<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Fri, 03 Apr 2026 18:35:06 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>TechSNAP - Episodes Tagged with “Crypto”</title>
    <link>https://techsnap.systems/tags/crypto</link>
    <pubDate>Fri, 03 Apr 2020 00:15:00 -0700</pubDate>
    <description>Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a portion of the show to answer audience questions, discuss best practices, and solving your problems.
</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>Systems, Network, and Administration Podcast. </itunes:subtitle>
    <itunes:author>Jupiter Broadcasting</itunes:author>
    <itunes:summary>Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a portion of the show to answer audience questions, discuss best practices, and solving your problems.
</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:owner>
      <itunes:name>Jupiter Broadcasting</itunes:name>
      <itunes:email>chris@jupiterbroadcasting.com</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<item>
  <title>426: Storage Stories</title>
  <link>https://techsnap.systems/426</link>
  <guid isPermaLink="false">658dd254-b721-4281-8415-9357e180e92b</guid>
  <pubDate>Fri, 03 Apr 2020 00:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/658dd254-b721-4281-8415-9357e180e92b.mp3" length="22528023" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We take a look at Cloudflare's impressive Linux disk encryption speed-ups, and explore how zoned storage tools like dm-zoned and zonefs might help mitigate the downsides of Shingled Magnetic Recording.</itunes:subtitle>
  <itunes:duration>31:17</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We take a look at Cloudflare's impressive Linux disk encryption speed-ups, and explore how zoned storage tools like dm-zoned and zonefs might help mitigate the downsides of Shingled Magnetic Recording.  
Plus we celebrate WireGuard's inclusion in the Linux 5.6 kernel, and fight some exFAT FUD. 
</description>
  <itunes:keywords>WireGuard, Linux 5.6, kernel module, networking, encryption, security, Ubuntu, Debian, Windows, zonefs, Zoned Storage, SMR, Shingled Magnetic Recording, SSD, NVMe, firmware, block device, dm-zoned, filesystems, device mapper, Western Digital, ZFS, RAID, Seagate, Microsoft, Samsung, Google, Andoird, Paragon Software, exFAT, FUD, open source, free software, NTFS, NTFS-3G, SMB, Samba, Cloudfare, crypto, dm-crypt, DevOps, TechSNAP, Jupiter Broadcasting, A Cloud Guru, sysadmin podcast, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We take a look at Cloudflare&#39;s impressive Linux disk encryption speed-ups, and explore how zoned storage tools like dm-zoned and zonefs might help mitigate the downsides of Shingled Magnetic Recording.  </p>

<p>Plus we celebrate WireGuard&#39;s inclusion in the Linux 5.6 kernel, and fight some exFAT FUD.</p><p>Links:</p><ul><li><a title="WireGuard VPN makes it to 1.0.0—and into the next Linux kernel" rel="nofollow" href="https://arstechnica.com/gadgets/2020/03/wireguard-vpn-makes-it-to-1-0-0-and-into-the-next-linux-kernel/">WireGuard VPN makes it to 1.0.0—and into the next Linux kernel</a> &mdash; It's a good day for WireGuard users—DKMS builds will soon be behind us.
</li><li><a title="Linux 5.6 Is The Most Exciting Kernel In Years With So Many New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=article&amp;item=linux-56-features&amp;num=1">Linux 5.6 Is The Most Exciting Kernel In Years With So Many New Features</a></li><li><a title="fs: New zonefs file system" rel="nofollow" href="https://lwn.net/Articles/793585/">fs: New zonefs file system</a> &mdash; zonefs is a very simple file system exposing each zone of a zoned block device as a file. This is intended to simplify implementation of application zoned block device raw access support by allowing switching to the well known POSIX file API rather than relying on direct block device file ioctls and read/write.</li><li><a title="Ama-ZNS! Zonefs File-System Will Land with Linux® 5.6" rel="nofollow" href="https://blog.westerndigital.com/zonefs-file-system-linux-5-6/">Ama-ZNS! Zonefs File-System Will Land with Linux® 5.6</a></li><li><a title="What is Zoned Storage and the Zoned Storage Initiative?" rel="nofollow" href="https://blog.westerndigital.com/what-is-zoned-storage-initiative/">What is Zoned Storage and the Zoned Storage Initiative?</a> &mdash; Zoned Storage is a new paradigm in storage motivated by the incredible explosion of data. Our data-driven society is increasingly dependent on data for every-day life and extreme scale data management is becoming a necessity. </li><li><a title="Linux Kernel Support - ZonedStorage.io" rel="nofollow" href="https://www.zonedstorage.io/introduction/linux-support/">Linux Kernel Support - ZonedStorage.io</a></li><li><a title="dm-zoned" rel="nofollow" href="https://www.kernel.org/doc/html/latest/admin-guide/device-mapper/dm-zoned.html">dm-zoned</a> &mdash; The dm-zoned device mapper target exposes a zoned block device as a regular block device.</li><li><a title="Device Mapper - ZonedStorage.io" rel="nofollow" href="https://zonedstorage.io/linux/dm/#dm-zoned">Device Mapper - ZonedStorage.io</a></li><li><a title=" What are PMR and SMR hard disk drives?" rel="nofollow" href="https://www.synology.com/en-us/knowledgebase/DSM/tutorial/Storage/PMR_SMR_hard_disk_drives"> What are PMR and SMR hard disk drives?