Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #270469 > unrolled thread
| Started by | Lee <ler762@gmail.com> |
|---|---|
| First post | 2024-06-25 16:00 +0200 |
| Last post | 2024-07-06 17:50 +0200 |
| Articles | 8 on this page of 48 — 18 participants |
Back to article view | Back to linux.debian.user
how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 16:00 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 16:30 +0200
Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-25 16:50 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:30 +0200
Re: how2 format a flash drive "Thomas Schmitt" <scdbackup@gmx.net> - 2024-06-25 18:50 +0200
Re: how2 format a flash drive eben@gmx.us - 2024-06-25 19:20 +0200
Re: how2 format a flash drive David Wright <deblis@lionunicorn.co.uk> - 2024-06-26 01:00 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:40 +0200
Re: how2 format a flash drive Joe <joe@jretrading.com> - 2024-06-25 17:50 +0200
Re: how2 format a flash drive Hans <hans.ullrich@loop.de> - 2024-06-25 18:50 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-26 01:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-25 21:50 +0200
Re: how2 format a flash drive eben@gmx.us - 2024-06-25 22:20 +0200
Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-06-26 01:30 +0200
Re: how2 format a flash drive sd@swampdog.co.uk - 2024-06-27 15:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-06-29 18:50 +0200
Re: how2 format a flash drive Dan Ritter <dsr@randomstring.org> - 2024-06-29 19:40 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 04:40 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 07:50 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-01 15:10 +0200
Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-01 15:50 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-01 21:30 +0200
Re: how2 format a flash drive Stefan Monnier <monnier@iro.umontreal.ca> - 2024-07-02 05:50 +0200
Re: how2 format a flash drive gene heskett <gheskett@shentel.net> - 2024-07-02 06:10 +0200
Re: how2 format a flash drive <tomas@tuxteam.de> - 2024-07-02 06:40 +0200
Re: how2 format a flash drive George at Clug <Clug@goproject.info> - 2024-07-02 06:50 +0200
Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-02 10:20 +0200
Telemetry, data hoarding [was: how2 format a flash drive] <tomas@tuxteam.de> - 2024-07-02 10:30 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:20 +0200
Re: how2 format a flash drive John Hasler <john@sugarbit.com> - 2024-07-02 17:20 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 10:30 +0200
Re: how2 format a flash drive jeremy ardley <jeremy.ardley@gmail.com> - 2024-07-02 11:30 +0200
Re: how2 format a flash drive Lee <ler762@gmail.com> - 2024-07-02 22:40 +0200
Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-06-29 22:50 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 03:40 +0200
Re: Browser traffic interception/inspection Jeffrey Walton <noloader@gmail.com> - 2024-06-30 08:00 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-06-30 17:40 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-01 09:00 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-01 17:10 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-07 23:50 +0200
Re: Browser traffic interception/inspection Max Nikulin <manikulin@gmail.com> - 2024-07-08 04:40 +0200
Re: Browser traffic interception/inspection Lee <ler762@gmail.com> - 2024-07-08 16:30 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Lee <ler762@gmail.com> - 2024-07-01 03:40 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 03:50 +0200
Re: Browser traffic interception/inspection (was: how2 format a flash drive) Jeffrey Walton <noloader@gmail.com> - 2024-07-01 07:50 +0200
Re: how2 format a flash drive Keith Bainbridge <keithrbau@gmail.com> - 2024-06-30 08:20 +0200
Re: how2 format a flash drive Jeffrey Walton <noloader@gmail.com> - 2024-07-01 08:00 +0200
Re: how2 format a flash drive Marc SCHAEFER <schaefer@alphanet.ch> - 2024-07-06 17:50 +0200
Page 3 of 3 — ← Prev page 1 2 [3]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-07-08 04:40 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IXMsk-AE3-17@gated-at.bofh.it> |
| In reply to | #270907 |
On 08/07/2024 04:42, Lee wrote: > On Mon, Jul 1, 2024 at 11:02 AM Max Nikulin wrote: >> On 01/07/2024 13:57, Lee wrote: >>> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292 [...] >> Is libnss built with logging support ABI compatible with the variant in >> Debian repositories? (Or can it be patched to achieve ABI >> compatibility?) Instead of asking for changing compile flags for all >> users, from my point of view, it is better to suggest alternative >> packages with and without logging enabled. >> >> Browsers are rather sensitive applications, so I find it reasonable that >> dumping of encryption keys are not available by default. > > Maybe I don't know enough to know what's "reasonable" or not.. but I > don't see a problem with me being able to inspect the traffic between > me and some website. Is it OK for you that e.g. GnuPG agent disables tracing by default, so attaching a debugger or a tool like strace is not so easy? It makes harder to debug some issues. From my point of view, by default libnss3 should not allow logging of private keys. At the same time I do not mind that some users should be able to inspect TLS sessions. My idea is an *alternative* package that may be optionally installed instead of regular libnss3. Comments to the bug report request to enable debugging for *all* and I agree with the maintainers who have not do it. You may ask for providing an additional package for TLS debugging. > Anyone else wants to intercept my traffic and they'll have to set an > environment variable - which root can do, but who else? IAny regular user may start browser with this variable set. Some unintentionally executed code in a user session may restart browser with enabled logging. I would not argue that it is a great trouble if an exploit is executed. However some measures may be taken to increase attack complexity and disabling TLS logging is a small step in this direction. >> <https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions> > > but I don't know how to evaluate the security > implications of modifying apt-get files. So I just downloaded the > binary from mozilla So you trust mozilla anyway. Notice the "Signed-By" key in repository configuration: sources.list(5), <https://wiki.debian.org/DebianRepository/UseThirdParty> <https://wiki.debian.org/SourcesList> apt-secure(8), <https://wiki.debian.org/SecureApt> > tar -xvf firefox-115.12.0esr.tar.bz2 > sudo mv firefox /opt/firefox-115.12.0esr/ > sudo ln -s /opt/firefox-115.12.0esr/firefox /usr/local/bin/firefox I suspect that a regular user owns /opt/firefox-115.12.0esr/ and may modify files. It should allow autoupdates, but I believe, it is an administrator task to update browser.
