Felix Krohn
felix@sozial.dezern.at
DON'T PANIC! Doing a bit here, a byte there @ Puzzle ITC 馃З: k8s, OpenShift, Container Security. Bare metal background.

I鈥檓 not pirating movies, I鈥檓 just training my model.

2锔忊儯1锔忊儯 Here's the 21st post highlighting key new features of the upcoming v257 release of systemd. #systemd257

systemd-repart is systemd's dynamic, incremental automatic disk repartitioning tool. It started out as a tool for automatically creating additional partitions on first boot, in a declarative way, but turned into something a lot more powerful: a generic image builder with a deep understanding of fancy encryption (dm-crypt), authentication (dm-verity) and more.

Is Escapism the only working therapy for the Dystopia that's called Reality? Asking for a friend.

Situation Summary

SELinux bypasses

An amazing article by Klecko about different approaches to bypassing SELinux in Android kernel exploits.

The author lists multiple ways to disable SELinux via an arbitrary address read/write primitive and shows which of them are detected by the Samsung and Huawei hypervisors (spoiler: not all 馃榿).

klecko.github.io/posts/selinux

Sometimes Google's AI results are accurate.

Code comments