</a></li><li><a title="Beware of SMR drives in PMR clothing" rel="nofollow" href="https://zfsonlinux.topicbox.com/groups/zfs-discuss/T759a10612888a9d9-Me469c98023e1a2cb059f9391/beware-of-smr-drives-in-pmr-clothing">Beware of SMR drives in PMR clothing</a> &mdash; WD and Seagate are both submarining Drive-managed SMR (DM-SMR) drives into channels, disguised as "normal" drives.</li><li><a title="Beware of SMR drives in PMR clothing [Reddit]" rel="nofollow" href="https://www.reddit.com/r/zfs/comments/frsic7/beware_of_smr_drives_in_pmr_clothing/">Beware of SMR drives in PMR clothing [Reddit]</a></li><li><a title="The exFAT filesystem is coming to Linux—Paragon software’s not happy about it" rel="nofollow" href="https://arstechnica.com/information-technology/2020/03/the-exfat-filesystem-is-coming-to-linux-paragon-softwares-not-happy-about-it/">The exFAT filesystem is coming to Linux—Paragon software’s not happy about it</a> &mdash; When software and operating system giant Microsoft announced its support for inclusion of the exFAT filesystem directly into the Linux kernel back in August, it didn't get a ton of press coverage. But filesystem vendor Paragon Software clearly noticed this month's merge of the Microsoft-approved, largely Samsung-authored version of exFAT into the VFS for-next repository, which will in turn merge into Linux 5.7—and Paragon doesn't seem happy about it.</li><li><a title="The New Microsoft exFAT File-System Driver Is Set To Land With Linux 5.7" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=New-exFAT-For-Linux-5.7">The New Microsoft exFAT File-System Driver Is Set To Land With Linux 5.7</a></li><li><a title="Speeding up Linux disk encryption - The Cloudflare Blog" rel="nofollow" href="https://blog.cloudflare.com/speeding-up-linux-disk-encryption/">Speeding up Linux disk encryption - The Cloudflare Blog</a> &mdash; Encrypting data at rest is vital for Cloudflare with more than 200 data centres across the world. In this post, we will investigate the performance of disk encryption on Linux and explain how we made it at least two times faster for ourselves and our customers.</li><li><a title="Add inline dm-crypt patch and xtsproxy Crypto API patch" rel="nofollow" href="https://github.com/cloudflare/linux/blob/master/patches/0023-Add-DM_CRYPT_FORCE_INLINE-flag-to-dm-crypt-target.patch">Add inline dm-crypt patch and xtsproxy Crypto API patch</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We take a look at Cloudflare&#39;s impressive Linux disk encryption speed-ups, and explore how zoned storage tools like dm-zoned and zonefs might help mitigate the downsides of Shingled Magnetic Recording.  </p>

<p>Plus we celebrate WireGuard&#39;s inclusion in the Linux 5.6 kernel, and fight some exFAT FUD.</p><p>Links:</p><ul><li><a title="WireGuard VPN makes it to 1.0.0—and into the next Linux kernel" rel="nofollow" href="https://arstechnica.com/gadgets/2020/03/wireguard-vpn-makes-it-to-1-0-0-and-into-the-next-linux-kernel/">WireGuard VPN makes it to 1.0.0—and into the next Linux kernel</a> &mdash; It's a good day for WireGuard users—DKMS builds will soon be behind us.
</li><li><a title="Linux 5.6 Is The Most Exciting Kernel In Years With So Many New Features" rel="nofollow" href="https://www.phoronix.com/scan.php?page=article&amp;item=linux-56-features&amp;num=1">Linux 5.6 Is The Most Exciting Kernel In Years With So Many New Features</a></li><li><a title="fs: New zonefs file system" rel="nofollow" href="https://lwn.net/Articles/793585/">fs: New zonefs file system</a> &mdash; zonefs is a very simple file system exposing each zone of a zoned block device as a file. This is intended to simplify implementation of application zoned block device raw access support by allowing switching to the well known POSIX file API rather than relying on direct block device file ioctls and read/write.</li><li><a title="Ama-ZNS! Zonefs File-System Will Land with Linux® 5.6" rel="nofollow" href="https://blog.westerndigital.com/zonefs-file-system-linux-5-6/">Ama-ZNS! Zonefs File-System Will Land with Linux® 5.6</a></li><li><a title="What is Zoned Storage and the Zoned Storage Initiative?" rel="nofollow" href="https://blog.westerndigital.com/what-is-zoned-storage-initiative/">What is Zoned Storage and the Zoned Storage Initiative?</a> &mdash; Zoned Storage is a new paradigm in storage motivated by the incredible explosion of data. Our data-driven society is increasingly dependent on data for every-day life and extreme scale data management is becoming a necessity. </li><li><a title="Linux Kernel Support - ZonedStorage.io" rel="nofollow" href="https://www.zonedstorage.io/introduction/linux-support/">Linux Kernel Support - ZonedStorage.io</a></li><li><a title="dm-zoned" rel="nofollow" href="https://www.kernel.org/doc/html/latest/admin-guide/device-mapper/dm-zoned.html">dm-zoned</a> &mdash; The dm-zoned device mapper target exposes a zoned block device as a regular block device.