Mechanicon 2024 is going great! So many creative and curious people sharing their ideas and finding out what else there is to see. @stdevel told me “You think you have seen it all, but then you see something at Mechanicon and you realize, that there is no limit.”
Novità in ONLYOFFICE Desktop Editors v8.1: Editor PDF completo e Slide Master https://www.marcosbox.com/2024/06/22/novita-in-onlyoffice-desktop-editors-v8-1-editor-pdf-completo-e-slide-master/ #onlyoffice #windows #macos #linux #unolinux
systemd 256.1: Now slightly less likely to delete `/home`
https://www.theregister.com/2024/06/20/systemd_2561_data_wipe_fix/
Fixes catastrophic d̵a̵t̵a̵ ̵l̵o̵s̵s̵, er, b̶u̶g̶, er, p̶o̶o̶r̶l̶y̶ ̶d̶o̶c̶u̶m̶e̶n̶t̶e̶d̶ ̶f̶e̶a̶t̶u̶r̶e̶ ... user error
← by me on @theregister
We spoke to Son Ngyuen, the founder of SimpleLogin.
Phoenix UEFI flaw puts long list of Intel chips in hot seat https://go.theregister.com/feed/www.theregister.com/2024/06/21/uefi_vulnerability_intel_chips/ #news
KDE Plasma 6.1 deliver a bunch of ace features, including Remote Desktop integration, session resume, and slick new edit mode - https://www.omgubuntu.co.uk/2024/06/kde-plasma-6-1-new-features #kde #opensource #linux
TikTok is looking more and more like Yelp https://www.theverge.com/2024/6/21/24183085/tiktok-location-page-categories-travel-recommendations #news
New Post: MySudo - KYC for UK numbers
--
Join the discussion below 👋 https://discuss.techlore.tech/t/mysudo-kyc-for-uk-numbers/8963
“A Short IPv6 Guide for Home IPv4 Admins” - taught me a bunch of useful things I didn't know that I didn't know about IPv6 in practice. Good stuff! https://gist.github.com/timothyham/dd003dbad5614b425a8325ec820fd785
Driving forward in Android drivers
An article by @jenkins about exploiting a race condition in the MediaTek mtk_jpeg driver that leads to a variety of memory corruption side-effects.
The described data-only exploit leverages the bug to get a use-after-free on a dmabuf file structure and then gets an arbitrary read/write primitive to disable SELinux and gain root on Asus ROG 6D.
In the exploit, Seth deliberately avoided using the cross-cache techniques, as these might soon get mitigated by SLAB_VIRTUAL.
The article also covers:
— Approaches to discovering device drivers accessible to unprivileged users on Android;
— Using the MediaTek GED (GPU Extension Device) driver to gain extremely powerful slab memory control primitives.
https://googleprojectzero.blogspot.com/2024/06/driving-forward-in-android-drivers.html
Shoddy infosec costs PwC spinoff and NMA $11.3M in settlement with Uncle Sam https://go.theregister.com/feed/www.theregister.com/2024/06/17/guidehouse_nma_fined/ #news
AI Is Being Trained on Images of Real Kids Without Consent
https://futurism.com/ai-trained-images-kids?utm_source=flipboard&utm_medium=activitypub
Posted into Artificial intelligence and misinformation @artificial-intelligence-and-misinformation-NewsLitProject
Hey #AskFedi,
I'm looking for a #FOSS program that merges duplicate contacts in vcf or csv format.
I found vcf_contacts_merger, but it has weird python requirements that I just couldn't manage to satisfy.
Ideally either a downloadable linux app or a FOSS #Android app (or at least a non-foss Android app that I can run with networking privileges revoked).
It can't be a google app or rely on uploading my contacts to "the cloud."
PostmarketOS v24.06 released
Dive into our list of the best open-source email servers: