The xz package has been backdoored, you need to update your system now
shirro @ shirro @aussie.zone Posts 1Comments 290Joined 2 yr. ago
I was setting up a modded minecraft launcher for the family to use and and I have trust issues with the modding ecosystem and kids installing random jar files. I used bwrap and it works really well. The launcher uses wayland, minecraft typically X, needs dri access for opengl, pipewire, input devices, networking and dns resolve to connect to servers etc. Doesn't need filesystem access to much other than some shared libs (ro) and a directory in .config. There is a bit of trial and error involved and making the bwrap robust to differences between desktops (different sockets for dns or mdns resolvers) and makes me appreciate apps packaged as flatpak as this level of sandboxing should be standardised for all distributed apps. Half the stuff in AUR should be bwrapped IMO.
Civilized countries don't execute criminals and somehow don't experience more criminality or unacceptably high incarceration costs as a result. Capital punishment is an outdated cultural practice like slavery, genital mutilation or child brides and has nothing to do with the administration of justice. It is cultural and nothing else. They like the killing. They believe in the killing. It has no other purpose.
I don't know why much of the discussion is about the method of execution. Would it matter how they were fucking kids or beating slaves in Alabama or that they were doing those things at all? State executions are barbaric and indefensible in any form.
Growth of a few million subscribers is nothing for a company the size of Netflix and there could be all sorts of creative accounting going on.
Executives patting themselves in the back to justify bonuses is self serving bullshit. Quality and value build long term brand profitability but that is too hard for MBAs. Cost cutting and screwing customers is all they know. In a few years people will be asking what the fuck happened to Netflix.
I was a relatively early adopter of Netflix before it was available in my country and used it via VPN back when Netflix had more to gain by allowing that. They made some interesting shows that justified the very affordable price. Now there is more content and most is crap. I rotated subscriptions for the last year but I am hard out now. And ad supported tiers don't fix it for me because I would rather eat shit than watch them.
There are a small number of terminal emulators I would be happy to use as daily drivers and most of them have been named here but my default is kitty. It supports everything I need and a lot I don't and doesn't have any showstoppers. All the modern terminal implementations are performant enough. I used real terminals like vt-100s and vt-220s. Everything we have today is awesome by comparison. We fetishize performance and features too much. Once you have something that works there isn't much reason to change IMO.
I made an effort to only use Firefox because browser diversity is important for the web. It can be rough sometimes when things like.chromecast only work.via unstable extensions but I persist even on mobile.
I suspect the Mozilla corporate structure and leadership needs to be reviewed. They don't seem to know where they are going and get sidetracked.
Things like lack of good cross platform support for passkeys (fido2/ctap stuff) is going to hurt them even more as people won't be able to use Firefox to login to many sites on Linux where there is currently no blessed platform libraries for this. Unfortunately stuff like that is going to drag me back to Chrome for some stuff which handles this fine on Linux.
Framework ship laptops to Australia and has a headphone socket. Great company. Great products. Great experience, highly recommend. I can't recommend products that don't sell and support in my market. I don't have any loyalty to Fairphones or Steamdecks or any other product from low effort companies that don't ship beyond NA or Europe.
I like repairable hardware and own a Framework laptop. It has a headphone socket that I use every day. If Framework made a phone I might be interested. If most fairphones end up paired to disposable wireless earbuds with limited battery life that end in landfill I don't get how that is more sustainable than adding a socket for the declining but still sizeable number of people who cling to wired stuff that just works.
My rugged mid-range Nokia refuses to take damage. The thing is cursed. I have dropped it so many times it is ridiculous. It might be years before I replace it. Has a jack as well. Made me totally re-evaluate what I value in a phone. I realized I am not a feature/performance fetishist. I want solidly made gear that has regular updates.
Every day. Aux in on my car, wired headphones, aux in on old stereo. I could replace it all with bluetooth but it isn't broken and I can still use bluetooth on other devices. I like choice and I hate waste and conspicuous consumption. Rechargeable wireless devices with limited battery life that can't be serviced or repaired is peak consumption/pollution bullshit. The headphone jack may wear out before my phone's usb, battery or something else but that hasn't been my experience historically.
IMO the only truly difficult part of self hosting is mail delivery because you end up at the mercy of big stupid companies (eg Microsoft) that don't give a shit. It is possible and possibly advisable to use a paid service for delivery and let someone else deal with the bastards.
With a bit of research and a methodical approach I think just about anybody comfortable setting up other linux network services should be fine. I am very lazy and have been doing it for 2 decades. I like being in control of my own mail store. I choose to do my own delivery and the only persistently difficult provider is Microsoft's free email offerings which I care about about as much as they care about running a reliable mail system for their users. They seem to penalize infrequent low volume senders. I have always been signed up to their spam monitoring bullshit and have never had a negative report but they don't seem to communicate there so you can be blocked and nobody knows how or why. They blocked most of my hosting provider once so I routed my outgoing email with correct dkim, spf etc from a server hosted elsewhere. Easy to do with Postfix.
Long time family premium user (household of parents and kids). Anything Youtube do to preserve their revenue within reason doesn't bother me too much as long as they don't reduce the split with quality creators. If they were successful with all this bullshit perhaps they wouldn't have needed to notify me that subs are almost doubling next year. My guess is all they are doing is fucking things up for everyone. It is only going to get worse if their premium subscription base reduces. They should be pricing premium as an alternative to ad-blockers but instead they are pushing people including premium subscribers towards ad-blockers.
