User:Pietinger

From Gentoo Wiki
Jump to:navigation Jump to:search
Pietinger
Peter B.
Male
German
Contact info
pietinger (IRC)
Gentoo user since 2005
Babel
deThis user is a native speaker of German.
en-1This user is able to contribute with a basic level of English.

About me

Hi, I'm an old man speaking only poor school english.

On IRC, find me in #gentoo-de (webchat) as pietinger in german language, and in #gentoo-forums (webchat) in english language (with the same name).

My projects

I wrote a german articles series named "Installation Guide for Paranoid Dummies" as posts in our Gentoo Forums. It is focused on security and uses only OpenRC. In my starting post you will find links to more articles explaining FireWall, SecureBoot, encryption, AppArmor and some more. If you speak german you might be interested in it: [1]

I have translated some of this in the meantime and written it up as a wiki article. The starting article is:

User:Pietinger/New_at_Gentoo

(From here, you can also access all of the articles listed below individually.)

Personal Statements

Why did I wrote these articles?

The challenge with any technical description is striking a balance between too much and too little. If it's too long, it can discourage people from reading it. And too little information always leads to a shortfall. The Gentoo documentation, consisting of the Handbook and all Wiki articles, is no exception. That is why you won't find an introduction to using Linux on our Wiki. Likewise, our Wiki cannot cover every special case (or specific problem). However, after being active on our Gentoo Forum for many years (and still am), questions have come up there that weren’t answered by our Handbook or Wiki articles. Instead of repeating the same answers over and over again on our forum, I’ve started documenting some of this information here, so that I can simply post a link in the forum. So please consider ALL of my articles merely as "add-ons" to the existing official reference articles in our Wiki. As you read my articles, you'll also notice that I often link to existing documentation and simply describe the information that's missing from those sources, or compile it all in one place.

Why is it in the personal space instead of the official wiki space?

I often include recommendations in my articles - especially for Gentoo beginners who are sometimes overwhelmed by the possibilities Gentoo offers. And the problem with a recommendation is always: Who is making the recommendation? I can’t write "Gentoo recommends ..." unless it’s been approved by all our developers. That’s very time-consuming and impractical for "minor" recommendations. But if I write "I recommend ...", then it can’t be a reference article on our official Wiki. So it’s safe to keep it in this private space ... and that way you can hold me responsible instead of embarrassing Gentoo. :-D

Another reason is the personal tone I use when addressing you. I find that friendlier and more ‘warm’ than a ‘cold’ "One can do that". However, a personal tone is not appropriate in a reference. Our former, wonderful Sakaki also addressed you personally in her guide. (Although, unfortunately, she is no longer able to update these articles, some of them are very informative – particularly her explanations regarding SecureBoot.)

Links

Subpages

Contributions

External link collection

  • The impacts are getting closer ...

[2026-07-22] https://securityaffairs.com/195774/ai/openai-ai-models-exploited-zero-days-to-reach-hugging-face-in-benchmark-test.html

  • Even though it's just a (real) security bug in FreeBSD, this website is a must-visit:

[2026-06-11] https://bumsrake.de/

  • Thinking outside the box: Not Linux, but Windows ... or rather Microsoft: "MSRC; Tell The Whole Story Please"

[2026-05-31] https://jericho.blog/2026/05/31/msrc-tell-the-whole-story-please/

  • Why I'm not a fan of BPF: BPFdoor in Telecom Networks: Sleeper Cells in the Backbone -> "Instead, it abuses Berkeley Packet Filter (BPF) functionality to inspect network traffic directly inside the kernel, activating only when it receives a specifically-crafted trigger packet."

[2026-03-26] https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/

  • GregKH awarded the Prize for Excellence in Open Source 2026

[2026-01-30] https://daniel.haxx.se/blog/2026/01/30/gregkh-awarded-the-prize-for-excellence-in-open-source-2026/

  • A free and open-source rootkit for Linux -> "Users who feel their computers are too secure can install the Singularity kernel module in order to allow remote code execution, disable security features [...]"

[2026-01-16] https://lwn.net/Articles/1053099/ -> [[2]]

  • A slightly different interview with Linus Torvalds

[2025-12-04] https://www.youtube.com/watch?v=mfv0V1SxbNA

  • KDE Plasma 6.8 will be Wayland-only

[2025-11-26] https://lwn.net/Articles/1048208/

  • About 200K Linux systems from Framework shipped with signed UEFI components vulnerable to Secure Boot bypass [...] To defend, experts recommend [...] managing custom Secure Boot keys [...]

[2025-10-15] https://securityaffairs.com/183426/hacking/200000-linux-systems-from-framework-are-shipped-with-signed-uefi-components-vulnerable-to-secure-boot-bypass.html

  • If they really do that, it's one more reason for me not to use an LTS kernel, but only the latest kernel:

[2025-08-27] https://www.phoronix.com/news/AI-Help-Backporting-Linux-Patch

  • AI-Generated Malware in Panda Image Hides Persistent Linux Threat

[2025-07-25] https://www.aquasec.com/blog/ai-generated-malware-in-panda-image-hides-persistent-linux-threat/

  • Why I use my own keys for SecureBoot (and therefore don't need/can't use a shim):

[2025-06-27] https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856

[2025-07-16] See also: https://lwn.net/Articles/1029767/

  • I like Linus Torvalds' approach: "No, we don't make random features default to being on."

[2025-06-10] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=aef17cb3d3c43854002956f24c24ec8e1a0e3546

  • Oh no, there could be a lot of work on us (me) ... let's see what the next default config of the kernel will look like

[2025-05-05] https://www.phoronix.com/news/Linux-Modernize-x86-defconfig

  • This article shows why I am not a friend of automatic configuration creation; especially the IPv6 stateless address autoconfiguration (SLAAC)

[2025-04-30] https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/

  • The current CPU microcode is becoming increasingly important:

[2025-04-21] https://www.phoronix.com/news/Intel-Old-Microcode-Vulnerable

  • Why I have always been suspicious of “grub” (and all other boot loaders) and therefore boot my kernel directly via UEFI:

[2025-03-31] https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/

  • Tracing the thoughts of a large language model

[2025-03-27] https://www.anthropic.com/research/tracing-thoughts-language-model