LINUX Unplugged - 680: Go Hack Yourself

Episode Date: August 17, 2026

We turn HexStrike’s red team agents loose on our systems, as OpenSSH warns that AI-assisted bug hunting is already changing the security race....

Transcript
Discussion (0)
Starting point is 00:00:00 Hello, friends, and welcome back to your weekly Linux talk show. My name is Chris. My name is Wes. And my name is Brent. Hello, gentlemen. Coming up on the show, we'll break down the open-sh-h-fly you probably need to know about. And then we're going to attack our own systems. In the spirit of finding issues before the bad guys do, we're going to go over how to red team your own network for fun and security.
Starting point is 00:00:32 Then we're going to round out with some great booths, some picks, and a lot more. So before we get to all of that, let's say time appropriate greetings. to our mobile room. Hello, Virtual Lug. Hey, Chris. Hi, Wes. Hello. Look at those guys.
Starting point is 00:00:46 Hello, everybody. And hello up there in the quiet listening. Hello to the live. Matrix room. Yeah, we're live. We make it a Tuesday on a Sunday over at jbblive.tv, and you can get at jupiterbroadcasting.com slash calendar in your time zone.
Starting point is 00:00:57 My time zone? Well, any time zone. We never know what time zone you're in. That's why we have the system. If we deployed the calendar today, we'd probably say it's using AI to automatically determine your location. It is, in fact,
Starting point is 00:01:09 It may be using JavaScript. It's what I guess whatever Google calendars do it, technically. I also want to say good morning to our friends over at Define Networking. Go check out Define.net slash unplug and meet Managed Nebula from the Define Networking. It's built on the open source Nebula platform. We love it. We use it. It's great. Nebula gives you fast encrypted peer-to-peer networking without routing everything through somebody else's cloud.
Starting point is 00:01:32 And it's ready for modern networks. IPV6 is built in with IPV4 or dual-stack support when you need it. And it's, the technical implementation should be studied. I'm telling you, it's great. And you can run your own lighthouses so that way you can define your network. You have control of the core of your network. And of course, they'll now provision one for you as well as part of manage nebula. And you could use Bolt.
Starting point is 00:01:56 It's huge. It was originally built for Slack for serious scale, serious privacy. And today you can connect up to 100 hosts for free, no credit card or required. You just go to define.net slash unplug. Nothing else offers nebulous level of resilience, speed, and scalability. I am telling you you're going to be impressed. Get started 100 hosts absolutely free. No credit card required.
Starting point is 00:02:19 Defined.net slash unplugged. Big thank you to Define for sponsoring the Unplugged program. And go redefine your VPN experience. Control your network destiny at Defined.net slash unplugged. We now have the schedule for Texas Linux Fest, 2026. Yeah, you can go check it out if you're curious what talks are on. offer. For a quick reminder here, it will be at the UT Commons Event Center, same place as last year, November 6th through the 7th, 2026. Yeah, not October, November 6th through the 7th. And there is early bird pricing right now. You do need to buy tickets that ends soon. So very soon. So go grab your tickets now and support Texas Linux Fest. And we'll have a link to the full schedule. We are still putting together our plan. We really, really do want to go. We feel like there's a few of these events really, really, There's no other industry that does an event like Texas Linux Fest.
Starting point is 00:03:14 The Linux community is unique in this, where it's community run, community organized, and it's so more like refreshing and recharging. It's such a great time. It's so welcoming. It's so earnest and open. How do you describe the difference between this and like a commercial vendor event? Night and day. Night and day, right?
Starting point is 00:03:32 Like going to see family instead of like some kind of scale like function. I could do five. I could do five Texas Linux events to work. one like Red Hat Summit. You know what I mean? It really is a recharger. And so even if you're not a podcaster, if you're not in the J.B. community directly,
Starting point is 00:03:49 but you're just kind of in the industry or kind of in the Linux space, I think you'd really, really enjoy it if you can make it. Well, speaking of beloved Linux conferences, we do have some news on scale as well. 24X will be taking place next year, but the dates are different. Before it's been like early March.
Starting point is 00:04:06 Yeah. Now it's going to be early April. April 1st through the 4th, 27 at the Pasadena Convention Center. April could be really busy. Yeah. Yep, at the Pasadena Convention Center. And they do have their call for presentations going now.
Starting point is 00:04:19 Yeah, open now. So closes November 1st. You've got a little while, but don't sleep on it. And then last but not least, really, Knicks Vegas. Yeah, so Nix Vegas and DefConn 34 just wrapped up. I was lucky enough to go last year. Had a wonderful time. And they did it again this year.
Starting point is 00:04:35 Another fantastic looking badge and a great set of talks. and it seems like an even more impressive setup because they've already got those talks turned around and up on YouTube. So if you want to go check them out, please do. Winks in the notes. All right, so OpenSH 10.5 has come out, and it's, A, an important update
Starting point is 00:04:54 that you probably need to install. But B, I think sort of shows us the shape of things to come. It is perhaps an example of what's probably going to be more and more common. So Mr. Payne, as best you can, can you kind of tell us what's going on and why they had to release 10.5 this week? Yeah, the big bit here is around SSH agent forwarding, which maybe you've done, right, where you have
Starting point is 00:05:16 like an SSH agent to handle how you handle your keys, maybe you got a fancy UB key or something, or you just got a key with a password and all of that kind of going. But you want to be able to use that throughout a network, right? So like you're going to one box and then you want to be able to still use your agent to be able to answer cryptographic questions further down the chain. Yeah. So that's where SSH agent forwarding comes in. well, there was an interaction between agent locking and open SSH's session binding that could allow certain operations that were supposed to stay local happen remotely through a forwarded agent.
Starting point is 00:05:48 Oh. Yeah, this included adding PKCS11 tokens and in some cases using destination restricted keys. The SSH client also, the update for it, also fixes a potential use after free bug. And on the server side, they've fixed the restrict option. in authorized keys, so it now properly applies to tunnel forwarding too. So more work in the tunnel area. Worth noting, though, tunnel forwarding is still disabled by default, so it only applies if you've actually explicitly turned it on, though plenty of people do. Yeah. Yeah. Guilty. And then, furthermore, OpenSH says it's seen, as surprise, surprise, not really,
Starting point is 00:06:27 they're seeing a surge in AI-assisted vulnerability reports. Now, of course, a lot of them don't really hold up under realistic threat models. You kind of fill out the details. But they do explicitly say findings backed by human analysis, test cases, and fixes are welcome. And perhaps more interestingly, they've seen vulnerabilities first found with AI, later independently discovered by other researchers. So two notes to that, Wes. Number one is it's sort of this double-edged sword that we continue to see with AI contributions is maybe you get 10 crappy slop reports and then you get one or two genuinely important security reports. And they still have to go through those 10 or 11 slop reports to get that one genuine.
Starting point is 00:07:13 And figuring out how to do that well and at scale is now a new open problem. But also, it seems likely that the genuinely good reports will increase as things like Kimmy K3 and DeepSeek 4 become more prevalent in the community. Yeah, the signals and noise should get better as model capability and our techniques get better. Yeah. You would have a goodness. Yeah, yeah.
Starting point is 00:07:35 So there, but that doesn't mean they see less submissions, right? So they're going to have this, and OpenSH is one of many, they're going to have this accelerated issue of if one LLM with one guy can find it, then another gal with another LM is going to find it. And it's almost, can almost be an assumed that if an LLM found that bug,
Starting point is 00:07:55 it's almost public at that point. So there's sort of an urgency in which they have to move. Yeah, and especially because we've seen like with Bitcoin projects, and I think SSH is another one, right, where it's independently maintained, not a huge team and is like a high leverage tool where if you can own that, then you can really get everywhere. They do also say that as, you know, and I wonder if we'll see this more because it's kind of a stress test of the whole like software delivery pipeline.
Starting point is 00:08:21 They are talking about doing release fixes, releasing fixes more frequently. Yeah, faster release cadence because of them. problem. Probably a good idea. Maybe. I mean, it doesn't mean that the rail boxes in Ubuntu LTS boxes up there are going to get updated any sooner. No. But hopefully it means we do have to polish that and pay us more attention. It's a good excuse to invest in securing that entire pipeline. And I mean, you're right, it doesn't mean anyone actually does the updates, but at least maybe they're there. Maybe it forces people to adopt a system that can update more frequently. I would imagine this updated release cadence, though, puts a lot of pressure on these projects to
Starting point is 00:08:55 like push forward in a pace they haven't previously seen. And so is that sustainable long term? I sure hope so because we need it more than ever. I think that's an open question too. Yeah. And could there be more security mistakes that slip in if you're going faster? There's always that concern as well. And it's, I think, isn't just an open-ness to say story, like we've said. We're really discovering bugs that have sat quietly for years getting discovered now because a machine that just has unlimited patients can go through and find these things. So we're going to see, I think, more projects with more frequent security releases. They're going to have to have some sort of continuous scanning themselves and some sort of assisted triage.
