Bonum Certa Men Certa

Links 31/7/2015: Lennart Poettering as 'Linux Hero' and systemd Conference Coming





GNOME bluefish

Contents





GNU/Linux



Free Software/Open Source



  • Accuvant researchers to release open source RFID access tool
    Security researchers have long known about the vulnerabilities of the RFID readers that many buildings use instead of door locks, but facilities managers have been slow to upgrade to more secure systems.

    To draw attention to the problem, at next week's Black Hat conference, Accuvant researchers will be releasing an open source piece of hardware that can be used to circumvent these readers.


  • VA Secretary: Open source is the only way to operate
    Veterans Affairs Department Secretary Bob McDonald voiced his support for open source technology July 30, as he outlined a broad reform plan that includes streamlining information technology and taking a more "holistic" look at customer service.

    "We have over 200 databases with customer information. That means if you want to change your address, you have to go to at least nine places to change your address at VA," said McDonald during a morning keynote July 30 at a conference in Bethesda, Md.


  • OpenDaylight Project Picks Up Steam


  • Kim Dotcom to create Wikimedia-style open source Mega 3.0
    Dotcom's first file locker, Megaupload, saw him accused of knowingly hosting, and indeed encouraging the upload and distribution of, stolen films and music. From his new home in New Zealand, he's fought a long legal battle on numerous fronts, fending off extradition attempts, accusing kiwi authorities of working without warrants end even trying, and failing miserably, to promote a political part .


  • Databases



  • Oracle/Java/LibreOffice



  • CMS



    • Dummy projects for new Drupal hires
      Lakhani's current role involves promoting the use of applications like Drupal, WordPress, Magento, and Redline through free tools and services. But, this Denver-based executive's experience shows most in forming the global, distributed team of developers and support staff inherent to success.




  • BSD



    • from distribution to project
      OpenBSD is going through something of a minimalist phase right now, but that wasn’t always the case. There was definitely an era of aggressive importation as well. Times change, priorities change, projects change. I wasn’t involved with OpenBSD during the early years, but I think I can explain the shift in attitudes. This is part three of an apparently ongoing series that started with Pruning and Polishing and out with the old, in with the less.


    • sashan@ on SMP pf progress
      One of our new developers, Alexandr Nedvedicky (sashan@), writes in to tell us about his trip to the lovely locale of Calgary for c2k15.




  • Public Services/Government



    • Open source part of Bulgarian eGovernment tender requirements
      The Bulgarian government has added open source as a requirement to its 'Preliminary criteria for the eligibility of eGovernment projects'.


    • IT trade groups protest Slovak licence deal
      Two IT trade associations in the Slovak Republic are objecting the renewal of a proprietary software licence contract negotiated by the country’s Ministry of Finance for all government organisations. Instead of continuing to rely on proprietary office suites, the groups want the Slovakian government to explore a transition to open source alternatives.




  • Standards/Consortia



    • WEBINAR - A standard that is not managed is not a standard
      Through their brief webinar Marijke and Marco will share with the audience how the Dutch Government is promoting the adoption of open standards through BOMOS, a method (initiated by Dr. Erwin Folmer, TNO with contribution from Marijke) which describes how to maintain and manage open standards.






Leftovers



  • Security



    • Tuesday's security updates


    • Security updates for Wednesday


    • Security updates for Thursday


    • Remote code execution via serialized data
      Serialization and, more importantly, deserialization of data is unsafe due to the simple fact that the data being processed is trusted implicitly as being “correct.” So if you’re taking data such as program variables from a non trusted source you’re making it possible for an attacker to control program flow. Additionally many programming languages now support serialization of not just data (e.g. strings, arrays, etc.) but also of code objects. For example with Python pickle() you can actually serialize user defined classes, you can take a section of code, ship it to a remote system, and it is executed there.


    • To exec or transition that is the question...