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-08 16:30 +0200 |
| Subject | Re: Browser traffic interception/inspection |
| Message-ID | <IXXxn-Htz-1@gated-at.bofh.it> |
| In reply to | #270931 |
Hi, On Sun, Jul 7, 2024 at 10:31 PM Max Nikulin wrote: > > On 08/07/2024 04:42, Lee wrote: > > On Mon, Jul 1, 2024 at 11:02 AM Max Nikulin wrote: > >> On 01/07/2024 13:57, Lee wrote: > >>> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842292 > [...] > >> Is libnss built with logging support ABI compatible with the variant in > >> Debian repositories? (Or can it be patched to achieve ABI > >> compatibility?) Instead of asking for changing compile flags for all > >> users, from my point of view, it is better to suggest alternative > >> packages with and without logging enabled. > >> > >> Browsers are rather sensitive applications, so I find it reasonable that > >> dumping of encryption keys are not available by default. > > > > Maybe I don't know enough to know what's "reasonable" or not.. but I > > don't see a problem with me being able to inspect the traffic between > > me and some website. > > Is it OK for you that e.g. GnuPG agent disables tracing by default, so > attaching a debugger or a tool like strace is not so easy? It makes > harder to debug some issues. I didn't realize that GnuPG disables tracing by default, so the idea of it being OK or not has never come up for me. But my first question is does it actually improve security or is it more like security theater? I don't know how hard it would be to build your own version of GnuPG that allows tracing, but if it's relatively easy it seems like disabling tracing is just a minor stumbling block instead of an actual security enhancement. > From my point of view, by default libnss3 should not allow logging of > private keys. At the same time I do not mind that some users should be > able to inspect TLS sessions. My idea is an *alternative* package that > may be optionally installed instead of regular libnss3. Comments to the > bug report request to enable debugging for *all* and I agree with the > maintainers who have not do it. You may ask for providing an additional > package for TLS debugging. > > > Anyone else wants to intercept my traffic and they'll have to set an > > environment variable - which root can do, but who else? > > IAny regular user may start browser with this variable set. Right, but presumably they intended that the variable be set. I'm asking about malicious use of that variable. Root can do pretty much whatever they want to, but how does a non-root attacker set that variable? > Some > unintentionally executed code in a user session may restart browser with > enabled logging. I would not argue that it is a great trouble if an > exploit is executed. However some measures may be taken to increase > attack complexity and disabling TLS logging is a small step in this > direction. Well, debian has taken that small step. It's no big deal for me to download firefox from mozilla, so I've got my work-around. And this is on my laptop, so the minor lack of security is only going to impact me -- nobody else uses this laptop :) > >> <https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions> > > > > but I don't know how to evaluate the security > > implications of modifying apt-get files. So I just downloaded the > > binary from mozilla > > So you trust mozilla anyway. Yes, I trust them enough to run their binary. I lack the knowledge to evaluate the security implications of following their instructions to add their repository to .. whatever it is on my machine (I don't even know what it's called.) "When in doubt, leave it out." seems applicable here. > Notice the "Signed-By" key in repository > configuration: sources.list(5), > <https://wiki.debian.org/DebianRepository/UseThirdParty> > <https://wiki.debian.org/SourcesList> > apt-secure(8), <https://wiki.debian.org/SecureApt> > > > tar -xvf firefox-115.12.0esr.tar.bz2 > > sudo mv firefox /opt/firefox-115.12.0esr/ > > sudo ln -s /opt/firefox-115.12.0esr/firefox /usr/local/bin/firefox > > I suspect that a regular user owns /opt/firefox-115.12.0esr/ and may > modify files. You're right :) Everything in /opt/firefox-115.12.0esr/ is owned by me. But again, this in on a laptop that nobody else is going to use so ... I dunno.. maybe I'll chown everything to root so it can't be accidentally updated. > It should allow autoupdates, but I believe, it is an > administrator task to update browser. I agree. I've got it set up that way on my windows machine. I should probably fix it so I have to become root to update firefox. Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-07-01 03:40 +0200 |