Starting point is 00:09:38 And you may see some of these projects. Would you be surprised to find like an, maybe not OpenSSAH, but a project like OpenSH have a daily branch that a company like maybe Red Hat and canonical and others are ingesting, they're running their own check. against it and they're shipping those patches as fast as possible to their customers after they've done a pass for quality checks. You could see like these LTS distros getting a faster stream of software to resolve some of this stuff. So I think it doesn't look like an isolated incident. And it reminds me of a talk just a couple of weeks ago that Open AI gave at Black Hat 2026. And this was just a few days after it became public that Open AI's testing models had breached Hugging Faces
Starting point is 00:10:23 systems. And it's a good talk. We'll link to the whole talk. I thought it was surprisingly candid. Yeah, refreshing. Very technical. And some stuff, I think, is new. Some stuff in here is novel. And there's a bit in here that's one of their takeaways is that as these models advance and as agents begin to work together, which is something that led to this breach, you're going to have to have a different speed in which you respond. He wanted to have this talk in such a rapid fashion was to share our belief of lessons learned with you as defenders. We believe this is a watershed moment for computer security as an industry, as well as, of course, for open AI and AI as a whole.
Starting point is 00:11:04 What I would internalize is that AI orchestrated, fully automated, offensive attacks are real now. And the actions we have discussed today were an unintended side effect of running evaluations on Frontier AI. In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here. The use of these offensive agent collectives results in exploit and offensive work that is faster occurring at larger scale, if you can scale up your model inference capacity or GPU count, etc., and with significantly better coordination and lower latency than you would expect of a human red team. The challenge in this moment for the industry is that we have seen what will be a dramatic acceleration of offensive capability for attackers. We have an existence proof that was unintentional, but it exists before us, and we have,
Starting point is 00:12:10 as a consequence, seen a glimpse into the near future of what attacks will look like for our industry. The challenge is that we need a similar acceleration of defense. And today, we see fully automated offense as possible. we have no such existence proof for full automation of core defensive loops in cycles and behavior. We believe it's vital at this moment to begin accelerating defense and finding ways to automate SDLC, like in the modern parlance, so incident response, vulnerability detection, vulnerability patching. There's some things that are at standout acutely as challenges for the industry to begin tackling with high urgency.
Starting point is 00:12:53 So continuous agentic red teaming is one of them. As you can see from this incident, agents are quite good at finding zero-dea-tax in the infrastructure of companies. The question that's now going to be posed is, are companies able to invest sufficient model intelligence and effort in finding and remediating their vulnerabilities before someone else that's a threat actor, does it for you? This style of operating will be different now, but ultimately we need to invest in having AI agent red teaming that enables defenders to find and remediate vulnerabilities before attackers do. And Wes made implication of this earlier, but this has been really pronounced over in the Bitcoin community recently
Starting point is 00:13:34 as that's sort of been the front line because you compromise a Bitcoin wallet, you can steal somebody's funds, you immediately get the reward. And so it's been going through the Bitcoin community, almost like locust, just going from one project after the other, stealing funds and whatnot,
Starting point is 00:13:49 as they use these tools, mostly via Kimi K3, to find weaknesses in projects, like by scanning GitHub repos and exploiting those. Yeah, the other thing that kind of stuck out with some of these recent quote-unquote escapes or just the various stories we've been talking about is just that it's not really like suddenly
Starting point is 00:14:07 all security principles or thrown out the window. If anything, it means things like defense in depth and like knowing where you're, you know, what your threat vectors are and like what you're actually trying to protect and why and having a good understanding of what's going on with your systems is more important than ever.
Starting point is 00:14:21 I mean, there is a component of being able to find more zero days, But a lot of this is also the orchestration side being able to go from doing a scan to actually executing through to getting a persistent vector or getting through the network or whatever. Yeah, like in the case of the open AI exploit, they took advantage of a package manager that was connected to the internet that had exploits. And then they took advantage of a web dev share that was available to do agent coordination. So they didn't create those exploits. They took advantage of those things, which they can be very good at. You're right. So if they had proper isolation and proper security on the Open AI network, these things would have never got now. Yeah, there's just ways you could design it if you're really trying to do this in a hardened way from the get-go.
Starting point is 00:15:03 Though that would surely slow you down. Of course, I guess the silver lining or maybe the Steelman, it would be as the models get more advanced, they have to come up with new and more sophisticated ways to isolate them, perhaps. But when you look into the root cause, it was, yeah, there was mistakes made. And, you know, it's not like necessarily there's, we will see different. zero-day rates across different projects and there's been you know and um a big part of this is sort of an economic thing of there's one part of like what is the frontier what is the you know you can pop novel software quickly sort of aspect but then just the the other side is you can just now have this market to be able to buy the automation on demand for the rest of it yeah and i think that just sort of
Starting point is 00:15:44 changes what which low-hanging fruit now becomes economic to actually attack yeah now is can you afford the credits, the token credits, and can you, you know, are you creative of what project you pointed at, et cetera. Yeah. And that's where I think there's also then on the defensive side, as we kind of heard a little bit there, is like we're going to talk a little bit about maybe what you can do with your home lab or things like that. But we also need to figure out how we can invest at scale for the free and open source communities because projects are going to need resources on the defensive side. Yeah. So I figured it was worth time figuring out how we could, as they say, red team ourselves, to try to figure out where we have low-hanging fruit. Because my
Starting point is 00:16:22 suspicion is, and I don't like making this forecast, but I suspect likely that a lot of the free software we rely on for infrastructure is going to get poked at pretty soon because that's the same infrastructure. Banks rely on, e-commerce relies on. A lot of money rides on top of the Linux stack. It's embedded in the industry in innumerable places. Yeah. And then there's monitoring and spine. If you pop, there's all kinds of advantages to popping the stuff that we rely on every single day. So I'm sort of operating under the assumption that once they get done having their fun with the Bitcoiners, they're kind of coming for the rest of us. And you're starting to see it a little bit with OpenSysh.
Starting point is 00:16:59 That makes sense. That'd be another low-hanging fruit. The other one that could be fun if you want to do a little homework is Apple released a patch for remote desktop, and now the AI-assisted reverse engineering made it possible for them to go out and chase every single Mac that hasn't been patched now. so now there's a cat and mouse game playing out. That's happening right now as we record this episode. So how do you protect yourself? It seems like it's clanker versus clanker.
Starting point is 00:17:21 It's like some sort of horrible sci-fi novel where you need to have a defensive clanker that's checking your own systems. And so I built a Red Team agent that has been hacking our infrastructure literally all week long. Chris, you alluded to attacking your own infrastructure, which I would imagine.
Starting point is 00:17:49 revealed a few things, but A, how, and B, Y? Oh, all right. You know, the Y is just to try to catch stuff. Also, you know, just try to get a sense of what it needs to be retired first. Last week, we talked about retiring our node box, and so I figured before we take it offline, let's attack it and see how vulnerable and risky it really was to have that thing in production. So you can get a sense of that. Could be nice to run it against your VPSs.
Starting point is 00:18:16 I want to stress, this is for really to audits. it your own stuff to make sure you're safe. And that's really the intention of all of this. And also to kind of get a sense of what kind of automation was out there in terms of, you know, could help, like we can run NMAP or a couple of commands ourselves, but like can we take it to the next level? You could totally just, you could do a lot of this with some port scan in and identifying the versions of stuff and then going looking up that version with CVEs it has.
Starting point is 00:18:42 Like, you could do this manually. I wanted to be able to go to my agent data and say, data, attack this. and give me a full audit. And what it would do is it would initiate some of those basics, like an NMAP and a PING and all that kind of stuff. Identify what services are open and what versions of them. And then based on that, look up the CVEs and then proceed to try to exploit them. And then if it gets that far, give me a report.
Starting point is 00:19:07 And so to accomplish that, I'm using a project. There's a lot of them out there. Don't do as I do. I'm using a project called Hex Strike, AI. And it's essentially a collection of MCPs with behind it 150 different security tools and a bunch of different autonomous AI subagents that can do these tasks. And it's pretty conventional in the execution order, but actually pretty great in the document, recovery, discovery, documentation, authorization for more advanced attacks. So Hex Strike is both a very powerful tool, but can also be a footgun because because of the types of tools it's using, they're moving so fast that the tools themselves often have exploits. So you have to build this in a way where it's extremely isolated because there is conceivably a possibility where these types of tools can be turned back around on yourself.
Starting point is 00:20:03 So I spent a quiet bit of time designing this in a way where it was completely offline and isolated. individual components would be spun up on demand, continue to be isolated, operated with wrappers and the MCPs. And so underneath it, there's a really, really good set of tools. One of them is called Nuceli, NU-C-L-E-I, which does a lot of the CVEE heavy lifting.
Starting point is 00:20:26 SQL map. Yeah. Oh, yeah, thank you. Hydra's in there, hash cats in here, NetExec, various DNS tools, web exploits, framework exploits, binary analysis tools. Fuzzers.
