & Dentists Jude DaShiell <jdashiel@panix.com> - 2021-07-14 20:30 +0200
Re: MDs & Dentists John Hasler <john@sugarbit.com> - 2021-07-14 21:30 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200
Re: MDs & Dentists ellanios82 <ellanios82@gmail.com> - 2021-07-14 21:50 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-14 22:00 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:40 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 01:00 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 01:40 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 02:40 +0200
Re: MDs & Dentists Gene Heskett <gheskett@shentel.net> - 2021-07-15 03:20 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:00 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 04:00 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:10 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200
Re: MDs & Dentists jeremy ardley <jeremy@ardley.org> - 2021-07-15 01:10 +0200
Re: MDs & Dentists jeremy ardley <jeremy@ardley.org> - 2021-07-15 02:30 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:00 +0200
Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-15 03:50 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 04:00 +0200
Re: MDs & Dentists ellanios82 <ellanios82@gmail.com> - 2021-07-15 09:50 +0200
Re: MDs & Dentists Jeremy Ardley <jeremy@ardley.org> - 2021-07-15 10:10 +0200
Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 10:10 +0200
Re: MDs & Dentists Joe <joe@jretrading.com> - 2021-07-15 11:40 +0200
Re: MDs & Dentists <tomas@tuxteam.de> - 2021-07-15 12:30 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-15 08:50 +0200
Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-20 17:40 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 10:20 +0200
Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 17:00 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 17:40 +0200
Re: MDs & Dentists Dan Ritter <dsr@randomstring.org> - 2021-07-21 18:00 +0200
Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 15:40 +0200
Re: MDs & Dentists "Andrew M.A. Cater" <amacater@einval.com> - 2021-08-01 16:00 +0200
Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 16:00 +0200
Re: MDs & Dentists rhkramer@gmail.com - 2021-08-01 18:30 +0200
Re: MDs & Dentists "Andrew M.A. Cater" <amacater@einval.com> - 2021-08-01 19:10 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:30 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:50 +0200
Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:00 +0200
Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:00 +0200
Re: MDs & Dentists Dan Ritter <dsr@randomstring.org> - 2021-08-01 18:00 +0200
Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 15:50 +0200
Hard to understand, being clear [ was Re: MDs & Dentists] Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:40 +0200
Re: Hard to understand, being clear [ was Re: MDs & Dentists] Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:40 +0200
Re: Hard to understand, being clear [ was Re: MDs & Dentists] Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 16:00 +0200
Re: MDs & Dentists Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-07-21 18:20 +0200
Re: MDs & Dentists "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-07-21 18:40 +0200
Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 19:10 +0200
Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-21 19:40 +0200
Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 20:20 +0200
Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-21 21:50 +0200
Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 23:50 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-21 19:20 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 19:40 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 19:30 +0200
Re: MDs & Dentists Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-07-21 22:40 +0200
Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 20:40 +0200
Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 21:10 +0200
Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 22:30 +0200
Re: MDs & Dentists Richard Hector <richard@walnut.gen.nz> - 2021-07-21 21:20 +0200
Re: MDs & Dentists Michael Lange <klappnase@freenet.de> - 2021-07-15 13:10 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 15:40 +0200
Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
| From | ellanios82 <ellanios82@gmail.com> |
|---|---|
| Date | 2021-07-15 09:50 +0200 |
| Message-ID | <CB4i5-2pg-1@gated-at.bofh.it> |
| In reply to | #237406 |
On 7/15/21 2:03 AM, jeremy ardley wrote: > suggesting Windows is certified for any risk of life application!? > > It has a huge spectrum of vulnerabilities .... - believe wikipedia had mention : 100% of world's super-computers run on Linux .... rgds .
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-07-15 10:10 +0200 |
| Message-ID | <CB4Br-2Lk-1@gated-at.bofh.it> |
| In reply to | #237424 |
[Multipart message — attachments visible in raw view] — view raw
On 15/7/21 4:00 pm, Weaver wrote: > On 15-07-2021 17:48, ellanios82 wrote: >> On 7/15/21 2:03 AM, jeremy ardley wrote: >>> suggesting Windows is certified for any risk of life application!? >>> >>> It has a huge spectrum of vulnerabilities >> .... >> >> - believe wikipedia had mention : 100% of world's super-computers run on Linux > https://top500.org/statistics/list/ > Cheers! > > Harry > I'm not sure how they differentiate Centos and RHEL from Linux, but yeah there doesn't seem to be much Windows in the space. Also no Debian? Or is that in the 'Linux' fold, with Ubuntu sufficiently down-market to get it's own mentions? -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Weaver <weaver@riseup.net> |
|---|---|
| Date | 2021-07-15 10:10 +0200 |
| Message-ID | <CB4Br-2Lk-3@gated-at.bofh.it> |
| In reply to | #237424 |
On 15-07-2021 17:48, ellanios82 wrote: > On 7/15/21 2:03 AM, jeremy ardley wrote: >> suggesting Windows is certified for any risk of life application!? >> >> It has a huge spectrum of vulnerabilities > > .... > > - believe wikipedia had mention : 100% of world's super-computers run on Linux https://top500.org/statistics/list/ Cheers! Harry -- `When injustice becomes law, resistance becomes duty' -- Thomas Jefferson
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2021-07-15 11:40 +0200 |
| Message-ID | <CB5QR-3pb-1@gated-at.bofh.it> |
| In reply to | #237406 |
On Thu, 15 Jul 2021 07:03:18 +0800 jeremy ardley <jeremy@ardley.org> wrote: > You can't be seriously suggesting Windows is certified for any risk > of life application!? > > It has a huge spectrum of vulnerabilities and a constant stream of > zero day exploits for both the O/S Yes, but most of them were placed there by Microsoft for the benefit of the US government, and can be instantly removed when discovered (and replaced by an alternative). -- Joe
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-07-15 12:30 +0200 |
| Message-ID | <CB6MV-41o-1@gated-at.bofh.it> |
| In reply to | #237427 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Jul 15, 2021 at 10:27:25AM +0100, Joe wrote: > On Thu, 15 Jul 2021 07:03:18 +0800 > jeremy ardley <jeremy@ardley.org> wrote: > > > > You can't be seriously suggesting Windows is certified for any risk > > of life application!? > > > > It has a huge spectrum of vulnerabilities and a constant stream of > > zero day exploits for both the O/S > > Yes, but most of them were placed there by Microsoft for the benefit of > the US government, and can be instantly removed when discovered (and > replaced by an alternative). Wrong. They just want you to believe that, so that you come across as a conspiracy theorist and people stop taking you seriously. It's tuttles all the way down! (tongue-in-cheek ;-P - tomás
