<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator><link href="https://lavaux.lv/feed.xml" rel="self" type="application/atom+xml" /><link href="https://lavaux.lv/" rel="alternate" type="text/html" /><updated>2026-07-18T11:46:02+00:00</updated><id>https://lavaux.lv/feed.xml</id><title type="html">Pierre Lavaux</title><subtitle>The personal website of Pierre Lavaux. A collection of tech tips, notes and thoughts.
</subtitle><author><name>Pierre Lavaux</name></author><entry><title type="html">Some Housekeeping</title><link href="https://lavaux.lv/2024/08/06/some-housekeeping/" rel="alternate" type="text/html" title="Some Housekeeping" /><published>2024-08-06T00:00:00+00:00</published><updated>2024-08-06T00:00:00+00:00</updated><id>https://lavaux.lv/2024/08/06/some-housekeeping</id><content type="html" xml:base="https://lavaux.lv/2024/08/06/some-housekeeping/"><![CDATA[<p>Though I don’t publish too often on this website, it’s still looked after.</p>

<p>Today comes with some minor housekeeping:</p>

<ul>
  <li>Updated <a href="/about">About</a> page with more details.</li>
  <li>Updated <a href="/investments">Investments</a> to reflect the most recent investments and exits + include website links.</li>
  <li>Tech tips are now considered potentially obsolete (with a short banner) after two years rather than three.</li>
  <li>Minor cosmetic tweaks.</li>
</ul>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="updates" /><summary type="html"><![CDATA[Though I don’t publish too often on this website, it’s still looked after.]]></summary></entry><entry><title type="html">A new chapter with OSS Ventures</title><link href="https://lavaux.lv/2023/05/22/a-new-chapter-with-oss-ventures/" rel="alternate" type="text/html" title="A new chapter with OSS Ventures" /><published>2023-05-22T00:00:00+00:00</published><updated>2023-05-22T00:00:00+00:00</updated><id>https://lavaux.lv/2023/05/22/a-new-chapter-with-oss-ventures</id><content type="html" xml:base="https://lavaux.lv/2023/05/22/a-new-chapter-with-oss-ventures/"><![CDATA[<p><img src="/assets/posts/oss-banner.jpg" alt="OSS Ventures Banner" loading="lazy" /></p>

<p>After close to 6 years with SGH Capital, I’m pleased to announce I’ve joined <a href="https://www.oss.ventures/" target="_blank">OSS Ventures</a> to scale up their VC arm and operations. I’ll be forever grateful for my time at SGH: from Entrepreneur in Residence to Partner, the learning curve has been incredible, and it now felt like the right time to hone in on what I like and understand best – B2B SaaS.</p>

<p>Founded in 2018, OSS is a hyper-focused venture builder and investor tackling the future of operations and manufacturing. Even though the industrial sector (including construction) represents ~27% of the world’s GDP<sup id="fnref:1"><a href="#fn:1" class="footnote" rel="footnote" role="doc-noteref">1</a></sup>, it only attracts ~3% of VC funding<sup id="fnref:2"><a href="#fn:2" class="footnote" rel="footnote" role="doc-noteref">2</a></sup>!</p>

<p>Climate change, geopolitical tensions, the energy crisis, inflation and supply-chain woes have magnified the weaknesses of our production and consumption models. To turn the tide, world leaders are undertaking massive investments, such as the Inflation Reduction Act, the CHIPS Act, or the Critical Raw Materials Act. Meanwhile, swaths of VCs are fighting for the hottest artificial intelligence deals but our factories and critical infrastructure rely on equipment that won’t be upgraded for another decade or two.</p>

<p>OSS leverages a wide network of industrial partners to build and invest in the modern factory stack. In the last years, we have incubated and funded a dozen startups, whose solutions are used in over 1.000 factories. Our companies help manufacturers unlock tangible operational efficiencies and compound the know-how of their employees. These solutions fill information gaps, replace paper forms, disjointed spreadsheets and antiquated software so that not just white-collar but also blue-collar and deskless workers can work smarter instead of harder.</p>

<p>OSS also invests ahead of or alongside top-tier VCs in extraordinary founders who want to build enduring businesses in that field in the US and Europe. We partner from pre-seed through Series B, and our hands-on operating partners help entrepreneurs scale their teams and revenues and set them up for success.</p>