</li><li><a title="Device Mapper - ZonedStorage.io" rel="nofollow" href="https://zonedstorage.io/linux/dm/#dm-zoned">Device Mapper - ZonedStorage.io</a></li><li><a title=" What are PMR and SMR hard disk drives?" rel="nofollow" href="https://www.synology.com/en-us/knowledgebase/DSM/tutorial/Storage/PMR_SMR_hard_disk_drives"> What are PMR and SMR hard disk drives?</a></li><li><a title="Beware of SMR drives in PMR clothing" rel="nofollow" href="https://zfsonlinux.topicbox.com/groups/zfs-discuss/T759a10612888a9d9-Me469c98023e1a2cb059f9391/beware-of-smr-drives-in-pmr-clothing">Beware of SMR drives in PMR clothing</a> &mdash; WD and Seagate are both submarining Drive-managed SMR (DM-SMR) drives into channels, disguised as "normal" drives.</li><li><a title="Beware of SMR drives in PMR clothing [Reddit]" rel="nofollow" href="https://www.reddit.com/r/zfs/comments/frsic7/beware_of_smr_drives_in_pmr_clothing/">Beware of SMR drives in PMR clothing [Reddit]</a></li><li><a title="The exFAT filesystem is coming to Linux—Paragon software’s not happy about it" rel="nofollow" href="https://arstechnica.com/information-technology/2020/03/the-exfat-filesystem-is-coming-to-linux-paragon-softwares-not-happy-about-it/">The exFAT filesystem is coming to Linux—Paragon software’s not happy about it</a> &mdash; When software and operating system giant Microsoft announced its support for inclusion of the exFAT filesystem directly into the Linux kernel back in August, it didn't get a ton of press coverage. But filesystem vendor Paragon Software clearly noticed this month's merge of the Microsoft-approved, largely Samsung-authored version of exFAT into the VFS for-next repository, which will in turn merge into Linux 5.7—and Paragon doesn't seem happy about it.</li><li><a title="The New Microsoft exFAT File-System Driver Is Set To Land With Linux 5.7" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=New-exFAT-For-Linux-5.7">The New Microsoft exFAT File-System Driver Is Set To Land With Linux 5.7</a></li><li><a title="Speeding up Linux disk encryption - The Cloudflare Blog" rel="nofollow" href="https://blog.cloudflare.com/speeding-up-linux-disk-encryption/">Speeding up Linux disk encryption - The Cloudflare Blog</a> &mdash; Encrypting data at rest is vital for Cloudflare with more than 200 data centres across the world. In this post, we will investigate the performance of disk encryption on Linux and explain how we made it at least two times faster for ourselves and our customers.</li><li><a title="Add inline dm-crypt patch and xtsproxy Crypto API patch" rel="nofollow" href="https://github.com/cloudflare/linux/blob/master/patches/0023-Add-DM_CRYPT_FORCE_INLINE-flag-to-dm-crypt-target.patch">Add inline dm-crypt patch and xtsproxy Crypto API patch</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>422: Multipath Musings</title>
  <link>https://techsnap.systems/422</link>
  <guid isPermaLink="false">7c9cef4d-3995-411c-9613-8e74e8156f5a</guid>
  <pubDate>Fri, 07 Feb 2020 00:15:00 -0800</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/7c9cef4d-3995-411c-9613-8e74e8156f5a.mp3" length="17013783" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We take a look at a few exciting features coming to Linux kernel 5.6, including the first steps to multipath TCP.</itunes:subtitle>
  <itunes:duration>23:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We take a look at a few exciting features coming to Linux kernel 5.6, including the first steps to multipath TCP. 
Plus the latest Intel speculative execution vulnerability, and Microsoft's troubled history with certificate renewal. 
</description>
  <itunes:keywords>Automation, Let's Encrypt, SSL, TLS, CacheOut, Microsoft, Teams, Nagios, Monitoring, Linux, WireGuard, VPN, Edge, Edgium, browser wars, Chrome, blink, Chromium, Firefox, open standards, world wide web, Linux 5.6, Ubuntu 20.04, poly1305, Jason Donenfeld, networking, crypto, cryptography, mptcp, Multipath TCP, iOS, Apple, mobile, LTE, 5G, failover, 3GPP, Intel, speculative execution, ZombieLoad, TSX, SGX, cloud, virtualization, buffer overflow, stack smashing, stack canary, ASLR, DevOps, TechSNAP, Jupiter Broadcasting, A Cloud Guru, Linux Academy, sysadmin podcast, </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We take a look at a few exciting features coming to Linux kernel 5.6, including the first steps to multipath TCP. </p>

<p>Plus the latest Intel speculative execution vulnerability, and Microsoft&#39;s troubled history with certificate renewal.</p><p>Links:</p><ul><li><a title="Oregon company makes top bid for Microsoft check - CNET" rel="nofollow" href="https://www.cnet.com/news/oregon-company-makes-top-bid-for-microsoft-check/">Oregon company makes top bid for Microsoft check - CNET</a></li><li><a title="Microsoft’s failures to renew: Teams, Hotmail, and Hotmail.co.uk | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/02/yesterdays-multi-hour-teams-outage-was-due-to-an-expired-ssl-certificate/">Microsoft’s failures to renew: Teams, Hotmail, and Hotmail.co.uk | Ars Technica</a></li><li><a title="Microsoft Teams goes down after Microsoft forgot to renew a certificate - The Verge" rel="nofollow" href="https://www.theverge.com/2020/2/3/21120248/microsoft-teams-down-outage-certificate-issue-status">Microsoft Teams goes down after Microsoft forgot to renew a certificate - The Verge</a></li><li><a title="Browser review: Microsoft’s new “Edgium” Chromium-based