    • CIL – Part1: Faster SELinux policy (re)build


    • FCC Rules Block use of Open Source
      The United States Federal Communications Commission (FCC) has introduced ‘software security requirements’ obliging WiFi device manufacturers to “ensure that only properly authenticated software is loaded and operating the device”. The document specifically calls out the DD-WRT open source router project, but clearly also applies to other popular distributions such as OpenWRT. This could become an early battle in ‘The war on general purpose computing’ as many smartphones and Internet of Things devices contain WiFi router capabilities that would be covered by the same rules.


    • Hacked Jeep Cherokee Exposes Weak Underbelly of High-Tech Cars
      The Jeep Cherokee brought to a halt by hackers last week exposed wireless networks as the weakest link in high-tech vehicles, underscoring the need to find fast over-the-air fixes to block malicious intrusions.

      Features that buyers now expect in most modern automobiles, such as driving directions and restaurant guides, count on a constant connection to a telecommunications network. But that link also makes cars vulnerable to security invasions like those that threaten computers in homes and businesses.




  • Censorship



    • David Cameron wants to block non-age verifiying porn sites
      PRIME MINISTER David Cameron is looking to ensure that adult websites, the sort that MPs like, will abide by age verification standards and make sure that fumbling punters are of adult age.

      Cameron has a thing about these sites, as does a huge chunk of Westminster, and would like to see adult content subjected to bondage and inspection. He would like to give it a firm political going over and a good legislative seeing to. He wants to take it in hand.




  • Civil Rights



  • Internet/Net Neutrality



    • FCC has already gotten 2,000 “net neutrality” complaints
      The Federal Communications Commission received about 2,000 net neutrality complaints from consumers over a one-month period, according to a National Journal article today. The overarching theme of the complaints is that customers are fed up with their Internet service providers, often due to slow speeds, high prices, and data caps. In a sampling of 60 complaints, the most frequent targets were AT&T, Comcast, and Verizon.






Recent Techrights' Posts

"Bad Shim Signature"; So 'Secure' That It Overrides Users' Preferences and Turns Itself Back on (Coercive Measure)
This was a few hours ago
We Covered UEFI 'Secure Boot' Scandals. The World Listened.
To hell with UEFI 'secure boot'
Fake News With Fake Numbers About Microsoft
"This is what happens when the world's economy is governed by sick old men"
Slopwatch: "Google News" is Fast Becoming a Mashup of Slopfarms, Linux Journal ("LJ") is a Dump of LLM Slop
Well done, Google News. Google itself can flourish as a slopfarm mashup.
Torturing Users Who Just Want to Run GNU/Linux on Their Own PC
"Linux does not want to install"
European Authorities, Already Bribed and Infiltrated by Microsoft, Won't Help You Find BigBlueButton, Jami, Ring, and Jitsi
Because they're paid by Microsoft and are Microsoft 'addicts' themselves
Moving From Content Management Systems (CMSs) to Static Site Generators (SSGs) Saves You Time, Makes You a Lot More Productive
try to reduce the cost (financial and computational) of running your site
Leak: European Patent Office (EPO) is Now Attacking Amicale Clubs
corruption has become the norm and scientists are robbed of any dignity
Oracle Fraud (or Defrauding Shareholders)
"the obvious [lie] is that watts are (wasted) electricity [and] and FLOPS are computing capacity"
 
