Skip to main content




Local Privilege Escalation Vulnerability Affecting X.Org Server For 18 Years


Crosspost of lemmy.sdf.org/post/24401210
This entry was edited (1 year ago)

reshared this

in reply to wizardbeard

What do you expect? X11 is in maintenance mode. Although I'll miss Polybar, I won't miss the protocol.
in reply to Phoenixz

It is. That's why Wayland is being pushed so hard, it's a codebase that's actually maintainable, with hopefully some more modern design and engineering principles.
in reply to Phoenixz

Well, freedesktop.org is now focused on Wayland (Xorg is not getting HDR, new synchronization protocols, or proper VRR (unless through XWayland), while Wayland is). RedHat RHEL marked Xorg as deprecated last year and will not even support it by next year (RHEL 10). KDE and GNOME also default to Wayland.
in reply to Matt

I think it's still valuable to document these things so that the users who insist on sticking with X11 can receive a healthy dose of (replace diapers with vulnerabilities) when the proverbial shit hits the fan and it becomes as hackable as Windows XP
This entry was edited (1 year ago)

in reply to John

Does anyone know if PDFs still cause crashes? I should switch again. Used the beta for a while but had some issues and removed it.

Btw, here is how you get the Beta Flatpak (flathub beta)

here is how you get the Nightly Flatpak (GNOME nightly)

in reply to John

There have been so many announcements that a release candidate of a release will be coming out /soon/. It's utterly pointless non-news.

Please can this drivel be banished.

Wait until 3.0.0 is actually released and then post it for discussion.

This entry was edited (1 year ago)



in reply to §ɦṛɛɗɗịɛ ßịⱺ𝔩ⱺɠịᵴŧ

Western media has perpetrated a dangerous myth: that individual actions alone can solve the climate crisis. This narrative deliberately ignores the systemic roots of the problem, shifting the burden onto individuals while corporations and oligarchs continue with business as usual.

Individual actions are utterly dwarfed by the impact of industrial pollution, unsustainable agriculture, and fossil fuel extraction. We've been tricked into focusing on recycling while the planet burns. The truth is, our entire economic system, built on the insatiable hunger for constant growth and consumption, is fundamentally incompatible with a livable planet.

The powerful have masterfully manipulated public perception, diverting attention from the true drivers of the climate crisis. This propaganda campaign protects their profits while undermining the urgent need for systemic change. We're being gaslit into believing we're the problem, not the system.

in reply to ☆ Yσɠƚԋσʂ ☆

Why the "Western" in media here? Did "Eastern" media promote the opposite?

don't like this

in reply to massive_bereavement

The east, specifically China, is taking concrete action to make the necessary structural changes instead of using the media to manipulate public opinion. As a result, emissions in China have now entered a structural decline, China dominates renewables such as wind and solar with China having added more solar capacity in 2023 alone than the US has in its entire history, and continues rapidly expanding its nuclear capacity. This clean energy infrastructure is now being exported to the Global South as well. That's what real tangible action looks like.
in reply to ☆ Yσɠƚԋσʂ ☆

Have those emissions results been verified by an independent third party?

I agree that at least on paper China is taking much stronger action than many other countries.

in reply to Pulptastic

The analysis was done by an independent third party:

Emissions from the world’s most polluting country have rebounded this year after the Chinese government dropped its Covid restrictions in January, according to analysis undertaken for Carbon Brief.


Furthermore, I'm not sure what basis there is for being skeptical here. It's universally acknowledged that China has created massive renewable infrastructure, and it follows that as clean energy production increases the emissions would fall.



Raspberry Pi OS improves touchscreen support and now uses Wayland by default

Raspberry Pi OS is a Debian-based GNU/Linux distribution that’s developed by the Raspberry Pi team and designed to run on the company’s single-board computers. The latest version brings a big change that causal users might not even notice: it uses the labwc Wayland compositor by default on all Raspberry Pi models rather than the wayfire compositor or X Window system.

There’s also a smaller […]

liliputing.com/?p=173001

#labwc #phosh #raspberryPi #raspberryPiOs #squeekboard #wayfire #wayland



What Is Israel’s Elite Ghost Unit That Was Targeted in Gaza?


in reply to not_now_kitten

The Ghost Unit’s Key Features and Capabilities Ghost Unit 888 operates on a unique, high-speed combat philosophy called the “kill chain,” aimed at instantly detecting and killing targets. Its rapid response strategy is designed to close the detection-to-elimination cycle in mere seconds, far faster than traditional combat timelines. For instance, recent conflicts like Ukraine demonstrate a five-minute detection-to-response time, yet Unit 888 seeks to compress this to near-instantaneous action.


In short, they don't take time to discern whether or not the target is a civilian or combatant.



Some (Slightly Biased) Thoughts On The State Of Decentralized Social Media - TechDirt


in reply to ElectroVagrant

The key to every “killer app” on a new system, even ones that start out mimicking the old paradigm, is enabling something that couldn’t be done on the old system.


This makes me think of my biggest gripe with the social media I use and it's the lack of feeling safe, and I don't mean that I want to be sheltered or have content hidden from me. I'm tired of living in the giant melting pot.


Unknown parent

lemmy - Link to source
hedgehog

Right? It’s weird how so many people upset about the situation in this thread are incapable of explaining why it’s a problem without lying.

Like, I get that it sucks to be removed as a maintainer because of reasons outside your control. But being, or continuing to be, a maintainer of a project isn’t a right that’s integral to that project being free.

