-- Leo's gemini proxy

-- Connecting to gemini.techrights.org:1965...

-- Connected

-- Sending request

-- Meta line: 20 text/gemini;lang=en-GB


● 07.20.21


● Links 21/7/2021: WordPress 5.8, Wine 6.13, and VirtualBox 6.1.24


Posted in News Roundup at 6:20 pm by Dr. Roy SchestowitzContentsGNU/LinuxDistributionsDevices/EmbeddedFree Software/Open SourceLeftovers

GNU/Linux


Desktop/Laptop


↺ Microsoft has its own Linux distribution.


The days when Microsoft CEO, the shy and retiring Steve Ballmer, called Linux cancer on the software industry, are really dead and buried – Vole now has its own Linux distribution which it is even telling people about.


Audiocasts/Shows


↺ The Killer Feature Of Tiling Window Managers Isn’t Tiling


I often get people telling me that they don’t see the point of using a tiling window manager. I think part of the problem is the name “tiling window manager”.


↺ Using Linux at work – KDE Edition


This is an update on the Linux at work series I started a while ago! At the time, I was using elementary OS on a Huawei matebook 13, to work as a Product Owner. Since then, remote work became a lot more prevalent, and I also changed distros, and laptops, so let’s see how I’m making Linux and KDE work as my primary OS, on my laptop, and desktop!


Kernel Space


↺ Linux 5.12 Kernel Reaches End of Life, Upgrade to Linux Kernel 5.13 Now


Released about three months ago, Linux kernel 5.12 introduced lots of goodies, including support for Playstation 5 DualSense and Nintendo 64 game controllers, eMMC inline encryption support, support for the Lenovo IdeaPad platform profile and the Lenovo ThinkPad X1 Tablet Gen 2, as well as a new memory-debugging tool called KFENCE.


It also introduced initial support for zoned block devices to the Btrfs file system, LTO in Clang support, AMDGPU Freesync HDMI support, and many other cool features, but it’s now marked as EOL (End of Life) on the kernel.org website, which means that it will no longer receive support upstream and that you must upgrade to a newer or LTS kernel as soon as possible.


↺ Linux 5.13.4


↺ Linux 5.12.19


↺ Linux 5.10.52


↺ Linux 5.4.134


↺ Linux 4.19.198


↺ Linux 4.14.240


↺ Linux 4.9.276


↺ Linux 4.4.276


Graphics Stack


↺ AMD Posts Linux Graphics Driver Patches For “Cyan Skillfish”


AMD posted a new patch series bringing up a new graphics processor, Cyan Skillfish.


As usual, this is a Linux-focused codename for a yet-to-be-launched product with their naming convention of an X11 color name paired with a fish species.


While yet to be launched, Cyan Skillfish isn’t as exciting as some of the recent RDNA2 or CDNA GPUs. Cyan Skillfish is the support for a Navi (1x) graphics processor in a forthcoming APU.


↺ Reverse-engineering the Mali G78


After a month of reverse-engineering, we’re excited to release documentation on the Valhall instruction set, available as a PDF. The findings are summarized in an XML architecture description for machine consumption. In tandem with the documentation, we’ve developed a Valhall assembler and disassembler as a reverse-engineering aid.


Valhall is the fourth Arm® Mali™ architecture and the fifth Mali instruction set. It is implemented in the Arm® Mali™-G78, the most recently released Mali hardware, and Valhall will continue to be implemented in Mali products yet to come.


↺ Arm Mali “Valhall” Reverse-Engineering Started


The Panfrost open-source Linux graphics driver stack has matured nicely for Arm Mali Midgard and Bifrost generations but for the past two years now there has been Valhall as the latest-generation Arm Mali microarchitecture. There is now work underway on reverse-engineering Valhall for ultimately wiring up with open-source graphics driver support.


Panfrost lead developer Alyssa Rosenzweig commented today that reverse-engineering work has begun for Valhall with a focus on the Mali G78 in particular. This reverse engineering has been going on for just about one month but there is already some instruction set documentation made as well as an XML-based representation.


↺ NVIDIA Brings Its RTX Tech To Linux On Arm


When NVIDIA sets out to acquire a company, it doesn’t seem to waste any time to start producing custom product with the new IP access. After the company announced its plans to acquire Arm last fall, the company announced a full-fledged Arm-based supercomputer called Grace this past spring. Arm in the enterprise seemed likely, but did you expect to see the label “RTX” tied in with it, as well?


