Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Moon

Private Russian Company Proposes Lunar Base 81

MarkWhittington writes According to an article in Sputnik, a private Russian company called Lin Industrial has announced that it is capable of building a lunar base. However, according to information contained to a recent post in Parabolic Arc, this announcement may be more the result of idle boasting than an objective assessment of actual ability. Nevertheless, Lin seems to be one of the few entrepreneurial startups in Russia in the style of much more robust enterprises in the West such as SpaceX and Blue Origin.
Open Source

Docker Image Insecurity 73

An anonymous reader writes Developer Jonathan Rudenberg has discovered and pointed out a glaring security hole in Docker's system. He says, "Recently while downloading an 'official' container image with Docker I saw this line: ubuntu:14.04: The image you are pulling has been verified

I assumed this referenced Docker's heavily promoted image signing system and didn't investigate further at the time. Later, while researching the cryptographic digest system that Docker tries to secure images with, I had the opportunity to explore further. What I found was a total systemic failure of all logic related to image security.

Docker's report that a downloaded image is 'verified' is based solely on the presence of a signed manifest, and Docker never verifies the image checksum from the manifest. An attacker could provide any image alongside a signed manifest. This opens the door to a number of serious vulnerabilities."
Docker's lead security engineer has responded here.
Science

Does Journal Peer Review Miss Best and Brightest? 139

sciencehabit writes: A study published today indicates that the scientific peer review system does a reasonable job of predicting the eventual interest in most papers, but it may fail when it comes to identifying really game-changing research. Papers that were accepted outright by one of the three elite journals tended to garner more citations than papers that were rejected and then published elsewhere (abstract). And papers that were rejected went on to receive fewer citations than papers that were approved by an editor. But there is a serious chink in the armor: All 14 of the most highly cited papers in the study were rejected by the three elite journals, and 12 of those were bounced before they could reach peer review. The finding suggests that unconventional research that falls outside the established lines of thought may be more prone to rejection from top journals.

Slashdot Top Deals

HELP!!!! I'm being held prisoner in /usr/games/lib!

Working...