This entry was edited (1 year ago)
Unknown parent

lemmy - Link to source
uiiiq
It doesn’t. Russians are still free to use and contribute to Linux development. Just a few people lost their maintainer rights.

in reply to learnbyexample

Does anyone here actually use awk for more than trivial operations? If I ever have to have to consider writing anything substantial with bash/awk/sed/etc, I just start writing a Python script. No hate to the classic tools, but Python is just really nice.
in reply to BitSound

Yeah. Heaviest awk I've ever done is extracting a value to a variable from a line with one pattern and using it to populate output from later lines matching another pattern.
in reply to BitSound

If find myself writing anything I'd call a "program" (rather than just a script) in bash then it's time to think about using a proper language rather than a shell script, let alone awk or sed!
in reply to BitSound

I've reached for some complex awk when I am looking to parse snippets of code where breaking out a full language parser would have been too much.

One example is parsing statements from a Dockerfile but only within certain stages of the image. So I reach for regex range in awk and I can make something that works everywhere.

Of course I probably could have done the same thing in python by controlling the beginning and end via variables, but I like awk sometimes.



The CUPS Vulnerability


in reply to deadcade

Even if you computer is not exposed to the internet: are you certain that every other device on the network is safe (even on public wifi)? Would you immediately raise the alarm if you saw a second printer in the list with the same name, or something like "Print to file"? I think I personally could fall for that under the right circumstances.
in reply to koper

That was a possibility with this exploit, but realistically that doesn't affect nearly as many people as "All GNU/Linux systems".

in reply to Linktank

Would you like to add some details on why do you see this as a "braindead take"? It might help you to convince other people that it is "braindead take" :)
in reply to Bobr

Anybody who needs convincing of this is beyond any help that an explanation of my opinion could provide. If you are looking for moral quibbles between two situations where civilians are being murdered then there might be something wrong with you.


Europe Is Not Prepared for the Looming Lebanese Refugee Crisis | naked capitalism


Conor here: I don’t understand why this is so hard. If Europe doesn’t want or is unprepared for so many refugees, it should stop with the destruction of societies in the vicinity of the “garden” walls. The media always seems to ignore Europe’s role in creating these crises. The way the EU and/or some of its member countries keeps launching or supporting these bloody messes (Libya, Syria, Ukraine, Palestine, Lebanon) is enough to make one wonder if it’s actually a conscious policy in order to bring in more exploitable refugee labor. But to believe that, you’d have to believe the current crop of European officials and their benefactors have the ability of such foresight.

[...]

This entry was edited (1 year ago)
in reply to not_now_kitten

Europe hasn't politically recovered from the last few refugee crises, nor have national collectives been able to properly integrate or adjust to the fact they're there, it's been ran as a pressure point, and adding even more pressure will certainly enable those politicians to hit this button with greater effect.

I don't fucking understand why no European leader is looking at what Israel is doing with realpolitik and go "why the fuck are you creating another migrant crisis", unless that is exactly what they want, to get power for themselves. Urgh.

in reply to JoJo

Yes, as you implied, some have in their mind as realpolitik that refugee crises create opportunities for fascism, and that's cool. It's just practical politics to fuel climate change and war.
in reply to JoJo

Collective guilt combined with massive Israeli political pressure.
in reply to not_now_kitten

35-40% of Lebanese are Christians, it will be interesting if Europeans will care or tell the difference.



Apparently, the mods at Linuxsucks are really sensitive?


Saw a post without noticing the community and commented a genuine comment with good intentions.

Apparently it was against the rules of that community and I was banned.

Original post:
Image/photo

My (removed) comment:
Image/photo

And yeah, the last comment was sarcasm.

I just don't really understand why is there a community for shitting on Linux? Like I can get not liking it, and hating the Linux die hard fans, but it really is an amazing thing that is integral to almost all modern computing... Kind of like hating social media by having a facebook page for it.

in reply to MTK

When I was on reddit the ones spouting the most linux hate seemed to fall into two main categories.

1) those that tried it like 15 years ago and still hold a grudge.

2) dudes who heard people rave about linux but they themselves struggled with certain concepts when trying it out. And rather than realize they need to read instructions and learn new things, instead would rather blame linux for not working as expected.

in reply to MTK

The Linux world have bad things, especially in userland and libc


in reply to Tux

If you're using Twitter, fuck you.

I don't care why you're still on some fascist manchild's propaganda box. Leave. You're already here - you know alternatives exist. Stop visiting the Nazi bar.

in reply to Tux

If you have the choice between Firefox and Xitter and are conflicted... What are you even doing with your life??


WhatsApp running through android-translation-layer (no container!) on Linux desktop


Since reddit.com/r/linux/comments/1g… got a bit of traction yesterday, this is WhatsApp straight from Meta running on Linux desktop using android-translation-layer.

android-translation-layer (ATL) is a Wine-like approach to run Android applications on Linux. Rather than running an Android container like for example Waydroid does this instead implements the Android API. Note that right now it's very much work in progress and almost no app will work yet, but the fact that they have apps like Newpipe and WhatsApp running already is very promising!

Join the Matrix chat at #android-translation-layer:matrix.org and follow along!

in reply to The Ramen Dutchman

Think of the phrase: about music. “90’s music” would imply music from specifically 90 (probably 1990 where we assume the writer was lazy about the initial apostrophe)—possessive form. “’90s music” uses ’90s as an adjective for the entire decade—and with the preceeding apostrophe makes it clearer 19 is omitted. 1 year versus 10 years as a big difference. Using an apostrophe in the right place clearly removes the ambiguity.

It was an error. It happens, and too many people do it so next time maybe you won’t with a good habit being formed.