At the ongoing Game Developers Conference, NVIDIA announced that it’s bringing RTX to Arm on Linux, which should result in a number of different types of devices adopting it. With the help of two tech demos, the company utilized MediaTek’s Kompanio 120 (eight-core with 1-3-4 config) and gave it a GeForce RTX 3060 to work with. With one demo, the fast-paced Wolfenstein: Youngblood was shown-off, utilizing both ray tracing and DLSS. You can check it running in real-time in the video below:


Applications


↺ HandBrake 1.4.0


HandBrake is an open-source, GPL-licensed, multiplatform, multithreaded video transcoder, available for MacOS X, Linux and Windows. Handbrake can process most common multimedia files and any DVD or BluRay sources that do not contain any kind of copy protection.


↺ VirtualBox 6.1.24 Released with Support for Linux 5.13 and Ubuntu Specific Kernels


VirtualBox 6.1.24 comes almost three months after version 6.1.22 to introduce support for the latest and greatest Linux 5.13 kernel series, for both hosts and guests. As you can imagine, this means that you can now run GNU/Linux distributions powered by Linux kernel 5.13 on virtual machines or install VirtualBox on a distro running Linux 5.13.


For the first time, VirtualBox introduces support for kernels that are specific to a certain GNU/Linux distribution. In this release, there’s support for Ubuntu specific kernels, as well as kernels that are specific to the SUSE Linux Enterprise Server and Desktop (SLES/SLED) 15 SP3 (Service Pack 3) operating systems.


↺ The best email client for Linux, Windows and macOS isn’t Outlook


I rely on email. In fact, it’s my primary method of communication with the outside world. While most people are busy on Slack and other chat platforms, I still prefer email. Why? For one thing, I retain a digital trail of my communication. I can search through email threads to follow conversations with a single person (or multiple persons) with ease. Another reason is that I’ve been using email since the late ’90s, so it’s a very comfortable and familiar format.


Does that mean I ignore chat and other types of communication platforms? Not at all. But for my primary method of communication with clients, editors and publishers, it’s email all the way. It’s easy, fast and always there. I don’t have to worry about whether or not a recipient is online; they’ll get the communication one way or another.


But there is a slight problem. Which email client to use? There are quite a large number of apps available on every platform, and not every app is available for every operating system. You have Apple Mail for macOS, Outlook for Windows and macOS, Evolution for Linux, and a host of other possibilities. And for the longest time, everyone just assumed Microsoft Outlook was the single best email client on the planet.


For anyone who’s had to troubleshoot Outlook problems, you know just how bad that client can get when it’s in a fussy mood. I’ve experienced Outlook problems so bad, the only way to solve the problem was a complete reinstall of the OS. Granted, that situation was not normal, but it is very indicative of what can go wrong with that particular email client. And although Apple Mail is a very good email application, its macOS-only limitation is problematic. I will go so far as to say if Apple Mail was available for Linux, macOS and Windows, it would probably wind up at the very top of this list.


Instructionals/Technical


↺ How to Create Rust Virtual Environment Using Conda on Linux


Conda is an open-source package management system and environment management system for installing multiple versions of software packages and their dependencies. It is mainly developed for Python and not tied to any specific programming language. Conda allows you to install many programming languages in multiple different environments.


In this post, we will show you how to create Rust virtual environments using Conda in Linux.


↺ How to Install the Latest HPLIP Driver in Ubuntu 20.04 [Fix Dependency Issue] | UbuntuHandbook


Need the most recent HPLIP to get your HP printer or scanner working in Ubuntu? Here’s how to install guide as well as workaround to fix the python-pyqt5 dependency issue.


HPLIP is an open-source Linux drivers for HP’s inkjet and laser printers. The project is initiated and led by HP Inc. While the package in Ubuntu repositories is always old, you can install the official binary to get new devices support.


However, the most recent releases refuse to install in my Ubuntu 20.04 due to python-pyqt5 dependency issue. If you’re facing with the similar issue, then this tutorial may help!


↺ Linux Essentials – Automatically mounting storage volumes with /etc/fstab


In a previous video we went over the basics of storage, and in this episode of Linux Essentials, I’ll show you how to automatically mount storage volumes when you boot your server.