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2021-07-15 08:50 +0200 |
| Message-ID | <CB3m1-1My-3@gated-at.bofh.it> |
| In reply to | #237401 |
On Wed, Jul 14, 2021 at 06:26:58PM -0400, Polyna-Maude Racicot-Summerside wrote: > Him > > On 2021-07-14 3:42 p.m., ellanios82 wrote: > > On 7/14/21 9:27 PM, Jude DaShiell wrote: > >> Doctors and Dentists run windows as the base for all of their practice > >> software. I don't know of any linux software that could replace that > >> software either. Could it be some software house would be able to get > >> linux versions available and make some money? > > > > - at one stage needed windows stuff : ran on Virtual-Box : perfect !! > > > > > That's the usual "geek non-sense" answer. > > Can you tell me one big advantage of using Linux in a medical practice ? Sure, I can name two such advantages. You cannot catch a ransomware cryptolocker using Linux on a desktop, it's definitely Windows-only kind of software. In fact, any FOSS OS has this advantage, unless you're using Wine (software). Also, you can ensure that your patients' data won't be uploaded to M$ or Apple, but that can be considered a common practice these days. Reco
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2021-07-20 17:40 +0200 |
| Message-ID | <CD00F-1XX-3@gated-at.bofh.it> |
| In reply to | #237421 |
On Thu, 15 Jul 2021 09:46:59 +0300 Reco <recoverym4n@enotuniq.net> wrote: ... > You cannot catch a ransomware cryptolocker using Linux on a desktop, Of course you can, although it's certainly much less likely than when using Windows. > it's definitely Windows-only kind of software. In fact, any FOSS OS has > this advantage, unless you're using Wine (software). It's definitely not Windows-only, although it is (at this point) still mostly Windows: https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/ https://phoenixnap.com/blog/linux-ransomware https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/ Celejar
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2021-07-21 10:20 +0200 |
| Message-ID | <CDfCp-3bn-1@gated-at.bofh.it> |
| In reply to | #237547 |
Hi. On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote: > On Thu, 15 Jul 2021 09:46:59 +0300 > Reco <recoverym4n@enotuniq.net> wrote: > > ... > > > You cannot catch a ransomware cryptolocker using Linux on a desktop, > > Of course you can, although it's certainly much less likely than when > using Windows. > > > it's definitely Windows-only kind of software. In fact, any FOSS OS has > > this advantage, unless you're using Wine (software). > > It's definitely not Windows-only, although it is (at this point) still > mostly Windows: I'm not arguing with that, but links you're providing fail to illustrate your point. > https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/ Requires Java to be installed. A rare case on a Linux *desktop*. > https://phoenixnap.com/blog/linux-ransomware Quote: The ransomware is human-operated, so threat actors need time to compromise a network, steal credentials, and spread across devices. > https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack Quote 1: Unlike Windows ransomware variants which spread via email or maladvertising, Linux ransomware infection relies on vulnerability exploitation. Quote 2: Linux ransomware exploits either unpatched system vulnerabilities or flaws in a service, such as a web server or email server, to obtain access to a target system and compromise files. For instance, the infamous Lilocked ransomware exploits out-of-date versions of the Exim message transfer agent to gain a foothold in a target environment. Rex, another dangerous strain of Linux ransomware, uses vulnerability scanners specific to Drupal, WordPress, Magento, Kerner, Airos, Exagrid, and Jetspeed to detect SQL injection vulnerabilities that can be exploited to gain admin credentials. > https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/ Quote: RansomEXX is what security researchers call a "big-game hunter" or "human-operated ransomware." Conclusion: So, unless your Linux *desktop* is a target of an "attack" - your desktop is safe. Third link also shows us that if one runs an Internet-facing website or MTA - one should better know what they're doing. It's true that the security history of Exim, Wordpress and Drupal is far from being flawless (I'm not familiar with other CMSes mentioned at that article, I assume they're no better in this regard). And now, let's compare the scenario above to the usual "a user opens a specially crafted M$ Word document" and "user clicks on an innocent-looking link". To me, the difference is obvious, especially considering the original point of this topic. Reco
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2021-07-21 17:00 +0200 |
| Message-ID | <CDlRw-6JH-13@gated-at.bofh.it> |
| In reply to | #237564 |
On Wed, 21 Jul 2021 11:16:46 +0300 Reco <recoverym4n@enotuniq.net> wrote: > Hi. > > On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote: > > On Thu, 15 Jul 2021 09:46:59 +0300 > > Reco <recoverym4n@enotuniq.net> wrote: > > > > ... > > > > > You cannot catch a ransomware cryptolocker using Linux on a desktop, > > > > Of course you can, although it's certainly much less likely than when > > using Windows. > > > > > it's definitely Windows-only kind of software. In fact, any FOSS OS has > > > this advantage, unless you're using Wine (software). > > > > It's definitely not Windows-only, although it is (at this point) still > > mostly Windows: > > I'm not arguing with that, but links you're providing fail to illustrate > your point. > > > https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/ > > Requires Java to be installed. A rare case on a Linux *desktop*. Rare? I don't have statistics, but on one of my Linux desktops, I do some development work for Android, using IntelliJ IDEA / Android Studio, which depend on at least some Java components. I don't know if I have enough Java installed to be susceptible to the malware in question ;) > > https://phoenixnap.com/blog/linux-ransomware > > Quote: > The ransomware is human-operated, so threat actors need time to > compromise a network, steal credentials, and spread across devices. > > > https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack > > Quote 1: > Unlike Windows ransomware variants which spread via email or > maladvertising, Linux ransomware infection relies on vulnerability > exploitation. > > Quote 2: > Linux ransomware exploits either unpatched system vulnerabilities or > flaws in a service, such as a web server or email server, to obtain > access to a target system and compromise files. For instance, the > infamous Lilocked ransomware exploits out-of-date versions of the Exim > message transfer agent to gain a foothold in a target environment. Rex, > another dangerous strain of Linux ransomware, uses vulnerability > scanners specific to Drupal, WordPress, Magento, Kerner, Airos, Exagrid, > and Jetspeed to detect