Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All/All+Images) (Single Column)

LinuxSecurity - Security Advisories







LWN.net

  • [$] May the FOLL_FORCE not be with you
    One of the simplest hardening concepts to understand is that memory shouldnever be both writable and executable, otherwise an attacker can use it toload and run arbitrary code. That rule is generally followed in Linuxsystems, but there is a glaring loophole that is exploitable from userspace to inject code into a running process. Attackers have duly exploitedit. A new effort to close the hole ran into trouble early in the mergewindow, but a solution may yet be found in time for the 6.11 kernelrelease.


  • Security updates for Friday
    Security updates have been issued by AlmaLinux (linux-firmware and squid), Debian (bind9), Fedora (kubernetes, thunderbird, and tinyproxy), Oracle (containernetworking-plugins, cups, edk2, httpd, httpd:2.4, kernel, kernel-container, libreoffice, libuv, libvirt, python3, and runc), Red Hat (freeradius:3.0, httpd, and squid), and SUSE (giflib and python-dnspython).


  • [$] What became of getrandom() in the vDSO
    In the previous episode of thevgetrandom() story, Jason Donenfeld had put together a version ofthe getrandom()system call that ran in user space, significantly improving performance forapplications that need a lot of random data while retaining all of theguarantees provided by the system call. At that time, it seemed that aconsensus had built around the implementation and that it was headed towardthe mainline in that form. A few milliseconds after that article wasposted, though, a Linus-Torvalds-shaped obstacle appeared in its path.That obstacle has been overcome and this work has now been merged for the6.11 kernel, but its form has changed somewhat.


  • [$] More informative kernel panics for Fedora
    On July 12, Jocelyn Falempeproposed a change to the configuration options that Fedora sets for itskernels, in order to make kernel panics easier to report.Falempe would like to enable the kernel's recently addedDRM-panic feature, which addsa graphical crash screen that is reminiscent of the infamousWindows "blue screen of death" for kernel panics. The feature introduces a fewtradeoffs, including currently limited driver support, so the proposal spawned agood deal of discussion.


  • Rust 1.80.0 released
    Version1.80.0 of the Rust language has been released. Changes include the newLazyCell and LazyLock types (which delay datainitialization until the first access), the stabilization of theexclusive-range syntax for match patterns, and more.


  • Three new stable kernels
    The 6.9.11, 6.6.42, and 6.1.101 stable kernels have been released. Asusual, they contain important fixes throughout the tree.


  • Security updates for Thursday
    Security updates have been issued by AlmaLinux (containernetworking-plugins, cups, edk2, httpd, httpd:2.4, libreoffice, libuv, libvirt, python3, and runc), Fedora (exim, python-zipp, xdg-desktop-portal-hyprland, and xmedcon), Red Hat (cups, fence-agents, freeradius, freeradius:3.0, httpd:2.4, kernel, kernel-rt, nodejs:18, podman, and resource-agents), Slackware (htdig and libxml2), SUSE (exim), and Ubuntu (ocsinventory-server, php-cas, and poppler).


  • Linux Mint 22 "Wilma" released
    Linux Mint has announced version 22 ofthe distribution in three editions: Cinnamon, MATE, and Xfce. Mint 22is based on Ubuntu 24.04 and uses kernel version 6.8.0:
    Linux Mint 22 is a long term support release which will be supporteduntil 2029. It comes with updated software and brings refinements andmany new features to make your desktop even more comfortable to use.
    LWN covered theLinux Mint 22 beta in early July. See the newfeatures page and release notes formore information on this release.



  • Stable kernel update 6.10.1
    Greg Kroah-Hartman has released the 6.10.1 stable kernel update. This releasecontains a small number of seemingly urgent regression fixes. Users ofthis kernel series are advised to upgrade.



LXer Linux News


  • How to Exclude Directories from the Find Command Search in Linux
    In this article, we will delve into the methods for explicitly excluding directories from the find command‘s search in Linux. The find command is a powerful utility for searching for files and directories within a directory hierarchy. However, there are scenarios where you may want to exclude certain directories from your search to speed up the process or to avoid irrelevant results. We’ll explore different options and provide practical examples using a sandbox directory structure.










Linux Insider"LinuxInsider"












Slashdot

  • Adobe Exec: Early Termination Fees Are 'Like Heroin'
    Longtime Slashdot reader sandbagger shares a report from The Verge: Early termination fees are "a bit like heroin for Adobe," according to an Adobe executive quoted in the FTC's newly unredacted complaint against the company for allegedly hiding fees and making it too hard to cancel Creative Cloud. "There is absolutely no way to kill off ETF or talk about it more obviously" in the order flow without "taking a big business hit," this executive said. That's the big reveal in the unredacted complaint, which also contains previously unseen allegations that Adobe was internally aware of studies showing its order and cancellation flows were too complicated and customers were unhappy with surprise early termination fees. In response to the quote, Adobe's general counsel and chief trust officer, Dana Rao, said that he was "disappointed in the way they're continuing to take comments out of context from non-executive employees from years ago to make their case." Rao added that the person quoted was not on the leadership team that reports to CEO Shantanu Narayen and that whether to charge early termination fees would "not be their decision." The early termination fees in the FTC case represent "less than half a percent of our annual revenue," Rao told The Verge. "It doesn't drive our business, it doesn't drive our business decisions."


    Read more of this story at Slashdot.


  • Boeing Starliner Astronauts Have Been In Space Six Weeks Longer Than Originally Planned
    Longtime Slashdot reader Randseed writes: Boeing Starliner is apparently still stuck at the ISS, six weeks longer than planned due to engine troubles. The root cause seems to be overheating. NASA is still hopeful that they can bring the two astronauts back on the Starliner, but if not apparently there is a SpaceX Dragon craft docked at the station that can get them home. This is another in a long list of high profile failures by Boeing. This comes after a series of failures in their popular commercial aircraft including undocumented flight system modifications causing crashes of the 737 MAX, doors blowing out in mid-flight, and parts falling off the aircraft. The latter decimated a Toyota in a populated area."I think we're starting to close in on those final pieces of flight rationale to make sure that we can come home safely, and that's our primary focus right now," said Steve Stich, manager of NASA's commercial crew program. "Our prime option is to complete the mission," Stich said. "There are a lot of good reasons to complete this mission and bring Butch and Suni home on Starliner. Starliner was designed, as a spacecraft, to have the crew in the cockpit."


    Read more of this story at Slashdot.


  • NASA Fires Lasers At the ISS
    joshuark shares a report from The Verge: NASA researchers have successfully tested laser communications in space by streaming 4K video footage originating from an airplane in the sky to the International Space Station and back. The feat demonstrates that the space agency could provide live coverage of a Moon landing during the Artemis missions and bodes well for the development of optical communications that could connect humans to Mars and beyond. NASA normally uses radio waves to send data and talk between the surface to space but says that laser communications using infrared light can transmit data 10 to 100 times faster than radios. "ISS astronauts, cosmonauts, and unwelcomed commercial space-flight visitors can now watch their favorite porn in real-time, adding some life to a boring zero-G existence," adds joshuark. "Ralph Kramden, when contacted by Ouiji board, simply spelled out 'Bang, zoom, straight to the moon!'"


    Read more of this story at Slashdot.


  • 'Copyright Traps' Could Tell Writers If an AI Has Scraped Their Work
    An anonymous reader quotes a report from MIT Technology Review: Since the beginning of the generative AI boom, content creators have argued that their work has been scraped into AI models without their consent. But until now, it has been difficult to know whether specific text has actually been used in a training data set. Now they have a new way to prove it: "copyright traps" developed by a team at Imperial College London, pieces of hidden text that allow writers and publishers to subtly mark their work in order to later detect whether it has been used in AI models or not. The idea is similar to traps that have been used by copyright holders throughout history -- strategies like including fake locations on a map or fake words in a dictionary. [...] The code to generate and detect traps is currently available on GitHub, but the team also intends to build a tool that allows people to generate and insert copyright traps themselves. "There is a complete lack of transparency in terms of which content is used to train models, and we think this is preventing finding the right balance [between AI companies and content creators]," says Yves-Alexandre de Montjoye, an associate professor of applied mathematics and computer science at Imperial College London, who led the research. The traps aren't foolproof and can be removed, but De Montjoye says that increasing the number of traps makes it significantly more challenging and resource-intensive to remove. "Whether they can remove all of them or not is an open question, and that's likely to be a bit of a cat-and-mouse game," he says.


    Read more of this story at Slashdot.


