RSS 생중계
[$] Responses to gpg.fail
At the 39th Chaos Communication Congress (39C3) in December, researchers Lexi Groves ("49016") and Liam Wachter said that they had discovered a number of flaws in popular implementations of OpenPGP email-encryption standard. They also released an accompanying web site, gpg.fail, with descriptions of the discoveries. Most of those presented were found in GNU Privacy Guard (GPG), though the pair also discussed problems in age, Minisign, Sequoia, and the OpenPGP standard (RFC 9580) itself. The discoveries have spurred some interesting discussions and as well as responses from GPG and Sequoia developers.
Japan Restarts World's Largest Nuclear Plant as Fukushima Memories Loom Large
Read more of this story at Slashdot.
Security updates for Wednesday
Comic-Con Bans AI Art After Artist Pushback
Read more of this story at Slashdot.
YouTube CEO Acknowledges 'AI Slop' Problem, Says Platform Will Curb Low-Quality AI Content
Read more of this story at Slashdot.
CEOs Say AI is Making Work More Efficient. Employees Tell a Different Story.
Read more of this story at Slashdot.
Verizon Wastes No Time Switching Device Unlock Policy To 365 Days
Read more of this story at Slashdot.
Snap Settles Social media Addiction Lawsuit Ahead of Landmark Trial
Read more of this story at Slashdot.
Aurora Watch In Effect As Severe Solar Storm Slams Into Earth
Read more of this story at Slashdot.
Era of 'Global Water Bankruptcy' Is Here, UN Report Says
Read more of this story at Slashdot.
cURL Removes Bug Bounties
Read more of this story at Slashdot.
OpenAI and ServiceNow Strike Deal to Put AI Agents in Business Software
Read more of this story at Slashdot.
Developer Rescues Stadia Bluetooth Tool That Google Killed
Read more of this story at Slashdot.
HHS Announces New Study of Cellphone Radiation and Health
Read more of this story at Slashdot.
UK Mulls Australia-Like Social Media Ban For Users Under 16
Read more of this story at Slashdot.
Majority of CEOs Report Zero Payoff From AI Splurge
Read more of this story at Slashdot.
Meta's Oversight Board Takes Up Permanent Bans In Landmark Case
Read more of this story at Slashdot.
Ryabitsev: Tracking kernel development with korgalore
We cannot fix email delivery, but we can sidestep it entirely. Public-inbox archives like lore.kernel.org store all mailing list traffic in git repositories. In its simplest configuration, korgalore can shallow-clone these repositories directly and upload any new messages straight to your mailbox using the provider's API.
56% of Companies Have Seen Zero Financial Return From AI Investments, PwC Survey Says
Read more of this story at Slashdot.
Remote authentication bypass in telnetd
The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter.
If the client supplies a carefully crafted USER environment value being the string "-f root", and passes the telnet(1) -a or --login parameter to send this USER environment to the server, the client will be automatically logged in as root bypassing normal authentication processes.
