Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #237388 > unrolled thread

Re: MDs & Dentists

Started byCharlie Gibbs <cgibbs@surfnaked.ca>
First post2021-07-14 17:40 +0200
Last post2021-07-15 00:30 +0200
Articles 20 on this page of 63 — 23 participants

Back to article view | Back to linux.debian.user


Contents

  Re: MDs & Dentists Charlie Gibbs <cgibbs@surfnaked.ca> - 2021-07-14 17:40 +0200
    Re: MDs & Dentists Jude DaShiell <jdashiel@panix.com> - 2021-07-14 20:30 +0200
      Re: MDs & Dentists John Hasler <john@sugarbit.com> - 2021-07-14 21:30 +0200
        Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200
      Re: MDs & Dentists ellanios82 <ellanios82@gmail.com> - 2021-07-14 21:50 +0200
        Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-14 22:00 +0200
          Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:40 +0200
            Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 01:00 +0200
              Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 01:40 +0200
              Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 02:40 +0200
                Re: MDs & Dentists Gene Heskett <gheskett@shentel.net> - 2021-07-15 03:20 +0200
                Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:00 +0200
                  Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 04:00 +0200
                    Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:10 +0200
        Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200
          Re: MDs & Dentists jeremy ardley <jeremy@ardley.org> - 2021-07-15 01:10 +0200
            Re: MDs & Dentists jeremy ardley <jeremy@ardley.org> - 2021-07-15 02:30 +0200
              Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 04:00 +0200
            Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-15 03:50 +0200
              Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 04:00 +0200
            Re: MDs & Dentists ellanios82 <ellanios82@gmail.com> - 2021-07-15 09:50 +0200
              Re: MDs & Dentists Jeremy Ardley <jeremy@ardley.org> - 2021-07-15 10:10 +0200
              Re: MDs & Dentists Weaver <weaver@riseup.net> - 2021-07-15 10:10 +0200
            Re: MDs & Dentists Joe <joe@jretrading.com> - 2021-07-15 11:40 +0200
              Re: MDs & Dentists <tomas@tuxteam.de> - 2021-07-15 12:30 +0200
          Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-15 08:50 +0200
            Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-20 17:40 +0200
              Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 10:20 +0200
                Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 17:00 +0200
                  Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 17:40 +0200
                    Re: MDs & Dentists Dan Ritter <dsr@randomstring.org> - 2021-07-21 18:00 +0200
                      Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 15:40 +0200
                        Re: MDs & Dentists "Andrew M.A. Cater" <amacater@einval.com> - 2021-08-01 16:00 +0200
                          Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 16:00 +0200
                            Re: MDs & Dentists rhkramer@gmail.com - 2021-08-01 18:30 +0200
                            Re: MDs & Dentists "Andrew M.A. Cater" <amacater@einval.com> - 2021-08-01 19:10 +0200
                            Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:30 +0200
                            Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:50 +0200
                              Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:00 +0200
                              Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:00 +0200
                          Re: MDs & Dentists Dan Ritter <dsr@randomstring.org> - 2021-08-01 18:00 +0200
                      Re: MDs & Dentists Gunnar Gervin <dofeelok@gmail.com> - 2021-08-01 15:50 +0200
                        Hard to understand, being clear [ was Re: MDs & Dentists] Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-01 22:40 +0200
                          Re: Hard to understand, being clear [ was Re: MDs & Dentists] Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 15:40 +0200
                          Re: Hard to understand, being clear [ was Re: MDs & Dentists] Gunnar Gervin <dofeelok@gmail.com> - 2021-08-02 16:00 +0200
                    Re: MDs & Dentists Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-07-21 18:20 +0200
                      Re: MDs & Dentists "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2021-07-21 18:40 +0200
                        Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 19:10 +0200
                          Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-21 19:40 +0200
                            Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 20:20 +0200
                              Re: MDs & Dentists Stefan Monnier <monnier@iro.umontreal.ca> - 2021-07-21 21:50 +0200
                                Re: MDs & Dentists "Thomas Schmitt" <scdbackup@gmx.net> - 2021-07-21 23:50 +0200
                        Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-21 19:20 +0200
                          Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 19:40 +0200
                        Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 19:30 +0200
                          Re: MDs & Dentists Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-07-21 22:40 +0200
                    Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 20:40 +0200
                      Re: MDs & Dentists Reco <recoverym4n@enotuniq.net> - 2021-07-21 21:10 +0200
                        Re: MDs & Dentists Celejar <celejar@gmail.com> - 2021-07-21 22:30 +0200
                    Re: MDs & Dentists Richard Hector <richard@walnut.gen.nz> - 2021-07-21 21:20 +0200
          Re: MDs & Dentists Michael Lange <klappnase@freenet.de> - 2021-07-15 13:10 +0200
            Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 15:40 +0200
      Re: MDs & Dentists Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-07-15 00:30 +0200

Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →


#237424

Fromellanios82 <ellanios82@gmail.com>
Date2021-07-15 09:50 +0200
Message-ID<CB4i5-2pg-1@gated-at.bofh.it>
In reply to#237406
On 7/15/21 2:03 AM, jeremy ardley wrote:
> suggesting Windows is certified for any risk of life application!?
>
> It has a huge spectrum of vulnerabilities

....

  - believe wikipedia had mention : 100% of world's super-computers run 
on Linux


....

  rgds

.

[toc] | [prev] | [next] | [standalone]


#237425

FromJeremy Ardley <jeremy@ardley.org>
Date2021-07-15 10:10 +0200
Message-ID<CB4Br-2Lk-1@gated-at.bofh.it>
In reply to#237424

[Multipart message — attachments visible in raw view] — view raw

On 15/7/21 4:00 pm, Weaver wrote:
> On 15-07-2021 17:48, ellanios82 wrote:
>> On 7/15/21 2:03 AM, jeremy ardley wrote:
>>> suggesting Windows is certified for any risk of life application!?
>>>
>>> It has a huge spectrum of vulnerabilities
>> ....
>>
>>   - believe wikipedia had mention : 100% of world's super-computers run on Linux
> https://top500.org/statistics/list/
> Cheers!
>
> Harry
>

I'm not sure how they differentiate Centos and RHEL from Linux, but yeah 
there doesn't seem to be much Windows in the space.

Also no Debian? Or is that in the 'Linux' fold, with Ubuntu sufficiently 
down-market to get it's own mentions?

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#237426

FromWeaver <weaver@riseup.net>
Date2021-07-15 10:10 +0200
Message-ID<CB4Br-2Lk-3@gated-at.bofh.it>
In reply to#237424
On 15-07-2021 17:48, ellanios82 wrote:
> On 7/15/21 2:03 AM, jeremy ardley wrote:
>> suggesting Windows is certified for any risk of life application!?
>>
>> It has a huge spectrum of vulnerabilities
> 
> ....
> 
>  - believe wikipedia had mention : 100% of world's super-computers run on Linux

https://top500.org/statistics/list/
Cheers!

Harry

-- 
`When injustice becomes law, resistance becomes duty' 
-- Thomas Jefferson

[toc] | [prev] | [next] | [standalone]


#237427

FromJoe <joe@jretrading.com>
Date2021-07-15 11:40 +0200
Message-ID<CB5QR-3pb-1@gated-at.bofh.it>
In reply to#237406
On Thu, 15 Jul 2021 07:03:18 +0800
jeremy ardley <jeremy@ardley.org> wrote:


> You can't be seriously suggesting Windows is certified for any risk
> of life application!?
> 
> It has a huge spectrum of vulnerabilities and a constant stream of
> zero day exploits for both the O/S 

Yes, but most of them were placed there by Microsoft for the benefit of
the US government, and can be instantly removed when discovered (and
replaced by an alternative).

