RSS 생중계
FCC To End Biden-Era Rule That Forces ISPs To List All Their Fees
Read more of this story at Slashdot.
China's DeepSeek Developing Its Own AI Chip
Read more of this story at Slashdot.
Major Banks In Talks To Exploit Debit Card Loophole
Read more of this story at Slashdot.
Microsoft Can Track Users Via a Windows Device ID
Read more of this story at Slashdot.
Amazon Will Stop Accepting New Customers For Mechanical Turk
Read more of this story at Slashdot.
Learning Another Language Appears To Slow Brain Aging By Up To 13 Years
Read more of this story at Slashdot.
Woodruff: You shouldn't trust trusted publishing
William Woodruff, better known online as "yossarian", has published a blog post to make the case that users should not place their trust in trusted publishing:
Trusted Publishing is a mechanism for establishing trust between an external machine identity (like a CI/CD workflow) and one or more projects on a package index/registry. The "trust" in "Trusted Publishing" refers to that trust relationship, and not to anything else.
It is not, and cannot be, a signal for package trust or quality. You cannot use it to determine whether a package is safe or "good," and PyPI consciously stymies attempts to misuse it for that purpose by not rendering it as a "green checkmark" or anything else of the sort.
Or as another framing: Trusted Publishing is just a form of authentication. It doesn't tell you anything other than that an upload was authenticated, which all uploads to PyPI are.
LWN covered trusted publishing in June.
[$] Faster RCUs and lockless memory allocation
Puranjay Mohan shared some of the work he's been doing recently on improving the performance of read-copy-update (RCU) at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit; his talk would have been nice context to have earlier in the day when Harry Yoo and Alexei Starovoitov led a session about the new kmalloc_nolock() function that allows for lockless allocation from any kernel context, and which interacts with the RCU subsystem to allow that. This article therefore covers the two sessions together and in the reverse order, to provide that missing context.
Security updates for Tuesday
US Cyber Agency Is Using Anthropic's Mythos To Audit Government Code
Read more of this story at Slashdot.
GitHub Thumbs Nose At Sony's Controversial End to Physical Media With Its Introduction of Repo CDs
Read more of this story at Slashdot.
Research Universities Are Admitting Fewer PhDs, a Bad Sign For Science
Read more of this story at Slashdot.
Small AI Models Gain Traction Around the World
Read more of this story at Slashdot.
Supreme Court Allows Texas To Require Age Verification For Mobile Apps
Read more of this story at Slashdot.
South Korea's SK Hynix Launching $28 Billion US Listing To Ride Global AI Wave
Read more of this story at Slashdot.
Zombie 'Who Owns Unix?' Lawsuit Comes Alive Again
Read more of this story at Slashdot.
Secret Claude Tracker Shocks Users After Anthropic's Anti-Surveillance Stance
Read more of this story at Slashdot.
Microsoft Lays Off Nearly 5,000 Employees Across Xbox, Commercial Sales
Read more of this story at Slashdot.
Nintendo Switch 2 Is Getting a Replaceable Battery in Europe
Read more of this story at Slashdot.
OpenSSH 10.4 released
OpenSSH 10.4 has been released. In addition to a number of security and bug fixes, there are a few notable changes; this release adds experimental support for a composite post-quantum signature scheme combining ML-DSA 44 and Ed25519 as described in this IETF draft. With 10.4, if OpenSSH is compiled with sandbox support it will fail on Linux systems that have not enabled SECCOMP or NO_NEW_PRIVS; prior to this release, sshd would log an error but continue operation. See the release notes for a full list of changes.