Edge | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/01/browser-review-microsofts-new-edgium-chromium-based-edge/">Browser review: Microsoft’s new “Edgium” Chromium-based Edge | Ars Technica</a></li><li><a title="Linus Torvalds pulled WireGuard VPN into the 5.6 kernel source tree | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/01/linus-torvalds-pulled-wireguard-vpn-into-the-5-6-kernel-source-tree/">Linus Torvalds pulled WireGuard VPN into the 5.6 kernel source tree | Ars Technica</a></li><li><a title="Ubuntu 20.04 LTS Adds WireGuard Support - Phoronix" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Ubuntu-20.04-Adds-WireGuard">Ubuntu 20.04 LTS Adds WireGuard Support - Phoronix</a></li><li><a title="Multipath TCP Support Is Working Its Upstream - First Bits Landing With Linux 5.6 - Phoronix" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Linux-5.6-Starts-Multipath-TCP">Multipath TCP Support Is Working Its Upstream - First Bits Landing With Linux 5.6 - Phoronix</a></li><li><a title="MultiPath TCP - Linux Kernel implementation" rel="nofollow" href="https://www.multipath-tcp.org/">MultiPath TCP - Linux Kernel implementation</a></li><li><a title="Upstreaming multipath TCP" rel="nofollow" href="https://lwn.net/Articles/800501/">Upstreaming multipath TCP</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=Y64n_R14GtI">LPC2019 - Multipath TCP Upstreaming - YouTube</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - Slides" rel="nofollow" href="https://linuxplumbersconf.org/event/4/contributions/435/attachments/247/438/LPC2019-Upstreaming-MPTCP-slides.pdf">LPC2019 - Multipath TCP Upstreaming - Slides</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - Paper" rel="nofollow" href="https://linuxplumbersconf.org/event/4/contributions/435/attachments/246/428/LPC2019-Upstreaming-MPTCP-paper.pdf">LPC2019 - Multipath TCP Upstreaming - Paper</a></li><li><a title="Using MultiPath TCP to enhance home networks" rel="nofollow" href="https://www.sajalkayan.com/post/fun-with-mptcp.html">Using MultiPath TCP to enhance home networks</a></li><li><a title="Linux 5.6 Crypto Getting AVX/AVX2/AVX-512 Optimized Poly1305" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Linux-5.6-Crypto-AVX-Poly1305">Linux 5.6 Crypto Getting AVX/AVX2/AVX-512 Optimized Poly1305</a></li><li><a title="Poly1305" rel="nofollow" href="https://en.wikipedia.org/wiki/Poly1305">Poly1305</a></li><li><a title="CacheOut" rel="nofollow" href="https://cacheoutattack.com/">CacheOut</a></li><li><a title="CacheOut Paper" rel="nofollow" href="https://cacheoutattack.com/CacheOut.pdf">CacheOut Paper</a></li><li><a title="Intel Responds to ZombieLoad and CacheOut Attacks | Tom&#39;s Hardware" rel="nofollow" href="https://www.tomshardware.com/news/intel-responds-to-zombieload-and-cacheout-attacks">Intel Responds to ZombieLoad and CacheOut Attacks | Tom's Hardware</a></li><li><a title="New CacheOut Attack Targets Intel CPUs, Leaks Data From VMs And Secure Enclave" rel="nofollow" href="https://hothardware.com/news/cacheout-attack-intel-cpus-leaks-data-vms-secure-enclave">New CacheOut Attack Targets Intel CPUs, Leaks Data From VMs And Secure Enclave</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We take a look at a few exciting features coming to Linux kernel 5.6, including the first steps to multipath TCP. </p>

<p>Plus the latest Intel speculative execution vulnerability, and Microsoft&#39;s troubled history with certificate renewal.</p><p>Links:</p><ul><li><a title="Oregon company makes top bid for Microsoft check - CNET" rel="nofollow" href="https://www.cnet.com/news/oregon-company-makes-top-bid-for-microsoft-check/">Oregon company makes top bid for Microsoft check - CNET</a></li><li><a title="Microsoft’s failures to renew: Teams, Hotmail, and Hotmail.co.uk | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/02/yesterdays-multi-hour-teams-outage-was-due-to-an-expired-ssl-certificate/">Microsoft’s failures to renew: Teams, Hotmail, and Hotmail.co.uk | Ars Technica</a></li><li><a title="Microsoft Teams goes down after Microsoft forgot to renew a certificate - The Verge" rel="nofollow" href="https://www.theverge.com/2020/2/3/21120248/microsoft-teams-down-outage-certificate-issue-status">Microsoft Teams goes down after Microsoft forgot to renew a certificate - The Verge</a></li><li><a title="Browser review: Microsoft’s new “Edgium” Chromium-based Edge | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/01/browser-review-microsofts-new-edgium-chromium-based-edge/">Browser review: Microsoft’s new “Edgium” Chromium-based Edge | Ars Technica</a></li><li><a title="Linus Torvalds pulled WireGuard VPN into the 5.6 kernel source tree | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2020/01/linus-torvalds-pulled-wireguard-vpn-into-the-5-6-kernel-source-tree/">Linus Torvalds pulled WireGuard VPN into the 5.6 kernel source tree | Ars Technica</a></li><li><a title="Ubuntu 20.04 LTS Adds WireGuard Support - Phoronix" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Ubuntu-20.04-Adds-WireGuard">Ubuntu 20.04 LTS Adds WireGuard Support - Phoronix</a></li><li><a title="Multipath TCP Support Is Working Its Upstream - First Bits Landing With Linux 5.6 - Phoronix" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Linux-5.6-Starts-Multipath-TCP">Multipath