Informacje z Sieci
CentOS Successor Rocky Linux Gets $26M to Fund Push Into Enterprise Space
"CIQ has landed $26 million in funding to support its plans to expand the use of Rocky Linux in the enterprise space," reports ZDNet.
Last year, Red Hat decided to stop supporting CentOS 8 and shifted focus to CentOS Stream. CentOS had some huge enterprise users, among them Disney, GoDaddy, RackSpace, Toyota, and Verizon. In response, Greg Kurtzer, one of CentOS's founders, kicked off Rocky Linux in December 2020.... Kurtzer says Rocky Linux adoption has been "massive", with monthly downloads of OS images typically 250,000, reaching 750,000 in a bumper month. "Within two months we had 10,000 developer and contributors trying to be part of this project...."
The project has gained the support of Greg Kroah-Hartman, the maintainer of the main-line stable Linux kernel, to meet community demands for Rocky Linux to run on a more modern, optimized kernel, Kurtzer said. Kroah-Hartman is leading Rocky Linux special interest group (SIG) for the kernel to create an optional enhanced kernel for Rocky Linux. "He's working closely with us to make sure the kernel we use is blessed by him. He's in the loop as bugs come up and help us manage that kernel in Rocky Linux," says Kurtzer.
"Moreover, today's news follows shortly after CIQ inked a major deal with Google to help support companies looking to deploy Rocky Linux on Google's cloud infrastructure," reports VentureBeat.
Kurtzer tells the site that Rocky Linux "has been a rocket ship in terms of uptake across the enterprise and cloud."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Hackers Are Exploiting WordPress Tools to Hawk Scams
"If you've visited a website in recent days and been randomly redirected to the same pages with sketchy "resources" or unwanted ads, it's likely the site in question was 1) built with WordPress tools and 2) hacked," reports Gizmodo.
Details come from this blog post by researchers at Sucuri (a security provider owned by GoDaddy):
As outlined in our latest hacked website report, we've been tracking a long-lasting campaign responsible for injecting malicious scripts into compromised WordPress websites. This campaign leverages known vulnerabilities in WordPress themes and plugins and has impacted an enormous number of websites over the year — for example, according to PublicWWW, the April wave for this campaign was responsible for nearly 6,000 infected websites alone. Since these PublicWWW results only show detections for simple script injections, we can assume that the scope is significantly larger.
We recently investigated a number of WordPress websites complaining about unwanted redirects. Interestingly enough, they were found to be related to a new wave of this massive campaign and were sending website visitors through a series of website redirects to serve them unwanted ads. The websites all shared a common issue — malicious JavaScript had been injected within their website's files and the database, including legitimate core WordPress files... This JavaScript was appended under the current script or under the head of the page where it was fired on every page load, redirecting site visitors to the attacker's destination.... Domains at the end of the redirect chain may be used to load advertisements, phishing pages, malware, or even more redirects....
At the time of writing, PublicWWW has reported 322 websites impacted by this new wave... Considering that this count doesn't include obfuscated malware or sites that have not yet been scanned by PublicWWW, the actual number of impacted websites is likely much higher. Our team has seen an influx in complaints for this specific wave of the massive campaign targeting WordPress sites beginning May 9th, 2022, which has impacted hundreds of websites already at the time of writing....
We expect the hackers will continue registering new domains for this ongoing campaign as soon as existing ones become blacklisted.
"It's important to note that these hacks are related to themes and plugins built by thousands of third-party developers using the open source WordPress software, not WordPress.com, which offers hosting and tools to build websites," Gizmodo points out.
But this also cite this warning from Sucuri malware analyst Krasimir Konov:
"This page tricks unsuspecting users into subscribing to push notifications from the malicious site. If they click on the fake CAPTCHA, they'll be opted in to receive unwanted ads even when the site isn't open — and ads will look like they come from the operating system, not from a browser," Konov wrote.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Want to Run Python Code in a Browser? Soon You Might Be Able To
ZDNet reports news from PyCon 2022 ("the first in-person meet-up for Python contributors since 2019 due to the pandemic")
"Developers revisited the idea of running Python code in the browser...."