| Subject | Re: Browser traffic interception/inspection (was: how2 format a flash drive) |
| Message-ID | <IVebn-6Og5-1@gated-at.bofh.it> |
| In reply to | #270616 |
Hi, On Sat, Jun 29, 2024 at 4:45 PM Jeffrey Walton wrote: > > On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: > > > > [...] Debian firefox does NOT allow one to do > > TLS intercept - ie. this does not work: > > C:\UTIL>cat firefox-tlsdecode.bat > > set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt > > start C:\"Program Files\Firefox\Firefox.exe" > > > > @rem wireshark: > > @rem edit / preferences > > @rem protocols / tls (v2.6: protocols / ssl) > > @rem paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log > > filename (was SSL debug file entry) > > I'm not sure who your complaint is against -- Debian, Firefox or > Linux. I'm also not sure that it is a valid complaint. It is 100% a valid complaint. And it's a complaint against Debian because they're the ones that turned off that functionality. They have <reasons>, I disagree, I'm free to build Firefox for myself, get somebody else to doit for me, or get it somewhere else. ... which is the downside of free software. Technically, yes, I'm free to build the software with whatever I want enabled, with whatever changes I want added/deleted. In practice, my ability to build Firefox is .. lacking :( > Firefox uses its own certificate store. If you want to proxy your > traffic, then the proxy's root cert needs to be in Mozilla's > certificate store. See > <https://support.mozilla.org/en-US/kb/setting-certificate-authorities-firefox>. Right. I have privoxy & occasionally do set it for +https-inspection when I want it to inspect/modify web traffic. > Chrome is different. I've never used Chrome & don't intend to. > When you are intercepting/inspecting traffic, you typically setup your > proxy, and then proxy Firefox and Chrome traffic through your proxy. > The proxy can run on your local machine, like 127.0.0.1. Your proxy's > root certificate should be in the browser's store (as described > above). Or you can tell firefox to write the SSL key info to a file that wireshark can read & then decrypt the traffic. For example https://everything.curl.dev/usingcurl/tls/sslkeylogfile.html Best Regards, Lee
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-07-01 03:50 +0200 |
| Subject | Re: Browser traffic interception/inspection (was: how2 format a flash drive) |
| Message-ID | <IVel3-6Om4-3@gated-at.bofh.it> |
| In reply to | #270682 |
On Sun, Jun 30, 2024 at 9:35 PM Lee <ler762@gmail.com> wrote: > > On Sat, Jun 29, 2024 at 4:45 PM Jeffrey Walton wrote: > > > > On Sat, Jun 29, 2024 at 4:13 PM Lee wrote: > > > > > > [...] Debian firefox does NOT allow one to do > > > TLS intercept - ie. this does not work: > > > C:\UTIL>cat firefox-tlsdecode.bat > > > set SSLKEYLOGFILE=C:\Users\Lee\AppData\Local\Temp\FF-SSLkeys.txt > > > start C:\"Program Files\Firefox\Firefox.exe" > > > > > > @rem wireshark: > > > @rem edit / preferences > > > @rem protocols / tls (v2.6: protocols / ssl) > > > @rem paste SSLKEYLOGFILE filename into (Pre)-Master-Secret log > > > filename (was SSL debug file entry) > > > > I'm not sure who your complaint is against -- Debian, Firefox or > > Linux. I'm also not sure that it is a valid complaint. > > It is 100% a valid complaint. And it's a complaint against Debian > because they're the ones that turned off that functionality. > They have <reasons>, I disagree, I'm free to build Firefox for myself, > get somebody else to doit for me, or get it somewhere else. It looks like the change is due to NSS (Network Security Services), not Firefox: <https://bugzilla.mozilla.org/show_bug.cgi?id=908046> and <https://bugzilla.mozilla.org/show_bug.cgi?id=1183318>. I think the 3318 bug is most relevant, but I may be mistaken. If I am parsing the various bug reports properly, it looks like SSLKEYLOGFILE was disabled by default for release builds. It looks like you might have to perform your own debug build to gain access again. Or maybe the nightly builds of Firefox will have it. > ... which is the downside of free software. Technically, yes, I'm > free to build the software with whatever I want enabled, with whatever > changes I want added/deleted. > In practice, my ability to build Firefox is .. lacking :( Yeah, trying to build some of these projects is the pits. Jeff