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#237430

From<tomas@tuxteam.de>
Date2021-07-15 12:30 +0200
Message-ID<CB6MV-41o-1@gated-at.bofh.it>
In reply to#237427

[Multipart message — attachments visible in raw view] — view raw

On Thu, Jul 15, 2021 at 10:27:25AM +0100, Joe wrote:
> On Thu, 15 Jul 2021 07:03:18 +0800
> jeremy ardley <jeremy@ardley.org> wrote:
> 
> 
> > You can't be seriously suggesting Windows is certified for any risk
> > of life application!?
> > 
> > It has a huge spectrum of vulnerabilities and a constant stream of
> > zero day exploits for both the O/S 
> 
> Yes, but most of them were placed there by Microsoft for the benefit of
> the US government, and can be instantly removed when discovered (and
> replaced by an alternative).

Wrong.

They just want you to believe that, so that you come across as a
conspiracy theorist and people stop taking you seriously.

It's tuttles all the way down!

(tongue-in-cheek ;-P

 - tomás

[toc] | [prev] | [next] | [standalone]


#237421

FromReco <recoverym4n@enotuniq.net>
Date2021-07-15 08:50 +0200
Message-ID<CB3m1-1My-3@gated-at.bofh.it>
In reply to#237401
On Wed, Jul 14, 2021 at 06:26:58PM -0400, Polyna-Maude Racicot-Summerside wrote:
> Him
> 
> On 2021-07-14 3:42 p.m., ellanios82 wrote:
> > On 7/14/21 9:27 PM, Jude DaShiell wrote:
> >> Doctors and Dentists run windows as the base for all of their practice
> >> software.  I don't know of any linux software that could replace that
> >> software either.  Could it be some software house would be able to get
> >> linux versions available and make some money?
> > 
> >  - at one stage needed windows stuff : ran on Virtual-Box : perfect !!
> > 
> > 
> That's the usual "geek non-sense" answer.
> 
> Can you tell me one big advantage of using Linux in a medical practice ?

Sure, I can name two such advantages.

You cannot catch a ransomware cryptolocker using Linux on a desktop,
it's definitely Windows-only kind of software. In fact, any FOSS OS has
this advantage, unless you're using Wine (software).

Also, you can ensure that your patients' data won't be uploaded to M$ or
Apple, but that can be considered a common practice these days.

Reco

[toc] | [prev] | [next] | [standalone]


#237547

FromCelejar <celejar@gmail.com>
Date2021-07-20 17:40 +0200
Message-ID<CD00F-1XX-3@gated-at.bofh.it>
In reply to#237421
On Thu, 15 Jul 2021 09:46:59 +0300
Reco <recoverym4n@enotuniq.net> wrote:

...

> You cannot catch a ransomware cryptolocker using Linux on a desktop,

Of course you can, although it's certainly much less likely than when
using Windows.

> it's definitely Windows-only kind of software. In fact, any FOSS OS has
> this advantage, unless you're using Wine (software).

It's definitely not Windows-only, although it is (at this point) still
mostly Windows:

https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/
https://phoenixnap.com/blog/linux-ransomware
https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack
https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/

Celejar

[toc] | [prev] | [next] | [standalone]


#237564

FromReco <recoverym4n@enotuniq.net>
Date2021-07-21 10:20 +0200
Message-ID<CDfCp-3bn-1@gated-at.bofh.it>
In reply to#237547
	Hi.

On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote:
> On Thu, 15 Jul 2021 09:46:59 +0300
> Reco <recoverym4n@enotuniq.net> wrote:
> 
> ...
> 
> > You cannot catch a ransomware cryptolocker using Linux on a desktop,
> 
> Of course you can, although it's certainly much less likely than when
> using Windows.
> 
> > it's definitely Windows-only kind of software. In fact, any FOSS OS has
> > this advantage, unless you're using Wine (software).
> 
> It's definitely not Windows-only, although it is (at this point) still
> mostly Windows:

I'm not arguing with that, but links you're providing fail to illustrate
your point.

> https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/

Requires Java to be installed. A rare case on a Linux *desktop*.

> https://phoenixnap.com/blog/linux-ransomware

Quote:
The ransomware is human-operated, so threat actors need time to
compromise a network, steal credentials, and spread across devices.

> https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack

Quote 1:
Unlike Windows ransomware variants which spread via email or
maladvertising, Linux ransomware infection relies on vulnerability
exploitation.

Quote 2:
Linux ransomware exploits either unpatched system vulnerabilities or
flaws in a service, such as a web server or email server, to obtain
access to a target system and compromise files. For instance, the
infamous Lilocked ransomware exploits out-of-date versions of the Exim
message transfer agent to gain a foothold in a target environment. Rex,
another dangerous strain of Linux ransomware, uses vulnerability
scanners specific to Drupal, WordPress, Magento, Kerner, Airos, Exagrid,
and Jetspeed to detect SQL injection vulnerabilities that can be
exploited to gain admin credentials.

> https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/

Quote:
RansomEXX is what security researchers call a "big-game hunter" or
"human-operated ransomware."


Conclusion:
So, unless your Linux *desktop* is a target of an "attack" - your
desktop is safe. Third link also shows us that if one runs an
Internet-facing website or MTA - one should better know what they're
doing. It's true that the security history of Exim, Wordpress and Drupal
is far from being flawless (I'm not familiar with other CMSes mentioned
at that article, I assume they're no better in this regard).


And now, let's compare the scenario above to the usual "a user opens a
specially crafted M$ Word document" and "user clicks on an
innocent-looking link".

To me, the difference is obvious, especially considering the original
point of this topic.

Reco

[toc] | [prev] | [next] | [standalone]


#237576

FromCelejar <celejar@gmail.com>
Date2021-07-21 17:00 +0200
Message-ID<CDlRw-6JH-13@gated-at.bofh.it>
In reply to#237564
On Wed, 21 Jul 2021 11:16:46 +0300
Reco <recoverym4n@enotuniq.net> wrote:

> 	Hi.
> 
> On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote:
> > On Thu, 15 Jul 2021 09:46:59 +0300
> > Reco <recoverym4n@enotuniq.net> wrote:
> > 
> > ...
> > 
> > > You cannot catch a ransomware cryptolocker using Linux on a desktop,
> > 
> > Of course you can, although it's certainly much less likely than when
> > using Windows.
> > 
> > > it's definitely Windows-only kind of software. In fact, any FOSS OS has
> > > this advantage, unless you're using Wine (software).
> > 
> > It's definitely not Windows-only, although it is (at this point) still
> > mostly Windows:
> 
> I'm not arguing with that, but links you're providing fail to illustrate
> your point.
> 
> > https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/
> 
> Requires Java to be installed. A rare case on a Linux *desktop*.