Starting point is 00:20:38 Yeah, there's a lot of, There's a lot of really good stuff in here. And what I wanted is I wanted something that was essentially on demand for my agent, that I could have a system that then they would give me a report. It would be documented in a particular place every single time. And I would get a summary in telegram. And so the idea was, is I want to do an attack by prompt. It's kind of what I was going for. And I know you looked at this, Wes.
Starting point is 00:21:05 Oh, yeah. I got a sort of, I'm curious to see how similar are setups were. Well, okay, so I went pretty wild. I will admit, I blew way too much time on this. I literally started this project when I got home from the show last week. You can cook it. And I finished it this morning while we were doing the stream. So, during the pre-show, as far as I said.
Starting point is 00:21:25 But I went way over complicated because I wanted to isolate. I wanted to integrate it with my Hermes agent. Oh, yeah, that's nice. If you just ran it standalone with the MCP tools, like through open code, I think it would be a much leaner, faster setup. Yeah, so that's what I basically did. Tell me about this. Yeah, I stood up Cali VM because Hextrike doesn't provide the tools. It just, like, runs them and orchestrates them.
Starting point is 00:21:45 It makes them available services them to the agent. Yeah. And I just figured, like, half of these are already in Cali, and the rest are in easy repos are easy to run on Cali because it's all designed on that. So I got that spun up in just a quick QEMU VM, and then have forwarded some ports there to wire up SSH access for the agent as well as the MCP server back. And then, yeah, kind of just kicked it off from there. I think VM is a really good approach.
Starting point is 00:22:10 You know, that keeps it as isolated as you kind of can. Yeah, and then I chose to connect it up with a mesh network, a quick little nebula network, and then I could just kind of add some groups that I could add it into. And so I knew just like, okay, well, whatever I'm actually going to target. Like, obviously you're not going to do the full, like, layer two, like all the complicated, but for sort of scanning what services were running in that kind of thing, it was perfect. Right, for really, which is what a remote attacker is going to go after, right?
Starting point is 00:22:33 Like, my analysis going in is, what is somebody who's not familiar with the land, somebody who's remote likely going to get? Maybe they've somehow got on the Wi-Fi or the land, but they're not really intricately familiar with it. So I think that accomplishes that. And then obviously in another situation, like, if I was trying to scan, like, a public VPS of mine, then I would attack it through that interface or whatever. I like the, you know, mesh network nebula, just put the host on there that you're scanning. A lot of this, too, was like, I was learning how to use this tool, right? So it's like, I didn't really want. I wasn't, I haven't got as far as like, this is like a trusted tool that I know well, right?
Starting point is 00:23:06 So I kind of wanted to have some known good hosts I could attack and be like, okay, this is stuff that even if something goes wrong is fine and I have backups of and all the rest. So one of the nice things about Heckstrike is because it is essentially, like West said, it's orchestrating established tools, but you can have, it is aware of like these are critical like financially important systems or production important systems. And this is a box I can bang on. And it comes with, it seems like a lot of prompts that it provides with as you, as you run through the tools and integrate with it, that kind of shape that too. So it's very, the resulting system just out of the box is pretty careful around, like,
Starting point is 00:23:37 I'm only going to do this with authorization and, like, you know, are we checking these boxes? And one of the things I spent a lot of time was reducing ceremony. That was the term I had to keep using is like, it wants you to sign with a key here, wants you to open up a markdown document initially and put your name in there and a date.
Starting point is 00:23:50 Like, it is serious about authorizing stuff. I'm like, no, no, no, no. I don't want to do any of that. So I did do like some initial tests. So, like, it was doing NMAP. It was doing some curls against stuff. It was using a fuzzer to attack just sort of basic ports or basic web services. It was using nuclei.
Starting point is 00:24:06 Yeah. It did some SSFRF probes. It didn't find too much because... Everything's up to date, right? Yeah, it's like a NixOS box. It's up to date. But it did... The thing that it would have found if it was a problem is...
Starting point is 00:24:17 It did immediately latch on that I have an LLM gateway there, right? And it was like, you know, you have like pretty much all your stuff. I can't get the actual key data, but I can get every all the rest of the metadata about the key, and I can see all your models and I can send requests. But it did. try like Fuzz Insert XNG, didn't find anything there.
Starting point is 00:24:34 Good, good, good, good. And then as a parallel request, I was checking out the new meta model, Muse Glimmer that they released because it was their first open weight model for a while. And this is before I'd set up
Starting point is 00:24:46 Heckstrike, so I just had that run and trying to do, because a bunch of these tools are also in mixed packages. Yes, they are. I did a separate attempt with an unknown model, so it was kind of a mixed bag,
Starting point is 00:24:56 but to just see like, well, if I just give you some of the basic tools that you would want anyway, how far can you get on the same thing. Sure. And kind of similar results, not as rich, not as well structured,
Starting point is 00:25:06 but it did get, it did find basically the same thing. It was telling, though, because one of the... This is using the meta, meta, self-hosted model? Yes, and I was running it on a rented RTX, A6,000. One issue with that model is it seems to be kind of high with hallucinations, and after doing a review, like it did all of the stuff,
Starting point is 00:25:25 it just definitely did some exaggerating in the report. So it's another, like, you've got to, going to use this kind of automation, definitely apply sort of good techniques to cut down on that kind of thing. I'd be curious if you tried one of the distilled Kimmy K3 models where they've left in all the cybers offensive, defensive stuff. Good idea. That could be really.
Starting point is 00:25:43 Some follow-up. Yeah, yeah. I did try like a whole crisscross of models I put in the dock, deep seek, memo, quens, Neematron. So I was, I drove a few of this with a bunch of them just to see which ones would refuse and which ones would actually keep doing. I got constant refusal from GPT. constant refusal. Like as soon as it realized it was dealing with a cyber security tool, it would bail. It could build all the scaffolding and all the configs. But when it kind of like dug in and realized, oh, no, this is a tool for hacking, it would stop the whole session. So I have to give a huge shout out to Minimax M3 thinking, not only is that sucker an open source model, but like never said no. Never said no. Now it's not the most clever model, but it's a hell of a worker.
Starting point is 00:26:28 and it had no problem driving some of this for me when GPT would say no. And I'm trying to do self-defense here. I'm not trying to attack anybody. I'm just trying to do self-defense. Also, I got to try groc 4.6 for like 15 minutes before I ran out of usage. And that also had no problem. And boy, did it cook. So, yeah, I like that you tried the different models.
Starting point is 00:26:47 I also use deep seek for a lot. Yeah, I think the only one of the like open ones or, you know, that non-frontier class was like high three that refused me on one part of that. Oh, really? Yeah, it was kind of surprising. But the rest of them, yeah, it was all totally fine. Yeah, the bouncing around sort of stunk. So what are the things I built into my Hermes system is when it begins, so normally it's being, it's like, it might be on,
Starting point is 00:27:10 if it's on a GPT model when it begins a process, it has to switch over to mini-max, or if it's really going deep, it could go, yeah, actually it has a, it drops to deep-seek, and if deep-seek's slower on available, it uses Kimmy K-3. Oh, nice. Yeah, it's got like a whole... A little tiered system.
Starting point is 00:27:23 Yeah, yeah. So just as a recap, you kind of have these goals, these attack goals, these audit goals that you give of Hexstrike and then you task the agent to go off and perform one of those audit goals. Hex strike runs all of the various tools, orchestrates all of the stuff you've heard about for years plus stuff you've never heard of. If it finds something, it then sort of can kick off a next layer. So there's a level one pass, a level two pass, and that level three pass, it can actually
Starting point is 00:27:48 go in there and try to exploit stuff if you've given a permission to do that and investigate further. So that is sort of the setup I wanted. and I figured we could do a little demo if you want. Yeah, we should. You want to try it? See how it goes. So I have it ready to go.
Starting point is 00:28:04 I will say that for time, I'm not going to do the most extensive, right? Because there's 150 different tools in here, all of this. So the way this kicks off is I prompt my agent, my Hermes agent data, to access the system, the Hex Strike system via a set of MCPs. And then it has a separate set of wrappers I've created, of audit and monitor the process. And then it generates a markdown report and it saves it to a sync thing directory
Starting point is 00:28:32 that will sync to my computer. So when we're done, we'll get the high-level results. Sound good, boys? Are you ready? Here we go. Please stand by. Your scan is very important to us. Thank you for scanning with data. Your patience is appreciated.
Starting point is 00:28:54 Your scan is being processed in the order it was received. Your agent is attacking your box. I'm not screwing around with this scan. I'm really giving this box everything I've got. Your report is now ready. Oh, yeah, I forgot to mention it. It plays a little thinking music while it scans. That's how I roll.
Starting point is 00:29:16 Mandatory. It's a nice touch. Thank you. Thank you. So, all right. So here we got our report. This is the box we retired last week. It's still online because it's finishing up some work.
Starting point is 00:29:25 And it's not a perfect report. I think I could have turned it up a little bit and had to be a little more aggressive. so we don't have any like massive vulnerabilities standing out here. But it discovered 10 TCP services were reachable and tested remotely. And it discovered that OpenSH identifies itself as 8.2P1. That doesn't sound modern. And EngineX identifies itself as 11718. Cockpit is well behind as well.
