Recent Changes - Search:
NTLUG

Linux is free.
Life is good.

Linux Training
10am on Meeting Days!

1825 Monetary Lane Suite #104 Carrollton, TX

Do a presentation at NTLUG.

What is the Linux Installation Project?

Real companies using Linux!

Not just for business anymore.

Providing ready to run platforms on Linux

Show Descriptions... (Show All) (Two Column)

LinuxSecurity - Security Advisories







LWN.net

  • Kernel prepatch 6.19-rc1
    Linus has released 6.19-rc1, perhaps a bitearlier than expected.
    So it's Sunday afternoon in the part of the world where I am now, so if somebody was looking at trying to limbo under the merge window timing with one last pull request and is taken by surprise by the slightly unusual timing of the rc1 release, that failed.
    Teaching moment, or random capricious acts? You be the judge.


  • Conill: Rethinking sudo with object capabilities
    Ariadne Conill isexploring a capability-based approach to privilege escalation on Linuxsystems.
    Inspired by the object-capability model, I've been working on a project named capsudo. Instead of treating privilege escalation as a temporary change of identity, capsudo reframes it as a mediated interaction with a service called capsudod that holds specific authority, which may range from full root privileges to a narrowly scoped set of capabilities depending on how it is deployed.


  • [$] The state of the kernel Rust experiment
    The ability to write kernel code in Rust was explicitly added as anexperiment — if things did not go well, Rust would be removed again. Atthe 2025 Maintainers Summit, a session was held to evaluate the state ofthat experiment, and to decide whether the time had come to declare theresult to be a success. The (arguably unsurprising) conclusion was thatthe experiment is indeed a success, but there were some interesting pointsmade along the way.


  • Three new stable kernels
    Greg Kroah-Hartman has released the 6.18.1, 6.17.12, and 6.12.62 stablekernels. Each contains important fixes; users of those kernelsare advised to upgrade.


  • [$] Best practices for linux-next
    One of the key components in the kernel's development process is thelinux-next repository. Every day, a large number of branches, eachcontaining commits intended for the next kernel development cycle, ispulled into linux-next and integrated. If there are conflicts betweenbranches, the linux-next process will reveal them. In theory, many othertypes of problems can be found as well. Some developers feel thatlinux-next does not work as well as it could, though. At the 2025Maintainers Summit, Mark Brown, who helps to keep linux-next going, led asession on how it could be made to work more effectively.


  • KDE Gear 25.12 released
    KDE has announced therelease of KDE Gear 25.12. This release adds more"extractors" to the Itinerary travel-assistantapplication, improved Git support in the Kate text editor, better PDFexport in Konqueror, andmuch more. See the changelogfor all new features, improvements, and bug fixes.



  • Security updates for Friday
    Security updates have been issued by AlmaLinux (firefox, luksmeta, mysql, mysql:8.0, mysql:8.4, tomcat, and wireshark), Debian (chromium, kernel, and tzdata), Fedora (brotli, dr_libs, perl-Alien-Brotli, python-urllib3, singularity-ce, wireshark, and yarnpkg), Oracle (firefox, grafana, lasso, libsoup3, luksmeta, ruby, ruby:3.3, tomcat, and wireshark), Slackware (mozilla), SUSE (container-suseconnect, kubernetes-client, libpoppler-cpp2, postgresql14, postgresql15, and python3), and Ubuntu (c-ares, keystone, linux, linux-aws, linux-aws-5.15, linux-azure, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-oracle-5.15, linux-xilinx-zynqmp, linux-azure, linux-azure-4.15, linux-oracle,, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-hwe-6.8, linux-oracle-6.8, linux-raspi, linux-realtime, linux-intel-iot-realtime, and python-urllib3).


  • Pop!_OS 24.04 LTS released
    Version 24.04 LTS of the Ubuntu-based Pop!_OS distribution hasbeen released with the COSMIC Desktop Environment:

    Today is special not only in that it's the culmination of overthree years of work, but even more so in that System76 has built acomplete desktop environment for the open source community. We'reproud of this contribution to the open source ecosystem. COSMIC isbuilt on the ethos that the best open source projects enable people tonot only use them, but to build with them. COSMIC is modular andcomposable. It's the flagship experience for Pop!_OS in its own way,and can be adapted by anyone that wants to build their own unique userexperience for Linux.

    In addition to the COSMIC desktop environment, Pop!_OS is nowavailable for Arm computers with the 24.04 LTS release, and thedistribution has added hybrid graphics support for better batterylife. LWN covered analpha version of COSMIC in August 2024.



  • Rust 1.92.0 released
    Version1.92.0 of Rust has been released. This release includes a numberof stabilized APIs, emits unwind tables by default on Linux, validatesinput to #[macro_export], and much more. See the separaterelease notes for Rust,Cargo,and Clippy.



  • [$] Toward a policy for machine-learning tools in kernel development
    The first topic of discussion at the 2025 Maintainers Summit has been inthe air for a while: what role — if any — should machine-learning-basedtools have in the kernel development process? While there has been a fairamount of controversy around these tools, and concerns remain, it seemsthat the kernel community, or at least its high-level maintainership, iscomfortable with these tools becoming a significant part of the developmentprocess.


  • Security updates for Thursday
    Security updates have been issued by Debian (ffmpeg, firefox-esr, libsndfile, and rear), Fedora (httpd, perl-CGI-Simple, and tinyproxy), Oracle (firefox, kernel, libsoup, mysql8.4, tigervnc, tomcat, tomcat9, and uek-kernel), SUSE (alloy, curl, dovecot24, fontforge, glib2, himmelblau, java-17-openjdk, java-21-openjdk, kernel, krb5, lasso, libvirt, mozjs128, mysql-connector-java, nvidia-open-driver-G07-signed-check, openssh, poppler, postgresql17, postgresql18, python-cbor2, python-Django, python310, python311-Django, runc, strongswan, tomcat11, and xwayland), and Ubuntu (binutils, libpng1.6, linux, linux-aws, linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-6.14, linux-gcp, linux-hwe-6.14, linux-raspi, linux, linux-aws, linux-gcp, linux-realtime, and qtbase-opensource-src).


  • [$] LWN.net Weekly Edition for December 11, 2025
    Inside this week's LWN.net Weekly Edition:
    Front: Rust in CPython; Python frozendict; Bazzite; IETF post-quantum disagreement; Distrobox; 6.19 merge window; Leaving the TAB. Briefs: Let's Encrypt retrospective; PKI infrastructure; Rust in kernel to stay; CNA series; Alpine 3.23.0; cmocka 2.0; Firefox 146; 2024 Free Software Awards; Quotes; ... Announcements: Newsletters, conferences, security updates, patches, and more.


  • 10 Years of Let's Encrypt Certificates
    Let's Encrypt has publisheda retrospective that covers the decade since it published its firstpublicly trusted certificate in September 2015:
    In March 2016, we issued our one millionth certificate. Just two yearslater, in September 2018, we were issuing a million certificates everyday. In 2020 we reached a billion total certificates issued and as oflate 2025 we're frequently issuing ten million certificates perday. We're now on track to reach a billion active sites, probablysometime in the coming year.


  • Kroah-Hartman: Linux CVEs, more than you ever wanted to know
    Greg Kroah-Hartman is writinga series of blog posts about Linux becoming a CertificateNumbering Authority (CNA):

    It's been almost 2 full years since Linux became a CNA (CertificateNumbering Authority) which meant that we (i.e. the kernel.orgcommunity) are now responsible for issuing all CVEs for the Linuxkernel. During this time, we've become one of the largest creators ofCVEs by quantity, going from nothing to number 3 in 2024 to number 1in 2025. Naturally, this has caused some questions about how we areboth doing all of this work, and how people can keep track of it.

    So far, Kroah-Hartman has published the introductory post, as wellas a detailedpost about kernel version numbers that is well worth reading.



  • [$] Mix and match Linux distributions with Distrobox
    Linux containers have made it reasonably easy to develop, distribute, anddeploy server applications along with all the distribution dependencies that theyneed. For example, anyone can deploy and run a Debian-based PostgreSQL container on a Fedora Linux host. Distrobox is a project that is designed tobring the cross-distribution compatibility to the desktop and allow users tomix-and-match Linux distributions without fussing with dual-booting, virtualmachines, or multiple computers. It is an ideal way to installadditional software on image-based systems, such as Fedora's Atomic Desktopsor Bazzite, and alsoprovides a convenient way to move a development environment orfavorite applications to a new system.


LXer Linux News


  • HealthyPi 6 provides open-source biosignal acquisition for research and education
    The HealthyPi 6 is an open-source biosignal acquisition platform available through Crowd Supply, targeting academic research, education, and digital health prototyping. The system supports standalone acquisition and visualization of physiological data without relying on a PC or cloud service. The platform is built around a tri-core processing architecture. The main controller is STMicroelectronics’ STM32H757, combining […]


  • TrixiePup64 11.2 Released For Debian-Based Puppy Linux With Wayland & X11 Options
    For those with fond memories of the original Puppy Linux as a lightweight Linux distribution that used to run well back in the day on systems with less than 1GB of RAM, TrixiePup64 is out with a new release of this Puppy Linux based distribution with Debian GNU/Linux components. The new TrixiePup64 11.2 release is based on the latest Debian Trixie sources while continuing to offer separate builds for either X11 or Wayland usage...



  • RISC-V-based ESP32-P4 handheld integrates AMOLED display and LoRa
    LILYGO has introduced the T-Display P4, a handheld development board built around Espressif’s ESP32-P4 application processor and a companion ESP32-C6 for wireless connectivity. The platform targets portable HMIs, sensor-equipped field devices, and edge systems that require a display, camera support, and multiple radios in a compact enclosure. Measuring about 63 × 109 × 22 mm, […]


  • LoongArch32 Support Begins Taking Shape In Linux 6.19, GCC 16
    The LoongArch CPU architecture changes have been merged for the Linux 6.19 merge window. This domestic Chinese CPU architecture inspired by MIPS and RISC-V began with 64-bit LoongArch64 but with Linux 6.19 the foundation is being laid for LoongArch32 as a 32-bit variant...















  • Ubuntu Studio 26.04 May Modernize Its Desktop Layout
    Ubuntu Studio is the variant of Ubuntu Linux focused on content creation and audio recording needs, video editing, and other creative workloads. Ubuntu Studio's desktop hasn't seen too many changes since Ubuntu 12.04 LTS some 13+ years ago. But Ubuntu Studio developers are now considering desktop layout changes to help modernize its appearance...


Error: It's not possible to reach RSS file http://services.digg.com/2.0/story.getTopNews?type=rss&topic=technology ...

Slashdot

  • Time Magazine's 'Person of the Year': the Architects of AI
    Time magazine used its 98th annual "Person of the Year" cover to "recognize a force that has dominated the year's headlines, for better or for worse. For delivering the age of thinking machines, for wowing and worrying humanity, for transforming the present and transcending the possible, the Architects of AI are TIME's 2025 Person of the Year." One cover illustration shows eight AI executives sitting precariously on a beam high above the city, while Time's 6,700-word article promises "the story of how AI changed our world in 2025, in new and exciting and sometimes frightening ways. It is the story of how [Nvidia CEO] Huang and other tech titans grabbed the wheel of history, developing technology and making decisions that are reshaping the information landscape, the climate, and our livelihoods." Time describes them betting on "one of the biggest physical infrastructure projects of all time," mentioning all the usual worries — datacenters' energy consumption, chatbot psychosis, predictions of "wiping out huge numbers of jobs" and the possibility of an AI stock market bubble. (Although "The drumbeat of warning that advanced AI could kill us all has mostly quieted"). But it also notes AI's potential to jumpstart innovation (and economic productivity)This year, the debate about how to wield AI responsibly gave way to a sprint to deploy it as fast as possible. "Every industry needs it, every company uses it, and every nation needs to build it," Huang tells TIME in a 75-minute interview in November, two days after announcing that Nvidia, the world's first $5 trillion company, had once again smashed Wall Street's earnings expectations. "This is the single most impactful technology of our time..." The risk-averse are no longer in the driver's seat. Thanks to Huang, Son, Altman, and other AI titans, humanity is now flying down the highway, all gas no brakes, toward a highly automated and highly uncertain future. Perhaps Trump said it best, speaking directly to Huang with a jovial laugh in the U.K. in September: "I don't know what you're doing here. I hope you're right."


