|
|
Log in / Subscribe / Register

Brief items

Security

Security quotes of the week

[...] Pick just about any crypto, it should be good enough. It's the key management that'll let you down.

When I'm auditing crypto code for security vulns, I pretty much ignore the crypto itself, I just use it as a beacon to where the mistakes are being made.

Peter Gutmann

Today the Canadian Supreme Court ordered Google to remove search results that the Court doesn't feel should be present. The court demands that Google remove those results not just for Canadian users, but for the entire planet. That's right, Canada has declared itself a global Google censor.

I've been predicting for many years this move toward global censorship imposed by domestic governments. I suspected all along that attempts by Google to mollify government censorship demands through the use of geoblocking would never satisfy countries that have the sweet taste of censorship already in their authoritarian mouths — no matter if they're ostensibly democracies or not. Censorship is like an addictive drug to governments — once they get the nose of the censorship camel under the tent, the whole camel will almost always follow in short order.

Lauren Weinstein

[...] I regularly get e-mails from people explaining in graphic detail how their whole lives have been hacked. Most of them are just paranoid. But a few of them are probably legitimate. And I have no way of telling them apart.

This problem isn't going away. As computers permeate even more aspects of our lives, it's going to get even more debilitating. And we don't have any way, other than hiring a "professional cybersecurity firm," of telling the paranoids from the victims.

Bruce Schneier

Comments (1 posted)

Kernel development

Kernel release status

The current development kernel is 4.12-rc7, released on June 25. Linus said: "It's fairly small, and there were no huge surprises, so if nothing untoward happens this upcoming week, this will be the final rc. But as usual, I reserve the right to just drag things out if I end up feeling uncomfortable about things for any reason including just random gut feelings, so we'll see."

Stable updates: 4.11.7 and 4.9.34 were released on June 24; 4.4.74 and 3.18.58 followed on June 26.

The 4.11.8, 4.9.35, 4.4.75, and 3.18.59 updates are in the review process as of this writing; they can be expected on or after June 29.

Comments (none posted)

Quotes of the week

The GPU vendor mexican-standoff-farce is bound to become the laughing stock of history. I would put my hopes to the reverse-engineered drivers like Freedreno or the fine work from the etnaviv people.
Linus Walleij

The combination of SELinux, Smack, AppArmor and/or TOMOYO is not the goal so much as the test case. MAC was the coolest possible technology in 1990. We've implemented it. I don't see anyone doing a new MAC implementation. I *do* see security modules that implement other security models in the pipeline. Some of these need to maintain state, which means using security blobs in the LSM architecture. Some of these models will want to use secmarks to implement socket based controls. If we can provide for SELinux+Smack* we can be confident that we can support anything today's kids want to throw at us. If we blow that off Linux won't be able to adapt to the security needs of the future.
Casey Schaufler

Comments (2 posted)

Distributions

Distribution quotes of the week

One thing that I realized recently is that nowadays, distributions lost the war. As the title of this post says, difference is our strength, but at the same time, it is also the seed of our ruin. Take distributions: Gentoo, Fedora, Debian, SuSE, Archlinux, Ubuntu. They all look and act differently, focusing on different target users, and because of this they differ significantly in which software they make available, which versions are made available, and how much effort is spent on testing, both the package itself and the system integration.

While describing it this way, there is nothing that scream «Conflict!», except at this point we all know that they do conflict, and the solutions from many different communities, have been to just ignore distributions: developers of libraries for high level languages built their own packaging (Ruby Gems, PyPI, let’s not even talk about Go), business application developers started by using containers and ended up with Docker, and user application developers have now started converging onto Flatpak.