TCP Support Is Working Its Upstream - First Bits Landing With Linux 5.6 - Phoronix</a></li><li><a title="MultiPath TCP - Linux Kernel implementation" rel="nofollow" href="https://www.multipath-tcp.org/">MultiPath TCP - Linux Kernel implementation</a></li><li><a title="Upstreaming multipath TCP" rel="nofollow" href="https://lwn.net/Articles/800501/">Upstreaming multipath TCP</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - YouTube" rel="nofollow" href="https://www.youtube.com/watch?v=Y64n_R14GtI">LPC2019 - Multipath TCP Upstreaming - YouTube</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - Slides" rel="nofollow" href="https://linuxplumbersconf.org/event/4/contributions/435/attachments/247/438/LPC2019-Upstreaming-MPTCP-slides.pdf">LPC2019 - Multipath TCP Upstreaming - Slides</a></li><li><a title="LPC2019 - Multipath TCP Upstreaming - Paper" rel="nofollow" href="https://linuxplumbersconf.org/event/4/contributions/435/attachments/246/428/LPC2019-Upstreaming-MPTCP-paper.pdf">LPC2019 - Multipath TCP Upstreaming - Paper</a></li><li><a title="Using MultiPath TCP to enhance home networks" rel="nofollow" href="https://www.sajalkayan.com/post/fun-with-mptcp.html">Using MultiPath TCP to enhance home networks</a></li><li><a title="Linux 5.6 Crypto Getting AVX/AVX2/AVX-512 Optimized Poly1305" rel="nofollow" href="https://www.phoronix.com/scan.php?page=news_item&amp;px=Linux-5.6-Crypto-AVX-Poly1305">Linux 5.6 Crypto Getting AVX/AVX2/AVX-512 Optimized Poly1305</a></li><li><a title="Poly1305" rel="nofollow" href="https://en.wikipedia.org/wiki/Poly1305">Poly1305</a></li><li><a title="CacheOut" rel="nofollow" href="https://cacheoutattack.com/">CacheOut</a></li><li><a title="CacheOut Paper" rel="nofollow" href="https://cacheoutattack.com/CacheOut.pdf">CacheOut Paper</a></li><li><a title="Intel Responds to ZombieLoad and CacheOut Attacks | Tom&#39;s Hardware" rel="nofollow" href="https://www.tomshardware.com/news/intel-responds-to-zombieload-and-cacheout-attacks">Intel Responds to ZombieLoad and CacheOut Attacks | Tom's Hardware</a></li><li><a title="New CacheOut Attack Targets Intel CPUs, Leaks Data From VMs And Secure Enclave" rel="nofollow" href="https://hothardware.com/news/cacheout-attack-intel-cpus-leaks-data-vms-secure-enclave">New CacheOut Attack Targets Intel CPUs, Leaks Data From VMs And Secure Enclave</a></li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>406: SACK Attack</title>
  <link>https://techsnap.systems/406</link>
  <guid isPermaLink="false">310be811-6d1b-4463-96f3-8fc9579a5d66</guid>
  <pubDate>Sun, 23 Jun 2019 18:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/310be811-6d1b-4463-96f3-8fc9579a5d66.mp3" length="31361276" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>A new vulnerability may be the next 'Ping of Death'; we explore the details of SACK Panic and break down what you need to know.</itunes:subtitle>
  <itunes:duration>43:33</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>A new vulnerability may be the next 'Ping of Death'; we explore the details of SACK Panic and break down what you need to know.
Plus Firefox zero days targeting Coinbase, the latest update on Rowhammer, and a few more reasons it's a great time to be a ZFS user. 
</description>
  <itunes:keywords>SACK Panic, TCP, networking, Linux, FreeBSD, security, mss, ping of death, rowhammer, rambleed, RAM, ECC, memory, DRAM, Firefox, backdoor, Mozilla, zero day, sandbox, sandbox escape, targeted attack, cryptocurrency, crypto, ZFS, OpenZFS, TRIM, SSD, encryption, raw send, device removal, DevOps, TechSNAP</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>A new vulnerability may be the next &#39;Ping of Death&#39;; we explore the details of SACK Panic and break down what you need to know.</p>

<p>Plus Firefox zero days targeting Coinbase, the latest update on Rowhammer, and a few more reasons it&#39;s a great time to be a ZFS user.</p><p>Links:</p><ul><li><a title="SACK Panic Security Bulletin" rel="nofollow" href="https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md">SACK Panic Security Bulletin</a> &mdash; Netflix has identified several TCP networking vulnerabilities in FreeBSD and Linux kernels. The vulnerabilities specifically relate to the Maximum Segment Size (MSS) and TCP Selective Acknowledgement (SACK) capabilities. The most serious, dubbed “SACK Panic,” allows a remotely-triggered kernel panic on recent Linux kernels.</li><li><a title="Ubuntu SACK Panic Guidance" rel="nofollow" href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic">Ubuntu SACK Panic Guidance</a> &mdash; You should update your kernel to the versions specified below in the Updates section and reboot. Alternatively, Canonical Livepatch updates will be available to mitigate these two issues without the need to reboot.
</li><li><a title="Red Hat SACK Panic Advisory" rel="nofollow" href="https://access.redhat.com/security/vulnerabilities/tcpsack">Red Hat SACK Panic Advisory</a> &mdash; Red Hat customers running affected versions of these Red Hat products are strongly recommended to update them as soon as errata are available. Customers are urged to apply the available updates immediately and enable the mitigations as they feel appropriate.   