Rare? I don't have statistics, but on one of my Linux desktops, I do
some development work for Android, using IntelliJ IDEA / Android Studio,
which depend on at least some Java components. I don't know if I have
enough Java installed to be susceptible to the malware in question ;)

> > https://phoenixnap.com/blog/linux-ransomware
> 
> Quote:
> The ransomware is human-operated, so threat actors need time to
> compromise a network, steal credentials, and spread across devices.
> 
> > https://linuxsecurity.com/features/anatomy-of-a-linux-ransomware-attack
> 
> Quote 1:
> Unlike Windows ransomware variants which spread via email or
> maladvertising, Linux ransomware infection relies on vulnerability
> exploitation.
> 
> Quote 2:
> Linux ransomware exploits either unpatched system vulnerabilities or
> flaws in a service, such as a web server or email server, to obtain
> access to a target system and compromise files. For instance, the
> infamous Lilocked ransomware exploits out-of-date versions of the Exim
> message transfer agent to gain a foothold in a target environment. Rex,
> another dangerous strain of Linux ransomware, uses vulnerability
> scanners specific to Drupal, WordPress, Magento, Kerner, Airos, Exagrid,
> and Jetspeed to detect SQL injection vulnerabilities that can be
> exploited to gain admin credentials.
> 
> > https://www.zdnet.com/article/linux-version-of-ransomexx-ransomware-discovered/
> 
> Quote:
> RansomEXX is what security researchers call a "big-game hunter" or
> "human-operated ransomware."
> 
> 
> Conclusion:
> So, unless your Linux *desktop* is a target of an "attack" - your
> desktop is safe. Third link also shows us that if one runs an
> Internet-facing website or MTA - one should better know what they're
> doing. It's true that the security history of Exim, Wordpress and Drupal
> is far from being flawless (I'm not familiar with other CMSes mentioned
> at that article, I assume they're no better in this regard).
> 
> 
> And now, let's compare the scenario above to the usual "a user opens a
> specially crafted M$ Word document" and "user clicks on an
> innocent-looking link".
> 
> To me, the difference is obvious, especially considering the original
> point of this topic.

Fair enough - but I see no reason why in principle desktop Linux will
remain immune from ransomware. Even if Linux word processors are safer
than their Windows counterparts, browsers are just full of
vulnerabilities, so why couldn't ransomware get in that way?

Celejar

[toc] | [prev] | [next] | [standalone]


#237578

FromReco <recoverym4n@enotuniq.net>
Date2021-07-21 17:40 +0200
Message-ID<CDmud-7bz-9@gated-at.bofh.it>
In reply to#237576
On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> On Wed, 21 Jul 2021 11:16:46 +0300
> Reco <recoverym4n@enotuniq.net> wrote:
> 
> > 	Hi.
> > 
> > On Tue, Jul 20, 2021 at 11:32:26AM -0400, Celejar wrote:
> > > On Thu, 15 Jul 2021 09:46:59 +0300
> > > Reco <recoverym4n@enotuniq.net> wrote:
> > > 
> > > ...
> > > 
> > > > You cannot catch a ransomware cryptolocker using Linux on a desktop,
> > > 
> > > Of course you can, although it's certainly much less likely than when
> > > using Windows.
> > > 
> > > > it's definitely Windows-only kind of software. In fact, any FOSS OS has
> > > > this advantage, unless you're using Wine (software).
> > > 
> > > It's definitely not Windows-only, although it is (at this point) still
> > > mostly Windows:
> > 
> > I'm not arguing with that, but links you're providing fail to illustrate
> > your point.
> > 
> > > https://hacked.com/linux-ransomware-notorious-cases-and-ways-to-protect/
> > 
> > Requires Java to be installed. A rare case on a Linux *desktop*.
> 
> Rare? I don't have statistics, but on one of my Linux desktops, I do
> some development work for Android, using IntelliJ IDEA / Android Studio,
> which depend on at least some Java components.

Numbers show that I was incorrect. Let's call it "unlikely" instead of
"rare". Let the popcon graphs speak for themselves:

https://qa.debian.org/popcon.php?package=firefox-esr
vs
https://qa.debian.org/popcon.php?package=openjdk-11


I agree with you that one should uninstall Java unless it's needed.
After all, they at Oracle always find something to fix in Java security
every three months, and this goes on for last ten years.

> I don't know if I have
> enough Java installed to be susceptible to the malware in question ;)

Famous Java's slogan "you write it once and run it everywhere" is an
exaggeration, to put it lightly. Chances are, you don't have that exact
minor update of Oracle JRE that this malware actually needs.


> Fair enough - but I see no reason why in principle desktop Linux will
> remain immune from ransomware.

It won't by itself, of course. One sure way to beat ransomware is to
take immutable backups (i.e. unmodifiable by host during and after the
backup is taken), and as recent history shows us - ransomware victims
apparently do not use this approach.

Another sure way is to forbid running executables downloaded from random
Internet sites, but no thanks to appimage, flatpak, snap, and Go Linux
desktop goes straight into Windows desktop direction.
And again, as recent history shows us - ransomware victims apparently do
not use this approach too.


Currently a Linux desktop is better in this regard, but I agree that it
may not remain the same.


> Even if Linux word processors are safer than their Windows counterparts,

Last time I ran Libreoffice I had that distinct feeling I'm running a
Java program. You know - long startup, eating memory like no tomorrow,
trying to write useless junk at least to four different places at my
filesystems, and eating the unhealthy amounts of CPU time in the
process.

I know that Libreoffice is written in C++, but the code quality of it is
definitely left to be desired. At least then the thing crashes (it did,
several times) it produces a standard core dump, not some unreadable
stack trace and a heapdump.

In retrospect, maybe feeding Libreoffice Draw that 800-pages PDF was not
the best of ideas, but no free software tool comes close to the
capabilities of Libreoffice in editing PDFs, and I really needed that
PDF to be modified (mass-replacing embedded fonts, to be specific).


On the other hand, Windows counterparts are typical enterprisey software
written by generations of overseas workers with the code quality (or
rather the lack of) that's expected from enterprisey software.

My opinion on this - both are bad. Lireoffice is better being free
software, of course, but that does not make it secure by definition.


> browsers are just full of vulnerabilities,

True. Every version of Chromium and Firefox fixes at least one.
Most of said vulnerabilities do cannot be used to get Remote Code
Execution (RCE) though. Which leaves us with "random download" scenario,
which I've discussed above.

> so why couldn't ransomware get in that way?

It could. In a lack of a proper execution environment (be it JRE,
flatpak, snap or whatever) - what should it do next? Wait for a user to
execute it?

Reco

[toc] | [prev] | [next] | [standalone]


#237579

FromDan Ritter <dsr@randomstring.org>
Date2021-07-21 18:00 +0200
Message-ID<CDmNz-7ih-3@gated-at.bofh.it>
In reply to#237578
Reco wrote: 
> On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> Numbers show that I was incorrect. Let's call it "unlikely" instead of
> "rare". Let the popcon graphs speak for themselves:
> 
> https://qa.debian.org/popcon.php?package=firefox-esr
> vs
> https://qa.debian.org/popcon.php?package=openjdk-11

Standard reminder: popcon vastly over-represents
individually-owned laptops and desktops over servers and
corporately-owned anything.

In this case, individuals are sometimes infected with ransomware
by happenstance, but corporates are actually targets.

> It won't by itself, of course. One sure way to beat ransomware is to
> take immutable backups (i.e. unmodifiable by host during and after the
> backup is taken), and as recent history shows us - ransomware victims
> apparently do not use this approach.

Yes indeed. 

