news
today's howtos
-
Piya Gehi ☛ Homelab networking: the basics
This setup worked just fine, however I was curious if I could separate the routing configuration into a VM of its own. I’d seen posts and videos configuring routers using open-source router distributions like pfSense and OpenWRT, and I wanted to try them out too.
-
Feld ☛ Ignore Discord Updates
I'm running Discord on FreeBSD at the moment and it was going well, but my most recent launch caused me to be caught in a loop preventing me from getting past the forced update screen. I'd update if it was possible, but a newer version isn't available in my package manager yet.
-
Linux Handbook ☛ Find Subdomains Fast with OWASP Amass: Don't Miss Hidden Entry Points
In this lab, you'll practice asset discovery with OWASP Amass. Get a comprehensive list of subdomains you might not have even known existed.
-
Bring CachyOS KVM Hypervisor along with KDE Plasma 6.5.2 and Kernel 6.17.7 to Arch GNU/Linux VM
-
University of Toronto ☛ OIDC, Identity Providers, and avoiding some obvious security exposures
OIDC (and OAuth2) has some frustrating elements that make it harder for programs to support arbitrary identity providers (as discussed in my entry on the problems facing MFA-enabled IMAP in early 2025). However, my view is that these elements exist for good reason, and the ultimate reason is that an OIDC-like environment is by default an obvious security exposure (or several of them). I'm not sure there's any easy way around the entire set of problems that push towards these elements or something quite like them.