    Read more of this story at Slashdot.


  • Trump Ban on Wind Energy Permits 'Unlawful', Court Rules
    A January order blocking wind energy projects in America has now been vacated by a U.S. judge and declared unlawful, reports the Associated Press:[Judge Saris of the U.S. district court for the district of Massachusetts] ruled in favor of a coalition of state attorneys general from 17 states and Washington DC, led by Letitia James, New York's attorney general, that challenged President Trump's day one order that paused leasing and permitting for wind energy projects... The coalition that opposed Trump's order argued that Trump does not have the authority to halt project permitting, and that doing so jeopardizes the states' economies, energy mix, public health and climate goals. The coalition includes Arizona, California, Colorado, Connecticut, Delaware, Illinois, Maine, Maryland, Massachusetts, Michigan, Minnesota, New Jersey, New Mexico, New York, Oregon, Rhode Island, Washington state and Washington DC. They say they have invested hundreds of millions of dollars collectively to develop wind energy and even more on upgrading transmission lines to bring wind energy to the electrical grid... Wind is the United States' largest source of renewable energy, providing about 10% of the electricity generated in the nation, according to the American Clean Power Association. But the BBC quotes Timothy Fox, managing director at the Washington, DC-based research firm ClearView Energy Partners, as saying he doesn't expect the ruling to reinvigorate the industry: "It's more symbolic than substantive," he said. "All the court is saying is ... you need to go back to work and consider these applications. What does that really mean?" he said.Officials could still deny permits or bog applications down in lengthy reviews, he noted.


    Read more of this story at Slashdot.


  • New Rule Forbids GNOME Shell Extensions Made Using AI-Generated Code
    An anonymous reader shared this report from Phoronix:Due to the growing number of GNOME Shell extensions looking to appear on extensions.gnome.org that were generated using AI, it's now prohibited. The new rule in their guidelines note that AI-generated code will be explicitly rejected: "Extensions must not be AI-generated While it is not prohibited to use AI as a learning aid or a development tool (i.e. code completions), extension developers should be able to justify and explain the code they submit, within reason. Submissions with large amounts of unnecessary code, inconsistent code style, imaginary API usage, comments serving as LLM prompts, or other indications of AI-generated output will be rejected." In a blog post, GNOME developer Javad Rahmatzadeh explains that"Some devs are using AI without understanding the code..."


    Read more of this story at Slashdot.


  • Is the R Programming Language Surging in Popularity?
    The R programming language "is sometimes frowned upon by 'traditional' software engineers," says the CEO of software quality services vendor Tiobe, "due to its unconventional syntax and limited scalability for large production systems." But he says it "continues to thrive at universities and in research-driven industries, and "for domain experts, it remains a powerful and elegant tool." Yet it's now gaining more popularity as statistics and large-scale data visualization become important (a trend he also sees reflected in the rise of Wolfram/Mathematica). That's according to December's edition of his TIOBE Index, which attempts to rank the popularity of programming languages based on search-engine results for courses, third-party vendors, and skilled engineers. InfoWorld explains:In the December 2025 index, published December 7, R ranks 10th with a 1.96% rating. R has cracked the Tiobe index's top 10 before, such as in April 2020 and July 2020, but not in recent years. The rival Pypl Popularity of Programming Language Index, meanwhile, has R ranked fifth this month with a 5.84% share. "Programming language R is known for fitting statisticians and data scientists like a glove," said Paul Jansen, CEO of software quality services vendor Tiobe, in a bulletin accompanying the December index... Although data science rival Python has eclipsed R in terms of general adoption, Jansen said R has carved out a solid and enduring niche, excelling at rapid experimentation, statistical modeling, and exploratory data analysis. "We have seen many Tiobe index top 10 entrants rising and falling," Jansen wrote. "It will be interesting to see whether R can maintain its current position." "Python remains ahead at 23.64%," notes TechRepublic, "while the familiar chase group behind it holds steady for the moment. The real movement comes deeper in the list, where SQL edges upward, R rises to the top 10, and Delphi/Object Pascal slips away... SQLclimbs from tenth to eighth at 2.10%, adding a small +0.11% that's enough to move it upward in a tightly packed section of the table. Perl holds ninth at 1.97%, strengthened by a +1.33% gain that extends its late-year resurgence." It's interesting to see how TIOBE's ranking compare with PYPL's (which ranks languages based solely on how often language tutorials are searched on Google): TIOBE PYPL Python Python C C/C++ C++ Objective-C Java Java C# R JavaScript JavaScript Visual Basic Swift SQL C# Perl PHP R Rust Despite their different methodologies, both lists put Python at #1, Java at #5, and JavaScript at #7.


    Read more of this story at Slashdot.


  • System76 Launches First Stable Release of COSMIC Desktop and Pop!_OS 24.04 LTS
    This week System76 launched the first stable release of its Rust-based COSMIC desktop environment. Announced in 2021, it's designed for all GNU/Linux distributions — and it shipping with Pop!_OS 24.04 LTS (based on Ubuntu 24.04 LTS). An anonymous reader shared this report from 9to5Linux:Previous Pop!_OS releases used a version of the COSMIC desktop that was based on the GNOME desktop environment. However, System76 wanted to create a new desktop environment from scratch while keeping the same familiar interface and user experience built for efficiency and fun. This means that some GNOME apps have been replaced by COSMIC apps, including COSMIC Files instead of Nautilus (Files), COSMIC Terminal instead of GNOME Terminal, COSMIC Text Editor instead of GNOME Text Editor, and COSMIC Media Player instead of Totem (Video Player). Also, the Pop!_Shop graphical package manager used in previous Pop!_OS releases has now been replaced by a new app called COSMIC Store. "If you're ambitious enough, or maybe just crazy enough, there eventually comes a time when you realize you've reached the limits of current potential, and must create something completely new if you're to go further..." explains System76 founder/CEO Carl Richell:For twenty years we have shipped Linux computers. For seven years we've built the Pop!_OS Linux distribution. Three years ago it became clear we had reached the limit of our current potential and had to create something new. Today, we break through that limit with the release of Pop!_OS 24.04 LTS with the COSMIC Desktop Environment.Today is special not only in that it's the culmination of over three years of work, but even more so in that System76 has built a complete desktop environment for the open source community...I hope you love what we've built for you. Now go out there and create. Push the limits, make incredible things, and have fun doing it!


    Read more of this story at Slashdot.


  • 'Free Software Awards' Winners Announced: Andy Wingo, Alx Sa, Govdirectory
    This week the Free Software Foundation honored Andy Wingo, Alx Sa, and Govdirectory with this year's annual Free Software Awards (given to community members and groups making"significant" contributions to software freedom):Andy Wingo is one of the co-maintainers of GNU Guile,the official extension language of the GNU operating system and theScheme "backbone" of GNUGuix. Upon receiving the award, he stated: "Since I learnedabout free software, the vision of a world in which hackers freelyshare and build on each others' work has been a profound inspirationto me, and I am humbled by this recognition of my small efforts inthe context of the Guile Scheme implementation. I thank myco-maintainer, Ludovic Courtès, for his comradery over the years: weare just building on the work of the past maintainers of Guile, and Ihope that we live long enough to congratulate its many futuremaintainers." The 2024 Award forOutstanding New FreeSoftware Contributor went to Alx Sa for work on the GNUImage Manipulation Program (GIMP). When asked to comment, Alxresponded: "I am honored to receive this recognition! I startedcontributing to the GNU Image Manipulation Program as a way to returnthe favor because of all the cool things it's allowed me to do.Thanks to the help and mentorship of amazing people like Jehan Pagès,Jacob Boerema, Liam Quin, and so many others, I hope I've been ableto help other people do some cool new things, too." Govdirectory was presentedwith this year's Awardfor Projects of Social Benefit, given to a project or teamresponsible for applying free software, or the ideas of the freesoftware movement, to intentionally and significantly benefitsociety. Govdirectory provides a collaborative and fact-checkedlisting of government addresses, phone numbers, websites, and socialmedia accounts, all of which can be viewed with free software andunder a free license, allowing people to always reach theirrepresentatives in freedom... The FSF plans to further highlight the Free Software Award winnersin a series of events scheduled for the new year to celebrate theircontributions to free software.


    Read more of this story at Slashdot.


  • Applets Are Officially Going, But Java In the Browser Is Better Than Ever
    "The entire java.applet package has been removed from JDK 26, which will release in March 2026," notes Inside Java. But long-time Slashdot reader AirHog links to this blog post reminding us that"Applets Are Officially Gone, But Java In The Browser Is Better Than Ever."This brings to an official end the era of applets, which began in 1996. However, for years it has been possible to build modern, interactive web pages in Java without needing applets or plugins. TeaVM provides fast, performant, and lightweight tooling to transpile Java to run natively in the browser... TeaVM, at its heart, transpiles Java code into JavaScript (or, these days, WASM). However, in order for Java code to be useful for web apps, much more is required, and TeaVM delivers. It includes a minifier, to shrink the generated code and obfuscate the intent, to complicate reverse-engineering. It has a tree-shaker to eliminate unused methods and classes, keeping your app download compact. It packages your code into a single file for easy distribution and inclusion in your HTML page. It also includes wrappers for all popular browser APIs, so you can invoke them from your Java code easily, with full IDE assistance and auto-correct. The blog post also touts Flavour, an open-sourceframework "for coding, packaging, and optimizing single-page apps implemented in Java... a full front-end toolkit with templates, routing, components, and more" to "build your modern single-page app using 100% Java."


    Read more of this story at Slashdot.


  • Startup Successfully Uses AI to Find New Geothermal Energy Reservoirs
    A Utah-based startup announced last week it used AI to locate a 250-degree Fahrenheit geothermal reservoir, reports CNN. It'll start producing electricity in three to five years, the company estimates — and at least one geologist believes AI could be an exciting "gamechanger" for the geothermal industry.[Startup Zanskar Geothermal & Minerals] named it "Big Blind," because this kind of site — which has no visual indication of its existence, no hot springs or geysers above ground, and no history of geothermal exploration — is known as a "blind" system. It's the first industry-discovered blind site in more than three decades, said Carl Hoiland, co-founder and CEO of Zanskar. "The idea that geothermal is tapped out has been the narrative for decades," but that's far from the case, he told CNN. He believes there are many more hidden sites across the Western U.S. Geothermal energy is a potential gamechanger. It offers the tantalizing prospect of a huge source of clean energy to meet burgeoning demand. It's near limitless, produces scarcely any climate pollution, and is constantly available, unlike wind and solar, which are cheap but rely on the sun shining and the wind blowing. The problem, however, has been how to find and scale it. It requires a specific geology: underground reservoirs of hot water or steam, along with porous rocks that allow the water to move through them, heat up, and be brought to the surface where it can power turbines... The AI models Zanskar uses are fed information on where blind systems already exist. This data is plentiful as, over the last century and more, humans have accidentally stumbled on many around the world while drilling for other resources such as oil and gas. The models then scour huge amounts of data — everything from rock composition to magnetic fields — to find patterns that point to the existence of geothermal reserves. AI models have "gotten really good over the last 10 years at being able to pull those types of signals out of noise," Hoiland said... Zanskar's discovery "is very significant," said James Faulds, a professor of geosciences at Nevada Bureau of Mines and Geology.... Estimates suggest over three-quarters of US geothermal resources are blind, Faulds told CNN. "Refining methods to find such systems has the potential to unleash many tens and perhaps hundreds of gigawatts in the western US alone," he said... Big Blind is the company's first blind site discovery, but it's the third site it has drilled and hit commercial resources. "We expect dozens, to eventually hundreds, of new sites to be coming to market," Hoiland said.... Hoiland says Zanskar's work shows conventional geothermal still has huge untapped potential. Thanks to long-time Slashdot reader schwit1 for sharing the article.


    Read more of this story at Slashdot.