CPython developer Christian Heimes and fellow contributor Ethan Smith detailed how they enabled the CPython main branch to compile to WebAssembly. CPython, short for Core Python, is the reference implementation that other Python distributions are derived from. CPython now cross-compiles to Wasm using Emscripten, a toolchain that compiles projects written in C or C++ to Node.js or Wasm runtimes. The Python Software Foundation highlighted the work in a blog post: "Python can be run on many platforms: Linux, Windows, Apple Macs, microcomputers, and even Android devices. But it's a widely known fact that, if you want code to run in a browser, Python is simply no good — you'll just have to turn to JavaScript," it notes.
"Now, however, that may be about to change."
While the Foundation notes cross-compiling to WebAssembly is still "highly experimental" due to missing modules in the Python standard library, nonetheless, PyCon 2022 demonstrated growing community interest in making Python a better language for the browser.
The article notes additional news from Anaconda (makers of the a Python distribution for data science): the announcement of PyScript, "a system for interleaving Python in HTML (like PHP)."
It allows developers to write and run Python code in HTML, and call Javascript libraries in PyScript. This system allows a website to be written entirely in Python.
PyScript is built on Pyodide, a port of CPython, or a Python distribution for the browser and Node.js that's based on WebAssembly and Emscripten.... "Pyodide makes it possible to install and run Python packages in the browser with micropip. Any pure Python package with a wheel available on PyPI is supported," the Pyodide project states. Essentially, it compiles Python code and scientific libraries to WebAssembly using Emscripten.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
After 28 Flights, Is NASA's 'Ingenuity' Mars Helicopter Nearing the End of Its Life?
After traveling 300 miles on the underbelly of the Perseverance rover, the "Ingenuity" helicopter has made 28 different flights over the surface of Mars, reports the Washington Post, staying aloft for a total of nearly one hour, flying 4.3 miles with a maximum speed of 12.3 miles per hour and a top altitude of 39 feet. "It's traversed craters, taken photos of regions that would be hard to reach on the ground, and served as a surprisingly resilient scout that has adapted to the changing Martian atmosphere and survived its harsh dust storms and frigid nights.
"Now the engineers and scientists at NASA's Jet Propulsion Laboratory are worried that their four-pound, solar-powered drone on Mars, may be nearing the end of its life."
Winter is setting in on Mars. The dust is kicking up, coating Ingenuity's solar panels and preventing it from fully charging its six lithium-ion batteries. This month, for the first time since it landed on Mars more than a year ago, Ingenuity missed a planned communications session with Perseverance, the Mars rover that it relies on to send data and receive commands from Earth. Will a dust-coated Ingenuity survive a Martian winter where temperatures routinely plunge below minus-100 degrees Fahrenheit? And if it doesn't, how should the world remember the little helicopter that cost $80 million to develop and more than five years to design and build? Those closest to the project say that as time winds down for Ingenuity, it's hard to overstate its achievements....
"We built it as an experiment," Lori Glaze, the director of NASA's planetary science division, told The Washington Post. "So it didn't necessarily have the flight-qualified parts that we use on the big missions like Perseverance." Some, such as components from smartphones, were even bought off-the-shelf, so "there were chances that they might not perform in the environment as we expected. And so there was a risk that it wasn't going to work.... What happened was, and this is really key, after Ingenuity performed so well on those first five flights, the science team from Perseverance came to us and said, 'You know what, we want this helicopter to keep operating to help us in our exploration and achieving our science goals,' " Glaze said.
So NASA decided to keep flying....
On April 29, it took its last flight to date, No. 28, a quarter-of-a-mile jaunt that lasted two-and-a-half minutes. Now NASA wonders if that will be the last one. The space agency thinks the helicopter's inability to fully charge its batteries caused the helicopter to enter a low-power state. When it went dormant, the helicopter's onboard clock reset, the way household clocks do after a power outage. So the next day, as the sun rose and began to charge the batteries, the helicopter was out of sync with the rover: "Essentially, when Ingenuity thought it was time to contact Perseverance, the rover's base station wasn't listening," NASA wrote.
Then NASA did something extraordinary: Mission controllers commanded Perseverance to spend almost all of May 5 listening for the helicopter.
Finally, little Ingenuity phoned home.
The radio link, NASA said, "was stable," the helicopter was healthy, and the battery was charging at 41 percent.
But, as NASA warned, "one radio communications session does not mean Ingenuity is out of the woods. The increased (light-reducing) dust in the air means charging the helicopter's batteries to a level that would allow important components (like the clock and heaters) to remain energized through the night presents a significant challenge."