<p>We are absolutely convinced that the next crop of billion-dollar companies will include several industrial SaaS platforms because that’s what our portfolio growth and numbers hint at.</p>

<p>If you are working on something in that space, please reach out!</p>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:1">
      <p><a href="https://data.worldbank.org/indicator/NV.IND.TOTL.ZS" target="_blank">World Bank</a> <a href="#fnref:1" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:2">
      <p><a href="https://www.oecd-ilibrary.org/sites/entrepreneur_aag-2017-27-en/index.html?itemId=/content/component/entrepreneur_aag-2017-27-en" target="_blank">OECD</a> <a href="#fnref:2" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="updates" /><summary type="html"><![CDATA[I’m pleased to announce I’ve joined OSS Ventures to scale up their VC arm and operations. Founded in 2018, OSS is a hyper-focused venture builder and investor tackling the future of operations and manufacturing.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://lavaux.lv/assets/posts/oss-banner.jpg" /><media:content medium="image" url="https://lavaux.lv/assets/posts/oss-banner.jpg" xmlns:media="http://search.yahoo.com/mrss/" /></entry><entry><title type="html">Do not forget SPF and DMARC policies on parked domains</title><link href="https://lavaux.lv/2023/04/23/spf-and-dmarc-policy-on-parked-domains/" rel="alternate" type="text/html" title="Do not forget SPF and DMARC policies on parked domains" /><published>2023-04-23T00:00:00+00:00</published><updated>2023-04-23T00:00:00+00:00</updated><id>https://lavaux.lv/2023/04/23/spf-and-dmarc-policy-on-parked-domains</id><content type="html" xml:base="https://lavaux.lv/2023/04/23/spf-and-dmarc-policy-on-parked-domains/"><![CDATA[<p>I’ve <a href="/2022/05/16/preventing-email-spoofing-dmarc-policy">previously written</a> on DMARC policies to prevent email spoofing.</p>

<p>Besides your primary domain, it is also crucial to properly configure any parked domains you might have. Companies will most often register similar domains across multiple TLDs to ensure that malicious actors cannot set up misleading websites or mess with their online presence.</p>

<p><strong>However, simply owning the domain is not good enough!</strong></p>

<p>If you do not set up proper SPF and DMARC records at the DNS level, anyone can easily send spoof emails from your parked domain: domain registrars may not preemptively set such records for you. Alas, spoofed emails could look very convincing, especially if the parked domain resembles your primary domain or brand.</p>

<p>The good news is that you just need two TXT records on each domain:</p>

<ul>
  <li>One <code class="language-plaintext highlighter-rouge">TXT</code> record with the value <code class="language-plaintext highlighter-rouge">"v=spf1 -all"</code> (mind the double quotes).</li>
  <li>One <code class="language-plaintext highlighter-rouge">TXT</code> record with the value <code class="language-plaintext highlighter-rouge">v=DMARC1; p=reject; rua=YOUR_REPORTING_URL; pct=100;</code>.</li>
</ul>

<p>In my case, I manage all my DNS zones with Cloudflare, so I wrote the following bash script, which uses <code class="language-plaintext highlighter-rouge">flarectl</code> (which assumes there are no existing TXT records):</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nb">export </span><span class="nv">CF_API_TOKEN</span><span class="o">=</span>YOUR_API_KEY

<span class="k">for </span>zone <span class="k">in </span>parked-domain1.com parked-domain2.com parked-domain3.com<span class="p">;</span> <span class="k">do
    </span>flarectl dns create <span class="nt">--zone</span><span class="o">=</span><span class="s2">"</span><span class="nv">$zone</span><span class="s2">"</span> <span class="nt">--name</span><span class="o">=</span><span class="s2">"</span><span class="nv">$zone</span><span class="s2">"</span> <span class="nt">--type</span><span class="o">=</span><span class="s2">"TXT"</span> <span class="nt">--content</span><span class="o">=</span><span class="s2">"</span><span class="se">\"</span><span class="s2">v=spf1 -all</span><span class="se">\"</span><span class="s2">"</span>
    flarectl dns create <span class="nt">--zone</span><span class="o">=</span><span class="s2">"</span><span class="nv">$zone</span><span class="s2">"</span> <span class="nt">--name</span><span class="o">=</span><span class="s2">"_dmarc.</span><span class="nv">$zone</span><span class="s2">"</span> <span class="nt">--type</span><span class="o">=</span><span class="s2">"TXT"</span> <span class="nt">--content</span><span class="o">=</span><span class="s2">"v=DMARC1; p=reject; rua=YOUR_REPORTING_URL; pct=100;"</span>
<span class="k">done</span>
</code></pre></div></div>

