Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LWN.net


  • Mourning Steve French
    From Jeremy Allison we have thesad news of the passing of Steve French. He was the maintainer of thekernel's SMB filesystem code for many years, having only dropped thatrole due to health issues in the last week. "I've known Steve forover 20 years. He was a legend in the community, and a really goodfriend. He will be greatly missed. Farewell Steve." He will indeed be missed.


  • [$] Considering the OpenMDW license
    The open-source world has been struggling for a few years now to understandhow to approach large language models (LLMs) and the licensing applied tothem. What constitutes "freedom" with respect to a black box filled withnumerical weights? The process taken by the Open Source Initiative (OSI)in the development of its Open Source AIDefinition was controversial at best, as was its output. Now, theLinux Foundation's Mike Dolan has broughta new license to the OSI for approval. It is called the OpenMDW ("OpenModel, Data, and Weights"), and it aims to clarify licensing for thedistribution of LLMs and related materials, but consensus is proving hardto find for this license as well.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (ansible-core and pcp), Debian (chromium, libgit2, python-httplib2, and sabnzbdplus), Fedora (dokuwiki, domoticz, dotnet10.0, dotnet8.0, dotnet9.0, firefox, i2c-display, libgit2, lyx, ntpsec, openssh, perl-DBI, php-phpseclib3, python-alembic, python-asyncmy, python-sqlalchemy, python3.13, roundcubemail, trafficserver, wireshark, and wordpress), Red Hat (compat-openssl10, compat-openssl11, fence-agents, gnutls, kernel, kernel-rt, libarchive, libreswan, multiple packages, openssl, python-idna, python-pillow, qemu-kvm, resource-agents, rh-podman-desktop, ruby, unbound, and vim), SUSE (buildah, chromium, container-suseconnect, containerd, cosign, ctop, docker, firefox, forgejo-cli, gitea-tea, go1.25, go1.26, helm, kubernetes, kubernetes-old, kubevirt1.8, podman, python-pytest-html, python-unearth, python311, python313, rootlesskit, and rsync), and Ubuntu (linux, linux-aws, linux-aws-5.4, linux-azure, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-oracle, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-7.0, linux-ibm, linux-oem-7.0, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure-fips, linux-gkeop, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle, linux-oracle-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-aws-6.8, linux-azure-5.15, linux-gcp, linux-gcp-fips, linux-hwe-5.15, linux-lowlatency-hwe-5.15, linux-gcp, linux-gcp-4.15, linux-gcp-fips, linux-gcp, linux-gke, linux-gke, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-hwe-6.8, linux-nvidia, linux-nvidia-7.0, linux-nvidia-bos, linux-raspi, linux-raspi-realtime, netty, postgresql-14, postgresql-16, postgresql-18, vim, and wget).


  • [$] A look at the Quickshell desktop-component toolkit
    Quickshell is a toolkit forbuilding desktop components, such as toolbars or menus. It uses QML, which is a declarative languagefor designing GUI applications. Quickshell helps developers create graphical toolsfor common desktop use cases with a focus on ease of development. It offers aconvenient method for writing user interfaces and has been adopted by a numberof projects, such as caelestia-shell and DankMaterialShell, thatprovide desktop environments for minimal window managers like Sway and niri.


  • KDE Gear 26.08 released
    Version 26.08 ofthe KDE Gearcollection of applications has been released. Notable changes in this releaseinclude improvements in the signingfeatures of Okular, improved file-groupingfeatures in the Dolphin filemanager, and a number of enhancements to the Kdenlive video editor. See the changelog fora full list of updates, enhancements, and bug fixes.


  • Supply chain attack on arrayref (Rust blog)
    The Rust blog reportson a malicious crate, called proc-macro1, that was uploaded to thecrates.io repository.
    Furthermore, we discovered that the popular arrayref crate had recently been republished and made to depend on this crate, with the most recent versions yanked. We have removed the malicious version and unyanked the maliciously-yanked versions. Other crates by that author (internment, append-only-vec) were also affected so we have done the same for those, and locked the account as a precaution. We do not believe the author of arrayref to be acting maliciously, but their computer or credentials are likely compromised, and we are attempting to contact them.


  • RPM 6.1.0 released
    Version 6.1.0 of the RPM Package Manager has been released. Notablechanges include the ability to provide modifiers to RPM macros at definitiontime, improved build and verification error handling, support for signing fileswith PKCS11 tokens using rpmsign, as well asthe addition of several new man pages. The 6.1.0 release also debuts a new release modelinspired by the Linux kernel's.



  • [$] The beginning of the 7.3 merge window
    As of this writing, 2,346 non-merge changesets have been pulled into themainline repository for the 7.3 kernel release. That, clearly, is a meredown payment on the flood that is to come. Even so, those early pullsbrought in some noteworthy changes, including (but not limited to) asignificant reworking of how group scheduling works on multiprocessorsystems.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (bind9.18, glib2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, kernel-rt, libcupsfilters, mysql8.4, mysql:8.4, pcp, perl-Date-Manip, php8.4, php:7.4, php:8.2, php:8.3, python3, and yggdrasil), Debian (designate, firefox-esr, and swift), Gentoo (acl, attr, Emacs, libssh2, and quickjs-ng), Oracle (.NET 10.0, .NET 9.0, attr, bind9.18, curl, glib2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, kernel, libXfont2, mysql8.4, nghttp2, nodejs:22, nodejs:24, pam, pcp, perl-Date-Manip, php8.4, python3, sg3_utils, and yggdrasil), Slackware (mozilla-firefox and mozilla-thunderbird), SUSE (open-iscsi, podman, python311, and python313), and Ubuntu (bind9, capnproto, curl, libheif, libpng, libpng1.6, libssh, nginx, and tiff).



  • Go 1.27 released
    Go 1.27, the most recent version ofthe Go programming language, has been releasedwith a number of new tools, the addition of support for the ML-DSA post-quantum algorithm,new JSON-processing packages, language updates, and more.




  • [$] Debian weighs eight options in vote on LLM usage
    The Debian Project is voting on the usageof large language models (LLMs) to make contributions to the project. The firstproposal, sent in late July by Matthias Geiger, would expressly forbid anycontributions to Debian that are created by or with the assistance of LLMs. Thatkicked off a firestorm of discussion and a flood of alternate proposals. Debiandevelopers are now voting oneight proposals in total that range from banning LLM-assisted contributionsto explicitly approving them, as well as the standard "none of the above" optionthat would leave Debian with no agreed policy.


  • Tuba 0.11 released
    Version0.11 of the Tubafediverse client has been released. Notable changes in this release includesupport for Mastodon collectionsand quotes,ability to create custom thumbnails for attachments, a new emoji picker, a buildfor Android, as well as many other enhancements.



LXer Linux News

  • Fedora Badges Revamp Project: From The Ground Up
    After years of technical research and foundational work, the Fedora Badges application service has been rebuilt from the ground up, and it is heading to production. Whether you have been collecting badges for years or you are brand new to the Fedora Project community, here is what is waiting for you there. Completely modernized user interface The archaic server rendered pages are now gone. The Fedora Badges application service […]



  • Longtime Linux CIFS/SMB3 Maintainer Steps Down
    There is a changing of the guard with Linux 7.3 as the maintainer of the Common Internet File System (CIFS) / SMB3 code within the Linux kernel. Longtime maintainer, principal Linux CIFS author, and current Microsoft employee Steve French has stepped down due to health reasons...





  • Linux 7.3 x86/mm Lands Patches To Greatly Improve Latency-Sensitive Workloads
    The highlight of this week's x86/mm pull request of changes for the Linux 7.3 kernel are fixes that reduce the time that the TLB flushing code has interrupts disabled. This helps significantly with latency-sensitive workloads but Intel engineer Dave Hansen noted in the pull request that "it's certainly something to keep an eye on" in looking out for any regressions...


  • K230 handheld couples AMOLED display with LoRa and keyboard
    LILYGO has updated its T-Display K230 handheld, packaging its Kendryte K230-based development platform into a compact enclosure with a physical keyboard. The device combines dual-core 64-bit RISC-V processing with a 4.1-inch AMOLED touchscreen, LoRa, Wi-Fi, Ethernet, camera support, HDMI output, and an nRF52840 companion microcontroller. The T-Display K230 is based on the Kendryte K230 SoC, […]




  • Framework Laptop 16 With GeForce RTX 5070 12GB, One-Piece Keyboard & Haptic Touchpad
    While the past few weeks have been quite busy with the new Framework Laptop 13 Pro testing with that all-new laptop model and paired with Intel's Core Ultra Series 3 "Panther Lake", at the same time Framework Computer has begun shipping some updated components for the Framework Laptop 16 laptop. If looking for a bit more GPU compute power hor larger form factor than the 13-inch model, the Framework Laptop 16 can now be equipped with the NVIDIA GeForce RTX 5070 GPU as well as a haptic touchpad and one-piece keyboard for improving the input experience.