Maybe Ingenuity will fly again. Maybe not.
"At this point, I can't tell you what's going to happen next," Glaze said. "We're still working on trying to find a way to fly it again. But Perseverance is the primary mission, so that we need to start setting our expectations appropriately."
For Ingenuity's "Wright Brothers moment" — when it flew for the first time on another planet — it was actually carrying a postage-sized bit of fabric from the Wright Brothers original 1903 aircraft.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
FAA Revokes Certificates of Two Pilots Involved in Plane-Swapping Attempt
Whatever happened to those two pilots who attempted to swap planes in mid-air — skydiving from one to the other while the planes slowly tumbled toward the desert 65 miles southeast of Phoenix?
One pilot successfully reached the other plane — but the other pilot didn't, parachuting safely to the ground instead. "All of our safety protocols worked," the first pilot said triumphantly in a documentary streamed on Hulu. Er, but what about that second plane, slowly tumbling toward the ground without a pilot? It fell 14,000 feet, landing "nose first" (according to footage from a local newscast) — though its descent was also slowed by a parchute. (Both planes also had a specially-engineered braking system to slow their fall so the skydiving pilots could overtake them.) The stunt was sponsored by Red Bull.
Both pilots had previously conducted more than 20,000 skydives — "but there's a problem," that local newscast pointed out. "The FAA says it had denied Red Bull permission to attempt the plane swap because it would not be in the public's interest." So now both pilots — who'd had "commercial pilot certificates" from America's Federal Aviation Administration — have had their certificates revoked.
The Associated Press reports:
In a May 10 emergency order, the FAA cites the two pilots, Luke Aikins and Andrew Farrington, and describes their actions as "careless and reckless." Aikins also faces a proposed $4,932 fine from the agency....
Aikins had petitioned for an exemption from the rule that pilots must be at the helm with safety belts fastened at all times. He argued the stunt would "be in the public interest because it would promote aviation in science, technology, engineering and math."
While both pilots must surrender their certificates immediately, there is an appeal process.
Aikins had shared a statement on Instagram after the stunt, saying he made the "personal decision to move forward with the plane swap" despite the lack of the FAA exemption.
"I regret not sharing this information with my team and those who supported me."
"I am now turning my attention to cooperatively working transparently with the regulatory authorities as we review the planning and execution."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Security Expert Nabs Expired Domain for a Popular NPM Library's Email Address
"Security consultant Lance Vick recently acquired the expired domain used by the maintainer of a widely used NPM package," reports the Register, "to remind the JavaScript community that the NPM Registry still hasn't implemented adequate security."
"I just noticed 'foreach' on NPM is controlled by a single maintainer," wrote Vick in a Twitter post on Monday. "I also noticed they let their domain expire, so I bought it before someone else did. I now control 'foreach' on npm, and the 36,826 projects that depend on it."
That's not quite the full story — he probably could have taken control but didn't. Vick acquired the lapsed domain that had been used by the maintainer to create an NPM account and is associated with the "foreach" package on NPM. But he said he didn't follow through with resetting the password on the email account tied to the "foreach" package, which is fetched nearly six million times a week. In an email to the Register, Vick explained... "I did not log into the account, as again, that crosses a line. I just sent a password reset email and bailed.
"Regardless of how much control I have over this particular package, which is unclear, NPM admits this particular expired domain problem is a known issue, citing this 2021 [research paper] which says, 'We also found 2,818 maintainer email addresses associated with expired domains, allowing an attacker to hijack 8,494 packages by taking over the NPM accounts.' In other words, anyone poking around is going to find accounts easy to take over in this way. I was not lucky or special." His point, which he has been trying for several years to communicate to those overseeing NPM — a part of GitHub since March 2020 — is that taking over the NPM account of a popular project to conduct a software supply chain attack continues to be too easy.
Part of the problem is that JavaScript developers often use packages that implement simple functions that are either already built into the language, like forEach, or ought to be crafted manually to avoid yet another dependency, like left-pad (now built-in as padStart). These trivial packages get incorporated into other packages, which may in turn become dependencies in different packages, thereby making the compromise of something like "foreach" a potentially far-reaching security incident.