I already have ad-blockers and apps for circumventing youtube ads. Not using them in favour of a fairly priced (to me) subscription was a choice but sadly one Google seems to be discouraging.
There isn't much to differentiate ISPs anymore. It used to be a huge benefit to have unmetered, low latency game servers, streaming radio mirrors, usenet feeds, IP phone services and ISP email. Internet offered a huge amount of extra value through the dialup, ISDN, ADSL1, ADSL2 era. They offered IPv6 early which was interesting to a techie early adopter and were rolling out ADSL2+ in some exchanges and wireless systems. I stuck with Internode for a long time because if your system just works there isn't a lot of incentive to chase other providers who are more or less the same. In the NBN era they were a bit slow to deal with congestion a couple of times and I ended up moving to Superloop. I don't know that Superloop are anything special but that is kind of the point these days. The industry is commoditised and as long as their network and billing is competently run all the NBN resellers should be fairly comparable.
Not just the degoogled open source Android disros either. Amazon has a commercial fork of Android with its own app store. There was Oppo's AOSP derived ColorOS which was not based on Google's stock Android. I don't think Google should control the core apps as tightly as they do on stock Android but on the other hand those apps sort of define stock android and the default user experience in the marketplace. Epic could roll their own fork if they wanted and substitute apps.
On the subject of Oppo, I think Tencent went after them and other Chinese manufacturers as well to get into their platforms. Tencent are the guys who push their own app store and one app to rule them that Musk has wet dreams about. I sometimes wonder if they are using Epic to wedge open US based app stores for a future WeChat/MyApp like approach. Not that the US government would allow that.
Valve created their own console and helped fund Wine development, presumably as a strategic move to counter Microsoft's platform control. I might be missing something but I don't see similar effort or innovation from Epic.
I believe Microsoft and Nvidia did deals with hardware manufacturers for years that helped exclude competition and those sorts of deals probably pose more difficulty in court. Google might have fallen into a trap and done something similar. Being vertically integrated Apple doesn't have to do deals with other manufacturers but presumably they have some deals with developers. Obviously Sony, Nintendo have exclusives, agreements with developers and tight control of their platforms as well that go far beyond anything I can see with Google so I do find it a bit confusing.
Probably comes down to the unwillingness of US legislators to create clear laws. Too many compromises to satisfy lobbyists and avoid any negative campaign they might sponsor. Judges likely do the best they can trying to interpret the mess of case law they depend on in the absence of modern legislation. I have no idea why the US supreme court gets to decide on matters like abortion based on hand wavy interpretations of historical documents when in any normal democracy the politicians do the will of the people and enact legislation that reflects modern society.
My interpretation of the article is that it wasn't Google's app store but the deals Google did with other manufacturers and big studios that caused them problems. Unlike iOS Android has both open source and commercial forks. Amazon have their own app store for their own range of devices and you can load that app store on regular Android I believe if you want to access a shittier range of apps. There are degoogled versions of Android and many people including myself run f-droid or side load apks. It is much more open than Apple's system which won.
Coalition tells Cop28 it will back tripling of nuclear energy if Peter Dutton becomes prime minister
I am moderately pro nuclear but the coalition is not. They are on the payroll of the fossil fuel industry (as are some in the ALP) and their fake fascination with nuclear is entirely a delaying tactic to prolong the value of fossil fuel investments. Renewables have been getting all the investment and R&D and that is reflected in the declining costs and ease of deployment. Nuclear has stagnated and the economics and time to market suck. The fossil fuel lobby is not threatened by nuclear which won't take business away from them in Australia. Send uranium to France where they have a mature nuclear industry and restart reactors shut down by fools in places like Germany. Meanwhile lets ramp up our deployment of renewables and shut down more carbon emitters.
Whatever your political leanings, unless you are a billionaire with huge fossil fuel investments they aren't looking out for us, our families or our country. They represent people like the Saudi royals and Adani not us. They care about local coal jobs about as much as Thatcher did and our kid's futures even less.
All reddit did was unmask themselves a little but only for those with their eyes open. Social media is close enough to a cult operation utilizing addictive behaviors and conditioning to control people. People are scared to leave their church and be shunned. Reddit is just another exploitative techbro run business. It isn't a social enterprise or open source community and it is weird that volunteers invested so much of their time and effort propping up shareholder value instead of contributing to real communities.
Plenty of independent thinkers left and found federated alternatives or walked away. The predatory and manipulative nature of social media was bad enough when it was all about controlling and manipulating the masses but now it is also a huge machine learning harvesting operation. The only people who really benefit are the ultra rich.
All our PCs run linux which is the most unloved, unsupported platform for commercial software and media distribution companies. Can't watch most streaming video better than 720p so the streaming services can get fucked raising their prices and delivering a shit service. Gabe gave us Steam and Steam sales and made shit just work and he can take my money. There are overpriced games on Steam and there are games that are not available there but that still leaves a lot of good stuff so I can understand why more people are willing to pay than pirate reducing torrent availability and seeders. Also PC hardware can be very expensive and if you can afford a high end GPU you can probably afford to support game development.
It is a compression library that is in the dependency tree for a large number of other packages though not as many as zlib which is in practically everything.
xz development appears to have been compromised by some organisation in a long game targeting sshd in Debian and derivatives. Debian maintainers have a nasty habit of adding lots of patches to upstream sources which occasionally have unintended consequences. I am a long term Debian user but I wish they would stop doing this. Thankfully arch generally doesn't modify upstream as much as Debian and arch sshd doesn't link in the backdoored library.