SQL injection vulnerabilities that can be > exploited to gain admin credentials. > > > https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/ > > Quote: > RansomEXX is what security researchers call a "big-game hunter" or > "human-operated ransomware." > > > Conclusion: > So, unless your Linux *desktop* is a target of an "attack" - your > desktop is safe. Third link also shows us that if one runs an > Internet-facing website or MTA - one should better know what they're > doing. It's true that the security history of Exim, Wordpress and Drupal > is far from being flawless (I'm not familiar with other CMSes mentioned > at that article, I assume they're no better in this regard). > > > And now, let's compare the scenario above to the usual "a user opens a > specially crafted M$ Word document" and "user clicks on an > innocent-looking link". > > To me, the difference is obvious, especially considering the original > point of this topic. Fair enough - but I see no reason why in principle desktop Linux will remain immune from ransomware. Even if Linux word processors are safer than their Windows counterparts, browsers are just full of vulnerabilities, so why couldn't ransomware get in that way? Celejar
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2021-07-21 17:40 +0200 |
| Message-ID | <CDmud-7bz-9@gated-at.bofh.it> |
| In reply to | #237576 |
On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > On Wed, 21 Jul 2021 11:16:46 +0300 > Reco <recoverym4n@enotuniq.net> wrote: > > > Hi. > > > > On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote: > > > On Thu, 15 Jul 2021 09:46:59 +0300 > > > Reco <recoverym4n@enotuniq.net> wrote: > > > > > > ... > > > > > > > You cannot catch a ransomware cryptolocker using Linux on a desktop, > > > > > > Of course you can, although it's certainly much less likely than when > > > using Windows. > > > > > > > it's definitely Windows-only kind of software. In fact, any FOSS OS has > > > > this advantage, unless you're using Wine (software). > > > > > > It's definitely not Windows-only, although it is (at this point) still > > > mostly Windows: > > > > I'm not arguing with that, but links you're providing fail to illustrate > > your point. > > > > > https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/ > > > > Requires Java to be installed. A rare case on a Linux *desktop*. > > Rare? I don't have statistics, but on one of my Linux desktops, I do > some development work for Android, using IntelliJ IDEA / Android Studio, > which depend on at least some Java components. Numbers show that I was incorrect. Let's call it "unlikely" instead of "rare". Let the popcon graphs speak for themselves: https://qa.debian.org/popcon.php?package=firefox-esr vs https://qa.debian.org/popcon.php?package=openjdk-11 I agree with you that one should uninstall Java unless it's needed. After all, they at Oracle always find something to fix in Java security every three months, and this goes on for last ten years. > I don't know if I have > enough Java installed to be susceptible to the malware in question ;) Famous Java's slogan "you write it once and run it everywhere" is an exaggeration, to put it lightly. Chances are, you don't have that exact minor update of Oracle JRE that this malware actually needs. > Fair enough - but I see no reason why in principle desktop Linux will > remain immune from ransomware. It won't by itself, of course. One sure way to beat ransomware is to take immutable backups (i.e. unmodifiable by host during and after the backup is taken), and as recent history shows us - ransomware victims apparently do not use this approach. Another sure way is to forbid running executables downloaded from random Internet sites, but no thanks to appimage, flatpak, snap, and Go Linux desktop goes straight into Windows desktop direction. And again, as recent history shows us - ransomware victims apparently do not use this approach too. Currently a Linux desktop is better in this regard, but I agree that it may not remain the same. > Even if Linux word processors are safer than their Windows counterparts, Last time I ran Libreoffice I had that distinct feeling I'm running a Java program. You know - long startup, eating memory like no tomorrow, trying to write useless junk at least to four different places at my filesystems, and eating the unhealthy amounts of CPU time in the process. I know that Libreoffice is written in C++, but the code quality of it is definitely left to be desired. At least then the thing crashes (it did, several times) it produces a standard core dump, not some unreadable stack trace and a heapdump. In retrospect, maybe feeding Libreoffice Draw that 800-pages PDF was not the best of ideas, but no free software tool comes close to the capabilities of Libreoffice in editing PDFs, and I really needed that PDF to be modified (mass-replacing embedded fonts, to be specific). On the other hand, Windows counterparts are typical enterprisey software written by generations of overseas workers with the code quality (or rather the lack of) that's expected from enterprisey software. My opinion on this - both are bad. Lireoffice is better being free software, of course, but that does not make it secure by definition. > browsers are just full of vulnerabilities, True. Every version of Chromium and Firefox fixes at least one. Most of said vulnerabilities do cannot be used to get Remote Code Execution (RCE) though. Which leaves us with "random download" scenario, which I've discussed above. > so why couldn't ransomware get in that way? It could. In a lack of a proper execution environment (be it JRE, flatpak, snap or whatever) - what should it do next? Wait for a user to execute it? Reco
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2021-07-21 18:00 +0200 |
| Message-ID | <CDmNz-7ih-3@gated-at.bofh.it> |
| In reply to | #237578 |
Reco wrote: > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > Numbers show that I was incorrect. Let's call it "unlikely" instead of > "rare". Let the popcon graphs speak for themselves: > > https://qa.debian.org/popcon.php?package=firefox-esr > vs > https://qa.debian.org/popcon.php?package=openjdk-11 Standard reminder: popcon vastly over-represents individually-owned laptops and desktops over servers and corporately-owned anything. In this case, individuals are sometimes infected with ransomware by happenstance, but corporates are actually targets. > It won't by itself, of course. One sure way to beat ransomware is to > take immutable backups (i.e. unmodifiable by host during and after the > backup is taken), and as recent history shows us - ransomware victims > apparently do not use this approach. Yes indeed. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Gunnar Gervin <dofeelok@gmail.com> |
|---|---|
| Date | 2021-08-01 15:40 +0200 |
| Message-ID | <CHjR7-6wM-9@gated-at.bofh.it> |
| In reply to | #237579 |
[Multipart message — attachments visible in raw view] — view raw