But Vick argues that with so many upstream attack vectors, "We are all just trusting strangers on the internet to give us good candy from their truck," according to the Register. Their article points out that on Tuesday GitHub launched a beta test of improved 2FA security for all its NPM accounts — which Vick calls "a huge win... [T]hat is the best way to protect accounts. We in the security community have been demanding this for years."
But he's still worried about the possibility of email addresses with weak two-factor authentication or compromised NPM employees, and would like to see NPM implement cryptographic signatures for code. "I am talking with a member of their team tomorrow and we will see where this goes."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
White House Joins OpenSSF, Linux Foundation In Securing Open-Source Software
An anonymous reader quotes a report from ZDNet: Securing the open-source software supply chain is a huge deal. Last year, the Biden administration issued an executive order to improve software supply chain security. This came after the Colonial Pipeline ransomware attack shut down gas and oil deliveries throughout the southeast and the SolarWinds software supply chain attack. Securing software became a top priority. In response, The Open Source Security Foundation (OpenSSF) and Linux Foundation rose to this security challenge. Now, they're calling for $150 million in funding over two years to fix ten major open-source security problems.
The government will not be paying the freight for these changes. $30 million has already been pledged by Amazon, Ericsson, Google, Intel, Microsoft, and VMWare. More is already on the way. Amazon Web Services (AWS) has already pledged an additional $10 million. At the White House press conference, OpenSSF general manager Brian Behlendorf said, "I want to be clear: We're not here to fundraise from the government. We did not anticipate needing to go directly to the government to get funding for anyone to be successful."
Here are the ten goals the open-source industry is committed to meeting:
1. Security Education: Deliver baseline secure software development education and certification to all.
2. Risk Assessment: Establish a public, vendor-neutral, objective-metrics-based risk assessment dashboard for the top 10,000 (or more) OSS components.
3. Digital Signatures: Accelerate the adoption of digital signatures on software releases.
4. Memory Safety: Eliminate root causes of many vulnerabilities through the replacement of non-memory-safe languages.
5. Incident Response: Establish the OpenSSF Open Source Security Incident Response Team, security experts who can step in to assist open source projects during critical times when responding to a vulnerability.
6. Better Scanning: Accelerate the discovery of new vulnerabilities by maintainers and experts through advanced security tools and expert guidance.
7. Code Audits: Conduct third-party code reviews (and any necessary remediation work) of up to 200 of the most-critical OSS components once per year.
8. Data Sharing: Coordinate industry-wide data sharing to improve the research that helps determine the most critical OSS components.
9. Software Bill of Materials (SBOMs): Everywhere Improve SBOM tooling and training to drive adoption.
10. Improved Supply Chains: Enhance the 10 most critical open-source software build systems, package managers, and distribution systems with better supply chain security tools and best practices.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Classic Japanese Audio Brand Onkyo Files For Bankruptcy
Onkyo, one of the best-known Japanese manufacturers of home theater equipment, has "filed for bankruptcy at Osaka District Court on Friday, with total liabilities of around 3.1 billion yen ($24 million)," reports Nikkei Asia. The report is sparse on details but attributes the bankruptcy to a "market shift to streaming and smartphones."
In mid-2020, Onkyo USA Corporation ended a 45-year run as Onkyo's exclusive sales, marketing and distribution division for the Americas, according to Audioholics.
Onkyo has appeared in a few stories on Slashdot over the years. Our personal favorite was a story in 2003 about a new use of embedded Linux in Onkyo's home music server.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
House of Representatives To Give Staff Free Peloton Memberships
schwit1 shares a report: The House of Representatives [...] will provide taxpayer-funded Peloton memberships to all of its staff, costing taxpayers roughly $100,000 per month. The move comes one year after the fitness company set up a lobbying shop in Washington. Memberships to the exercise service, which offers workout classes, will be available to House staff in Washington, D.C., and in district offices, as well as to Capitol police officers, Fox Business reported. The number of people eligible for the fully taxpayer-funded memberships totals roughly 12,300.
