Bonum Certa Men Certa

Links 19/12/2018: VirtualBox 6.0, RawTherapee 5.5, Mir 1.1.0, LibreOffice 6.1.4 Released





GNOME bluefish

Contents





GNU/Linux



Free Software/Open Source



  • Events



    • Event Report: g0v Summit 2018 — Taipei
      Gov zero summit is a decentralized, grass-roots civic tech community based in Taiwan. Built on the spirits of open source and activism, g0v aims to use technology in the interest of the public good, advocate information transparency and build tech solutions to promote civic engagement. I was lucky my talk got selected and got an opportunity to speak at the event.




  • Web Browsers



    • Mozilla



      • BBN challenge resolution: Getting the flag from a browser extension
        My so far last BugBountyNotes challenge is called Can you get the flag from this browser extension?. Unlike the previous one, this isn’t about exploiting logical errors but the more straightforward Remote Code Execution. The goal is running your code in the context of the extension’s background page in order to extract the flag variable stored there.

        If you haven’t looked at this challenge yet, feel free to stop reading at this point and go try it out. Mind you, this one is hard and only two people managed to solve it so far. Note also that I won’t look at any answers submitted at this point any more. Of course, you can also participate in any of the ongoing challenges as well.




  • LibreOffice



    • LibreOffice 6.1.4 Office Suite Released with More Than 125 Bug Fixes, Update Now
      LibreOffice 6.1.4 comes one and a half months after version 6.1.3 with yet another layer of bug fixes across all the components of the office suite, including Writer, Calc, Draw, Impress, Base, and Math. However, it remains the choice of bleeding-edge users and early adopters until the LibreOffice 6.1 series matures enough to be offered to enterprises. A total of 126 changes are included, as detailed here and here.



    • LibreOffice 6.1.4 announced
      The Document Foundation announces LibreOffice 6.1.4, the 4th minor release of the LibreOffice 6.1 family, targeted at tech savvy individuals: early adopters, technology enthusiasts and power users.




  • Openness/Sharing/Collaboration



    • Open Hardware/Modding



      • MIPS Processor ISA To Be Open-Sourced In 2019
        Months after MIPS Technologies was acquired by Wave Computing, the company announced it's working on open-sourcing the MIPS processor instruction set architecture.

        The MIPS ISA will be open-sourced with both the 32-bit and 64-bit versions opening up and will be free of any licensing or royalty fees as well as access to existing MIPS patents.






  • Programming/Development





Leftovers



  • Security



    • How Shopify Avoided a Data Breach, Thanks to a Bug Bounty
      At KubeCon + CloudNativeCon NA 2018, Shopify and Google detail a Kubernetes security incident reported by a bug bounty security researcher that was quickly remediated before any harm was done.



    • Logitech Options App Plagued By PID Exploit, Security Vulnerability Fixed With New Update
      Logitech Options is an app that controls all of Logitech’s mice and keyboards. It offers several different configurations like Changing function key shortcuts, Customizing mouse buttons, Adjusting point and scroll behavior and etc. This app contained a huge security flaw that was discovered by Tavis Ormandy who is a Google security researcher. It was found that Logitech Options was opening a WebSocket server on each individual computer Logitech Options was run on. This WebSocket server would open on port 10134 on which any website could connect and send several various commands which would be JSON-encoded.



    • pwnedkeys: who has the keys to *your* kingdom?
      I am extremely pleased to announce the public release of pwnedkeys.com – a database of compromised asymmetric encryption keys. I hope this will become the go-to resource for anyone interested in avoiding the re-use of known-insecure keys. If you have a need, or a desire, to check whether a key you’re using, or being asked to accept, is potentially in the hands of an adversary, I would encourage you to take a look.



    • “123456” Tops The List Of Worst Passwords For 5th Consecutive Year




  • Defence/Aggression



    • Peoples Vote in Danger of Becoming War Criminal Rehabilitation
      Regular readers know I have largely steered clear of discussing Brexit for the three years its possibility then prospect has dominated the UK political agenda. I used to be enthusiastically pro-EU, as part of my general outlook of supporting international law and organisations. I was however shocked, deeply, by the enthusiastic support of all three institutional strands – council, commission and parliament – for the appalling Francoist paramilitary violence in Catalonia, and decided that the EU is no longer an institution I can support.