  • EPIC SBC packs Ryzen AI X100 with dual 2.5GbE and triple M.2
    IEI has detailed the NANO-X100, a compact EPIC single-board computer based on AMD’s Ryzen AI Embedded X100 Series. The 115 × 165mm board integrates 64GB of LPDDR5X memory, dual 2.5GbE networking, three M.2 expansion slots, four USB 3.2 ports, HDMI and DisplayPort outputs, and multiple serial interfaces for embedded and industrial applications. The preliminary specifications […]



  • Linus Torvalds Endures A Debug Session From Hell, "Enormously Helped" By AI
    It's pretty rare to see Linus Torvalds author patches himself pertaining to the open-source Linux graphics drivers, but waking up this morning I was surprised to see he authored and committed an Intel Xe kernel graphics driver change himself. It ended up being after he encountered a "debug session from hell" but was ultimately helped by AI in fixing a bug that had been irking him...





  • ESP32-S3 handhelds with 3.97-inch e-paper and optional LoRa/NFC
    M5Stack’s new PaperMono and PaperMono-Lite are compact ESP32-S3-based e-paper development platforms built around a 3.97-inch grayscale touchscreen. Both models include Wi-Fi, microSD storage, an IMU, real-time clock, frontlight, microphone, buzzer, and an integrated 1150mAh battery, while the higher-end PaperMono adds LoRa and NFC connectivity. Both devices are based on the ESP32-S3R8, which integrates a dual-core […]


Linux Insider"LinuxInsider"












Slashdot

  • Slovakia Finds Russian Backdoor In Traffic Speed Cameras
    Slovakia acquired speed cameras to modernize its traffic control-- but there was a surprise. Tom's Hardware cites this story from the Risky Bulletin Newsletter:Unfortunately, the country's national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary... [The cameras] are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon... reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations... Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access... [T]he SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP. Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU's findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.


    Read more of this story at Slashdot.


  • Stanford Economist Now Believes an AI Job Apocalypse Is Unlikely
    "There is still no sign of economy-wide job destruction," says economist Erik Brynjolfsson. Working with researchers at the Stanford Digital Economy Lab, Brynjolfsson has determined an AI "job apocalypse" is unlikely, reports the Washington Post, "even though it will likely impact entry-level jobs." And Brynjolfsson "predicts that demand for experienced workers such as senior coders will still be high even if AI takes on more routine knowledge and coding work in the future."Earlier this month, Brynjolfsson and his colleagues at the Stanford Digital Economy Lab updated their widely publicized report, "Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence," to reflect that they do not see widespread, economy-wide job displacement associated with AI... Brynjolfsson: What has moved on the upside is productivity. Nonfarm business productivity growth is running over 2 percent, the best sustained stretch since the late-1990s boom... The gains show up years after the investment, and they're starting to show up... By 2030, we will have enormously more capable AI, meaningfully faster productivity growth and an unemployment rate that looks unremarkable — somewhere in its historical range. That surprises people, but it's what the mechanism implies... [T]he technology is becoming much more powerful, and it's going to be even more powerful. Secondly, there are huge implications for business and the economy, including some increases in living standards, but also, potentially, job disruption. And then, thirdly, we must act now to address this gap. We can't just sit back and wait for the tsunami to hit us. And one of the things we can do is put in place institutions, policies and research to make the technology more complementary — using AI to complement people so it creates more jobs. A common misconception among business managers is AI, in order to be effective, has to reduce jobs. That's just not true. You can use AI to increase employment and productivity at the same time. It's kind of a win-win... Right now, tax policy is very skewed toward favoring capital versus labor — and, as a consequence, a lot of entrepreneurs and managers, they're basically being guided by the federal government to replace workers with machines. And I don't think that's necessarily what we'd like to have happen. From an economist's perspective, what you want to be doing is not mimicking and replacing things. You want to be extending and complementing — have humans do new things they never could have done before. He acknowledges "real, persistent and widening" effects on entry-level jobs, with a labor market "closing the on-ramp for people starting their careers... If companies don't hire people at the base of the pyramid, then they're not going to have those people later when they need them." One he points out that one company is instead using AI to speed up its training of young employees.


    Read more of this story at Slashdot.


  • 23 Years After SimCity 4's Release, 'Eternal Commuter' Bug Finally Fixed
    "It began life just a year after SimCity 4's 2003 launch," writes the blog PCGamesN. "Now, over 20 years later, it's still going strong with the arrival of Network Addon Mod update 50."The SimCity 4 Network Addon Mod, or simply 'NAM' among the community, has long been a de facto recommendation to anyone looking to pick up the classic city builder. It's a comprehensive overhaul to the game's transportation and infrastructure networks that combines key fixes with a vast set of additional build pieces such as overpasses, intersections, on-ramps, roundabouts, and so on.... [Y]ou'll be able to place down elements adjacent to one another that might previously have needed a one-tile gap between them. Streets can be dragged diagonally, slope tolerances have been improved, and you can build tunnels with the street network. The new version also includes a fix for the 'Eternal Commuter Loop' bug, which might sound fairly innocuous if you're not deep in the weeds. In actuality, it's a 23-year-long frustration that has plagued modders ever since launch. Essentially, it's a problem with the regional pathfinding across city boundaries in certain layouts, causing your Sims to bounce from location to location in search of work without actually taking up a job in any of them. Your zone demand is ruined, traffic builds to unsustainable levels, and the economy falls to pieces before your very eyes. Until now, the only real solution was to simply avoid building layouts that gave your commuters the chance to loop between locations. Now, by blocking specific neighbor-to-neighbor routes while allowing the rest to run as normal, the problem has been resolved... Equally impressively, the mandatory implementation of the DLL has reduced the size of the NAM codebase "by almost 90% and by more than ten million lines, making it easier to maintain and reducing the chance of bugs." Thanks to long-time Slashdot reader Striek for sharing the news.


    Read more of this story at Slashdot.


  • Canonical is Funding a PhD to Automate C to Rust Translation
    An anonymous reader shared this report from the blog It's FOSS:Canonical has committed funding to a three-year PhD project focused on building a system that can automatically translate large C codebases into Rust. And they are not alone; UK Research and Innovation is matching their funding for the project, which is set to run through the University of Bristol's Programming Languages Research Group. The PhD is aiming to build an all-encompassing platform that can take a C repository running into hundreds of thousands of lines and translate it into Rust that's "safe, behaviourally correct and maintainable Rust." The work will be carried out by a student, Alex Wood, who will be supported by Professor Meng Wang leading the work, with Dr. Cristina David and Canonical's Jon Seager serving as co-supervisors.


    Read more of this story at Slashdot.


  • Supply Chain Issues Delaying US Grid Batteries' Installation
    Falling prices have made grid-scale storage batteries more attractive, reports Bloomberg. But after decades of stagnant investment, America's grids "are racing to make the upgrades needed to plug them in," with supplies straining for the necessary equipment.Demand for batteries has skyrocketed as electricity use across the U.S. swells, driven by data centers' booming energy needs and increasing electrification. It's also getting harder to get them connected to power grids... As those upgrades get delayed, storage projects are piling up in interconnection queues from coast to coast. For example, Consolidated Edison Inc., a major utility in New York state, says over the last two years the volume of battery storage projects waiting to be connected has grown by 300%... "The whole process of interconnecting these new power plants got really log-jammed and bottlenecked," said Joseph Rand, an energy policy researcher at the Lawrence Berkeley National Laboratory... Nationwide, some 750 gigawatts of energy storage projects — roughly equivalent to the generating capacity of more than 700 nuclear reactors — are in line to get grid connections, according to the lab's research. Not all of these projects will get built. Many developers already abandoned the queue because of delays. Still, the waiting time is increasing; the median was five years in 2025, up from a year and a half in 2015. The flood of battery projects is expected to continue. Wood Mackenzie, an energy consultancy, projects the U.S. energy storage market will quadruple in the next six years... [Shortages in key equipment] have driven up construction costs and time lines for grid upgrades, leaving utilities struggling to build fast enough. A drought of skilled workers is further slowing them down... In California, PG&E Corp., the state's largest utility, told regulators in January that a key driver of delays was long lead times for specialized equipment. Procuring certain breakers could take nearly four years, according to the utility, which reported a 300% increase in its interconnection workload compared to prior years. In Northern California, for example, holdups to circuit breaker upgrades to a substation in Solano County led to projected delays for two battery projects worth a combined 450 megawatts. Transmission line work in the Bay Area has put another 800 megawatts of energy storage at risk of delay, according to PG&E. Last year New York's Con Ed started requiring developers to help pay for upgrades if their projects will push power demand and strain infrastructure. But that also drew criticism:According to a survey conducted by the trade group New York Battery and Energy Storage Technology Consortium (NY-BEST), the new methodology raised costs by an average of $21 million per project, a 14-fold increase. At least 25 projects have been canceled as a result, according to the group. Battery advocates have appealed to state regulators to get Con Ed to abandon the new policy. Thanks to Slashdot reader Bruce66423 for sharing the news.


    Read more of this story at Slashdot.


