RSS 생중계
One step forward, two steps back on CA age bill (EFF Deeplinks Blog)
The EFF has a blog post looking at a new bill in California that would exempt open-source operating systems from the Digital Age Assurance Act passed last year, but has problems of its own:
While the open source exemption, if passed, would improve the law, the remaining amendments proposed by AB 1856 would require all web browsers and websites to request and collect users' ages. This is an expansion of last year's AB 1043's age-bracketing system that compounds its constitutional harms to users' speech, privacy, and security.
[...] EFF understands this amendment to exempt open-source operating systems from the requirement to collect and transmit users' age-bracket data. That is a definite win for open-source developers. The bill is narrower now than it was before, and lawmakers clearly responded to concerns raised by EFF and the broader open-source community.
Some important questions still remain—for example, it is unclear how the law would apply when an open-source operating system is incorporated into a commercial product or service. And, given the structure of where the exemption is placed under the "operating system provider" definition, lawmakers could stand to clarify that the exemption applies to open-source operating systems and applications.
LWN covered California's age-attestation law in March.
Security updates for Thursday
NASA Says Goodbye to Its Longtime Mars MAVEN Mission
Read more of this story at Slashdot.
Amazon's New Stargate Series Is Officially Dead
Read more of this story at Slashdot.
Demand Is Booming For New No Tech, Repairable Tractor
Read more of this story at Slashdot.
[$] LWN.net Weekly Edition for June 4, 2026
- Front: MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module.
- Briefs: Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust 1.96.0; rsync; Vim Classic 8.3; Quotes; ...
- Announcements: Newsletters, conferences, security updates, patches, and more.
Fedora Linux 43 Exposes 20-Year-Old Microsoft Outlook Security Failure
Read more of this story at Slashdot.
EU Plots To Abandon US Tech
Read more of this story at Slashdot.
MacBook Neo is So Popular That Apple Reportedly Doubled Production
Read more of this story at Slashdot.
Google Launches 'Gemma 4 12B' AI Model That Can Run On Your Laptop
Read more of this story at Slashdot.
Google Shares Fitbit Air Blueprints So Anyone Can 3D-Print Accessories
Read more of this story at Slashdot.
Microsoft Plans Linux Tools, RTX Spark Desktop For Windows Devs
Read more of this story at Slashdot.
Meta Workers Can Opt Out of Workplace Tracking for Up to 30 Minutes
Read more of this story at Slashdot.
Microsoft Claims New Quantum Chip 1,000 Times Better Than Before
Read more of this story at Slashdot.
[$] Open-source security is not a solo activity
Over time, many open-source maintainers face the same problem: they lack the time to do all of the work that their project needs, and no one else is stepping up to provide adequate help. Maintainers, though, are often reluctant to throw in the towel. The result is suboptimal all around; the maintainer is stressed out, project quality suffers, and users face security risks that they may not be fully aware of. At the 2026 Open Source Summit North America, Robin Bender Ginn spoke about this problem, when it might be time for maintainers to pass the torch, and the responsibilities of users.
Android Gets Fake Call Detection That Uses RCS
Read more of this story at Slashdot.
[$] BPF in the agentic era
Alexei Starovoitov gave "less of a presentation, more of a scream of realization" at the BPF track of the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit. He shared a set of ideas for how BPF could change to avoid being swept away by the sea-change in programming represented by modern large language models (LLMs) and the coding agents based on them. In a follow-up session, the discussion covered more problems with how coding agents use tools like bpftrace, and the current deluge of patches in need of review in the BPF subsystem.
Tridgell: rsync and outrage
Andrew Tridgell has written a blog post responding to complaints that he has begun using LLM tools in his work maintaining rsync:
Like many developers of open source packages I've been hit by a flood of security reports lately in my role as the rsync maintainer. Many of those reports are AI generated (not all though, there are some notable ones with very careful and high quality manual analysis).
As this flood started to get more intense I realised I needed to raise the defences on rsync a lot — we needed much more thorough test suites, code coverage analysis, CI testing on a lot more platforms, deliberate and thorough scanning for possible security issues (so I find at least some of them before other people!) and the addition of a whole lot of defence-in-depth hardening techniques.
[...] Now to the future, because we're not done yet by a long shot. The security reports keep rolling in. I'm working on a bunch of CVEs right now. Luckily I've been joined by some other very good developers with great systems development skills and security knowledge. Some of these people came to my attention partly because of all the rage happening at the moment, so I get some rage storm clouds have silver linings. Watch out for some credits for some great new rsync developers in the next release.
Security updates for Wednesday
Thanks To Robots, Ukraine Is Now Talking About Winning, Not Just Surviving
Read more of this story at Slashdot.