↺ Automatically bring up a SocketCAN interface on boot


Working with Controller Area Network (CAN) on your Linux PC? Through the SocketCAN kernel modules, Linux supports CAN quite well. It can be a bit tricky though, to get your USB-to-CAN adapter configured and up-and-running. This tutorial not only explains how to bring up your SocketCAN network interface, it also shows you how to configure your Linux system to automatically bring up your SocketCAN network interface, each time you plug it in or boot up your Linux system.


↺ How to Build a Package from Source in Linux – Make Tech Easier


Besides its open-source nature, customizability is one of the other reasons many users love Linux: you can modify and configure almost every file to meet your specific needs and style. This includes the ability to rebuild a package from source.


The ability to rebuild a package from the source can be beneficial to any Linux power user because it allows you to change packages, enable or disable a feature, or even apply custom modifications.


Wine or Emulation


↺ Wine 6.13


↺ Wine 6.13 Released With Proper Scrollbar Theming, More PE Conversion


The Wine project usually puts out new open-source development releases reliably every other week, but as is sometimes the case during the summer months, last Friday’s was missed due to summer holidays. That update — Wine 6.13 — has now shipped today.


Alexandre Julliard just issued the belated Wine 6.13 release. Among the changes this time around are now having proper scrollbar theming for Windows applications running in Wine, preparation work for the GDI system call interface, and more PE conversion work. There still is work going on the WinSock portable executable conversion and now on the IPHLPAPI PE conversion too.


Games


↺ Ubisoft are keeping an eye on the Steam Deck, will release on it if it’s big enough


Today during the Ubisoft conference call where they discussed first-quarter 2021-2022 sales, Steam Deck got mentioned.


It’s an interesting one, since Ubisoft has pretty much left Steam behind in favour of other stores like the Epic Games Store. The Epic store doesn’t support Linux, and Epic currently have no intention to do so. So unless people are expected to manually load up Windows to replace SteamOS, companies like Ubisoft would need to bring their games back to Steam to give users a good experience.


During the conference call that we listened to today, a question was asked about the Steam Deck from one investor.


↺ Space station building and management sim Starmancer confirmed for GOG


The release of the fantastic space station building and management game Starmancer is getting ever closer, and now a GOG released has been confirmed today. It’s been a while since the Kickstarter in 2018, which showed a hugely promising idea.


Starmancer follows long after some sort of catastrophe on Earth with the remains of humanity having their brains uploaded into special memory banks. You’re responsible for building up a sustainable station to enable supporting human life, which you end up growing in special pods to have a consciousness downloaded into.


“Starmancer offers gameplay with consequences, a living sandbox environment, crafting, and managing the daily lives of colonists. Create a utopian society where everyone is well fed, happy, and safe. Or go rogue and figure out how many times a colonist can eat wheat before they go crazy. The choice is yours!”


↺ DXVK-NVAPI 0.4 Released For Improving NVIDIA Integration Atop DXVK


DXVK-NVAPI 0.4 is out today for improving the implementation of this NVIDIA driver public API interface (NVAPI) within DXVK for running Windows Direct3D games on Linux. DXVK-NVAPI 0.4 updates against the latest public NVAPI header files, now makes use of the NVIDIA Management Library (NVML) for querying various attributes on Linux, changes around log level options, and adds an optional test suite for helping to verify the NVAPI support.


↺ The Nvidia Arm race has just put Microsoft, AMD, and Intel on notice


Nvidia is paving the way for entirely GeForce-powered notebooks, potentially shoving Microsoft, Intel, and AMD aside in its quest for high-performance gaming laptops. The green team has now proven the power of both ray tracing and DLSS running in a Linux distro, on ARM-based silicon, with RTX graphics cards plumbed into them.


And that should scare the crap out of everyone involved in the traditional Microsoft/x86 PC gaming monopoly.


So yeah, it sure looks like GDC 2021 is kicking off with a bang, as Nvidia has today shown Wolfenstein: Youngblood running with ray traced reflections enabled, and DLSS in operation, on a system using an eight-core MediaTek CPU and an Nvidia RTX 3060 GPU.


↺ Nvidia’s ARM-Powered Linux RTX Demo Is a Warning Shot to x86, Microsoft


↺ The Steam Deck Might Not Play All Games in Your Library


As of now, the Steam Deck might play all of the games in the Steam Library, though the developers at Valve are working hard to make everything work.


The Steam Deck is a portable gaming console. Its biggest selling point is its hardware specs capable of running even the most demanding PC games. So, if you’re the type of person who wants to play games on the go, this thing is ideal for you.


