 2015-03-02 DSA-3178 unace - security update

Jakub Wilk discovered that unace, an utility to extract, test and view .ace archives, contained an integer overflow leading to a buffer overflow. If a user or automated system were tricked into processing a specially crafted ace archive, an attacker could cause a denial of service (application crash) or, possibly, execute arbitrary code.

 2015-02-26 DSA-3176 request-tracker4 - security update

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

 2015-02-25 DSA-3175 kfreebsd-9 - security update

Mateusz Kocielski and Marek Kroemeke discovered that an integer overflow in IGMP processing may result in denial of service through malformed IGMP packets.

 2015-03-03T11:35:08Z SSDOptimization
 2015-03-03T09:22:20Z fr/Network
update links
 Modem
 Mon, 02 Mar 2015 23:00:00 -0800 How to make your bash prompts more useful and interesting

 ITworld: Had enough of $ and #? You can make your bash prompts far more interesting and likely a lot more useful by customizing them.

 Mon, 02 Mar 2015 19:00:00 -0800 Ubuntu MATE Donates Money to a Project That Helped Them with Features

 softpedia: There was quite a furious debate in the Linux community about what the elementary OS devs said about financial contributions from the community.

 Mon, 02 Mar 2015 15:00:00 -0800 Firefox OS heading for Africa -- and the U.S. too

 LinuxGizmos: Orange announced a $40 "Klif" Firefox OS phone for Africa, and Mozilla says it???s working with Verizon Wireless and others on Firefox OS feature phones.