</li><li><a title="RFC 2018 - TCP Selective Acknowledgment Options" rel="nofollow" href="https://tools.ietf.org/html/rfc2018">RFC 2018 - TCP Selective Acknowledgment Options</a> &mdash; TCP may experience poor performance when multiple packets are lost from one window of data. With the limited information available from cumulative acknowledgments, a TCP sender can only learn about a single lost packet per round trip time.  An aggressive sender could choose to retransmit packets early, but such retransmitted segments may have already been successfully received. A Selective Acknowledgment (SACK) mechanism, combined with a selective repeat retransmission policy, can help to overcome these limitations.</li><li><a title="Ping of Death" rel="nofollow" href="https://insecure.org/sploits/ping-o-death.html">Ping of Death</a> &mdash; In a nutshell, it is possible to crash, reboot or otherwise kill a large number of systems by sending a ping of a certain size from a remote machine.</li><li><a title="Firefox zero-day was used in attack against Coinbase employees, not its users | ZDNet" rel="nofollow" href="https://www.zdnet.com/article/firefox-zero-day-was-used-in-attack-against-coinbase-employees-not-its-users/">Firefox zero-day was used in attack against Coinbase employees, not its users | ZDNet</a> &mdash; A recent Firefox zero-day that has made headlines across the tech news world this week was actually used in attacks against Coinbase employees, and not the company's users.</li><li><a title="Mozilla fixes second Firefox zero-day exploited in the wild | ZDNet" rel="nofollow" href="https://www.zdnet.com/article/mozilla-fixes-second-firefox-zero-day-exploited-in-the-wild/">Mozilla fixes second Firefox zero-day exploited in the wild | ZDNet</a> &mdash; Mozilla has released a second security update this week to patch a second zero-day that was being exploited in the wild to attack Coinbase employees and other cryptocurrency organizations.

</li><li><a title="RAMBleed" rel="nofollow" href="https://rambleed.com/">RAMBleed</a> &mdash; RAMBleed is a side-channel attack that enables an attacker to read out physical memory belonging to other processes. The implications of violating arbitrary privilege boundaries are numerous, and vary in severity based on the other software running on the target machine. As an example, in our paper we demonstrate an attack against OpenSSH in which we use RAMBleed to leak a 2048 bit RSA key. </li><li><a title="Digging into the new features in OpenZFS post-Linux migration | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2019/06/zfs-features-bugfixes-0-8-1/">Digging into the new features in OpenZFS post-Linux migration | Ars Technica</a> &mdash; One of the most important new features in 0.8 is Native ZFS Encryption. Until now, ZFS users have relied on OS-provided encrypted filesystem layers either above or below ZFS. While this approach does work, it presented difficulties.</li><li><a title="Allan Jude on Twitter" rel="nofollow" href="https://twitter.com/allanjude/status/1138651704558346245">Allan Jude on Twitter</a> &mdash; Once the FreeBSDs are upstreamed, everything is changing to 'OpenZFS', including the github organization currently know as 'zfsonlinux'.</li><li><a title="ZFS on Linux Releases" rel="nofollow" href="https://github.com/zfsonlinux/zfs/releases">ZFS on Linux Releases</a></li><li><a title="Linux Academy is hiring! " rel="nofollow" href="https://jobs.lever.co/linuxacademy/">Linux Academy is hiring! </a></li><li><a title="Mozilla teases $5-per-month ad-free news subscription" rel="nofollow" href="https://www.theverge.com/2019/7/5/20683059/mozilla-news-subscription-service-ad-free-scroll-price">Mozilla teases $5-per-month ad-free news subscription</a> &mdash; Mozilla has started teasing an ad-free news subscription service, which, for $5 per month, would offer ad-free browsing, audio readouts, and cross-platform syncing of news articles from a number of websites.</li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>A new vulnerability may be the next &#39;Ping of Death&#39;; we explore the details of SACK Panic and break down what you need to know.</p>

<p>Plus Firefox zero days targeting Coinbase, the latest update on Rowhammer, and a few more reasons it&#39;s a great time to be a ZFS user.</p><p>Links:</p><ul><li><a title="SACK Panic Security Bulletin" rel="nofollow" href="https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md">SACK Panic Security Bulletin</a> &mdash; Netflix has identified several TCP networking vulnerabilities in FreeBSD and Linux kernels. The vulnerabilities specifically relate to the Maximum Segment Size (MSS) and TCP Selective Acknowledgement (SACK) capabilities. The most serious, dubbed “SACK Panic,” allows a remotely-triggered kernel panic on recent Linux kernels.</li><li><a title="Ubuntu SACK Panic Guidance" rel="nofollow" href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SACKPanic">Ubuntu SACK Panic Guidance</a> &mdash; You should update your kernel to the versions specified below in the Updates section and reboot. Alternatively, Canonical Livepatch updates will be available to mitigate these two issues without the need to reboot.
</li><li><a title="Red Hat SACK Panic Advisory" rel="nofollow" href="https://access.redhat.com/security/vulnerabilities/tcpsack">Red Hat SACK Panic Advisory</a> &mdash; Red Hat customers running affected versions of these Red Hat products are strongly recommended to update them as soon as errata are available. Customers are urged to apply the available updates immediately and enable the mitigations as they feel appropriate.   