That said, while there are many games to choose from, you might not get them running on this device.


↺ Steam Deck SSD Replacement Possible on All Models


Valve’s upcoming handheld Steam Deck will allow its users to replace and upgrade its internal SSD with their own, although the company strongly recommends against it.


The news was first brought to light by Valve’s head Game Newell himself by responding to a redditor’s inquiry about the system’s SSD. The Steam Deck’s website was later updated (spotted via VGC) to state that all models “use socketed 2230 m.2 modules (not intended for end-user replacement).”


↺ Gadgets Weekly: Valve Steam Deck, Asus Chromebooks and more


Out of the blue, Valve Corp on Thursday unveiled the company’s first-ever hand-held gaming console Steam Deck, which competes directly with the popular Nintendo Switch series.


The new Steam Deck sports wide 7.0-inch HD+ (1,280x800p) LCD panel with a 16:10 aspect ratio. It supports up to 60Hz display refresh rate, and offers close to 400 nits of peak brightness.


Yes, the screen is touch-sensitive and also comes with an ambient light sensor, stereo speakers and a dual microphone array.


Inside, it houses AMD’s custom APU, optimized for handheld gaming. The APU’s power ranges from 4W to 15W, which promises to deliver more than enough performance to run the latest AAA games very efficiently.


Desktop Environments/WMs


K Desktop Environment/KDE SC/Qt


↺ Akademy 2021 Interview: In Conversation with Jeri Ellsworth


A *loooong* conversation with Jeri Ellsworth, self-made inventor, chip designer, AR entrepreneur and keynote speaker at Akademy 2021.


GNOME Desktop/GTK


↺ How Calls became a part of GNOME


Since Purism’s philosophy and GNOME’s principles are closely aligned it is not far fetched to call them a match made in heaven.


As you probably know the software stack in use on the Librem 5 is built upon GNOME technologies and has been designed by parts the GNOME Design Team.


This is why we’re happy to officially announce that Calls will become a part of the GNOME project. Having a dialer application available shows that mobile is an important use case for GNOME. Furthermore this shows that we take upstreaming our development efforts and making them available to the wider community very seriously.


The old repository has been archived and the new repository where development takes place can be found here while the packaging for PureOS can be found here.


By moving to GNOME infrastructure we hope to generate more community interest around Calls.


Distributions


IBM/Red Hat/Fedora


↺ How natural language processing can fight deforestation: MANA-Vox


Every second, more than one hectare of tropical forestland is destroyed around the planet, in many cases, by large global corporations in the incessant hunt for agricultural space, timber, and urban expansion. Many times, this shows up on the web and in social media, but finding credible, up-to-date information from the thousands of posts produced every day can be a full-time job for a researcher, and a tough proposition for any non-profit working in this space.


↺ Gartner dumps IBM from 2021 enterprise backup’n’recovery MQ leader corner


↺ didn’t renew the payment (bribe) to Gartner


Debian Family


↺ Debian GNU/Linux 10 “Buster” Users Get New Linux Kernel Security Update, 4 Flaws Patched


The new Linux kernel security update comes about three months after the previous kernel update and it’s here to address a total of four security vulnerabilities discovered by various security researchers in the upstream Linux 4.19 kernel series used by the Debian GNU/Linux 10 “Buster” operating system.


The four security flaws patched in this kernel update are CVE-2020-36311, a vulnerability discovered in the KVM subsystem for AMD CPUs that could allow an attacker to cause a denial of service (soft lockup) by triggering the destruction of a large Secure Encrypted Virtualization (SEV) virtual machine.


Devices/Embedded


↺ Tiny compute module and dev kit give root to STM32MP1 applications


MYIR’s tiny “MYC-YA15XC-T” module runs Linux on ST’s STM32MP1 with up to 512MB DDR3L and 4GB eMMC and optional -45 to -85°C support. The module is supported with a “MYD-YA15XC-T” dev kit.


MYIR announced a 39 x 37mm MYC-YA15XC-T module as a more compact alternative to its 45 x 43mm MYC-YA157C module, which similarly runs Linux on STMicroelectronics’ 650MHz to 800MHz, single- or dual-core, Cortex-A7 STM32MP1. The SoC also integrates a 209MHz Cortex-M4 MCU, cryptography, and secure boot.