  • Debian is Voting on Whether to Allow AI-Assisted Contributions
    Debian developers are voting on whether to ban AI-assisted contributions, reports the blog Linuxiac, with a ballot listing eight proposals and a "None of the above" option.The first one is still the original proposal to ban LLM-assisted contributions by changing the Debian Social Contract. This would stop generative AI from being used for direct Debian work like packaging, software, documentation, translations, websites, and project communication. However, upstream projects made with AI help would not be affected. The proposal gives several reasons for the ban, such as unclear copyright and licensing, doubts about the reliability of AI-generated work, extra review work for maintainers, aggressive scraping of Free Software resources, and the high resource use of large AI systems... The second option would clearly allow contributions that are partly or fully made by an LLM, as long as contributors check their technical quality, security, licensing, and usefulness, fully understand the changes, and disclose major AI help. It would also ban sending private or sensitive Debian information to untrusted external AI services. A similar fourth option recognizes worries about generative AI but says banning it would be hard to enforce and not helpful. This proposal would accept AI-assisted Debian work if it follows the Debian Free Software Guidelines, is properly reviewed and understood by the contributor, and is marked as AI-assisted when needed. The fifth proposal is even more open. It says Debian should not support or ban generative AI tools, but should apply the same standards for quality, correctness, maintainability, and legality to all contributions, no matter how they were made... One unique proposal is called "Debian is created by humans." Instead of banning AI tools for contributors, it focuses on what actually gets included in Debian. With this approach, contributors could use generative AI for research, analysis, exploration, or critique, but could not submit AI-generated output directly as Debian packaging, patches, documentation, bug reports, project communications, or other Debian work. As the proposal says: humans create Debian. Another, much stricter proposal asks Debian contributors to avoid LLM use as much as possible. It would require all Debian communication, like bug reports, mailing-list messages, Salsa discussions, and Planet Debian posts, to be written only by humans. Any AI use in Debian work would have to be disclosed, and violations could be handled under the project's Code of Conduct. The CEO/founder of AI-native compliance management platform company Strike Graph believes a Debian AI ban is "the wrong fix for the actual problem" at hand, reports The New Stack:"Debian's ban isn't really about banning AI," [CEO Justin] Beals says. "It's an admission that nobody has built a reliable way to verify what an AI agent actually produced before it lands in a codebase this many systems depend on, including infrastructure running in orbit. That's a legitimate thing to be worried about...." He thinks that any policy statement that says AI isn't allowed simply won't hold up, as the tooling keeps getting harder to detect... Looking across the complete set of tabled propositions, proposal A (no LLM contributions to Debian via social contract) needs a 3:1 majority to pass; the other seven proposals (B to H) need a simple majority.


    Read more of this story at Slashdot.


  • Defamation Suit Demanding Elsevier Retract Paper Heads Closer To Trial
    Retraction Watch reports:A trial date has been set in a $1 billion defamation case against Elsevier that alleges the company published what plaintiffs say was a manipulated study about an air purifying technology over objections from peer reviewers. The case has already cost Elsevier a $10,000 sanction from a judge. Global Plasma Solutions (GPS), which makes air quality products, sued Elsevier in 2022 after the publisher declined to retract a 2021 paper in Building and Environment about GPS' needlepoint bipolar ionization technology, which it heavily marketed during the COVID-19 pandemic as an air purifier. The complaint claims Elsevier is responsible for the authors' alleged omission of data and misleading conclusions in the paper that fueled "massive" financial losses for the company, its lawyers claim. Elsevier knew the paper "failed peer review" under its "own standards," but moved forward with the article despite this knowledge, according to GPS, which now goes by GPS Air. The complaint has survived a bid by Elsevier to dismiss the case, and a trial has been set for Dec. 7. In allowing the case to proceed, U.S. Magistrate Judge David Keesler said in a May 2024 opinion that GPS has "plausibly alleged actual malice" by Elsevier defined as "knowledge of falsity or reckless disregard for the truth." Chief Judge Martin Reidinger of the U.S. District Court for the Western District of North Carolina upheld Keesler's recommendation in July 2025... Citing internal and discovery documents, GPS alleges an assessment of 19 journals revealed Elsevier has published more than 1,200 articles either without any peer review, or against the recommendations of the reviewers. Thanks to long-time Slashdot reader sandbagger for sharing the article.


    Read more of this story at Slashdot.


  • Microsoft Blames Windows Gaming Issues On RGB Lighting Devices
    BleepingComputer reports:Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. As Microsoft explained when it confirmed it's investigating on Wednesday, this known issue affects games like ARC Raiders, MARVEL Tokon: Fighting Souls, and The Finals on systems running Windows 11 24H2 and 25H2... "[Peripherals or internal device components with RGB lighting features] may install drivers or code components with file names similar to inpoutx64. In systems where these drivers are found, the issue is then triggered by launching certain games," it noted. Thanks to Slashdot reader joshuark for sharing the article.


    Read more of this story at Slashdot.


  • Battery Fires At Recycling Centres Are Costing the UK £1bn a Year
    Wrongly discarded lithium batteries, such as those in vapes, are causing more than 10 fires a week at U.K. recycling centers, according to figures shared with the Guardian:The Environment Services Association (ESA), the trade body for waste management companies, said its members had reported 1,518 fires in the year to March 2026. At least 541 of these fires were directly attributed to lithium ion batteries, the survey found. There were a further 216 battery fires in bin lorries [garbage trucks]. The ESA said the reported number of battery-related fires underestimated the scale of the problem, because in most incidents it was impossible to determine the cause of the blaze. A spokesperson said: "We know 40% of fires at recycling centres are caused by batteries, but we think the actual number is more like 70%." It estimates that annual cost of these fires has increased from £150m in 2021 to £1bn today...The ESA is calling for a £5 deposit scheme on the sale of all vapes to ensure that vape users have an incentive to return used devices to retailers for safe disposal... [Patrick Brighty, the head of recycling policy at the ESA, said] "Vapes are among the biggest culprits because they're cheap, abundant and typically have a short use-life." Thanks to long-time Slashdot reader AmiMoJo for sharing the news.


    Read more of this story at Slashdot.


  • How Will AI Change the Field of Mathematics?
    "AI went from being very terrible to seemingly genuinely quite good at a professional level in a very short space of time..." says the Verge's AI reporter.But AI systems "are still truly, truly terrible at some areas of math... even the days of the week."If you look at academic math papers, a lot of the time you won't see numbers... So they're still terrible, but they're now also very good at this other part. As to why, at some point you reach a critical mass of what these systems can do. We saw it with writing, we've seen it with programming. They're very good at forging connections between different areas, applying old methods in new ways, those kinds of things. It appears that the newer models they're training have apparently reached that level where it clicks, and now it can do math... There are areas now where it seems to be producing work that is on par with good mathematicians, alongside other parts where yeah, it can't count. All caught up in that is whether it's going to rewrite employment structures or funding structures... One would hope [math researchers] would branch out into all of these new exciting areas or pose new questions. But AI won't do that, and that's the concern. And then that would leave the field quite sterile, and it will have all of these things that have been done, and maybe nothing left to pursue... [A] lot are scared that it's closing off the field. So by definition, those breakthroughs that lead to something surprising and new that you can say, "Oh, this works here," may not be happening anymore... There were some bleak responses from graduate students I saw in essays posted online. Where's their place in this as future researchers? Do they have a place in this? Is it as glorified AI proof checkers? That will be quite an unsatisfying career, I imagine. Or maybe not, I don't know. We will see. I think anything used properly will be a net boon. They also had an interesting response when asked if AI democratizes access to high-level mathematical proofs:A lot of the mathematicians I spoke to were almost quite weary of this, actually. They love the idea, in theory, of democratizing access. They're also quite fed up with AI-generated or -assisted papers that are flooding every publication imaginable, as well as the pre-print servers that they use in these fields. Some of those I spoke to said things like, "Oh, I got three emails this week alone with people being like, 'Hey, is this legit?'" Because they thought they'd solved something with ChatGPT or with Claude, and they also don't have the mathematical skills to check whether they've actually solved something. On the flip side, there are parts where they said, "Well, we've got a talented undergrad who's done something that a talented undergrad would probably have never managed, and here they are doing grad-level work and they've produced a paper that is legit." And in the bigger scheme of things, a few I spoke to said, "Well yeah, a lot of these are in the ivory tower. Having access to this kind of thing globally could really boost access to the kind of things here." On the flip side, the cost. These things cost a lot to run.


    Read more of this story at Slashdot.