  • Firefox Survey Finds Only 16% Feel In Control of Their Privacy Choices Online
    Choosing your browser "is one of the most important digital decisions you can make, shaping how you experience the web, protect your data, and express yourself online," says the Firefox blog. They've urged readers to "take a stand for independence and control in your digital life." But they also recently polled 8,000 adults in France, Germany, the UK and the U.S. on "how they navigate choice and control both online and offline" (attending in-person events in Chicago, Berlin, LA, and Munich, San Diego, Stuttgart):The survey, conducted by research agency YouGov, showcases a tension between people's desire to have control over their data and digital privacy, and the reality of the internet today — a reality defined by Big Tech platforms that make it difficult for people to exercise meaningful choice online: — Only 16% feel in control of their privacy choices (highest in Germany at 21%) — 24% feel it's "too late" because Big Tech already has too much control or knows too much about them. And 36% said the feeling of Big Tech companies knowing too much about them is frustrating — highest among respondents in the U.S. (43%) and the UK (40%) — Practices respondents said frustrated them were Big Tech using their data to train AI without their permission (38%) and tracking their data without asking (47%; highest in U.S. — 55% and lowest in France — 39%) And from our existing research on browser choice, we know more about how defaults that are hard to change and confusing settings can bury alternatives, limiting people's ability to choose for themselves — the real problem that fuels these dynamics. Taken together our new and existing insights could also explain why, when asked which actions feel like the strongest expressions of their independence online, choosing not to share their data (44%) was among the top three responses in each country (46% in the UK; 45% in the U.S.; 44% in France; 39% in Germany)... We also see a powerful signal in how people think about choosing the communities and platforms they join — for 29% of respondents, this was one of their top three expressions of independence online. "For Firefox, community has always been at the heart of what we do," says their VP of Global Marketing, "and we'll keep fighting to put real choice and control back in people's hands so the web once again feels like it belongs to the communities that shape it." At TwitchCon in San Diego Firefox even launched a satirical new online card game with a privacy theme called Data War.


    Read more of this story at Slashdot.


  • The World's Electric Car Sales Have Spiked 21% So Far in 2025
    Electrek reports:EV and battery supply chain research specialists Benchmark Mineral Intelligence reports that 2.0 million electric vehicles were sold globally in November 2025, bringing global EV sales to 18.5 million units year-to-date. That's a 21% increase compared to the same period in 2024.Europe was the clear growth leader in November, while North America continued to lag following the expiration of US EV tax credits. China, meanwhile, remains the world's largest EV market by a wide margin. Europe's EV market jumped 36% year-over-year in November 2025, with BEV sales up 35% and plug-in hybrid (PHEV) sales rising 39%. That brings Europe's total EV sales to 3.8 million units for the year so far, up 33% compared to January-November 2024... In North America, EV sales in the US did tick up month-over-month in November, following a sharp October drop after federal tax credits expired on September 30, 2025. Brands including Kia (up 30%), Hyundai (up 20%), Honda (up 11%), and Subaru (232 Solterra sales versus just 13 the month before) all saw gains, but overall volumes remain below levels when the federal tax credit was still available... [North America shows a -1% drop in EV sales from January to November 2025 vs. January to November 2024] Year-to-date, EV sales in China are up 19%, with 11.6 million units sold. One of the biggest headlines out of China is exports. BYD reported a record 131,935 EV exports in November, blowing past its previous high of around 90,000 units set in June. BYD sales in Europe have jumped more than fourfold this year to around 200,000 vehicles, doubled in Southeast Asia, and climbed by more than 50% in South America... "Overall, EV demand remains resilient, supported by expanding model ranges and sustained policy incentives worldwide," said Rho Motion data manager Charles Lester. Beyond China, Europe, and North America, the rest of the world saw a 48% spike in EV sales in 2025 vs the same 11 months in 2024, representing 1.5 million EVs sold. "The takeaway: EV demand continues to grow worldwide," the article adds, "but policy support — or the lack thereof — is increasingly shaping where this growth shows up."


    Read more of this story at Slashdot.


  • How a 23-Year-Old in 1975 Built the World's First Handheld Digital Camera
    In 1975, 23-year-old electrical engineer Steve Sasson joined Kodak. And in a new interview with the BBC, he remembers that he'd found the whole photographic process "really annoying.... I wanted to build a camera with no moving parts. Now that was just to annoy the mechanical engineers...""You take your picture, you have to wait a long time, you have to fiddle with these chemicals. Well, you know, I was raised on Star Trek, and all the good ideas come from Star Trek. So I said what if we could just do it all electronically...?" Researchers at Bell Labs in the US had, in 1969, created a type of integrated circuit called a charge-coupled device (CCD). An electric charge could be stored on a metal-oxide semiconductor (MOS), and could be passed from one MOS to another. Its creators believed one of its applications might one day be used as part of an imaging device — though they hadn't worked out how that might happen. The CCD, nevertheless, was quickly developed. By 1974, the US microchip company Fairchild Semiconductors had built the first commercial CCD, measuring just 100 x 100 pixels — the tiny electronic samples taken of an original image. The new device's ability to capture an image was only theoretical — no-one had, as yet, tried to take an image and display it. (NASA, it turned out, was also looking at this technology, but not for consumer cameras....) The CCD circuit responded to light but could only form an image if Sasson was somehow able to attach a lens to it. He could then convert the light into digital information — a blizzard of 1s and 0s — but there was just one problem: money. "I had no money to build this thing. Nobody told me to build it, and I certainly couldn't demand any money for it," he says. "I basically stole all the parts, I was in Kodak and the apparatus division, which had a lot of parts. I stole the optical assembly from an XL movie camera downstairs in a used parts bin. I was just walking by, you see it, and you take it, you know." He was also able to source an analogue to digital converter from a $12 (about £5 in 1974) digital voltmeter, rather than spending hundreds on the part. I could manage to get all these parts without anybody really noticing," he says.... The bulky device needed a way to store the information the CCD was capturing, so Sasson used an audio cassette deck. But he also needed a way to view the image once it was saved on the magnetic tape. "We had to build a playback unit," Sasson says. "And, again, nobody asked me to do that either. So all I got to do is the reverse of what I did with the camera, and then I have to turn that digital pattern into an NTSC television signal." NTSC (National Television System Committee) was the conversion standard used by American TV sets. Sasson had to turn only 100 lines of digital code captured by the camera into the 400 lines that would form a television signal. The solution was a Motorola microprocessor, and by December 1975, the camera and its playback unit was complete, the article points out. With his colleague Jim Schueckler, Sasson had spent more than a year putting together the "increasingly bulky" device, that "looked like an oversized toaster."The camera had a shutter that would take an image at about 1/20th of a second, and — if everything worked as it should — the cassette tape would start to move as the camera transferred the stored information from its CCD [which took 23 seconds]. "It took about 23 seconds to play it back, and then about eight seconds to reconfigure it to make it look like a television signal, and send it to the TV set that I stole from another lab...." In 1978, Kodak was granted the first patent for a digital camera. It was Sasson's first invention. The patent is thought to have earned Eastman Kodak billions in licensing and infringement payments by the time they sold the rights to it, fearing bankruptcy, in 2012... As for Sasson, he never worked on anything other than the digital technology he had helped to create until he retired from Eastman Kodak in 2009. Thanks to long-time Slashdot reader sinij for sharing the article.


    Read more of this story at Slashdot.


  • More of America's Coal-Fired Power Plants Cease Operations
    New England's last coal-fired power plant "has ceased operations three years ahead of its planned retirement date," reports the New Hampshire Bulletin. "The closure of the New Hampshire facility paves the way for its owner to press ahead with an initiative to transform the site into a clean energy complex including solar panels and battery storage systems.""The end of coal is real, and it is here," said Catherine Corkery, chapter director for Sierra Club New Hampshire. "We're really excited about the next chapter...." The closure in New Hampshire — so far undisputed by the federal government — demonstrates that prolonging operations at some facilities just doesn't make economic sense for their owners. "Coal has been incredibly challenged in the New England market for over adecade," said Dan Dolan, president of the New England Power Generators Association. Merrimack Station, a 438-megawatt power plant, came online in the1960s and provided baseload power to the New England region for decades. Gradually, though, natural gas — which is cheaper and more efficient — took over the regional market... Additionally, solar power production accelerated from 2010 on, lowering demand on the grid during the day and creating more evening peaks. Coal plants take longer to ramp up production than other sources, and are therefore less economical for these shorter bursts of demand, Dolan said. In recent years, Merrimack operated only a few weeks annually. In 2024, the plant generated just0.22% of the region's electricity. It wasn't making enough money to justify continued operations, observers said. The closure "is emblematic of the transition that has been occurring in the generation fleet in New England for many years," Dolan said. "The combination of all those factors has meant that coal facilities are no longer economic in this market." Meanwhile Los Angeles — America's second-largest city — confirmed that the last coal-fired power plant supplying its electricity stopped operations just before Thanksgiving, reports the Utah News Dispatch:Advocates from the Sierra Club highlighted in a news release that shutting down the units had no impact on customers, and questioned who should "shoulder the cost of keeping an obsolete coal facility on standby...." Before ceasing operations, the coal units had been working at low capacities for several years because the agency's users hadn't been calling on the power [said John Ward, spokesperson for Intermountain Power Agency]. The coal-powered units "had a combined capacity of around 1,800 megawatts when fully operational," notes Electrek, "and as recently as 2024, they still supplied around 11% of LA's electricity. The plant sits in Utah's Great Basin region and powered Southern California for decades." Now, for the first time, none of California's power comes from coal.There's a political hiccup with IPP, though: the Republican-controlled Utah Legislature blocked the Intermountain Power Agency from fully retiring the coal units this year, ordering that they can't be disconnected or decommissioned. But despite that mandate, no buyers have stepped forward to keep the outdated coal units online. The Los Angeles Department of Water and Power (LADWP) is transitioning to newly built, hydrogen-capable generating units at the same IPP location, part of a modernization effort called IPP Renewed. These new units currently run on natural gas, but they're designed to burn a blend of natural gas and up to 30% green hydrogen, and eventually100% green hydrogen. LADWP plans to start adding green hydrogen to the fuel mix in 2026. "With the plant now idled but legally required to remain connected, serious questions remain about who will shoulder the cost of keeping an obsolete coal facility on standby," says the Sierra Club. One of the natural gas units started commerical operations last Octoboer, with the second starting later this month, IPP spokesperson John Ward told Agency]. the Utah News Dispatch.


    Read more of this story at Slashdot.


  • Rust in Linux's Kernel 'is No Longer Experimental'
    Steven J. Vaughan-Nichols files this report from Tokyo:At the invitation-only LinuxKernel Maintainers Summit here, the top Linux maintainers decided, as Jonathan Corbet, Linux kernel developer, put it, "The consensus among the assembled developers is that Rustin the kernel is no longer experimental — it is now a core partof the kernel and is here to stay. So the 'experimental' tagwill be coming off." As Linux kernel maintainer Steven Rosted toldme, "There was zero pushback." This has been a long time coming. This shift caps five years ofsometimes-fierce debate over whether the memory-safe language belonged alongside C at the heart of the world's most widely deployed open source operating system... It all began when AlexGaynor and GeoffreyThomas at the 2019 Linux Security Summit said that abouttwo-thirds of Linux kernel vulnerabilities come from memory safetyissues. Rust, in theory, could avoid these by using Rust'sinherently safer application programming interfaces (API)... In those early days, the plan was not to rewrite Linux in Rust; it still isn't, but to adopt it selectively where it can provide themost security benefit without destabilizing mature C code. In short,new drivers, subsystems, and helper libraries would be the firsttargets... Despite the fuss, more and more programs were ported to Rust. ByApril 2025, the Linux kernel contained about 34 million lines of Ccode, with only 25 thousand lines written in Rust. At the same time,more and more drivers and higher-level utilities were being writtenin Rust. For instance, the Debian Linux distro developers announcedthat going forward, Rustwould be a required dependency in its foundationalAdvanced Package Tool (APT). This change doesn't mean everyone will need to use Rust. C isnot going anywhere. Still, as several maintainers told me, theyexpect to see many more drivers being written in Rust. In particular,Rust looks especially attractive for "leaf" drivers (network,storage, NVMe, etc.), where the Rust-for-Linuxbindings expose safe wrappers over kernel C APIs. Nevertheless, for would-be kernel and systems programmers, Rust'snew status in Linux hints at a career path that blends deepunderstanding of C with fluency in Rust's safety guarantees. Thiscombination may define the next generation of low-level developmentwork.