The MYC-YA15XC-T lacks the MYC-YA157C’s GbE controller and is limited to 148 stamp-hole (castellated-hole) pins instead of 164. This was enough of a difference for MYIR to whip up a custom MYD-YA15XC-T carrier board for the module instead of using the MYC-YA157C’s smaller MYD-YA157C board (see farther below).


Open Hardware/Modding


↺ An Arduino-powered micro quadruped that fits in the palm of your hand | Arduino Blog


Arduino-powered quadruped robots are quite common projects for hobbyists to build once they are a bit more comfortable with embedded systems. One problem with many of the pre-designed quadruped platforms is that they require a lot of time to assemble owing to their large size. This is what inspired Technovation to come up their own micro quadruped robot, which requires only a fraction of the normal amount of material and hours to construct.


The robot is based around a central chassis that houses the Arduino Uno and sensor shield components, which provide power and signaling to the motors. Underneath this hardware stack are four servos that can rotate to the side and act as hip joints. Lastly, each leg is comprised of two servos to allow for forward motion.


↺ Design for Disassembly: This Old Idea is the Wave of the Future


The stats feel tired at this point: the EPA tells us that over 10 million tons of furniture are taken to US landfills each year, and more than 2 thousand tons of major appliances will be tossed onto the heap in 2021 alone. As product designers, this can lead us straight to an existential fever dream, imagining Victor Papanek whispering in our ear: “There are professions more harmful than industrial design, but only a few.”


The reality is that consumption-based capitalism isn’t going anywhere. But we as designers and business leaders have the opportunity and the agency to devise ways to implement healthier making and sourcing methods by rethinking our approaches to design.


How can our products’ life spans be prolonged? How can our designs encourage repair? How can we insist on our work’s participation in a circular economy? I give you, with as much bravado as I may, our solution: Design for Disassembly (DfD).


Mobile Systems/Mobile Applications


↺ Poll: How long do you keep your Android smartphone before upgrading? | Android Central


↺ How To Record Calls on Your Android Smartphone


↺ Gboard Material You redesign rolling out on Android 12 – 9to5Google


↺ Android 12 has a controversial change — and some people are really upset | Tom’s Guide


↺ LG G8X ThinQ Android 11 update imminent as source code gets published


↺ Motorola Android 11 update: List of eligible devices & release date


↺ Motorola Android 11 update bugs, issues, & problems tracker


↺ Samsung impressively updates the old and humble Galaxy A10e to Android 11 in the US – PhoneArena


↺ Android TV gains some of Google TV’s best features | What Hi-Fi?


↺ Some URL shortener services distribute Android malware, including banking or SMS trojans | WeLiveSecurity


↺ Anker PowerWave Alloy review: The best wireless charger for Android | Android Central


↺ Sony clarifies: the Xperia 1 III will get at least two Android updates – GSMArena.com news


↺ Verizon is also switching to Android Messages as default for RCS – The Verge


↺ Chrome for Android will make it easier to manage sites’ permissions – The Verge


↺ Google shutting down My Maps Android app in favor of web – 9to5Google


↺ OnePlus Nord 2 5G’s design confirmed in latest teaser


The OnePlus Nord 2 5G’s renders that leaked last month revealed the smartphone’s design, which is now officially confirmed by the phone maker as it posted a teaser of the Nord 2 5G on its social media accounts.


The image shows us the Nord 2 5G’s rear side, which is similar to the OnePlus 9′s. It has a OnePlus logo, and a camera island in the top-left corner housing three cameras, with the primary camera already confirmed to use a 50MP Sony IMX7666 sensor with OIS.


Free, Libre, and Open Source Software


Web Browsers


Mozilla


↺ Firefox May Have Lost Up to 12% Of Its Users So Far In 2021


Firefox is the default web browser installed on most Linux distributions. It is a well-known browser by Mozilla that respects user privacy by design, and currently remains the only major web browser pushing for open web standards and community interest rather than giant corporations like Google, Microsoft or Apple.


The existence of Firefox is important for the open source community. Both to prevent the monopoly of these corporations on the web and also to ensure a free and open source web browser (and engine!) remains accessible for end-users.


However, Firefox has been recently struggling on many different fronts and on a number of issues and topics. We have covered a story in October, 2020 where Mozilla’s CEO was found to be getting a large $2.4M annual salary, while 25% of Mozilla’s workforce was let go because of financial issues at Mozilla. And yet, Mozilla is promoting initiatives to fight political ads, misinformation and “promote diversity” rather than fixing its own problems.


