Boudhayan Gupta (he/him)
sudo.foo
Boudhayan Gupta (he/him)
@sudo.foo
Aging nerd, anti-Stuxnet guy at Siemens. Free software, open-source tech, pro-EU, anti-surveillence, all the good stuff. And lots of travel. #SlavaUkraini
Reposted by Boudhayan Gupta (he/him)
Full US tarrifs 🇺🇸⚡️
April 2, 2025 at 8:36 PM
Reposted by Boudhayan Gupta (he/him)
Mozilla’s response to the ToS change. I’ve been in enough meetings with lawyers on GDPR, policy etc to believe them
March 1, 2025 at 2:04 PM
Reposted by Boudhayan Gupta (he/him)
December 13, 2024 at 7:54 PM
Reposted by Boudhayan Gupta (he/him)
Origami Black Hole xkcd.com/3033
January 3, 2025 at 7:02 PM
Reposted by Boudhayan Gupta (he/him)
(explaining bluesky to incoming folks) YOU RELEASE THE UNHINGED THOUGHT INTO THE TEXTBOX AND PRESS POST
November 11, 2024 at 3:08 AM
Reposted by Boudhayan Gupta (he/him)
bro: you let your dog sleep in your bed?

me: bro, i’d let my dog borrow my car if he needed it
November 11, 2024 at 4:22 AM
Reposted by Boudhayan Gupta (he/him)
Disposal xkcd.com/3005
October 31, 2024 at 3:21 AM
Very reasonable
But... why?!
October 19, 2024 at 5:23 PM
Reposted by Boudhayan Gupta (he/him)
Photography: The Final Days of the Dinosaur, 65m BC (colorized)
October 18, 2024 at 1:14 AM
Reposted by Boudhayan Gupta (he/him)
Software Testing Day xkcd.com/2928
May 4, 2024 at 3:25 AM
Reposted by Boudhayan Gupta (he/him)
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.
This might be the best executed supply chain attack we've seen described in the open, and it's a nightmare scenario: malicious, competent, authorized upstream in a widely used library.

Looks like this got caught by chance. Wonder how long it would have taken otherwise.
Woah. Backdoor in liblzma targeting ssh servers.

www.openwall.com/lists/oss-se...

It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…

Now I’m curious what it does in RSA_public_decrypt
March 30, 2024 at 5:13 PM
Reposted by Boudhayan Gupta (he/him)
if you want to survive on here you have to establish yourself. you gotta look around, find the biggest, wokest account you can, walk right up to them and scold them for insufficient intersectionality
February 6, 2024 at 6:16 PM
Reposted by Boudhayan Gupta (he/him)
Today’s bake for brother’s 40th. I believe I have outdone myself.
January 28, 2024 at 12:34 PM
Reposted by Boudhayan Gupta (he/him)
the punishment is a bit medieval but i appreciate the enthusiasm
January 17, 2024 at 2:11 PM
Reposted by Boudhayan Gupta (he/him)
nailed it
December 16, 2023 at 5:51 AM
Reposted by Boudhayan Gupta (he/him)
homosexuals always say “be gay do crimes” until someone like george santos actually tries to live that life
October 16, 2023 at 10:34 PM
Reposted by Boudhayan Gupta (he/him)
Typical Seating Chart xkcd.com/2862
December 2, 2023 at 12:42 AM
After some 3 years of waiting for everyone to have enough time, I finally got around to watching The VelociPastor, and boy what a movie it is! 15/10 recommended watch, can't wait for the sequel!

Like seriously, the movie is almost too good to be a trash movie.
December 1, 2023 at 10:53 AM
Reposted by Boudhayan Gupta (he/him)
This really is the greatest correction of all time.
November 24, 2023 at 3:03 AM
Reposted by Boudhayan Gupta (he/him)
Breaker Box xkcd.com/2848
October 31, 2023 at 2:25 AM
Reposted by Boudhayan Gupta (he/him)
I'm addressing the controversy.

Time to tackle the popcorn button
youtu.be/Limpr1L8Pss
November 21, 2023 at 4:23 PM
Can you still use this app on a day the sky is not blue?
November 20, 2023 at 10:25 AM
Wait what? We'd been hearing for years that Jimmy Carter was gonna die in the next 10 mins and now he's outlived his wife?
November 19, 2023 at 10:11 PM