Under the contract with Peloton, which takes effect May 18, the government will pay the company $10,000 up front and $10 per month for each staffer who chooses to enroll, according to Fox Business. With high participation among House staffers, the monthly cost of the contract for taxpayers could exceed $100,000 per month. [...] In March 2021, Peloton hired an in-house lobbyist and two lobbying firms to influence Congress on issues including "government programming to support health and wellness of Americans."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Hackers Are Using SEO To Rank Malicious PDFs On Search Engines, Research Finds
An anonymous reader quotes a report from VentureBeat: Today, researchers at security service edge provider, Netskope, published the Netskope Cloud and Threat Report: Global Cloud and Malware Trends, which found that phishing downloads rose 450% over the past 12 months, and highlighted that attackers are using search engine optimization (SEO) to rank malicious PDF files on search engines. The report's findings show that phishing attempts are constantly evolving, and attackers aren't just targeting employees through their email inboxes; they're also using popular search engines like Google and Bing. The increase in phishing attacks and the growing popularity of SEO techniques among cybercriminals highlights the need for enterprises to provide their employees with security awareness training so they're prepared to spot threats and not at risk of handing over sensitive information.
When it comes to defending against these SEO-driven attacks, [Ray Canzanese, director of Netskope's Threat Labs] highlights several methods that security teams can use to protect employees. One of the most effective is to use a solution that can decrypt and scan web traffic for malicious content. At the same time, security teams should encourage users to inspect all links they click on, and to exercise caution if the link takes them to an unfamiliar website. In the event an employee does click on a malicious PDF, they can expect to see a fake captcha at the top of the first page, followed by text on other pages. In these scenarios, users should close the file, delete it from the device and report it to the security team ASAP. Canzanese also notes that it's important for users to report malicious URLs that feature on popular search engines to help the provider unlist them from the site and prevent other users from falling victim to a scam.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
San Francisco Police Are Using Driverless Cars As Mobile Surveillance Cameras
BeerFartMoron shares a report from Motherboard: For the last five years, driverless car companies have been testing their vehicles on public roads. These vehicles constantly roam neighborhoods while laden with a variety of sensors including video cameras capturing everything going on around them in order to operate safely and analyze instances where they don't. While the companies themselves, such as Alphabet's Waymo and General Motors' Cruise, tout the potential transportation benefits their services may one day offer, they don't publicize another use case, one that is far less hypothetical: Mobile surveillance cameras for police departments.
"Autonomous vehicles are recording their surroundings continuously and have the potential to help with investigative leads," says a San Francisco Police department training document obtained by Motherboard via a public records request. "Investigations has already done this several times."
Privacy advocates say the revelation that police are actively using AV footage is cause for alarm. "This is very concerning," Electronic Frontier Foundation (EFF) senior staff attorney Adam Schwartz told Motherboard. He said cars in general are troves of personal consumer data, but autonomous vehicles will have even more of that data from capturing the details of the world around them. "So when we see any police department identify AVs as a new source of evidence, that's very concerning."
As companies continue to make public roadways their testing grounds for these vehicles, everyone should understand them for what they are -- rolling surveillance devices that expand existing widespread spying technologies," said Chris Gilliard, Visiting Research Fellow at Harvard Kennedy School Shorenstein Center. "Law enforcement agencies already have access to automated license plate readers, geofence warrants, Ring Doorbell footage, as well as the ability to purchase location data. This practice will extend the reach of an already pervasive web of surveillance."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
AT&T Is About To Get Away With Its Bogus $1.99 'Administrative Fee'
Sean Hollister writes via The Verge: Since 2013, AT&T has quietly bilked customers out of hundreds of millions of dollars with a bogus "administrative fee," a fee it more than doubled to $1.99 a month in 2018. For a few years there, a California class-action lawsuit made it seem like AT&T might finally get taken to task. But this week, both sides told a judge they'd settle for just $14 million -- meaning customers may get less than 10 percent of what they paid AT&T, while AT&T gets to keep on charging them. According to the proposed settlement agreement in Vianu v. AT&T Mobility -- which still needs to be approved by a judge -- just about every AT&T Wireless postpaid customer in California since 2015 will be eligible for an estimated payment of between $15 and $29.
But again, that's only a fraction of what AT&T's own records show it charged: $180 per customer on average since 2015, according to documents. The settlement "represents a refund of approximately 6-11 months of the average fees," they read. Meanwhile, the lawyers are likely to get $3.5 million. "The estimated payment amount represents a strong result for the Settlement Class, particularly given the substantial risks, costs, and delay of continued litigation," reads the proposed settlement agreement, going on to list all the ways that the lawyers suing AT&T believe that AT&T might still win the case. [...]