  • Crooks Bypassed Google's Email Verification To Create Workspace Accounts, Access 3rd-Party Services
    Brian Krebs writes via KrebsOnSecurity: Google says it recently fixed an authentication weakness that allowed crooks to circumvent the email verification required to create a Google Workspace account, and leverage that to impersonate a domain holder at third-party services that allow logins through Google's "Sign in with Google" feature. [...] Google Workspace offers a free trial that people can use to access services like Google Docs, but other services such as Gmail are only available to Workspace users who can validate control over the domain name associated with their email address. The weakness Google fixed allowed attackers to bypass this validation process. Google emphasized that none of the affected domains had previously been associated with Workspace accounts or services. "The tactic here was to create a specifically-constructed request by a bad actor to circumvent email verification during the signup process," [said Anu Yamunan, director of abuse and safety protections at Google Workspace]. "The vector here is they would use one email address to try to sign in, and a completely different email address to verify a token. Once they were email verified, in some cases we have seen them access third party services using Google single sign-on." Yamunan said none of the potentially malicious workspace accounts were used to abuse Google services, but rather the attackers sought to impersonate the domain holder to other services online.


    Read more of this story at Slashdot.


  • Courts Close the Loophole Letting the Feds Search Your Phone At the Border
    On Wednesday, Judge Nina Morrison ruled that cellphone searches at the border are "nonroutine" and require probable cause and a warrant, likening them to more invasive searches due to their heavy privacy impact. As reported by Reason, this decision closes the loophole in the Fourth Amendment's protection against unreasonable searches and seizures, which Customs and Border Protection (CBP) agents have exploited. Courts have previously ruled that the government has the right to conduct routine warrantless searches for contraband at the border. From the report: Although the interests of stopping contraband are "undoubtedly served when the government searches the luggage or pockets of a person crossing the border carrying objects that can only be introduced to this country by being physically moved across its borders, the extent to which those interests are served when the government searches data stored on a person's cell phone is far less clear," the judge declared. Morrison noted that "reviewing the information in a person's cell phone is the best approximation government officials have for mindreading," so searching through cellphone data has an even heavier privacy impact than rummaging through physical possessions. Therefore, the court ruled, a cellphone search at the border requires both probable cause and a warrant. Morrison did not distinguish between scanning a phone's contents with special software and manually flipping through it. And in a victory for journalists, the judge specifically acknowledged the First Amendment implications of cellphone searches too. She cited reporting by The Intercept and VICE about CPB searching journalists' cellphones "based on these journalists' ongoing coverage of politically sensitive issues" and warned that those phone searches could put confidential sources at risk. Wednesday's ruling adds to a stream of cases restricting the feds' ability to search travelers' electronics. The 4th and 9th Circuits, which cover the mid-Atlantic and Western states, have ruled that border police need at least "reasonable suspicion" of a crime to search cellphones. Last year, a judge in the Southern District of New York also ruled (PDF) that the government "may not copy and search an American citizen's cell phone at the border without a warrant absent exigent circumstances."


    Read more of this story at Slashdot.


  • Nvidia's Open-Source Linux Kernel Driver Performing At Parity To Proprietary Driver
    Nvidia's new R555 Linux driver series has significantly improved their open-source GPU kernel driver modules, achieving near parity with their proprietary drivers. Phoronix's Michael Larabel reports: The NVIDIA open-source kernel driver modules shipped by their driver installer and also available via their GitHub repository are in great shape. With the R555 series the support and performance is basically at parity of their open-source kernel modules compared to their proprietary kernel drivers. [...] Across a range of different GPU-accelerated creator workloads, the performance of the open-source NVIDIA kernel modules matched that of the proprietary driver. No loss in performance going the open-source kernel driver route. Across various professional graphics workloads, both the NVIDIA RTX A2000 and A4000 graphics cards were also achieving the same performance whether on the open-source MIT/GPLv2 driver or using NVIDIA's classic proprietary driver. Across all of the tests I carried out using the NVIDIA 555 stable series Linux driver, the open-source NVIDIA kernel modules were able to achieve the same performance as the classic proprietary driver. Also important is that there was no increased power use or other difference in power management when switching over to the open-source NVIDIA kernel modules. It's great seeing how far the NVIDIA open-source kernel modules have evolved and that with the upcoming NVIDIA 560 Linux driver series they will be defaulting to them on supported GPUs. And moving forward with Blackwell and beyond, NVIDIA is just enabling the GPU support along their open-source kernel drivers with leaving the proprietary kernel drivers to older hardware. Tests I have done using NVIDIA GeForce RTX 40 graphics cards with Linux gaming workloads between the MIT/GPL and proprietary kernel drivers have yielded similar (boring but good) results: the same performance being achieved with no loss going the open-source route. You can view Phoronix's performance results in charts here, here, and here.


    Read more of this story at Slashdot.


  • How a Cheap Barcode Scanner Helped Fix CrowdStrike'd Windows PCs In a Flash
    An anonymous reader quotes a report from The Register: Not long after Windows PCs and servers at the Australian limb of audit and tax advisory Grant Thornton started BSODing last Friday, senior systems engineer Rob Woltz remembered a small but important fact: When PCs boot, they consider barcode scanners no differently to keyboards. That knowledge nugget became important as the firm tried to figure out how to respond to the mess CrowdStrike created, which at Grant Thornton Australia threw hundreds of PCs and no fewer than 100 servers into the doomloop that CrowdStrike's shoddy testing software made possible. [...] The firm had the BitLocker keys for all its PCs, so Woltz and colleagues wrote a script that turned them into barcodes that were displayed on a locked-down management server's desktop. The script would be given a hostname and generate the necessary barcode and LAPS password to restore the machine. Woltz went to an office supplies store and acquired an off-the-shelf barcode scanner for AU$55 ($36). At the point when rebooting PCs asked for a BitLocker key, pointing the scanner at the barcode on the server's screen made the machines treat the input exactly as if the key was being typed. That's a lot easier than typing it out every time, and the server's desktop could be accessed via a laptop for convenience. Woltz, Watson, and the team scaled the solution -- which meant buying more scanners at more office supplies stores around Australia. On Monday, remote staff were told to come to the office with their PCs and visit IT to connect to a barcode scanner. All PCs in the firm's Australian fleet were fixed by lunchtime -- taking only three to five minutes for each machine. Watson told us manually fixing servers needed about 20 minutes per machine.


    Read more of this story at Slashdot.


  • RFK Jr. Says He'd Direct the Government to Buy $615 Billion in Bitcoin or 4 Million Bitcoins
    US presidential candidate, Robert F. Kennedy Jr., announced during his keynote Friday at the Bitcoin Conference that he would direct the US government to buy Bitcoin until the size of its Bitcoin reserves matched its gold reserves. At current prices, that equates to $615 billion worth of gold. RFK Jr. said: "I will sign an executive order directing the US Treasury to purchase 550 Bitcoin daily until the US has built a reserve of at least 4,000,000 Bitcoins and a position of dominance that no other country will be able to usurp." 4 million Bitcoin is 19% of all Bitcoin that will ever exist.


    Read more of this story at Slashdot.


  • White House Announces New AI Actions As Apple Signs On To Voluntary Commitments
    The White House announced that Apple has "signed onto the voluntary commitments" in line with the administration's previous AI executive order. "In addition, federal agencies reported that they completed all of the 270-day actions in the Executive Order on schedule, following their on-time completion of every other task required to date." From a report: The executive order "built on voluntary commitments" was supported by 15 leading AI companies last year. The White House said the agencies have taken steps "to mitigate AI's safety and security risks, protect Americans' privacy, advance equity and civil rights, stand up for consumers and workers, promote innovation and competition, advance American leadership around the world, and more." It's a White House effort to mobilize government "to ensure that America leads the way in seizing the promise and managing the risks of artificial intelligence," according to the White House.


    Read more of this story at Slashdot.


The Register


  • Kamala Harris' $7M support from LinkedIn founder comes with a request: Fire Lina Khan
    FTC boss must be doing something right if folks will pay to get her binned
    LinkedIn cofounder and venture capitalist Reid Hoffman was quick to express support for Kamala Harris' bid for the US presidency this year after incumbent Joe Biden stepped aside, and now the reason has become clear: He's hoping she'll fire FTC boss and Big Tech arch-critic Lina Khan.…




  • CrowdStrike meets Murphy's Law: Anything that can go wrong will
    And boy, did last Friday's Windows fiasco ever prove that yet again
    Opinion CrowdStrike's recent Windows debacle will surely earn a prominent place in the annals of epic tech failures. On July 19, the cybersecurity giant accomplished what legions of hackers could only dream of – bringing millions of Windows systems worldwide to their knees with a single botched update.…



  • Intel nabs Micron exec to oversee foundry business ambitions
    Memory veteran to help Gelsinger and co with longstanding internal/external contract manufacturing plans
    Intel is set to hire an executive from memory chipmaker Micron to head its foundry biz as the company pursues its strategy of turning its former internal manufacturing operations into a money-spinning concern.…


  • Happy Sysadmin Day, the Bitlocker keys are in a bowl on top of the fridge
    Vote below for the best way to celebrate our underappreciated heroes
    Seven days after CrowdStrike's bad update took down Windows-based computers around the world, System Administrator Appreciation Day has arrived. And what lovely gifts did your employer spoil you with today? Shares in the company? A brand new Cybertruck? A USB stick?…


  • Boeing Starliner crew get their ISS sleepover extended
    Bosses regret talking up mission duration as Capsule's lifetime extended to 90 days
    The crew of the Boeing Starliner will spend the summer aboard the International Space Station (ISS) as NASA and Boeing refused to set a return date for the craft.…




Linux.com











Phoronix

  • EEVDF Scheduler On The Verge Of Being "Complete"
    Merged one year ago for Linux 6.6 was the EEVDF scheduler as a replacement to the CFS code and designed to provide a better scheduling policy for the kernel and being more robust. With a new set of patches for this "Earliest Eligible Virtual Deadline First" scheduling code, it's nearing the point of officially being completed...