<p>If you are not collecting DMARC reports, you can safely remove the <code class="language-plaintext highlighter-rouge">rua</code> directive.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[I’ve previously written on DMARC policies to prevent email spoofing.]]></summary></entry><entry><title type="html">Is Incogni worth it?</title><link href="https://lavaux.lv/2022/12/02/is-incogni-worth-it/" rel="alternate" type="text/html" title="Is Incogni worth it?" /><published>2022-12-02T00:00:00+00:00</published><updated>2022-12-02T00:00:00+00:00</updated><id>https://lavaux.lv/2022/12/02/is-incogni-worth-it</id><content type="html" xml:base="https://lavaux.lv/2022/12/02/is-incogni-worth-it/"><![CDATA[<p>Last August, I signed up for <a href="https://incogni.com/">Incogni</a>, a service that automates data removal requests from data brokers and marketers on your behalf. It’s owned by Surfshark, a subsidiary of Nord Security, the owner of NordVPN.</p>

<p>For 69.48 Euros (annually), they promise that they’ll make data brokers remove your data so that it “stays secure and private”. But is it worth it?</p>

<p>In theory, as soon as you sign up, they send requests to all of the data brokers they have on file. Brokers then have one calendar month (GDPR) or 45 days (CCPA) to comply.</p>

<p>Brokers acting in bad faith could argue that the request is complex, which buys them two more calendar months. But after three months, you should definitely have confirmation that your data has been removed from their systems (or was never on it in the first place).</p>

<p>Have a look at my dashboard below:</p>

<p><img src="/assets/posts/incogni.png" alt="My Incogni Dashboard" class="lightbox" loading="lazy" /></p>

<p><strong>After nearly four months, the completion rate is 36%. The rest of the requests are still “In Progress”.</strong></p>

<p>I don’t think this completion rate is a success. Do I have confidence that Incogni is chasing the remaining brokers? I can’t tell.</p>

<p>Their dashboard ought to be designed to provide more insights into the process. Clicking on a broker in the list of requests does not pull up any details about the request itself but rather a general description of their business and Incogni’s assessment of the sensitivity of the data they may hold.</p>

<p><img src="/assets/posts/incogni-brokers.png" alt="My Incogni Dashboard" class="lightbox" loading="lazy" /></p>

<p>Instead, I wish they provided a simple timeline with key events such as “Request Sent”, “Action Required”, “Follow Up Sent”, “Request Completed”, etc.</p>

<p>Last September, their support team said this was “valuable feedback” but I didn’t notice any improvements to the dashboard.</p>

<p><strong>Since then, I have discovered <a href="https://databrokerswatch.org/">Data Brokers Watch</a>, a very comprehensive database (over 900 brokers!), curated by a non-profit. They also enable you to request the deletion or a copy of your data (albeit one broker at a time).</strong></p>

<p>You should go through their <a href="https://databrokerswatch.org/top-ten">top 10 brokers</a>, especially if you live in the US. It will only take you a couple of minutes.</p>

<p>As far as Incogni is concerned, more than 69 Euros per year is likely needed to go after hundreds of brokers properly. If you are unsure about signing up, it’s all about having the right expectations and knowing that they will only send a bunch of automated emails on your behalf.</p>

<p>Lastly, it’s absurd that Incogni, a privacy service, uses Google Analytics and Google Tag Manager. They should know better!</p>