  • Rush Rescue Mission for NASA's $500M Space Telescope Fails
    Remember that rush rescue mission for NASA's $500M space telescope? It failed, reports CNN, and the LINK satellite won't be able to boost the telescope's orbit. NASA says its decades-old Swift telescope will now continue losing altitude, until it reaches Earth's atmosphere later this year and burns up. CNN reports:Just weeks after LINK lifted off on July 3, it started to spin out of control. [Satellite designer] Katalyst was able to regain control of the satellite, but the company acknowledged that the issue cost it time, which would delay LINK's rendezvous with Swift by about a month. However, that postponement — at least initially — did not seem to be a deterrent to the mission. Now, NASA and Katalyst have announced that LINK's mission will not capture and boost Swift to a higher orbit "due to ongoing attitude control issues," according to statements Wednesday. "NASA should be willing to move quickly and take smart risks when the potential return is worth it, and that is exactly what we did with this mission," NASA Administrator Jared Isaacman said in a statement. "This is not the outcome we were working toward, but it does not change why this mission was worth attempting. The team moved with extraordinary speed to give Swift a chance to carry out more science while advancing capabilities America will need for satellite servicing in the future...." The mission team is forging ahead with its plan for LINK to rendezvous with Swift — but as a demonstration rather than a rescue. "We are going to learn everything we can from LINK's rendezvous attempt and put those lessons to work on the missions that follow," Isaacman said... Swift wasn't designed to be serviced in space, which means that insights from the demonstration could be used for future missions... "We have already learned a tremendous amount," [said Ghonhee Lee, CEO of Katalyst Space Technologies], "and now our job is to turn those lessons into something durable — building a repeatable playbook to inform future rendezvous and proximity operations and satellite servicing."


    Read more of this story at Slashdot.


  • Flock is Secretly Building a Powerful New Prompt-Based AI Tool for Police
    Slashdot reader fjo3 shared this article from Wired:[Flock] has told the public for years that its technology "cannot recognize, identify, or track individuals." It has now built a system that does both, an artificial intelligence tool for police that can identify drivers and track vehicles by their patterns of movement alone, WIRED has learned... Because the system also reaches police case files, 911 dispatch logs, and commercial identity records, those plates can be turned into names, home addresses, and relatives. It can search for people in an area drawn on a map based on nothing more than a physical description... The code describes 45 tools at the AI's disposal, giving it access to plate scans and camera metadata, arrest records, case files, dispatch logs, ballistics results, and commercial databases that contain Social Security numbers, dates of birth, phone numbers, email addresses, relatives and associates. Flock says it is testing the product with a small group of law enforcement partners and describes it as still in development, with capabilities that may not reflect what it eventually sells. It arrives as the company faces bipartisan political pressure, a growing record of officers caught misusing its platform, and a wave of vandalism that has left cameras sawed off and lenses painted over in cities across the country... An officer no longer needs a plate, a name, or a crime to begin: They supply a place, a stretch of time, and a pattern of behavior, and the system is designed to hand back the people who fit... One prompt Flock preloaded into the system reads: "Find me witnesses based on vehicles most seen in [neighborhood] during [last 14 days] during [daily timeframe] *(will not include whitelisted vehicles)." An officer would fill in the blanks and submit it. The output is a list of plates, which other tools in the product then convert into names and home addresses. Another prompt instructs the system to list everyone arrested more than twice in two years for "any offense," exempting only narcotics arrests, and then says to map where those people live, retrieve the calls for service at their homes, and "do a workup on the top three individuals." The prompt begins with everyone in the area who has an arrest record and ends with dossiers on three of them, chosen by the software. A "workup," in Flock's terminology, is a one-command background check. It starts with a name and a date of birth and returns what the department's records and commercial data hold: vehicles, prior listings as a suspect, and, on a second screen, relatives, phone numbers, and online accounts. Wired shares this reaction from a law professor at George Washington University. "It is clear Flock has aspirations far beyond ALPRs to become a digital platform for policing,"


    Read more of this story at Slashdot.


  • Low Emission Zone Led To Better Lung Size, Function Among London Children
    Long-time Slashdot reader AmiMoJo shared this report from the Guardian:Children's lungs grew bigger and stronger after the most polluting vehicles were restricted from entering London, a study has found. Examinations of London schoolchildren before and after the introduction of the city's ultra-low emission zone found a restoration of lung capacity that had been stunted by exposure to pollution... "Traffic pollution in cities damages children's health and development," said Chris Griffiths, a professor of primary care at the University of Oxford and Queen Mary University of London, and the study's joint senior author. "We provide the strongest evidence yet on how these harms can be prevented. Ambitious clean-air zones should be considered a priority for cities globally with traffic-related air pollution." Air pollution from traffic has stunted the development of children's lungs in London for decades. Previous research found that by the age of eight or nine, children from the most polluted areas had 5-10% less lung capacity than their peers elsewhere. That impairment, which scientists said was the result of exposure to nitrogen dioxide, put them at increased risk as adults of developing respiratory diseases, such as asthma and chronic obstructive pulmonary disease, cardiovascular and metabolic disease, and premature death.


    Read more of this story at Slashdot.


  • Moderna-Merck Vaccine Cuts Recurrence And Spread of Melanoma, Raises New Treatment Hope
    Reuters reports "a major success in a new field of cancer treatment this week, as Moderna and Merck announced a personalized mRNA cancer vaccine "reduced the risk of recurrence and spread of melanoma in a late-stage trial". The vaccine was tested with Merck's widely used immunotherapy drug Keytruda:Thousands of patients who have undergone surgery to remove high-risk melanoma tumors could benefit as soon as next year if regulators approve the vaccine, Moderna President Stephen Hoge said in an interview. This is the first positive late-stage trial result for an mRNA cancer vaccine, which trains a patient's immune system to fight tumors by targeting specific mutations in those cells, and the first such study to show that adding a treatment to Keytruda worked better than that therapy alone... Interim results of the ongoing study, released on Wednesday, found the treatment, Intismeran, met both its primary target of reducing cancer recurrence and its secondary goal of preventing tumors from spreading to other parts of the body, compared with Keytruda alone. When the vaccine is injected into a patient, the patient's cells produce copies of mutations for the immune system to recognize and destroy... Merck said the companies are already in talks with regulators about the treatment. "Merck, Moderna and other companies are testing similar approaches against lung, breast and pancreatic cancers," the article points out. It adds that Karen Knudsen, CEO of the Parker Institute for Cancer Immunotherapy, "said the Moderna results could signal a new era for treating solid-tumor cancers." More from CNN:The trial result is "a monumental leap forward," validating mRNA technology as a cancer treatment, said Dr. Julie Gralow, chief medical officer of the American Society of Clinical Oncology... Roche and BioNTech, whose mRNA technology was used in the Pfizer COVID vaccines, are testing a similar treatment called autogene cevumeran in mid-stage studies in colon and pancreatic cancer patients who have undergone surgery. Results of the colon cancer trial are expected in 2027, with pancreatic trial results to follow in 2031. "We should be hearing results from multiple studies over the next few years and there's every reason to hope now, with this news, that many of them will be positive," said Dr. Robert Vonderheide, director of Penn Medicine's Abramson Cancer Center and president-elect of the American Association for Cancer Research.


    Read more of this story at Slashdot.


  • Is AI Really to Blame for High Unemployment Among Recent Graduates? What Economists Say
    47% of recent graduates say AI has already impacted hiring in their field, according to an April survey from ZipRecruiter. "But is AI really the problem, or is it more complicated?" asks NPR. "Here's what economists have to say."According to the Federal Reserve Bank of New York, the unemployment rate for recent graduates — which it defines as 22-to-27-year-olds with a new bachelor's degree or higher — was 5.7% as of June, more than the rate for all workers, which stands at 4.1%... Stanford University economist Erik Brynjolfsson says AI is impacting the labor market for entry-level roles. "AI is not the whole story, but it's part of the story and the evidence is building," he says. Using payroll data, Brynjolfsson and his co-authors found that since late 2022 — when large language models like ChatGPT started popping up — early-career workers ages 22 to 25 in AI-exposed roles, like software developers and marketing managers, have experienced a 16% relative employment decline. In comparison, employment rates for older workers in AI-exposed fields and for all workers in jobs that aren't easily automated — like home health aides, physical therapists and construction workers — remained stable or have grown over that same time period... [Though he also says often when companies pull back on hiring, they cut junior roles first.] Harvard University economist David Deming isn't convinced that AI is to blame for the challenging early-career job market. "If you look very carefully at the timing, it looks like the decline in junior hiring actually started a bit like six months before ChatGPT was released. And so what that tells me is it's something else," Deming says. "I think it's more like remote work." A recent analysis from the New York Fed found that companies are less likely to hire recent college grads into roles that can be done remotely. As remote jobs increased following the COVID-19 pandemic, so did unemployment among younger college grads, the New York Fed found. The analysis also found that AI didn't explain the rise in unemployment among younger workers and that remote work was more of a driving force... Employers hiring for remote jobs may be less likely to choose an entry-level candidate because it's harder to train them from afar... [And with remote positions, there's many more senior candidates to choose from.] And here's another thing to consider: University of Chicago economist Anders Humlum says if AI were replacing entry-level jobs, you'd expect to see companies that rely heavily on AI to hire fewer workers. But that's not what the data shows. Humlum points to a study done by the financial accounting firm Ramp and the workforce research company Revelio Labs. The study examined AI spending and employee head count across more than 21,000 U.S. firms, from early 2021 to early 2026. It found that at companies making the largest AI investments, entry-level head count grew by 12% over the two years following AI adoption.


