Posts
549
Following
36
Followers
2347

Jonathan Corbet

Ah what a world we have built...

"In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.

What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves."

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
1
9
15

You will be sorely missed Dan Williams, you were a good engineer and a great person, I will miss seeing you at our conferences every year. You were the best of us and you leave quite the hole.

0
6
2
@Epic_Null @Li The first step after a GrapheneOS install is to lock the bootloader again so no, it's not unlocked.
1
0
4
@lienrag As a general rule you have to unlock the phone before you can image it — and the contents of the drive are encrypted. If the phone is in the before-first-unlock state, especially, getting at its contents will be hard.

There are, naturally, forensics tools out there meant to bypass these protections. I have no way to know how effective they are on a GrapheneOS install.
0
0
5

Jonathan Corbet

GrapheneOS has a "duress code" feature that will wipe the device if it is used in an attempt to unlock it. A potentially useful feature, but the US is now trying to prosecute somebody for having given the duress code to an officer demanding the unlocking of his phone.

https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
26
310
261
@JohnAZoidberg Conversations in a forum site are trapped within that site; you have to go there to see them at all. It makes any sort of cross-project interaction harder, and makes life difficult for people trying to follow a number of different projects.
0
0
1

Jonathan Corbet

Years ago, I complained loudly when the Fedora project proclaimed that its mailing lists were dead and all discussions would move to its forum silo. So, needless to say, I applaud the decision (or at least the proposed decision) to begin moving back toward the mailing lists:

https://lwn.net/ml/all/CAJqbrbdZ9R47=otYx2h5YmCFcsKzA7xHVWqWAZ2qT4503gLZCg@mail.gmail.com
2
6
21

Jonathan Corbet

"The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV."

— Krebs https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/

Better late than never, I guess.
1
7
22

Haha. CCS2 electrical vehicle chargers communicate by running powerline commnication (yes, a full IP networking stack) over the wires plugged in your vehicle. And yes, some charging stations have a ssh listening, with default credentials (root/root).

https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers

(thanks @faheus for pointing me to it)

5
23
1

Jonathan Corbet

I've been spending rather too much of my time reading the depressing threads on LLM use in the kernel. But I thought that this contribution from Lyude Paul worth the investment.

"For many people who need their jobs, guidelines around acceptable use of these tools beyond "a person needs to own the the code" may end up being the only thing allowing employees to be responsible with their contributions without repercussion from employers."

https://lwn.net/ml/all/3a5d891b536588e8e4fc84d60a5c8af72091d852.camel@redhat.com
4
52
94

Jonathan Corbet

I'm not normally one for posting videos, but I stumbled across this recording of Neil Young playing Cowgirl in the Sand and no work got done for a solid 20 minutes.

https://www.youtube.com/watch?v=5CBCnaHDpwQ
2
0
12
@rostedt To quote Douglas Adams: "This had made many people very angry and has been widely regarded as a bad move." :)
0
0
3

Jonathan Corbet

The dog days of summer
3
2
28

Jonathan Corbet

"More generally, liability concerns could mean that many current use cases for agents won’t be commercially viable. Companies may not be able to profitably operate AI lawyers, doctors and media influencers if they are held responsible for what they say and do.

We’re OK with this outcome. There’s nothing in the law that requires us to accommodate AI systems if they are fundamentally untrustworthy, just as we don’t need to accommodate untrustworthy human systems."

— Bruce Schneier https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html
0
36
53
@danyork @lwn Hopefully that will help, at least for a while. The takedown of IPIDEA earlier this year calmed things considerably for a few months. They always seem to rebuild their botnets, though...
0
0
2
@kkarhan @lwn So if we get one hit on, say, an article written in 2010, do we go through that whole process? How do we know that that isn't the one case of a real human following a link of interest? And how do we send, say, two-million abuse reports without just ending up on the spam blacklists ourselves?

Absolutist solutions like that sound good, but lack practicality.
1
0
1
@ezarowny @lwn Someday I would love to talk about them. I'm somewhat reluctant to do that now, though, at least until I've figured out what we're going to do when those strategies stop being effective.
1
0
1
@kkarhan @lwn The problem it that it's *all* the ASNs. Probably even yours. These scrapers are built into apps and running on devices without the knowledge of their ostensible owners. Perhaps your phone is one of them.

Have a look at companies like Bright Data or opscloudio.com if you want to see how that sleazy business works.
2
5
10
@StompyRobot @lwn User agent is whatever random fiction they choose to put in there; there is no useful signal there. We really don't want to inflict captchas or cloudflare or any of that onto our readers, so we've had to find other ways to defend the site.
1
0
12
Show older