-dsr-

[toc] | [prev] | [next] | [standalone]


#237975

FromGunnar Gervin <dofeelok@gmail.com>
Date2021-08-01 15:40 +0200
Message-ID<CHjR7-6wM-9@gated-at.bofh.it>
In reply to#237579

[Multipart message — attachments visible in raw view] — view raw

Security.
Rarely discussed in Linux(?)..
Was scammed recently; naive me let a man w/Bad accent take over my laptop
to 'help refund BTC' & make me pay 100$.
Because of that &/or me in Synaptic bloating (2 many) packages, which led
to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't
find key file" messages (yes, all 3 !).
After trying "all" workarounds, I installed another, more simple Linux
distro, built up a new setup of relevant programs to build VM, containers,
websites, Debian iso image, & CHEF.
Now Chef asks me to give URL to continue setting up a VM etc.
Plz advise &/or help to do it/this.
BR,
GEG

On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote:

> Reco wrote:
> > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> > Numbers show that I was incorrect. Let's call it "unlikely" instead of
> > "rare". Let the popcon graphs speak for themselves:
> >
> > https://qa.debian.org/popcon.php?package=firefox-esr
> > vs
> > https://qa.debian.org/popcon.php?package=openjdk-11
>
> Standard reminder: popcon vastly over-represents
> individually-owned laptops and desktops over servers and
> corporately-owned anything.
>
> In this case, individuals are sometimes infected with ransomware
> by happenstance, but corporates are actually targets.
>
> > It won't by itself, of course. One sure way to beat ransomware is to
> > take immutable backups (i.e. unmodifiable by host during and after the
> > backup is taken), and as recent history shows us - ransomware victims
> > apparently do not use this approach.
>
> Yes indeed.
>
> -dsr-
>
>

[toc] | [prev] | [next] | [standalone]


#237978

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-08-01 16:00 +0200
Message-ID<CHkau-6Ef-5@gated-at.bofh.it>
In reply to#237975
On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
> Security.
> Rarely discussed in Linux(?)..
> Was scammed recently; naive me let a man w/Bad accent take over my laptop
> to 'help refund BTC' & make me pay 100$.
> Because of that &/or me in Synaptic bloating (2 many) packages, which led
> to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't
> find key file" messages (yes, all 3 !).
> After trying "all" workarounds, I installed another, more simple Linux
> distro, built up a new setup of relevant programs to build VM, containers,
> websites, Debian iso image, & CHEF.

Which distro - are you still using Debian?

If not, we can't really help you. Although many of us have run other 
distributions in the past, all of the Debian/Ubuntu derivatives do
something slightly different - we can only really help with generic
Debian things. If we offer help with any other distribution, it's
only ever best efforts - Debian derivatives have their own support
infrastructure.

> Now Chef asks me to give URL to continue setting up a VM etc.
> Plz advise &/or help to do it/this.

It may not be relevant but the chef and chef-zero packages in Buster appear 
to no longer be packaged in Bullseye - the upcoming release due in two weeks.

Ask on a Chef list, perhaps?

> BR,
> GEG

All best, as ever,

Andrew Cater

> 
> On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote:
> 
> > Reco wrote:
> > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> > > Numbers show that I was incorrect. Let's call it "unlikely" instead of
> > > "rare". Let the popcon graphs speak for themselves:
> > >
> > > https://qa.debian.org/popcon.php?package=firefox-esr
> > > vs
> > > https://qa.debian.org/popcon.php?package=openjdk-11
> >
> > Standard reminder: popcon vastly over-represents
> > individually-owned laptops and desktops over servers and
> > corporately-owned anything.
> >
> > In this case, individuals are sometimes infected with ransomware
> > by happenstance, but corporates are actually targets.
> >
> > > It won't by itself, of course. One sure way to beat ransomware is to
> > > take immutable backups (i.e. unmodifiable by host during and after the
> > > backup is taken), and as recent history shows us - ransomware victims
> > > apparently do not use this approach.
> >
> > Yes indeed.
> >
> > -dsr-
> >
> >

[toc] | [prev] | [next] | [standalone]


#237979

FromGunnar Gervin <dofeelok@gmail.com>
Date2021-08-01 16:00 +0200
Message-ID<CHkau-6Ef-7@gated-at.bofh.it>
In reply to#237978

[Multipart message — attachments visible in raw view] — view raw

I expected that answer.
Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
Trying to set up Debian in a VM in another Linux distro, with Chef
So I cannot really see irrelevance
of my question?? Like Nobody here knows how to fix this one, cos it's
slightly out of D. politics?
Geg

On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com> wrote:

> On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
> > Security.
> > Rarely discussed in Linux(?)..
> > Was scammed recently; naive me let a man w/Bad accent take over my laptop
> > to 'help refund BTC' & make me pay 100$.
> > Because of that &/or me in Synaptic bloating (2 many) packages, which led
> > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't
> > find key file" messages (yes, all 3 !).
> > After trying "all" workarounds, I installed another, more simple Linux
> > distro, built up a new setup of relevant programs to build VM,
> containers,
> > websites, Debian iso image, & CHEF.
>
> Which distro - are you still using Debian?
>
> If not, we can't really help you. Although many of us have run other
> distributions in the past, all of the Debian/Ubuntu derivatives do
> something slightly different - we can only really help with generic
> Debian things. If we offer help with any other distribution, it's
> only ever best efforts - Debian derivatives have their own support
> infrastructure.
>
> > Now Chef asks me to give URL to continue setting up a VM etc.
> > Plz advise &/or help to do it/this.
>
> It may not be relevant but the chef and chef-zero packages in Buster
> appear
> to no longer be packaged in Bullseye - the upcoming release due in two
> weeks.
>
> Ask on a Chef list, perhaps?
>
> > BR,
> > GEG
>
> All best, as ever,
>
> Andrew Cater
>
> >
> > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote:
> >
> > > Reco wrote:
> > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> > > > Numbers show that I was incorrect. Let's call it "unlikely" instead
> of
> > > > "rare". Let the popcon graphs speak for themselves:
> > > >
> > > > https://qa.debian.org/popcon.php?package=firefox-esr
> > > > vs
> > > > https://qa.debian.org/popcon.php?package=openjdk-11
> > >
> > > Standard reminder: popcon vastly over-represents
> > > individually-owned laptops and desktops over servers and
> > > corporately-owned anything.
> > >
> > > In this case, individuals are sometimes infected with ransomware
> > > by happenstance, but corporates are actually targets.
> > >
> > > > It won't by itself, of course. One sure way to beat ransomware is to
> > > > take immutable backups (i.e. unmodifiable by host during and after
> the
> > > > backup is taken), and as recent history shows us - ransomware victims
> > > > apparently do not use this approach.
> > >
> > > Yes indeed.
> > >
> > > -dsr-
> > >
> > >
>
>

[toc] | [prev] | [next] | [standalone]


#237988

Fromrhkramer@gmail.com
Date2021-08-01 18:30 +0200
Message-ID<CHmvD-8g1-1@gated-at.bofh.it>
In reply to#237979
On Sunday, August 01, 2021 09:58:48 AM Gunnar Gervin wrote:
> So I cannot really see irrelevance
> of my question?? 

> Like Nobody here knows how to fix this one, cos it's
> slightly out of D. 

Someone who uses Debian, maybe even someone who subscribes to this list might 
know how to fix your problem, but I think at least part of the point that 
Andrew was making is that it is a catch as catch can situation -- somebody 
might be able to help, but the people that really concentrate on taking care 
of Debian probably can't as they are not familiar with your distro or Chef or 
both.

> politics?