↺ Spring Cleaning MDN: Part 1


Most notably MDN now manages its content from a repository on GitHub. Prior to this, the content was stored in a database and edited by logging in to the site and modifying content via an in-page (WYSIWYG) editor, aka ‘The Wiki’. Since the big move, we have determined that MDN accounts are no longer functional for our users. If you want to edit or contribute content, you need to sign in to GitHub, not MDN.


SaaS/Back End/Databases


↺ SQLite Extraction of Oracle Tables Tools, Methods and Pitfalls


The SQLite database is a wildly successful and ubiquitous software package that is mostly unknown to the larger IT community. Designed and coded by Dr. Richard Hipp, the third major revision of SQLite serves many users in market segments with critical requirements for software quality, which SQLite has met with compliance to the DO-178B avionics standard. In addition to a strong presence in aerospace and automotive, most major operating system vendors (including Oracle, Microsoft, Apple, Google, and RedHat) include SQLite as a core OS component.


There are a few eccentricities that may trip up users from other RDBMS environments. SQLite is known as a “flexibly-typed” database, unlike Oracle which rigidly enforces columnar datatypes; character values can be inserted into SQLite columns that are declared integer without error (although check constraints can strengthen SQLite type rigidity, if desired). While many concurrent processes are allowed to read from a SQLite database, only one process is allowed write privilege at any time (applications requiring concurrent writers should tread carefully with SQLite). There is no network interface, and all connections are made through a filesystem; SQLite does not implement a client-server model. There is no “point in time recovery,” and backup operations are basically an Oracle 7-style ALTER DATAFILE BEGIN BACKUP that makes a transaction-consistent copy of the whole database. GRANT and REVOKE are not implemented in SQLite, which uses filesystem permissions for all access control. There are no background processes, and newly-connecting clients may find themselves delayed and responsible for transaction recovery, statistics collection, or other administrative functions that are quietly performed in the background in this “zero-administration database.” Some history and architecture of SQLite can be found in audio and video records of Dr. Hipp’s discussions.


Despite these eccentricities, SQLite is likely a superior format for data exchange as opposed to CSV, XML, or even JSON, as indexes can be included, enabling recipients to perform high-speed queries in SQL92 without any preprocessing, licensing, or activation. SQLite’s conservative coding style and commentary is intended to benefit “future programmers who are not yet born,” and the on-disk database format has further been defined as a long-term storage standard by the Library of the U.S. Congress.


CMS


↺ WordPress 5.8 Tatum


Introducing 5.8 “Tatum”, our latest and greatest release now available for download or update in your dashboard. Named in honor of Art Tatum, the legendary Jazz pianist. His formidable technique and willingness to push boundaries inspired musicians and changed what people thought could be done.


So fire up your music service of choice and enjoy Tatum’s famous recordings of ‘Tea for Two’, ‘Tiger Rag’, ‘Begin the Beguine’, and ‘Night and Day’ as you read about what the latest WordPress version brings to you.


FSF


↺ Freedom moving forward: An overview of the FSF’s history


Our thirty-fifth birthday as an organization has given us the opportunity to think about the Free Software Foundation’s (FSF) development over the years. More than thirty-five years of history is hard to bring together in a few sentences, so much so that even staff at the FSF sometimes have to do serious research into the exact dates that milestones occurred. This being the case, we realized it was high time to create an overview listing key points in the history of the FSF and GNU.


Today we launched the FSF history timeline page which shows a clear overview of milestones for the organization, like when the GPLv3 was published, or when the first LibrePlanet conference took place.


Licensing/Legal


↺ Our lawsuit against ChessBase


The Stockfish project strongly believes in free and open-source software and data. Collaboration is what made this engine the strongest chess engine in the world. We license our software using the GNU General Public License, Version 3 (GPL) with the intent to guarantee all chess enthusiasts the freedom to use, share and change all versions of the program.


Unfortunately, not everybody shares this vision of openness. We have come to realize that ChessBase concealed from their customers Stockfish as the true origin of key parts of their products (see also earlier blog posts by us and the joint Lichess, Leela Chess Zero, and Stockfish teams). Indeed, few customers know they obtained a modified version of Stockfish when they paid for Fat Fritz 2 or Houdini 6 – both Stockfish derivatives – and they thus have good reason to be upset. ChessBase repeatedly violated central obligations of the GPL, which ensures that the user of the software is informed of their rights. These rights are explicit in the license and include access to the corresponding sources, and the right to reproduce, modify and distribute GPLed programs royalty-free.