  • UBIFS File-System Being Hardened Against Power Loss Scenarios
    While most Linux file-systems are rather robust in recovering when the system experiences a power loss, the UBIFS file-system is more prone to problems when a power-cut happens. With patches submitted for the Linux 6.11 merge window, UBIFS is seeing some hardening so it can better cope with the loss of power...




  • Linus Torvalds Addresses His Latest ARM64 Annoyance: Installing Compressed Kernel Images
    Following Linus Torvalds receiving an Ampere Altra Max workstation from Ampere Computing, he's been dabbling more with ARM64 now that it affords him more AArch64 compute power than his Apple Silicon powered MacBook. Torvalds kicked off the Linux 6.11 merge window by landing some of his own code to further enhance the ARM64 kernel and as we approach the end of the v6.11 merge window this weekend, he's merged some more ARM64 code...


  • NVIDIA9s Open-Source Linux Kernel Driver Performing At Parity To Proprietary Driver
    With the recently introduced NVIDIA 555 Linux driver stable series their open-source GPU kernel driver modules are in great shape across consumer and professional graphics products. Over the past two years the support has evolved so much that NVIDIA is now promoting their open-source kernel driver usage and with the NVIDIA 560 Linux driver beta posted this week they are defaulting to using their open-source kernel driver modules in place of the proprietary option -- on the Turing and newer GPUs supported by the open-source code. Here is a fresh look at the impact.




  • Linux 6.11 Is Looking Good In Early Benchmarks On AMD Ryzen Threadripper
    With the Linux 6.11 kernel merge window wrapping up this weekend, I've begun "kicking the tires" on the new kernel that will then see the weekly release candidates over the next two months. For some initial Linux 6.10 vs. 6.11 Git benchmarking on an AMD Ryzen Threadripper workstation, the new kernel is appearing fit and offering some nice performance gains in a few areas...



Engadget"Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics"

  • Amazon drops the first teaser for its upcoming Yakuza adaptation
    Amazon has released its first teaser video for San Diego Comic-Con. There9s a lot of focus on the inking process of Kazuma Kiryu9s iconic dragon tattoo, but you9ll also get glimpses of Kamurocho9s night scene, various characters in the series and the underground fight club that shows up as a mini-game across the franchise. In the last few seconds of the video, you9ll see a shirtless Kiryu heading to a circle of cheering viewers betting on his match. 

    When the company announced the show in June, it described the adaptation as a "crime-suspense-action series" that "follows the life, childhood friends, and repercussions of the decisions of Kazuma Kiryu, a fearsome and peerless Yakuza warrior with a strong sense of justice, duty, and humanity." Seeing as the show is set between 1995 and 2005, it will most like be based on the first Yakuza game with glimpses of the years that took place after the events in Yakuza 0.

    The first three of episodes of Like A Dragon: Yakuza will arrive on Prime Video on October 24, with the next three coming on October 31. It stars Ryoma Takeuchi (Kamen Rider Drive, Roppongi Class) as Kiryu. And as this teaser has revealed, his best friend Nishiki, who plays a pivotal role in the story, will be portrayed by Kento Kaku (Netflix9s House of Ninjas).




    This article originally appeared on Engadget at https://www.engadget.com/amazon-drops-the-first-teaser-for-its-upcoming-yakuza-adaptation-110442602.html?src=rss


  • ISPs are fighting to raise the price of low-income broadband
    A new government program is trying to encourage Internet service providers (ISPs) to offer lower rates for lower income customers by distributing federal funds through states. The only problem is the ISPs don’t want to offer the proposed rates.

    Ars Technica obtained a letter sent to US Commerce Secretary Gina Raimondo signed by more than 30 broadband industry trade groups like ACA Connects and the Fiber Broadband Association as well as several state based organizations. The letter raises “both a sense of alarm and urgency” about their ability to participate in the Broadband Equity, Access and Deployment (BEAD) program. The newly formed BEAD program provides over $42 billion in federal funds to “expand high-speed internet access by funding planning, infrastructure, deployment and adoption programs” in states across the country, according to the National Telecommunications and Information Administration (NTIA).

    The money first goes to the NTIA and then it’s distributed to states after they obtain approval from the NTIA by presenting a low-cost broadband Internet option. The ISP industries’ letter claims a fixed rate of $30 per month for high speed Internet access is “completely unmoored from the economic realities of deploying and operating networks in the highest-cost, hardest-to-reach areas.”

    The letter urges the NTIA to revise the low-cost service option rate proposed or approved so far. Twenty-six states have completed all of the BEAD program’s phases.

    Americans pay an average of $89 a month for Internet access. New Jersey has the highest average bill at $126 per month, according to a survey conducted by U.S. News and World Report. A 2021 study from the Pew Research Center found that 57 percent of households with an annual salary of $30,000 or less have a broadband connection.
    This article originally appeared on Engadget at https://www.engadget.com/isps-are-fighting-to-raise-the-price-of-low-income-broadband-220620369.html?src=rss


  • Amazon is giving The Boys the prequel treatment
    The Boys may be one season away from ending but it’s not done caking your screens with blood and torn muscle tissue. Cast member Jensen Ackles who plays Soldier Boy on The Boys revealed at the San Diego Comic-Con that Amazon will produce a prequel of the superhero show called Vought Rising.

    The new prequel will take place in the 1950s during the early days of the evil Vought empire, the mega conglomerate that runs the entire superhero industry in The Boys’ universe. The new series will show the early exploits of characters like Soldier Boy and the almost-immortal Nazi supe Stormfront played by Aya Cash. The story will revolve around some kind of “twisted murder mystery about the origins of Vought,” according to executive producer Eric Kripke and showrunner and executive producer Paul Grellong.

    Vought Rising sounds like a reimagining of Watchmen without the brooding and self-importance. That’s not to say Watchmen is bad. Those things and its brutal honesty about the nature of its characters are what makes it great but would it kill Rorschach to make just one curse-laden pop culture reference?

    The Boys has become Amazon’s Game of Thrones. Even when the main series ends, it won’t be the last we hear from it. The same Comic-Con panel also revealed its college themed spinoff Gen V is getting another season, according to GamesRadar+. There’s also another spinoff in development called The Boys: Mexico with Diego Luna, Gael García Bernal and Blue Beetle writer Gareth Dunnet-Alcocer, according to Deadline.

    There’s also The Boys Presents: Diabolical, the animated anthology series in which some of the original series’ writers and producers like Garth Ennis and Seth Rogen and special guest stars like Awkwafina and Andy Samberg penned original stories about supes and presented them in different animation styles. Not to sound ungrateful but when are we gonna get another season of that?
    This article originally appeared on Engadget at https://www.engadget.com/amazon-is-giving-the-boys-the-prequel-treatment-201058614.html?src=rss


  • You can date everything in Date Everything!

    Have you ever looked at something in your home like a dining room table or an adjustable height desk and wondered what it would be like to go on a date with it? Also, were you sober at the time? A new dating sim game called Date Everything! will let you see just what it’s like to search for true, meaningful love with the things you see almost every day (in the cleanest way possible, of course).

    The surreal sounding dating sim game comes from an LA-based studio called Sassy Chap Games founded by a group of voice actors who’ve worked on games and shows like Critical Role, HiFi-Rush, One Punch Man, Final Fantasy XV, X-Men ‘97 and Genshin Impact. The indie game publisher Team17 will distribute the game for PC on Steam, the Nintendo Switch, PlayStation 5 and Xbox Series X/S, according to a press release.

    The game puts players in the role of a lonely heart who receives a special pair of glasses called a “Dateviator” that transforms items in their home into human date candidates. For instance, the vacuum cleaner turns into a hunky heartthrob named Hoove and the laundry hamper transforms into a fiery redhead named Harper. Date Everything! has 100 possible mates in your home with their own voices, styles and personalities.

