Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by Joanna Rootkovska ☠️ (rootkovska@mastodon.social)

  1. Joanna Rootkovska ☠️ (rootkovska@mastodon.social)'s status on Monday, 24-Apr-2017 08:44:53 UTC Joanna Rootkovska ☠️ Joanna Rootkovska ☠️

    I really like draw.io, a free Visio alternative, which also works fine in *offline* mode as a Chrome app (I tested it in offline VM).

    But it would be even cooler if there was an easy way to package Chrome Apps as RPM or DEB, as then it could be easily installed in a template VM for use in many different AppVMs. Anyone knows how to do that?

    (The diagram below is for an upcoming post on Qubes Compromises Recovery, BTW)

    In conversation Monday, 24-Apr-2017 08:44:53 UTC from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/000/324/520/original/2ceefc28a9eae3ad.png
  2. Joanna Rootkovska ☠️ (rootkovska@mastodon.social)'s status on Thursday, 13-Apr-2017 15:05:22 UTC Joanna Rootkovska ☠️ Joanna Rootkovska ☠️
    • Micah Lee

    About the Subgraph attack:
    1. The main problem that @micahflee exploited is the unfortunate decision made by Subgraph OS to keep Gnome/Nautilus in the TCB *and* letting this complex software process *untrusted* files,
    2. The specific Nautilus bug (handling of .desktop files) is just *one* example of what could go wrong in this case,
    3. We can think of other potential problems (e.g. Thumbnails processing)
    4. More details: https://micahflee.com/2017/04/breaking-the-security-model-of-subgraph-os/

    In conversation Thursday, 13-Apr-2017 15:05:22 UTC from mastodon.social permalink

    Attachments


User actions

    Joanna Rootkovska ☠️

    Joanna Rootkovska ☠️

    Distrusts Things

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          3019
          Member since
          11 Apr 2017
          Notices
          2
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • Privacy
          • Source
          • Version
          • Contact

          Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.