    Read more of this story at Slashdot.


  • Germany Covers Nearly 56 Percent of 2025 Electricity Use With Renewables
    Longtime Slashdot reader AmiMoJo shares a report from Clean Energy Wire: Renewable energy sources covered nearly 56 percent of Germany's gross electricity consumption in 2025, according to preliminary figures by energy industry group BDEW and research institute ZSW. Despite a 'historically weak' first quarter of the year for wind power production and a significant drop in hydropower output, the share of renewables grew by 0.7 percentage points compared to the previous year thanks to an increase in installed solar power capacity. Solar power output increased by 18.7 percent over the whole year, while the strong growth in installed capacity from previous years could be sustained, with more than 17 gigawatts (GW) added to the system. With March being the least windy month in Germany since records began in 1950, wind power output, on the other hand, faced a drop of 5.2 percent compared to 2024. However, stronger winds in the second and third quarter compensated for much of the early-year decrease. Onshore turbines with a capacity of 5.2 GW were added to the grid, a marked increase from the 3.3 GW in the previous year. Due to significantly less precipitation this year compared to 2024, hydropower output dropped by nearly one quarter (24.1%), while remaining only a fraction (3.2%) of total renewable power output.


    Read more of this story at Slashdot.


  • Chinese Whistleblower Living In US Is Being Hunted By Beijing With US Tech
    A former Chinese official who fled to the U.S. says Beijing has used advanced surveillance technology from U.S. companies to track, intimidate, and punish him and his family across borders. ABC News reports: Retired Chinese official Li Chuanliang was recuperating from cancer on a Korean resort island when he got an urgent call: Don't return to China, a friend warned. You're now a fugitive. Days later, a stranger snapped a photo of Li in a cafe. Terrified South Korea would send him back, Li fled, flew to the U.S. on a tourist visa and applied for asylum. But even there -- in New York, in California, deep in the Texas desert -- the Chinese government continued to hunt him down with the help of surveillance technology. Li's communications were monitored, his assets seized and his movements followed in police databases. More than 40 friends and relatives -- including his pregnant daughter -- were identified and detained, even by tracking down their cab drivers through facial recognition software. Three former associates died in detention, and for months shadowy men Li believed to be Chinese operatives stalked him across continents, interviews and documents seen by The Associated Press show. The Chinese government is using an increasingly powerful tool to cement its power at home and vastly amplify it abroad: Surveillance technology, much of it originating in the U.S., an AP investigation has found. Within China, this technology helped identify and punish almost 900,000 officials last year alone, nearly five times more than in 2012, according to state numbers. Beijing says it is cracking down on corruption, but critics charge that such technology is used in China and elsewhere to stifle dissent and exact retribution on perceived enemies. Outside China, the same technology is being used to threaten wayward officials, along with dissidents and alleged criminals, under what authorities call Operations "Fox Hunt" and "Sky Net." The U.S. has criticized these overseas operations as a "threat" and an "affront to national sovereignty." More than 14,000 people, including some 3,000 officials, have been brought back to China from more than 120 countries through coercion, arrests and pressure on relatives, according to state information.


    Read more of this story at Slashdot.


The Register


  • British Airways fears a future where AI agents pick flights and brands get ghosted
    CEO warns airlines that don’t learn to sell themselves to machines could soon be flying under the radar
    British Airways' chief executive has warned that the airline industry is fast heading for a future where AI agents, not humans, decide which brands get booked – and carriers that fail to adapt are at risk of quietly disappearing from the digital shop window.…


  • Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit
    Exploit hasn't been picked up by any malware detection engines, CEO tells The Reg
    A Microsoft zero-day vulnerability that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service now has a free, unofficial patch - with no word as to when Redmond plans to release an official one - along with a working exploit circulating online.…


  • New React vulns leak secrets, invite DoS attacks
    And the earlier React2Shell patch is vulnerable
    If you're running React Server Components, you just can't catch a break. In addition to already-reported flaws, newly discovered bugs allow attackers to hang vulnerable servers and potentially leak Server Function source code, so anyone using RSC or frameworks that support it should patch quickly.…


  • Trump gives state AI regulation the presidential middle finger
    Executive order sidesteps Congress and sets up Litigation Task Force
    President Trump and his patrons in big tech have long wanted to block states from implementing their own AI regulations. After failing twice to do so in Congress, the US president has issued an executive order that would attempt to punish states that try to restrain the bot business.…


  • Workday project at Washington University hits $266M
    Protests force disclosure of costs totaling $16,000 per student over 7 year rollout replacing 80 legacy systems
    The total cost of a Workday implementation project at Washington University in St. Louis is set to hit almost $266 million, it was revealed after the project was the subject of protests from students.…


  • The CRASH Clock is ticking as satellite congestion in low Earth orbit worsens
    It's getting crowded up there
    Earth's orbit is starting to look like an LA freeway, with more and more satellites being launched each year. If you're worried about collisions and space debris making the area unusable – and you should be – scientists have proposed a new metric to contribute to your anxiety: the CRASH Clock.…


  • AI datacenter boom could end badly, Goldman Sachs warns
    Bank sketches four scenarios in which monetization falters or demand swamps supply by 2030
    Goldman Sachs warns that datacenter investments may fail to pay off if the industry is unable to monetize AI models, but hedges its bets by saying that demand could also overwhelm available capacity by 2030.…


  • Microsoft promises more bug payouts, with or without a bounty program
    Critical vulnerabilities found in third-party applications eligible for award under 'in scope by default' move
    Microsoft is overhauling its bug bounty program to reward exploit hunters for finding vulnerabilities across all its products and services, even those without established bounty schemes.…




  • UK watchdog urged to probe GDPR failures in Home Office eVisa rollout
    Rights groups say digital-only record is leaking data and courting trouble
    Civil society groups are urging the UK's data watchdog to investigate whether the Home Office's digital-only eVisa scheme is breaching GDPR, sounding the alarm about systemic data errors and design failures that are exposing sensitive personal information while leaving migrants unable to prove their lawful status.…


  • Half of exposed React servers remain unpatched amid active exploitation
    Wiz says React2Shell attacks accelerating, ranging from cryptominers to state-linked crews
    Half of the internet-facing systems vulnerable to a fast-moving React remote code execution flaw remain unpatched, even as exploitation has exploded into more than a dozen active attack clusters ranging from bargain-basement cryptominers to state-linked intrusion tooling.…


  • Salesforce opts for seat-based AI licensing as customers demand predictability
    Analysts say the shift offers stability, but embedded usage caps ensure vendors keep control
    Salesforce CEO Marc Benioff last week came closer to answering a multibillion-dollar question when he said seat-based pricing – with some caveats – was becoming the norm for its AI agents after flirting with pricing based on consumption and per-conversation payments.…



  • User insisted their screen was blank, until admitting it wasn't
    Getting that confession took hours, during which L1 and L2 support gave up
    On Call Welcome once more to On Call, the Friday column in which we share stories of tech support incidents that went pear-shaped until cunning Reg readers stepped in to save the day.…





  • AI superintelligence is a Silicon Valley fantasy, Ai2 researcher says
    The dream of electric sheep gets a reality check from Moore’s Law
    You want artificial general intelligence (AGI)? Current-day processors aren't powerful enough to make it happen and our ability to scale up may soon be coming to an end, argues well-known researcher Tim Dettmers.…


  • VMware kills vSphere Foundation in parts of EMEA
    Broadcom told The Register that EMEA customers need to check with their local dealer to see if VVF remains on the menu
    Exclusive Broadcom has recently killed off VMware vSphere Foundation in parts of EMEA, the company told The Register, dealing a blow to smaller customers, one of whom told us they would likely switch to a rival hypervisor as a result.…


  • Disney turns to dark side, licenses IP to OpenAI for videos, images
    Begun, these AI wars have
    Amid controversy over its ability to generate content with copyrighted characters, OpenAI has struck a three-year deal with Disney to license more than 200 Disney, Pixar, Marvel, and Star Wars characters for use in Sora videos and ChatGPT Images.…



  • European cloud trade group says EU should have blocked VMware-Broadcom merger
    Org argues that the approval process was flawed and regulators should have known better
    A trade group of European cloud providers has laid into the European Commission’s decision to allow the VMware-Broadcom merger to go ahead, alleging that it failed to assess the infrastructure and semiconductor company’s incentives to massively raise prices on customers.…


  • Space-power startup claims it can beam energy to solar farms
    So far, Overview Energy says it has only beamed power from a moving aircraft to standard solar panels
    You can't generate solar power at night unless your panels are in space. A startup that wants to beam orbital sunlight straight into existing solar farms has just emerged from stealth, claiming a world-first power-beaming demo, but with a lot of critical information left unreported. …


  • Google fixes super-secret 8th Chrome 0-day
    No details, no CVE, update your browser now
    Google issued an emergency fix for a Chrome vulnerability already under exploitation, which marks the world's most popular browser's eighth zero-day bug of 2025.…


  • LastPass hammered with £1.2M fine for 2022 breach fiasco
    UK data regulator says failures were unacceptable for a company managing the world's passwords
    The UK's Information Commissioner's Office (ICO) says LastPass must cough up £1.2 million ($1.6 million) after its two-part 2022 data breach compromised information from up to 1.6 million UK users.…




  • Trump's AI 'Genesis Mission' emerges from Land of Confusion
    DOE lays out $320M plan for science platform linking national labs, industry, and academia
    President Trump's "Genesis Mission" is taking shape with the award of more than $320 million from the Department of Energy (DOE) to advance AI in scientific research.…



  • Microsoft research shows chatbots seeping into everyday life
    Copilot – your cuddly companion for nighttime introspection
    Microsoft analyzed 37.5 million de-identified Copilot conversations from January to September 2025, excluding commercial and educational accounts. The findings reveal distinct usage patterns based on device, time, and day.…


  • 10K Docker images spray live cloud creds across the internet
    Flare warns devs are unwittingly publishing production-level secrets
    Docker Hub has quietly become a treasure trove of live cloud keys and credentials, with more than 10,000 public container images exposing sensitive secrets from over 100 companies, including a Fortune 500 firm and a major bank.…


  • Airbus exec: Most CIOs in Europe will not finish SAP ECC6 migration by 2030
    Aerospace giant faces 'massive work' to move legacy ERP systems to S/4HANA as support deadline looms
    Exclusive Airbus is undertaking a major overhaul to migrate its sprawling SAP environment to S/4HANA – and potentially to the cloud – as the aerospace giant grapples with the same deadline pressures facing thousands of enterprise customers worldwide.…





  • NASA loses contact with MAVEN Mars orbiter
    Didn’t phone home as expected on December 6th and nobody knows why
    Houston, we have a problem: NASA has lost contact with the Mars Atmosphere and Volatile EvolutioN (MAVEN) spacecraft.…



  • Oracle raises AI spending estimate, spooks investors
    But if you assume cloud IOUs will be fulfilled, business is booming
    Oracle expects its FY 2026 capital expenditures will be $15 billion higher that previously predicted, as the cloudy database biz invests to accommodate AI workloads.…




  • US teens not only love AI, but also let it rot their brains
    Yeah, not shocking, but with other studies linking AI to weaker learning and mental-health risks, it’s a worry
    Alongside TikTok and Instagram, teens have added ChatGPT to the mix. Pew says about two-thirds of US teenagers have tried an AI chatbot, with nearly a third using one every day. Negative mental-health warnings be damned!…


  • Really Simple Licensing spec lets web publishers demand their due from AI scrapers
    Publishers now have more comprehensive tools for managing automated content harvesting
    Most big AI providers scrape the open web, hoovering up content to improve their chatbots, which then compete with publishers for the attention of internet users. However, more AI orgs might have to pay up soon, because the Really Simple Licensing (RSL) spec has reached version 1.0, providing guidance on how to set machine-readable rules for crawlers.…




  • US extradites Ukrainian woman accused of hacking meat processing plant for Russia
    The digital intrusion allegedly caused thousands of pounds of meat to spoil and triggered an ammonia leak in the facility
    A Ukrainian woman accused of hacking US public drinking water systems and a meat processing facility on behalf of Kremlin-backed cyber groups was extradited to the US earlier this year and will stand trial in early 2026.…