No, and most of us here probably don't like the suggestion.

[toc] | [prev] | [next] | [standalone]


#237989

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-08-01 19:10 +0200
Message-ID<CHn8l-hU-5@gated-at.bofh.it>
In reply to#237979
On Sun, Aug 01, 2021 at 04:58:48PM +0300, Gunnar Gervin wrote:
> I expected that answer.
> Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
> Trying to set up Debian in a VM in another Linux distro, with Chef
> So I cannot really see irrelevance
> of my question?? Like Nobody here knows how to fix this one, cos it's
> slightly out of D. politics?
> Geg

So: do the simple things.

1.) If you want to keep Windows - use this Windows machine or another to 
produce a Windows .iso for installation using Microsoft's media creation tool to put 
it onto a USB flash disk. 

Use Debian boot media to delete the whole of Windows: reinstall Windows 
using your new USB flash disk after removing all existing partitions on the 
hard disk. If you get the chance to partition the blank disk - set aside space for a 
Linux install. If not, use Windows partitioning tools to shrink Windows to 
allow space for a Linux distribution. Install Windows using UEFI boot if
at all possible.

2.) Install Debian - and only Debian on the empty space. Debian should find
the Windows partition and include it into the Grub boot menu. If you choose
to install any other Linux, we may or may not be able to help you as
previously written.

Saying this because I've a machine in the room on which I did just that.
Save yourself a lot of XYZ problems by doing two things slowly and carefully.

Why you think that someone from another Linux distribution should have
scammed you / been attacking your Windows partition is your own affair.
In most instances, a clean reinstall of an operating system will help
to see them away significantly and good patching and updating is also a must.
. 
You may need to consider about what makes you, especially, special enough for 
someone else to try and hack you and, objectively, whether facts support this.

All the very best, as ever,

Andrew Cater
> 
> On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com> wrote:
> 
> > On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
> > > Security.
> > > Rarely discussed in Linux(?)..
> > > Was scammed recently; naive me let a man w/Bad accent take over my laptop
> > > to 'help refund BTC' & make me pay 100$.
> > > Because of that &/or me in Synaptic bloating (2 many) packages, which led
> > > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", & "can't
> > > find key file" messages (yes, all 3 !).
> > > After trying "all" workarounds, I installed another, more simple Linux
> > > distro, built up a new setup of relevant programs to build VM,
> > containers,
> > > websites, Debian iso image, & CHEF.
> >
> > Which distro - are you still using Debian?
> >
> > If not, we can't really help you. Although many of us have run other
> > distributions in the past, all of the Debian/Ubuntu derivatives do
> > something slightly different - we can only really help with generic
> > Debian things. If we offer help with any other distribution, it's
> > only ever best efforts - Debian derivatives have their own support
> > infrastructure.
> >
> > > Now Chef asks me to give URL to continue setting up a VM etc.
> > > Plz advise &/or help to do it/this.
> >
> > It may not be relevant but the chef and chef-zero packages in Buster
> > appear
> > to no longer be packaged in Bullseye - the upcoming release due in two
> > weeks.
> >
> > Ask on a Chef list, perhaps?
> >
> > > BR,
> > > GEG
> >
> > All best, as ever,
> >
> > Andrew Cater
> >
> > >
> > > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org> wrote:
> > >
> > > > Reco wrote:
> > > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> > > > > Numbers show that I was incorrect. Let's call it "unlikely" instead
> > of
> > > > > "rare". Let the popcon graphs speak for themselves:
> > > > >
> > > > > https://qa.debian.org/popcon.php?package=firefox-esr
> > > > > vs
> > > > > https://qa.debian.org/popcon.php?package=openjdk-11
> > > >
> > > > Standard reminder: popcon vastly over-represents
> > > > individually-owned laptops and desktops over servers and
> > > > corporately-owned anything.
> > > >
> > > > In this case, individuals are sometimes infected with ransomware
> > > > by happenstance, but corporates are actually targets.
> > > >
> > > > > It won't by itself, of course. One sure way to beat ransomware is to
> > > > > take immutable backups (i.e. unmodifiable by host during and after
> > the
> > > > > backup is taken), and as recent history shows us - ransomware victims
> > > > > apparently do not use this approach.
> > > >
> > > > Yes indeed.
> > > >
> > > > -dsr-
> > > >
> > > >
> >
> >

[toc] | [prev] | [next] | [standalone]


#237995

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2021-08-01 22:30 +0200
Message-ID<CHqfT-2dE-9@gated-at.bofh.it>
In reply to#237979

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 2021-08-01 9:58 a.m., Gunnar Gervin wrote:
> I expected that answer.
> Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
> Trying to set up Debian in a VM in another Linux distro, with Chef
> So I cannot really see irrelevance
> of my question?? Like Nobody here knows how to fix this one, cos it's
> slightly out of D. politics?
There's no such thing as "Debian Politics" (or what would D.Politics
mean, could be useful to put a bit more effort in making your message
intelligible for others).

What there's present here is a community of user that revolve around the
Debian Linux distribution, centered over the Debian distribution. So if
you run Distribution XYZ and are trying to get Debian running on a VM,
we can help you with the Debian part, not much with setting up the VM or
what goes with the underlying OS.

Not because of some "politics" or because we are stubborn or stillborn,
but because we probably have not much experience with the underlying
system. We have interest in Debian and this is what we all use mostly.

We've exchanged (me and many others) at least two dozen of messages in
the last weeks or so. And still, we don't have a clue if you are running
Debian.

But, we have gave you chances and tools to straight this out.

https://lists.debian.org/debian-user/2021/07/msg01216.html

*Here's a short part...*

Rather than a back and forth on whether Gunnar's description of the
machine is correct, it might be more productive to suggest running
some simple, definitive commands like:

$ ls /sys/firmware/
acpi  dmi  efi  memmap
$

It either includes "efi" (UEFI-booted), or it doesn't (BIOS-booted).

$ uname -a
Linux ajax 4.19.0-17-amd64 #1 SMP Debian 4.19.194-3 (2021-07-18) x86_64
GNU/Linux
$

The kernel architecture is given (x86_64 here). The "arch" command is
terser. i686/i586/i486 would indicate an i386 architecture.

$ grep address /proc/cpuinfo
address sizes   : 36 bits physical, 48 bits virtual
$

Anything over 32 indicates 64-bit capability, whether or not
it is being exploited. A 32-bit processor will only yield:

address sizes   : 32 bits physical, 32 bits virtual

*And here goes another one...*

https://lists.debian.org/debian-user/2021/07/msg01240.html

Of course I haven't. I see scattered posts (only some) from Gunnar
that don't seem to make a lot of sense, followed up by discussion and
argument, much of which could be avoided by getting some facts into
the posts. Hence my suggestion (snipped) to run

$ ls /sys/firmware/
$ uname -a
$ grep address /proc/cpuinfo

and clarify what type of machine (machines?) is being discussed.
Perhaps it's reckless not to have suggested a command proving
it's a Debian system.

In all of Gunnar's posts, I think I have only seen one report of actual
output posted, and I have no idea what the origin of that was, viz:

  # UNCONFIGURED FSTAB FOR BASE SYSTEM
  overlay / overlay rw 0 0
  tmpfs /tmp tmpfs nosuid,nodev 0 0
  /dev/sda1 /mnt/sda1 EXT2 nosuid,nodev,nofail,x-gvfs-show 0 0
  /dev/sda3 /mnt/sda3 EXT2
nosuid,nodev,nofail,x-gvfs-show,noauto,x-udisks-auth 0 0
  /dev/sda2 none swap sw,x-udisks-auth,noauto 0 0

*Now sorry...*
Maybe English is not your main language or there's something else but I
have to agree with the writter of this last message.
Some your post don't make much sense and take more energy to understand
the text themselves than they require to really find any type of
computing problem.