Diego Elio Pettenò

I have also reviewed the patches and after I wiped the blood from my eyes, things looked marvelous there as well. ;) (I am always amazed as to the scale of changes introduced in Apache minor versions...)
Antoine Beaupré

I really enjoyed my time working on FirefoxOS, and getting a nice clean break from platform work, but it was always bitter-sweet. Everyone working on the project was very enthusiastic to see it through and do a good job, but it never felt like upper management’s focus was in the correct place. We spent far too much time kowtowing to the desires of phone carriers and trying to copy Android and not nearly enough time on basic features and polish. Up until around v2.0 and maybe even 2.2, the experience of using FirefoxOS was very rough. Unfortunately, as soon as it started to show some promise and as soon as we had freedom from carriers to actually do what we set out to do in the first place, the project was cancelled, in favour of the whole Connected Devices IoT debacle.
Chris Lord

Comments (none posted)

Development

digiKam 5.6.0 is released

The digiKam Team has released version 5.6.0 of the digiKam Software Collection for photo management. "With this version the HTML gallery and the video slideshow tools are back, database shrinking (e.g. purging stale thumbnails) is also supported on MySQL, grouping items feature has been improved, the support for custom sidecars type-mime have been added, the geolocation bookmarks introduce fixes to be fully functional with bundles, the support for custom sidecars, and of course a lots of bug has been fixed."

Comments (none posted)

The mkosi OS generation tool

Last week Lennart Poettering introduced casync, a tool for distributing system images. This week he introduces mkosi, a tool for making OS images. "mkosi is definitely a tool with a focus on developer's needs for building OS images, for testing and debugging, but also for generating production images with cryptographic protection. A typical use-case would be to add a mkosi.default file to an existing project (for example, one written in C or Python), and thus making it easy to generate an OS image for it. mkosi will put together the image with development headers and tools, compile your code in it, run your test suite, then throw away the image again, and build a new one, this time without development headers and tools, and install your build artifacts in it. This final image is then "production-ready", and only contains your built program and the minimal set of packages you configured otherwise. Such an image could then be deployed with casync (or any other tool of course) to be delivered to your set of servers, or IoT devices or whatever you are building."

Comments (20 posted)

Development quotes of the week

I’m thankful that the sewing machine was invented a long time ago, not today. If the sewing machine were invented today, most sewing tutorials would be twice as long, because all the thread would come in proprietary cartridges, and you would usually have to hack the cartridge to get the type of thread you need in a cartridge that works with your machine.
Don Marti

POSIX threads are also terribly low-level. Asking someone to build a system with mutexes and cond vars is like building a house with exploding toothpicks.
Andy Wingo

Comments (none posted)

Miscellaneous

FSF: Fifteen new devices from Technoethical now RYF-certified

The Free Software Foundation has awarded Respects Your Freedom (RYF) certification to fifteen devices from Technoethical (formerly Tehnoetic): the TET-N150HGA, the TET-N300, the TET-N300HGA, the TET-N300DB, the TET-N450DB, the TET-BT4, the TET-X200, the TET-X200T, the TET-X200S, the TET-T400, the TET-400S, the TET-T500, the TET-X200DOCK, the TET-T400DOCK, and the TET-D16. "These are not the first devices from Technoethical to receive RYF certification. These fifteen new devices join Technoethical's Mini N150 WI-FI USB adapter TET-N150, certified in 2014. With these additions, Technoethical is now home to an incredible breadth of devices that users can trust to respect their freedom."

Full Story (comments: none)

GitHub announces Open Source Friday

GitHub has announced a new program that aims to make it easier for people to contribute to open source projects. "Open Source Friday isn't limited to individuals. Your team, department, or company can take part, too. Contributing to the software you already use isn't altruistic—it's an investment in the tools your company relies on. And you can always start small: spend two hours every Friday working on an open source project relevant to your business. Whether you're an aspiring contributor or active maintainer of open source software, we help you track and share your Friday contributions. We also provide a framework for regular contribution, along with resources to help you convince your employers to join in."

Comments (20 posted)

Intel Skylake/Kaby Lake processors: broken hyper-threading

Henrique de Moraes Holschuh has posted an advisory about a processor/microcode defect recently identified on Intel Skylake and Intel Kaby Lake processors with hyper-threading enabled. "TL;DR: unfixed Skylake and Kaby Lake processors could, in some situations, dangerously misbehave when hyper-threading is enabled. Disable hyper-threading immediately in BIOS/UEFI to work around the problem. Read this advisory for instructions about an Intel-provided fix."

Full Story (comments: 30)

Page editor: Jake Edge
Next page: Announcements>>


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds