Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Submission + - CentOS 8 to be released next week (twitter.com)

JDShewey writes: The CentOS Project has announced that CentOS 8.0 will be available for download beginning Tuesday, Sept 24th. This release was deferred so that work to release CentOS 7.7 could be completed, which means that CentOS 7.7 will be out shortly as well (and 7.7 it is already beginning to appear in mirrors and repos). This comes 20 weeks to the day from the release of Red Hat Enterprise Linux 8.

Submission + - iOS 13 Lock Screen Lets Anyone See Your Adress Book (theregister.co.uk)

dryriver writes: A security researcher discovered that if you get your hands on someone else's iThing running iOS 13, and place a phonecall to it, you can choose to respond with a TXT message, and get to see the contents of the address book on the iThing without actually getting past the lock screen. From the Register article: 'The procedure, demonstrated below in a video, involves receiving a call and opting to respond with a text message, and then changing the "to" field of the message, which can be accomplished via voice-over. The "to" field pulls up the owner's contacts list, thus giving an unauthorized miscreant the ability to crawl through the address book without ever needing to actually unlock the phone.' The security researcher who found the flaw was not financially rewarded or acknowledged by Apple, but rather given the cold shoulder, and it is unclear whether the official release of iOS 13 will have fixed this rather glaring lock screen design flaw.

Comment Import it into your own code base, and review it. (Score 4, Interesting) 68

Simply import it into your own code base, and then review it as if it was written internally. Basically, learn it inside out, as if you wrote it yourself. If that is not legally sufficient, then the laws need to be rewritten since the lines they would be attempting to delineate would at this point be completely imaginary. It doesn't matter whose head it originates from, what matters is that it is fully reviewed and completely understood to the point where everyone on your team is prepared to stand behind the entire body of code. If that confidence comes from actual understand, it becomes irrelevant who wrote the code in the first place. How would it be any different if, instead, it was code written by somebody who no longer works at the company.

Slashdot Top Deals

Always look over your shoulder because everyone is watching and plotting against you.

Working...