 Mon, 02 Mar 2015 23:11:57 GMT Google confirms plans to launch its own mobile service
Google's Sundar Pichai has essentially confirmed reports that the company will become a wireless provider of sorts in "the coming months." During his appearance at Mobile World Congress today, Pichai acknowledged that Google is working with "existing partners" to create its own MVNO, but stopped short of confirming that Sprint and T-Mobile are those partnering networks, as has been rumored. But he did reveal that Google has been in contact with Verizon Wireless and AT&T about its plans - likely to head off any potential ugly conflict between Mountain View and the largest, most powerful providers in the United States. "Carriers in the US are what powers most of our Android phones, and that model works really well for us," he said. Additionally, The Verge has an interesting article about just how far along Google's Project Loon is.
 Mon, 02 Mar 2015 23:03:26 GMT Ubuntu MATE becomes official member of Ubuntu
As of the release of Ubuntu 15.04 Vivid Vervet Beta 1, Ubuntu MATE is now officially a Canonical project, alongside the likes of Kubuntu, Xubuntu, and friends. MATE is the continuation of GNOME 2.
 Mon, 02 Mar 2015 22:59:42 GMT Jolla shows Sailfish OS 2.0
Jolla has "introduced" Sailfish OS 2.0. It didn't really introduce it though as it's not available to anyone right now - it's only potentially available to OEMs. The independent Sailfish OS is soon reaching a major milestone as it is scaling from smartphones to tablets with the introduction of the Jolla Tablet. The first shipments of Jolla’s second Sailfish OS product are expected to start in Q2/2015. At this point, Sailfish OS is maturing to the next generation, 'Sailfish OS 2.0', and is introducing e.g. a new enhanced user interface, support for Intel architecture, and previously unseen software integration capabilities for partners. The new interface is interesting - it greatly simplifies all the gestures and seems to function much more like Harmattan on the N9. As awesome as all this sounds, this still doesn't address the biggest concern: applications. Some may be content running Android applications (poorly) on Sailfish, but I want the real deal. However, without - still - any word on paid applications, it doesn't seem like this issue will be addressed any time soon. That being said - I'm an early backer for the tablet, and can't wait for it to arrive this May. I hope Sailfish OS 2.0 will find its way to my Jolla phone at around the same time.
 Mon, 02 Mar 2015 17:21:54 GMT New Lollipop devices not encrypted by default
Big news a few months ago: Google announced that all new devices which ship with Lollipop would have encryption enabled by default. Fast forward to today, and aside from Google's own Nexus devices, none of the new Lollipop devices actually seem to have encryption enabled by default. It turns out that Google has quietly relaxed this requirement in the Android Compatibility Definition, from 'MUST' to 'very strongly RECOMMENDED'. Why? Performance, supposedly. Our best guess at this point is that the encrypted-by-default requirement was relaxed to give OEMs more time to prepare their hardware for the transition. The performance problems can be offset by using faster flash memory, faster file systems like F2FS, and chips that are better at encrypting and decrypting data quickly, but phones and tablets take long enough to design that OEMs will need time to make these changes. Whether the change in policy was prompted by external pressure or an internal decision isn't clear, but the performance explanation makes the most logical sense. Ouch. It's pretty clear Google wanted to quickly gain some positive press, especially after Apple announced it would turn encryption on by default in iOS, but failed to look at any possible performance repercussions. Sleazy move.
 Mon, 02 Mar 2015 09:14:58 GMT Chip makers will merge in deal worth $11.8 billion
NXP Semiconductors said on Sunday that it would buy a smaller peer, Freescale Semiconductor, in an $11.8 billion deal that would create a big maker of chips for industries as varied as automobiles and mobile payments. The merger will also offer some relief to the private equity firms that bought Freescale at the height of the leveraged buyout boom, only to see the financial crisis bring the company low. NXP is Dutch, and I have to admit, seeing a Dutch chip maker acquire Freescale makes me feel a little bit proud. Together with ASML, my little swamp does contribute at least something to the world of computing.
 Sun, 01 Mar 2015 19:10:15 GMT Samsung unveils Galasy S6, S6 Edge
Samsung, naturally, is hoping to put the Galaxy S series back on people's radar as a top device, and it's doing so by starting afresh with the Galaxy S6 and S6 edge. Though it numerically follows the GS5, the Galaxy S6 bears little resemblance to the previous model, and marks a pretty significant change in the way Samsung designs phones. At the same time, the S6 edge picks up the fun parts of the Galaxy Note Edge and leaves behind the poor software experience. There's a brand new design philosophy in play with the Galaxy S6 and S6 edge, starting with the radical hardware change and flowing into a more considered software experience. These are the phones that Samsung's hoping will change the perception of its devices in 2015 - let us show you what they're all about. After HTC, Samsung was up. Most of the information regarding the new Galasy S6 and Galasy S6 Edge were leaked before their official unveiling, so we already knew what to expect. I'm particularly pleased with Samsung greatly simplifying TouchWiz, and the simplified camera interface and performance are very welcome too. The all-metal construction is nice, and I personally really like the Edge's curved display - not because of any software functionality, but because it just looks really nice and ergonomic. During the unveiling event, one thing really stood out: confidence. Rarely have I seen Samsung personnel being this genuinely enthousiastic and confident about their new phones. They didn't resort to crazy antics or heavy buzzword dropping - they showed the device, its strengths, and that was it. For the first time, it felt as if Samsung truly believes the S6 and S6 Edge can stand on their own merit, instead of being held up by marketing and similar tricks. My contract renewal is up later this year, and the S6 looks quite intriguing, and I haven't found any Samsung phone even remotely intriguing since the SII.
