/srv/irclogs.ubuntu.com/2024/06/13/#ubuntu-discuss.txt

Psi-Jackheh. So what's the real difference between here, and the main #ubuntu channel really anyway? heh02:04
arraybolt3Psi-Jack: #ubuntu = strictly support, generally strictly on-topic. #ubuntu-discuss = anything about Ubuntu, including non-support, semi-topical. #ubuntu-offtopic = free for all mess02:09
arraybolt3(well, not quite free for all but still a bit of a mess :P the Ubuntu Code of Conduct still applies but there isn't any topic at all)02:09
Psi-JackCool. So maybe a little more on the higher challenging topics would be here, such as AppArmor things, for example? *wiggles his eyebrows*02:10
arraybolt3AppArmor things are perfectly fine in #ubuntu (support topics of any difficulty are good there), but if you're thinking about enhancing/fixing/griping about AppArmor, this is the place.02:12
Psi-JackYeah. I mean, a new area of concern has been this specific lockdown of unprivileged_userns. While some things sorta kinda work, other things are outright being denied. Something as simple as discord's ipc unix socket, for a systemd user service, is being denied access to connect and read/write to the discord-ipc-0 socket for example. And I'm not02:15
Psi-Jacksure, personally, how to get that working without doing the nasty disable unprivileged_userns sysctl option.02:15
lotuspsychjegood morning02:15
Psi-JackGood aftermorning. :)02:18
luna_morning05:21
=== EriC^^_ is now known as EriC^^
luna_updating Debian and Ubuntu Servers at work today07:15
oerhekssnap refresh07:16
luna_oerheks: still at the apt update apt upgrade step ;)07:16
luna_but i am sure a snap refresh will come later today too (4 times) :D07:17
oerhekssnapd got an update recently too07:17
luna_oerheks: then i have more to do, these machines have not been updated since April-May but they are standing at a school thats having summer break now from 10th of June to 10th of August so having time to update stuff when they are not running actual production 24/7 :P07:18
oerheksoh dear07:19
luna_https://social.linux.pizza/@bittin/11260810302640564607:24
oerhekspump up the volume?07:28
luna_its up07:31
luna_anyways /me continues to work07:31
daftykinsschool kids working 24x7? now there's inaccuracy ;)14:33
ice9why until now the main ubuntu repo is not using HTTPS ?15:15
ice9package integrity checking upon download is not enough15:16
ravage1and why is it not enough?15:16
ice9because if there is MiTM on your network, the attacker can see what packages you are downloading and this is not good for privacy; also if the signing key of Ubuntu's repo is stolen somehow, the attacker can replace a package being downloading over HTTP and sign it with the authentic key15:19
ravage1then choose a mirror that supports https if you think that is a privacy problem for you15:20
ravage1https://launchpad.net/ubuntu/+archivemirrors15:20
ice9I'm talking about the main server as the main source and the default mirror. also 3rd party mirrors will sync from the main repo using HTTP right?15:21
ravage1usually rsync15:21
ravage1if the repo key is stolen you have a much bigger problem15:21
ravage1https does not help you then either15:21
ogra_yeah ... thats just fake security 15:31
luna_daftykins: well i am the IT Admin and also involved in several open source projects and have a partner, but almost done now, just gonna update some snap packages on the last machine15:31
daftykinsevery weekend is downtime though to my mind15:33
luna_daftykins: i am not hired to work on weekends ;) :P15:35
luna_but yeah true15:35
ogra_you should work on weekends, double pay and such 😉15:35
=== madmax__ is now known as madmax

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!