emacs/var/elfeed/db/data/45/4598795ecdb8d430de57bd364c436216518b9826
2022-01-03 12:49:32 -06:00

165 lines
6.3 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<h3><strong>-- During The Show --</strong></h3>
<h4>00:45 Steve&#39;s OpenSuse Experience</h4>
<ul>
<li>Splash Screen</li>
<li>Kernel Panic</li>
</ul>
<h4>03:10 Caller Ed</h4>
<ul>
<li>Best VM server</li>
<li><a href="https://www.proxmox.com/en/" rel="nofollow">Proxmox</a></li>
<li><a href="https://libvirt.org/" rel="nofollow">Libvirt</a> + <a href="https://cockpit-project.org/" rel="nofollow">Cockpit</a></li>
<li><a href="https://www.ovirt.org/" rel="nofollow">Ovirt</a></li>
</ul>
<h4>08:08 Sleuth Asked</h4>
<ul>
<li>Is there software to send and receive audio over the network that work on phones and Linux machines? My usecase is I want to listen to podcasts from antennapod on my computer and to monitor jitsi and mumble from my phone.</li>
<li>Alsa Mixer</li>
<li><a href="https://icecast.org/" rel="nofollow">IceCast</a></li>
</ul>
<h4>09:58 TwoBit Asked</h4>
<ul>
<li>Still using the Google Glass?</li>
<li>Yes</li>
</ul>
<h4>10:43 Docker Server - Mathieu</h4>
<ul>
<li>TLS/HTTPS is more than a cert</li>
<li><a href="https://www.haproxy.org/" rel="nofollow">HAProxy</a>/Nginx Reverse Proxy</li>
<li>Check documentation for the project</li>
<li>Security is more than closing ports</li>
<li><a href="https://letsencrypt.org/" rel="nofollow">LetsEncrypt</a></li>
</ul>
<h4>19:25 Archiving Emails? - Jose</h4>
<ul>
<li>Download an archive + Thunderbird</li>
</ul>
<h4>23:26 SIP Questions - Andrew</h4>
<ul>
<li><a href="https://www.3cx.com/docs/3cx-tunnel-session-border-controller/" rel="nofollow">3CX SBC</a></li>
<li>Upgrade Router to PFSense/OPNSense</li>
</ul>
<h4>28:10 Pick of the Week</h4>
<ul>
<li><a href="https://www.casaos.io/" rel="nofollow">CasaOS</a></li>
<li><a href="https://www.helpnetsecurity.com/2021/12/13/casaos-home-cloud-system/" rel="nofollow">Help Net Security Article</a></li>
<li>Based on Docker</li>
<li>Easy Self Hosted Services</li>
</ul>
<h4>30:23 Gadget of the Week</h4>
<ul>
<li><a href="https://shop.m5stack.com/products/m5stickc-plus-esp32-pico-mini-iot-development-kit?variant=35275856609444" rel="nofollow">M5stick</a></li>
<li>$14 ESP32 Dev Kit</li>
</ul>
<h4>32:52 Centos 8 EOL</h4>
<ul>
<li><a href="https://www.zdnet.com/article/centos-linux-8-is-about-to-die-what-do-you-do-next/" rel="nofollow">ZDNet Article</a></li>
<li>CentOS EOL Dec 31 2021</li>
<li>Zero Day security patches until Jan 31 2022</li>
<li>Options
<ul>
<li>Red Hat Proper</li>
<li>Free Red Hat Developer License&#39;s</li>
<li><a href="https://www.centos.org/centos-stream/" rel="nofollow">CentOS Stream</a></li>
<li><a href="https://almalinux.org/" rel="nofollow">Alma Linux</a></li>
<li>Cloud Linux OS</li>
<li>Rocky Linux</li>
</ul></li>
</ul>
<h4>38:00 Toyota Makes Keyfob a Service</h4>
<ul>
<li><a href="https://www.thedrive.com/news/43329/toyota-made-its-key-fob-remote-start-into-a-subscription-service" rel="nofollow">The Drive Article</a></li>
<li>Requiring subscription to use local keyfob functions</li>
</ul>
<h4>40:38 Pop!_OS 21.10 Released</h4>
<ul>
<li><a href="https://blog.system76.com/post/670564272872488960/popos-2110-has-landed" rel="nofollow">System76 Blog Post</a></li>