      The increasingly illiberal developments of the EU’s Third Pillar – including the abuse of arrest warrant procedure against Julian Assange and the internationalising of “Prevent” style Islamophobia – had already increasingly been worrying me. My reservations about the EU are therefore different to those of many. I particularly bemoan the loss of Freedom of Movement which I believe to have been one of the greatest achievements of civilisation in my lifetime. I remain incensed at the success of the elite in conning the deprived that their poverty is caused by immigrants, whereas it is caused by massive inequality of wealth.

      So I am conflicted on Brexit, but on balance would prefer to leave but stay part of the single market, thus retaining freedom of movement. My personal preferences aside, there is plainly a huge majority against leaving the EU in Scotland, so for Scotland to leave the EU at all at present would be wrong. It is my profound hope that the SNP will find the courage shortly to move on towards Independence.



    • No One’s Asking the Right Questions About Police Drones
      Police drones are expanding, but are the media asking questions?

      The NYPD, the nation’s largest police force, announced this week that they had purchased over a dozen flying robots to fly over Gotham, while promising that the new technology wouldn’t be used for any of the illegal spying shenanigans the police department has been caught up in time and time again. The announcement, however, was awkwardly timed, as the police department had already purchased drones—last December.

      Instead of asking the kinds of questions one might expect for a scandal-plagued agency obtaining expansive new surveillance powers—Why did you wait a year to announce the move? Was the public consulted? Are there oversight mechanisms to guard against misuse?—most media outlets questioned nothing, quoted generously from police officials and (at best) sprinkled in few concerns from legal organizations.


    • He Said He’d Be Murdered If Deported. He Was.
      Nearly a year after a judge rejected Santos Chirino’s case for asylum, his 18-year-old daughter and 19-year-old son returned to the very same courtroom to plead their own.

      “Your honor, this is a difficult case,” their father’s lawyer, Benjamin Osorio, told Judge John Bryant. “I represented their father, Santos Chirino Cruz. … I lost the case in this courtroom. … He was murdered in April.”

      As Maria Sacchetti described for The Washington Post, “Osorio paused, and the judge blanched and stammered.”

      “You said their father’s case — did I understand I heard [it]?” Bryant asked, eyes wide.

      “No,” Osorio said. “In this court. Not before your honor.”

      “Well good, because — all right, my blood pressure can go down now,” Bryant said. “Yeah. I mean. Okay.”




  • Transparency/Investigative Reporting



    • Everyone hates Julian Assange, except for when you used to love him
      It’s not hard to find people in Washington with strong opinions about Wikileaks and its founder, Julian Assange. But good luck finding someone with an opinion about Assange that hasn’t flipped 180 degrees (and maybe back again) over the past ten years. Assange has managed the rare feat of becoming a pariah to both the left and the right, politicians and the press, “the masses” and their elected leaders. Foreign and domestic, coastal and “flyover,” red and blue—everyone seems to hate Assange (except for that time when they used to love him). As a result, Assange has become a poster boy for the importance of First Amendment protections. At its core, the First Amendment is an expression of “anti-majoritarian” rights—it is meant to protect social pariahs from persecution by political majorities. Popular people and popular ideas generally don’t need constitutional protection. Haters and lunatics and radicals? Their speech needs protection for the very reason that strong majorities reject it—it is so far outside the norm that ordinary politics will almost certainly persecute it.


    • Roger Stone says he pushed false statements on Infowars


    • Twenty-One Thoughts On The Persecution Of Julian Assange
      1. I write a lot about the plight of Julian Assange for the same reason I write a lot about the Iraq invasion: his persecution, when sincerely examined, exposes undeniable proof that we are ruled by a transnational power establishment which is immoral and dishonest to its core.

      2. Assange started a leak outlet on the premise that corrupt and unaccountable power is a problem in our world, and that the problem can be fought with the light of truth. Corrupt and unaccountable power has responded by detaining, silencing and smearing him. The persecution of Assange has proved his thesis about the world absolutely correct.