  • Welcome to America - now show us your last five years of social media posts
    Countries subject to newly proposed rule include supposed trusted friends like the UK, France, and Germany
    The next time someone visits the US, customs may ask to see their passport, their Facebook feed, and all of their Instagram posts. The United States maintains a list of 42 countries whose citizens are allowed to enter without a visa, but visitors from those nations may soon have to provide five years' worth of their social media history in order to gain entry. …


  • Crisis in Icebergen: How NATO crafts stories to sharpen cyber skills
    1,500 military digital defenders spent the past week cleaning up a series of cyberattacks on fictional island
    feature Andravia and Harbadus – two nations so often at odds with one another – were once again embroiled in conflict over the past seven days, which thoroughly tested NATO's cybersecurity experts' ability to coordinate defenses across battlefield domains.…


Polish Linux

  • Security: Why Linux Is Better Than Windows Or Mac OS
    Linux is a free and open source operating system that was released in 1991 developed and released by Linus Torvalds. Since its release it has reached a user base that is greatly widespread worldwide. Linux users swear by the reliability and freedom that this operating system offers, especially when compared to its counterparts, windows and [0]


  • Essential Software That Are Not Available On Linux OS
    An operating system is essentially the most important component in a computer. It manages the different hardware and software components of a computer in the most effective way. There are different types of operating system and everything comes with their own set of programs and software. You cannot expect a Linux program to have all [0]


  • Things You Never Knew About Your Operating System
    The advent of computers has brought about a revolution in our daily life. From computers that were so huge to fit in a room, we have come a very long way to desktops and even palmtops. These machines have become our virtual lockers, and a life without these network machines have become unimaginable. Sending mails, [0]


  • How To Fully Optimize Your Operating System
    Computers and systems are tricky and complicated. If you lack a thorough knowledge or even basic knowledge of computers, you will often find yourself in a bind. You must understand that something as complicated as a computer requires constant care and constant cleaning up of junk files. Unless you put in the time to configure [0]


  • The Top Problems With Major Operating Systems
    There is no such system which does not give you any problems. Even if the system and the operating system of your system is easy to understand, there will be some times when certain problems will arise. Most of these problems are easy to handle and easy to get rid of. But you must be [0]


  • 8 Benefits Of Linux OS
    Linux is a small and a fast-growing operating system. However, we can’t term it as software yet. As discussed in the article about what can a Linux OS do Linux is a kernel. Now, kernels are used for software and programs. These kernels are used by the computer and can be used with various third-party software [0]


  • Things Linux OS Can Do That Other OS Cant
    What Is Linux OS?  Linux, similar to U-bix is an operating system which can be used for various computers, hand held devices, embedded devices, etc. The reason why Linux operated system is preferred by many, is because it is easy to use and re-use. Linux based operating system is technically not an Operating System. Operating [0]


  • Packagekit Interview
    Packagekit aims to make the management of applications in the Linux and GNU systems. The main objective to remove the pains it takes to create a system. Along with this in an interview, Richard Hughes, the developer of Packagekit said that he aims to make the Linux systems just as powerful as the Windows or [0]


  • What’s New in Ubuntu?
    What Is Ubuntu? Ubuntu is open source software. It is useful for Linux based computers. The software is marketed by the Canonical Ltd., Ubuntu community. Ubuntu was first released in late October in 2004. The Ubuntu program uses Java, Python, C, C++ and C# programming languages. What Is New? The version 17.04 is now available here [0]


  • Ext3 Reiserfs Xfs In Windows With Regards To Colinux
    The problem with Windows is that there are various limitations to the computer and there is only so much you can do with it. You can access the Ext3 Reiserfs Xfs by using the coLinux tool. Download the tool from the  official site or from the  sourceforge site. Edit the connection to “TAP Win32 Adapter [0]


OSnews

  • Haiku gets new Go port
    Theres a new Haiku monthly activity report, and this ones a true doozy. Lets start with the biggest news. The most notable development in November was the introduction of a port of the Go programming language, version 1.18. This is still a few years old (from 2022; the current is Go 1.25), but it’s far newer than the previous Go port to Haiku (1.4 from 2014); and unlike the previous port which was never in the package repositories, this one is now already available there (for x86_64 at least) and can be installed via pkgman. ↫ Haiku activity report As the project notes, theyre still a few versions behind, but at least its a lot more modern of an implementation than they had before. Now that its in the repositories for Haiku, it might also attract more people to work on the port, potentially bringing even newer versions to the BeOS-inspired operating system. Welcome as it may be, this new Go port isnt the only big ticket item this month. Haiku can now gracefully recover from an app_server crash, something it used to be able to do a long time ago, but which was broken for a long time. The app_server is Haikus display server and window manager, so the ability to restart it at runtime after a crash, and have it reconnect with still-running applications, is incredibly welcome. As far as I can tell, all modern operating systems can do this by now, so its great to have this functionality restored in Haiku. Of course, aside from these two big improvements, theres the usual load of fixes and changes in applications, drivers, and other components of the operating system.


  • Rethinking sudo with object capabilities
    Alpine Linux maintainer Ariadne Conill has published a very interesting blog post about the shortcomings of both sudo and doas, and offers a potential different way of achieving the same goals as those tools. Systems built around identity-based access control tend to rely on ambient authority: policy is centralized and errors in the policy configuration or bugs in the policy engine can allow attackers to make full use of that ambient authority. In the case of a SUID binary like doas or sudo, that means an attacker can obtain root access in the event of a bug or misconfiguration. What if there was a better way? Instead of thinking about privilege escalation as becoming root for a moment, what if it meant being handed a narrowly scoped capability, one with just enough authority to perform a specific action and nothing more? Enter the object-capability model. ↫ Ariadne Conill To bring this approach to life, they created a tool called capsudo. Instead of temporarily changing your identity, capsudo can grant far more fine-grained capabilities that match the exact task youre trying to accomplish. As an example, Conill details mounting and unmounting  with capsudo, you can not only grant the ability for a user to mount and unmount whatever device, but also allow the user to only mount or unmount just one specific device. Another example given is how capsudo can be used to give a service account user to only those resources the account needs to perform its tasks. Of course, Conill explains all of this way better than I ever could, with actual example commands and more details. Conill happens to be the same person who created Wayback, illustrating that they have a tendency to look at problems in a unique and interesting way. Im not smart enough to determine if this approach makes sense compared to sudo or doas, but the way its described it does feel like a superior, more secure solution.


  • One too many words on AT8Ts $2000 Korn shell and other Usenet topics
    Unix has been enormously successful over the past 55 years. It started out as a small experiment to develop a time-sharing system (i.e., a multi-user operating system) at AT8T Bell Labs. The goal was to take a few core principles to their logical conclusion. The OS bundled many small tools that were easy to combine, as it was illustrated by a famous exchange between Donald Knuth and Douglas McIlroy in 1986. Today, Unix lives on mostly as a spiritual predecessor to Linux, Net/Free/OpenBSD, macOS, and arguably, ChromeOS and Android. Usenet tells us about the height of its early popularity. ↫ Gábor Nyéki There are so many amazing stories in this article, I honestly have no idea what to highlight. So first and foremost, I want you to read the whole thing yourself, as everyones bound to have their own personal favourite section that resonates the most. My personal favourite story from the article  which is just an aside, to illustrate that even the asides are great  is that when Australia joined Usenet in 1983, new posts to Usenet were delivered to the country by airmail. On magnetic tape. Once per week. The overarching theme here is that the early days of UNIX, as documented on Usenet, were a fascinating wild west of implementations, hacks, and personalities, which, yes, clashed with each other, but also spread untold amounts of information, knowledge, and experience to every corner of the world. I hope Nyéki will write more of these articles.


  • COSMIC Desktop reaches first stable release
    System76, creator of Pop!_OS and prominent Linux OEM, has just announced the release of Pop!_OS 24.04 LTS  normally not something I particularly care about, but in this case, it comes with the first stable release of COSMIC Desktop. COSMIC is a brand new desktop environment by System76, written in Rust, and after quite some time in development, its now out in the wild as a stable release. Today is special not only in that it’s the culmination of over three years of work, but even more so in that System76 has built a complete desktop environment for the open source community. We’re proud of this contribution to the open source ecosystem. COSMIC is built on the ethos that the best open source projects enable people to not only use them, but to build with them. COSMIC is modular and composable. It’s the flagship experience for Pop!_OS in its own way, and can be adapted by anyone that wants to build their own unique user experience for Linux. ↫ Carl Richell You dont need to run Pop!_OS to try out COSMIC, as its already available on a variety of other distributions (although it may take a bit for this stable version to land in the respective repositories).


  • Windows 3.1s infamous Hot Dog Stand! colour scheme was not a joke
    Im sure most of us here are aware of the bright red-and-yellow colour scheme called Hot Dog Stand!, included in Windows 3.1. While its not the only truly garish colour scheme included in Windows 3.1, its name probably did a lot to make it stand out from the others. Theres been a ton of speculation about the origins of the colour scheme, and why it was included in Windows 3.1, but it seems nobody ever bothered to look for someone who actually worked on the Windows 3.1 user interface  until now. PC Gamers Wes Fenlon contacted Virginia Howlett, Microsofts first user interface designer who joined the company in 1985, and asked her about the infamous colour scheme. It turns out that the origin story for the infamous colour scheme is rather mundane. In Howletts own words: I do remember some discussion about whether we should include it, and some snarky laughter. But it was not intended as a joke. It was not inspired by any hot dog stands, and it was not included as an example of a bad interface—although it was one. It was just a garish choice, in case somebody out there liked ugly bright red and yellow. ↫ Virginia Howlett, quoted by Wes Fenlon in PC Gamer Howlett then lists a few other included colour schemes that were just as garish, or even more so, as examples to underline her point. Personally, Im a huge proponent of allowing users to make their interfaces as ugly and garish as they want, as the only arbiter on whats on your screen is you, and nobody else. Hot Dog Stand and similar garish themes need to make a comeback, because theres bound to be some people out there whose vibes align with it.


  • Using AI! to manage your Fedora system seems like a really bad idea
    IBM owns Red Hat which in turn runs Fedora, the popular desktop Linux distribution. Sadly, shit rolls downhill, so were starting to see some worrying signs that Fedora is going to be used a means to push AI!. Case in point, this article in the Fedora Magazine: Generative AI systems are changing the way people interact with computers. MCP (model context protocol) is a way that enables generate AI systems to run commands and use tools to enable live, conversational interaction with systems. Using the new linux-mcp-server, let’s walk through how you can talk with your Fedora system for understanding your system and getting help troubleshooting it! ↫ Máirín Duffy and Brian Smith at Fedora Magazine This linux-mcp-server! tool is developed by IBMs Red Hat, and of course, IBM has a vested interest in further increasing the size of the AI! bubble. As such, it makes sense from their perspective to start pushing AI! services and tools all the way down to the Fedora community, ending up with articles like this one. Whats sad is that even in this article, which surely uses the best possible examples, its hard to see how any of it could possibly be any faster than doing the example tasks without the help! of an AI!. In the first example, the AI! is supposed to figure out why the computer is having Wi-Fi connection issues, and while it does figure that out, the solutions it presents are really dumb and utterly wrong. Most notably, even though this is an article about running these tools on a Fedora system, written for Fedora Magazine, the AI! stubbornly insists on using apt for every solution, which is a basic, stupid mistake that doesnt exactly instill confidence in any of its other findings being accurate. The second example involves asking the AI! to explain how much disk space the system is using, and why. The prompt! (the human-created question! the AI! is supposed to answer!) is bonkers long  its a 117 words long monstrosity, formatted into several individual questions  and the output is so verbose and it takes such a scattershot approach that following-up on everything is going to take a huge amount of time. Within that same time frame, it wouldve been not only much faster, but also much more user-friendly to just open Filelight (installed by default as part of KDE), which creates a nice diagram which instantly shows you what is taking up space, and why. The third example is about creating an update readiness report for upgrading from Fedora 42 to Fedora 43, and its prompt! is even longer at 190 words, and writing that up with all those individual questions mustve taken more time than to just0 Do a simple dry-run of a dnf system upgrade which gets you like 90% of the way there. Here, too, the AI! blurts out so much information, much of which entirely useless, that going through it all takes more time than just manually checking up on a dnf dry run and peaking at your disk space usage. All this effort to set all of this up, and so much effort to carefully craft complex prompts!, only to end up with clearly wrong information, and way too much superfluous information that just ends up distracting you from the task you set out to accmplish. Is this really the kind of future of computing were supposed to be rooting for? Is this the kind of stuff Fedoras new AI! policy is supposed to enable? If so, Im afraid the disconnect between Fedoras leadership and whatever its users actually use Fedora for is far, far wider than I imagined.