    You get to know items like the refrigerator or the drawing room piano in their human forms. Depending on how things go, the relationship can end in one of three ways: Love, Friend or Hate. These relationships create a chain of different possible paths in which your choices influence the outcome along a “critical path tying it all together,” according to the press release.
    Team17/Sassy Chap Games
    Since Date Everything! comes from a studio founded by voice actors, all of the characters are fully voiced. Some of the more familiar names include Felicia Day from Supernatural and Mystery Science Theater 3000, Johnny Yong Bosch from Mighty Morphin’ Power Rangers and Grey DeLisle from Scooby-Doo and The Last Airbender.

    Date Everything! doesn’t just sound like a new and interesting twist on the dating sim game concept. It also sounds like a great way to boost your ego. If you’re down because you don’t have someone in your life, at least you can play the game and realize, “Well, at least I’m not trying to date my garbage disposal.”
    This article originally appeared on Engadget at https://www.engadget.com/you-can-date-everything-in-date-everything-190032967.html?src=rss



  • Warner Bros. Discovery sues the NBA in a last-ditch effort to block Amazon’s new streaming package
    Warner Bros. Discovery followed through on its threat to “take appropriate action” against the NBA for rejecting its broadcasting rights offer. Variety reported on Friday that the media company sued the league in the New York State Supreme Court after the NBA turned down its bid to match Amazon’s streaming package that kicks in starting in the 2025-26 season.

    The conflict stems from Warner’s belief that its current contract gives it the right to match any offer that would replace Warner’s TNT as a home for NBA games (and the iconic Inside the NBA) in the upcoming deal. As for the league’s stance, The Athletic reported that since the current agreements were signed when streaming was “on the horizon, but not part of the deals,” the NBA disagrees with Warner’s matching claim.

    The lawsuit was expected as soon as the league announced its new broadcasting and streaming package, which also includes Disney (ABC and ESPN) and Comcast (NBC). The NBA reportedly told Warner it rejected its matching offer because it wanted to put all its games on its streaming service, Max, in addition to TNT. Amazon also allegedly offered to pay its first three years in full, whereas Warner offered a three-year line of credit. Finally, the NBA reportedly believed Amazon’s reach was simply greater.

    “Warner Bros. Discovery’s most recent proposal did not match the terms of Amazon Prime Video’s offer and, therefore, we have entered into a long-term arrangement with Amazon,” the NBA’s statement on Wednesday read.
    Charles BarkleyTNT / Warner Bros. Discovery
    Unless Warner can force the NBA’s hand, the new agreement will almost certainly mean the end of Inside the NBA. The decades-old sports show, starring Ernie Johnson, Kenny Smith, Charles Barkley and Shaquille O’Neal, has harnessed a rare blend of comedy, chemistry and (sometimes taking a backseat to the first two) sports analysis. The beloved program, which has won 19 Sports Emmy Awards, began in 1989 as a Johnson solo effort before fleshing out its tight-knit cast through the following years and (in the case of Shaq) decades.

    Turner has partnered with the NBA since the 1984-85 season, which coincided with Barkley’s (and Michael Jordan’s) entrance into the league out of college.

    Barkley lashed out at the NBA after hearing about the new rights package, accusing it of wanting to “break up with us from the beginning” in a statement on X. Adding, “I’m not sure TNT ever had a chance,” the Hall of Famer described it as “a sad day when owners and commissioners choose money over the fans.”

    “It just sucks,” Barkley wrote before thanking Turner’s fans for the last 24 years he’s been on the show. Inside the NBA will return next season, perhaps its last, along with the network’s standard lineup of NBA games, before the new deal begins in the 2025-26 season.
    This article originally appeared on Engadget at https://www.engadget.com/warner-bros-discovery-sues-the-nba-in-a-last-ditch-effort-to-block-amazons-new-streaming-package-183352404.html?src=rss


  • Apple’s M3 MacBook Air with 16GB of RAM is $200 off right now
    Apple’s M3 MacBook Air combines Apple’s lightest and thinnest laptop design with the impressive horsepower of third-generation Apple silicon. B&H Photo Video has the 2024 laptop on sale for $200 off. Usually $1,299, the variant with 16GB of RAM and 256GB of storage is only $1,099.

    The 2024 MacBook Air adds the M3 chip, Apple’s silicon with a 3nm process that crams more electronic components into a smaller space compared to its predecessor. Apple’s Neural Engine, which will become more crucial with the introduction of Apple Intelligence AI features this fall, is also 15 percent faster in the M3 family than the M2. While the M3 MacBook Air may not provide a dramatic speed boost over the M2 in day-to-day tasks, it has a higher ceiling for intensive work and is more future-proofed.



    The M3 model adds support for dual screens with the lid closed. It also supports Wi-Fi 6E’s faster speeds and lower latency if you have a compatible router.

    Engadget Senior Editor Devindra Hardawar praised the device in his review from earlier this year, describing the two sizes of the laptop as “great computers with excellent performance, gorgeous screens and incredible battery life.” The M3 MacBook Air lasted over 10 hours in our video-playback battery stress test.

    Although the $200 off deal at B&H is for the 13-inch model, the retailer (which operates online but also has a robust Manhattan retail outlet) has the 15-inch model for $150 off. If you like more real estate for your apps and desktop (or, like me, need larger text for aging eyes), the larger model may be the better choice.

    One thing to keep in mind before ordering is that B&H’s return policy states that it won’t take computers back for a refund once the packaging has been unsealed. Although you can contact customer service for an exchange if something is wrong out of the box, buyer’s remorse alone won’t cut it for getting your money back. This contrasts with competitors like the Apple Store, Amazon and Best Buy, so consider that before proceeding. However, apart from that footnote, B&H has been an Apple partner for nearly a decade and has built a solid reputation with customers since its 1973 founding.

    Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/apples-m3-macbook-air-with-16gb-of-ram-is-200-off-right-now-165605741.html?src=rss


  • Here's how to stop Grok's AI models using your tweets for training
    There's word going around that X just enabled a setting that lets it train Grok on public tweets, as well as any interactions they have with the chatbot. That's not entirely true: a help page instructing users how to opt-out of X using their data to train Grok has been live since at least May. X just never exactly made it crystal clear that it was opting everyone into this, which is a sketchy move. If you don't want a bad chatbot to use your bad tweets for training, it's thankfully easy to switch that off.

    You just need to uncheck a box from the Grok data sharing tab in the X settings. If that link doesn't work, you can go to Settings > Privacy and Safety > Grok. For the time being, the setting isn't accessible through X's mobile apps (the company says it will be soon), so you'll have to uncheck the box on the web for now. It's also worth noting that Grok isn't trained on any tweets from private X accounts. 
    All X users have the ability to control whether their public posts can be used to train Grok, the AI search assistant. This option is in addition to your existing controls over whether your interactions, inputs, and results related to Grok can be utilized. This setting is…
    — Safety (@Safety) July 26, 2024
    One of X's selling points for Grok when it rolled out the chatbot was that it had the advantage of using real-time information that's published on the platform — in other words, users' tweets. That only works if users opt-in or are automatically enrolled into sharing their data with the chatbot. But X isn't exactly the pinnacle of truth and accuracy. It's full of pranksters, and lifting their jokes might be one of the reasons why Grok keeps on getting stuff wrong. In any case, it's not exactly uncommon for AI models to be trained on material without explicit permission from the original creators.
    This article originally appeared on Engadget at https://www.engadget.com/heres-how-to-stop-groks-ai-models-using-your-tweets-for-training-161041266.html?src=rss



  • The 65-inch LG C3 OLED TV is nearly half off for today only
    The 65-inch LG C3 OLED TV is 48 percent off via Woot, which brings the price down to $1,298. That’s a savings of around $1,200 on the well-regarded OLED panel. There’s one major caveat. This deal is for today only, or until the stock runs out. To that end, there’s a limit of one per customer, but that’s probably not a huge deal unless you’re in the process of furnishing a mansion or something.



    The LG C3 OLED is considered one of the best TVs for gaming, and with good reason. We loved this television’s high contrast and the deep blacks on offer. We also praised the low input lag, increased motion response and wide array of appropriate viewing angles. It follows HDR guidelines, works with all the major VRR formats and has four HDMI 2.1 ports that are capable of outputting 4K 120Hz with a gaming console or PC.

    It supports all the major HDR standards, including Dolby Vision. This TV is available in sizes up to 83-inches, but the larger models aren’t on sale. I use a 65-inch OLED, though not this one, and it’s plenty big enough for TV and gaming.

    Despite being a dang good value, this isn’t a perfect television. The WOLED panel doesn’t get quite as bright as a QD-OLED like the Samsung S90C. Also, it doesn’t support a 144Hz refresh rate, which could be a dealbreaker to picky PC gamers. Still, the price is definitely right. Just make sure you pick this up sooner rather than later.

