mintCast 256 – Open Source Collaboration Tools

Download

News:

BASHing on Windows:

Main Topic: Open Source Collaboration Tools

Tips & Websites:

Pre-Show Music:

Podcast Announcements:

More Information:

Hosts: Rob, Scott, Joe and Isaac
Live Stream every other Sunday 2:00 p.m.(Central): mintcast.org/livestream

Contact Us:

More Linux Mint info: website, blog, forums, community

Credits:

Podcast Entry and exit music provided by Mark Blasco (podcastthemes.com). Podcast bumpers provided by Oscar.

Advertisements

8 thoughts on “mintCast 256 – Open Source Collaboration Tools

  1. No comments about the content of this podcast yet, but some O.T. thoughts …
    – not happy about the election, but at least here in Cali we finally Decriminalized marijuana. Too bad Texas is still in the Deep Dark Ages, Rob. Perhaps some of your politicos will tour the border, be hit by a flying bale of weed and come to their senses.
    – did Scott ever bring this website 11foot8.com to your attention? Plenty of clueless truck drivers in his backyard.
    – just found a namesake malware, forgot if you’ve covered it: https://malwaretips.com/blogs/ads-by-mint-cast-network-removal/ Yikes!

  2. Issac, I wouldn’t worry too much about ‘broadening the attack surface’ of Windows 10 from Bash-on-Linux-on-Windows-for-subsystem-kernel-developer-addon. This feature is so well hidden and obfuscated that it’s user base is likely to be the same as FerinOS. (Six or seven users max).
    Security in obfuscation!!!

  3. Seems like there’s a lot of confusion over the Windows Subsystem for Linux (WSL). While it is in effect like a linux virtual machine, it’s more akin to Wine than a virtual machine. So there’s no actual Linux kernel in there and no code is shared with the Linux kernel. It’s more of an implementation of the Linux kernel API using native Windows calls. It’s not a complete implementation either, but it can run a lot of unmodified Linux binaries. And as such, Linux kernel patches are not directly applicable or relevant to the WSL. The Linux COW bug, for example does not exist in the WSL, as that sort of thing is done in the Windows kernel. Any bug there is a Windows bug and would affect Windows’ native apps and security and would be patched there.

    Yes WSL does theoretically increase the attack surface somewhat because of some elevated privileges drivers that get installed in the Windows kernel. This is unlike Wine which implements and emulates everything without root privileges. But it’s not as if MS will have to be following kernel exploit patching since they don’t use the Linux kernel, unless the bug is something fundamental in how the kernel API works. Except for the work done by these Windows kernel drivers, to my knowledge, everything you do in the WSL is running as your normal user, even when you are root in the WSL.

    I’ve had the Ubuntu “Bash” stuff (horrible name) installed for a while and it’s a novelty, but I don’t really see the usefulness of it. It certainly doesn’t really help folks who have to work in Window but would prefer a Linux command line, as you can’t really do much with Windows from inside the WSL. So it’s no good for scripting. And if you just want a comfortable command line and your favorite text editor, you can run those from Cygwin. I’ve used Cygwin for decades to assist me in managing and scripting (remotely even) work on Windows.

    If your listeners want to play with the WSL but don’t have Windows 10 lying around, you can download[1] the official ISO from Microsoft and install it in a virtual machine. It will run unactivated indefinitely (if you do activate it as a demo you’ll only get 30 days). You can also download virtual machines[2] from Microsoft to play with, but those come pre-activated and expire after 30 days.

    [1] https://www.microsoft.com/en-us/software-download/windows10ISO
    [2] https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/

  4. Not pointed at you guys, but in general at all the un-informed reporting that started with the pre-release announcement. There is so much information available straight from the horses mouth it just doesn’t make sense to speculate, wonder, pontificate, or slam concepts or uses that may not be fully understood. Here are several videos and articles that contain actual information.
    http://blog.dustinkirkland.com/2016/03/questions-and-answers-about-bash-and.html
    http://blog.dustinkirkland.com/2016/08/howdy-windows-six-part-series.html

Comments are closed.