Posts
261
Following
25
Followers
1213
@ariadne One way around the problem, of course, is to propose a talk about some interesting work you are doing. OSS is starving for good technical content, and that makes the admission-fee problem go away.
1
0
1
@ricci @cloudlab @sachindhke I've often wished I could submit a patch to the brute-force scripts to recognize an SSH server that has password authentication disabled. The resources saved would be considerable.
1
1
7

Jonathan Corbet

Edited 8 months ago
The eclipse was only 64% here but the solar panels definitely noticed.
0
2
9
@monsieuricon I got around this by thinking of ln as a rename that doesn't remove the old file. And, indeed, they are the same program underneath.
1
1
17

Jonathan Corbet

Sigh ... John Barth is gone ... https://www.theguardian.com/books/2024/apr/03/john-barth-death-american-novelist-dies-dead-aged-93 time to get into Giles Goat Boy again
1
1
1

I am a bit concerned by all the focus on small-ish projects with overwhelmed maintainers. There indeed are a lot of problems in that area.

But I am certain that lots of experienced OSS devs can think of a few large and crucial projects where they fairly easily could have hidden something small in a larger change. Without a lot of prior contributions to the project.

2
2
1

Jonathan Corbet

Edited 8 months ago
Quote of the day (from the Fedora devel list):
We have no mechanism to flag when J. Random Packager adds "Supplements: glibc" to their random leaf node package. As a reminder, *we are a project that allows 1,601 minimally-vetted people to deliver arbitrary code executed as root on hundreds of thousands of systems*, and this mechanism allows any one of those people to cause the package they have complete control over to be automatically pulled in as a dependency on virtually every single one of those systems.
— Adam Williamson
1
81
99

Jonathan Corbet

Edited 8 months ago
I'm on a holiday and only happened to look at my emails and it seems to be a major mess.
— Lasse Collin
0
27
58
@zeruch Well, I don't know any more than anybody else (and less than many) so I'm not sure why you're asking me. It's all speculation at this point, but it would not surprise me to learn that there is indeed some agency behind this.
0
0
1

Jonathan Corbet

Edited 8 months ago
Also if you're on F41 and/or think you might have installed the vulnerable xz anywhere, note that the exploit has not been fully analyzed and no one really knows what it could do. I'm currently reinstalling a couple of machines from scratch and have regenerated my SSH keys.

— Richard W.M. Jones

0
8
10
@brauner Yup, I've been doing some digging. That patch (and the series containing it) is in linux-next now, but hasn't made it to mainline.

The last patch from Lasse Collin in mainline is from October 2021. There are reasons for people to go quiet, but one does wonder about why they returned just now.
0
1
4

Jonathan Corbet

Random, unordered, probably useless thoughts on today's apocalypxze...

Part of the success in getting this into Debian may be the result of there being no xz maintainer there. It is "maintained" by people whose attention is normally elsewhere doing occasional non-maintainer updates.

This code will have been running on the machines of a lot of distribution maintainers. If it has already been exploited, it could be that its real purpose has already been achieved and the real problem is now elsewhere. I sure hope somebody can figure out a way to determine if this backdoor has been used.

The multi-front nature of the attack, including multiple efforts to get the malicious code installed more widely more quickly, suggests we're not just dealing with a lone sociopath. I fear we'll never know who was really behind this, but I would sure like to.

There is surely more where this cam from.
13
156
227

Jonathan Corbet

One of the things I have been doing to approve my language skills is reading science fiction in Italian. It's surprisingly hard to find books by Italian SF authors (even though there are many of them) rather than yet another Tolkien translation; this is especially true in Italian bookstores, sadly. Ebooks fill in nicely, though, once you discover who you're looking for.

I recently read WOHPE by Salvatore Sanfilippo. The story, which deals with fears of the AI apocalypse, was a fun read, and it was clear that the author actually had a clue about how systems like language models actually work. I definitely enjoyed it.

Meanwhile, I'm a kernel person, relatively ignorant of areas like databases. So as I was reviewing an upcoming article by another LWN author about the Redis mess, I learned a lot. One thing I picked up was that one of the creators of Redis was ... a certain Salvatore Sanfilippo (aka @antirez) Some searching establishes that it's indeed the same person; no wonder the book was as clueful as it was.

Small world...and people say hackers can't write :)
2
8
32
@jvoisin So I went to look at your article to see if I missed anything in my LWN piece about this work ... but the low-contrast fonts used there are such that I literally cannot read the text. I honestly don't understand why people do that.
1
0
1

ðŸŠĶ Vernor Vinge, author of many influential hard science fiction works, died March 20 at the age of 79.

https://file770.com/vernor-vinge-1944-2024/

0
3
0
@kernellogger Sorry I had to work through a few other docs patches first, or I would have gotten it in sooner...
0
0
7

Jonathan Corbet

Once upon a time, if I enabled tethering on an Android phone, it would take the phone off the local WiFi network and route traffic over the cellular link

Now, if the phone is on a WiFi network, tethering will route packets from the tethered device over that WiFi network.

I'm guessing that improvements in WiFi interfaces and drivers have enabled this change. But it misses an important point: if I'm tethering a device in an environment where a WiFi network exists, it is almost certainly because said WiFi network sucks and I want to circumvent it. Having the phone continue to use it silently thwarts that purpose.

It's easy enough to work around — just turn off WiFi on the phone — but for slow folks like me that only happens after wondering for a while why the performance is still bad. Does anybody know of a way to disable this behavior permanently?
5
2
10
@gnomon Interesting, I was not aware of that tool...

Anyway, full-text RSS has been on the list for a while; I just have to figure out how to make the authentication work. I'll try to actually get around to that...meanwhile, though, unfortunately, I don't have anything to offer you.
1
0
1
@robpike Along with the ability to support electrification, as others have mentioned, heat pumps can reach 3-500% efficiency — better than fossil fuels and vastly better than electric resistance heating.
0
0
1
Show older