Communick News

120 readers
1 users here now

Communick is a professional, privacy-focused service provider who supports open source and the indieweb. We support back the fediverse and the developers by pledging 20% of our yearly profits to the main development teams.

All users from this instance are expected to follow the Code of Conduct.

At the moment, only the admins can create communities. We are still figuring out what type of content we would like to provide here, but the general guideline is that we want to build a home of good discussion about culture, sports, and anything that can inspire and elevate our spirits.

Communick also provides managed hosting for Lemmy instances if you want to run your own.

For further questions, try our support.

founded 3 years ago
ADMINS
1
 
 
2
 
 
3
 
 
4
 
 
5
6
 
 

Christa Pike, who survived two doses of a lethal injection drug last week during a botched execution in Tennessee, is conscious and speaking, her lawyers said in a statement on Tuesday.

Ms. Pike continues to receive critical medical care at a Nashville hospital, the lawyers said. The prognosis remains unclear, they said, but they expect a long recovery.

“Christa is a survivor and will take recovery one day at a time,” the lawyers said.

Ms. Pike, 50, is believed to be the first person to have survived doses of a lethal injection drug. She has been hospitalized since the execution attempt on Sept. 30, after it became clear to witnesses that she was still breathing after two doses of pentobarbital, the drug used in lethal injection executions.

...

7
 
 
8
 
 
9
 
 
10
 
 
11
 
 

Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.

12
 
 

I'm sharing this one because I'm curious what more knowledgeable people think about this one. Please take a peek at the article before joining the discussion, as my limited quote might have dropped useful information

The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.

For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.

Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.

13
 
 
14
 
 
15
 
 

Psiphon, which helps people living in oppressive regimes evade online censorship, says Bill C-22 would compel it to help build a surveillance system in this country

16
 
 

17
 
 
18
 
 
19
 
 

20
 
 

21
 
 
22
 
 
23
 
 

A federal judge in Boston has blocked one of the Trump administration's most aggressive immigration enforcement tools: civil fines imposed on migrants who remain in the United States after receiving final deportation orders. U.S. District Judge George O'Toole ruled that the administration's system was unlawfully imposed and stopped enforcement of the penalties while a class-action lawsuit continues. The case was brought by two migrants facing the fines and the Immigrant Legal Resource Center.

full story : https://realnarrativenews.com/editorial/trump-migrant-fines-ruling-otoole-998-dollar-a-day/

24
 
 
25
 
 

I've been trying to set up hibernation on my laptop while also maintaining an encrypted root partition and swap using secure boot and my laptop's TPM. I've documented the steps I've followed below, but I still am unable to enable hibernation.

I was under the impression that the only reason you can't normally have both an encrypted harddrive and hibernation was because swap had to be encrypted as well, but if both the root partition and the swap are encrypted, I'm using UEFI secure boot, and they are automatically decrypted at boot using the TPM, shouldn't that relieve those security concerns?

After completing the below, entering systemctl hibernate errors saying hibernation is not set up for the system. Am I missing something or is it just not possible? I can confirm not needing to enter passwords for my swap or root FS due to the TPM unlock.

My personal documentation below:

Drop into root shell

sudo su -

Setup LUKS encryption with automatic unlock with TPM

Install necessary components, regenerate initramfs and reboot

dnf install -y clevis clevis-luks clevis-dracut clevis-udisks2 clevis-systemd
dracut -fv --regenerate-all && systemctl reboot

Identify swap and root partition devices, names, and luks UUIDs...

lsblk -f
cryptsetup luksUUID <UUID>

In my case, my home partition is on /dev/nvme0n1p4 and my swap is /dev/nvme0n1p3

# the encrypted home partition
clevis luks bind -d /dev/nvme0n1p4 tpm2 '{"pcr_ids":"1,4,5,7"}'

# the encrypted swap
clevis luks bind -d /dev/nvme0n1p3 tpm2 '{"pcr_ids":"1,4,5,7"}'

Set a timeout before the system asks for a password, to allow time for the TPM to load and enter the password for you systemctl edit systemd-ask-password-plymouth.service

Add the below then ctrl+o ctrl+x to save and exit

[Service]
ExecStartPre=/bin/sleep 10

Create a dracut configuration file to install the systemd-ask-password-plymouth service: vi /etc/dracut.conf.d/systemd-ask-password-plymouth.conf

Add the below, ensure there are spaces inside the quotation marks on either side of the filename

install_items+=" /etc/systemd/system/systemd-ask-password-plymouth.service.d/override.conf "

Regenerate initramfs and reboot

dracut -fv ‐‐regenerate-all && systemctl reboot

Edit crypttab file (/etc/crypttab)to specify decryption of swap file at boot, duplicate the already present line for your root FS crypttab entry and change the UUIDs to reflect the swap file, use cryptsetup luksUUID /dev/nvme0n1p3 and cryptsetup luksUUID /dev/nvme0n1p4 to get the luks UUIDs for your root and swap partitions.

<swap LUKS UUID> UUID=<swap UUID> none x-initrd.attach
<root FS LUKS UUID> UUID=<root FS UUID> none x-initrd.attach

Regenerate initramfs and reboot: dracut -fv --regenerate-all && systemct reboot

Edit fstab to include swap, append the following to /etc/fstab:

UUID=<swap UUID> none swap defaults,x-systemd.device-timeout=0 1 1

Rebind your home and swap partitions. You will have to do this every time you update the kernel.

# encrypted home partition
clevis luks regen -d /dev/nvme0n1... -s 1

# encrypted swap
clevis luks regen -d /dev/nvme0n1... -s 1
view more: next ›