 Sun, 01 Mar 2015 18:28:15 GMT HTC unveils One M9
It's hard not to have high hopes for the HTC One M9. Its immediate predecessor and the first phone in this rebirth of the HTC's flagship line - that'd be 2014's HTC One M8 and 2013's M7 - were fan favorites, and highly regarded by those of us who critique phones for a living. But those phones were not without their flaws. And as we've seen HTC slowly address its devices' shortcomings (while growing and innovating in other areas), it's been difficult to not expect it to finally get things - all the things - right. At least that's what we've been hoping, especially when it comes to its one tragic feature: The inconsistent performance of its UltraPixel camera. And that brings us to this. The HTC One M9. We've spent a little time with HTC's latest, and this is what we've found thus far. The HTC One M9 - the new one, announced today - looks very similar to the M8, but of course with better specifications and updated software. As much as I think the One series might be the best Android phones out there in terms of build quality, I just can't get myself to like its overall design. I do hope, though, that the M9 sells in large enough numbers, because HTC is going to need it.
 Sun, 01 Mar 2015 18:23:17 GMT Xfce 4.12 released
Today, after 2 years and 10 months of work, we are pleased to announce the release of the Xfce desktop 4.12, a new stable version that supersedes Xfce 4.10. This long period can only be explained by how awesome Xfce 4.10 was. But as all things, it needed some refreshing - and for that we saw lots of new contributors providing valuable feedback, features and bugfixes. As always, Xfce follows its steady pace of evolution without revolution that seems to match our users' needs. In this 4.12 cycle, we mainly focused on polishing our user experience on the desktop and window manager, and on updating some components to take advantage of newly available technologies.
 Sat, 28 Feb 2015 22:39:21 GMT This is the Huawei Watch
Huawei is about to make its presence felt at MWC with the announcement of the Huawei Watch. The watch itself was first spotted yesterday on a billboard, but we now have full promo videos for this Android Wear-powered beauty that will be made official in a few hours. Posted to the Huawei YouTube channel, two videos walk through the design process for the watch and also show how cheesy Euros are when they take vacations with their brosephs. Aside from the cheese, the videos do show one of the prettiest (this actually might be the prettiest) smartwatches we have seen to date. It features sapphire glass, a heart rate sensor, interchangeable leather or metal straps, crown, a bunch of classy watch faces, and a perfectly round watch face. This thing is just gorgeous - full stop. Of course, it still has Android Wear which needs a lot of work, but it's clear that round is the way to go. Square just looks bulky, computery, and geeky.
 Fri, 27 Feb 2015 22:23:59 GMT "Lenovo's promise for a cleaner, safer PC"
A Lenovo press release today: The events of last week reinforce the principle that customer experience, security and privacy must be our top priorities. With this in mind, we will significantly reduce preloaded applications. Our goal is clear: To become the leader in providing cleaner, safer PCs. We are starting immediately, and by the time we launch our Windows 10 products, our standard image will only include the operating system and related software, software required to make hardware work well (for example, when we include unique hardware in our devices, like a 3D camera), security software and Lenovo applications. This should eliminate what our industry calls "adware" and "bloatware." For some countries, certain applications customarily expected by users will also be included. A step in the right direction, but still way too much wiggle room. Why, for instance, do they insist on shipping third party antivirus crap when Windows has its own, faster security software built right in? And what are "Lenovo applications"?
 Fri, 27 Feb 2015 21:55:19 GMT Video demos Ubuntu Convergence on tablet, phone
Although long talked about, the Ubuntu Edge campaign exemplified the concept best with its "super phone" boast: your phone would hook up to a monitor, mouse and keyboard and become a fully functioning Ubuntu desktop PC. Phone apps would run on the desktop in an appropriate guise like responsive websites do on phones. Today, ahead of Mobile World Congress next month, Ubuntu Desktop Manager Will Cooke has posted a three-minute video that shows how Canonical's engineering team is progressing. My dream smartphone would be a phone that automatically turns into a PC the moment I get home. It knows I'm home, wirelessly and automatically hooks up to my display, mouse, and keyboard in my office, and done. Of course, it'd also automatically detect other displays and input devices in my house - say, a remote control and my TV. Ubuntu is working on it.
 Fri, 27 Feb 2015 21:50:52 GMT Genode 15.02 adds support for ARM virtualization