Oh, and you won't even get a check in the mail if you're still an AT&T customer, assuming this version of the settlement is approved. The money will be credited back to your AT&T account, where AT&T can dip its hand right back in again for that $1.99 -- or more if it feels emboldened enough to increase the fee yet again. (Admittedly, the AT&T account could be a more reliable way to make sure customers get money back.) The settlement websites can be found here.
An AT&T spokesperson issued the following response: "We deny the allegations in this lawsuit because we clearly disclose all fees that are charged to our customers. However, we have decided to settle this case to avoid lengthy, expensive litigation."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Samsung Is Reportedly Planning To Raise Chip Prices By 20%
Samsung is currently considering raising the cost of its semiconductor products by up to 20%, as well as those it manufactures for other companies, which would ultimately lead to consumers paying more for new devices. PC Magazine reports: As Bloomberg reports, the price hike consideration is in response to just about everything in the world getting more expensive, including the cost of raw materials and the logistics surrounding production pipelines. The final price increase is expected to be linked to sophistication of the components being manufactured, but that still means vendors will end up paying between 15-20% more for chips. Samsung is a huge player in the semiconductor industry, producing processors for a wide-range of industries, as well as memory products, storage solutions, and foundry solutions which allow other semiconductor products to be manufactured. Adding up to a 20% price rise across all those sectors will inevitably push up prices for any products that use Samsung components.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Ex-eBay Exec Pleads Guilty To Terrorizing Couple With Spiders, Funeral Wreaths
An anonymous reader quotes a report from The Guardian: A former eBay executive pleaded guilty on Thursday to participating in a scheme to terrorize the creators of an online newsletter that included the delivery of live spiders and other disturbing items to their home. David Harville, eBay's former director of global resiliency, is the final onetime eBay employee charged in the case to plead guilty. Six others have admitted to their roles in the harassment campaign targeting a Massachusetts couple who publish the newsletter EcommerceBytes, which eBay executives viewed as critical of the company.
The scheme included sending items like a box of live cockroaches, a funeral wreath and books about surviving the loss of a spouse to the couple's home with the hopes of getting them to stop publishing negative articles about the company, prosecutors say. eBay employees also set up fake social media accounts to send threatening messages to the couple and posted the couple's home address online. Harville and others were charged in June 2020 over the plot, which authorities say was orchestrated by members of eBay's executive leadership team after the newsletter published an article about a lawsuit filed by eBay accusing Amazon of poaching its sellers, authorities said. Another former executive who pleaded guilty last month, James Baugh, held meetings to coordinate the harassment campaign and directed Harville to go with him to Boston to spy on the couple, prosecutors say.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Startup Raises $17 Million To Develop Smart Gun
Biofire Technologies has raised $17 million in seed funding to further develop its smart gun, which uses a fingerprint sensor to unlock the trigger. Axios reports: Biofire's guns only can be fired by authorized users, which should exclude kids or teens from using guns that their parents didn't secure. Even if you're someone who decries firearms proliferation and supports stricter gun control, this is an innovation that should be welcomed. "I see firearm ownership continuing to be part of American culture for the foreseeable future," says Biofire founder and CEO Kai Kloepfer. "This issue has become so politicized that really nothing is being done, even for things that shouldn't be political in any way, like kids getting hold of guns ... A smart gun isn't a cure-all, but we do think that we can have an immediate and substantial impact."
Kloepfer, who dropped out of MIT to pursue Biofire, adds that the gun is being beta tested with law enforcement and firearms experts, and that it doesn't have any RFID or other wireless capabilities that could turn off prospective buyers A recent Morning Consult poll found that 55% of current gunowners would be comfortable using a smart gun.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Google Announces Flutter 3, Now With macOS and Linux Desktop Support
An anonymous reader quotes a report from XDA Developers: Google created Flutter a number of years ago, with the aim to make a cross-platform software framework. Flutter's biggest strength is that it can be used to build applications for Android, iOS, Linux, Windows, macOS, and even the web, and all from the same shared codebase. While building apps for Windows received stable support back in February, both macOS and Linux were still only in beta. Now that's changing, as Google has announced Flutter 3 at this year's Google I/O, complete with stable support for building apps for macOS and Linux.
