Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×

Comment Just sign the installer (Score 1) 180

Not sure how feasible this is in Java, but if your distributable is just a tiny installer with its own cryptographic verification, you would a) have a smaller chance of hitting a false positive and b) if you do get hit, at least your customers can still launch and use the program, even if they can temporarily not do new installations.

Comment Re:Package management is *not* a feature (Score 2) 230

Even worse, Go programs cannot be linked dynamically. That means that if a vulnerability is found in (say) a crypto library, all programs using it need to be recompiled.

And because the Go package manager (like most language specific package managers) is developer-centric, you have to rely on the developer to keep an eye out for CVE announcements for all the libraries they use. The number of developers that actually do this consistently is very small.

The Almighty Buck

Science Journals Are Laughing All the Way To the Bank, Locking the Results of Publicly Funded Research Behind Exorbitant Paywalls. This Must Be Stopped. (newscientist.com) 140

Here is a trivia question for you: what is the most profitable business in the world? You might think oil, or maybe banking. You would be wrong. The answer is academic publishing. Its profit margins are vast, reportedly in the region of 40 per cent. New Scientist: The reason it is so lucrative is because most of the costs of its content is picked up by taxpayers. Publicly funded researchers do the work, write it up and judge its merits. And yet the resulting intellectual property ends up in the hands of the publishers. To rub salt into the wound they then sell it via exorbitant subscriptions and paywalls, often paid for by taxpayers too.

The academic publishing business model is indefensible. Practically everybody -- even the companies that profit from it -- acknowledges that it has to change. And yet the status quo has proven extremely resilient. The latest attempt to break the mould is called Plan S, created by umbrella group cOAlition S. It demands that all publicly funded research be made freely available. When Plan S was unveiled in September, its backers expected support to snowball. But only a minority of Europe's 43 research funding bodies have signed up, and hoped-for participation from the US has failed to materialise. Meanwhile, a grass-roots campaign against it is gathering momentum. Plan S deserves a chance.

Businesses

Verizon's New Phone Plan Proves It Has No Idea What 'Unlimited' Actually Means (gizmodo.com) 171

Verizon has unveiled its third "unlimited" smartphone plan that goes to show just how meaningless the term has become in the U.S. wireless industry. "In addition to its Go Unlimited and Beyond Unlimited plans, Verizon is now adding a premium Above Unlimited plan to the mix, which offers 75GB of 'unlimited' data per month (as opposed to the 22GB of 'unlimited' data you get on less expensive plans), along with 20GB of 'unlimited' data when using your phone as a hotspot, 500GB of Verizon cloud storage, and five monthly international Travel Passes, which are daily vouchers that let you use your phone's wireless service abroad the same as if you were in the U.S.," reports Gizmodo. Are you confused yet? From the report: And as if that wasn't bad enough, Verizon has also updated its convoluted sliding pricing scheme that adjusts based on how many phones are on a single bill. For families with four lines of service, the Above Unlimited cost $60 per person, but if you're a single user the same service costs $95, which really seems like bullshit because if everything is supposed to be unlimited, it shouldn't really make a difference how many people are on the same bill. As a small concession to flexibility, Verizon says families with multiple lines can now mix and match plans instead of having to choose a single plan for every line, which should allow families to choose the right service for an individual person's needs and help keep costs down. The new Above Unlimited plan and the company's mix-and-match feature arrives next week on June 18th.
Earth

More Than 75 Percent of Earth's Land Areas Are 'Broken,' Major Report Finds (vice.com) 145

Like a broken cell phone that can only text or take pictures, but not make a single call, more than 75 percent of the Earth's land areas have lost some or most of their functions, undermining the well-being of the 3.2 billion people that rely on them to produce food crops, provide clean water, control flooding and more. From a report: These once-productive lands have either become deserts, are polluted, or have been deforested and converted for unsustainable agricultural production. This is a major contributor to increased conflict and mass human migration, and left unchecked, could force as many as 700 million to migrate by 2050, according to the world's first comprehensive evidence-based assessment of land degradation, released today in MedellÃn, Colombia.