Starting point is 00:29:54 Here's the one I thought you might find interesting though, Wes. Port 3,000 leaks in application stack trace to an unethical. unauthenticated scanner. Hmm. What's that? A malformed basic HTTP request produces a 500 internal survey or the response exposes the internal
Starting point is 00:30:12 paths, including Apputil's proxy JS, Apputil's safe handler JS, and expresses router internals. It even reveals the failing operation cannot read properties of undefined reading ends with. So it's sort of an information disclosure, error handling weakness it discovered, that would be
Starting point is 00:30:28 a little interesting to push on, potentially. Like you read this. Yeah, what's on 3,000? So you could come back. One of the things you could do with the report is say, all right, come back and let's push on that, right? Yeah, you get things you can go drill down and on if it seems worthwhile.
Starting point is 00:30:40 It kind of critiques the Bitcoin Lightning setup we have for, hey, for responding to network requests. Anything jump out at you, Wes? It gave us a one-sentence takeaway. You ought to found a surprisingly broad and somewhat chatty service surface, including admin Bitcoin Lightning and RPC interfaces. But the part designed to determine whether any of this actually is vulnerable and failed, it failed. Because we didn't do the actual deeper scan.
Starting point is 00:31:09 So the strongest conclusion is interesting exposure, incomplete security assessment, no vulnerability is detected yet. So then it gives us a list of what we could do next here, five further steps to drill in deeper here and get Newcelli giving us a complete working vulnerability report. Newcelli completes the report, but sometimes it doesn't complete in time, so it doesn't get included. And then we also... Oh yeah, I think that was one thing I saw the bot identified with Hextrite as some timeouts were always handled kind of that great. Yeah, yeah. So there's a little bits you have to fix in there.
Starting point is 00:31:38 Also, it suggests we renew or rotate some of our TLS certificates before September 6th. And I think that also speaks to this to like, it's kind of nice just from understanding what all is happening, especially on a box like this that's like just been kind of off in the corner, right, checking up on things. Especially you could go poke around like your whole tail net
Starting point is 00:31:56 and check things out there or, you know, Right. Once the bulk of getting Hextrike set up, and depending on how you do it, it could be a really quick thing or it could be a week-long thing. But then the end of thing is like, all right, go check this box, go audit it for me. And then you can have a produce report that's consumable for yourself or a team of people. It just depends on what your audience is. So that's all manageable. And there is a few things in here. Like we need to get OpenSSH. If we were going to keep this box online, my immediate takeaways are we would have to update, we would have to update OpenSSH, EngineX, and Cockpit. And we'd probably want to look at this JSONRPC. service on 5,000 or 50,000 and one or whatever it is, and the service on 3,000. We probably need to figure out what those are, this HTTP thing that we're leaking. It does at least seem, like it makes sense given what the box is, which is a crazy smattering of Docker composed containers with a whole bunch of different ports open. And those paths are umbral paths that it's exposing through that port 3,000. So that, you know, right there, if I were putting my old hat on back in the day when I was
Starting point is 00:32:56 getting hired to do these security audits with tools that were way less cooler than this, that would be the number one thing I would go, I'd go knock on that port 3,000 a lot more and figure out what's going on there. Because it's revealing the internal structure of the entire freaking umbral setup, which is where the Bitcoin node lives. So that's a pretty juicy reveal right there. And if you knew going in, like I do, the umbral app structure, I would immediately recognize that.
Starting point is 00:33:19 And I would, that's, so machine or not, right, I could take this report. I could take it further. Or the other thing. That's what's kind of great, right? you don't need to just rely on the, like, it can just be a tool that you can use. It could be a tool to, like, work together. You can learn a bunch of how the tools work and drive it yourself. The Hermes system, this is why I wanted to integrate.
Starting point is 00:33:37 The Hermes system knows what this system is. It knows what this box's role is. It's important. So it knows, like, in a way that makes it very useful because it, first of all, before it even scan this note, I never told any, it just, hey, this is an important economic machine. Do we want to, do want to be carefully? Like, it knew all of that, right? But it also knows umbrells on there.
Starting point is 00:33:55 So it can use all of this information to inform its attack. So it's really, if you have an agent system that's managing infrastructure, you can stand this up alongside of it. And it can use that information to essentially go be a chaos monkey under your control. And you can turn up the heat depending. If you just want port knocking and pinging, you can do that. But if you want like CVE identification and then try to exploit it, you can do that. You can turn it all the way up.
Starting point is 00:34:19 But I do think it is something that's kind of a more advanced tool that people need to be extremely careful with. but looking at this open SSH situation, right? Like now I could go point this at some of our GitHub code repos or something like that. Yeah, that'd be the next thing that I was kind of trying to get set up for it, but haven't yet would be trying to get the bot tooled up to go to see if it could find things like a zero-day or issue in code. Especially if you compare it, right, you have the metadata report so you know what versions are running on whatever boxes you're trying to check out. So then it can go clone that exact version and then go check through it and run tests or, you know, set up that version. running locally to hit against as it develops the theory, that kind of thing.
Starting point is 00:34:57 I think if you want to just play with it, your setup, you know, where you had a Cali VM, really straightforward, got it going probably within an hour, I would imagine. Yeah, it was pretty easy. Yeah. And so that's how I want to try this and see what it tells me, see what I can figure out with this. Obviously, it would be a little more work. Like if I need to set up like proper bridge networking or put it, like, if I was trying to do it proper like on a land or, you know, corporate environment or something like that,
Starting point is 00:35:19 it would be more work. But because I was doing a pretty minimal test run, it made it easy. Yeah. And it's, you can do it all the way if you want. You can turn up all the way. There's a lot of tools out there to do this kind of thing. So if you have any suggestions, boost.jubiter Broadcasting.com and let us know. Yeah, because we could, we could only talk about so.
Starting point is 00:35:34 Yeah, yeah. I have a couple questions for you, Jens. Go for it. You mentioned Cali was like an important tool to use as a base for this research. I actually just pulled as much as I could from Nix packages. But Wes, I think, has a nice cheat code there. Yeah, my curiosity there is like, Callie was the golden goose for doing this. previously because it sort of collected all these tools in a place that you can use them.
Starting point is 00:35:57 And that sounds a lot like what HECStrike is doing. It's collecting a bunch of, at least, tool knowledge. It's not providing the tools themselves, but that's kind of trivial at this point. And so is this sort of the new Cali that people are going to go to, or these tools at least? I mean, I think it might be fair. Or the next wave, right? Like how we've seen, this is a really stretched analogy, right? But we saw, we see a whole lot of people generating songs and pictures that could never make music
Starting point is 00:36:23 or take a great picture before, right? So now I think you're going to see a lot of people, and you see a lot of people making some good review PRs, some bad PRs. You just see a lot more code getting generated. So what you have now is, if you know just a little bit about your network, you now have a system that can operate the tools for you. This is both enabling and also risky. It's a double-edged story.
Starting point is 00:36:48 It has more leverage, so there's more leverage. So before it took a... an understanding of how to orchestrate and stack these tools together. Like, you need to have a sense of, oh, there's something, like, you would do an enmap yourself. You would see that port 3,000 yourself. You would go try to poke at it with Telnet or throw some curls at it or whatever. And then you would just have that instinct and you would use additional tools to drill down and go do the searching you need to do. There's various workflows you've learned, right?
Starting point is 00:37:12 Attack patterns, processes that human experts have developed over years. Now this thing's doing it for you. It can do it dynamically. It can be updated every single week. and it can do it at scale. So the real trick now is the knowledge about it, how to set it up, that kind of knowledge, and then the budget to spend the tokens on some API or local model.
Starting point is 00:37:36 Like there are distilled models now that can do this locally. Like there's a Quinn model that runs locally, even on laptops that can do this. And there is that Kimi K3 model that can run on some reasonably powerful local systems now that's distilled that can do this. These are open source and local. There's also lots available.
Starting point is 00:37:51 via the APIs. So if you have access to hardware or you can pay for API credits, you essentially have access to this now. That's the barrier now. Can we talk about your token budget this week? Really? You're going to... I know it's not in the dock, but like... You're going to shame me like that? It's important. So, you know, I haven't... I have not really had to pay a lot for tokens recently, because I find minimax to be extremely useful. And it gets me really, really far. However, to get this over the hump, I did end up pulling in some Kimmy K3 and some grok.
Starting point is 00:38:28 And so to build this for my system, I spent my budget on this, I guess, you could say, I guess, was $43.90, and that was $716.4 million tokens. So it's not a cheap thing, but for me, $43, $45 to now to be able to audit JB infrastructure
Starting point is 00:38:49 on demand in a report style, that I can share with you guys. And a lot of that I imagine was the setup and tuning that would be amortized over each individual scan, which would not be that much. And you could probably drive with not the Premier. 100%. Because once you have the structure, Minimax is totally capable of handling it.