<p><strong>Update (Jan. 02, 2023)</strong>: Incogni sends weekly “Progress Reports” emails. On my Dec. 31, 2022 report, the number of requests sent actually <em>decreased</em> from 93 a month ago to 89, which raises questions about Incogni’s accuracy.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="thoughts" /><summary type="html"><![CDATA[Last August, I signed up for Incogni, a service that automates data removal requests from data brokers and marketers on your behalf. It’s owned by Surfshark, a subsidiary of Nord Security, the owner of NordVPN.]]></summary></entry><entry><title type="html">Migrating this site from Netlify to Cloudflare Pages</title><link href="https://lavaux.lv/2022/12/02/migrating-this-site-to-cloudflare-pages/" rel="alternate" type="text/html" title="Migrating this site from Netlify to Cloudflare Pages" /><published>2022-12-02T00:00:00+00:00</published><updated>2022-12-02T00:00:00+00:00</updated><id>https://lavaux.lv/2022/12/02/migrating-this-site-to-cloudflare-pages</id><content type="html" xml:base="https://lavaux.lv/2022/12/02/migrating-this-site-to-cloudflare-pages/"><![CDATA[<p>Two years ago, <a href="/2020/04/08/migrating-this-site-to-netlify">this site moved from GitHub Pages to Netlify</a>.</p>

<p>Overall, Netlify is a wonderful solution and I expect I’ll continue to use it for other projects.</p>

<p>This blog is a very simple sandbox: it’s pure Jekyll and doesn’t use any serverless functions, making it trivial to move from one provider to another. I didn’t need to change, but I was curious – knowing that it would require almost zero configuration or fixing.</p>

<p>Plus, Cloudflare and Netlify both have the relevant features for this site:</p>

<ul>
  <li>CSS/JS minification out of the box, though this website is purposely very light.</li>
  <li>Custom header, even with the same <code class="language-plaintext highlighter-rouge">_headers</code> file and syntax.</li>
  <li>Automagic HTTPS.</li>
</ul>

<p>Even though <a href="https://blog.cloudflare.com/cloudflare-pages-build-improvements/">Cloudflare has improved build times</a> already, they are still <em>very</em> much behind Netlify in my experience: my last commit took 18s to build and deploy on Netlify vs 3m 16s on Cloudflare! A shocking ten times slower!</p>

<p>Cloudflare Pages also lacks build/deploy notifications, which is a big downer.</p>

<p><strong>If you are using the JAMstack to its fullest potential, Netlify is the better option, without a doubt.</strong> It’s not worth migrating unless you want to leverage other Cloudflare products like R2 and KV Store.</p>

<p>In my case, I’ll continue to use this blog as a guinea pig to see how the product grows.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[Two years ago, this site moved from GitHub Pages to Netlify.]]></summary></entry><entry><title type="html">Ubiquiti - Upgrading UDM SE to UniFi OS v3 requires reinstalling NextDNS</title><link href="https://lavaux.lv/2022/11/29/ubiquiti-udm-v3-nextdns/" rel="alternate" type="text/html" title="Ubiquiti - Upgrading UDM SE to UniFi OS v3 requires reinstalling NextDNS" /><published>2022-11-29T00:00:00+00:00</published><updated>2022-11-29T00:00:00+00:00</updated><id>https://lavaux.lv/2022/11/29/ubiquiti-udm-v3-nextdns</id><content type="html" xml:base="https://lavaux.lv/2022/11/29/ubiquiti-udm-v3-nextdns/"><![CDATA[<p>Ubiquiti released the v3 (RC) of UniFi OS a few days ago. You can see the <a href="https://community.ui.com/releases/UniFi-OS-Dream-Machine-SE-3-0-13/cf25f68e-6906-4125-9d77-9fce05d6658a">full changelog here</a>.</p>

<p>Since my setup is quite simple and based on the community feedback, I didn’t feel the need to wait for potential bugs to be fixed and went ahead.</p>

<p><img src="/assets/posts/udm-pro-se.png" alt="UDM Pro SE" loading="lazy" /></p>

<p>The title of this post is self-explanatory, but this information might be helpful to UDM users who are unsure about upgrading to v3: upgrading to v3.0.13 breaks NextDNS.</p>

<p>In my case, after upgrading, I realized that my devices went back to using my ISP DNS and that custom names were no longer resolving.</p>

<p><strong>Fixing this issue takes two minutes: <a href="https://github.com/nextdns/nextdns/wiki/UnifiOS">re-install the CLI client</a>, confirm the settings and you should be good to go.</strong></p>