↺ Stockfish sues ChessBase


The Stockfish project, which distributes a chess engine under GPLv3, has announced the filing of a GPL-enforcement lawsuit against ChessBase, which has been (and evidently still is) distributing proprietary versions of the Stockfish code.


↺ Are you compliant with open-source license obligations?


A short answer is no. Your piece of software will not be open-source if it doesn’t have an open-source license. Under copyright law, such software is copyrighted by default, with all the restrictions that this implies.


If you want anyone to use your code freely, you should ensure certain liberties commonly called “the four freedoms“. They say that OS software may be used, studied, modified, and distributed freely, as long as the license is respected.


For the first three, there are no conditions of any kind; you are free to use, study, and modify the code for any purpose. If you move beyond that and decide to distribute your modified version (or the original), this is when open-source license compliance starts.


Missing license texts are the number one cause of license infringement cases, which, as we’ve seen above, can lead to the loss of ownership rights and enforcement actions such as an interim injunction.


Programming/Development


Python


↺ The data worker’s guide to psiphiorrhea


A dataset I recently audited had a record for a marine specimen observed at latitude 6.47457312, longitude -52.5741239, depth 103.8799973 metres. I’ve changed the coordinates (but not their number of decimal places) to protect the data owner’s privacy.


While those coordinates aren’t as impressive as the -33.8903169365705 151.198409720645 I blogged about in 2019 for a huge building in Sydney, Australia, they still specify the specimen’s underwater location ±0.55 millimetres in latitude. And the depth measurement is ±0.00005 millimetres.


I suspect that the marine recorder might be afflicted with psiphiorrhea. I concocted this word (pronounced siff-ee-oh-REE-uh) from Greek roots meaning “digit or numeral” and “flux”. In the same way that someone who talks far too much is exhibiting logorrhea, or excessive word-iness, someone who uses far too many digits in their numbers is exhibiting psiphiorrhea, or excessive digit-iness.


Leftovers


Science


↺ Not only is Hubble back online after outage, it’s already taking photos of the cosmos • The Register


The Hubble Space Telescope is back in action doing what it does best – capturing stunning images of the universe – after more than 50 NASA engineers worked hundreds of hours to get the instrument working again.


After activating redundant components within the orbiting observatory on Friday to clear a hardware glitch, the telescope has been able to use its sensors again. NASA released two photos of oddball galaxies Hubble snapped over the weekend: one depicting two galaxies intersecting each other, and the other showing a large spiral galaxy with three arms.


Integrity/Availability


Proprietary


↺ China says Microsoft hacking accusations fabricated by US and allies


↺ US legal eagles representing Apple, IBM, and more take 5 months to inform clients of ransomware data breach


Security


↺ Researchers flag 7-years-old privilege escalation flaw in Linux kernel (CVE-2021-33909)


A vulnerability (CVE-2021-33909) in the Linux kernel’s filesystem layer that may allow local, unprivileged attackers to gain root privileges on a vulnerable host has been unearthed by researchers.


↺ New Linux kernel bug lets you get root on most modern distros


↺ Nasty Linux systemd security bug revealed


Qualsys has found an ugly Linux systemd security hole that can enable any unprivileged user to crash a Linux system. The patch is available, and you should deploy it as soon as possible.


↺ How IBM i Fits Into a Zero-Trust Security Framework


One of the hot new trends in cybersecurity these days is the zero-trust security model. Instead of implicitly trusting network traffic behind the firewall, zero-trust demands that traffic have explicit permission to be there. But how does that model work with the strange beast known as IBM i? IT Jungle recently sat down with PJ Kirner, the CTO and co-founder of zero-trust software provider Illumio, to find out.


Illumio is an eight-year-old venture-backed startup based in Sunnyvale, California, that is working in the field of zero-trust security. It develops an offering, called Illumio Core, that allows companies to begin implementing the zero-trust security model in their own data centers.


It’s a fairly radical shift in philosophy, Kirner says. “There’s a mentality change from ‘I trust everything’ to . . . ‘I need a policy enforcement point of some sort everywhere, not just in the one place at the boundary of two things,’” he says.