Security. Rarely discussed in Linux(?).. Was scammed recently; naive me let a man w/Bad accent take over my laptop to 'help refund BTC' & make me pay 100$. Because of that &/or me in Synaptic bloating (2 many) packages, which led to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't find key file" messages (yes, all 3 !). After trying "all" workarounds, I installed another, more simple Linux distro, built up a new setup of relevant programs to build VM, containers, websites, Debian iso image, & CHEF. Now Chef asks me to give URL to continue setting up a VM etc. Plz advise &/or help to do it/this. BR, GEG On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote: > Reco wrote: > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > Numbers show that I was incorrect. Let's call it "unlikely" instead of > > "rare". Let the popcon graphs speak for themselves: > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > vs > > https://qa.debian.org/popcon.php?package=openjdk-11 > > Standard reminder: popcon vastly over-represents > individually-owned laptops and desktops over servers and > corporately-owned anything. > > In this case, individuals are sometimes infected with ransomware > by happenstance, but corporates are actually targets. > > > It won't by itself, of course. One sure way to beat ransomware is to > > take immutable backups (i.e. unmodifiable by host during and after the > > backup is taken), and as recent history shows us - ransomware victims > > apparently do not use this approach. > > Yes indeed. > > -dsr- > >
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-08-01 16:00 +0200 |
| Message-ID | <CHkau-6Ef-5@gated-at.bofh.it> |
| In reply to | #237975 |
On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > Security. > Rarely discussed in Linux(?).. > Was scammed recently; naive me let a man w/Bad accent take over my laptop > to 'help refund BTC' & make me pay 100$. > Because of that &/or me in Synaptic bloating (2 many) packages, which led > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't > find key file" messages (yes, all 3 !). > After trying "all" workarounds, I installed another, more simple Linux > distro, built up a new setup of relevant programs to build VM, containers, > websites, Debian iso image, & CHEF. Which distro - are you still using Debian? If not, we can't really help you. Although many of us have run other distributions in the past, all of the Debian/Ubuntu derivatives do something slightly different - we can only really help with generic Debian things. If we offer help with any other distribution, it's only ever best efforts - Debian derivatives have their own support infrastructure. > Now Chef asks me to give URL to continue setting up a VM etc. > Plz advise &/or help to do it/this. It may not be relevant but the chef and chef-zero packages in Buster appear to no longer be packaged in Bullseye - the upcoming release due in two weeks. Ask on a Chef list, perhaps? > BR, > GEG All best, as ever, Andrew Cater > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote: > > > Reco wrote: > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > Numbers show that I was incorrect. Let's call it "unlikely" instead of > > > "rare". Let the popcon graphs speak for themselves: > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > > vs > > > https://qa.debian.org/popcon.php?package=openjdk-11 > > > > Standard reminder: popcon vastly over-represents > > individually-owned laptops and desktops over servers and > > corporately-owned anything. > > > > In this case, individuals are sometimes infected with ransomware > > by happenstance, but corporates are actually targets. > > > > > It won't by itself, of course. One sure way to beat ransomware is to > > > take immutable backups (i.e. unmodifiable by host during and after the > > > backup is taken), and as recent history shows us - ransomware victims > > > apparently do not use this approach. > > > > Yes indeed. > > > > -dsr- > > > >
[toc] | [prev] | [next] | [standalone]
| From | Gunnar Gervin <dofeelok@gmail.com> |
|---|---|
| Date | 2021-08-01 16:00 +0200 |
| Message-ID | <CHkau-6Ef-7@gated-at.bofh.it> |
| In reply to | #237978 |
[Multipart message — attachments visible in raw view] — view raw
I expected that answer. Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam Trying to set up Debian in a VM in another Linux distro, with Chef So I cannot really see irrelevance of my question?? Like Nobody here knows how to fix this one, cos it's slightly out of D. politics? Geg On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com> wrote: > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > Security. > > Rarely discussed in Linux(?).. > > Was scammed recently; naive me let a man w/Bad accent take over my laptop > > to 'help refund BTC' & make me pay 100$. > > Because of that &/or me in Synaptic bloating (2 many) packages, which led > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't > > find key file" messages (yes, all 3 !). > > After trying "all" workarounds, I installed another, more simple Linux > > distro, built up a new setup of relevant programs to build VM, > containers, > > websites, Debian iso image, & CHEF. > > Which distro - are you still using Debian? > > If not, we can't really help you. Although many of us have run other > distributions in the past, all of the Debian/Ubuntu derivatives do > something slightly different - we can only really help with generic > Debian things. If we offer help with any other distribution, it's > only ever best efforts - Debian derivatives have their own support > infrastructure. > > > Now Chef asks me to give URL to continue setting up a VM etc. > > Plz advise &/or help to do it/this. > > It may not be relevant but the chef and chef-zero packages in Buster > appear > to no longer be packaged in Bullseye - the upcoming release due in two > weeks. > > Ask on a Chef list, perhaps? > > > BR, > > GEG > > All best, as ever, > > Andrew Cater > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote: > > > > > Reco wrote: > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > Numbers show that I was incorrect. Let's call it "unlikely" instead > of > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > > > vs > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > > > > > > Standard reminder: popcon vastly over-represents > > > individually-owned laptops and desktops over servers and > > > corporately-owned anything. > > > > > > In this case, individuals are sometimes infected with ransomware > > > by happenstance, but corporates are actually targets. > > > > > > > It won't by itself, of course. One sure way to beat ransomware is to > > > > take immutable backups (i.e. unmodifiable by host during and after > the > > > > backup is taken), and as recent history shows us - ransomware victims > > > > apparently do not use this approach. > > > > > > Yes indeed. > > > > > > -dsr- > > > > > > > >
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-08-01 18:30 +0200 |
| Message-ID | <CHmvD-8g1-1@gated-at.bofh.it> |
| In reply to | #237979 |
On Sunday, August 01, 2021 09:58:48 AM Gunnar Gervin wrote: > So I cannot really see irrelevance > of my question?? > Like Nobody here knows how to fix this one, cos it's > slightly out of D. Someone who uses Debian, maybe even someone who subscribes to this list might know how to fix your problem, but I think at least part of the point that Andrew was making is that it is a catch as catch can situation -- somebody might be able to help, but the people that really concentrate on taking care of Debian probably can't as they are not familiar with your distro or Chef or both. > politics? No, and most of us here probably don't like the suggestion.
