Forgot your password?
typodupeerror

Submission + - LG to Ban Residential Proxies from Smart TV Apps (krebsonsecurity.com)

An anonymous reader writes: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. On July 2, [Krebs on Security] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.

Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is "well underway now." "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

Submission + - [oss-security] 432 Linux kernel CVEs

alanw writes: Previously on Slashdot: Linux Becomes a CVE Numbering Authority (Like Curl and Python). Is This a Turning Point? (kroah.com)

And now, on the OSS Security mailing list:

Hello,

As observed on social media[1], the Linux kernel published 432 CVEs between 2026-07-19T09:09 and 2026-07-20T16:27 (in addition to the >40 other CVEs already published this month alone):

https://lore.kernel.org/linux-cve-announce/

I understand the position that CVEs were always a flawed way to track or prioritize security changes, and "but it's the only thing we have" isn't a great argument in favor.

But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes.

You might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them for your environment based on the additional context you may be able to feed it with, but if it spits out a dozen today and another 25 the next, you haven't won much.

Alternatively, you might shrug and wait to see which of these will get a logo and catchy name in the next few weeks and then try to focus on those.

Another approach might be to sit back, have a nice cup of zen, and just always pull all updates and then update your entire fleet of systems on a weekly basis, which, yes, I sure would like to be able to do, but reality keeps getting in my way.

I'm not sure what to do here going forward.

-Jan

[1] https://mstdn.social/@nixCraft...

Submission + - D&D players raise millions in real-life campaign against 'corporate elite' (theguardian.com)

Alain Williams writes: Just before their election day, six Los Angeles city council candidates stood on stage at Hollywood’s Fonda Theatre. But they weren’t there for a debate or a black-tie gala. They were there to play Dungeons and Dragons.

Comedian Brennan Lee Mulligan guided the politicians through a short D&D campaign to defeat corporate villains and an evil dragon. Hundreds of enthusiastic fans in the crowd pledged additional donations up to $150 each to give the candidates what is called an “auto crit” for maximum damage to the dragon.

If this sounds like a bizarre merging of politics and play, organizers say it is not. “Most people want to be tapped and told how to help,” said Mulligan, a longtime DSA member and the dungeon master of D&D-themed hit YouTube series Critical Role and Dropout’s Dimension 20. “Then, lo and behold, there’s this new way to participate, bringing the platform I have to bear.”

The DSA-LA show raised $30,000 for the city’s primary election in June; five of the candidates onstage that night either won re-election or advanced to the general in November. The event is just one in a wider resistance movement by players of D&D and other tabletop role playing games (TTRPGs) against the current political climate – ICE raids, attacks on transgender rights and the rise of artificial intelligence. Over the past few years, groups across the country have been playing TTRPGs online and in person to raise money to develop games that express their frustration with the federal government and instruct people on how to help those most affected by its policies.

Submission + - Inside the dystopian world of Germany's free speech crackdown (telegraph.co.uk)

An anonymous reader writes: Dr Rainer Zitelmann doesn't even remember posting the meme on social media that nearly landed him in prison.

"When I opened the letter from police, I thought it was a misunderstanding," Dr Zitelmann, a German historian and author of about 30 books, told The Telegraph.

Berlin police told Dr Zitelmann he had been accused of violating a post-Second World War law that bans the display of Nazi symbols, slogans and imagery – and could now face three years in prison if found guilty.

The 69-year-old found out the offending social media post was a meme about Adolf Hitler. But it was one in which he criticised the Nazi dictator and compared his invasion of Czechoslovakia to Vladimir Putin's invasion of Ukraine.

"It was crystal clear the post was negative ... I was saying that Putin is so bad he is like Hitler," he explains from his study in Berlin, surrounded by hundreds of books about the rise of fascism, including his own doctoral thesis. "The comparison only works if you think Hitler was evil."

He lets out an ironic chuckle at the absurdity of it all: after decades of excoriating the Nazis in his books, a mere click of a mouse led to accusations of him being one.

Dr Zitelmann is one of thousands of Germans who have been threatened with fines or prison sentences for social media posts that fall foul of the country's political speech laws, which are unusually stringent for an EU member state.

Some of the cases are sinister and farcical in equal measure.

One German had his home raided for calling a minister a "Schwachkopf [dummy]" while another was fined €2,000 for calling Friedrich Merz a "lying Fritz" under a law that, critics claim, makes it effectively illegal to make fun of politicians.

The number of investigations under Section 86a, the Nazi symbols ban that Dr Zitelmann was investigated for, has more than doubled over the past decade according to official police statistics. Investigations into the "political insult" law also reached record levels in 2025.

The surge in cases is so vast that the UN has launched an investigation into free speech violations in Germany, a step typically reserved for dictatorships and banana republics.

Submission + - Capita launched civil service pension scheme site without 'basic' web security

An anonymous reader writes: Capita launched civil service pension scheme site without ‘basic’ web security

‘Capita was warned in December that the security of the web domain which manages the pensions of 1.7 million members of the Civil Service Pension Scheme (CSPS), lacked “basic controls”. ’

“News of the CSPS issues prompted us to undertake some research as cited experts and the threat intelligence is simply too damning not to try and reach out to you all collectively.”

Submission + - ESA - Asteroid 2024 YR4 will not impact the Moon

alanw writes: https://www.esa.int/Space_Safe...

Last year, an approximately 60 metre near-Earth object captured global attention. For a brief period, asteroid 2024 YR4 became the most dangerous asteroid discovered in the last 20 years. While an Earth impact was soon ruled out, the asteroid faded from view with a lingering 4% chance of striking the Moon on 22 December 2032.

Now, that risk has been eliminated. Astronomers have confirmed that 2024 YR4 will not impact the Moon using new observations made by the Near-Infrared Camera (NIRCam) on the NASA/ESA/CSA James Webb Space Telescope. Instead, it will safely pass the Moon at a distance of more than 20 000 km.

Submission + - Dave Farber has died 1

alanw writes: From the NANOG mailing list: https://seclists.org/nanog/202...

We are heartbroken to report that our colleague — our mentor, friend, and conscience — David J. Farber passed away suddenly at his home in Roppongi, Tokyo. He left us on Saturday, Feb. 7, 2026, at the too-young age of 91.

https://www.internethalloffame...

https://en.wikipedia.org/wiki/...

https://www.scientificamerican...

Farber is sometimes called the "Grandfather of the Internet" both because of his pioneering work in distributed computing and his mentoring of graduate students who helped build the Internet. He remains deeply involved in debates over how to maximize benefits and minimize risks of the Internet.

Comment Re:This stuff worries me... (Score 1) 111

... to roads... many things that we use today were paved and made available by the US government.

Reg: All right, but apart from the sanitation, medicine, education, wine, public order, irrigation, roads, the fresh water system and public health, what have the Romans^H^H^H^H^H^H Americans ever done for us?

(I'm afraid HTML strike doesn't work here)

Slashdot Top Deals

You don't have to know how the computer works, just how to work the computer.

Working...