<p>As far as I can tell, there are no other issues with NextDNS and UniFi OS v3 at this time.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[Ubiquiti released the v3 (RC) of UniFi OS a few days ago. You can see the full changelog here.]]></summary></entry><entry><title type="html">An important security patch for the qpress file archiver</title><link href="https://lavaux.lv/2022/08/21/qpress-file-archiver-security-update/" rel="alternate" type="text/html" title="An important security patch for the qpress file archiver" /><published>2022-08-21T00:00:00+00:00</published><updated>2022-08-21T00:00:00+00:00</updated><id>https://lavaux.lv/2022/08/21/qpress-file-archiver-security-update</id><content type="html" xml:base="https://lavaux.lv/2022/08/21/qpress-file-archiver-security-update/"><![CDATA[<blockquote>
  <p><strong>TL;DR: If you rely on the <code class="language-plaintext highlighter-rouge">qpress</code> file archiver, you should update it ASAP.</strong></p>
</blockquote>

<p>On August 19th, 2022, <a href="https://github.com/ottok">Otto Kekalainen</a> and <a href="https://github.com/Chaloff">Mikhail Chalov</a> from AWS reached out by email to let me know they had found and fixed a directory traversal vulnerability in the <code class="language-plaintext highlighter-rouge">qpress</code> file archiver.</p>

<p>Traversals are a big no-no, especially in production environments. On top of that, Percona and MariaDB rely on <code class="language-plaintext highlighter-rouge">qpress</code> to perform database backups since it can compress large amounts of data very quickly, meaning that it’s bound to be installed on sensitive hosts.</p>

<p>Unfortunately, the project upstream is dead - which prompted me to fork it in the first place. As of this writing, <a href="http://www.quicklz.com/">the project homepage</a> no longer loads.</p>

<p>Mikhail’s pull request is available <a href="https://github.com/PierreLvx/qpress/pull/6">here</a>, with step-by-step instructions to reproduce the issue (which requires a malicious payload) if you are interested.</p>

<p>If you installed the <code class="language-plaintext highlighter-rouge">qpress</code> archiver, either from the original source or an older version of my fork, you should build a fresh binary using the <code class="language-plaintext highlighter-rouge">20220819</code> tag (or later) of my fork, which includes Mikhail’s fix.</p>

<p>If you installed <code class="language-plaintext highlighter-rouge">qpress</code> from a Linux repo, as far as I can tell, these are still using the original unpatched 2010 source. You should replace your executable with a freshly built binary which includes the patch.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[TL;DR: If you rely on the qpress file archiver, you should update it ASAP.]]></summary></entry><entry><title type="html">Reverse-engineering the Xiaomi RoboRock S5 firmware (Part 1)</title><link href="https://lavaux.lv/2022/05/27/reverse-engineering-roborock-s5-firmware_part_1/" rel="alternate" type="text/html" title="Reverse-engineering the Xiaomi RoboRock S5 firmware (Part 1)" /><published>2022-05-27T00:00:00+00:00</published><updated>2022-05-27T00:00:00+00:00</updated><id>https://lavaux.lv/2022/05/27/reverse-engineering-roborock-s5-firmware_part_1</id><content type="html" xml:base="https://lavaux.lv/2022/05/27/reverse-engineering-roborock-s5-firmware_part_1/"><![CDATA[<p>I’ve owned a RoboRock S5 for two years but only recently came across Dennis Giese’s research around the security of Xiaomi IoT products. His <a href="https://dontvacuum.me/thesis/Security_Analysis_of_the_Xiaomi_IoT_Ecosystem.pdf">master thesis</a>, where he details how he dumped and analyzed multiple firmwares, to gain root access ultimately, is a great read. His <a href="https://www.youtube.com/watch?v=DHsqb2poGII">Def Con 26 talk</a> is worth a watch too.</p>

<p><strong>As soon as I realized my RoboRock was <a href="https://dontvacuum.me/robotinfo/">a capable quad-core computer running Ubuntu Trusty</a>, I wanted to look at the firmware first-hand.</strong></p>

<p>This post is not about “jailbreaking” the S5 - which has been covered <a href="https://github.com/dgiese/dustcloud">elsewhere</a>. Instead, I will be sharing the steps you can use to get your copy of the firmware so that you can review and decompile the scripts and binaries used to provision and run the robot.</p>

<h2 id="get-a-readable-copy-of-the-firmware">Get a readable copy of the firmware</h2>

<p>1) Get a copy of the firmware file. See <a href="https://github.com/dgiese/dustcloud/wiki/Xiaomi-Vacuum-Firmware">here</a> if you want to download a different version.</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code>wget https://cdn.cnbj2.fds.api.mi-img.com/rubys/updpkg/v11_002034.fullos.55915876-2190-407a-9fcb-f1e760d9b623.pkg
</code></pre></div></div>

<p>2) Decrypt the firmware file (use <code class="language-plaintext highlighter-rouge">rockrobo</code> when prompted for a decryption key):</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code>ccrypt <span class="nt">-d</span> v11_002034.fullos.55915876-2190-407a-9fcb-f1e760d9b623.pkg
</code></pre></div></div>

<blockquote class="post-content-warning">
  <p>NB: Newer robots use a different encryption mechanism.</p>
</blockquote>

<p>3) The decrypted “pkg” is actually a gzip archive which contains a <code class="language-plaintext highlighter-rouge">disk.img</code>, so we’ll decompress it:</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nb">tar </span>zxvf v11_002034.fullos.55915876-2190-407a-9fcb-f1e760d9b623.pkg
</code></pre></div></div>

<p>4) Let’s find out more about <code class="language-plaintext highlighter-rouge">disk.img</code> with the <code class="language-plaintext highlighter-rouge">file</code> command:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>disk.img: Linux rev 1.0 ext4 filesystem data, UUID=c3a11fc8-0afb-4909-948f-f764e532f7a6, volume name "rootfs" (extents) (huge files)
</code></pre></div></div>

<p>5) It’s time to mount this image:</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nb">sudo </span>mount <span class="nt">-o</span> loop disk.img /mnt
</code></pre></div></div>

<blockquote class="post-content-warning">
  <p>NB: This command will fail on Mac OS (no native support of ext4 or loop devices). Ubuntu in a VM will do.</p>
</blockquote>

<p>6) You can now freely inspect the firmware! To go to the main folder, do:</p>

<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nb">cd</span> /mnt/opt/rockrobo
</code></pre></div></div>

<h2 id="so-what-can-we-see">So what can we see?</h2>

<p><strong>You can preview the full <code class="language-plaintext highlighter-rouge">rockrobo/</code> file tree on <a href="https://gist.github.com/PierreLvx/62887a59ee2d6dc9de8363f6085f6f90">this GitHub gist</a> (26 directories, 738 files).</strong></p>

<p>From <code class="language-plaintext highlighter-rouge">cloc</code>:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>--------------------------------------------------------------------------------
Language                      files          blank        comment           code
--------------------------------------------------------------------------------
Bourne Shell                     11            154             38           1044
Perl                              1             19              2            110
Bourne Again Shell                1              1              0             21
--------------------------------------------------------------------------------
SUM:                             13            174             40           1175
--------------------------------------------------------------------------------
</code></pre></div></div>

<p>That’s a lot of bash scripts! It also turns out that they perform critical operations, but I’ll keep that and other fun facts for a future post.</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[I’ve owned a RoboRock S5 for two years but only recently came across Dennis Giese’s research around the security of Xiaomi IoT products. His master thesis, where he details how he dumped and analyzed multiple firmwares, to gain root access ultimately, is a great read. His Def Con 26 talk is worth a watch too.]]></summary></entry><entry><title type="html">Preventing email spoofing with a DMARC Policy</title><link href="https://lavaux.lv/2022/05/16/preventing-email-spoofing-dmarc-policy/" rel="alternate" type="text/html" title="Preventing email spoofing with a DMARC Policy" /><published>2022-05-16T00:00:00+00:00</published><updated>2022-05-16T00:00:00+00:00</updated><id>https://lavaux.lv/2022/05/16/preventing-email-spoofing-dmarc-policy</id><content type="html" xml:base="https://lavaux.lv/2022/05/16/preventing-email-spoofing-dmarc-policy/"><![CDATA[<blockquote>
  <p>DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication protocol. <strong>It is designed to give email domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing.</strong> The purpose and primary outcome of implementing DMARC is to protect a domain from being used in business email compromise attacks, phishing email, email scams and other cyber threat activities.<sup id="fnref:1"><a href="#fn:1" class="footnote" rel="footnote" role="doc-noteref">1</a></sup></p>
</blockquote>