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-07-01 07:50 +0200 |
| Subject | Re: Browser traffic interception/inspection (was: how2 format a flash drive) |
| Message-ID | <IVi5j-6RpY-7@gated-at.bofh.it> |
| In reply to | #270683 |
On Sun, Jun 30, 2024 at 9:46 PM Jeffrey Walton <noloader@gmail.com> wrote: > > On Sun, Jun 30, 2024 at 9:35 PM Lee <ler762@gmail.com> wrote: > >[...] > > ... which is the downside of free software. Technically, yes, I'm > > free to build the software with whatever I want enabled, with whatever > > changes I want added/deleted. > > In practice, my ability to build Firefox is .. lacking :( > > Yeah, trying to build some of these projects is the pits. One way out of this may be to make a Request for Packaging, <https://wiki.debian.org/RFP>. Ask for debug builds of Firefox. Since Debian is now supplying release builds in their release channel, it might make sense for Debian to provide debug builds for web developers. Web developers can install firefox-debug as a www-browser alternative, and do things like debug protocol issues. Regular users would still get the release version of Firefox, so regular users would be protected from some of the security problems associated with the debug build. And you still might try the nightly build of Firefox, and see if it provides the features that you are looking for. If the nightly build has what you need, then you won't have to spend time on the RFP. Jeff
[toc] | [prev] | [next] | [standalone]
| From | Keith Bainbridge <keithrbau@gmail.com> |
|---|---|
| Date | 2024-06-30 08:20 +0200 |
| Message-ID | <IUW4N-6CL2-3@gated-at.bofh.it> |
| In reply to | #270603 |
On 30/6/24 06:43, mick.crane wrote: > On 2024-06-29 17:46, Lee wrote: > >> My gripes and difficulties are the same thing. No universal image >> viewer like Ifranview, > > geeqie is quick, > something equivalent to notepad++, > Geany > +5 for geany -- All the best Keith Bainbridge keithrbau@gmail.com keith.bainbridge.3216@gmail.com +61 (0)447 667 468 UTC + 10:00
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-07-01 08:00 +0200 |
| Message-ID | <IVif0-6RuW-3@gated-at.bofh.it> |
| In reply to | #270603 |
On Sat, Jun 29, 2024 at 4:13 PM Lee <ler762@gmail.com> wrote: > > On Tue, Jun 25, 2024 at 7:26 PM George wrote: > > [...] > > If you have any grips or difficulties, please mention them. > > My gripes and difficulties are the same thing. [...] > something equivalent to notepad++, You might give Notepadqq a spin. I've used it in the past, and it has a comparable look and feel to Notepad++. <https://github.com/notepadqq/notepadqq>. If TAB works kind of funny, then see this bug report and fix: <https://github.com/notepadqq/notepadqq/issues/792#issuecomment-569470654>. (I don't know if it was merged). Jeff
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2024-07-06 17:50 +0200 |
| Message-ID | <IXfPH-fUp-1@gated-at.bofh.it> |
| In reply to | #270469 |
Hello,
On Tue, Jun 25, 2024 at 09:53:41AM -0400, Lee wrote:
> My question is: how do I reformat the flash drive so it's usable as a
> "normal" flash drive again?
Nowadays, people rarely "format" (*) their "drives".
They create filesystems on raw devices.
For example `mkfs.ext4 /dev/sdX`, where /dev/sdX is the raw device
corresponding to your USB key (see the lsblk command, for example).
> Nothing I tried worked.. I ended up putting the thumb drive in a
> Windows machine and formatting it there; it would be nice to know how
> to restore the thumb drive to working order on Debian.
However, for Microsoft compatibility, in addition, you will need
a partition table. Linux, except for booting (because of BIOS
requirements), does not require partition tables.
So, first create a partition e.g. with fdisk[1]: this will make
/dev/sdX1 available in lsblk.
Then again, for Microsoft compatibility, you need to create
a Microsoft-compatible filesystem. One good alternative is
VFAT.
Thus with `mkfs.vfat /dev/sdX1`.
Please double-check you use the right raw device name, as fdisk and mkfs
commands are destructive.
(*) actually the last time I did format a device using a SCSI
command was in the nineties -- some people differentiate
"low-level formatting" with "high-level formatting", which
is better called "creating a filesystem" -- yes back then
it was sometimes useful to reformat using 256 bytes/sector
for RAID0 applications :)
[1] https://www.digitalocean.com/community/tutorials/create-a-partition-in-linux
[toc] | [prev] | [standalone]
Page 3 of 3 — ← Prev page 1 2 [3]
Back to top | Article view | linux.debian.user
csiph-web