    Read more of this story at Slashdot.


www.theregister.com - Articles




















































Linux.com



  • From DHCP to SZTP – The Trust Revolution
    By Juha Holkkola, FusionLayer Group The Dawn of Effortless Connectivity In the transformative years of the late 1990s, a quiet revolution took place, fundamentally altering how we connect to networks. The introduction of DHCP answered a crucial question, Where are you on the network?!, by automating IP address assignment. This innovation eradicated the manual configuration [0]

    The post From DHCP to SZTP – The Trust Revolution appeared first on Linux.com.









Phoronix




  • Linux 7.3 Introduces New AES Encryption APIs - Will Open Up More Performance
    Eric Biggers of Google continues carrying out great work on the Linux kernel crypto code. For Linux 7.3 he's landed work on new library APIs for most of the AES encryption modes used within the kernel. Moving forward this will open the door to more performance optimizations, reducing code duplication, and other enhancements...



  • Longtime Linux CIFS/SMB3 Maintainer Passes Away
    There is a changing of the guard with Linux 7.3 as the maintainer of the Common Internet File System (CIFS) / SMB3 code within the Linux kernel. Longtime maintainer, principal Linux CIFS author, and current Microsoft employee Steve French has stepped down due to health reasons...


  • eCryptfs Sees Fixes For Potential Malicious Intent, Some Dating Back To Its 2006 Debut
    The eCryptfs stacked cryptographic filesystem implementation for the Linux kernel to transparently encrypt files saw a number of bug fixes for the Linux 7.3 kernel. A number of these bug fixes deal with potential maliciously-crafted data and vulnerable going back to the 2006 introduction of eCryptfs as this option known for its use on Ubuntu home directory encryption and Chrome OS...



  • Apple HFS / HFS+ File-System Support Continues Seeing Fixes With Linux 7.3
    In early 2025 it was being discussed to potentially drop the HFS and HFS+ file-system support with the code having been orphaned over a decade and becoming a maintenance burden. But that dismal outlook quickly turned around with some developers stepping up to maintain the old Apple file-system support. Over a year later, fortunately, it's turned out to be a success story with more HFS/HFS+ file-system fixes continuing to work their way into the mainline Linux kernel...



  • AMD RDNA 4m Firmware Published For Linux Ahead Of Launch
    In addition to AMD's Friday afternoon big code drop of all the UALink enablement patches for the Linux kernel and the AMDGPU driver, there was another big drop from AMD to end out the week... Upstreamed to the linux-firmware.git repository is all the firmware binaries needed by the open-source driver stack for initializing their forthcoming RDNA 4m "GFX 11.7" graphics...





  • Open-Source Etnaviv Driver Now Able To Run YOLOX
    The open-source, reverse-engineered Etnaviv driver stack that began for providing accelerated graphics support on Vivante GPU IP and since expanded to handle Vivante NPUs as well is now able to handle YOLOX object detection...


  • Linux 7.3 x86/mm Lands Patches To Greatly Improve Latency-Sensitive Workloads
    The highlight of this week's x86/mm pull request of changes for the Linux 7.3 kernel are fixes that reduce the time that the TLB flushing code has interrupts disabled. This helps significantly with latency-sensitive workloads but Intel engineer Dave Hansen noted in the pull request that "it's certainly something to keep an eye on" in looking out for any regressions...





  • Proton 11.0-2 Enables More Titles With Steam Play / Linux Gaming
    Just in time for those that enjoy their Linux / Steam Play gaming on weekends, Valve and CodeWeavers today released Proton 11.0-2 as the newest stable release of this Wine 11.0 downstream that powers Steam Play for running Windows games gracefully on Linux...


  • AMD Posts Massive Patch Series For Enabling UALink In The Linux Kernel
    Whether coincidental or intentional, AMD engineers tend to drop interesting, feature patches for the open-source/Linux space on Friday afternoons. Hitting the kernel mailing list minutes ago were two patch series sent out by AMDGPU maintainer Alex Deucher for introducing UALink infrastructure...


  • Linux 7.3 Lands Improvements For Voodoo 3 / 4 / 5 & Vintage Atari Computers In 2026
    At a time when Linux continues dropping older hardware drivers due to the influx of AI/LLM-generated bug reports and patches for hardware extremely unlikely to be used with modern versions of the mainline Linux kernel, Voodoo graphics cards and vintage Atari computers are seeing some reprieve with the upcoming Linux 7.3 kernel release...


  • Framework Laptop 16 With GeForce RTX 5070 12GB, One-Piece Keyboard & Haptic Touchpad
    While the past few weeks have been quite busy with the new Framework Laptop 13 Pro testing with that all-new laptop model and paired with Intel9s Core Ultra Series 3 "Panther Lake", at the same time Framework Computer has begun shipping some updated components for the Framework Laptop 16 laptop. If looking for a bit more GPU compute power hor larger form factor than the 13-inch model, the Framework Laptop 16 can now be equipped with the NVIDIA GeForce RTX 5070 GPU as well as a haptic touchpad and one-piece keyboard for improving the input experience.


  • Nginx Dark Mode Support For Error Pages Remains Elusive
    In early 2025 I wrote about the upstream Nginx web server rejecting dark mode support for its error pages on the basis of wanting to keep the default error pages simple and developers arguing the extra HTML tag for the dark mode styling as superfluous. Following a lot of public backlash for being against offering native dark mode handling by default, Nginx stakeholders were polled and largely came out in favor of supporting the functionality but more than one year later it remains elusive from upstream Nginx...


  • Intel Computer Vision Sensing Driver Now Ready For Nova Lake
    The main set of media subsystem updates have been merged for the ongoing Linux 7.3 merge window. Notable this round is the Intel Computer Vision Sensing "CVS" driver merged the previous cycle now supporting next-gen Nova Lake platforms...





  • Linus Torvalds Endures A Debug Session From Hell, "Enormously Helped" By AI
    It's pretty rare to see Linus Torvalds author patches himself pertaining to the open-source Linux graphics drivers, but waking up this morning I was surprised to see he authored and committed an Intel Xe kernel graphics driver change himself. It ended up being after he encountered a "debug session from hell" but was ultimately helped by AI in fixing a bug that had been irking him...


  • Intel Mesa Linux Drivers Now Treating Nova Lake S / U / H / HX As Stable
    Intel's open-source Mesa drivers for Iris Gallium3D (OpenGL) and ANV (Vulkan) on Linux are no longer treating next-gen Nova Lake processors with integrated graphics as experimental and off-by-default. With today's Mesa 26.3-devel code, the Intel driver code across Nova Lake's S, U, H, and HX product families are considered stable and enabled by default...


  • Linux 7.3 Network Changes Merged But Developers "Completely Overwhelmed" Due To AI/LLMs
    All of the networking subsystem feature updates were merged today for the Linux 7.3 kernel's merge window. There are a lot of wired and wireless networking improvements this cycle but also a ton of bug fixes -- including many not so important fixes spun up by AI/LLM agents. The networking subsystem maintainers admit now they are "completely overwhelmed" due to this code churn from the output of AI large language models...


  • Intel Hyper Threading Performance On The Xeon 678X "Granite Rapids-WS"
    With the Intel Xeon 678X "Granite Rapids WS" processor that I have been recently testing within the HP Z4 G6i workstation, there are 48 cores plus with Hyper Threading is a total of 96 threads for this high-end workstation processor with a 300 Watt TDP. For those curious about the performance impact of HT/SMT on this Intel Xeon 600 series workstation processor, here are some comparison benchmarks.



Engadget"Engadget - Technology News & Expert Reviews"



  • Is a liquid-cooled PC worth it?
    Air cooling is reliable, while liquid cooling is visually slick. Which one you should use depends on how heavy you game on your system.



















OSnews

  • Windows news sites are reviewing context menus and its perversely delightful
    When I wrote about using Windows 11 for a month as part of the ongoing OSNews fundraiser (keep donating to get me to do the same for macOS!), one of the things I mentioned was that the modern desktop context menu has its own classic Win32 context menu!. This is, in fact, a long-standing complaint Ive repeatedly used as the perfect example of just how chaotic and low-quality Windows has become. Thankfully, and naturally I fully attribute this to my repeated complaints (*), Microsoft has been working on a brand new, faster, configurable context menu, and Neowin actually reviewed it. If you ask me, this revamped context menu addresses just about the biggest problem users had with the one in Windows 11, and that is the need to click through more buttons than necessary to do simple things like renaming a file or opening its properties. That problem is now basically gone. I have no issues with the new design. It looks modern, it feels more consistent with the rest of Windows, and even though all the new sections can still make it look a little busy, you now have the option to make it as simple or as button-packed as you want. That should cover most use cases and preferences well. I’d even say that when the new context menu becomes available to everyone, my guide on how to bring back the classic context menu might become obsolete. ↫ Ivan Jenic at Neowin The biggest reason Im linking to this is not because I care about whatever monster of a context menu Windows users are having to deal with. No, Im only linking to this because I never in my life imagined Id be linking to a review of a context menu. I mean, at least its not the chess application icon. That would be embarrassing. I get a perverse sense of joy out of this.