[toc] | [prev] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-08-01 19:10 +0200 |
| Message-ID | <CHn8l-hU-5@gated-at.bofh.it> |
| In reply to | #237979 |
On Sun, Aug 01, 2021 at 04:58:48PM +0300, Gunnar Gervin wrote: > I expected that answer. > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam > Trying to set up Debian in a VM in another Linux distro, with Chef > So I cannot really see irrelevance > of my question?? Like Nobody here knows how to fix this one, cos it's > slightly out of D. politics? > Geg So: do the simple things. 1.) If you want to keep Windows - use this Windows machine or another to produce a Windows .iso for installation using Microsoft's media creation tool to put it onto a USB flash disk. Use Debian boot media to delete the whole of Windows: reinstall Windows using your new USB flash disk after removing all existing partitions on the hard disk. If you get the chance to partition the blank disk - set aside space for a Linux install. If not, use Windows partitioning tools to shrink Windows to allow space for a Linux distribution. Install Windows using UEFI boot if at all possible. 2.) Install Debian - and only Debian on the empty space. Debian should find the Windows partition and include it into the Grub boot menu. If you choose to install any other Linux, we may or may not be able to help you as previously written. Saying this because I've a machine in the room on which I did just that. Save yourself a lot of XYZ problems by doing two things slowly and carefully. Why you think that someone from another Linux distribution should have scammed you / been attacking your Windows partition is your own affair. In most instances, a clean reinstall of an operating system will help to see them away significantly and good patching and updating is also a must. . You may need to consider about what makes you, especially, special enough for someone else to try and hack you and, objectively, whether facts support this. All the very best, as ever, Andrew Cater > > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com> wrote: > > > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > > Security. > > > Rarely discussed in Linux(?).. > > > Was scammed recently; naive me let a man w/Bad accent take over my laptop > > > to 'help refund BTC' & make me pay 100$. > > > Because of that &/or me in Synaptic bloating (2 many) packages, which led > > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't > > > find key file" messages (yes, all 3 !). > > > After trying "all" workarounds, I installed another, more simple Linux > > > distro, built up a new setup of relevant programs to build VM, > > containers, > > > websites, Debian iso image, & CHEF. > > > > Which distro - are you still using Debian? > > > > If not, we can't really help you. Although many of us have run other > > distributions in the past, all of the Debian/Ubuntu derivatives do > > something slightly different - we can only really help with generic > > Debian things. If we offer help with any other distribution, it's > > only ever best efforts - Debian derivatives have their own support > > infrastructure. > > > > > Now Chef asks me to give URL to continue setting up a VM etc. > > > Plz advise &/or help to do it/this. > > > > It may not be relevant but the chef and chef-zero packages in Buster > > appear > > to no longer be packaged in Bullseye - the upcoming release due in two > > weeks. > > > > Ask on a Chef list, perhaps? > > > > > BR, > > > GEG > > > > All best, as ever, > > > > Andrew Cater > > > > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote: > > > > > > > Reco wrote: > > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > > Numbers show that I was incorrect. Let's call it "unlikely" instead > > of > > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > > > > vs > > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > > > > > > > > Standard reminder: popcon vastly over-represents > > > > individually-owned laptops and desktops over servers and > > > > corporately-owned anything. > > > > > > > > In this case, individuals are sometimes infected with ransomware > > > > by happenstance, but corporates are actually targets. > > > > > > > > > It won't by itself, of course. One sure way to beat ransomware is to > > > > > take immutable backups (i.e. unmodifiable by host during and after > > the > > > > > backup is taken), and as recent history shows us - ransomware victims > > > > > apparently do not use this approach. > > > > > > > > Yes indeed. > > > > > > > > -dsr- > > > > > > > > > > > >
[toc] | [prev] | [next] | [standalone]
| From | Polyna-Maude Racicot-Summerside <debian@polynamaude.com> |
|---|---|
| Date | 2021-08-01 22:30 +0200 |
| Message-ID | <CHqfT-2dE-9@gated-at.bofh.it> |
| In reply to | #237979 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On 2021-08-01 9:58 a.m., Gunnar Gervin wrote: > I expected that answer. > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam > Trying to set up Debian in a VM in another Linux distro, with Chef > So I cannot really see irrelevance > of my question?? Like Nobody here knows how to fix this one, cos it's > slightly out of D. politics? There's no such thing as "Debian Politics" (or what would D.Politics mean, could be useful to put a bit more effort in making your message intelligible for others). What there's present here is a community of user that revolve around the Debian Linux distribution, centered over the Debian distribution. So if you run Distribution XYZ and are trying to get Debian running on a VM, we can help you with the Debian part, not much with setting up the VM or what goes with the underlying OS. Not because of some "politics" or because we are stubborn or stillborn, but because we probably have not much experience with the underlying system. We have interest in Debian and this is what we all use mostly. We've exchanged (me and many others) at least two dozen of messages in the last weeks or so. And still, we don't have a clue if you are running Debian. But, we have gave you chances and tools to straight this out. https://lists.debian.org/debian-user/2021/07/msg01216.html *Here's a short part...* Rather than a back and forth on whether Gunnar's description of the machine is correct, it might be more productive to suggest running some simple, definitive commands like: $ ls /sys/firmware/ acpi dmi efi memmap $ It either includes "efi" (UEFI-booted), or it doesn't (BIOS-booted). $ uname -a Linux ajax 4.19.0-17-amd64 #1 SMP Debian 4.19.194-3 (2021-07-18) x86_64 GNU/Linux $ The kernel architecture is given (x86_64 here). The "arch" command is terser. i686/i586/i486 would indicate an i386 architecture. $ grep address /proc/cpuinfo address sizes : 36 bits physical, 48 bits virtual $ Anything over 32 indicates 64-bit capability, whether or not it is being exploited. A 32-bit processor will only yield: address sizes : 32 bits physical, 32 bits virtual *And here goes another one...* https://lists.debian.org/debian-user/2021/07/msg01240.html Of course I haven't. I see scattered posts (only some) from Gunnar that don't seem to make a lot of sense, followed up by discussion and argument, much of which could be avoided by getting some facts into the posts. Hence my suggestion (snipped) to run $ ls /sys/firmware/ $ uname -a $ grep address /proc/cpuinfo and clarify what type of machine (machines?) is being discussed. Perhaps it's reckless not to have suggested a command proving it's a Debian system. In all of Gunnar's posts, I think I have only seen one report of actual output posted, and I have no idea what the origin of that was, viz: # UNCONFIGURED FSTAB FOR BASE SYSTEM overlay / overlay rw 0 0 tmpfs /tmp tmpfs nosuid,nodev 0 0 /dev/sda1 /mnt/sda1 EXT2 nosuid,nodev,nofail,x-gvfs-show 0 0 /dev/sda3 /mnt/sda3 EXT2 nosuid,nodev,nofail,x-gvfs-show,noauto,x-udisks-auth 0 0 /dev/sda2 none swap sw,x-udisks-auth,noauto 0 0 *Now sorry...