Of course, cross-platform support for both of these new platforms requires more than just programs being able to run. They need to fit in with the rest of the experience, and they need to support specific features that may be unique, as well. That's why Google is highlighting two things: the first is that Linux support helped by Canonical (the publisher of Ubuntu) and Google collaborating in order to "offer a highly-integrated, best-of-breed option for development."
As Google puts it, Canonical is already developing with "Flutter for key shell experiences including installation and firmware updates." What's more, their Linux-specific packages "provide an idiomatic API for core operating system services including dbus, gsettings, networkmanager, Bluetooth and desktop notifications, as well as a comprehensive theme and widget set for Yaru, the Ubuntu look and feel." As for macOS, Google invested in supporting both Intel and Apple Silicon devices, with Universal Binary support that allows apps to package executables that run natively on both architectures. Tim Sneath, Director of Product and UX for Flutter & Dart, highlights all the new improvements in a Medium post.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
How Much Will It Cost To Secure Open-Source Software? OpenSSF Says $147.9 Million
Today at the Open Source Software Security Summit II in Washington, D.C., OpenSSF announced an ambitious, multipronged plan with 10 key goals to better secure the entire open-source software ecosystem. From a report: While open-source software itself can sometimes be freely available, securing it will have a price. OpenSSF has estimated that its plan will require $147.9 million in funding over a two-year period. In a press conference held after the summit, Brian Behlendorf, general manager of OpenSSF, said that $30 million has already been pledged by OpenSSF members including Amazon, Intel, VMware, Ericsson, Google and Microsoft.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Calling a Man Bald Counts as Sexual Harassment, UK Judge Rules
Calling a man bald can now be classed as sexual harassment, a U.K. employment tribunal judge has ruled. From a report: Three members of the tribunal who decided on the ruling, and alluded to their own experience of hair loss, said that baldness was more prevalent in men than women. Therefore, they argued that the use of the word "bald" as an insult related to a "protected characteristic of sex." The tribunal compared calling a man bald to commenting on the size of woman's breasts, based on a 1995 case. The ruling, published Wednesday, was made on a case where the insult was alleged to have been used against Tony Finn, while he worked as an electrician for the British Bung Manufacturing Company. Finn had worked at the company, which manufactures wooden cask closures for the brewing industry, in Yorkshire in the northeast of England, for nearly 24 years. He was fired last year and the circumstances around his dismissal were also part of the case. Finn claimed that he was called a "bald c---" and was also threatened by his shift supervisor, Jamie King, in a dispute in July 2019.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Elon Musk Says Twitter Deal 'Temporarily On Hold Over Spam'
Third Position shares a report from The Verge: Elon Musk says his deal to buy Twitter is "temporarily on hold" after the social network reported that false or spam accounts comprised less than 5 percent of its 226 million monetizable daily active users. The Tesla CEO, who offered to buy twitter for $44 billion, tweeted a link to a May 2nd Reuters report on Twitter's filing, saying he wants to see the company's calculations. "Twitter deal temporarily on hold pending details supporting calculation that spam/fake accounts do indeed represent less than 5% of users," Musk tweeted. However, in a follow-up tweet, he added that he's "still committed to [the] acquisition," suggesting that it'll proceed after Twitter provides satisfactory information on its numbers. Slashdot reader Excelcia shared a similar report from the BBC, which cited analysts speculating "he could be seeking to renegotiate the price or even walk away from the takeover."
"One analyst, as quoted in the story, suggests that 'Many will view this as Musk using this Twitter filing/spam accounts as a way to get out of this deal in a vastly changing market,'" writes Excelcia. "Shares have dropped another 10% since the announcement."
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci
Facebook-Owner Meta Tells Hardware Staffers To Prepare for Cutbacks
Facebook-owner Meta Platforms is preparing cutbacks in its Reality Labs division, a unit at the center of the company's strategy to refocus on hardware products and the "metaverse," a spokesperson confirmed to Reuters on Wednesday. From a report: Chief Technology Officer Andrew Bosworth told Reality Labs staffers during a weekly Q&A session on Tuesday to expect the changes to be announced within a week, according to a summary of his comments viewed by Reuters. The Meta spokesperson confirmed that Bosworth told staffers the division could not afford to do some projects anymore and would have to postpone others, without specifying which projects would be affected. She said Meta was not planning layoffs as part of the changes.
Read more of this story at Slashdot.
Kategorie: Informacje z Sieci