  • The road to MS-DOS 2
    A great and concise history of the run-up to MS-DOS 2.0. Yet, there was a nagging feeling that a single-tasking CP/M clone was inadequate for the new generation of personal computers. Digital Research released multi-user, multitasking MP/M-86 in September 1981 and announced the single‑user multitasking Concurrent CP/M in early 1982. In response, Microsoft came up with a plan for tiered approach to its operating systems: single-user/single-tasking MS-DOS at the bottom; multi-user/multitasking XENIX at the top; and in the middle, something called XEDOS: a single-user version of XENIX. This “pyramid of upward-compatible operating systems” was announced in a Byte Magazine editorial in January 1982. ↫ Nemanja Trifunovic Ive always found this tiered approach fascinating, and the world surely wouldve looked quite different had Microsoft been able to make it work. I doubt Windows NT would ever have existed, and most of the world would probably be running a XENIX-based Windows today (all else being equal, which is of course unlikely and silly). Regardless, MS-DOS 2.0 contained a few UNIX-like utilities to deal with its brand new support for directory trees and other new features, and even had a /dev directory.


  • PervertPods: Apple is adding cameras to AirPods
    If you thought pervert glasses werent bad enough, Apple is taking it up a notch by adding cameras to its AirPods. Apple is working on camera-equipped AirPods that appear to be nearly ready to launch, based on a video MacRumors found in the macOS Tahoe 26.7 release candidate. In a short demo, a man holds a book up so the camera in the AirPods can see the title. With Visual Intelligence, your world becomes savable. See something you like? Just ask me to save it for later,! says the voiceover text. ↫ Juli Clover at MacRumors AirPods are tiny. Ive seen people use them at the gym. Ive seen them on playgrounds. Ive seen them around swimming pools. People use them at the beach. Theyre used at schools. In locker rooms. Tiny cameras in tiny AirPods that can photograph anything in front of the user are a perverts wet dream. Abusers are going to love this. Why wear bulky glasses anyone can see and try to demand you take off, when you can wear tiny AirPods that have already been fully normalised in society? Was there not a single woman or parent on the team that made this? All over the United States, people are destroying Flock surveillance cameras. More and more communities are rising up and demanding these things removed from their streets and neighbourhoods. The awareness of just how pervasive mass government surveillance has become is growing, and Silicon Valleys complicity is not exactly a secret. And in this climate of rapidly growing concern and anger, Apple is going to add tiny cameras to its tiny AirPods. Was there not a single person of colour or protester on the team that made this? How detached from reality do you have to be to greenlight something like this? Does anyone  regardless of skin colour, gender, or political leaning  want even more cameras around them?


  • Quake shareware, a CD-ROM just a little too full
    I was around when Quake was launched, but I was entirely unaware of this story. By June 1996, after three years of hard work, id Software had completed their next title, Quake. As for their previous title, they were going to release both a shareware version and a full version of their game. Since it used a mere 22 MiB of storage, people at id Software had the idea of leveraging the remaining capacity of a CD-ROM. Why not include encrypted versions of the full id catalogue of games? Not only this would cut out the middlemen, it would give instant access to gamers with a simple phone call and a credit card. The concept was implemented. The CD was announced on July 3, 1996 and released on August 30th. The hacker group GNOMON released Quakecrk.zip only 39 days later. The archive contained QCRACK.EXE, a tool allowing to decrypt every single game on the CD-ROM. ↫ Fabien Sanglard The system id employed turned out to be incredibly primitive and simple, and hackers found out quite easily that the system required no secret sauce from id at all  the code youd get over the phone contained no secret, and all the validation program on the disk did was check to ensure the code received over the phone matched the code generated by the disk. No wonder it took them only 39 days to crack this.


  • Beyond the limits of physical VRAM
    Earlier this year, Natalie Vock made a splash with a set of patches to the Linux kernel that greatly increased performance on AMD GPUs with lower amounts of VRAM. With that work now accepted by upstream, Vock decided to turn their attention to another interesting problem: what if you run out of VRAM, and how can we improve performance when we do? Regardless, what I hope this blogpost can demonstrate is that even if you end up with some memory evicted to system RAM, the slowdown can be manageable. There’s measures that drivers (particularly, the kernel driver) can take to make overcommit work as fast as possible, and even applications can do their part in coordinating with the driver stack to mitigate the effects of their memory being evicted. With everything in place, VRAM overcommit isn’t really as big of a deal as one may think it is at first sight. ↫ Natalie Vock The work Vock has done has already been in SteamOS for a while, and theyre currently in the process of upstreaming it to the vanilla kernel as well. Since this is a complex set of patches and changes, this may take a while, and as such, theyve prepared custom kernel and Mesa branches for adventurous users. Do note that these branches wont be maintained much, and are entirely experimental, not as well-tested as the SteamOS kernel, and probably wont yield the same performance improvements. Still, this is the kind of work that has a material impact for users. Not everyone has a 16GB monster GPU, especially not today with supply chains ravaged and ruined by slopmakers, so its great to see the Linux world working to improve performance for everyone, not just the wealthy few.


  • Were Touch Bar’s problems software rather than hardware?
    The Touch Bar arrived in 2016 seemingly already pre-doomed, on a generation of machines that had a “we’ve run out of ideas” smell all around them. The arrow keys were reshaped, the keyboard got a slimming down, and even the beloved MagSafe wasn’t, in fact, safe. All of these changes would prove unpopular and get reverted in time, and the axe would eventually come for the Touch Bar, too. With an enormous benefit of hindsight, a decade after its arrival, and on the (rumored) eve of fully multitouch MacBooks, I wanted to look critically at the Touch Bar in more detail. I put a spicy title above this post, and while I’m not sure I can answer it in the affirmative, I feel I got surprisingly close to that. ↫ Marcin Wichary I have never spent this much reading about and pondering a technology seemingly nobody liked and that I never really used. I still think theres merit to the idea of screen on a keyboard, but only if the screens are integrated into the individual keys (as some products have tried over the years). Of course, this would also be astronomically expensive, delicate, and virtually impossible to repair, so Im not sure something like that can be reasonably made at an affordable price.


  • Linux 7.2 released
    Version 7.2 of the Linux kernel has been released. Significant features in this release include common attributes support in the bpf()vsystem call, cache-aware load balancing for the CPU scheduler, large-folio support in the Btrfs filesystem, further swap subsystem improvements, improvements to the Landlock security module, support for block devices with inline encryption hardware via the dm-inlinecrypt device-mapper target, and much more. ↫ corbet at LWN.net If you run Linux, youll get it sooner or later.


  • Pascal for small machines
    We talked about the latest release of Delphi a few days ago, and that brought me to Hans Ottens website. This site is about my experience with the Wirth school of languages, based on the ideas and implementations of Prof Niklaus Wirth, Kenneth Bowles, Per Brinch Hansen,`colleagues,`and their students. And my experience with the various variants, from the P2 and P4 compilers originating in Zürich ETH, via UCSD Pascal P-System to the Borland compilers and Modula and Oberon systems. All applicable to small computers and device control. On this website you will find information on Pascal for small machines, like Wirth compilers, the UCSD Pascal system, many scanned books and other files on UCSD Pascal,`Pascal on MSX and CP/M, Delphi programming on PC, Freepascal and Lazarus on Windows and Raspberry Pi, Oberon systems. Many sources of early Pascal compilers! And last but not least my Pascal-M system! ↫ Hans Otten If youre into Pascal and its related languages and technologies, this is a treasure trove of information.


  • Super Mario derivations
    One of the most surprising aspects of the Nix language is that it is lazy, especially if you have never used a lazy language before. This laziness is what makes much of Nixpkgs possible, and its complexity. I decided to take that idea and make the attribute path a sequence of button presses in Super Mario Bros. 3. Each node in the tree is a frame of the game, and each child is a button press that produces a new frame. Game states are recursive by nature. ↫ Farid Zakaria This has zero practical applications, and yet, its absolutely genius. I love this.