Starting point is 00:39:05 And I can basically run that forever. But, yeah, you wanted something a little more advanced to build out the structure and get this thing right. And so some Kimmy in there, some Grok in there, probably. Oh, yeah, lots of deep seek. Lots of deep seek. But deep seek's pretty cheap. that worked and then mine's all using podband containers that spin up and then disappear when they're done and stuff like that and then like with different levels of gating.
Starting point is 00:39:29 Ooh, that's fun. Mm-hmm. Mm-hmm. Mm-hmm. I'm curious, what's the next step then? Like, are you going to push this further and look at all the boxes on the J.B network? Are you going to put it aside for a second until you reassess whether you put enough controls in? I'm going to tweak the reporting a bit and the timeout issue a little bit so I can get more information.
Starting point is 00:39:51 in the report. But then what I think is probably best to point at the boxes that are sort of on the top of our list to retire and kind of just make a priority list based on these findings. You just sort of use that data to derive our decisions to sort of shore up infrastructure. Yeah, that and maybe whatever the few maximally exposed things are. Yeah. And hopefully, you know, find stuff before we get to a point where this stuff is getting widely exploited. And we, you know, we don't really want to be in a position where once a week or every few days where SSH you know these boxes and updating them. Right. And if we do get to that point, we want to have a fleet that's lean enough that it's manageable.
Starting point is 00:40:25 And probably reset up in a, you know, declarative, repeatable way so that that becomes a more sane task. I want to take a moment and mention my friends over at Connected Internet and use the promo code Jupyter 35 to get $35 off your order. They're not a sponsor, but they sent me some gear a while ago, and I just ended up using it over the weekend. And I'm like, this is so good. It's one box and it combines all of the high-speed data networks in the U.S. and Canada. And it has technology in there. It's based on, I think, an open WRTOS, and it kind of picks between the best for your signal and data and all of that.
Starting point is 00:41:00 And they have truly unlimited plans as well, including plans with priority Internet access, which means you get higher priority on the LTE network or the 5G network, and they have plans with no data caps. It's really rare out there. I mean, I have been doing this since the days of buying bootleg sims off of eBay. And to have something like this now is just remarkable. And to have it across the different popular networks, too, is really great.
Starting point is 00:41:25 And not too long ago, they introduced their backup plan. $39 a month that comes with a router and the antennae and everything you need. And it just auto fails over when your Internet goes out and auto fails back, if that's a term, auto restores, when your Internet returns. It's just great. And they also have things for more permanent installs, like their Fortress Router, which I have up at the farm. Seven antenna beast also run an OpenWRT. It's impressive. connectininternet.com is where you go connect 10 internet.com.
Starting point is 00:41:55 And if you use our promo code, Jupiter 35, you can take $35 off your entire order. They hooked me up when they send some gear, and I'm giving them a shout because I'm still using it to this day, and I think it's great. And since we don't have an official sponsor for this spot, I say go check out Connected Internet. I really liked it. And if you're mobile or you need a backup internet connection, it's a no-brainer. promo code, Jupiter 35. I've got a bunch of beautiful feedback this week, and we're going to start with Nathan. Nathan says, literally just discovered this podcast, and you happen to mention Trek, which has been my recent obsession.
Starting point is 00:42:32 I'm currently planning my honeymoon with it. Oh, cool. Oh, he means the tool. Yeah, the collaborative. No, yeah. Yeah, not Star Trek. No. The collaborative road trip and travel planning.
Starting point is 00:42:43 Okay. Okay. Continuous. I'm currently planning my honeymoon. Congratulations. With it. And it's been a dream. compared to my normal spreadsheet slash calendar workflow for trips.
Starting point is 00:42:54 It comes with a built-in MCP, so I hooked it up to my LOM setup, and I've been doing some research that way to try and find some spots off the beaten path and working them into the trip plan to include travel time, cluster locations, proximity to our hotels. It's a super polished app. I haven't tested out the collaborative features yet, but they all seem quite promising. I figured I'd write in to give the Trek recommendation a plus one.
Starting point is 00:43:22 Thank you. Now off to download the MacLog of the show because, well, seems super cool. You know, you can plug out all kinds of like travel APIs to those agents as well. There's all kinds of stuff with those. You bring it all together with Trek. I think that's great. I love how it's just like such a thoughtful thing to spend time crafting. And thank you, Nathan.
Starting point is 00:43:41 Glad you found the show. I'll take the next one. Peter Wright's in. I just want to turn you guys onto Top Grade. if you haven't heard of it yet. It updates all the things in one command so you don't have to remember what you have installed. Super useful.
Starting point is 00:43:53 Upgrade all the things with TopGrade. This may have been an ancient pick on the show way back in the day. It doesn't support every distro, obviously, but it does support quite a few of them. It also got the coveted Drew plus one behind the scenes. Oh, did it? Okay, good.
Starting point is 00:44:11 Does he use it? Yeah. Second this, Top Grade is super rat, says Drew. That is nice. That's one of the things. I like about the U-Blue stack is they have that like a U update or whatever, I don't know even now it just runs. And that updates all your packages and your flat packles.
Starting point is 00:44:25 You want to take that next one there, Mr. Pagel? Yeah, we got actually two messages from Magnus here. Okay. First one here. Hi, guys. Thanks for the fantastic content universe. You're providing long-time listener and intermittent member. I thought you might find this useful.
Starting point is 00:44:38 Yes, this is completely shameless self-promotion. Paul Hibbert even made a video on it. And I thought maybe you guys would find some exciting ways in using this home assistant tailored open code app. Super simple to start using and flexible. And it seems like it's sort of an open code that you add on to Home Assistant and then you can sort of have it directly control Home Assistant
Starting point is 00:44:58 just from the plugin. In Open Code. Yeah. So that... Fascinating. It can drive everything. I mean, that makes sense. Home Assistant has an extensive API and an MCP. So it seems like that should be pretty doable.
Starting point is 00:45:11 Very nice. Yeah, it seems pretty clever. I haven't tried it. I've only checked it a little bit here when I was gathering the feedback, but smart idea, especially if you don't already have any of that info setup, but you want something to help you manage? Before you get his next one, can I just say I'm surprised.
Starting point is 00:45:23 I haven't heard a lot of people talking. Hermes 0.2O added conversational voice support. So that evening, I set up an anchor USBC speakerphone that has two microphones and a speaker. And immediately it outclasses anything the Alexa units or the home pods or the Google Homes have ever done. And it ties in with my home assistant. And I can even say things like play Magnum.
Starting point is 00:45:50 And it will activate the Apple TV. It'll launch the infuse app. It'll play the most recent episode of MagnumPI. And I don't have to even touch the remote. And I control lights, temperature. It's way better than anything from any of the big tech companies. And I don't see anybody talking about it. And I even like the thinking music.
Starting point is 00:46:09 I have thinking music when you like say, hey, you know, hey, Laura, what's the weather? he's pulling from my local weather station over home assistant and while he's doing that I have a little thinking music that plays I like to do the thinking music. I like that so you know what's going on. Magnus goes on listening to the backwards episode where you dig into the old Zeon server.
Starting point is 00:46:29 Yeah. You mentioned self-documenting. Have you ever thought about running a Sherpa type agent on your server's task with keeping tabs on all the stuff running there? The config, containers, mapping, ports, and proxies. This could be posted as JSON somewhere to keep a centralized documentation report. and once it's there, you could build dashboards from it.
Starting point is 00:46:48 And the best part, it could be a set and forget type feature just picking up on new stuff being set up or config that changes. So unofficially, my agent data does sort of manage a lot of the important infra and has a little index of everything, but that's just on my system. So yeah, that would be something we should formalize. Hey, how about this? Thank you, by the way. Appreciate that, Magnus. How about this? Mike wrote in, you could try running and sharing this.
Starting point is 00:47:13 and he links us to something called C.BBS.S. Pie. A vintage CBBS-style bulge-in-board system emulator from MacOS Linux Docker and the Raspberry Pi. Something's happening here. I think we're going to have a BBS. The energy is building. The energy is building. I don't know if this is it. I'm kind of, I hate to be this guy. I just can't even stand sitting at my Raspberry Pi anymore. It just feels so archaic and slow and like it's just this weird platform that I have to
Starting point is 00:47:43 bend over just to get working right and then like do weird twister games versus like an x86 sBC that just works dude like i don't know i don't know i'm having a hard time i got too many pies i'm having a hard time uh bretley you want to wrap us up with uh ryan's email ryan sent in a juicy one for the show ooh all right not sure if you're still in the apple or iOS ecosystem but i just stumbled upon the mother hen app in the apple store it's written by a west in Bustron, why am I writing you to inform you about this? Well, it's a purpose-built chicken egg hen laying app. Hey, all right.
Starting point is 00:48:23 And it tracks when eggs are ready by the flock. I mean, they just lay every morning. I don't understand. I like this next bit. Okay. It's somewhat random, but I know you're the original chicken coop home assistant guy. So maybe it's worth checking it out as a $3 curiosity. I'm kind of curious what kind of an app you could use for chickens.