</li><li><a title="RFC 2018 - TCP Selective Acknowledgment Options" rel="nofollow" href="https://tools.ietf.org/html/rfc2018">RFC 2018 - TCP Selective Acknowledgment Options</a> &mdash; TCP may experience poor performance when multiple packets are lost from one window of data. With the limited information available from cumulative acknowledgments, a TCP sender can only learn about a single lost packet per round trip time.  An aggressive sender could choose to retransmit packets early, but such retransmitted segments may have already been successfully received. A Selective Acknowledgment (SACK) mechanism, combined with a selective repeat retransmission policy, can help to overcome these limitations.</li><li><a title="Ping of Death" rel="nofollow" href="https://insecure.org/sploits/ping-o-death.html">Ping of Death</a> &mdash; In a nutshell, it is possible to crash, reboot or otherwise kill a large number of systems by sending a ping of a certain size from a remote machine.</li><li><a title="Firefox zero-day was used in attack against Coinbase employees, not its users | ZDNet" rel="nofollow" href="https://www.zdnet.com/article/firefox-zero-day-was-used-in-attack-against-coinbase-employees-not-its-users/">Firefox zero-day was used in attack against Coinbase employees, not its users | ZDNet</a> &mdash; A recent Firefox zero-day that has made headlines across the tech news world this week was actually used in attacks against Coinbase employees, and not the company's users.</li><li><a title="Mozilla fixes second Firefox zero-day exploited in the wild | ZDNet" rel="nofollow" href="https://www.zdnet.com/article/mozilla-fixes-second-firefox-zero-day-exploited-in-the-wild/">Mozilla fixes second Firefox zero-day exploited in the wild | ZDNet</a> &mdash; Mozilla has released a second security update this week to patch a second zero-day that was being exploited in the wild to attack Coinbase employees and other cryptocurrency organizations.

</li><li><a title="RAMBleed" rel="nofollow" href="https://rambleed.com/">RAMBleed</a> &mdash; RAMBleed is a side-channel attack that enables an attacker to read out physical memory belonging to other processes. The implications of violating arbitrary privilege boundaries are numerous, and vary in severity based on the other software running on the target machine. As an example, in our paper we demonstrate an attack against OpenSSH in which we use RAMBleed to leak a 2048 bit RSA key. </li><li><a title="Digging into the new features in OpenZFS post-Linux migration | Ars Technica" rel="nofollow" href="https://arstechnica.com/gadgets/2019/06/zfs-features-bugfixes-0-8-1/">Digging into the new features in OpenZFS post-Linux migration | Ars Technica</a> &mdash; One of the most important new features in 0.8 is Native ZFS Encryption. Until now, ZFS users have relied on OS-provided encrypted filesystem layers either above or below ZFS. While this approach does work, it presented difficulties.</li><li><a title="Allan Jude on Twitter" rel="nofollow" href="https://twitter.com/allanjude/status/1138651704558346245">Allan Jude on Twitter</a> &mdash; Once the FreeBSDs are upstreamed, everything is changing to 'OpenZFS', including the github organization currently know as 'zfsonlinux'.</li><li><a title="ZFS on Linux Releases" rel="nofollow" href="https://github.com/zfsonlinux/zfs/releases">ZFS on Linux Releases</a></li><li><a title="Linux Academy is hiring! " rel="nofollow" href="https://jobs.lever.co/linuxacademy/">Linux Academy is hiring! </a></li><li><a title="Mozilla teases $5-per-month ad-free news subscription" rel="nofollow" href="https://www.theverge.com/2019/7/5/20683059/mozilla-news-subscription-service-ad-free-scroll-price">Mozilla teases $5-per-month ad-free news subscription</a> &mdash; Mozilla has started teasing an ad-free news subscription service, which, for $5 per month, would offer ad-free browsing, audio readouts, and cross-platform syncing of news articles from a number of websites.</li></ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Episode 382: Domestic Disappointments</title>
  <link>https://techsnap.systems/382</link>
  <guid isPermaLink="false">20c841ff-5ccf-4058-8e2d-f59364827c26</guid>
  <pubDate>Thu, 06 Sep 2018 19:15:00 -0700</pubDate>
  <author>Jupiter Broadcasting</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/95197d05-40d6-4e68-8e0b-2f586ce8dc55/20c841ff-5ccf-4058-8e2d-f59364827c26.mp3" length="38035774" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>Jupiter Broadcasting</itunes:author>
  <itunes:subtitle>We’re joined by a special guest to discuss the failures of campaign security, the disastrous consequences of a mismanaged firewall, and the suspicious case of Speck.</itunes:subtitle>
  <itunes:duration>44:56</itunes:duration>
  <itunes:explicit>yes</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/9/95197d05-40d6-4e68-8e0b-2f586ce8dc55/cover.jpg?v=4"/>
  <description>We’re joined by a special guest to discuss the failures of campaign security, the disastrous consequences of a mismanaged firewall, and the suspicious case of Speck.
Plus the latest vulnerabilities in Wireshark and OpenSSH, the new forensic hotness from Netflix, and some great introductions to cryptography. 
 Special Guest: Martin Wimpress.