    Follow @EngadgetDeals on Twitter and subscribe to the Engadget Deals newsletter for the latest tech deals and buying advice.
    This article originally appeared on Engadget at https://www.engadget.com/the-65-inch-lg-c3-oled-tv-is-nearly-half-off-for-today-only-152153420.html?src=rss


OSnews

  • The bizarre secrets I found investigating corrupt Winamp skins
    In January of 2021 I was exploring the corpus of Skins I collected for the Winamp Skin Museum and found some that seemed corrupted, so I decided to explore them. Winamp skins are actually just zip files with a different file extension, so I tried extracting their files to see what I could find. This ended up leading me down a series of wild rabbit holes. ↫ Jordan Eldredge Im not going to spoil any of this.


  • Full-featured email server running OpenBSD
    This blog post is a guide explaining how to setup a full-featured email server on OpenBSD 7.5. It was commissioned by a customer of my consultancy who wanted it to be published on my blog. Setting up a modern email stack that does not appear as a spam platform to the world can be a daunting task, the guide will cover what you need for a secure, functional and low maintenance email system. ↫ Solène Rapenne If you ever wanted to set up and run your own email server, this is a great way to do it. Solène, an OpenBSD developer, will help you through setting up IMAP, POP, and Webmail, an SMTP server with server-to-server encryption and hidden personal information, every possible measure to make sure your server is regarded as legitimate, and all the usual firewall and anti-spam stuff you are definitely going to need. Taking back email from Google  or even Proton, which is now doing both machine learning and Bitcoin, of all things  is probably one of the most daunting tasks for anyone willing to cut ties with as much of big tech as possible. Not only is there the technical barrier, theres also the fact that the major email providers, like Gmail or whatever Microsoft offers these days, are trying their darnest to make self-hosting email as cumbersome as possible by trying to label everything you send as spam or downright malicious. Its definitely not an easy task, but at least with guides like this theres some set of easy steps to follow to get there.


  • OpenAI beta tests SearchGPT search engine
    Normally Im not that interested in reporting on news coming from OpenAI, but today is a little different  the company launched SearchGPT, a search engine thats supposed to rival Google, but at the same time, theyre also kind of not launching a search engine thats supposed to rival Google. What? We’re testing SearchGPT, a prototype of new search features designed to combine the strength of our AI models with information from the web to give you fast and timely answers with clear and relevant sources. We’re launching to a small group of users and publishers to get feedback. While this prototype is temporary, we plan to integrate the best of these features directly into ChatGPT in the future. If you’re interested in trying the prototype, sign up for the waitlist. ↫ OpenAI website Basically, before adding a more traditional web-search like feature set to ChatGPT, the company is first breaking them out into a separate, temporary product that users can test, before parts of it will be integrated into OpenAIs main ChatGPT product. Its an interesting approach, and with just how stupidly popular and hyped ChatGPT is, Im sure they wont have any issues assembling a large enough pool of testers. OpenAI claims SearchGPT will be different from, say, Google or AltaVista, by employing a conversation-style interface with real-time results from the web. Sources for search results will be clearly marked  good  and additional sources will be presented in a sidebar. True to the ChatGPT-style user interface, you can keep talking! after hitting a result to refine your search further. I may perhaps betray my still relatively modest age, but do people really want to talk! to a machine to search the web? Any time Ive ever used one of these chatbot-style user interfaces -including ChatGPT  I find them cumbersome and frustrating, like theyre just adding an obtuse layer between me and the computer, and that Id rather just be instructing the computer directly. Why try and verbally massage a stupid autocomplete into finding a link to an article I remember from a few days ago, instead of just typing in a few quick keywords? I am more than willing to concede Im just out of touch with what people really want, so maybe this really is the future of search. I hope I can just always disable nonsense like this and just throw keywords at the problem.


  • Two threads, one core: how simultaneous multithreading works under the hood
    Simultaneous multithreading (SMT) is a feature that lets a processor handle instructions from two different threads at the same time. But have you ever wondered how this actually works? How does the processor keep track of two threads and manage its resources between them? In this article, we’re going to break it all down. Understanding the nuts and bolts of SMT will help you decide if it’s a good fit for your production servers. Sometimes, SMT can turbocharge your systems performance, but in other cases, it might actually slow things down. Knowing the details will help you make the best choice. ↫ Abhinav Upadhyay Some light reading for the (almost) weekend.


  • Intel: Raptor Lake faults excessive voltage from microcode, fix coming in August
    In what started last year as a handful of reports about instability with Intels Raptor Lake desktop chips has, over the last several months, grown into a much larger saga. Facing their biggest client chip instability impediment in decades, Intel has been under increasing pressure to figure out the root cause of the issue and fix it, as claims of damaged chips have stacked up and rumors have swirled amidst the silence from Intel. But, at long last, it looks like Intels latest saga is about to reach its end, as today the company has announced that theyve found the cause of the issue, and will be rolling out a microcode fix next month to resolve it. ↫ Ryan Smith at AnandTech It turns out the root cause of the problem is elevated operating voltages!, caused by a buggy algorithm in Intels own microcode. As such, its at least fixable through a microcode update, which Intel says it will ship sometime mid-August. AnandTech, my one true source for proper reporting on things like this, is not entirely satisfied, though, as they state microcode is often used to just cover up the real root cause thats located much deeper inside the processor, and as such, Intels explanation doesnt actually tell us very much at all. Quite coincidentally, Intel also experienced a manufacturing flaw with a small batch of very early Raptor Lake processors. An oxidation manufacturing flaw! found its way into a small number of early Raptor Lake processors, but the company claims it was caught early and shouldnt be an issue any more. Of course, for anyone experiencing issues with their expensive Intel processors, this will linger in the back of their minds, too. Not exactly a flawless launch for Intel, but it seems its main only competitor, AMD, is also experiencing issues, as the company has delayed the launch of its new Ryzen 9000 chips due to quality issues. Im not at all qualified to make any relevant statements about this, but with the recent launch of the Snapdragon Elite X and Pro chips, these issues couldnt come at a worse time for Intel and AMD.


  • FreeBSD as a platform for your future technology
    Choosing an operating system for new technology can be crucial for the success of any project. Years down the road, this decision will continue to inform the speed and efficiency of development.`But should you build the infrastructure yourself or rely on a proven system? When faced with this decision, many companies have chosen, and continue to choose, FreeBSD. Few operating systems offer the immediate high performance and security of FreeBSD, areas where new technologies typically struggle. Having a stable and secure development platform reduces upfront costs and development time. The combination of stability, security, and high performance has led to the adoption of FreeBSD in a wide range of applications and industries. This is true for new startups and larger established companies such as Sony, Netflix, and Nintendo. FreeBSD continues to be a dependable ecosystem and an industry-leading platform. ↫ FreeBSD Foundation A FreeBSD marketing document highlighting FreeBSDs strengths is, of course, hardly a surprise, but considering its fighting what you could generously call an uphill battle against the dominance of Linux, its still interesting to see what, exactly, FreeBSD highlights as its strengths. It should come as no surprise that its licensing model  the simple BSD license  is mentioned first and foremost, since its a less cumbersome license to deal with than something like the GPL. Its philosophical debate we wont be concluding any time soon, but the point still stands. FreeBSD also highlights that its apparently quite easy to upstream changes to FreeBSD, making sure that changes benefit everyone who uses FreeBSD. While I cant vouch for this, it does seem reasonable to assume that its easier to deal with the integrated, one-stop-shop that is FreeBSD, compared to the hodge-podge of hundreds and thousands of groups whose software all together make up a Linux system. Like I said, this is a marketing document so do keep that in mind, but I still found it interesting.


  • You can contribute to KDE with non-C++ code
    Not everything made by KDE uses C++. This is probably obvious to some people, but it’s worth mentioning nevertheless. And I don’t mean this as just “well duh, KDE uses QtQuick which is written with C++ and QML”. I also don’t mean this as “well duh, Qt has a lot of bindings to other languages”. I mean explicitly “KDE has tools written primarily in certain languages and specialized formats”. ↫ Thiago Sueto If you ever wanted to contribute to KDE but werent sure if your preferred programming language or tools were relevant, this is a great blog post detailing how you can contribute if you are familiar with any of the following: Python, Ruby, Perl, Containerfile/Docker/Podman, HTML/SCSS/JavaScript, Web Assembly, Flatpak/Snap, CMake, Java, and Rust. A complex, large project like KDE needs people with a wide variety of skills, so its definitely not just C++. An excellent place to start.


  • New Samsung phones block sideloading by default
    The assault on a users freedom to install whatever they want on what is supposed to be their phone continues. This time, its Samsung adding an additional blocker to users installing applications from outside the Play Store and its own mostly useless Galaxy Store. Technically, Android already blocks sideloading by default at an operating system level. The permission that’s needed to silently install new apps without prompting the user, INSTALL_PACKAGES, can only be granted to preinstalled app stores like the Google Play Store, and it’s granted automatically to apps that request it. The permission that most third-party app stores end up using, REQUEST_INSTALL_PACKAGES, has to be granted explicitly by the user. Even then, Android will prompt the user every time an app with this permission tries to install a new app. Samsung’s Auto Blocker feature takes things a bit further. The feature, first introduced in One UI 6.0, fully blocks the installation of apps from unauthorized sources, even if those sources were granted the REQUEST_INSTALL_PACKAGES permission. ↫ Mishaal Rahman Im not entirely sure why Samsung felt the need to add an additional, Samsung-specific blocking mechanism, but at least for now, you can turn it off in the Settings application. This means that in order to install an application from outside of the Play Store and the Galaxy Store on brand new Samsung phones  the ones shipping with OneUI 6.1.1  you need to both give the regular Android permission to do so, but also turn off this nag feature. Having two variants of every application on your Samsung phone wasnt enough, apparently.


