Vue normale

FreeBSD 16 Retires the Last of Its GPL Code

Par : BeauHD
15 juillet 2026 à 18:00
FreeBSD 16 has removed the last GPL-licensed code from its base system, retiring the old GNU 'dialog' implementation after the installer moved to 'bsddialog' and the final dependency was disabled. Phoronix reports: This ticket to retire dialog was opened back in February while is now merged to the FreeBSD source tree for what will become FreeBSD 16.0. With dialog removed, the latest FreeBSD code now retires the GNU sub-tree of the FreeBSD base system now that no more GNU code remains. FreeBSD 16.0 is working its way toward release that is expected to happen in December 2027.

Read more of this story at Slashdot.

How the FSF Sysadmins are Blocking Botnets with reaction

11 juillet 2026 à 21:47
For nearly two years the Free Software Foundation has been fighting web crawlers (including many aggressively scraping training data for AI models). A botnet controlling about five million IPs hit one system for six months in 2025. Their systems administrator wrote this week that they view these as distributed denial-of-service attacks. How are they fighting back? We noticed patterns in the scrapers that were abnormal, which gave us material for writing regular expressions. Searching for the regular expression then gave us a large lists of IP addresses. Looking up the origin of those IP addresses revealed that some of the crawlers were using botnets of residential IP addresses to scrape faster and avoid detection. We looked for what kinds of botnets might be generating the kind of traffic that we were seeing, and one that we suspected was called the "Vo1d" botnet, comprised of smart TVs running some sort of compromised app... We got confirmation that at least some of the botnet traffic hitting GNU Savannah was originating through the Vo1d/Popa botnet. We placed our regular expressions in fail2ban, and found that we were hitting the maximum rules that could be added to UFW firewall rules on our systems which showed degradation around 65,000 rules... We learned about ipset and configured fail2ban to add IP addresses that it found to IP sets. Using ipset, we kept building larger IP sets and did not find instability with as large as five million rules... We eventually found a promising project on Framasoft's forge Framagit called reaction written by ppom... After we ran into scaling issues with our initial implementation, we developed a much faster implementation where the reaction shutdown process would export the IP sets to disk and the reaction startup process would restore the IP sets. This allowed us to have nearly instantaneous restarts of the service to apply new rules. We published both of our configurations upstream to reaction's wiki so that everyone can benefit from it. reaction's getting started documentation now leads to the method that we proposed... Many sysadmins know about fail2ban, but not enough people know about reaction. I am very grateful to ppom for the help they have provided and for the tremendous project they have released to the world with reaction. We have implemented other defenses as well, but reaction is doing the majority of the automated work keeping our sites online.

Read more of this story at Slashdot.

Sortie de Trisquel GNU/Linux 12 « Ecne »

Par : nspanti · Arkem
24 juin 2026 à 16:46

La distribution Trisquel GNU/Linux est sortie en version 12 dite « Ecne ». Elle est basée sur Ubuntu et plus précisément sa version 24.04 dite « Noble Numbat » qui est la précédente version maintenue à long terme (Long-Term Support, ou LTS pour les intimes). Mais il y a encore un support de 3 ans (jusqu'en mai 2029) par Canonical (la société derrière Ubuntu), donc ce n'est pas grave, et ça s'explique sans doute par le peu de force de la distribution.

Mais de toute façon, quel est l'intérêt de cette énième distribution GNU/Linux ? C'est rien de moins qu'une des rares qui est 100% libre et donc approuvée par la FSF (Free Software Foundation) sur la base des GNU FSDG (Free System Distribution Guidelines), contrairement par exemple à Debian qui n'en était historiquement pas loin et a récemment régressé. Avec Trisquel, il n'y a donc notamment pas de blob privateur dans le noyau Linux (car oui, de base il en contient) et pas d'incitation à installer du logiciel privateur.

De plus, Trisquel se veut respectueux de la vie privée. On peut constater ça avec le cas des navigateurs web. Firefox n'est pas proposé au profit de Abrowser qui en est une version dérivée (fork) avec quelques améliorations. De plus, GNU IceCat est proposé et va lui plus loin. Enfin, si on veut un autre moteur web majeur, il y a ungoogled-chromium, en plus bien sûr des navigateurs web basés sur WebKit (comme GNOME Web).

Si la souveraineté ordinatique vous intéresse (il parait que c'est devenu à la mode, dans les discours du moins…), Trisquel GNU/Linux est assurément un bon choix si vous vous fichez d'avoir les dernières versions des logiciels. Toutefois il y a aussi GNU Guix si ça vous dérange.

Pour l'anecdote, un VIP du logiciel libre utilise Trisquel. Et oui, rien de moins que Richard Stallman !

Commentaires : voir le flux Atom ouvrir dans le navigateur

❌