What is easy to understand for yourself may not be the case for others.

In the long term, you'll be the one facing penalties for this as people
will just get tired and start ignoring.

No one's got obligation here and we are all volunteer doing so for the
pleasure of helping others.

Even myself, when I take to explain things like I'm doing now.

And like I did for the "top posting".

Here's some tip...

I'll show you some hard to understand in the following post...



> Geg
> 
> On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com
> <mailto:amacater@einval.com>> wrote:
> 
>     On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
>     > Security.
>     > Rarely discussed in Linux(?)..
>     > Was scammed recently; naive me let a man w/Bad accent take over my
>     laptop
>     > to 'help refund BTC' & make me pay 100$.
>     > Because of that &/or me in Synaptic bloating (2 many) packages,
>     which led
>     > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", &
>     "can't
>     > find key file" messages (yes, all 3 !).
>     > After trying "all" workarounds, I installed another, more simple Linux
>     > distro, built up a new setup of relevant programs to build VM,
>     containers,
>     > websites, Debian iso image, & CHEF.
> 
>     Which distro - are you still using Debian?
> 
>     If not, we can't really help you. Although many of us have run other
>     distributions in the past, all of the Debian/Ubuntu derivatives do
>     something slightly different - we can only really help with generic
>     Debian things. If we offer help with any other distribution, it's
>     only ever best efforts - Debian derivatives have their own support
>     infrastructure.
> 
>     > Now Chef asks me to give URL to continue setting up a VM etc.
>     > Plz advise &/or help to do it/this.
> 
>     It may not be relevant but the chef and chef-zero packages in Buster
>     appear
>     to no longer be packaged in Bullseye - the upcoming release due in
>     two weeks.
> 
>     Ask on a Chef list, perhaps?
> 
>     > BR,
>     > GEG
> 
>     All best, as ever,
> 
>     Andrew Cater
> 
>     >
>     > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org
>     <mailto:dsr@randomstring.org>> wrote:
>     >
>     > > Reco wrote:
>     > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
>     > > > Numbers show that I was incorrect. Let's call it "unlikely"
>     instead of
>     > > > "rare". Let the popcon graphs speak for themselves:
>     > > >
>     > > > https://qa.debian.org/popcon.php?package=firefox-esr
>     <https://qa.debian.org/popcon.php?package=firefox-esr>
>     > > > vs
>     > > > https://qa.debian.org/popcon.php?package=openjdk-11
>     <https://qa.debian.org/popcon.php?package=openjdk-11>
>     > >
>     > > Standard reminder: popcon vastly over-represents
>     > > individually-owned laptops and desktops over servers and
>     > > corporately-owned anything.
>     > >
>     > > In this case, individuals are sometimes infected with ransomware
>     > > by happenstance, but corporates are actually targets.
>     > >
>     > > > It won't by itself, of course. One sure way to beat ransomware
>     is to
>     > > > take immutable backups (i.e. unmodifiable by host during and
>     after the
>     > > > backup is taken), and as recent history shows us - ransomware
>     victims
>     > > > apparently do not use this approach.
>     > >
>     > > Yes indeed.
>     > >
>     > > -dsr-
>     > >
>     > >
> 

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#237997

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2021-08-01 22:50 +0200
Message-ID<CHqzf-2lp-7@gated-at.bofh.it>
In reply to#237979

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 2021-08-01 9:58 a.m., Gunnar Gervin wrote:
> I expected that answer.
> Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
> Trying to set up Debian in a VM in another Linux distro, with Chef
> So I cannot really see irrelevance
> of my question?? Like Nobody here knows how to fix this one, cos it's
> slightly out of D. politics?
> Geg
> 

Not because of politics.
Because you don't seem to take help when it's given to you.

At least 3 persons (different ones) have gave you tips on how to
properly identify the OS you are running over (not only Linux but the
distribution itself) and been trying to find out what you are using.

Including one person that wasn't sure if your laptop description was
because it was running Bullseye and wanted to be added to the list of
computer supported or something else.

None got any answer.

So this may be the start of the whole problem.

Now if you have a belief that people are trying to scam you off, them I
can assure you of two things.

You probably aren't a interesting target unless you are a bank or some
big corporation. And if it would be the case, you wouldn't be
interacting this way on the mailing list.

If you got offer by someone you don't know to pay 100$ and get refunded
for BTC, then you are mostly the first person to blame. This trick has
been around for a very long time, and it's quite public notoriety that
the first thing to do is to hangup on those person.

If you come here for help and put a doubt behind every answer that
people will give you. Then it could be good to ask yourself why you came
here first ?

Maybe you never answered to the two other users who asked you to type
some command on the shell so we can know what type of system you run,
this way we'd know if it's Debian (as we don't seem to be sure yet) and
what architecture too. Because you talked about ex-Macbook, using BIOS,
etc... pretty unclear.

Nobody can undo what happened in the past. But if you need help, the
first thing will be some genuine cooperation from yourself. Or going out
to your local computer store and paying someone to do the job.

And surely stop using some acronym only you may understand. It's not a
run against the clock. Take time to write complete word and people will
maybe have more interest in helping too.

Why shall we make effort if you don't do so. If all the energy we have
is devoted trying to decrypt some message then there won't be any left
for the computer helping part of the job.

> On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com
> <mailto:amacater@einval.com>> wrote:
> 
>     On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
>     > Security.
>     > Rarely discussed in Linux(?)..
>     > Was scammed recently; naive me let a man w/Bad accent take over my
>     laptop
>     > to 'help refund BTC' & make me pay 100$.
>     > Because of that &/or me in Synaptic bloating (2 many) packages,
>     which led
>     > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", &
>     "can't
*lt fin broken packages* ?
lt ?

let ?


>     > find key file" messages (yes, all 3 !).

find key file messages ?

*yes, all 3!*

what 3 ?

>     > After trying "all" workarounds, I installed another, more simple Linux
>     > distro, built up a new setup of relevant programs to build VM,
>     containers,
>     > websites, Debian iso image, & CHEF.
> 
>     Which distro - are you still using Debian?

Again this question ?

How many time will it take before getting a bit of cooperation !?
> 
>     If not, we can't really help you. Although many of us have run other
>     distributions in the past, all of the Debian/Ubuntu derivatives do
>     something slightly different - we can only really help with generic
>     Debian things. If we offer help with any other distribution, it's
>     only ever best efforts - Debian derivatives have their own support
>     infrastructure.
> 
>     > Now Chef asks me to give URL to continue setting up a VM etc.
>     > Plz advise &/or help to do it/this.
> 
>     It may not be relevant but the chef and chef-zero packages in Buster
>     appear
>     to no longer be packaged in Bullseye - the upcoming release due in
>     two weeks.
> 
>     Ask on a Chef list, perhaps?
> 
A good shot would be to ask on a mailing list specific to this
particular software (or a forum).