      3. Anyone who offends the US-centralized empire will find themselves subject to a trial by media, and the media are owned by the same plutocratic class which owns the empire. To believe what mass media news outlets tell you about those who stand up to imperial power is to ignore reality.

      4. Corrupt and unaccountable power uses its political and media influence to smear Assange because, as far as the interests of corrupt and unaccountable power are concerned, killing his reputation is as good as killing him. If everyone can be paced into viewing him with hatred and revulsion, they’ll be far less likely to take WikiLeaks publications seriously, and they’ll be far more likely to consent to Assange’s silencing and imprisonment. Someone can be speaking 100 percent truth to you, but if you’re suspicious of him you won’t believe anything he’s saying. If they can manufacture that suspicion with total or near-total credence, then as far as our rulers are concerned it’s as good as putting a bullet in his head.




  • Privacy/Surveillance



    • PSA: Fake App Store Receipts Are Tricking People Into Providing All Their Personal Details
      A fascinating new phishing attempt it making the rounds disguising itself as a receipt from the App Store, tricking unsuspecting users into coughing up all of their personal details. Here’s what you need to know and how to stay safe.



    • At The CIA, A Fix To Communications System That Left Trail Of Dead Agents Remains Elusive
      Between around 2009 and 2013, the CIA’s online method of communicating with its human sources on the ground all over the world was tragically compromised — leading to the exfiltration, imprisonment or death of dozens of people spying for the agency, according to a November investigation by Yahoo News.

      The failure started when Iranian officials used a double agent to trace back a series of websites the CIA was using to communicate with its sources. Iran then located, detained and in some instances executed CIA sources it identified using this system. The problem then spread to China, where roughly 30 CIA sources were eventually executed. Once Iran and China were able to locate users of these covert CIA platforms in their own countries, sources told Yahoo News, they were very likely able to discover a large number of CIA sources using similar systems worldwide.

      But the fallout from that disaster, including internal battles at the CIA and struggles to replace and fix a complex web of interlocking technical systems, continues to rage on to this day, according to five former intelligence community sources familiar with the matter.




  • Civil Rights/Policing



    • No State Accountability for North Carolina Contractor Who Helped CIA Torture
      On December 9, 2014, the Senate Intelligence Committee released a 500-page executive summary of its 6,000-page report on the history of the CIA’s detention and interrogation program. The report exposed just how brutal and ineffective the torture was, and the lengths to which the CIA went to hide that truth from the public.

      Four years have passed since the report was released—yet only three copies of the full report exist outside Senate Intelligence Committee’s vault, and what is available for public scrutiny is less than 10 percent of the report. The Committee voted only to release a heavily redacted executive summary and, since then, the CIA and its allies in Congress have sought to limit who has access to the report and who can read it in its entirety. The U.S. public, in other words, is still in the dark when it comes to this crucial chapter of its own recent history.

      To be sure, the ACLU has been doing heroic work filing Freedom of Information Act requests. And citizen-led groups—like my own organization, the North Carolina Commission of Inquiry on Torture—work hard to use what’s available in the public record to piece together details on the CIA’s rendition, detention, and interrogation program and inform the public. Nonetheless, the vast majority of what the Senate Intelligence Committee discovered in their investigation remains shielded from public inquiry.



    • CIA created ‘remote controlled dogs’ using brain surgery in secret experiments
      America's Central Intelligence Agency conducted grisly experiments to create 'remote controlled dogs', with electrodes planted in their brains to 'receive orders'.