  • Google wont be deprecating third-party cookies from Chrome after all
    This story just never ever ends. After delays, changes in plans, more delays, we now have more changed plans. After years of stalling, Google has now announced it is, in fact, not going to deprecate third-party cookies in Chrome by default. In light of this, we are proposing an updated approach that elevates user choice. Instead of deprecating third-party cookies, we would introduce a new experience in Chrome that lets people make an informed choice that applies across their web browsing, and they’d be able to adjust that choice at any time. Were discussing this new path with regulators, and will engage with the industry as we roll this out. ↫ Anthony Chavez Google remains unclear about what, exactly, users will be able to choose between. The consensus seems to be that users will be able to choose between retaining third-party cookies and turning them off, but thats based on a statement by the British Competition and Market Authority, and not on a statement from Google itself. It seems reasonable to assume the CMA knows what its talking about, but with a company like Google you never know whats going to happen tomorrow, let alone a few months from now. While both Safari and Firefox have already made this move ages ago, its taking Google and Chrome a lot longer to deal with this issue, because Google needs to find different ways of tracking you that are not using third-party cookies. Googles own testing with Privacy Sandbox, Chromes sarcastically-named alternative to third-party cookies, shows that it seems to perform reasonable well, which should definitely raise some alarm bells about just how private it really is. Regardless, I doubt this saga will be over any time soon.


  • No, Southwest Airlines is not still using Windows 3.1
    A story thats been persistently making the rounds since the CrowdStrike event is that while several airline companies were affected in one way or another, Southwest Airlines escaped the mayhem because they were still using windows 3.1. Its a great story that fits the current zeitgeist about technology and its role in society, underlining that what is claimed to be technological progress is nothing but trouble, and that its better to stick with the old. At the same time, anybody who dislikes Southwest Airlines can point and laugh at the bumbling idiots working there for still using Windows 3.1. Its like a perfect storm of technology news click and ragebait. Too bad the whole story is nonsense. But how could that be? Its widely reported by reputable news websites all over the world, shared on social media like a strain of the common cold, and nobody seems to question it or doubt the veracity of the story. It seems that Southwest Airlines running on an operating system from 1992 is a perfectly believable story to just about everyone, so nobody is questioning it or wondering if its actually true. Well, I did, and no, its not true. Lets start with the actual source of the claim that Southwest Airlines was unaffected by CrowdStrike because theyre still using Windows 3.11 for large parts of their primary systems. This claim is easily traced back to its origin  a tweet by someone called Artem Russakovskii, stating that the reason Southwest is not affected is because they still run on Windows 3.1!. This tweet formed the basis for virtually all of the stories, but it contains no sources, no links, no background information, nothing. It was literally just this one line. It turned out be a troll tweet. A reply to the tweet by Russakovskii a day later made that very lear: To be clear, I was trolling last night, but it turned out to be true. Some Southwest systems apparently do run Windows 3.1. lol.! However, that linked article doesnt cite any sources either, so were right back where we started. After quite a bit of digging  that is, clicking a few links and like 3 minutes of searching online  following the various reference and links back to their sources, I managed to find where all these stories actually come from to arrive at the root claim that spawned all these other claims. Its from an article by The Dallas Morning News, titled What’s the problem with Southwest Airlines scheduling system?! At the end of last year, Southwest Airlines scheduling system had a major meltdown, leading to a lot of cancelled flights and stranded travelers just around the Christmas holidays. Of course, the media wanted to know what caused it, and thats where this The Dallas Morning News article comes from. In it, we find the paragraphs that started the story that Southwest Airlines is still using Windows 3.1 (and Windows 95!): Southwest uses internally built and maintained systems called SkySolver and Crew Web Access for pilots and flight attendants. They can sign on to those systems to pick flights and then make changes when flights are canceled or delayed or when there is an illness. “Southwest has generated systems internally themselves instead of using more standard programs that others have used,” Montgomery said. “Some systems even look historic like they were designed on Windows 95.” SkySolver and Crew Web Access are both available as mobile apps, but those systems often break down during even mild weather events, and employees end up making phone calls to Southwest’s crew scheduling help desk to find better routes. During periods of heavy operational trouble, the system gets bogged down with too much demand. ↫ Kyle Arnold at The Dallas Morning News Thats it. Thats where all these stories can trace their origin to. These few paragraphs do not say that Southwest is still using ancient Windows versions; it just states that the systems they developed internally, SkySolver and Crew Web Access, look historic like they were designed on Windows 95!. The fact that they are also available as mobile applications should further make it clear that no, these applications are not running on Windows 3.1 or Windows 95. Southwest pilots and cabin crews are definitely not carrying around pocket laptops from the 90s. These paragraphs were then misread, misunderstood, and mangled in a game of social media and bad reporting telephone, and here we are. The fact that nobody seems to have taken the time to click through a few links to find the supposed source of these claims, instead focusing on cashing in on the clicks and rage these stories would illicit, is a rather damning indictment of the state of online (tech) media. Many of the websites reporting on these stories are part of giant media conglomerates, have a massive number of paid staff, and theyre being outdone by a dude in the Arctic with a small Patreon, minimal journalism training, and some common sense. This story wasnt hard to debunk  a few clicks and a few minutes of online searching is all it took. Ask yourself  why do these massive news websites not even perform the bare minimum?



Linux Journal News

  • New 'Mirrored' Network Mode Introduced in Windows Subsystem for Linux

    Microsoft's Windows Subsystem for Linux (WSL) continues to evolve with the release of WSL 2 version 0.0.2. This update introduces a set of opt-in preview features designed to enhance performance and compatibility.

    Key additions include "Automatic memory reclaim" which dynamically optimizes WSL's memory footprint, and "Sparse VHD" to shrink the size of the virtual hard disk file. These improvements aim to streamline resource usage.

    Additionally, a new "mirrored networking mode" brings expanded networking capabilities like IPv6 and multicast support. Microsoft claims this will improve VPN and LAN connectivity from both the Windows host and Linux guest. 

    Complementing this is a new "DNS Tunneling" feature that changes how DNS queries are resolved to avoid compatibility issues with certain network setups. According to Microsoft, this should reduce problems connecting to the internet or local network resources within WSL.

    Advanced firewall configuration options are also now available through Hyper-V integration. The new "autoProxy" feature ensures WSL seamlessly utilizes the Windows system proxy configuration.

    Microsoft states these features are currently rolling out to Windows Insiders running Windows 11 22H2 Build 22621.2359 or later. They remain opt-in previews to allow testing before final integration into WSL.

    By expanding WSL 2 with compelling new capabilities in areas like resource efficiency, networking, and security, Microsoft aims to make Linux on Windows more performant and compatible. This evolutionary approach based on user feedback highlights Microsoft's commitment to WSL as a key part of the Windows ecosystem.
    Windows


  • Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in Attacks on Government Entities

    The threat actor Earth Lusca, linked to Chinese state-sponsored hacking groups, has been observed utilizing a new Linux backdoor dubbed SprySOCKS to target government organizations globally. 

    As initially reported in January 2022 by Trend Micro, Earth Lusca has been active since at least 2021 conducting cyber espionage campaigns against public and private sector targets in Asia, Australia, Europe, and North America. Their tactics include spear-phishing and watering hole attacks to gain initial access. Some of Earth Lusca's activities overlap with another Chinese threat cluster known as RedHotel.

    In new research, Trend Micro reveals Earth Lusca remains highly active, even expanding operations in the first half of 2023. Primary victims are government departments focused on foreign affairs, technology, and telecommunications. Attacks concentrate in Southeast Asia, Central Asia, and the Balkans regions. 

    After breaching internet-facing systems by exploiting flaws in Fortinet, GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca uses web shells and Cobalt Strike to move laterally. Their goal is exfiltrating documents and credentials, while also installing additional backdoors like ShadowPad and Winnti for long-term spying.

    The Command and Control server delivering Cobalt Strike was also found hosting SprySOCKS - an advanced backdoor not previously publicly reported. With roots in the Windows malware Trochilus, SprySOCKS contains reconnaissance, remote shell, proxy, and file operation capabilities. It communicates over TCP mimicking patterns used by a Windows trojan called RedLeaves, itself built on Trochilus.