* Maybe English is not your main language or there's something else but I have to agree with the writter of this last message. Some your post don't make much sense and take more energy to understand the text themselves than they require to really find any type of computing problem. What is easy to understand for yourself may not be the case for others. In the long term, you'll be the one facing penalties for this as people will just get tired and start ignoring. No one's got obligation here and we are all volunteer doing so for the pleasure of helping others. Even myself, when I take to explain things like I'm doing now. And like I did for the "top posting". Here's some tip... I'll show you some hard to understand in the following post... > Geg > > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com > <mailto:amacater@einval.com>> wrote: > > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > Security. > > Rarely discussed in Linux(?).. > > Was scammed recently; naive me let a man w/Bad accent take over my > laptop > > to 'help refund BTC' & make me pay 100$. > > Because of that &/or me in Synaptic bloating (2 many) packages, > which led > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & > "can't > > find key file" messages (yes, all 3 !). > > After trying "all" workarounds, I installed another, more simple Linux > > distro, built up a new setup of relevant programs to build VM, > containers, > > websites, Debian iso image, & CHEF. > > Which distro - are you still using Debian? > > If not, we can't really help you. Although many of us have run other > distributions in the past, all of the Debian/Ubuntu derivatives do > something slightly different - we can only really help with generic > Debian things. If we offer help with any other distribution, it's > only ever best efforts - Debian derivatives have their own support > infrastructure. > > > Now Chef asks me to give URL to continue setting up a VM etc. > > Plz advise &/or help to do it/this. > > It may not be relevant but the chef and chef-zero packages in Buster > appear > to no longer be packaged in Bullseye - the upcoming release due in > two weeks. > > Ask on a Chef list, perhaps? > > > BR, > > GEG > > All best, as ever, > > Andrew Cater > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org > <mailto:dsr@randomstring.org>> wrote: > > > > > Reco wrote: > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > Numbers show that I was incorrect. Let's call it "unlikely" > instead of > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > <https://qa.debian.org/popcon.php?package=firefox-esr> > > > > vs > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > <https://qa.debian.org/popcon.php?package=openjdk-11> > > > > > > Standard reminder: popcon vastly over-represents > > > individually-owned laptops and desktops over servers and > > > corporately-owned anything. > > > > > > In this case, individuals are sometimes infected with ransomware > > > by happenstance, but corporates are actually targets. > > > > > > > It won't by itself, of course. One sure way to beat ransomware > is to > > > > take immutable backups (i.e. unmodifiable by host during and > after the > > > > backup is taken), and as recent history shows us - ransomware > victims > > > > apparently do not use this approach. > > > > > > Yes indeed. > > > > > > -dsr- > > > > > > > -- Polyna-Maude R.-Summerside -Be smart, Be wise, Support opensource development
[toc] | [prev] | [next] | [standalone]
| From | Polyna-Maude Racicot-Summerside <debian@polynamaude.com> |
|---|---|
| Date | 2021-08-01 22:50 +0200 |
| Message-ID | <CHqzf-2lp-7@gated-at.bofh.it> |
| In reply to | #237979 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On 2021-08-01 9:58 a.m., Gunnar Gervin wrote: > I expected that answer. > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam > Trying to set up Debian in a VM in another Linux distro, with Chef > So I cannot really see irrelevance > of my question?? Like Nobody here knows how to fix this one, cos it's > slightly out of D. politics? > Geg > Not because of politics. Because you don't seem to take help when it's given to you. At least 3 persons (different ones) have gave you tips on how to properly identify the OS you are running over (not only Linux but the distribution itself) and been trying to find out what you are using. Including one person that wasn't sure if your laptop description was because it was running Bullseye and wanted to be added to the list of computer supported or something else. None got any answer. So this may be the start of the whole problem. Now if you have a belief that people are trying to scam you off, them I can assure you of two things. You probably aren't a interesting target unless you are a bank or some big corporation. And if it would be the case, you wouldn't be interacting this way on the mailing list. If you got offer by someone you don't know to pay 100$ and get refunded for BTC, then you are mostly the first person to blame. This trick has been around for a very long time, and it's quite public notoriety that the first thing to do is to hangup on those person. If you come here for help and put a doubt behind every answer that people will give you. Then it could be good to ask yourself why you came here first ? Maybe you never answered to the two other users who asked you to type some command on the shell so we can know what type of system you run, this way we'd know if it's Debian (as we don't seem to be sure yet) and what architecture too. Because you talked about ex-Macbook, using BIOS, etc... pretty unclear. Nobody can undo what happened in the past. But if you need help, the first thing will be some genuine cooperation from yourself. Or going out to your local computer store and paying someone to do the job. And surely stop using some acronym only you may understand. It's not a run against the clock. Take time to write complete word and people will maybe have more interest in helping too. Why shall we make effort if you don't do so. If all the energy we have is devoted trying to decrypt some message then there won't be any left for the computer helping part of the job. > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com > <mailto:amacater@einval.com>> wrote: > > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > Security. > > Rarely discussed in Linux(?).. > > Was scammed recently; naive me let a man w/Bad accent take over my > laptop > > to 'help refund BTC' & make me pay 100$. > > Because of that &/or me in Synaptic bloating (2 many) packages, > which led > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & > "can't *lt fin broken packages* ? lt ? let ? > > find key file" messages (yes, all 3 !). find key file messages ? *yes, all 3!