<li>Tech preview of Pop!_OS 21.10 for the RaspberryPi</li>
<li>System Refresh feature</li>
<li>Lots of new features </li>
</ul>
<h4>42:44 Main Segment - log4j Vulnerability</h4>
<ul>
<li>CVE-2021-44228</li>
<li>Remote Code Execution</li>
<li>Actively being exploited in the wild</li>
<li>Used in embedded and IOT devices as well</li>
<li><a href="https://www.youtube.com/watch?v=7qoPDq41xhQ" rel="nofollow">Minecraft Exploit Example</a></li>
<li>2.14.1 and earlier vulnerable</li>
<li>Fixed in Log4j 2.15.0</li>
<li><a href="https://github.com/YfryTchsGD/Log4jAttackSurface" rel="nofollow">Github Attack Surface List</a></li>
<li>Responsible disclosure was not followed</li>
<li>Alternative mitigations available</li>
<li>Flip the environmental variable ES JAVA OPTS= -D log4j2.formatMsgNoLookups=True</li>
<li><a href="https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/" rel="nofollow">Cloudflare Mitigation</a></li>
<li><a href="https://www.helpnetsecurity.com/2021/12/12/week-in-review-apache-log4j-0day-exploited-kali-linux-2021-4-released-patch-tuesday-forecast/" rel="nofollow">Help Net Security Article</a></li>
<li><a href="https://fortune.com/2021/12/13/cyber-security-log4j-hacker-breach/" rel="nofollow">Fortune Article</a></li>
<li><a href="https://www.welivesecurity.com/2021/12/13/log4shell-vulnerability-what-we-know-so-far/" rel="nofollow">We Live Securtiy Article</a></li>
<li><a href="https://thenextweb.com/news/log4j-bug-internet-open-source-contributors-analysis" rel="nofollow">The Next Web Article</a></li>
</ul>
<h3><strong>-- The Extra Credit Section --</strong></h3>
<p>For links to the articles and material referenced in this week&#39;s episode check out this week&#39;s page from our podcast dashboard!</p>
<p><a href="http://podcast.asknoahshow.com/263" rel="nofollow">This Episode&#39;s Podcast Dashboard</a></p>
<p><a href="http://www.voxtelesys.com/asknoah" rel="nofollow">Phone Systems for Ask Noah provided by Voxtelesys</a></p>
<p>Join us in our dedicated chatroom <a href="https://element.linuxdelta.com/#/room/#geeklab:linuxdelta.com" rel="nofollow">#GeekLab:linuxdelta.com on Matrix</a></p>
<h3><strong>-- Stay In Touch --</strong></h3>
<p><strong>Find all the resources for this show on the Ask Noah Dashboard</strong></p>
<blockquote>
<p><a href="http://www.asknoahshow.com" rel="nofollow">Ask Noah Dashboard</a></p>
</blockquote>
<p><strong>Need more help than a radio show can offer? Altispeed provides commercial IT services and theyre excited to offer you a great deal for listening to the Ask Noah Show. Call today and ask about the discount for listeners of the Ask Noah Show!</strong></p>
<blockquote>
<p><a href="http://www.altispeed.com/" rel="nofollow">Altispeed Technologies</a></p>
</blockquote>
<p><strong>Contact Noah</strong></p>
<blockquote>
<p>live [at] asknoahshow.com</p>
</blockquote>
<p><strong>-- Twitter --</strong></p>
<ul>
<li><a href="https://twitter.com/kernellinux" rel="nofollow">Noah - Kernellinux</a></li>
<li><a href="https://twitter.com/asknoahshow" rel="nofollow">Ask Noah Show</a></li>
<li><a href="https://twitter.com/altispeed" rel="nofollow">Altispeed Technologies</a></li>
</ul><p>Special Guest: Steve Ovens.</p><p><a href="https://patreon.com/linuxdelta" rel="payment">Support Ask Noah Show</a></p>