  • FreeBSD debates sunsetting power64/power64le support
    I have some potentially devastating news for POWER users interested in using FreeBSD, uncovered late last month by none other than Cameron Kaiser. FreeBSD is considering retiring powerpc64 prior to branching 16, which would make FreeBSD 15 the last stable version to support the architecture. (32-bit PowerPC is already dropped as of FreeBSD 14, though both OpenBSD and NetBSD generally serve this use case, and myself I have a Mac mini G4 running a custom NetBSD kernel with code from FreeBSD for automatic restart.) Although the message says powerpc64 and powerpc64le! it later on only makes specific reference to the big-endian port, whereas both endiannesses appear on the FreeBSD platform page and on the download server. ↫ Cameron Kaiser Theres two POWER9 systems in my office, so this obviously makes me quite sad. At the same time, though, its hard not to understand any possible decision to drop powerpc64/powerpc64le at this point in time. Raptors excellent POWER9 systems  the Blackbird, which I reviewed a few years ago, and the Talos II, which I also have  are very long in the tooth at this point and still quite expensive, and thanks to IBM royally screwing up POWER10, we never got any timely successors. There were rumblings about a possible POWER11-based successor from Raptor back in July 2025, but its been quiet on that front since. In other words, there are no modern powerpc64 and powerpc64le systems available. POWER10 and brand new POWER11 hardware are strictly IBM and incredibly expensive, so unless IBM makes some sort of generous donation to the FreeBSD Foundation, I honestly dont know how FreeBSD is supposed to keep their powerpc64 and powerpc64le ports up-to-date with the latest generation of POWER hardware in the first place. Its important to note that no final decision has been made yet, and since that initial report by Kaiser, several people have chimed in to argue the case that at least powerpc64le (the little endian variant) should remain properly supported. In fact, Timothy Pearson from Raptor Engineering stepped up the place, and stated hes willing to take over maintainership of the port, as Raptor has been contributing to it for years anyway. Raptor remains committed to the architecture as a whole, and we have resources to assist with development. In fact, we sponsor several FreeBSD build machines already in our cloud environment, and have kernel developers working on expanding and maintaining the FreeBSD codebase. If there is any concern regarding hardware availability or developer resources, Raptor is willing and able to assist. ↫ Timothy Pearson Whatever decision the FreeBSD project makes, the Linux world will be fine for a while yet as IBM contributes to its development, and popular distributions still consider POWER a primary target. However, unless either IBM moves POWER hardware downmarket (extremely unlikely) or the rumours around Raptor have merit, I think at least the FreeBSD powerpc64 (big endian) port is done for, with the powerpc64le port hopefully being saved by people hearing these alarm bells.


  • US government switches to Times New Roman because Calibri is woke!
    Secretary of State Marco Rubio waded into the surprisingly fraught politics of typefaces on Tuesday with an order halting the State Department’s official use of Calibri, reversing a 2023 Biden-era directive that Mr. Rubio called a “wasteful” sop to diversity. While mostly framed as a matter of clarity and formality in presentation, Mr. Rubio’s directive to all diplomatic posts around the world blamed “radical” diversity, equity, inclusion and accessibility programs for what he said was a misguided and ineffective switch from the serif typeface Times New Roman to sans serif Calibri in official department paperwork. ↫ Michael Crowley and Hamed Aleaziz at The New York Times


  • What do Linux kernel version numbers mean?
    If youre old enough, you no doubt remember that up until the 2.6.0 release of the Linux kernel, an odd number after the first version number indicated a pre-release, development version of the kernel. Even though this scheme was abandoned with the 2.6.0 release in 2003 and since then every single release has been a stable release, it seems the ghosts of this old versioning scheme still roam the halls, because prominent Linux kernel developer Greg Kroah-Hartman just published an explainer about Linux kernel versions. Despite having a stable release model and cadence since December 2003, Linux kernel version numbers seem to baffle and confuse those that run across them, causing numerous groups to mistakenly make versioning statements that are flat out false. So let’s go into how this all works in detail. ↫ Greg Kroah-Hartman I genuinely find it difficult to imagine what could possibly be unclear about Linux kernel version numbers. The Linux kernel uses a very generic major.minor scheme, but thats not where the problems lie  its the actual development process of each of these numbered release thats a bit more complex. This is where we have to talk about things like the roughly 10-week release cycle, containing a 2-week merge window, as well as Torvalds handing off the stable branch to the stable kernel maintainers. The other oddity is when the major version number gets incremented  the first number in the version number. Theres no real method to this, as Kroah-Hartman admits Torvalds increments this number whenever the remaining numbers get too high and unwieldy to deal with. Very practical, but it does mean that going from, say, 5.x to 6.x doesnt really imply theres any changes in there that are any bigger or more disruptive than when going from 6.8.x to 6.9.x or whatever. Theres a few more important details in here, of course, like where LTS releases come from, but thats really it  nothing particularly groundbreaking or confusing.


  • Microsoft will allow you to remove AI! actions from Windows 11s context menus
    With the current, rapidly deteriorating state of the Windows operating system, you have to take the small wins you can get: Microsoft is now offering the option of removing AI! actions from Windows 11s context menus. buried deep in the Windows 11 Insider Preview Build 26220.7344 release notes, theres this nugget: If there are no available or enabled AI Actions, this section will no longer show in the context menu. ↫ Windows Insider Preview release notes If you then go to Settings > Apps > Actions and uncheck all the AI! actions, the entire submenu in Windows 11s context menus will vanish. While this is great news for those Windows users who dont want to be bothered by all the AI! nonsense, I wish Microsoft would just give users a proper way to edit the context menu that doesnt involve third party hackery. KDEs Dolphin file manager gives me full control over what does and does not appear in its context menu, and I cant imagine living without this functionality  theres so many file-related operations I never use, and having them clutter up the context menu is annoying and just slows me down. Theres more substantial and important changes in this Insider Preview Build too, most notably the rollout of the Update Orchestration Platform, which should make downloading and installing application updates less cumbersome, but since its a new feature, application wont support it right away. This release also brings the new Windows MIDI Services, and Microsoft hopes this will improve the experience for musicians using MIDI 1.0 or MIDI 2.0 on Windows. Theres a slew of smaller changes, too, of course. Im not exactly sure when these new features will make their way to production installations  who does, honestly, with Microsofts convoluted release processes  but I hope its sooner rather than later.


  • The anatomy of a macOS application
    When Mac OS X was designed, it switched to the bundle structure inherited from NeXTSTEP. Instead of this multitude of resources, apps consisted of a hierarchy of directories containing files of executable code, and those with what had in Mac OS been supporting resources. Those app bundles came to adopt a standard form, shown below. ↫ Howard Oakley A short, but nonetheless informative overview of the structure of a macOS application. Im sure most people on OSNews are aware that a macOS application is a bundle, which is effectively a glorified directory containing a variety of files and subdirectories that together make up the application. I havent used macOS in a while, but I think you can right-click on an application and open it as a folder to dig around inside of it. Im trying to remember from my days as a Mac OS X user  15-20 years ago  if there was ever a real need to do so, but Im sure there were a few hacks you could do by messing around with the files inside of application bundles. These days, perhaps with all the code-signing, phoning-home to Apple, and other security trickery going on, such acts are quite frowned upon. Does making any otherwise harmless changes inside an application bundle set off a ton of alarm bells in macOs these days?


  • Applets are officially gone, but Java in the browser is better than ever
    The end of an era, perhaps. Applets are officially, completely removed from Java 26, coming in March of 2026. This brings to an official end the era of applets, which began in 1996. However, for years it has been possible to build modern, interactive web pages in Java without needing applets or plugins. TeaVM provides fast, performant, and lightweight tooling to transpile Java to run natively in the browser. And for a full front-end toolkit with templates, routing, components, and more, Flavour lets you build your modern single-page app using 100% Java. ↫ Andrew Oliver As consumers, we dont really encounter Java that much anymore unless we play Minecraft, but that doesnt mean Java no longer has a place in this world. In fact, it still consistently ranks in the top three of most popular programming languages, so any tools to make using Java easier, both for programmers and users, are welcome.


  • OSNews needs your donations to survive
    OSNews is funded entirely by you, our readers. There are no ads on OSNews, we are not part of a massive corporate publishing conglomerate like virtually every other technology news website, there are no wealthy (corporate) benefactors  its just whatever funds you, our readers, send our way. As such, I sometimes need to remind everyone about this, and December, the holiday month, seems as great a time as any to do this. If you want to support a truly independent technology news website, free from the corrupting influences of corporate interests, advertising companies, managers pushing AI!, and all the other nonsense destroying the web we once loved, you can do so by donating to keep OSNews alive. This gives me the time and means to write 9000 words about dead computer ecosystems, and Im already working on an article about the next final UNIX workstation. Every single donation, large or small, is deeply appreciated and keeps the lights on around here. There arent many websites like OSNews left, especially not independent ones that answer to nobody. Your support keeps OSNews going, with June 2026 marking a special moment for me: it will mark twenty years since I took over this place. Im not expecting a party  youre paying me to work, not to party  but it is still a meaningful anniversary for me personally.


  • Porting rePalm to Pixter devices
    Some of you may be aware of rePalm, a project by Dmitry Grinberg to port the PalmOS to various devices it was never supposed to run on. We covered rePalm back in 2019 and again in 2023. His latest project involved porting PalmOS to a set of digital toys that were never intended to run PalmOS in any way. Fisher-Price (owned by Mattel) produced some toys in the early 2000 under the Pixter brand. They were touchscreen-based drawing toys, with cartridge-based extra games one could plug in. Pixter devices of the first three generations ( classic!, plus!, and 2.0!) featured 8080 black-and-white screens, which makes them of no interest for rePalm. The last two generations of Pixter ( color! and multimedia!) featured 160160 color displays. Now, this was more like it! Pixter was quite popular, as far as kids toys go, in USA in the early 2000s. A friend brought it to my attention a year ago as a potential rePalm target. The screen resolution was right and looking inside a Pixter Color! showed an ARM SoC  a Sharp LH75411. The device had sound (games made noises), and touch panel was resistive. In theory  a viable rePalm target indeed. ↫ Dmitry Grinberg Considering the immensely limited ARMv7 implementation he had to deal with  no cache, no memory management unit, no memory protection unit  its a miracle Grinberg managed to succeed. To make matters even harder, the first revision boards of the color! model only had 1MB of flash, which is incredibly small even for PalmOS 5, so he had to rewrite parts of it to make it fit. Implementing communication over infrared was also a major difficulty, but that, too he managed to get working  on a device that doesnt have IrDA SIR modulation. Wild. Grinberg went above and beyond, making sure the buttons on the devices work, developing and building a way to put PalmOS on a game! cartridge, reverse-engineering the display controller to make sure things like brightness adjustment works, adding screen type detection for that one small run of Pixter Color devices that came with a TFT instead of an STN screen, and so, so much more. Until you read the article, you have no idea how much work Grinberg put into this project. I continue to be in awe of Grinbergs work every time I come across it.