<p>This post will not explain how to set up a DMARC policy on your domain.  Google has <a href="https://support.google.com/a/answer/10032473?hl=en">a great guide</a> to get you started. If you want to nerd out, <a href="https://datatracker.ietf.org/doc/html/rfc7489">RFC7489</a> has you covered.</p>

<p>Instead, I want to share my experience, which, hopefully, will convince you to roll out your own DMARC policy. <strong>Email spoofing is everywhere and unless you have the right DMARC policy in place, you can’t see and combat it.</strong></p>

<p>I work for a small early-stage venture capital firm. We don’t get much media attention because we usually invest alongside larger funds and don’t write eye-popping checks. But we still manage quite a bit of money and handle sensitive and generally confidential information. Some of that information needs to be shared externally with our investors, lawyers, auditors, accountants, banks, etc., which happens over email 99% of the time. <a href="https://www.wsj.com/articles/ransomware-attackers-begin-to-eye-midmarket-acquisition-targets-11646130601">Hackers know this</a> and will play the long game to <a href="https://www.forbes.com/sites/zakdoffman/2020/04/23/microsoft-365-hackers-hit-private-equity-in-new-million-dollar-heist-heres-how-it-works/">steal large sums of money</a>.</p>

<p>We rolled out SPF (Sender Policy Framework) and DKIM (Domain Keys Identified Mail) years ago. See <a href="https://serverfault.com/a/1024343">this quick recap</a> if you are unsure how they tie into DMARC.</p>

<p>Meanwhile, the quality of some of the spam and phishing we were receiving continued to improve, some of which was very well done and quite deceiving (fake capital call notices, fake shared folders, etc., with many pretending to come from our domain). Malicious actors were trying to leverage our brand/domain, likely to steal credentials or spread ransomware.</p>

<p>But you don’t have to be a financial institution to be a target. For example, eBay, Deliveroo and Netflix all have strict DMARC policies<sup id="fnref:2"><a href="#fn:2" class="footnote" rel="footnote" role="doc-noteref">2</a></sup>. Hypothetically, a forged transactional email could lead to an account takeover for example. With the right DMARC policy in place, a forged email is less likely to get to the recipient’s inbox.</p>

<p>So we deployed a basic, report-only, DMARC policy and used <a href="https://report-uri.com/">Report URI</a> to establish a baseline. A few weeks later, the stats showed dozens of unknown senders in odd countries. Then, we changed the policy to <code class="language-plaintext highlighter-rouge">quarantine</code> and continued to monitor. Finally, we updated the policy to <code class="language-plaintext highlighter-rouge">reject</code> 100% of the messages that failed DMARC checks.</p>

<p>We’ve had this setup for over two years now. <strong>On average, we see 30-50 DMARC rejects a month from all over the world.</strong> For instance, last month’s unauthorized senders came from Morocco, Pakistan, Vietnam, Serbia, and Puerto Rico. <strong>These numbers would undoubtedly be orders of magnitude higher if we were a more prominent firm.</strong></p>

<p>Go and get a robust DMARC policy set up!</p>

<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:1">
      <p><a href="https://en.wikipedia.org/wiki/DMARC">Wikipedia</a> <a href="#fnref:1" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:2">
      <p>At the time of this writing, they are all rejecting 100% of emails failing DMARC checks. <a href="#fnref:2" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication protocol. It is designed to give email domain owners the ability to protect their domain from unauthorized use, commonly known as email spoofing. The purpose and primary outcome of implementing DMARC is to protect a domain from being used in business email compromise attacks, phishing email, email scams and other cyber threat activities.1 Wikipedia &#8617;]]></summary></entry><entry><title type="html">How to fix the Netlify GLIBC build error with Node.js v18</title><link href="https://lavaux.lv/2022/04/26/fix-netlify-build-errors-with-node-18/" rel="alternate" type="text/html" title="How to fix the Netlify GLIBC build error with Node.js v18" /><published>2022-04-26T00:00:00+00:00</published><updated>2022-04-26T00:00:00+00:00</updated><id>https://lavaux.lv/2022/04/26/fix-netlify-build-errors-with-node-18</id><content type="html" xml:base="https://lavaux.lv/2022/04/26/fix-netlify-build-errors-with-node-18/"><![CDATA[<p>Node.js v18.0 was released <a href="https://nodejs.org/en/blog/announcements/v18-release-announce/">just a few days ago</a>. Generally speaking, I make sure to closely keep up with updates, especially with javascript projects, which sometimes have insane dependencies trees.</p>

<p>I maintain one static website, built with webpack and deployed on Netlify, which was an easy candidate to see if node v18 introduced any bugs in our build and deploy process.</p>

<p>In the Netlify site settings, I changed the <code class="language-plaintext highlighter-rouge">NODE_VERSION</code> environment variable to <code class="language-plaintext highlighter-rouge">18</code> and triggered a deploy, which failed. Here’s the log:</p>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>3:00:43 PM: Build ready to start
3:00:51 PM: build-image version: ac716c5be7f79fe384a0f3759e8ef612cb821a37 (xenial)
3:00:51 PM: build-image tag: v3.13.0
3:00:51 PM: buildbot version: e58b6be665675c0f99b33132a8c1eec1f775eba1
3:00:51 PM: Building without cache
3:00:51 PM: Starting to prepare the repo for build
3:00:51 PM: No cached dependencies found. Cloning fresh repo
3:00:51 PM: git clone [REDACTED]
3:00:54 PM: Preparing Git Reference refs/heads/master
3:00:55 PM: Parsing package.json dependencies
3:00:56 PM: Starting build script
3:00:56 PM: Installing dependencies
3:00:56 PM: Python version set to 2.7
3:00:57 PM: Downloading and installing node v18.0.0...
3:00:57 PM: Downloading https://nodejs.org/dist/v18.0.0/node-v18.0.0-linux-x64.tar.xz...
3:00:58 PM: Computing checksum with sha256sum
3:00:58 PM: Checksums matched!
3:01:00 PM: node: /lib/x86_64-linux-gnu/libm.so.6: version `GLIBC_2.27' not found (required by node)
node: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.25' not found (required by node)
node: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.28' not found (required by node)
nvm is not compatible with the npm config "prefix" option: currently set to ""
3:01:00 PM: Run `nvm use --delete-prefix v18.0.0` to unset it.
3:01:00 PM: Failed to install node version '18'
3:01:00 PM: Build was terminated: Build script returned non-zero exit code: 1
3:01:01 PM: Creating deploy upload records
3:01:01 PM: Failing build: Failed to build site
3:01:01 PM: Failed during stage 'building site': Build script returned non-zero exit code: 1 (https://ntl.fyi/exit-code-1)
3:01:01 PM: Finished processing build request in 10.203136084s
</code></pre></div></div>

<p>Clearing the cache and retrying the deploy yielded the same result.</p>

<p>Since Netlify uses <code class="language-plaintext highlighter-rouge">nvm</code> to manage node versions, I wondered what was wrong with the build environment. As can be seen in the logs, the build environment was still running Ubuntu Xenial (16.04), which is no longer actively maintained.</p>

<p>Thankfully, <a href="https://docs.netlify.com/configure-builds/manage-dependencies/#build-image-defaults">Netlify allows you to select Ubuntu Focal (20.04)</a>. To do so, navigate to <strong>Site settings &gt; Build &amp; deploy &gt; Continuous Deployment &gt; Build image selection</strong>.</p>

<p>I cleared the cache and it built and deployed perfectly this time.</p>

<p>Sometimes the build environment needs an update too!</p>]]></content><author><name>{&quot;twitter&quot; =&gt; &quot;prlvx&quot;}</name></author><category term="tips" /><summary type="html"><![CDATA[Node.js v18.0 was released just a few days ago. Generally speaking, I make sure to closely keep up with updates, especially with javascript projects, which sometimes have insane dependencies trees.]]></summary></entry></feed>