Starting point is 00:48:46 As close as MQTT integration as you can get. You know, I think close to this line of thinking, Ryan, is I need to be able to take the camera feed I have of the chickens entering the roost box and coming out and be able to track that. Because that's the real signal. And like good little birdies, I'm so proud of them. They're all laying in the nest box so far. They haven't laid anywhere else in the yard or in the run. So stinking proud of these birds. But, you know, I'm still trying to figure out which birds laying the eggs.
Starting point is 00:49:20 So something like that I think would be really good. There's some interesting information in the app description here. Okay. I guess there's a couple different parts to the apps. There's three parts. There's the harvest tab, which is designed to be used on a daily basis. So when you go out and find the latest batch of eggs waiting for you to collect, you just like bunch in some environmental factors such as light and stress
Starting point is 00:49:41 and how they can affect the egg production. Uh-huh. So by tracking all of that, and the egg counts specifically, you can watch all of the trends and make some informed decisions. Okay, okay, okay. There's also a flock tab for keeping tabs on the members of your flock. I mean, you've named them all already, so that makes it pretty easy. So if you're like the authors here,
Starting point is 00:50:01 sometimes it's hard to keep track of who's in the coop. Yeah. So adding a picture or name goes a long way. For the breeders out there, they added a family tree as well. And there's a last tab here. Okay. It's the finances tab that gives you the ability to see if you particularly want to, just how much your feathered friends are costing you in feed and other expenses.
Starting point is 00:50:24 Oh. Or if you sell your eggs, how much money they're making you. You just don't open that tab. It's fine. One of the preview screenshots has my type of chicken in it. I love it. You know, this is actually the more I think about it. Interesting because I have particularly controlled the lighting and heating of the henhouse.
Starting point is 00:50:40 to try to maintain chicken egg production during the winter. It would be interesting to see if I can achieve that. Is data controlling that again? Well, that's all controlled by home system, but data does operate and monitor that. That's really good stuff. I like that, Ryan. Thank you very much for sending that in.
Starting point is 00:50:55 There's some good stuff in there. And we'll put a link if you have some chickens to the mother hen app. And if you do have chickens, boost in and let us know. We want to hear about that. And now it is time for the boost. Gentlemen, it is time for LeBos, and let's start out with old brady, aka Kairing, coming in with a row of super McDucks. Wow, that's mega-Mick-Ducks?
Starting point is 00:51:18 Mega-U-LTRA-M-A-LTUX. That's a whole fuck. That's all the old McDuck. 222,22 Satoches. Incredible. Amazing. That is really something. Thank you very, very much, sir.
Starting point is 00:51:43 We appreciate that baller boost. Hey, yeah, new member. Hey, hey, all right. Yes, yes. Fun will now commence. Old time lurker, the web boost is the best thing yet. I have previously tried Fountain, but the hassle of dealing with buying sats, it's just, well, I like this edition. It gives us normies a way to support without the EBGVs.
Starting point is 00:52:01 Thanks for all the folks. That's the idea. Make it easy. Just wait, though, one day that Fiat will give you the EVGBs. But in the meantime, we appreciate it very much. You know, and he did it with Zap Wright. So he got the sats. So I'm impressed all around.
Starting point is 00:52:14 However you want to do it, man. We really appreciate it. And we thank you for being our boss. And look at this, another mega-mic duck, Lutris, lucidropy. All right, also coming in with a mega-McDuck. This old duck still got it. 222,22s.
Starting point is 00:52:31 Hey, rich lobster! Make a show. Wow. Thank you, sir. Thank you. Yeah, sorry, guys. Last couple of boosts through fountain. Splits didn't go right for some reason.
Starting point is 00:52:50 Chris and J.B. got their splits, but the others didn't go through. So here's a rectifier boost. Keep up the good work. Wow, that's really good. to do that, but thank you. That's very sweet. Thank you very much. Well, we've got our adversary 17 here with 54,321 sets.
Starting point is 00:53:06 All right. I hoard that with your kind. He's a good guy. He's a real good guy. No, you're a great guy. I've gone to dial pee. Get it? Plaid reversed.
Starting point is 00:53:16 Oh, I see. Because the episode was reversed last week. I've gone to doubt. So he's gotten clever with the numbers is what he's done there. How hell was that? Spaceball one. They've gone to plan. I think he actually wanted that backwards.
Starting point is 00:53:30 Yeah, yeah. Yeah, I'm sure he says I'll just escort myself. I kind of liked it. Thank adversaries. Appreciate that. The Incredible Mulk comes in with 32,810 Satoshis. Hey, another long-time listener, Jupiter Party member. Yes.
Starting point is 00:53:51 Awesome. First-time booster. Thank you for all the hard work, especially on last few shows. here's some help to keep the lights on. Thank you for the great content. And also, it's a zip code boost, boys. Ooh. Yes, zip code is a better deal.
Starting point is 00:54:06 Now, Wes, did you bring the... I pack the map every week. All right, all right. Let's look this up. I'm feeling... I'm feeling like you're going to nail this one. Yeah, I'm feeling Eastern Time Zone, I think. Sinking it to the digital map for us.
Starting point is 00:54:18 Okay, what do you got? Oh, Orlando, Florida. Ha, ha! I knew it. I knew it. Hello, Orlando. Rock and roll. Thank you for boosting in and for being a member too.
Starting point is 00:54:30 We appreciate it. Yeah, we do. IRU comes in with 11,11110. Now that the dust has settled, I've given B-Cash-FS a try. Hey, good job. I've set it up as the root-fess with encryption and secure boot. Mixing different drives and setting copies on a per file or directory basis, I can choose to have copies equals one for redownloadable files while keeping replicas
Starting point is 00:54:58 on important data, a godsend in this economy. No kidding. Look at you getting clever. I wouldn't mind a follow up in a little while to know how it's going. I mean, we're two years in on one of our systems running B-Cash-FES. A couple of major upgrades in there. You're how many years in now on that sucker?
Starting point is 00:55:14 Two and a half, three. Woo! And that system gets worked out. It does. Thank you. I.R. You appreciate you. Well, Gene Bean sent a collection of rose of ducks and late sats. This is a tasty burger. That's a total of 7,340 sats. Thanks, Jean.
Starting point is 00:55:32 Let's go through them. Number one, this episode was fun. Well, we appreciate it. That's the goal. We weren't sure if the reversal episode would be horrible or not. It was hard to gauge. Yeah, it was a surprisingly hard episode for us to do just because it took constant mental effort to remember how to do the show backwards. It was silly.
Starting point is 00:55:51 It was like doing the math every segment. Nearly 13 years of doing it one way. It was a muscle memory. Yeah. Note how we're not doing this episode backwards. Gene continues, I really like Local Send. Yeah. So that's another plus one there.
Starting point is 00:56:07 Thanks, Gene. I'm really interested to see where Buzz goes. Sounds really great. As a follow-up, it's a paid slack that I want to connect an agent to. This is a follow-up to a question from last week. And then I like this one, Brent, why in God's name would you want 18 windows of the same app? Same app. How the heck do you find anything?
Starting point is 00:56:27 This is our point, Gene. You're making a presumption that he does find anything. That's the thing, Jane. That's also quite a strong presumption. I would say I have put in tools to try to help myself here, and it is not completely succeeded. Okay. Maybe give us a follow-up on that down the line. We're just going to, yeah, we're just going to leave that one right there.
Starting point is 00:56:46 We'll do an episode at some point. Uh-huh. Uh-huh. Use the boots to get through! Every time I hear the break song, it scratches my showtune. itch, but then replaces it with another itch of needing J.B. The Musical. You know, like those old sitcoms that would have a random musical episode. J.B. The Musical? No. I don't know about that. Maybe one day we'll put together an album. I just, you know,
Starting point is 00:57:11 I don't know. I guess, I don't know. Send in your boost to vote for the album being released this year. Yeah, I don't know about that. All right. Okay. Okay. All right. Maybe one day. Maybe one day. I'm going to say Ensign, Nx. What do you think? Engine Nix. Ensign Nix. Oh, there you go. Ensign Nix comes in with a row of ducks. 2,222 cents. The Rust Project Leader has adopted
Starting point is 00:57:35 an LM policy that I completely agree with. If we were to rely on LM to write code, it will eventually become dependency and we risk not understanding what has been created. So, did you read the Rust LLM policy? I have not checked it out yet. Neither have I.
Starting point is 00:57:49 But I will have to. The people who review... Yeah, I think it's the, I mean, the high level here looks like you got to understand what you posted. You got to be responsible for what you committed, that kind of stuff. But I will try to read it after the show. Yeah, thanks for boosting in. Yes, thank you very much. I have that tab open now, and I don't have crazy amounts of tabs.
Starting point is 00:58:08 Hey. Well, I do have a lot of tabs, actually. I do have quite a bit of tabs. But I have it open. And probably a lot of them you can close after the show. I will, but not that one. Do you pin some of them? I have a bunch of pin tabs.