When fully built out, an IT estate with an active zero-trust security model will resemble a party where only invited guests are allowed in. Building from a whitelist, or “allow list,” is starkly different than starting with a blacklist, or an “exclude list,” Kirner says. “If you start by saying just these two things are not allowed to talk, well, that’s a whole bunch of implicit trust around everything else,” he says.


Illumio, which recently added support for IBM i systems, begins every zero-trust security engagement by making a map of network traffic behind the firewall. Illumio develops software that does this mapping, which can be quite illuminating in its own right.


↺ New Windows 10 vulnerability allows anyone to get admin privileges


↺ The virus rears its ugly head….


There is a virus going around. We thought we were winning the battle against it, but powerful forces and events have allowed it to raise its ugly head and cause unforeseen additional hardship. People thought that it was not so bad, they did not listen to reason and take the precautionary measures necessary to protect themselves. In letting down their guard they were unprepared and unprotected. After months of machines being turned off, software licenses (with their expiration dates never “dormant”) are up for renewal. Many companies, educational institutions and public buildings (like libraries) are turning on their Wintel PCs for the first time in over a year and finding that they need to renew their licenses, not only for what is called an operating system on their computer, but also for many of the closed source, proprietary add-on software packages that owners purchased in a wild attempt to make their hardware somewhat useful.


[...]


This variant is called “Windows 11”, and the creator of it seems to be unable to tell you how much havoc it will create for you. Does it run on your otherwise great hardware? You have a decent processor, a lot of RAM, and you bought it just two or three years ago….but it might not run Windows 11.


↺ UK.gov’s Huawei watchdog says firm made ‘no overall improvement’ on firmware security but won’t say why


Huawei has made “no overall improvement” in software engineering processes for its UK telecoms equipment’s firmware, its GCHQ overseers have warned.


The Huawei Cyber Security Evaluation Cell (HCSEC) oversight board’s annual report for 2020 was noticeably less critical than in previous years – but still says Huawei is dragging its feet in key areas.


↺ Northern Train’s ticketing system out to lunch as ransomware attack shuts down servers


Publicly owned rail operator Northern Trains has an excuse somewhat more technical than “leaves on the line” for its latest service disruption: a ransomware attack that has left its self-service ticketing booths out for the count.


“Last week we experienced technical difficulties with our self-service ticket machines, which meant all have had to be taken offline,” a spokesperson for Northern Trains confirmed to the The Register.


↺ Fortinet’s security appliances hit by remote code execution vulnerability


Security appliance slinger Fortinet has warned of a critical vulnerability in its products that can be exploited to allow unauthenticated attackers full control over the target system – providing a particular daemon is enabled.


The vulnerability, discovered by Orange Group security researcher Cyrille Chatras and sent to Fortinet privately for responsible disclosure, lies in the FortiManager and FortiAnalyzer software running atop selected models in the company’s FortiGate security appliance family. Should a particular daemon be enabled, the company admitted, a remote attacker can gain full control.


Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation


↺ Romanian Linux Cryptojacking Cybercriminals Spotted


Since at least 2020, an active threat organization based in Romania has been running a cryptojacking operation against Linux-based machines using the Golang-based SSH brute force, according to The Hacker News. The campaign’s objective is to infect Linux systems with Monero mining applications.


Privacy/Surveillance


↺ India IT minister denies illegal use of NSO Pegasus spyware


Indian IT Minister Ashwini Vaishnaw has denied the nation illegally used the NSO Group’s Pegasus spyware, but hasn’t denied that India used it.


The existence of Pegasus is not news. But over the weekend, Amnesty International, French outfit Forbidden Stories and a dozen publications around the world alleged the software has been widely misused to target media, dissidents, and other individuals, and that NSO Group’s assertions its products are only used in the cause of national security are insincere at best.


Environment


Wildlife/Nature


↺ Thousands of penguins crowding near Ukrainian polar station


Ukrainian polar explorers recorded large waddles of penguins near the Antarctic station “Academician Vernadsky”. “This July, our polar explorers recorded extremely large winter waddles of penguins: hundreds and thousands of individuals have a rest on different islands within a radius of 20 km from the station, and hundreds of penguins that eat can be observed in the water at the same time. These are mostly sub-Antarctic penguins (Gentoo) or Adélie penguins,” the National Antarctic Scientific Center of Ukraine posted on Facebook.


Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages. Permalink  Send this to a friend

----------

Techrights

➮ Sharing is caring. Content is available under CC-BY-SA.

-- Response ended

-- Page fetched on Tue May 7 10:28:53 2024