    At least two SprySOCKS versions have been identified, indicating ongoing development. This novel Linux backdoor deployed by Earth Lusca highlights the increasing sophistication of Chinese state-sponsored threats. Robust patching, access controls, monitoring for unusual activities, and other proactive defenses remain essential to counter this advanced malware.

    The Trend Micro researchers emphasize that organizations must minimize attack surfaces, regularly update systems, and ensure robust security hygiene to interrupt the tactics, techniques, and procedures of relentless threat groups like Earth Lusca.
    Security


  • Linux Kernel Faces Reduction in Long-Term Support Due to Maintenance Challenges

    The Linux kernel is undergoing major changes that will shape its future development and adoption, according to Jonathan Corbet, Linux kernel developer and executive editor of Linux Weekly News. Speaking at the Open Source Summit Europe, Corbet provided an update on the latest Linux kernel developments and a glimpse of what's to come.

    A major change on the horizon is a reduction in long-term support (LTS) for kernel versions from six years to just two years. Corbet explained that maintaining old kernel branches indefinitely is unsustainable and most users have migrated to newer versions, so there's little point in continuing six years of support. While some may grumble about shortened support lifecycles, the reality is that constantly backporting fixes to ancient kernels strains maintainers.

    This maintainer burnout poses a serious threat, as Corbet highlighted. Maintaining Linux is largely a volunteer effort, with only about 200 of the 2,000+ developers paid for their contributions. The endless demands on maintainers' time from fuzz testing, fixing minor bugs, and reviewing contributions takes a toll. Prominent maintainers have warned they need help to avoid collapse. Companies relying on Linux must realize giving back financially is in their interest to sustain this vital ecosystem. 

    The Linux kernel is also wading into waters new with the introduction of Rust code. While Rust solves many problems, it also introduces new complexities around language integration, evolving standards, and maintainer expertise. Corbet believes Rust will pass the point of no return when core features depend on it, which may occur soon with additions like Apple M1 GPU drivers. Despite skepticism in some corners, Rust's benefits likely outweigh any transition costs.

    On the distro front, Red Hat's decision to restrict RHEL cloning sparked community backlash. While business considerations were at play, Corbet noted technical factors too. Using older kernels with backported fixes, as RHEL does, risks creating divergent, vendor-specific branches. The Android model of tracking mainline kernel dev more closely has shown security benefits. Ultimately, Linux works best when aligned with the broader community.

    In closing, Corbet recalled the saying "Linux is free like a puppy is free." Using open source seems easy at first, but sustaining it long-term requires significant care and feeding. As Linux is incorporated into more critical systems, that maintenance becomes ever more crucial. The kernel changes ahead are aimed at keeping Linux healthy and vibrant for the next generation of users, businesses, and developers.
    kernel


  • Linux Celebrates 32 Years with the Release of 6.6-rc2 Version

    Today marks the 32nd anniversary of Linus Torvalds introducing the inaugural Linux 0.01 kernel version, and celebrating this milestone, Torvalds has launched the Linux 6.6-rc2. Among the noteworthy updates are the inclusion of a feature catering to the ASUS ROG Flow X16 tablet's mode handling and the renaming of the new GenPD subsystem to pmdomain.

    The Linux 6.6 edition is progressing well, brimming with exciting new features that promise to enhance user experience. Early benchmarks are indicating promising results, especially on high-core-count servers, pointing to a potentially robust and efficient update in the Linux series.

    Here is what Linus Torvalds had to say in today's announcement:
    Another week, another -rc.I think the most notable thing about 6.6-rc2 is simply that it'sexactly 32 years to the day since the 0.01 release. And that's a roundnumber if you are a computer person.Because other than the random date, I don't see anything that reallystands out here. We've got random fixes all over, and none of it looksparticularly strange. The genpd -> pmdomain rename shows up in thediffstat, but there's no actual code changes involved (make sure touse "git diff -M" to see them as zero-line renames).And other than that, things look very normal. Sure, the architecturefixes happen to be mostly parisc this week, which isn't exactly theusual pattern, but it's also not exactly a huge amount of changes.Most of the (small) changes here are in drivers, with some tracingfixes and just random things. The shortlog below is short enough toscroll through and get a taste of what's been going on. Linus Torvalds


  • Introducing Bavarder: A User-Friendly Linux Desktop App for Quick ChatGPT Interaction

    Want to interact with ChatGPT from your Linux desktop without using a web browser?

    Bavarder, a new app, allows you to do just that.

    Developed with Python and GTK4/libadwaita, Bavarder offers a simple concept: pose a question to ChatGPT, receive a response, and promptly copy the answer (or your inquiry) to the clipboard for pasting elsewhere.

    With an incredibly user-friendly interface, you won't require AI expertise (or a novice blogger) to comprehend it. Type your question in the top box, click the blue send button, and wait for a generated response to appear at the bottom. You can edit or modify your message and repeat the process as needed.

    During our evaluation, Bavarder employed BAI Chat, a GPT-3.5/ChatGPT API-based chatbot that's free and doesn't require signups or API keys. Future app versions will incorporate support for alternative backends, such as ChatGPT 4 and Hugging Chat, and allow users to input an API key to utilize ChatGPT3.

    At present, there's no option to regenerate a response (though you can resend the same question for a potentially different answer). Due to the lack of a "conversation" view, tracking a dialogue or following up on answers can be challenging — but Bavarder excels for rapid-fire questions.

    As with any AI, standard disclaimers apply. Responses might seem plausible but could contain inaccurate or false information. Additionally, it's relatively easy to lead these models into irrational loops, like convincing them that 2 + 2 equals 106 — so stay alert!

    Overall, Bavarder is an attractive app with a well-defined purpose. If you enjoy ChatGPT and similar technologies, it's worth exploring.
    ChatGPT AI


  • LibreOffice 7.5.3 Released: Third Maintenance Update Brings 119 Bug Fixes to Popular Open-Source Office Suite

    Today, The Document Foundation unveiled the release and widespread availability of LibreOffice 7.5.3, which serves as the third maintenance update to the current LibreOffice 7.5 open-source and complimentary office suite series.

    Approximately five weeks after the launch of LibreOffice 7.5.2, LibreOffice 7.5.3 arrives with a new set of bug fixes for those who have successfully updated their GNU/Linux system to the LibreOffice 7.5 series.

    LibreOffice 7.5.3 addresses a total of 119 bugs identified by users or uncovered by LibreOffice developers. For a more comprehensive understanding of these bug fixes, consult the RC1 and RC2 changelogs.

    You can download LibreOffice 7.5.3 directly from the LibreOffice websiteor from SourceForge as binary installers for DEB or RPM-based GNU/Linux distributions. A source tarball is also accessible for individuals who prefer to compile the software from sources or for system integrators.

    All users operating the LibreOffice 7.5 office suite series should promptly update their installations to the new point release, which will soon appear in the stable software repositories of your GNU/Linux distributions.

    In early February 2023, LibreOffice 7.5 debuted as a substantial upgrade to the widely-used open-source office suite, introducing numerous features and improvements. These enhancements encompass major upgrades to dark mode support, new application and MIME-type icons, a refined Single Toolbar UI, enhanced PDF Export, and more.

    Seven maintenance updates will support LibreOffice 7.5 until November 30th, 2023. The next point release, LibreOffice 7.5.4, is scheduled for early June and will include additional bug fixes.

    The Document Foundation once again emphasizes that the LibreOffice office suite's "Community" edition is maintained by volunteers and members of the Open Source community. For enterprise implementations, they suggest using the LibreOffice Enterprise family of applications from ecosystem partners.
    LibreOffice


  • Raspberry Pi OS Debuts New Version Featuring Linux Kernel 6.1, Improved Performance, and App Updates

    Today, the Raspberry Pi Foundation unveiled a fresh edition of their official Raspberry Pi OS distribution tailored for Raspberry Pi computers, featuring component updates, bug fixes, and several performance enhancements.

    The most significant alteration in the Raspberry Pi OS 2023-05-03 release is the transition from the long-term supported Linux 5.15 LTS kernel to the long-term supported Linux 6.1 LTS kernel. This shift is expected to boost the performance of Raspberry Pi devices.

    Indeed, current Raspberry Pi OS users, like myself, were already utilizing the Linux 6.1 LTS kernel when executing the rpi-update command via a terminal emulator. However, Linux 6.1 LTS is now the standard kernel in new Raspberry Pi OS images, available for download from the official website for those planning to install it on their Raspberry Pi computer.

    Various applications have received updates in this new Raspberry Pi OS version. The most notable is Chromium 113, the default browser for Raspberry Pi OS. In addition to incorporating the latest security patches, Chromium 113 introduces WebGPU support by default, potentially enhancing the performance of web apps and overall browsing experience.

    Other updates include Raspberry Pi Imager 1.7.4, RealVNC Viewer 7.0.1.48981, RealVNC Server 7.0.1.49073, Mathematica 13.2.1, and Matlab 23.1.0. Another intriguing update is the revised VLC hardware acceleration patch, designed to enhance video playback performance.