* what 3 ? > > After trying "all" workarounds, I installed another, more simple Linux > > distro, built up a new setup of relevant programs to build VM, > containers, > > websites, Debian iso image, & CHEF. > > Which distro - are you still using Debian? Again this question ? How many time will it take before getting a bit of cooperation !? > > If not, we can't really help you. Although many of us have run other > distributions in the past, all of the Debian/Ubuntu derivatives do > something slightly different - we can only really help with generic > Debian things. If we offer help with any other distribution, it's > only ever best efforts - Debian derivatives have their own support > infrastructure. > > > Now Chef asks me to give URL to continue setting up a VM etc. > > Plz advise &/or help to do it/this. > > It may not be relevant but the chef and chef-zero packages in Buster > appear > to no longer be packaged in Bullseye - the upcoming release due in > two weeks. > > Ask on a Chef list, perhaps? > A good shot would be to ask on a mailing list specific to this particular software (or a forum). > > BR, > > GEG > > All best, as ever, > > Andrew Cater > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org > <mailto:dsr@randomstring.org>> wrote: > > > > > Reco wrote: > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > Numbers show that I was incorrect. Let's call it "unlikely" > instead of > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > <https://qa.debian.org/popcon.php?package=firefox-esr> > > > > vs > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > <https://qa.debian.org/popcon.php?package=openjdk-11> > > > > > > Standard reminder: popcon vastly over-represents > > > individually-owned laptops and desktops over servers and > > > corporately-owned anything. > > > > > > In this case, individuals are sometimes infected with ransomware > > > by happenstance, but corporates are actually targets. > > > > > > > It won't by itself, of course. One sure way to beat ransomware > is to > > > > take immutable backups (i.e. unmodifiable by host during and > after the > > > > backup is taken), and as recent history shows us - ransomware > victims > > > > apparently do not use this approach. > > > > > > Yes indeed. > > > > > > -dsr- > > > > > > > -- Polyna-Maude R.-Summerside -Be smart, Be wise, Support opensource development
[toc] | [prev] | [next] | [standalone]
| From | Gunnar Gervin <dofeelok@gmail.com> |
|---|---|
| Date | 2021-08-02 15:00 +0200 |
| Message-ID | <CHFHX-3H9-3@gated-at.bofh.it> |
| In reply to | #237997 |
[Multipart message — attachments visible in raw view] — view raw
I see. It's now a dual boot; Debian 10.9 i386 32b Buster (installed from netinst dvd), in which Synaptic crashed 80%. Tried reinstall with above dvd, it was rejected, not sure why. So I restored the machine with a DVD with Linux Mint, dual boot; Debian above is 1/2 , Mint is 1/2 & set up Synaptic in Linux Mint, it works fine, just like in Debian. It is originally a Macbook 2.1, Intel, 2Core, 160GB, 3GB RAM, Version 3.0 Vesa Bios, 64 bit(!). Seems to use a lot 32b software Now I look for alternative VM builders to Chef. Synaptic programs seems same in Mint as in Debian. Debian works better in this machine than LMDE4. Mint runs better so far, than both Debian and Lmde4. But that's probably cos of my total lack of knowledge of anything incl. doing Backups(!). I took backups in Mac, not Linux. Geg On Sun, 1 Aug 2021, 23:46 Polyna-Maude Racicot-Summerside, < debian@polynamaude.com> wrote: > Hi, > > On 2021-08-01 9:58 a.m., Gunnar Gervin wrote: > > I expected that answer. > > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam > > Trying to set up Debian in a VM in another Linux distro, with Chef > > So I cannot really see irrelevance > > of my question?? Like Nobody here knows how to fix this one, cos it's > > slightly out of D. politics? > > Geg > > > > Not because of politics. > Because you don't seem to take help when it's given to you. > > At least 3 persons (different ones) have gave you tips on how to > properly identify the OS you are running over (not only Linux but the > distribution itself) and been trying to find out what you are using. > > Including one person that wasn't sure if your laptop description was > because it was running Bullseye and wanted to be added to the list of > computer supported or something else. > > None got any answer. > > So this may be the start of the whole problem. > > Now if you have a belief that people are trying to scam you off, them I > can assure you of two things. > > You probably aren't a interesting target unless you are a bank or some > big corporation. And if it would be the case, you wouldn't be > interacting this way on the mailing list. > > If you got offer by someone you don't know to pay 100$ and get refunded > for BTC, then you are mostly the first person to blame. This trick has > been around for a very long time, and it's quite public notoriety that > the first thing to do is to hangup on those person. > > If you come here for help and put a doubt behind every answer that > people will give you. Then it could be good to ask yourself why you came > here first ? > > Maybe you never answered to the two other users who asked you to type > some command on the shell so we can know what type of system you run, > this way we'd know if it's Debian (as we don't seem to be sure yet) and > what architecture too. Because you talked about ex-Macbook, using BIOS, > etc... pretty unclear. > > Nobody can undo what happened in the past. But if you need help, the > first thing will be some genuine cooperation from yourself. Or going out > to your local computer store and paying someone to do the job. > > And surely stop using some acronym only you may understand. It's not a > run against the clock. Take time to write complete word and people will > maybe have more interest in helping too. > > Why shall we make effort if you don't do so. If all the energy we have > is devoted trying to decrypt some message then there won't be any left > for the computer helping part of the job. > > > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com > > <mailto:amacater@einval.com>> wrote: > > > > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > > Security. > > > Rarely discussed in Linux(?).. > > > Was scammed recently; naive me let a man w/Bad accent take over my > > laptop > > > to 'help refund BTC' & make me pay 100$. > > > Because of that &/or me in Synaptic bloating (2 many) packages, > > which led > > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & > > "can't > *lt fin broken packages* ? > lt ? > > let ? > > > > > find key file" messages (yes, all 3 !). > > find key file messages ? > > *yes, all 3!* > > what 3 ? > > > > After trying "all" workarounds, I installed another, more simple > Linux > > > distro, built up a new setup of relevant programs to build VM, > > containers, > > > websites, Debian iso image, & CHEF. > > > > Which distro - are you still using Debian? > > Again this question ? > > How many time will it take before getting a bit of cooperation !? > > > > If not, we can't really help you. Although many of us have run other > > distributions in the past, all of the Debian/Ubuntu derivatives do > > something slightly different - we can only really help with generic > > Debian things. If we offer help with any other distribution, it's > > only ever best efforts - Debian derivatives have their own support > > infrastructure. > > > > > Now Chef asks me to give URL to continue setting up a VM etc. > > > Plz advise &/or help to do it/this. > > > > It may not be relevant but the chef and chef-zero packages in Buster > > appear > > to no longer be packaged in Bullseye - the upcoming release due in > > two weeks. > > > > Ask on a Chef list, perhaps? > > > A good shot would be to ask on a mailing list specific to this > particular software (or a forum). > > > > BR, > > > GEG > > > > All best, as ever, > > > > Andrew Cater > > > > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org > > <mailto:dsr@randomstring.org>> wrote: > > > > > > > Reco wrote: > > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > > Numbers show that I was incorrect. Let's call it "unlikely" > > instead of > > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > <https://qa.debian.org/popcon.php?package=firefox-esr> > > > > > vs > > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > > <https://qa.debian.org/popcon.php?package=openjdk-11> > > > > > > > > Standard reminder: popcon vastly over-represents > > > > individually-owned laptops and desktops over servers and > > > > corporately-owned anything. > > > > > > > > In this case, individuals are sometimes infected with ransomware > > > > by happenstance, but corporates are actually targets. > > > > > > > > > It won't by itself, of course. One sure way to beat ransomware > > is to > > > > > take immutable backups (i.e. unmodifiable by host during and > > after the > > > > > backup is taken), and as recent history shows us - ransomware > > victims > > > > > apparently do not use this approach. > > > > > > > > Yes indeed. > > > > > > > > -dsr- > > > > > > > > > > > > -- > Polyna-Maude R.-Summerside > -Be smart, Be wise, Support opensource development > >