  • Haiku highlights interesting stalled commits you might want to adopt
    Now this is a great initiative by the Haiku team: highlight a number of stale commits thatve been without interaction for years, explain why theyve stalled, and then hope renewed interest might grow (part 1 and part 2). Recently some discussions on the forum led to asking about the status of our Gerrit code review. There are a lot of changes there that have been inactive for several years, with no apparent interest from anyone. To be precise, there are currently 358 commits waiting for review (note that Gerrit, unlike Github and other popular code review tools, works on a commit-by-commit basis, so each commit from a multiple-commit change is counted separately). The oldest one has not seen any comments since 2018. Today, let’s have a look at some of these changes and see why they are stalled. Hopefully it will inspire someone to pick up the work and help finishing them up. ↫ Pulkomandy at the Haiku website Browsing through the highlighted stalled commits, theres a few that seem quite interesting and relatively easy for a (new?) contributor to seek their teeth into. For instance, theres a stalled commit to remove GCC from Haiku images built with clang/llvm, which stalled mostly because there are still other issues when building Haiku with clang/llvm. For a more complex problem, theres the issue of how every menu in BeOS/Haiku is also a window, including its own thread, which means navigating deeply nested menus creates and destroys a lot of threads, that all need to be synchronised, too. If you want to get really ambitious, theres the stalled commit to add initial 64bit PowerPC support. Theres more of these, of course, so if you have the skills and will to contribute to a project like Haiku, this might be a great place to start and get your feet wet. Now that these commits are back in the spotlight, theres sure to be team members and regular contributors lined up to lend an extra hand, as well.


  • Oracle Solaris 11.4 SRU 87 released
    Oracle has released Solaris 11.4 SRU 87, which brings with it a whole slew of changes, updates, and fixes. Primarily, it upgrades Firefox and Thunderbird to their latest ESR 140.3.0 releases, and adds GCC 15, alongside a ton of updated other open source packages. On more Solaris 11-specific notes, useradds account activation options have been changed to address some issues caused by stricter enforcement introduced in SRU 78, theres some preparations for the upgrade to BIND 9.20 in a future Solaris 11 release, a few virtualisation improvements, and much more. If youre unclear about the relationship between this new release and the Common Build Environment or CBE release of Solaris 11.4 for enthusiasts, released earlier this year, the gist is that these SRU updates are only available to people with Oracle Solaris support contracts, while any updates to the CBE release are available to mere mortals like you and I. If you have a support contract and are using the CBE, you can upgrade from the CBE to the official SRU releases, but without such a contract, youre out of luck. A new CBE release is in the works, and is planned to arrive in 2026  which is great news, but I would love for the enthusiast variant of Solaris 11.4 to receive more regular updates. I dont think making these SRU updates available to enthusiasts in a non-commercial, zero-warranty kind of way would pose any kind of threat to Oracles bottom line, but alas, I dont run a business like Oracle so perhaps Im wrong.


Linux Journal - The Original Magazine of the Linux Community

  • Linux Kernel 5.4 Reaches End-of-Life: Time to Retire a Workhorse
    by George Whittaker
    One of the most widely deployed Linux kernels has officially reached the end of its lifecycle. The maintainers of the Linux kernel have confirmed that Linux 5.4, once a cornerstone of countless servers, desktops, and embedded devices, is now end-of-life (EOL). After years of long-term support, the branch has been retired and will no longer receive upstream fixes or security updates.
    A Kernel Release That Defined a Generation of Linux Systems
    When Linux 5.4 debuted, it made headlines for bringing native exFAT support, broader hardware compatibility, and performance improvements that many distributions quickly embraced. It became the foundation for major OS releases, including Ubuntu LTS, certain ChromeOS versions, Android kernels, and numerous appliance and IoT devices.

    Its long support window made it a favorite for organizations seeking stability over bleeding-edge features.
    What End-of-Life Actually Means
    With the EOL announcement, the upstream kernel maintainers are officially done with version 5.4. That means:

    No more security patches

    No more bug fixes or performance updates

    No regressions or vulnerabilities will be addressed

    Some enterprise vendors may continue backporting patches privately, but the public upstream branch is now frozen. For most users, that makes 5.4 effectively unsafe to run.
    Why This Matters for Users and Organizations
    Many devices, especially embedded systems, tend to run kernels for much longer than desktops or servers. If those systems continue using 5.4, they now risk exposure to unpatched vulnerabilities.

    Running an unsupported kernel can also create compliance issues for companies operating under strict security guidelines or certifications. Even home users running older LTS distributions may unknowingly remain on a kernel that’s no longer protected.
    Upgrading Is the Clear Next Step
    With 5.4 retired, users should begin planning an upgrade to a supported kernel line. Today’s active long-term support kernels include more modern branches such as 6.1, 6.6, and 6.8, which provide:

    Better CPU and GPU support

    Significant security improvements

    Enhanced performance and energy efficiency

    Longer future support windows

    Before upgrading, organizations should test workloads, custom drivers, and hardware, especially with specialized or embedded deployments.
    Go to Full Article


  • Linux Distros Designed for Former Windows Users Are Picking Up Steam
    by George Whittaker
    For years, Windows users frustrated with constant changes, aggressive updates, and growing system bloat have flirted with switching to Linux. But 2025 marks a noticeable shift: a new generation of Linux distributions built specifically for ex-Windows users is gaining real traction. One of the standout examples is Bazzite, a gaming-optimized Fedora-based distro that has quickly become a go-to choice for people abandoning Windows in favor of a cleaner, more customizable experience.
    Why Many Windows Users Are Finally Jumping Ship
    Microsoft’s ecosystem has been slowly pushing some users toward the exit. Hardware requirements for Windows 11 left millions of perfectly functional PCs behind. Ads on the Start menu and in system notifications have frustrated many. And for gamers, launcher problems, forced reboots and background processes that siphon resources have driven a search for alternatives.

    Linux distributions have benefited from that frustration, especially those that focus on simplicity, performance and gaming readiness.
    Gaming-First Distros Are Leading the Movement
    Historically, switching to Linux meant sacrificing game compatibility. But with Valve’s Proton layer and Vulkan-based translation technologies, thousands of Windows games now run flawlessly, sometimes better than on Windows.

    Distros targeting former Windows users are leaning into this new reality:

    Seamless Steam integration

    Automatic driver configuration for AMD, Intel and NVIDIA

    Built-in performance overlays like MangoHUD

    Proton GE and tools for modding or shader fixes

    Support for HDR, VR and modern controller layouts

    This means a new Linux user can install one of these distros and jump straight into gaming with almost no setup.
    Bazzite: A Standout Alternative OS
    Bazzite has become the poster child for this trend. Built on Fedora’s image-based system and the Universal Blue infrastructure, it offers an incredibly stable base that updates atomically, similar to SteamOS.

    What makes Bazzite so attractive to Windows refugees?

    Gaming-ready out of the box no tweaking, no driver hunts

    Rock-solid performance thanks to an immutable system layout

    Support for handheld PCs like the Steam Deck, ROG Ally and Legion Go

    Friendly workflows that feel familiar to new Linux users

    Customization without the risk of breaking the system

    It’s no surprise that many “I switched to Linux!” posts now mention Bazzite as their distro of choice.
    Go to Full Article


  • Linux Kernel 6.18 Is Out: What’s New and Important
    by George Whittaker
    The stable release of Linux Kernel 6.18 was officially tagged on November 30, 2025.

    It’s expected to become this year’s major long-term support (LTS) kernel, something many users and distributions care about.

    Here’s a breakdown of the most significant changes and improvements in this release:
    Core Improvements: Performance, Memory, Infrastructure
    The kernel’s memory allocation subsystem gets a major upgrade with “sheaves”, a per-CPU caching layer for slab allocations. This reduces locking overhead and speeds up memory allocation and freeing, improving overall system responsiveness.

    A new device-mapper target dm-pcache arrives, enabling use of persistent memory (e.g. NVDIMM/CXL) as a cache layer for block devices, useful for systems with fast non-volatile memory, SSDs, or hybrid storage.

    Overall memory management and swapping performance have been improved, which should help under memory pressure or heavy workloads.
    Networking & Security Enhancements
    Networking gets a boost: support for Accurate Explicit Congestion Notification (AccECN) in TCP, which can provide better congestion signals and more efficient network behaviour under load.

    A new option for PSP-encrypted TCP connections has been added, a fresh attempt to push more secure transport-layer encryption (like a more efficient alternative to IPsec/TLS for some workloads) under kernel control.

    The kernel now supports cryptographically signed BPF programs (eBPF), so BPF bytecode loaded at runtime can be verified for integrity. This is a noteworthy security hardening step.

    The overall security infrastructure and auditing path, including multi-LSM (Linux Security Modules) support, has been refined, improving compatibility for setups using SELinux, AppArmor, or similar simultaneously.
    Hardware, Drivers & Architecture Coverage
    Kernel 6.18 brings enhanced hardware support: updated and new drivers for many platforms across architectures (x86_64, ARM, RISC-V, MIPS, etc.), including improvements for GPUs, CPU power management, storage controllers, and more.

    In particular, support for newer SoCs, chipsets, and embedded-board device trees has been extended, beneficial for people using SBCs, ARM-based laptops/boards, or niche hardware.

    For gaming rigs, laptops, and desktops alike: improvements to drivers, power-state management, and performance tuning may lead to better overall hardware efficiency.
    Go to Full Article


  • Wine 10.19 Released: Game Changing Support for Windows Reparse Points on Linux
    by George Whittaker Introduction
    If you use Linux and occasionally run Windows applications, whether via native Wine or through gaming layers like Proton, you’ll appreciate what just dropped in Wine 10.19. Released November 14 2025, this version brings a major enhancement: official support for Windows reparse points, a filesystem feature many Windows apps rely on, and a host of other compatibility upgrades.

    In simpler terms: Wine now understands more of the Windows filesystem semantics, which means fewer workarounds, better application compatibility, and smoother experiences for many games and tools previously finicky under Linux.
    What Are Reparse Points & Why They MatterUnderstanding Reparse Points
    On Windows, a reparse point is a filesystem object (file or directory) that carries additional data, often used for symbolic links, junctions, mount points, or other redirection features. When an application opens or queries a file, the OS may check the reparse tag to determine special behavior (for example “redirect this file open to this other path”).

    Because many Windows apps, installers, games, DRM systems, file-managers, use reparse points for features like directory redirection, path abstractions, or filesystem overlays, lacking full support for them in Wine means those apps often misbehave.
    What Wine 10.19 Adds
    With Wine 10.19, support for these reparse point mechanisms has been implemented in key filesystem APIs: for example NtQueryDirectoryFile, GetFileInfo, file attribute tags, and DeleteFile/RemoveDirectory for reparse objects.

    This means that in Wine 10.19:

    Windows apps that create or manage symbolic links, directory junctions or mount-point style re-parsing will now function correctly in many more cases.

    Installers or frameworks that rely on “when opening path X, redirect to path Y” will work with less tinkering.

    Games or utilities that check for reparse tags or use directory redirections will have fewer “stuck” behaviors or missing files.

    In effect, this is a step toward closer to native behavior for Windows file-system semantics under Linux.
    Other Key Highlights in Wine 10.19
    Beyond reparse points, the release brings several notable improvements:

    Expanded support for WinRT exceptions (Windows Runtime error handling) meaning better compatibility for Universal Windows Platform (UWP) apps and newer Windows-based frameworks.

    Refactoring of “Common Controls” (COMCTL32) following the version 5 vs version 6 split, which helps GUI applications that rely on older controls or expect mixed versions.
    Go to Full Article


  • Firefox 145: A Major Release with 32-Bit Linux Support Dropped
    by George Whittaker Introduction
    Mozilla has rolled out Firefox 145, a significant update that brings a range of usability, security and privacy enhancements, while marking a clear turning point by discontinuing official support for 32-bit Linux systems. For users on older hardware or legacy distros, this change means it’s time to consider moving to a 64-bit environment or opting for a supported version.

    Here’s a detailed look at what’s new, what’s changed, and what you need to know.
    Major Changes in Firefox 145End of 32-Bit Linux Builds
    One of the headline items in this release is Mozilla’s decision to stop building and distributing Firefox for 32-bit x86 Linux. As per their announcement:

    “32-bit Linux (on x86) is no longer widely supported by the vast majority of Linux distributions, and maintaining Firefox on this platform has become increasingly difficult and unreliable.”

    From Firefox 145 onward, only 64-bit (x86_64) and relevant 64-bit architectures (such as ARM64) will be officially supported. For those still running 32-bit Linux builds, Mozilla recommends migrating to 64-bit or switching to the Extended Support Release (ESR) branch (Firefox 140 ESR) which still supports 32-bit for a limited period.
    Usability & Interface Enhancements
    Firefox 145 brings several improvements designed to make everyday web browsing smoother and more flexible:

    PDF viewer enhancements: You can now add, edit, and delete comments in PDFs, and a comments sidebar helps you easily navigate your annotations.