    • GEORGE H.W. BUSH (1924-2018), AMERICAN WAR CRIMINAL
      THE UNITED STATES is now in the midst of a grotesque canonization of one of its imperial saints, George Herbert Walker Bush. This week on Intercepted: an honest memorial service for an unrepentant warmonger who dedicated his life to militarism, war, coups, regime change, and the lies of “American exceptionalism.” Jeremy Scahill details the crimes of Bush, the sick propaganda of the corporate media memorials, and the trail of blood, death, and tears Bush leaves behind. Independent journalist Arun Gupta covers decades of Bush, from his time at the helm of the CIA to the presidency. Gupta discusses Bush’s support for Manuel Noriega and his eventual invasion of Panama, the pardoning of Iran-Contra criminals, the dirty wars in Central America, the support for Saddam Hussein, and the launch of the Gulf War. Acclaimed Iraqi poet and scholar Sinan Antoon describes his life under the U.S.-backed dictatorship of Saddam, the horrors of the Gulf War, and how Bush’s destruction of Iraqi civilian society led to the rise of ISIS.

    • George H.W. Bush, the CIA and a Case of State-Sponsored Terrorism
      In early fall of 1976, after a Chilean government assassin had killed a Chilean dissident and an American woman with a car bomb in Washington, D.C., George H.W. Bush’s CIA leaked a false report clearing Chile’s military dictatorship and pointing the FBI in the wrong direction.

      The bogus CIA assessment, spread through Newsweek magazine and other U.S. media outlets, was planted despite CIA’s now admitted awareness at the time that Chile was participating in Operation Condor, a cross-border campaign targeting political dissidents, and the CIA’s own suspicions that the Chilean junta was behind the terrorist bombing in Washington.

      In a 21-page report to Congress on Sept. 18, 2000, the CIA officially acknowledged for the first time that the mastermind of the terrorist attack, Chilean intelligence chief Manuel Contreras, was a paid asset of the CIA.

      The CIA report was issued almost 24 years to the day after the murders of former Chilean diplomat Orlando Letelier and American co-worker Ronni Moffitt, who died on Sept. 21, 1976, when a remote-controlled bomb ripped apart Letelier’s car as they drove down Massachusetts Avenue, a stately section of Washington known as Embassy Row.



    • CIA used mind control experiments on dogs and humans during the 1960s


    • CIA once secretly implanted mind-control devices in dogs’ brains
      The CIA created remote-controlled dogs by operating on their brains during a bizarre mind-control experiment, according to freshly declassified documents.

      During the top-secret 1963 project, researchers implanted a device inside six canines’ skulls and guided them through an open field, according to documents posted on The Black Vault, a website specializing in declassified government records.


    • Trailer for 'Drugs as Weapons Against Us' Doc About CIA's Experiments
      "Much of it remains classified for 'national security' reasons." Gravitas Ventures has released a trailer for an indie documentary titled Drugs as Weapons Against Us, made by first-time filmmaker John Potash. The full title is actually Drugs as Weapons Against Us: The CIA War on Musicians and Activists, and it's an examination of the CIA's nefarious past when they manipulated musicians & activists to promote drugs for social control, particularly with the Civil Rights and anti-war movements. Some musicians that resisted these manipulations were killed. We've all heard these stories, and while some of it is true, some of it seems like they are drifting into conspiracy theory territory. Based on Potash's book "Drugs as Weapons Against Us", the film looks at evidence that the CIA targeted SDS, Black Panthers, Hendrix, Lennon, Cobain, Tupac, and other leftists. The footage in this trailer isn't that impressive, I wish it looked better than it does.





  • Intellectual Monopolies



    • Patent case: Sprint Communications Co., L.P. v. Time Warner Cable, Inc., USA
      The U.S. Court of Appeals for the Federal Circuit has affirmed a $139.8 million jury verdict in favor of Sprint Communications against Time Warner for infringement of five Sprint patents related to VoIP technology. The appeals court concluded that the district properly admitted evidence relating to the jury verdict in an earlier, related case brought by Sprint against Vonage, another carrier offering VoIP service.