  • The worst PDA of all time
    Today, you can get low-quality knockoffs of just about any popular smartphone on sites like AliExpress or Temu, whether they be iPhones, Galaxy phones, or whatever else. They have terrible build quality, bottom-of-the-barrel components and specifications, and all run outdated versions of Android  badly. At the same time, various consumer electronics brands, once popular in a bygone era, sell the rights to their brand name to unknown companies, who then put these brands on generic hardware to give their products a sheen of legitimacy. Thats why today, you can still buy Nokia smartphones, Polaroid cameras, and low-effort Hi-Fi equipment from various once-respected brands. None of this is new, however. In the late 90s and early 2000s, companies were already doing the same thing. In fact, theres one device from this era which combines both business practices  its both a cheap knockoff of a wildly successful device, and it carries a once-revered brand name. Also, just to add some juice, this story involves stolen source code. Lets take a look at the worst PDA of all time, the Olivetti daVinci. In 1997, Palm launched the Palm Pilot, and it and its successors proved to be a massive hit. Where countless before it had failed, Palm found the magic formula to make pocket computing work. I wrote an in-depth article about Palm over 13 years ago which goes into much (much) more detail, but the reason the Palm Pilot succeeded where things like the Newton, PenPoint OS, and Windows for Pen Computing failed, is that Palms founder, Jeff Hawkins, realised that they were competing with paper, not with desktop computers. Instead of trying to shove the capabilities of a full personal computer into a (barely) pockatable device, a pocket computer had to be as fast and convenient as paper, and therefore extremely strict about which features to add, and which to omit. To this day, the entirety of smartphone computing stands on the shoulders of Palm. Palms ideas, implementations, approaches, paradigms, and even people were absorbed by Apple and Google, where they shaped both iOS and Android. The phone youre looking at right now has a ton of Palm DNA in it, still. After all, youre still using the homescreen-with-apps paradigm Palm already perfected in the late 90s and early 2000s. The success of the Palm Pilot and its successors did not go unnoticed. Microsoft, most prominently, felt incredibly threatened by Palms success: The success of Palm’s products got the attention of Microsoft, and the company pretty much announced it was going to crush Palm. According to Hawkins, Microsoft had a sales conference, where, at some point, a big target appeared on the projector screen, with the Palm logo dead in the centre of it: “we are going to crush and kill these guys”, was the central message. Hawkins recalls that he got condolence letters after that, stating things like “Sorry Jeff. Too bad.” ↫ Thom Holwerda While Microsoft proved to be unable to kill and crush! Palm, it did manage to build a relatively successful business selling PDAs running various incarnations of Windows CE. Together, Palm and Microsoft dominated the PDA market pretty much throughout its entire existence, and while the market was a mere fraction of the smartphone market of today, other companies still wanted a piece of this pie too. One of these companies was Olivetti, a storied Italian company with a long history making typewriters, computers, and other electronics. Im not going into detail about Olivettis history, but the company was renowned for its attention to design, creating iconic products like the Lexikon 80, Lettera 22, Elea 9003, Programma 101, and so, so many more. Olivetti also entered the personal computer market, first with a variety of custom machines featuring Z80 and later Motorola 68000 processors running a variety of custom operating systems developed by Olivetti (including its own UNIX variant, X/OS). After a few machines using MIPS and Alpha processors in the early 90s, the company would eventually focus entirely on Intel-based PCs (including this amazing failure) running Windows. Like so many other computer makers from that era, Olivetti eventually left the PC business by selling it off in 1997. To this day, Olivetti PCs tend to cost more on the used market than those from other brands, despite no technical merits dictating so. At around this time, our current story begins. Seeing the success of the Palm Pilot and the emergence of copycat devices running Microsofts Windows CE, Olivetti wanted in on the action. And so, in the late 90s, the company introduced the Olivetti daVinci, a line of PDAs whose software looked suspiciously like Palm OS. Theres not a ton of information out there about the development history, but it seems that while Olivetti designed the hardware, it contracted the development of the operating system out to a company from Hong Kong, Echolink Design. And this is where things went horribly wrong for Olivetti. The software Echolink Design developed for the daVinci didnt just look like Palm OS, it was Palm OS  at least, according to Palm. After being on the market for about a year, the Palm Pilot maker, then a subsidiary of 3Com, filed for an injunction, alleging that the daVinci operating system designed by Echolink Design contained actual Palm OS source code. In addition, Palm also filed suit against CompanionLink Software, the company that developed the Outlook synchronisation software for the daVinci. Palm won handily, and within a day of the filing, temporary restraining orders were put in place on both Olivetti and CompanionLink, stopping sales of the daVinci and its software dead in its tracks. It seemed to have been a pretty clear-cut case. From The Wall Street Journal at the time: U.S. District Judge James Ware ruled Olivettis Royal daVinci organizer contains software that appears to have been copied from the operating system for 3Coms Palm organizers. Judge Ware said a review by a software expert found the daVinci software contains private Palm code and even grammatical


  • Making a game on a custom bytecode VM in 7 days and 3kB
    In the last few days, I built a shoot ’em up game by embedding a tiny custom bytecode VM and rendering the graphics using a fullscreen pixel shader. The result is a 3kB Windows executable. This was done for Langjam Gamejam, a 7-day challenge where you create a programming language and then use it to build a game. The project combines several interests of mine: language tooling, game development, procedural graphics, and demoscene-style size constraints. The game jam format forced me to keep the scope small and explore new ideas. Also, it was fun! ↫ Laurent Le Brun In seven days, Le Brun created a brand new programming language, compiler, bytecode interpreter, a game written in the new language, and rendered it, ending up with a 3kB self-contained executable. Its amazing what humans can do.


  • Why tiny JPEGs look different in Chrome
    A while back, when chatting with a colleague over their computer, I noticed that a logo did not look exactly the same as it did on mine. It looked thinner on theirs and more faithful to the original image. It was rendered at 15px; here is an upscaled version. If you squint, or take a step back, the one from Chrome looks thicker. A bit weird, but swapping the image for an SVG fixed it. Still, I was curious: why was it rendering like this in the first place? I did some digging and found a nifty optimization that Chrome uses when rendering JPEGs at small scales. ↫ Guillaume Técher I love it when people detail their discoveries like this.


  • Redox gets installer improvements, merges new CPU scheduler
    Another month started almost two weeks ago, so weve got a new monthly report from Redox, the general purpose operating system written in Rust. The month of July  it seems the report was published with a bit of a delay, regardless of what the date on their site says  brought improvements to the installer, with new options commonly found in most installers, such as a choice of installation method, network-based installation, and more. The Google Summer of Code work on the new CPU scheduler has also been merged, including a number of related performance enhancements. Theres improvements to the ARM port, Amlogic Meson UART ARM64 support, and uutils grep and sed have been successfully built on Redox, replacing their their GNU counterparts in the os-test test suite. In addition, a whole slew of demos were ported as well, from Ratatui demos to various Iced demos covering things like reading QR codes and processing Markdown. Of course, this is all topped off with the usual long list of lower-level, smaller changes and improvements to the kernel, drivers, Relibc, and more.


  • The OSNews Fundraiser continues: you made me use Windows, now make me use macOS
    The OSNews Fundraiser, to celebrate the fact I posted 20000 stories in 21 years, is still underway. The first major incentive was reached, and I, a long-time Linux user, published my experiences using Windows 11 for a month. It wasnt a success. Keep donating if you want to find out what a Linux user thinks of the current state of macOS! Why support OSNews? I want to make sure I can run OSNews for another two decades and another 20000 posts, and I need your help to do so. Since my wife, who has a tough, underpaid job in elderly care, is largely unable to work due to health reasons caused by that very same job, my income has become a lot more crucial for our kids, my wife, and myself. With OSNews readers being more skeptical of subscription-like things like our Patreon than most people, it’s exactly these one-time donations that make up the bulk of your support. Thank you.


  • The little-known winstart.bat batch file
    Raymond Chen explains what, exactly, the file winstart.bat in Windows 95 is used for. In Windows 95, you could create a winstart.bat file in your Windows directory. During startup, the virtual machine manager initializes and creates the so-called “System virtual machine” (the “System VM”), which is the virtual machine that all Windows programs run in. But before running the user-mode kernel in that virtual machine, the virtual machine manager runs the winstart.bat batch file if it exists. ↫ Raymond Chen Chen needs to use several diagrams to really explain what the batch file is used for, but as a very crude summary, it allows you to load TSRs that only apply to Windows programs, while not affecting any additional DOS command prompts you may load later after Windows is already running. While many think its a Windows 95 feature, it was already present in Windows 3.x. A unique feature that I doubt many people made active use of.


  • Delphi 13 Community Edition released
    Delphi is still very much a thing, and still very much in active development. The current stewards of Delphi, Embarcadero, released the Delphi 13 Community Edition today. Delphi Community Edition is a full-featured, free edition of Delphi for building native applications with the Delphi language. It includes a professional IDE, visual designers, integrated compilers and debuggers, the VCL framework for Windows development, and the FireMonkey framework for creating native applications from a shared codebase across Windows, macOS, iOS, and Android. It is designed for students, hobbyists, freelancers, and small teams that meet the Community Edition license requirements. ↫ Marco Cantu at the Embarcadero blog Delphi has been around since 1995, first released for Windows 3.1. Its both a programming language, a variant of Object Pascal, and the accompanying IDE and related tooling and frameworks, originally developed by legendary company Borland. This latest version of course adds a number of new features to the programming language, and further improves the IDE as well, this time with a brand new 64bit version. The two frameworks for visual application development, VCL and FireMonkey, have also been updated and improved. Sadly, its not open source, and the Community Edition is intended for mostly non-commercial, hobbyist use. If you want to actually earn any money using Delphi, youre going to have to step up to Delphi 13 Florence, which isnt free.



Linux Journal News

  • EU OS: A Bold Step Toward Digital Sovereignty for Europe
    Image
    A new initiative, called "EU OS," has been launched to develop a Linux-based operating system tailored specifically for the public sector organizations of the European Union (EU). This community-driven project aims to address the EU's unique needs and challenges, focusing on fostering digital sovereignty, reducing dependency on external vendors, and building a secure, self-sufficient digital ecosystem.
    What Is EU OS?
    EU OS is not an entirely novel operating system. Instead, it builds upon a Linux foundation derived from Fedora, with the KDE Plasma desktop environment. It draws inspiration from previous efforts such as France's GendBuntu and Munich's LiMux, which aimed to provide Linux-based systems for public sector use. The goal remains the same: to create a standardized Linux distribution that can be adapted to different regional, national, and sector-specific needs within the EU.