    The libcamera and libcamera-apps elements have also been updated to refine IMX296 sensor tuning, enhance audio resampling and encoding management using the libav library, boost the performance of Qt preview window rendering, optimize thumbnail rendering, support 16-bit Bayer in the DNG writer, manage generalized statistics, and rectify an overflow problem that caused inaccurate calculations in the AGC algorithm.

    The picamera2 library has also been updated, incorporating an MJPEG server example that utilizes the hardware MJPEG encoder, an example showcasing a preview from two cameras within a single Qt app, the capacity for the H.264 encoder to accept frame time intervals for SPS headers, promote the correct profile/level, and support constant quality parameters, as well as introduce new Exif DateTime and DateTimeOriginal tags.

    Several bugs were addressed, including an occasional segfault in the CPU temperature plugin, an X11 server crash when altering screen orientation, X11 server DPMS malfunctions, and the addition of new language translations.
    kernel


  • Debian 11.7 Released: Seventh ISO Update Brings Enhanced Security and Bug Fixes to "Bullseye" Operating System Series

    The Debian Project has unveiled the release and widespread availability of Debian 11.7, serving as the seventh ISO update to the current Debian GNU/Linux 11 "Bullseye" operating system series.

    Arriving approximately four and a half months after Debian 11.6, Debian 11.7 delivers updated installation media for those seeking to install the Debian GNU/Linux 11 "Bullseye" operating system series on new computers. This ensures that users won't need to download numerous updates from repositories following installation.

    Debian 11.7 incorporates all security and software updates from December 17th, 2022, the release date of Debian GNU/Linux 11.6, up until today. In total, Debian 11.7 consists of 102 security updates and various bug fixes for 92 packages.

    For more information on these security updates and bug fixes, consult the release announcement. The Debian Project emphasizes that this Debian Bullseye point release does not represent a new version of Debian GNU/Linux 11 but merely updates certain included packages.

    The Debian 11.7 installation images can be downloaded from the Debian website or via this direct link for 64-bit (amd64), 32-bit (i386), PowerPC 64-bit Little Endian (ppc64el), IBM System z (s390x), MIPS 64-bit Little Endian (mips64el), MIPS 32-bit Little Endian (mipsel), MIPS, Armel, ARMhf, and AArch64 (arm64) hardware architectures.

    Debian 11.7 live images, pre-installed with the KDE Plasma, GNOME, Xfce, LXQt, LXDE, Cinnamon, and MATE desktop environments, can also be downloaded from the aforementioned link, but only for 64-bit and 32-bit systems.

    Current Debian GNU/Linux 11 "Bullseye" users do not need to download these new ISO images to maintain up-to-date installations. Instead, they should regularly execute the sudo apt update && sudo apt full-upgrade commands in a terminal emulator.
    Debian


  • What’s New in Debian 11 “Bullseye”?
    Image
    Debian is a preferred choice of millions of Linux users for some of the most popular and powerful operating systems, like Ubuntu and its derivatives are based on Debian.
    Debian 11has finally been released, finally, after a long development work of two years. Bullseye – that’s the name given to this latest Debian Linux distro. So what are the updates and upgrades? In this article, let’s check out what’s new in Debian 11.
    Debian 11’s ArchitectureDebian supports a good range of hardware architectures. 
    Supported Architectures
    ARM EABI (armel) ARMv7 (EABI hard-float ABI and armhf) 64-bit ARM (arm64) 32-bit PC (i386) 64-bit PC (amd64) Little-endian MIPS (mipsel) 64-bit little-endian PowerPC 64-bit little-endian MIPS IBM System z (s390x)Not Supported Hardware
    Old MIPS 32-bit CPUsLinux Kernel InformationDebian 11 supports the Linux Kernel 5.10 LTS. Debian 10 Buster, the earlier version to Debian 11, used Linux Kernel 4.19 while released. A newer kernel means a new set of bug fixes, new hardware support, and improved performance.
    This is the perfect kernel for Debian bullseye considering the Debian lifecycle.   
    Supports exFATexFAT is the shortened form of the Extensible File Allocation Table. It’s a filesystem used for flash memory, such as SD cards and USB flash drives.
    Now Debian 11 provides support for the exFAT. For mounting the exFAT filesystem, you don’t need the filesystem-in-userspace implementation provided by the exfat-fuse package additionally anymore. Thanks to kernel 5.10! exFAT comes in handy with it. Tools for checking and creating an exFAT are given in the exfatprogs package.
    Bauhaus Movement Inspired Theme & WallpaperDebian features cool wallpapers and a default theme for each of the major releases. Debian 11’s theme is inspired by the Bauhaus movement. Bauhaus means “building house” and it was an art and design movement from 20th century Germany. The Bauhaus movement revolved around abstract, geometric style featuring little emotion or sentiments. 
    Its modern aesthetic still is immensely influential for designers, architects, and artists. You can see this theme all through Debian 11 whether it’s the installer, login window, or the Grub menu.
    Newer Desktop Environment VersionsDebian 11 offers newer desktop environment versions. Desktop flavors you get here are, KDE Plasma 5.20, GNOME 3.38, LXDE 11, LXQt 0.16, Xfce 4.16, and MATE 1.24. Debian prefers stability and it’s quite clear from the desktop environments. You might not get the latest cutting-edge distributions like Fedora or Arch/Manjaro.
    Updated PackagesDebian 11 consists of more than 11,294 new packages out of 59,551 packages. It also reduced over 9,519 “obsolete” packages and removed 42,821 that were updated. A total of 5,434 packages remained as they were.
    A good number of software applications and package updates are included in Debian bullseye, such as Apache 2.4.48, Calligra 3.2, Emacs 27.1, LibreOffice 7.0, Inkscape 1.0.2, Linux kernel 5.10 series, Perl 5.32, PHP 7.4, Vim 8.2, PostgreSQL 13, and the list goes on. All these ready-to-use software packages are built with over 30,000 source packages.
    With this huge selection of packages and wide architecture support, Debian has always stayed committed to its aim of being The Universal Operating System.
    Improved Printer and Scanner FeaturesDebian 11 presents a new ipp-usb package. It is built with a vendor-neutral IPP-over-USB protocol that is supported by many latest printers. So, many modern-day printers will be supported now by Debian. And you won’t need the drivers for that.
    SANE driverless backend lets you use scanners without any trouble.
    EndnotesWant to try Debian Bullseye? Get it from here. You can also check “bullseye” with Live Images without installing it on your PC. This will load and run the entire OS in read-only mode. These live images are available for the i386 and amd64 architectures in the form of USB sticks, DVDs, and netboot setups. Debian Live has a standard image. So you can try a basic Debian without any GUIs.
    And that’s the ending of this article. Hope you find our Debian 11 guide helpful.
    #Linux Debian News


  • Nvidia Linux drivers causing random hard crashes and now a major security risk still not fixed after 5+ months
    Image The recent fiasco with Nvidia trying to block Hardware Unboxed from future GPU review samples for the content of their review is one example of how they choose to play this game. This hatred is not only shared by reviewers, but also developers and especially Linux users.
    The infamous Torvalds videos still traverse the web today as Nvidia conjures up another evil plan to suck up more of your money and market share. This is not just one off shoot case; oh how much I wish it was. I just want my computer to work.
    If anyone has used Sway-WM with an Nvidia GPU I’m sure they would remember the –my-next-gpu-wont-be-nvidia option.
    These are a few examples of many.
    The Nvidia Linux drivers have never been good but whatever has been happening at Nvidia for the past decade has to stop today. The topic in question today is this bug: [https://forums.developer.nvidia.com/t/bug-report-455-23-04-kernel-panic-due-to-null-pointer-dereference]
    This bug causes hard irrecoverable crashes from driver 440+. This issue is still happening 5+ months later with no end in sight. At first users could work around this by using an older DKMS driver along with a LTS kernel. However today this is no longer possible. Many distributions of Linux are now dropping the old kernels. DKMS cannot build. The users are now FORCED with this “choice”:
    {Use an older driver and risk security implications} or {“use” the new drivers that cause random irrecoverable crashes.}
    This issue is only going to get more and more prevalent as the kernel is a core dependency by definition. This is just another example of the implications of an unsafe older kernel causing issue for users: https://archlinux.org/news/moving-to-zstandard-images-by-default-on-mkinitcpio/
    If you use Linux or care about the implications of a GPU monopoly, consider AMD. Nvidia is already rearing its ugly head and AMD is actually putting up a fight this year.
    #Linux NVIDIA News


Linux Magazine News (path: lmi_news)






  • Linux Mint 22 Stable Delayed
    If you're anxious about getting your hands on the stable release of Linux Mint 22, it looks as if you're going to have to wait a bit longer.






Page last modified on November 17, 2022, at 06:39 PM