RSS 생중계
LWN in EPUB format
We will also be creating special EPUB books at times. As an example of what is possible, our complete coverage from Kangrejos 2024 and the 2024 Linux Storage, Filesystem, Memory Management, and BPF Summit are available to all readers.
There are surely places where our EPUB books can be improved; please feel free to drop us a note (at lwn@lwn.net) with suggestions.
Copyright Office Offers Assurances on AI Filmmaking Tools
Read more of this story at Slashdot.
New Zealand Relaxes Visa Rules To Lure Digital Nomads
Read more of this story at Slashdot.
Credential-leaking vulnerability in some Git credential managers
Security researcher RyotaK has shared a series of vulnerabilities that all have to do with how Git interfaces with external credential managers. In short, while Git guards against newline characters (\n) being injected into a repository's URL, some programming languages also treat carriage return characters (\r) as being newlines. Adding a carriage return to a repository's URL can cause Git and the credential manager to disagree on how the URL should be parsed, ultimately resulting in Git credentials being sent to the wrong host. Malicious repositories could include Git submodules with malformed URLs, triggering the bug. Only password-based authentication with an external credential manager is vulnerable to this attack; SSH-based authentication remains secure. The Git project has chosen to consider this a vulnerability in Git, given the large amount of external software affected. The project has fixed the bug on its end by releasing updates for all supported versions that ban carriage returns in URLs entirely.
Affected software includes GitHub Desktop, Git LFS, and possibly other Git utilities:
Since Git itself doesn't use .lfsconfig file, specifying the URL that contains the newline character in .lfsconfig causes Git LFS to insert the newline character into the message, while bypassing [...] Git's validation.[$] Offline applications with Earthstar
Earthstar is a privacy-oriented, offline-first, LGPL-licensed database intended to support distributed applications. Unlike other distributed storage libraries, it focuses on providing mutable data with human-meaningful names and modification times, which gives it an interface similar to many non-distributed key-value databases. Now, the developers are looking at switching to a new synchronization protocol — one that is general enough that it might see wider adoption.
Virgin Money Chatbot Scolds Customer Who Typed 'Virgin'
Read more of this story at Slashdot.
Paper Mills Have Flooded Science With 400,000 Fake Studies, Experts Warn
Read more of this story at Slashdot.
Ubuntu developer discussion moving to Matrix
Ubuntu will be moving its "official realtime communications channels" from IRC to Matrix, beginning March 1, 2025, following a discussion on the ubuntu-devel mailing list.
"Official" communication, such as making realtime requests of privileged Ubuntu developer teams, could be expected to be actioned if requested on Matrix only. Similarly, you can consider your social responsibility to other developers in relation to your work in Ubuntu development to be fulfilled if you are present on that platform. And Canonical will follow in its requirement for its employed Ubuntu developers to be present on that agreed platform during their working hours.Security updates for Wednesday
OpenAI Says It Has Evidence DeepSeek Used Its Model To Train Competitor
Read more of this story at Slashdot.
CVS Might Let You Open Locked Shelves With Your Phone
Read more of this story at Slashdot.
Microplastics Found In the Brains of Mice Within Hours of Consumption
Read more of this story at Slashdot.
Technology For Lab-Grown Eggs Or Sperm On Brink of Viability, UK Watchdog Finds
Read more of this story at Slashdot.
'Ghost' That Haunts South Carolina Rail Line May Be Caused By Tiny Earthquakes
Read more of this story at Slashdot.
Record $4.5 Billion EU Fine Punished Its Innovation, Google Tells EU Court
Read more of this story at Slashdot.
White House 'Looking Into' National Security Implications of DeepSeek's AI
Read more of this story at Slashdot.
OPM Sued Over Privacy Concerns With New Government-Wide Email System
Read more of this story at Slashdot.
White House Says New Jersey Drones 'Authorized To Be Flown By FAA'
Read more of this story at Slashdot.
Boom Supersonic XB-1 Breaks Sound Barrier During Historic Test Flight
Read more of this story at Slashdot.
Apple Chips Can Be Hacked To Leak Secrets From Gmail, ICloud, and More
Read more of this story at Slashdot.
페이지