Land degradation -- including deforestation, soil erosion, and salinity and pollution of fresh water systems -- is also driving species to extinction and aggravating the effects of climate change, the report concludes. It was written by more than 100 leading experts from 45 countries for the Intergovernmental Science-Policy Platform on Biodiversity and Ecosystem Services (IPBES). IPBES is the 'IPCC for biodiversity,' a scientific assessment of the status of non-human life that makes up the Earth's life support system.

Businesses

How UPS Delivers Faster Using $8 Headphones and Code That Decides When Dirty Trucks Get Cleaned (technologyreview.com) 109

With Amazon's imminent plans to launch a low-cost package delivery service, UPS is about to face intense competition from a company with top customer-tracking capabilities and even artificial-intelligence expertise. To tackle it, the company is turning to advances analytics. From a report: In 2016, it began collecting data across its facilities. Today there are about 25 projects based on that data, grouped under the acronym EDGE (which stands for "enhanced dynamic global execution"). The program has sparked changes in everything from how workers place packages inside delivery trucks in the morning to how the vast army of temporary hires that UPS recruits during the busy holiday season are trained. Eventually, data will even dictate when UPS vehicles get washed. The company expects to save $200 million to $300 million a year once the program is fully deployed.

[...] Another project tells seasonal workers where to direct the outbound packages that UPS vehicles pick up throughout the day and bring to the company's sorting facilities. UPS hires nearly 100,000 of these workers from November through January. Typically, these people would need to memorize hundreds of zip codes to know where to place parcels, but last winter UPS outfitted about 2,500 of them with scanning devices and $8 Bluetooth headphones that issue one-word directions, such as "Green," "Red," or "Blue." The colors correspond to specific conveyor belts, which then transport the packages to other parts of the building for further processing.

Security

Meltdown and Spectre Patches Bricking Ubuntu 16.04 Computers (bleepingcomputer.com) 233

An anonymous reader writes: Ubuntu Xenial 16.04 users who updated to receive the Meltdown and Spectre patches are reporting they are unable to boot their systems and have been forced to roll back to an earlier Linux kernel image. The issues were reported by a large number of users on the Ubuntu forums and Ubuntu's Launchpad bug tracker. Only Ubuntu users running the Xenial 16.04 series appear to be affected.

All users who reported issues said they were unable to boot after upgrading to Ubuntu 16.04 with kernel image 4.4.0-108. Canonical, the company behind Ubuntu OS, deployed Linux kernel image 4.4.0-108 as part of a security update for Ubuntu Xenial 16.04 users, yesterday, on January 9. According to Ubuntu Security Notice USN-3522-1 and an Ubuntu Wiki page, this was the update that delivered the Meltdown and Spectre patches.

Twitter

The Public Is Growing Tired of Trump's Tweets, Says Voter Survey (arstechnica.com) 489

President Donald Trump is the tweeting president. His @realDonaldTrump handle has 31.8 million followers and "35K" tweets. While the president claims to use Twitter to "get the honest and unfiltered message out," many Americans aren't so fond of his favored form of communication. According to a new voter poll (PDF), the public is growing tired of Trump's tweets. Ars Technica reports: A Morning Consult, Politico survey published Wednesday found that 69 percent of voters who took the online survey said they thought Trump tweets too much. That's up from 56 percent from December, months before Trump took office. The survey said that 82 percent of Democrats polled thought Trump tweets too much, up from 75 percent in December. Republicans came in at 53 percent saying the president used Twitter too often, an 11-percent increase from December. Overall, 57 percent of voters who took the survey said Trump's tweets are hurting his presidency. Another 53 percent said his Twitter use undermines U.S. standing in the world. The poll found that 51 percent of all voters said Trump's tweets imperiled national security. What do you think of Trump's tweets? Do you think they are getting old, or do you find them particularly useful?

Comment Re:Finally (Score 1) 372

That's odd, one of the reasons I like systemd is that it *doesn't* eat process output. With sysvinit, non-syslog output would end up on /dev/console, scroll up and be lost forever (especially relevant for headless servers). With systemd's journalctl I can easily review the output of any process together with its syslog logs. There's plenty of things about systemd that annoy me but that ain't one.

Slashdot Top Deals

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...