Recent Techrights' Posts

Coping With the Site Going More Mainstream
Fame is no laughing matter
21 Pages in Less Than 7 Hours is No Joking Matter
We've become a lot more effective and efficient
Generation Chaff - Phase V: Censorship of Dissent (Painted as Harassment or Terrorism)
Censorship is all around us now
Generation Chaff - Phase IV: Apps Only Few Companies Decide On
Tools are being collectively confiscated, under the premise or false prospect of "security"
 
[Video] Richard Stallman's Talk in Sweden, Attended by Nearly 700 People, is Now Online
The Web page is in Swedish, but the talk is in English
Slopwatch: LinuxSecurity.com, Linux Journal, and Pet Slopfarms of Google News
Why does Google News still advance these fake sites to the top of search results?
Links 24/10/2025: Inequality Grows, Billion-Dollar Scam Center Industry
Links for the day
Links 24/10/2025: "Independent Media in Cambodia is Collapsing" and Serious F5 Breach
Links for the day
They Never 'Put Down' Corporations
There are "pests" that are traded in Wall Street
Correct Information is a Valued Asset in the Age of Slopfarms and Public Relations (PR) or Spin
Publishing suppressed facts is never easy
The Register MS Continues to Bag Money to Promote a Ponzi Scheme, Even Money From China
Today in the front page
analytics.usa.gov: The Only Supported Version of Windows (This Past Week) is Only Used by About 13.9% of People in the US, the Home Base of Windows
Even Vista 7 is still used more
Rust is Very Secure
If only Rust itself is secure
Who Will be Held Accountable for Breaking Ubuntu by Imposing Rust on Otherwise-Functional Programs, in Effect Replacing GNU With Proprietary Microsoft (GitHub)?
they're practical people who merely point out that a bunch of buffoons not only ruin Ubuntu but also every future distro based on Ubuntu
Generation Chaff - Phase VIII: In Summary
Like "Science" with a capital "S", what we see here commercial interests usurping everything
Generation Chaff - Phase VII: Curtailing Alternative Media
There was always an obligation - a collective duty of sorts - to uphold independent journalism
Generation Chaff - Phase VI: Centralisation of Information (X, Cheetok/Fentanylware)
Would you trust information when controlled by such people?
Generation Chaff - Phase III: Slop and Plagiarism
A lot of the current so-called 'economy' is built upon false valuations
Generation Chaff - Phase II: "Cloud", Blockchains and Other Hype
For those of us who turned down those propositions there was a struggle; we needed to justify not having skinnerboxes or "social" accounts in some site run by a private company
Generation Chaff - Phase I: Social Control Media
IRC predates the Web
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 23, 2025
IRC logs for Thursday, October 23, 2025
More Clues Shed on Collapse of Microsoft XBox
XBox is basically circling down the drain as Microsoft implements 2-3 waves of layoffs each month
'Vibe Coding' Doesn't Work
In a lot of ways, so-called 'Vibe Coding' is already considered vapourware or a passing fad promoted in the media by managers who try to justify mass layoffs, especially ridding companies of "very expensive" software engineers
Links 24/10/2025: Microsoft's Killing of XBox Connected to Revenue/Profit Problems, "How Elon Musk Ruined Twitter"
Links for the day
Gemini Links 24/10/2025: 86,400 Seconds and "Society's Task"
Links for the day
Slopwatch: Google News and Slopfarms That Relay Nonsense From LLMs
Google News, which once prioritised or used to care about provenance and quality, is feeding slopfarms
Links 23/10/2025: More Health Concerns Over Dumb Chatbots (LLMs) and "Talking Cars" as Latest Buzz
Links for the day
Gemini Links 23/10/2025: Daylight Savings Time and Duration Shorthand
Links for the day
Links 23/10/2025: LLM 'Hallucinations' (Defects) in Practical Code 'Generation', China Becomes More Economically and Technologically Independent
Links for the day
Why We Support Richard Stallman and You Probably Should Too
It's not about being "Richard Stallman fan", it is about maintaining the right to hold positions (on technology) like his
Linux Foundation Uses LLM Slop to Promote Microsoft in Linux.com (Again), Rendering It a Linux-Hostile Slopfarm
Openwashing with slop by "Linux.com Editorial Staff", which basically seems to be a bot