[toc] | [prev] | [next] | [standalone]
| From | Gunnar Gervin <dofeelok@gmail.com> |
|---|---|
| Date | 2021-08-02 15:00 +0200 |
| Message-ID | <CHFHX-3H9-5@gated-at.bofh.it> |
| In reply to | #237997 |
[Multipart message — attachments visible in raw view] — view raw
Scam: Was from outside of this list. This info because someone thought I accused this list. Sorry for the confusion I made. BR, Geg. On Sun, 1 Aug 2021, 23:46 Polyna-Maude Racicot-Summerside, < debian@polynamaude.com> wrote: > Hi, > > On 2021-08-01 9:58 a.m., Gunnar Gervin wrote: > > I expected that answer. > > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam > > Trying to set up Debian in a VM in another Linux distro, with Chef > > So I cannot really see irrelevance > > of my question?? Like Nobody here knows how to fix this one, cos it's > > slightly out of D. politics? > > Geg > > > > Not because of politics. > Because you don't seem to take help when it's given to you. > > At least 3 persons (different ones) have gave you tips on how to > properly identify the OS you are running over (not only Linux but the > distribution itself) and been trying to find out what you are using. > > Including one person that wasn't sure if your laptop description was > because it was running Bullseye and wanted to be added to the list of > computer supported or something else. > > None got any answer. > > So this may be the start of the whole problem. > > Now if you have a belief that people are trying to scam you off, them I > can assure you of two things. > > You probably aren't a interesting target unless you are a bank or some > big corporation. And if it would be the case, you wouldn't be > interacting this way on the mailing list. > > If you got offer by someone you don't know to pay 100$ and get refunded > for BTC, then you are mostly the first person to blame. This trick has > been around for a very long time, and it's quite public notoriety that > the first thing to do is to hangup on those person. > > If you come here for help and put a doubt behind every answer that > people will give you. Then it could be good to ask yourself why you came > here first ? > > Maybe you never answered to the two other users who asked you to type > some command on the shell so we can know what type of system you run, > this way we'd know if it's Debian (as we don't seem to be sure yet) and > what architecture too. Because you talked about ex-Macbook, using BIOS, > etc... pretty unclear. > > Nobody can undo what happened in the past. But if you need help, the > first thing will be some genuine cooperation from yourself. Or going out > to your local computer store and paying someone to do the job. > > And surely stop using some acronym only you may understand. It's not a > run against the clock. Take time to write complete word and people will > maybe have more interest in helping too. > > Why shall we make effort if you don't do so. If all the energy we have > is devoted trying to decrypt some message then there won't be any left > for the computer helping part of the job. > > > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com > > <mailto:amacater@einval.com>> wrote: > > > > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote: > > > Security. > > > Rarely discussed in Linux(?).. > > > Was scammed recently; naive me let a man w/Bad accent take over my > > laptop > > > to 'help refund BTC' & make me pay 100$. > > > Because of that &/or me in Synaptic bloating (2 many) packages, > > which led > > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & > > "can't > *lt fin broken packages* ? > lt ? > > let ? > > > > > find key file" messages (yes, all 3 !). > > find key file messages ? > > *yes, all 3!* > > what 3 ? > > > > After trying "all" workarounds, I installed another, more simple > Linux > > > distro, built up a new setup of relevant programs to build VM, > > containers, > > > websites, Debian iso image, & CHEF. > > > > Which distro - are you still using Debian? > > Again this question ? > > How many time will it take before getting a bit of cooperation !? > > > > If not, we can't really help you. Although many of us have run other > > distributions in the past, all of the Debian/Ubuntu derivatives do > > something slightly different - we can only really help with generic > > Debian things. If we offer help with any other distribution, it's > > only ever best efforts - Debian derivatives have their own support > > infrastructure. > > > > > Now Chef asks me to give URL to continue setting up a VM etc. > > > Plz advise &/or help to do it/this. > > > > It may not be relevant but the chef and chef-zero packages in Buster > > appear > > to no longer be packaged in Bullseye - the upcoming release due in > > two weeks. > > > > Ask on a Chef list, perhaps? > > > A good shot would be to ask on a mailing list specific to this > particular software (or a forum). > > > > BR, > > > GEG > > > > All best, as ever, > > > > Andrew Cater > > > > > > > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org > > <mailto:dsr@randomstring.org>> wrote: > > > > > > > Reco wrote: > > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote: > > > > > Numbers show that I was incorrect. Let's call it "unlikely" > > instead of > > > > > "rare". Let the popcon graphs speak for themselves: > > > > > > > > > > https://qa.debian.org/popcon.php?package=firefox-esr > > <https://qa.debian.org/popcon.php?package=firefox-esr> > > > > > vs > > > > > https://qa.debian.org/popcon.php?package=openjdk-11 > > <https://qa.debian.org/popcon.php?package=openjdk-11> > > > > > > > > Standard reminder: popcon vastly over-represents > > > > individually-owned laptops and desktops over servers and > > > > corporately-owned anything. > > > > > > > > In this case, individuals are sometimes infected with ransomware > > > > by happenstance, but corporates are actually targets. > > > > > > > > > It won't by itself, of course. One sure way to beat ransomware > > is to > > > > > take immutable backups (i.e. unmodifiable by host during and > > after the > > > > > backup is taken), and as recent history shows us - ransomware > > victims > > > > > apparently do not use this approach. > > > > > > > > Yes indeed. > > > > > > > > -dsr- > > > > > > > > > > > > -- > Polyna-Maude R.-Summerside > -Be smart, Be wise, Support opensource development > >
[toc] | [prev] | [next] | [standalone]
Page 2 of 4 — ← Prev page 1 [2] 3 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web