    Rather than reinventing the wheel, EU OS focuses on standardization, offering a solid Linux foundation that can be customized according to the unique requirements of various organizations. This approach makes EU OS a practical choice for the public sector, ensuring broad compatibility and ease of implementation across diverse environments.
    The Vision Behind EU OS
    The guiding principle of EU OS is the concept of "public money – public code," ensuring that taxpayer money is used transparently and effectively. By adopting an open-source model, EU OS eliminates licensing fees, which not only lowers costs but also reduces the dependency on a select group of software vendors. This provides the EU’s public sector organizations with greater flexibility and control over their IT infrastructure, free from the constraints of vendor lock-in.

    Additionally, EU OS offers flexibility in terms of software migration and hardware upgrades. Organizations can adapt to new technologies and manage their IT evolution at a manageable cost, both in terms of finances and time.

    However, there are some concerns about the choice of Fedora as the base for EU OS. While Fedora is a solid and reliable distribution, it is backed by the United States-based Red Hat. Some argue that using European-backed projects such as openSUSE or KDE's upcoming distribution might have aligned better with the EU's goal of strengthening digital sovereignty.
    Conclusion
    EU OS marks a significant step towards Europe's digital independence by providing a robust, standardized Linux distribution for the public sector. By reducing reliance on proprietary software and vendors, it paves the way for a more flexible, cost-effective, and secure digital ecosystem. While the choice of Fedora as the base for the project has raised some questions, the overall vision of EU OS offers a promising future for Europe's public sector in the digital age.

    Source: It's FOSS
    European Union


  • Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linus Torvalds Acknowledges Missed Release of Linux 6.14 Due to Oversight

    Linux kernel lead developer Linus Torvalds has admitted to forgetting to release version 6.14, attributing the oversight to his own lapse in memory. Torvalds is known for releasing new Linux kernel candidates and final versions on Sunday afternoons, typically accompanied by a post detailing the release. If he is unavailable due to travel or other commitments, he usually informs the community ahead of time, so users don’t worry if there’s a delay.

    In his post on March 16, Torvalds gave no indication that the release might be delayed, instead stating, “I expect to release the final 6.14 next weekend unless something very surprising happens.” However, Sunday, March 23rd passed without any announcement.

    On March 24th, Torvalds wrote in a follow-up message, “I’d love to have some good excuse for why I didn’t do the 6.14 release yesterday on my regular Sunday afternoon schedule,” adding, “But no. It’s just pure incompetence.” He further explained that while he had been clearing up unrelated tasks, he simply forgot to finalize the release. “D'oh,” he joked.

    Despite this minor delay, Torvalds’ track record of successfully managing the Linux kernel’s development process over the years remains strong. A single day’s delay is not critical, especially since most Linux users don't urgently need the very latest version.

    The new 6.14 release introduces several important features, including enhanced support for writing drivers in Rust—an ongoing topic of discussion among developers—support for Qualcomm’s Snapdragon 8 Elite mobile chip, a fix for the GhostWrite vulnerability in certain RISC-V processors from Alibaba’s T-Head Semiconductor, and a completed NTSYNC driver update that improves the WINE emulator’s ability to run Windows applications, particularly games, on Linux.

    Although the 6.14 release went smoothly aside from the delay, Torvalds expressed that version 6.15 may present more challenges due to the volume of pending pull requests. “Judging by my pending pile of pull requests, 6.15 will be much busier,” he noted.

    You can download the latest kernel here.
    Linus Torvalds kernel


  • AerynOS 2025.03 Alpha Released with GNOME 48, Mesa 25, and Linux Kernel 6.13.8
    Image
    AerynOS 2025.03 has officially been released, introducing a variety of exciting features for Linux users. The release includes the highly anticipated GNOME 48 desktop environment, which comes with significant improvements like HDR support, dynamic triple buffering, and a Wayland color management protocol. Other updates include a battery charge limiting feature and a Wellbeing option aimed at improving user experience.

    This release, while still in alpha, incorporates Linux kernel 6.13.8 and the updated Mesa 25.0.2 graphics stack, alongside tools like LLVM 19.1.7 and Vulkan SDK 1.4.309.0. Additionally, the Moss package manager now integrates os-info to generate more detailed OS metadata via a JSON file.

    Future plans for AerynOS include automated package updates, easier rollback management, improved disk handling with Rust, and fractional scaling enabled by default. The installer has also been revamped to support full disk wipes and dynamic partitioning.

    Although still considered an alpha release, AerynOS 2025.03 can be downloaded and tested right now from its official website.

    Source: 9to5Linux
    AerynOS


  • Xojo 2025r1: Big Updates for Developers with Linux ARM Support, Web Drag and Drop, and Direct App Store Publishing
    Image
    Xojo has just rolled out its latest release, Xojo 2025 Release 1, and it’s packed with features that developers have been eagerly waiting for. This major update introduces support for running Xojo on Linux ARM, including Raspberry Pi, brings drag-and-drop functionality to the Web framework, and simplifies app deployment with the ability to directly submit apps to the macOS and iOS App Stores.

    Here’s a quick overview of what’s new in Xojo 2025r1:
    1. Linux ARM IDE Support
    Xojo 2025r1 now allows developers to run the Xojo IDE on Linux ARM devices, including popular platforms like Raspberry Pi. This opens up a whole new world of possibilities for developers who want to create apps for ARM-based devices without the usual complexity. Whether you’re building for a Raspberry Pi or other ARM devices, this update makes it easier than ever to get started.
    2. Web Drag and Drop
    One of the standout features in this release is the addition of drag-and-drop support for web applications. Now, developers can easily drag and drop visual controls in their web projects, making it simpler to create interactive, user-friendly web applications. Plus, the WebListBox has been enhanced with support for editable cells, checkboxes, and row reordering via dragging. No JavaScript required!
    3. Direct App Store Publishing
    Xojo has also streamlined the process of publishing apps. With this update, developers can now directly submit macOS and iOS apps to App Store Connect right from the Xojo IDE. This eliminates the need for multiple steps and makes it much easier to get apps into the App Store, saving valuable time during the development process.
    4. New Desktop and Mobile Features
    This release isn’t just about web and Linux updates. Xojo 2025r1 brings some great improvements for desktop and mobile apps as well. On the desktop side, all projects now include a default window menu for macOS apps. On the mobile side, Xojo has introduced new features for Android and iOS, including support for ColorGroup and Dark Mode on Android, and a new MobileColorPicker for iOS to simplify color selection.
    5. Performance and IDE Enhancements
    Xojo’s IDE has also been improved in several key areas. There’s now an option to hide toolbar captions, and the toolbar has been made smaller on Windows. The IDE on Windows and Linux now features modern Bootstrap icons, and the Documentation window toolbar is more compact. In the code editor, developers can now quickly navigate to variable declarations with a simple Cmd/Ctrl + Double-click. Plus, performance for complex container layouts in the Layout Editor has been enhanced.
    What Does This Mean for Developers?
    Xojo 2025r1 brings significant improvements across all the platforms that Xojo supports, from desktop and mobile to web and Linux. The added Linux ARM support opens up new opportunities for Raspberry Pi and ARM-based device development, while the drag-and-drop functionality for web projects will make it easier to create modern, interactive web apps. The ability to publish directly to the App Store is a game-changer for macOS and iOS developers, reducing the friction of app distribution.
    How to Get Started
    Xojo is free for learning and development, as well as for building apps for Linux and Raspberry Pi. If you’re ready to dive into cross-platform development, paid licenses start at $99 for a single-platform desktop license, and $399 for cross-platform desktop, mobile, or web development. For professional developers who need additional resources and support, Xojo Pro and Pro Plus licenses start at $799. You can also find special pricing for educators and students.

    Download Xojo 2025r1 today at xojo.com.
    Final Thoughts
    With each new release, Xojo continues to make cross-platform development more accessible and efficient. The 2025r1 release is no exception, delivering key updates that simplify the development process and open up new possibilities for developers working on a variety of platforms. Whether you’re a Raspberry Pi enthusiast or a mobile app developer, Xojo 2025r1 has something for you.
    Xojo ARM


  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


Linux Magazine News (path: lmi_news)




  • CachyOS Gets an Update
    CachyOS August 2026 release is now available with the latest version of KDE, some new features, and plenty of improvements.











  • Hannah Montana Linux Is Back!
    Developer Noah Cagle decided the world needed the once obscure but beloved Linux distribution and gave it a decidedly pink refresh.




  • Kubuntu Focus Goes Ultra
    The Kubuntu Focus team has upped the performance ante of its M2 and Zr laptops with the latest, greatest CPUs from Intel.





Page last modified on November 17, 2022, at 06:39 PM