</description>
  <itunes:keywords>eMail, Elections, Election Security, Espionage, Attachments, Security Keys, CIA, USA, Firewall, China, NSA, Speck, Android, Google, OpenSSH, SSH, Wireshark, CVE, CVSS, Security, TCP, ISP, BGP, 500 mile email, TCP RST, Diffy, Netflix, crypto, cryptography, diffy, netflix, manga, linux, devops, podcast</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We’re joined by a special guest to discuss the failures of campaign security, the disastrous consequences of a mismanaged firewall, and the suspicious case of Speck.</p>

<p>Plus the latest vulnerabilities in Wireshark and OpenSSH, the new forensic hotness from Netflix, and some great introductions to cryptography. </p><p>Special Guest: Martin Wimpress.</p><p>Links:</p><ul><li><a title="I’m teaching email security to Democratic campaigns. It’s as bad as 2016." rel="nofollow" href="https://www.washingtonpost.com/outlook/2018/09/04/im-teaching-email-security-democratic-campaigns-its-bad/">I’m teaching email security to Democratic campaigns. It’s as bad as 2016.</a></li><li><a title="Botched CIA Communications System Helped Blow Cover of Chinese Agents" rel="nofollow" href="https://foreignpolicy.com/2018/08/15/botched-cia-communications-system-helped-blow-cover-chinese-agents-intelligence/">Botched CIA Communications System Helped Blow Cover of Chinese Agents</a></li><li><a title="NSA-Designed Speck Algorithm to Be Removed From Linux 4.20" rel="nofollow" href="https://www.tomshardware.com/news/nsa-speck-removed-linux-4-20,37747.html">NSA-Designed Speck Algorithm to Be Removed From Linux 4.20</a></li><li><a title="Vulnerability Affects All OpenSSH Versions Released in the Past Two Decades" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/">Vulnerability Affects All OpenSSH Versions Released in the Past Two Decades</a></li><li><a title="Wireshark can be crashed via malicious packet trace files" rel="nofollow" href="https://www.helpnetsecurity.com/2018/08/31/wireshark-dos-vulnerabilities/">Wireshark can be crashed via malicious packet trace files</a></li><li><a title="Service provider story about tracking down TCP RSTs" rel="nofollow" href="https://mailman.nanog.org/pipermail/nanog/2018-September/096871.html">Service provider story about tracking down TCP RSTs</a></li><li><a title="The case of the 500-mile email" rel="nofollow" href="http://www.ibiblio.org/harris/500milemail.html">The case of the 500-mile email</a></li><li><a title="Diffy: A cloud-centric triage tool for digital forensics and incident response" rel="nofollow" href="https://github.com/Netflix-Skunkworks/diffy">Diffy: A cloud-centric triage tool for digital forensics and incident response</a></li><li><a title="An intensive introduction to Cryptography" rel="nofollow" href="https://intensecrypto.org/public/">An intensive introduction to Cryptography</a></li><li><a title="The Manga Guide to Cryptography | No Starch Press" rel="nofollow" href="https://nostarch.com/mangacrypto">The Manga Guide to Cryptography | No Starch Press</a></li></ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We’re joined by a special guest to discuss the failures of campaign security, the disastrous consequences of a mismanaged firewall, and the suspicious case of Speck.</p>

<p>Plus the latest vulnerabilities in Wireshark and OpenSSH, the new forensic hotness from Netflix, and some great introductions to cryptography. </p><p>Special Guest: Martin Wimpress.</p><p>Links:</p><ul><li><a title="I’m teaching email security to Democratic campaigns. It’s as bad as 2016." rel="nofollow" href="https://www.washingtonpost.com/outlook/2018/09/04/im-teaching-email-security-democratic-campaigns-its-bad/">I’m teaching email security to Democratic campaigns. It’s as bad as 2016.</a></li><li><a title="Botched CIA Communications System Helped Blow Cover of Chinese Agents" rel="nofollow" href="https://foreignpolicy.com/2018/08/15/botched-cia-communications-system-helped-blow-cover-chinese-agents-intelligence/">Botched CIA Communications System Helped Blow Cover of Chinese Agents</a></li><li><a title="NSA-Designed Speck Algorithm to Be Removed From Linux 4.20" rel="nofollow" href="https://www.tomshardware.com/news/nsa-speck-removed-linux-4-20,37747.html">NSA-Designed Speck Algorithm to Be Removed From Linux 4.20</a></li><li><a title="Vulnerability Affects All OpenSSH Versions Released in the Past Two Decades" rel="nofollow" href="https://www.bleepingcomputer.com/news/security/vulnerability-affects-all-openssh-versions-released-in-the-past-two-decades/">Vulnerability Affects All OpenSSH Versions Released in the Past Two Decades</a></li><li><a title="Wireshark can be crashed via malicious packet trace files" rel="nofollow" href="https://www.helpnetsecurity.com/2018/08/31/wireshark-dos-vulnerabilities/">Wireshark can be crashed via malicious packet trace files</a></li><li><a title="Service provider story about tracking down TCP RSTs" rel="nofollow" href="https://mailman.nanog.org/pipermail/nanog/2018-September/096871.html">Service provider story about tracking down TCP RSTs</a></li><li><a title="The case of the 500-mile email" rel="nofollow" href="http://www.ibiblio.org/harris/500milemail.html">The case of the 500-mile email</a></li><li><a title="Diffy: A cloud-centric triage tool for digital forensics and incident response" rel="nofollow" href="https://github.com/Netflix-Skunkworks/diffy">Diffy: A cloud-centric triage tool for digital forensics and incident response</a></li><li><a title="An intensive introduction to Cryptography" rel="nofollow" href="https://intensecrypto.org/public/">An intensive introduction to Cryptography</a></li><li><a title="The Manga Guide to Cryptography | No Starch Press" rel="nofollow" href="https://nostarch.com/mangacrypto">The Manga Guide to Cryptography | No Starch Press</a></li></ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