>     > BR,
>     > GEG
> 
>     All best, as ever,
> 
>     Andrew Cater
> 
>     >
>     > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org
>     <mailto:dsr@randomstring.org>> wrote:
>     >
>     > > Reco wrote:
>     > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
>     > > > Numbers show that I was incorrect. Let's call it "unlikely"
>     instead of
>     > > > "rare". Let the popcon graphs speak for themselves:
>     > > >
>     > > > https://qa.debian.org/popcon.php?package=firefox-esr
>     <https://qa.debian.org/popcon.php?package=firefox-esr>
>     > > > vs
>     > > > https://qa.debian.org/popcon.php?package=openjdk-11
>     <https://qa.debian.org/popcon.php?package=openjdk-11>
>     > >
>     > > Standard reminder: popcon vastly over-represents
>     > > individually-owned laptops and desktops over servers and
>     > > corporately-owned anything.
>     > >
>     > > In this case, individuals are sometimes infected with ransomware
>     > > by happenstance, but corporates are actually targets.
>     > >
>     > > > It won't by itself, of course. One sure way to beat ransomware
>     is to
>     > > > take immutable backups (i.e. unmodifiable by host during and
>     after the
>     > > > backup is taken), and as recent history shows us - ransomware
>     victims
>     > > > apparently do not use this approach.
>     > >
>     > > Yes indeed.
>     > >
>     > > -dsr-
>     > >
>     > >
> 

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#238030

FromGunnar Gervin <dofeelok@gmail.com>
Date2021-08-02 15:00 +0200
Message-ID<CHFHX-3H9-3@gated-at.bofh.it>
In reply to#237997

[Multipart message — attachments visible in raw view] — view raw

I see.
It's now a dual boot;
Debian 10.9 i386 32b Buster (installed from netinst dvd), in which Synaptic
crashed 80%. Tried reinstall with above dvd, it was rejected, not sure why.
So I restored the machine with a DVD with Linux Mint, dual boot;
Debian above is 1/2 , Mint is 1/2 & set up Synaptic in Linux Mint, it works
fine, just like in Debian.
It is originally a Macbook 2.1, Intel, 2Core, 160GB, 3GB RAM, Version 3.0
Vesa Bios, 64 bit(!).
Seems to use a lot 32b software
Now I look for alternative VM builders to Chef. Synaptic programs seems
same in Mint as in Debian. Debian works better in this machine than LMDE4.
Mint runs better so far, than both Debian and Lmde4. But that's probably
cos of my total lack of knowledge of anything incl. doing Backups(!). I
took backups in Mac, not Linux.
Geg

On Sun, 1 Aug 2021, 23:46 Polyna-Maude Racicot-Summerside, <
debian@polynamaude.com> wrote:

> Hi,
>
> On 2021-08-01 9:58 a.m., Gunnar Gervin wrote:
> > I expected that answer.
> > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
> > Trying to set up Debian in a VM in another Linux distro, with Chef
> > So I cannot really see irrelevance
> > of my question?? Like Nobody here knows how to fix this one, cos it's
> > slightly out of D. politics?
> > Geg
> >
>
> Not because of politics.
> Because you don't seem to take help when it's given to you.
>
> At least 3 persons (different ones) have gave you tips on how to
> properly identify the OS you are running over (not only Linux but the
> distribution itself) and been trying to find out what you are using.
>
> Including one person that wasn't sure if your laptop description was
> because it was running Bullseye and wanted to be added to the list of
> computer supported or something else.
>
> None got any answer.
>
> So this may be the start of the whole problem.
>
> Now if you have a belief that people are trying to scam you off, them I
> can assure you of two things.
>
> You probably aren't a interesting target unless you are a bank or some
> big corporation. And if it would be the case, you wouldn't be
> interacting this way on the mailing list.
>
> If you got offer by someone you don't know to pay 100$ and get refunded
> for BTC, then you are mostly the first person to blame. This trick has
> been around for a very long time, and it's quite public notoriety that
> the first thing to do is to hangup on those person.
>
> If you come here for help and put a doubt behind every answer that
> people will give you. Then it could be good to ask yourself why you came
> here first ?
>
> Maybe you never answered to the two other users who asked you to type
> some command on the shell so we can know what type of system you run,
> this way we'd know if it's Debian (as we don't seem to be sure yet) and
> what architecture too. Because you talked about ex-Macbook, using BIOS,
> etc... pretty unclear.
>
> Nobody can undo what happened in the past. But if you need help, the
> first thing will be some genuine cooperation from yourself. Or going out
> to your local computer store and paying someone to do the job.
>
> And surely stop using some acronym only you may understand. It's not a
> run against the clock. Take time to write complete word and people will
> maybe have more interest in helping too.
>
> Why shall we make effort if you don't do so. If all the energy we have
> is devoted trying to decrypt some message then there won't be any left
> for the computer helping part of the job.
>
> > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com
> > <mailto:amacater@einval.com>> wrote:
> >
> >     On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
> >     > Security.
> >     > Rarely discussed in Linux(?)..
> >     > Was scammed recently; naive me let a man w/Bad accent take over my
> >     laptop
> >     > to 'help refund BTC' & make me pay 100$.
> >     > Because of that &/or me in Synaptic bloating (2 many) packages,
> >     which led
> >     > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", &
> >     "can't
> *lt fin broken packages* ?
> lt ?
>
> let ?
>
>
> >     > find key file" messages (yes, all 3 !).
>
> find key file messages ?
>
> *yes, all 3!*
>
> what 3 ?
>
> >     > After trying "all" workarounds, I installed another, more simple
> Linux
> >     > distro, built up a new setup of relevant programs to build VM,
> >     containers,
> >     > websites, Debian iso image, & CHEF.
> >
> >     Which distro - are you still using Debian?
>
> Again this question ?
>
> How many time will it take before getting a bit of cooperation !?
> >
> >     If not, we can't really help you. Although many of us have run other
> >     distributions in the past, all of the Debian/Ubuntu derivatives do
> >     something slightly different - we can only really help with generic
> >     Debian things. If we offer help with any other distribution, it's
> >     only ever best efforts - Debian derivatives have their own support
> >     infrastructure.
> >
> >     > Now Chef asks me to give URL to continue setting up a VM etc.
> >     > Plz advise &/or help to do it/this.
> >
> >     It may not be relevant but the chef and chef-zero packages in Buster
> >     appear
> >     to no longer be packaged in Bullseye - the upcoming release due in
> >     two weeks.
> >
> >     Ask on a Chef list, perhaps?
> >
> A good shot would be to ask on a mailing list specific to this
> particular software (or a forum).
>
> >     > BR,
> >     > GEG
> >
> >     All best, as ever,
> >
> >     Andrew Cater
> >
> >     >
> >     > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org
> >     <mailto:dsr@randomstring.org>> wrote:
> >     >
> >     > > Reco wrote:
> >     > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> >     > > > Numbers show that I was incorrect. Let's call it "unlikely"
> >     instead of
> >     > > > "rare". Let the popcon graphs speak for themselves:
> >     > > >
> >     > > > https://qa.debian.org/popcon.php?package=firefox-esr
> >     <https://qa.debian.org/popcon.php?package=firefox-esr>
> >     > > > vs
> >     > > > https://qa.debian.org/popcon.php?package=openjdk-11
> >     <https://qa.debian.org/popcon.php?package=openjdk-11>
> >     > >
> >     > > Standard reminder: popcon vastly over-represents
> >     > > individually-owned laptops and desktops over servers and
> >     > > corporately-owned anything.
> >     > >
> >     > > In this case, individuals are sometimes infected with ransomware
> >     > > by happenstance, but corporates are actually targets.
> >     > >
> >     > > > It won't by itself, of course. One sure way to beat ransomware
> >     is to
> >     > > > take immutable backups (i.e. unmodifiable by host during and
> >     after the
> >     > > > backup is taken), and as recent history shows us - ransomware
> >     victims
> >     > > > apparently do not use this approach.
> >     > >
> >     > > Yes indeed.
> >     > >
> >     > > -dsr-
> >     > >
> >     > >
> >
>
> --
> Polyna-Maude R.-Summerside
> -Be smart, Be wise, Support opensource development
>
>

[toc] | [prev] | [next] | [standalone]


#238031

FromGunnar Gervin <dofeelok@gmail.com>
Date2021-08-02 15:00 +0200
Message-ID<CHFHX-3H9-5@gated-at.bofh.it>
In reply to#237997

[Multipart message — attachments visible in raw view] — view raw

Scam:
Was from outside of this list.
This info because someone thought I accused this list.
Sorry for the confusion I made.
BR,
Geg.