    Tab-group preview: When you hover over the name of a collapsed tab group, a thumbnail preview of the tabs inside appears, helpful for reorganizing or returning to work.

    Access saved passwords from the sidebar, without needing to open a new tab or window.

    “Open links from apps next to your active tab” setting: When enabled, links opened from external applications insert next to your current tab instead of at the end of the tab bar.

    Slight UI refinements: Buttons, input fields, tabs and other elements get more rounded edges, horizontal tabs are redesigned to align with vertical-tab aesthetics.
    Privacy, Security & Under-the-Hood Upgrades
    Mozilla has also doubled down on privacy and risk reduction:

    Fingerprinting defenses: Firefox 145 introduces new anti-fingerprinting techniques that Mozilla estimates reduce the number of users identified as unique by nearly half when Private Browsing mode or Enhanced Tracking Protection (strict) is used.
    Go to Full Article


  • MX Linux 25 ‘Infinity’ Arrives: Debian 13 ‘Trixie’ Base, Modern Tools & A Fresh Installer
    by George Whittaker Introduction
    The team behind MX Linux has just released version 25, carrying the codename “Infinity”, and it brings a significant upgrade by building upon the stable base of Debian 13 “Trixie”. Released on November 9, 2025, this edition doesn’t just refresh the desktop, it introduces modernized tooling, updated kernels, dual init-options, and installer enhancements aimed at both newcomers and long-time users.

    In the sections that follow, we’ll walk through the key new features of MX Linux 25, what’s changed for each desktop edition, recommended upgrade or fresh-install paths, and why this release matters in the wider Linux-distribution ecosystem.
    What’s New in MX Linux 25 “Infinity”
    Here are the headline changes and improvements that define this release:
    Debian 13 “Trixie” Base
    By moving to Debian 13, Infinity inherits all the stability, security updates, and broader hardware support of the latest Debian stable release. The base system now aligns with Trixie’s libraries, kernels, and architecture support.
    Kernel Choices & Hardware Support
    The standard editions ship with the Linux 6.12 LTS kernel series, offering a solid baseline for most hardware.

    For newer hardware or advanced users, the “AHS” (Advanced Hardware Support) variants and the KDE Plasma edition adopt a Liquorix-flavored Linux 6.16 (or 6.15 in some variants) kernel, maximizing performance and compatibility with cutting-edge setups.
    Dual Init Option: systemd and SysVinit
    Traditionally associated with lighter-weight init options, MX Linux now offers both systemd by default and SysVinit editions (particularly for Xfce and Fluxbox variants). This gives users the freedom to choose their init system preference without losing new features.
    Updated Desktop Environments
    Xfce edition: Ships with Xfce 4.20. Improvements include a revamped Whisker Menu, updated archive management tools (Engrampa replacing File Roller in some editions).

    KDE Plasma edition: Uses KDE Plasma 6.3.6, defaults to Wayland for a modern session experience (with X11 still optionally available), adds root-actions and service menus to Dolphin, and switches TLP out for power-profiles-daemon to resolve power widget issues.

    Fluxbox edition: Offers a more minimal, highly customizable environment: new panel layouts, updated “appfinder” configs for Rofi, toolbar changes and themes refined. Defaults the audio player to Audacious (instead of the older DeaDBeeF).
    Go to Full Article


  • Arch Linux November 2025 ISO: Fresh Snapshot, Smarter Installer (Archinstall 3.0.12) & Pacman 7.1
    by George Whittaker
    Arch Linux has shipped its November 2025 ISO snapshot (2025.11.01), and while Arch remains a rolling distribution, these monthly images are a big deal, especially for new installs, labs, and homelab deployments. This time, the ISO lands alongside two important pieces:

    Archinstall 3.0.12 – a more polished, smarter TUI installer

    Pacman 7.1 – a package manager update with stricter security and better tooling

    If you’ve been thinking about spinning up a fresh Arch box, or you’re curious what changed under the hood, this release is a very nice jumping-on point.
    Why Arch Still Ships Monthly ISOs in a Rolling World
    Arch is famous for its “install once, update forever” model. Technically, you could install from a two-year-old image and just run:

    sudo pacman -Syu

    …but in practice, that’s painful:

    Huge initial update downloads

    Possible breakage jumping across many months of changes

    Outdated installer tooling

    That’s why the project publishes a monthly snapshot ISO: it rolls all current packages into a fresh image so you:

    Start with a current kernel and userland

    Spend less time updating right after install

    Get the latest Archinstall baked in (or just a pacman -Sy archinstall away)

    The 2025.11.01 ISO is exactly that: Arch as of early November 2025, ready to go.
    What’s Inside the November 2025 ISO (2025.11.01)
    The November snapshot doesn’t introduce new features by itself, it’s a frozen image of current Arch, but a few details are worth calling out:

    Ships with a Linux 6.17.x kernel, including improved AMD/Intel GPU support and updated Btrfs bits.

    Includes all the usual base packages plus current toolchains, drivers, and desktop stacks from the rolling repos.

    The image is intended only for new installs; existing Arch systems should keep using pacman -Syu for upgrades.

    You can download it from the official Arch Linux download page or via BitTorrent mirrors.

    One small twist: the ISO itself still ships with Archinstall 3.0.11, but 3.0.12 was released the same day – so we’ll grab the newer version from the repos before running the installer.
    Archinstall 3.0.12: What’s Actually New?
    Archinstall has evolved from “nice experiment” to “pretty solid way to install Arch” if you don’t want to script everything yourself. Version 3.0.12 is a refinement release focused on stability, storage, and bootloader logic.
    Go to Full Article


  • AMD Confirms Zen 5 RNG Flaw: When ‘Random’ Isn’t Random Enough
    by George Whittaker
    AMD has officially confirmed a high-severity security vulnerability in its new Zen 5–based CPUs, and it’s a nasty one because it hits cryptography right at the source: the hardware random number generator.

    Here’s a clear breakdown of what’s going on, how bad it really is, and what you should do if you’re running Zen 5.
    What AMD Just Confirmed
    AMD’s security bulletin AMD-SB-7055, now tracked as CVE-2025-62626, describes a bug in the RDSEED instruction on Zen 5 processors. Under certain conditions, the CPU can:

    Return the value 0 from RDSEED far more often than true randomness would allow

    Still signal “success” (carry flag CF=1), so software thinks it got a good random value

    The issue affects the 16-bit and 32-bit forms of RDSEED on Zen 5; the 64-bit form is not affected.

    Because RDSEED is used to feed cryptographically secure random number generators (CSPRNGs), a broken RDSEED can poison keys, tokens, and other security-critical values.

    AMD classifies the impact as:

    Loss of confidentiality and integrity (High severity).
    How the Vulnerability Works (In Plain English)What RDSEED Is Supposed to Do
    Modern CPUs expose hardware instructions like RDRAND and RDSEED:

    RDRAND: Gives you pseudo-random values from a DRBG that’s already been seeded.

    RDSEED: Gives you raw entropy samples suitable for seeding cryptographic PRNGs (it should be very close to truly random).

    Software like TLS libraries, key generators, HSM emulators, and OS RNGs may rely directly or indirectly on RDSEED to bootstrap secure randomness.
    What’s Going Wrong on Zen 5
    On affected Zen 5 CPUs:

    The 16-bit and 32-bit RDSEED variants sometimes return 0 much more often than a true random source should.

    Even worse, they simultaneously report success (CF=1), so software assumes the value is fine rather than retrying.

    In cryptographic terms, this means:

    Entropy can be dramatically reduced (many key bits become predictable or even fixed).

    Keys or nonces derived from those values can become partially or fully guessable.
    Go to Full Article


  • The Most Critical Linux Kernel Breaches of 2025 So Far
    by George Whittaker
    The Linux kernel, foundational for servers, desktops, embedded systems, and cloud infrastructure, has been under heightened scrutiny. Several vulnerabilities have been exploited in real-world attacks, targeting critical subsystems and isolation layers. In this article, we’ll walk through major examples, explain their significance, and offer actionable guidance for defenders.
    CVE-2025-21756 – Use-After-Free in the vsock Subsystem
    One of the most alarming flaws this year involves a use-after-free vulnerability in the Linux kernel’s vsock implementation (Virtual Socket), which enables communication between virtual machines and their hosts.

    How the exploit works:A malicious actor inside a VM (or other privileged context) manipulates reference counters when a vsock transport is reassigned. The code ends up freeing a socket object while it’s still in use, enabling memory corruption and potentially root-level access.

    Why it matters:Since vsock is used for VM-to-host and inter-VM communication, this flaw breaks a key isolation barrier. In multi-tenant cloud environments or container hosts that expose vsock endpoints, the impact can be severe.

    Mitigation:Kernel maintainers have released patches. If your systems run hosts, hypervisors, or other environments where vsock is present, make sure the kernel is updated and virtualization subsystems are patched.
    CVE-2025-38236 – Out-of-Bounds / Sandbox Escape via UNIX Domain Sockets
    Another high-impact vulnerability involves the UNIX domain socket interface and the MSG_OOB flag. The bug was publicly detailed in August 2025 and is already in active discussion.

    Attack scenario:A process running inside a sandbox (for example a browser renderer) can exploit MSG_OOB operations on a UNIX domain socket to trigger a use-after-free or out-of-bounds read/write. That allows leaking kernel pointers or memory and then chaining to full kernel privilege escalation.

    Why it matters:This vulnerability is especially dangerous because it bridges from a low-privilege sandboxed process to kernel-level compromise. Many systems assume sandboxed code is safe; this attack undermines that assumption.

    Mitigation:Distributions and vendors (like browser teams) have disabled or restricted MSG_OOB usage for sandboxed contexts. Kernel patches are available. Systems that run browser sandboxes or other sandboxed processes need to apply these updates immediately.
    CVE-2025-38352 – TOCTOU Race Condition in POSIX CPU Timers
    In September 2025, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
    Go to Full Article


  • Steam Deck 2 Rumors Ignite a New Era for Linux Gaming
    by George Whittaker
    The speculation around a successor to the Steam Deck has stirred renewed excitement, not just for a new handheld, but for what it signals in Linux-based gaming. With whispers of next-gen specs, deeper integration of SteamOS, and an evolving handheld PC ecosystem, these rumors are fueling broader hopes that Linux gaming is entering a more mature age. In this article we look at the existing rumors, how they tie into the Linux gaming landscape, why this matters, and what to watch.
    What the Rumours Suggest
    Although Valve has kept things quiet, multiple credible outlets report about the Steam Deck 2 being in development and potentially arriving well after 2026. Some of the key tid-bits:

    Editorials note that Valve isn’t planning a mere spec refresh; it wants a “generational leap in compute without sacrificing battery life”.

    A leaked hardware slide pointed to an AMD “Magnus”-class APU built on Zen 6 architecture being tied to next-gen handhelds, including speculation about the Steam Deck 2.

    One hardware leaker (KeplerL2) cited a possible 2028 launch window for the Steam Deck 2, which would make it roughly 6 years after the original.

    Valve’s own design leads have publicly stated that a refresh with only 20-30% more performance is “not meaningful enough”, implying they’re waiting for a more substantial upgrade.

    In short: while nothing is official yet, there’s strong evidence that Valve is working on the next iteration and wants it to be a noteworthy jump, not just a minor update.
    Why This Matters for Linux Gaming
    The rumoured arrival of the Steam Deck 2 isn’t just about hardware, it reflects and could accelerate key inflection points for Linux & gaming:
    Validation of SteamOS & Linux Gaming
    The original Steam Deck, running SteamOS (a Linux-based OS), helped prove that PC gaming doesn’t always require Windows. A well-received successor would further validate Linux as a first-class gaming platform, not a niche alternative but a mainstream choice.
    Handheld PC Ecosystem Momentum
    Since the first Deck, many Windows-based handhelds have entered the market (such as the ROG Ally, Lenovo Legion Go). Rumours of the Deck 2 keep spotlight on the form factor and raise expectations for Linux-native handhelds. This momentum helps encourage driver, compatibility and OS investments from the broader community.
    Go to Full Article


Page last modified on November 02, 2011, at 10:01 PM