With version 15.02, the Genode OS project complements its existing virtualization support for the x86 architecture with virtualization on ARM by turning their base-hw kernel into a microhypervisor. Besides virtualization, the most prominent underlying theme of the current release is the project's increasing focus on test automation and optimization. Virtualization has a long history within the Genode project. After originally focusing on paravirtualized Linux kernels (L4Linux and OKLinux), the added support for the NOVA kernel and the Vancouver VMM in 2011 cleared the way towards hardware-based virtualization on the x86 architecture. In 2012, the project started exploring ARM TrustZone as another flavour of virtualization. With the Noux runtime, Genode introduced their take on OS-level virtualization. Finally, the transplantation of VirtualBox to NOVA last year marked the project's most ambitioned virtualization-related work. It enables VirtualBox to run as unprivileged user-level program on top of the NOVA microhypervisor. During 2014, the Genode developers used those accumulated experiences to conquer another ground, namely the ARM virtualization extensions. The current release extends their custom kernel (called base-hw) with support for hosting virtual machines and adds a user-level virtual machine monitor that is capable of running an unmodified Linux-based system as guest OS. At a high level, it mirrors NOVA's virtualization architecture but for ARM-based systems. The microkernel/hypervisor implements merely the VM world switch and the virtualization of memory but leaves all the complex work to untrusted user-level virtual machine monitors. In fact, the added kernel complexity on account of virtualization support is less than 1,000 lines of code. Besides the virtualization-related work, the base-hw kernel gained a further improved scheduler that takes IPC relationships into account, which is inspired by the pioneering work of NOVA. Furthermore, the project is happy to announce the principal ability to run Genode as secure-world OS on the upcoming USB Armory hardware platform. Most of the other topics of the current release are concerned with improving the performance and stability of Genode-based system scenarios. The centerpiece of these efforts is a new tool kit for automating tests on a large variety of kernels and hardware platforms. In line with this overall theme, the new version vastly improves the user experience of VirtualBox on NOVA, comes with updated rump-kernel-based file-system support, and lifts long-standing scalability limitations on PC platforms. More background information about all the improvements of version 15.02 are available in the extensive release documentation.
 Fri, 27 Feb 2015 18:03:35 GMT Leonard Nimoy, Spock of 'Star Trek', dies at 83
Leonard Nimoy, the sonorous, gaunt-faced actor who won a worshipful global following as Mr. Spock, the resolutely logical human-alien first officer of the Starship Enterprise in the television and movie juggernaut "Star Trek," died on Friday morning at his home in the Bel Air section of Los Angeles. He was 83. "Of my friend, I can only say this: of all the souls I have encountered in my travels, his was the most... Human."
 Thu, 26 Feb 2015 16:36:03 GMT Pebble, Microsoft: what could have been with Windows Phone
Fascinating inside scoop by WPCentral. According to them, there were very advanced talks between Microsoft and Pebble to come to a close partnership between the two companies. Microsoft built a fully functional Pebble application for Windows Phone with complete integration, offered to bundle Pebble devices with Windows Phone sales through Microsoft stores and carriers, and a whole lot more. All this was set to be announced at BUILD 2014. However, it did not come to pass. There is just one problem: Pebble founder and CEO Eric Migicovsky. Despite Microsoft's attempts to win over Pebble, Migicovsky is reportedly not a fan of the company nor their mobile operating system. The young entrepreneur reportedly nixed any partnership. Growing up in a world where Google and Apple have dominated the mobile scene, this perception that Microsoft is old and out of touch is seemingly more frequent these days. Particularly with those under 30 (see Snapchat's Evan Spiegel for a similar attitude). Even Microsoft CEO Satya Nadella was unable to persuade him personally. If I were to take an uneducated stab at why Pebble didn't go through with this, I think we need to look no further than Apple. Apple has its watch coming, and that alone would be incentive enough for Apple to start making the life of other smartwatch makers who want to be compatible with iOS very difficult. Now imagine if Pebble, to boot, had a close partnership with Microsoft, including preferential treatment for Windows Phone? Apple is not exactly know for not being incredibly petty. I think Pebble made the wise choice here.
 Thu, 26 Feb 2015 16:08:03 GMT Multicore and Amiga: present and future
 2015-03-02T12:43:55+00:00 Distribution Release: Porteus Kiosk 3.3.0
Tomasz Jokiel has announced the release of Porteus Kiosk 3.3.0, a lightweight Gentoo-based distribution designed for web kiosks: "I'm happy to announce Porteus Kiosk 3.3.0 which is now available for download. This is a major kiosk release which brings a number of new features, package upgrades and security....
 2015-03-02T01:23:30+00:00 DistroWatch Weekly, Issue 599
This week in DistroWatch Weekly: Reviews: First look at Sabayon 15.02News: Debian works toward reproducible builds, Linux Mint tests its upcoming Debian Edition, new YaST modules coming to openSUSE and the Linux kernel gets a version bumpTips and Tricks: Choosing good passwordsTorrent Corner: ArchBang, Greenie, KaOS, Tails,....
 2015-03-01T14:42:28+00:00 Development Release: Simplicity Linux 15.4 Alpha
David Purse has announced the availability of Simplicity Linux 15.4 beta, a lightweight Puppy-based distribution - now also available in a 64-bit flavour: "Simplicity Linux 15.4 alpha is now available for download. This release cycle marks the start of a new chapter for Simplicity: you can now get....

