RSS 생중계
Instagram Discontinues End-To-End Encryption For DMs
Read more of this story at Slashdot.
Qatar Helium Shutdown Puts Chip Supply Chain On a Two-Week Clock
Read more of this story at Slashdot.
Don't Get Used To Cheap AI
Read more of this story at Slashdot.
Digg Relaunch Fails
Read more of this story at Slashdot.
Backblaze Hosts 314 Trillion Digits of Pi Online
Read more of this story at Slashdot.
Stable kernels for Friday the 13th
Meta Delays Rollout of New AI Model After Performance Concerns
Read more of this story at Slashdot.
Live Nation Execs Brag About 'Robbing' Ticket Buyers In Slack DMs
Read more of this story at Slashdot.
Apple's App Store In China Gets Lower 25% Commission To Appease Regulators
Read more of this story at Slashdot.
Facial Recognition Error Jails Innocent Grandmother For Months
Read more of this story at Slashdot.
An investigation of the forces behind the age-verification bills
I've been pulling public records on the wave of "age verification" bills moving through US state legislatures. IRS 990 filings, Senate lobbying disclosures, state ethics databases, campaign finance records, corporate registries, WHOIS lookups, Wayback Machine archives. What started as curiosity about who was pushing these bills turned into documenting a coordinated influence operation that, from a privacy standpoint, is building surveillance infrastructure at the operating system level while the company behind it faces zero new requirements for its own platforms.
(See also this article for a look at the California law.)
A set of AppArmor vulnerabilities
This "CrackArmor" advisory exposes a confused-deputy flaw allowing unprivileged users to manipulate security profiles via pseudo-files, bypass user-namespace restrictions, and execute arbitrary code within the kernel. These flaws facilitate local privilege escalation to root through complex interactions with tools like Sudo and Postfix, alongside denial-of-service attacks via stack exhaustion and Kernel Address Space Layout Randomization (KASLR) bypasses via out-of-bounds reads.
Italian Prosecutors Seek Trial For Amazon, Four Execs Over Alleged $1.4 Billion Tax Evasion
Read more of this story at Slashdot.
[$] More timing side-channels for the page cache
In 2019, researchers published a way to identify which file-backed pages were being accessed on a system using timing information from the page cache, leading to a handful of unpleasant consequences and a change to the design of the mincore() system call. Discussion at the time led to a number of ad-hoc patches to address the problem. The lack of new page-cache attacks suggested that attempts to fix things in a piecemeal fashion had succeeded. Now, however, Sudheendra Raghav Neela, Jonas Juffinger, Lukas Maar, and Daniel Gruss have found a new set of holes in the Linux kernel's page-cache-timing protections that allow the same general class of attack.
Security updates for Friday
Apple MacBook Neo Beats Every Single x86 PC CPU For Single-Core Performance
Read more of this story at Slashdot.
London Man Wore Smart Glasses For High Court 'Coaching'
Read more of this story at Slashdot.
Microsoft Backs Anthropic To Halt US DOD's 'Supply-Chain Risk' Designation
Read more of this story at Slashdot.
Google Chrome Is Finally Coming To ARM64 Linux
Read more of this story at Slashdot.
Adobe CEO to Step Down After 18 Years
Read more of this story at Slashdot.