On Sun, 1 Aug 2021, 23:46 Polyna-Maude Racicot-Summerside, <
debian@polynamaude.com> wrote:

> Hi,
>
> On 2021-08-01 9:58 a.m., Gunnar Gervin wrote:
> > I expected that answer.
> > Debian is still 1/2 of it, but kinda dysfunctional, cos of me & scam
> > Trying to set up Debian in a VM in another Linux distro, with Chef
> > So I cannot really see irrelevance
> > of my question?? Like Nobody here knows how to fix this one, cos it's
> > slightly out of D. politics?
> > Geg
> >
>
> Not because of politics.
> Because you don't seem to take help when it's given to you.
>
> At least 3 persons (different ones) have gave you tips on how to
> properly identify the OS you are running over (not only Linux but the
> distribution itself) and been trying to find out what you are using.
>
> Including one person that wasn't sure if your laptop description was
> because it was running Bullseye and wanted to be added to the list of
> computer supported or something else.
>
> None got any answer.
>
> So this may be the start of the whole problem.
>
> Now if you have a belief that people are trying to scam you off, them I
> can assure you of two things.
>
> You probably aren't a interesting target unless you are a bank or some
> big corporation. And if it would be the case, you wouldn't be
> interacting this way on the mailing list.
>
> If you got offer by someone you don't know to pay 100$ and get refunded
> for BTC, then you are mostly the first person to blame. This trick has
> been around for a very long time, and it's quite public notoriety that
> the first thing to do is to hangup on those person.
>
> If you come here for help and put a doubt behind every answer that
> people will give you. Then it could be good to ask yourself why you came
> here first ?
>
> Maybe you never answered to the two other users who asked you to type
> some command on the shell so we can know what type of system you run,
> this way we'd know if it's Debian (as we don't seem to be sure yet) and
> what architecture too. Because you talked about ex-Macbook, using BIOS,
> etc... pretty unclear.
>
> Nobody can undo what happened in the past. But if you need help, the
> first thing will be some genuine cooperation from yourself. Or going out
> to your local computer store and paying someone to do the job.
>
> And surely stop using some acronym only you may understand. It's not a
> run against the clock. Take time to write complete word and people will
> maybe have more interest in helping too.
>
> Why shall we make effort if you don't do so. If all the energy we have
> is devoted trying to decrypt some message then there won't be any left
> for the computer helping part of the job.
>
> > On Sun, 1 Aug 2021, 16:50 Andrew M.A. Cater, <amacater@einval.com
> > <mailto:amacater@einval.com>> wrote:
> >
> >     On Sun, Aug 01, 2021 at 04:30:45PM +0300, Gunnar Gervin wrote:
> >     > Security.
> >     > Rarely discussed in Linux(?)..
> >     > Was scammed recently; naive me let a man w/Bad accent take over my
> >     laptop
> >     > to 'help refund BTC' & make me pay 100$.
> >     > Because of that &/or me in Synaptic bloating (2 many) packages,
> >     which led
> >     > to "1t fix broken packages", "put in Debian 10.9 Netinst cdrom", &
> >     "can't
> *lt fin broken packages* ?
> lt ?
>
> let ?
>
>
> >     > find key file" messages (yes, all 3 !).
>
> find key file messages ?
>
> *yes, all 3!*
>
> what 3 ?
>
> >     > After trying "all" workarounds, I installed another, more simple
> Linux
> >     > distro, built up a new setup of relevant programs to build VM,
> >     containers,
> >     > websites, Debian iso image, & CHEF.
> >
> >     Which distro - are you still using Debian?
>
> Again this question ?
>
> How many time will it take before getting a bit of cooperation !?
> >
> >     If not, we can't really help you. Although many of us have run other
> >     distributions in the past, all of the Debian/Ubuntu derivatives do
> >     something slightly different - we can only really help with generic
> >     Debian things. If we offer help with any other distribution, it's
> >     only ever best efforts - Debian derivatives have their own support
> >     infrastructure.
> >
> >     > Now Chef asks me to give URL to continue setting up a VM etc.
> >     > Plz advise &/or help to do it/this.
> >
> >     It may not be relevant but the chef and chef-zero packages in Buster
> >     appear
> >     to no longer be packaged in Bullseye - the upcoming release due in
> >     two weeks.
> >
> >     Ask on a Chef list, perhaps?
> >
> A good shot would be to ask on a mailing list specific to this
> particular software (or a forum).
>
> >     > BR,
> >     > GEG
> >
> >     All best, as ever,
> >
> >     Andrew Cater
> >
> >     >
> >     > On Wed, 21 Jul 2021, 18:59 Dan Ritter, <dsr@randomstring.org
> >     <mailto:dsr@randomstring.org>> wrote:
> >     >
> >     > > Reco wrote:
> >     > > > On Wed, Jul 21, 2021 at 10:51:40AM -0400, Celejar wrote:
> >     > > > Numbers show that I was incorrect. Let's call it "unlikely"
> >     instead of
> >     > > > "rare". Let the popcon graphs speak for themselves:
> >     > > >
> >     > > > https://qa.debian.org/popcon.php?package=firefox-esr
> >     <https://qa.debian.org/popcon.php?package=firefox-esr>
> >     > > > vs
> >     > > > https://qa.debian.org/popcon.php?package=openjdk-11
> >     <https://qa.debian.org/popcon.php?package=openjdk-11>
> >     > >
> >     > > Standard reminder: popcon vastly over-represents
> >     > > individually-owned laptops and desktops over servers and
> >     > > corporately-owned anything.
> >     > >
> >     > > In this case, individuals are sometimes infected with ransomware
> >     > > by happenstance, but corporates are actually targets.
> >     > >
> >     > > > It won't by itself, of course. One sure way to beat ransomware
> >     is to
> >     > > > take immutable backups (i.e. unmodifiable by host during and
> >     after the
> >     > > > backup is taken), and as recent history shows us - ransomware
> >     victims
> >     > > > apparently do not use this approach.
> >     > >
> >     > > Yes indeed.
> >     > >
> >     > > -dsr-
> >     > >
> >     > >
> >
>
> --
> Polyna-Maude R.-Summerside
> -Be smart, Be wise, Support opensource development
>
>

[toc] | [prev] | [next] | [standalone]


Page 2 of 4 — ← Prev page 1 [2] 3 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web