Starting point is 00:58:19 I don't do that. No, you don't. You definitely don't pin your tab. Brandy won't open 10 new windows like some kind of entropy enthusiast. A Monday comes in with 19,941 Satoshi's. I would absolutely love a security camera deep dive. On the cusp of doing that myself, just finally got a real link doorbell cam and integrated into home assistant. And that's awesome.
Starting point is 00:58:44 Nicely done. That's amazing. Also very much enjoyed the reverse episode. It was fun. P.S. X5 for a zip code. Whoa. Whoa, another zip code and this one, okay, so Wes, you've got to do a little math. Did I bring my calculator today?
Starting point is 00:58:58 So, yes. So multiplied by five, is that right? I am very much considering going over my multi-frigot camera setup. So if people have any questions and I get a few of those, I'll definitely do an episode on. Wes, I think you have to solve for X actually on this one. Oh, well, I was just guessing. I thought. That's not going to work, Wes.
Starting point is 00:59:15 That's not going to. It's not going to. Okay. Okay, so we had 19,941 multiplied by five. That's 99,705. Oh, that's a nice boost. And when I'm finding it on my map, it's a little old, but it would seem to be the city of North Pole, Alaska.
Starting point is 00:59:33 Oh, really? Hello, Alaska. The county of Fairbanks, North Starboro. I love that. I have questions. It's not actually the North Pole, but they call themselves? Sure. Can we get a history?
Starting point is 00:59:44 Sure. You're right. We need to know more. Night 62 comes in with 12,000. Thank you for the boost. 12,345 cents. So the combination is 1,2, 3, 4, 5. Boost might not always be a clear indicator of a popular topic.
Starting point is 00:59:57 I often boost in just to say something, not because the episode sparked the topic. I enjoyed the buzz episode. Being ahead of future trends is good. Many of us are not vocal, but we trust your taste and enjoy quiet listening and learning. Thanks. Well, that's always good signal to hear too, right?
Starting point is 01:00:10 Yeah. Yeah. Thank you. Appreciate that. Keep doing what you're doing, is what I heard. Thank you for helping us. Help you, help us all. Yeah, we appreciate that.
Starting point is 01:00:16 You want to take MG there? I'll take MG.MG sends in a row of sticks 11,111s. Oh my God, this drawer is filled with broolopes. That reverse episode was fun. By the way, I've boosted the previous three shows, but I haven't heard those messages. What? I don't say much other than appreciate you. So didn't need to make it into the show.
Starting point is 01:00:39 I just wanted to make sure you guys are getting the support you need. If they're above 2,000 stats, they make into the show. But if they're below 2,000 stats, they will be included in the dock and we read them. We don't read them out loud on the air. That might have been it. But if not, let us know. Yes. Then something might be broken.
Starting point is 01:00:54 Thank you, M.G. That did make it in. So we appreciate you. Time for some Fiat boost. Let's do it. Yeah. Covered Bridge Cookies, a very old listener. 150 Fiat.
Starting point is 01:01:04 Oh, wow. All right. Covered Bridge cookies. Thank you very much. I was there for Stallman. Dot cloud. Matt's GTX-960, bacon, and more.
Starting point is 01:01:20 You helped my IT career more than words convey. I sense nuked that. Now I apply DevOps and Foss Principles to our co-op bakery. Covered Bridge Cookies.com. They look delicious. Look at this. Wow. That's so cool.
Starting point is 01:01:37 Coveredbridge cookies.com. It looks like they probably do shipping, too. Ginger snaps. All right. Oh, maple shortbread. What's going on here, Brent? Oh, you got me? mind if we mail you free cookies.
Starting point is 01:01:51 No way, really? That's what it says there. I mean, that sounds awful. I don't think you should be doing that. Yeah, we definitely wouldn't want a sampling of some of those delicious cookies. The Doc Cloud Reference is Deep and the GTX-960. Thank you very much. That's amazing.
Starting point is 01:02:06 Appreciate that. Thanks for boosting. I have a, it's a slight zip code boost because at least the website says they're baked in Vermont. Oh, cool. All right. Well, the Siffy Penguin boost. Well, it didn't boost in. Fiat it in.
Starting point is 01:02:20 Ten Fiats. You're doing very well. This is different from leaving voicemails to the launch. Also, I'm going to need you to not do averse show again. I already questioned my sanity. I don't need it coming from my favorite Linux podcast. Just kidding. That was funny as hell.
Starting point is 01:02:39 I mean, it was a little tough on the sanity. Senior smile comes in with $5. Oops, I forgot my name. on the Kubernetes and the colonel. Here, have a fiver. All right, thank you, smile. Appreciate you.
Starting point is 01:02:52 We got a free member boost from Anonymous. They're back. Chris, I think I heard you do have, I think you had a farm with some chickens. I'm not sure if it's worth mentioning. I've been working,
Starting point is 01:03:01 assisted, of course, although I am a professional dev, on an egg farm tracking system. What? Check it out. It's called two in one episode. Cluck work. Oh, I like the name.
Starting point is 01:03:10 This is a thing people are doing, guys. Yeah, I definitely have demands. There's a little short description. Poultry farm management. Look at this thing. C-sharp, typescript. All right, I got another thing to check out after the show.
Starting point is 01:03:23 How about that? That is really something right there. You mentioned needing a Slack export tool. You might try out Slack dump, which will put a link in the show notes. When the CNCF almost lost its free Slack instance, they recommended this project to Teams as a way to preserve history. I didn't end up using it because Slack backpedaled and kept sponsoring the plans. But it does seem nice.
Starting point is 01:03:42 Jumping off of Wes's idea, I put a full Butterfess Node, multi-node sync, plus load balancer app scheduler. I think this is the idea for what to put in the kernel if you could. Oh, oh, right. Oh, now this is clever. Actually, let's just pick a must have subset of Kubernetes and put it all. You know, I bet there's a lot of people that wouldn't mind some Kubernetes in the kernel. Uh-huh.
Starting point is 01:04:01 K-Kube. K-K8s. No, that's horrible. Cates in your kernel. That's horrible. Thank you, Anonymous. Nice to hear from you. Paul member Boussin to say, back again.
Starting point is 01:04:10 Hello, Paul. I wanted to make it clear that for audiobooks, I mostly buy them digitally from Libro FM. Good one. I use their subscription to get a credit every month, which I can use to buy an audiobook. You can use their app or download the DRM-free MP3 or M4B. Yeah, that's a good one. We should mention Libro FM, so thank you.
Starting point is 01:04:26 That is good. Audibooks are also way cheaper this way. I love audiobooks too. For road trips, I stack it up audiobooks and podcasts, unless I'm driving with peeps. And then these days, I'm just going to make Westbeat DJ. However, if you have music assistant,
Starting point is 01:04:41 you can actually just have your agent create playlist for you. That could also be fun. That's what I've been doing recently. Night 62, member boosted in. Can I get a few more characters in these here? Web boost. If not, is it permissible to add a pastebin link or something like that? I don't really want to chunk up my comments or split them across multiple boosts.
Starting point is 01:05:04 I don't need to write a book, but even AI is having trouble reducing my thoughts to 300 characters. Hmm, you can always send us a boost and refer to an email also. That's true. The thing is we do try to keep these moving. So that's why the length is an issue there. But you could always email it and let us know. All right, Papa John comes in with a member boost. I think the anonymous members assume their name will come through when they sign in with memberful.
Starting point is 01:05:27 So they don't feel out their username field. Great show, guys. Yeah, I don't know if I can bring that in without some additional approval, but I do think maybe that is a thing. Good catch, Papa John. Space Warlock comes in. The reversal format wasn't for me. I understand.
Starting point is 01:05:41 It wasn't bad content-wise. It felt like change for the sake of change. rather than positive impact. I like the idea of a SSH in the kernel. I can see a use for it. I think it was it, was it Brent's idea? How did it come up? Hey, it came up.
Starting point is 01:05:54 You blaming me now? Yeah. Yeah. It came up from like we were having a discussion somehow of on a topic and then it just sort of popped in my head, so I will take the blame. And then we tried it. And I, it was surprisingly difficult to be honest. It might be good.
Starting point is 01:06:10 It might have been a good exercise for us to do just to put us out of our comfort zone and, you know, push it a little bit. Thank you for your patience. Adversary 17's back with the member boost. Love the reverse episode. I think it broke all your brains a little except Chris, which just straight up broke entirely. It was bad. It was bad. Momentum.
Starting point is 01:06:27 Thank you, adversaries. Appreciate you. Mohan comes in to say this episode started off with outro and ended with the intro. It was backwards. Yeah. It was all leading up to that. Good observation. It was all leading up to that.
Starting point is 01:06:40 Well, Gene Bean sent in a member's booth saying, give this a read. OpenClaw with Claude Opus 4.6 hacked a gym. Oh yeah, I heard about this, yeah. Well, he found, like, the schedule, he found, like, a way to kick people off the reservation list and bump their operator up on the reservation list. Those reservation systems are often not really well controlled at all. Yeah, it's just beginning.