Some Large German Media Covers Richard Stallman's Talks in Germany Earlier This Week
LLM-based chatbots are just "bullshit generators" (as he has long called them)
Links 23/10/2025: Windows TCO Galore and "The Internet Is Going to Break Again"
Links for the day
Trouble in Red Hat/IBM and a Retreat to Ponzi Economics in Search of Wall Street Market Heist
Would you invest your life savings in this kind of crap?
Who Asked Software in the Public Interest (SPI) for a Refund? ($100,000, Resulting in Losses of $267,201 in 12 Months, Highest-Ever Losses)
The IRS does not reveal who or what's tied to this refund (or the cause/reason)
Social engineering attack: Debian voted to trick you on binary blobs
Reprinted with permission from Daniel Pocock
Techrights Will Always Stand for Women's Rights
We even invest money - personal savings that it - in our principles
Certified Lawyers Should Know Better (Than to Intimidate Us With Man Who Drives on Motorcycle Through a Really Bad Storm Between Distant Cities, Then Collects Photos of Our Home)
Mentioning someone was in prison for bad things isn't a crime, it's a public service
The "AI" (Slop) Bubble is Already Imploding
"ChatGPT Usage Has Peaked and Is Now Declining, New Data Finds"
The So-called "Sexy" Buckets (AI, Quantum) Cannot Save IBM From Reality, Shares Tank
"No matter how much financial hocus-pocus they use to reclassify revenues to land in the "sexy" buckets (AI, Quantum), it still smells old and musty - just like this company."
Paul Krugman is Wrong About the Scope of Mass Layoffs in the United States
A few years ago society was accelerating its journey towards feudalism, boosted by COVID-19
Links 23/10/2025: Proprietary Blunders and CISA's Latest Disclosure of Holes
Links for the day
Gemini Links 23/10/2025: Fast Past (F1), 99.9% Uptime
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, October 22, 2025
IRC logs for Wednesday, October 22, 2025
Slopwatch: Google News is Promoting Fake 'Articles' About Fake Xubuntu, Fake Articles About Replacing Windows With GNU/Linux
The quality of the Web deteriorates and unless someone cleans up the mess, real sites will lose an incentive to produce anything
When "AI Layoffs" Mean Layoffs Due to the "AI" Bubble Popping
many people that are laid off by Microsoft claim to be specialists in "AI"
Mysterious grant forfeited, $100,000 from Software in the Public Interest accounts 2023
Reprinted with permission from Daniel Pocock
Evidence: bullying, student union behaviour: Armijn Hemel's FSFE resignation
Reprinted with permission from Daniel Pocock
Evidence: psychological abuse, stalking, Galia Mancheva, Susanne Eiswirt ignored by FSFE judgment for Matthias Kirschner
Reprinted with permission from Daniel Pocock
Helping FSFE scam victims and conference organisers
Reprinted with permission from Daniel Pocock
Nigerian fraud in FSFE constitution
Reprinted with permission from Daniel Pocock
Worrying and Amusing Stories of "Clown Computing" Gone Awry
Many of these disasters could be avoided
Links 22/10/2025: Amazon Plans to Replace Workers With Robotics, AWS and Clown Computing in General Ridiculed
Links for the day
Gemini Links 22/10/2025: Niri Completely Changes Multitasking and Overview of Diff-ers
Links for the day
Links 22/10/2025: Study on Misinformation by Slop and Heavily Debt-Sabbled Microsoft OpenAI (ClosedSlop) Uses "Browser" as Gimmick/Distraction
Links for the day
They've Already Spent Close to a Million Dollars on Lawyers and Sent Us About 50 KG of Legal Papers (Sponsored by Mysterious Third Party) to Try to Censor Techrights, Without Success
They try to overcompensate with sheer volume for a lack of solid, clear arguments (we are the victims here)
12 Months Ago the 'Hulk Hogan of UEFI' Officially Went 'Tag-Team'
We're actually sort of flattered or proud that such despicable people are so desperate to censor us
"Cloud Computing" Was Always a Joke, But This Week Was the Punchline
Maybe stop following tech trends and fashions
"Cloud Computing" Does Not Mean Safety
Fault tolerance is related to the notion of software freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 21, 2025
IRC logs for Tuesday, October 21, 2025
The Fall of Windows: From Something to Nothing
Of course Microsoft will pretend everything is fine and "just trust the hey hi" (AI)