Daily Shaarli

All links of one day in a single page.

September 29, 2026

Remotely access devices that can't run Tailscale · Tailscale Docs
thumbnail

Subnet routers

Use subnet routers to give devices outside your local network access to services within specific subnets. Extend your private network with Tailscale.

New Attack Against RSA - Schneier on Security

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months).

The authors have a webpage that explains the context much better than the article. And here’s the paper.

Let's Try ServerCrate! Restic-Based Backups You Can Start Using for FREE! - LowEndBox
thumbnail

You can get started for FREE with a 10GB vault. I think that’s really cool, because it’s enough to actually give it a try and use it productively. It’s not time-limited, so you can set up a vault, stream some backups to it, and let it keep working to really test the service.

So I decided to do just that.

I have a small box I use for VPN purposes on DigitalOcean. It’s a 512MB “droplet” (ick – it’s a VPS people). I already back it up to my home lab, but it’s a good candidate for a Restic-based backup.

In general, when I backup, I capture the following:

  • Essential file and filesystems, using a “default include” model. I exclude a bunch of directories such as /dev, but by default I include everything.
  • I also include “status” dumps, such as dpkg -l, ps -ef, df -h, and other info.
  • Finally I do database dumps.

In the case of my VPN server, the things I care about are:

  • /etc, where all the OpenVPN config lives
  • because I use @Nyr’s Road Warrior script and I put the .ovpn file in /root, I should back that up, too.
  • My own backups put data in /backup (dpkg -l output, etc.) so I’ll back that up.