SELinux is unmanageable; just turn it off if it gets in your way

Security-Enhanced Linux (SELinux) is a type of Mandatory Access Control (MAC) in the Linux kernel. It can prevent software from performing unexpected — such as abusive or malicious actions — on your Linux systems. However, … it's also an unmanageable mess, and I have a much greater understanding of why people recommend that people disable it.

Should you trust a third-party bootloader to run newer MacOS versions?

OpenCore lets you run the latest MacOS on unsupported Apple legacy hardware (and PCs). But software that bypasses security restrictions requires a lot of trust.

Apple periodically drops support for its older hardware, and customers get left with an increasingly insecure and outdated system. The Hackintosh scene, a community dedicated to running MacOS on unsupported hardware, might help extend the life of your Mac. However, can you trust its community-developed software to the same degree as you blindly trust Apple?

Closing the open redirect vulnerability in the Libravatar ecosystem

Libravatar is a decentralized open-source alternative to Gravatar – the avatar image service. Last week, I noticed an URL Redirection to Untrusted Site ('Open Redirect') vulnerability (CWE-601) in the Libravatar application programming interface (API) specification.

Patch origin trust vs GitHub's URL hierarchy

Opening a pull request is all it takes to get a GitHub patch URL that's indistinguishable from patches/commits that are a part of an open-source GitHub project.

Attentive readers may have noticed something a bit weird with the GitHub patch links in my last article. I shared links to two patches for Ruby's Rake build system which I also said hadn't yet been accepted into Rake. Yet, the patches looked like they came directly from the Rake project's official code repository at https://github.com/ruby/rake/. So, how did I get a patch URL that's indistinguishable from commits/patches that are part of a project?

Your clipboard is only as secure as your device

A review/critique of the complexity, security, and unpredictable user experience of modern feature-laden copy–paste clipboards in today's operating systems.

The system clipboard is part of every modern operating system. It lets us copy and paste text, images, files, and data between different applications. Like everything else these days, it's increasingly getting tied up with other people's servers ("the cloud.") So, what does that mean for your clipboard privacy?