Brief items
Security
Security quotes of the week
As mobile phone masts went up across the world's jungles, savannas and
mountains, so did poaching. Wildlife crime syndicates can not only
coordinate better but can mine growing public data sets, often of geotagged
images. Privacy matters for tigers, for snow leopards, for elephants
and
rhinos – and even for tortoises and sharks. Animal data protection laws,
where they exist at all, are oblivious to these new threats, and no-one
seems to have started to think seriously about information security.
— Ross Anderson
So we have been doing some work on this, and presented some initial ideas via an invited talk at Usenix Security in August. A video of the talk is now online.
If you're an American of European descent, there's a 60% chance you can be
uniquely identified by public information in DNA databases. This is not
information that you have made public; this is information your relatives
have made public.
— Bruce
Schneier
Kernel development
Kernel release status
The current development kernel is 4.19-rc8, released on October 15. Greg said: "Please go and test and ensure that all works well for you. Hopefully this should be the last -rc release."
Stable updates: 4.18.14, 4.14.76, 4.9.133, 4.4.161, and 3.18.124 were all released on October 13.
The 4.18.15, 4.14.77, and 4.9.134 updates are in the review process; they are due on October 18.
Distributions
Distribution quote of the week
But to know why you
don't get a timely response, you need to intimately understand Gentoo's
inner dynamics, which you can't. So, you think we rudely ignore you.
But we don't, you're just lost in a Kafkaesque maze!
— Virgil
Dupras
Development
Tutanota, the First Encrypted Email Service with an App on F-Droid (Linux Journal)
Here's a Linux Journal article from one of the creators of the Tutanota encrypted email client. "That's why we decided to build Tutanota: a secure email service that is so easy to use, everyone can send confidential email, not only the tech-savvy. The entire encryption process runs locally on users' devices, and it's fully automated. The automatic encryption also enabled us to build fully encrypted email apps for Android and iOS. Finally, end-to-end encrypted email is starting to become the standard: 58% of all email sent from Tutanota already are end-to-end encrypted, and the percentage is constantly rising."
Bro becomes Zeek
The Bro network security monitoring project has announced a name change to "Zeek". "On the Leadership Team of the Bro Project, we heard clear concerns from the Bro community that the name 'Bro' has taken on strongly negative connotations, such as 'Bro culture'. These send a sharp, anti-inclusive - and wholly unintended and undesirable - message to those who might use Bro. The problems were significant enough that during BroCon community sessions, several people have mentioned substantial difficulties in getting their upper management to even consider using open-source software with such a seemingly ill-chosen, off-putting name."
Development quotes of the week
Using old documentation can be like hiking an overgrown trail. The prospects of rogue branches, poison ivy, and getting lost suggest you are unlikely to emerge unscathed.
— Janet Davies
Keyboard crusaders that would otherwise pounce on anyone daring to suggest that some language is better than any other will concede that Lisp is on another level. Lisp transcends the utilitarian criteria used to judge other languages, because the median programmer has never used Lisp to build anything practical and probably never will, yet the reverence for Lisp runs so deep that Lisp is often ascribed mystical properties.
— Sinclair
Target
The GNU Affero General Public License (AGPL) has done a wonderful job
defending the software freedom of community-developed projects like Mastodon
and Mediagoblin. So,
we should answer with skepticism a solitary for-profit company coming forward to claim that "Affero GPL has not resulted in sufficient legal incentives for some of the largest users of infrastructure software … to participate in the community. Many open source developers are struggling with a similar reality". If the last sentence were on Wikipedia, I'd edit it to add a Citation Needed tag, as I know of no multi-copyright-held or charity-based AGPL'd project that has "struggled with this reality". In fact, it's only a "reality" for those that engage in proprietary relicensing. Eliot Horowitz, co-founder of MongoDB and promulgator of their new license, neglects to mention that.
— Bradley M. Kuhn
Miscellaneous
SFLC: Automotive Software Governance and Copyleft
The Software Freedom Law Center has announced the availability of a whitepaper [PDF] about automotive software and copyleft, written by Mark Shuttleworth and Eben Moglen. At its core, it's an advertisement for Ubuntu and Snap, but it does look at some of the issues involved.
The fine grain of interface access rights provided by the snapd
governance agent can thus provide further isolation and security when it
is running user-modified code, guaranteed under the snap packaging
paradigm to cause no other program code to be modified, to break, or to
perform differently because of the presence of the user-modified
program. Such a structure of modification permission can be operated by the
OEM consistent with the requirements of GPLv3. The OEM can publish an
authenticated record of the installation permission issued, indexed by the
Vehicle Identification Number—without publishing the car owner’s
personal information—so that public and private parties can be assured that
no surreptitious modification of vehicle software occurs.
Page editor: Jake Edge
Next page:
Announcements>>