Starting point is 01:07:01 Clinker versus Clanker, tell you what. All right, thank you everybody who supported the show. When you hear a dynamic ad, you know, that means we didn't make an ad deal. It means we're barely, barely, barely, barely getting by. And if it wasn't for our members and our boosters, we just wouldn't be making it. And I want to say thank you to everybody who also stream stats. We didn't get as mini this last episode for some reason. 12 of you streamed sats and collectively you stacked 11,789 Satoshes.
Starting point is 01:07:23 Sometimes you're too confused to stream, and that's wonderful. That might happen, yeah. Maybe the sats stream reversed that episode and went to them. Who knows? When you bring that together with our Fiat boost and if we just price them at the current stats value, that brings our total for this episode. It's pretty great to 847,041 Satoshi. Thank you, everybody who supported the show.
Starting point is 01:07:49 show with a membership or a boost boost.bootubterbroadcasting.com. You know, we are, we might even be at the 13-year mark. And it's just like, feels like in so many ways a massive future ahead of the show and so much we can dig into. And new shows we could launch and, you know, all kinds of stuff. So we really do appreciate the support. Even if the ad market doesn't think a little old Linux podcast is worth supporting, we appreciate that you do. And you keep us going. And it means the world to us. It's all the difference. All right. We got a couple of picks. We got a couple of as we do. I was surprised to see that you picked I descriptor.
Starting point is 01:08:24 Well, I picked it for you. I know you have some I devices around. I do have some I devices around. So I thought maybe you would like an AGPL 3.0 free open source cross-platform, I device management tool, and it just stood out because it's not all of the time that things like this run on Linux.
Starting point is 01:08:40 That is true. And it's also it's cross-platform. So if you're on Windows, you could do that. It's developed with cute and... A little bit of us. Ooh, look at that. And C++, look at that. I guess I would say if you're familiar with iPhone management that you used to get on Macs for a while that was built into iTunes and then later built into Finder, it's kind of like that.
Starting point is 01:09:02 You get the information about your iPhone, the storage information. You can browse the files, the apps that are on there, and you can do it over a USB or Wi-Fi. It has AirPlay. Wow. Yeah. I dispatcher. I dispatcher. It really is the missing piece of iPhone management.
Starting point is 01:09:18 If you like to do this kind of stuff from the desktop, I think it's really cool. Also, if you go to jail broken route, it also gives you a few extra options. If you did that kind of thing. That's eye descriptor. Yeah, and like you said, it's AGPL3.0. All right, boys. Now I would like to present you something that I think is particularly interesting. And Brentley,
Starting point is 01:09:41 Stay a while and listen. This might be. be worth the consideration of a pivot. If I were not two, three years, however long four years, into obsidian, I may consider KiwiFS.
Starting point is 01:09:57 And so I want to mention it, and I'd also like to know if anybody could take a peek at it and tell us if it's something we should review. KiwiFS is a searchable structured version markdown system, and you can plug an agent into it in 30 seconds. KiwiFS makes markdown files writable, searchable, quarreable,
Starting point is 01:10:13 versioned, and human readable. They are the source of truth and everything else is a derivative index of your markdown files that you can build. And KiwiFS basically becomes a file system and a wiki for your AI agents as well. AI agents can read and write the same knowledge-based humans use. You can use an MCP, an API, webdav, views, all kinds of options. It's a obsidian style markdown knowledge management, but designed to be shared with agents and automation. It's self-hostable. It's a single go binary. and they pitch it as a markdown file system for you and your agents working together. Huh.
Starting point is 01:10:50 And I've thought about this too. Like, say you get a document. Say you get like a PDF for the van or you get a receipt. Like you want to be able to just give it to the agent and then two years later say, hey, I need that receipt from O'Reilly's that was in August of 2026, right? That's what I want. And that's what this is, that's one of the things along with notes. because it uses three tiers of indexing.
Starting point is 01:11:13 It can be really light. It can just use grep. Then you can graduate up to something that's called like the BM25 algorithm. You might know more. I don't know what. And then you can also go to vector. Yep, Fultzax plus vector,
Starting point is 01:11:25 and then you can kind of have it combined across different methods to sort of do a ranked final delivery. And you can have a pretty advanced backend that's using object storage and NFS and all the stuff. Get version of built in. I like that.
Starting point is 01:11:37 Yeah, yeah. Yeah. So I think if I hadn't gone down the obsidian path, I'd probably have deployed this this week. The other thing that is nice to see is they clearly have a concept of importers, because they say they have 19 data importers, including pay, post, grass, notions, obsidian, CSP, which perhaps also tells you that you could wire in your own converter. There's an interface for it. It's set up to have multiple of those already, which could be handy. I like the versioning built in. That's really nice.
Starting point is 01:12:04 The search stuff looks really good. The MCP, a lot of these things have that now, but they've built that. from the very beginning. Yeah, I don't know. I mean, I think KiwiFS looks really good. I don't know if it's worth replacing something you already have. It also could be a bit of a memory system for your agent, so you and your agents are kind of working from the same memory system.
Starting point is 01:12:24 Think about that for a moment. And it's... How did you know I was, like, diving into these tools, and I wasn't happy with anything that I've been finding recently? Because you've been doing that since we met you? Yeah, that's true. That's true, yeah. The project is new. I should warn you. It is new. It started in April of 2026, but it's already, it's already, I mean, it's got 600 GitHub stars. It's under active contributors and development. They've really got, they've moved something. They've got something quick. So it is apparently a business source license. Yeah. So it's free to use self-host and modify. The only restriction you can't offer QEFS as a commercial hosted service.
Starting point is 01:12:59 Right. Each release does convert to Apache 2 after four years. So, oh, interesting. You know that going on. If you are going to use it. Okay. See, there's a lot to like, right? And markdown is always the source of truth. I've been looking at, well, many of the suggestions from listeners recently, but Joplin made it into my list as well. And they have seemingly quite, you're shaking your head. I'm only mentioning it, I'm not using it. It's just I've been down the same path too. And I was thinking you would say that exactly.
Starting point is 01:13:33 The reason I bring it up is only because they seem to have a lot of some of the agent tools as well. So it's curious to see these not taking apps go in that direction. You're either going to fall back to Obsidian or you're going to try to give QO notes an earnest try. That's your next. No, I did that a long time. Yeah, I know. And you're like, I'm going to, no, you'll think about it. You'll be like, actually at the end of the day, QO notes is just the way I should go.
Starting point is 01:13:59 Here we go. He's a big git guy. Right? Well, so Brian in Matrix is his name. I've just been using my forgeo repo to store all my documentation for my agents. There you go. Simple.
Starting point is 01:14:10 Although, you know, if it ever gets too big, it would be nice to be able to vector that or something like that. All right, you know what we do? We put links to all this stuff. Linux unplug.com slash 680. And then there's the whole network over at jupiterbroadcasting.com. As long as that deals on going, you can find the links or whatever for all the other shows.
Starting point is 01:14:27 Yeah, the incredible community-powered website. Where are they going nowhere? As far as I know. Yeah, that is true. That is still a great community-powered webcast. website. And of course, we got boost.jupiter broadcasting.com as well. So here's the thing. If you want to really have some fun, you got to show up on a Sunday, you make it a Tuesday on a Sunday, you hang out with the boys, you listen to a linner or watch a little Linux unplug live.
Starting point is 01:14:47 See you next week. Same bad time. Same bad time. Sunday. Sunday and Pacific 1 p.m. Eastern and your time at Jupyterbroadcasting.com slash calendar. Now for the download itself in your RSS feed, we got some extra stuff. We do, including, you're familiar with the MP3. Yeah. We provide an upgraded MP4. That's one extra MP. In the feed? That's right.
Starting point is 01:15:06 Just sitting there in the feed? Right in the feed. Wow. Right next to the transcription files. What? Including, you know, ones that say who's talking to who? But you have any kind of like structured data my agent could use? Oh, yeah.
Starting point is 01:15:17 Like a JSON file that has cloud chapters in it. Maybe you have years worth of episodes that have all of that. Yeah, it's not every episode. And different ones got different parts at different times. Getting better and better. Getting better and richer all the time. There you have it. All right.
Starting point is 01:15:30 Thank you very much. I can tell you more. I'll just leave it with this. Thank you to our mumble room for hanging out with this. Thank you to the folks in the live chat. Our members, our boosters. And thank you for downloading and listening to this episode. I don't say it enough, but for those of you have been listening for a long time,
Starting point is 01:15:44 we deeply appreciate you. We really do. Thank you for hanging with us through all the ups and downs and changes. Well, it's all ups, of course. Through all the ups and ups and ups and slightly less ups. Yeah, that's it right there. Thank you. And also, thank you for joining us on this particular episode.
Starting point is 01:16:01 And we'll see you back here for next week's particular episode, which will not be in reverse, all right? We're done with that. It's going to be in regular order. We'll see you next week.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.