20 Years Later and Academia Isn't the Same
"I never dreamed of being a professor"
'Cancel Culture' by the Right: Microsoft Lunduke Contacts People's Employers Trying to Get Them Fired
Microsoft Lunduke panders to extremists online
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 13, 2025
IRC logs for Saturday, September 13, 2025
Microsoft is Rapidly Dropped From Web Servers, Shows Survey
Microsoft lost about 8% "market share" in just 3 months
Many GNU/Linux Users Report MOK (Machine Owner Key) Issues in Recent Days
many people don't report this online and never post in Reddit
Links 13/09/2025: Escalations in East Europe and POTUS’ Health Cover-Up
Links for the day
Gemini Links 13/09/2025: Lagrange Turns 5 and Lagrange 1.19.2 Released
Links for the day
Microsoft Inside Your Linux: "Security vulnerability that allowed an attacker to bypass UEFI Secure Boot."
2 hours ago
A New Low for "Linux Journal": Promoting MICROSOFT WINDOWS Using LLM Slop
They've just jumped the shark entirely
The Register MS Still Takes Money to Hype Up "AI" in Articles by Microsoft Resellers With the Term "AI" 30+ Times in Them
Notice how many times they mention "AI"
The Apache Logo News is VERY Old, Racists and 'Anti-Woke' Bigots Look for Something to Incite Other Bigots With
Nothing to see here, move along
Linux Mint 9/11: "4th One Today..." (in Reddit)
Remember that not everyone having an issue reports it to social control media like Reddit
Nepal Will Fall Without a Single Shot Fired, Thanks to Social Control Media
Or very few shots (by the authorities)
European Corruption in the European Patent Office (EPO) Targets Culture
"In reality, the project includes a new “legal instrument” shifting administrative burden and liability on EPO staff while creating new uncertainty and externalising Amicale activities."
UEFI Secure Boot Failing, as Expected for Nearly 15 Years Already (Techrights Said This Since 2012)
in the media
Debian 9/11
people report this issue
Gemini and Web Links 13/09/2025: MElon's Slop Grift and "Autonomous Trains"
Links for the day
Pursuing Peace Through Violence
You cannot "see" a person's mind, until the mouth opens
Can We Please Stop Celebrating Shooters?
"An important point to hammer on is that CoCs were never intended for uniform or symmetric application"
Geminispace is Growing Faster in 2025 Than It Did in 2024
What matters is that corporations haven't ruined it and LLM slop is extremely rare
Links 13/09/2025: China Punishes for 'Negative' Posts, US Police Unable to Find Shooter
Links for the day
Who's the Mystery Financier of SLAPP Against Techrights and Is That a Millionaire/Billionaire?
Whose idea was it to fund meritless lawsuits against my wife and I?
Slopwatch: Slow Slop Day
This distracts from or may take traffic away from the original articles, actually written by actual people
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 12, 2025
IRC logs for Friday, September 12, 2025
CoC Gone Wrong: Celebrating Murder OK, Complaining About the Celebration Gets You Banned
Hopefully the NixOS Foundation will have a word with (maybe replace) the moderator/s
Gemini Links 12/09/2025: Familiarity and Secondary Dominants
Links for the day
Explaining (in Length and Depth) the Damage Matthew Garrett Did to Linux and to GNU/Linux Users
no matter how many threats we receive
Links 12/09/2025: "Bad Reviews" as Extortion Weapon, "Free Speech At Risk in America’s Schools" According to ACLU
Links for the day
Only One Speaker Does Not Do Sharecropping for MElon (in X.com)
The man who puts principles before PR/optics
The Mind of the 'Hulk Hogan of UEFI'
in a nutshell
A Day After "UEFI 9/11": UEFI Secure Boot Bypass
In the news today (right now), as published in the past few hours
Links 12/09/2025: Slop Code as Liability, Microsoft Outlook Down for Many
Links for the day
It's Still Not to Late to Turn Off "Secure Boot"
If people reboot their PC or server today, and it relies on "Secure Boot" on Sept. 12 or later, then depending on the firmware there may be trouble ahead
Links 12/09/2025: Shira Perlmutter is Back, “Software Per Se” Patent Rejections in In re McFadden
Links for the day
Slopwatch: Linux Plagiarism, Slopfarms Still Infesting Google News, Many Images Are Fake
Google is promoting plagiarism
"This Morning Might Turn Out to be an Interesting One for System Admins Who Haven't Updated Their Devices' Secure Boot Certificate" (If They Reboot)
Who asked for this anyway?
Gemini Links 12/09/2025: Metric System, Dumping Windows, and Software Architecture is Dead
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 11, 2025
IRC logs for Thursday, September 11, 2025