Zum Inhalt der Seite gehen

Suche

Beiträge, die mit tech getaggt sind


:firefox: Mozilla warns Windows Users of critical Firefox Sandbox Escape Flaw.

The vulnerability impacts the latest Firefox standard and extended support releases (ESR) designed for organizations that require extended support for mass deployments. Mozilla fixed the security flaw in Firefox 136.0.4 & Firefox ESR versions 115.21.1 + 128.8.1.

https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/#CVE-2025-2857

#mozilla #firefox #update #it #security #privacy #engineer #media #tech #news
Mozilla has released Firefox 136.0.4 to patch a critical security vulnerability that can let attackers escape the web browser's sandbox on Windows systems. Tracked as CVE-2025-2857, this flaw is described as an "incorrect handle could lead to sandbox escapes" and was reported by Mozilla developer Andrew McCreight.

While Mozilla didn't share technical details regarding CVE-2025-2857, it said the vulnerability is similar to a Chrome zero-day exploited in attacks and patched by Google last week.

"Following the sanbdox escape in CVE-2025-2783, various Firefox developers identified a similar pattern in our IPC code. Attackers were able to confuse the parent process into leaking handles into unpriviled [sic] child processes leading to a sandbox escape," Mozilla said in a advisory. "The original vulnerability was being exploited in the wild. This only affects Firefox on Windows. Other operating systems are unaffected."


Ich werde den Verdacht nicht los, dass #OpenSource zu einem #Ablasshandel #Geschäftsmodell der großen #Tech-Firmen wird um den Kartellstrafen vorsorglich zu umgehen.

zB #Google hält #Mozilla am leben und #Adobe, #Epic uva sponsern #Blender und so weiter. So existiert eine frei zugängliche angebliche #Konkurrenz und kann von sich weisen, dass man ein Monopolist sei. Abgesehen davon, dass damit auch noch unterschwellig seine #Dienste unter die Leute gebracht wird, so zu sagen als Gegenleistung.


#Geopolitics LegalWonks. Sample below.

(Editor’s Note: This article is part of the Just Security symposium “Thinking Beyond Risks: #Tech and Atrocity Prevention,” organized with the Programme on International Peace and Security at the Oxford Institute for #Ethics, Law and Armed Conflict. Readers can find here an introduction and other articles in the series as they are published.)

When #AI Fuels Atrocities — And How It Can Help Prevent Them
https://www.justsecurity.org/109612/ai-can-fuel-or-prevent-atrocities/ #artificialintelligence
The third, and perhaps most concerning, threat vector is generative AI’s ability to broadly disrupt information environments through what researchers have called compositional deepfakes. This sophisticated technique embeds AI-generated content within layers of authentic material — Microsoft Chief Scientific Officer Eric Horvitz explains that, in a compositional deepfake, “a sequence of two fabricated ‘past’ deepfake media pieces are injected between two world occurrences and time-stamped as happening at appropriate times between the two events. Moving into the future in this canonical synthetic history, an in-world event is fabricated to complete the persuasive storyline.” In other words, fabricated past events are injected between real-world occurrences to shape a manipulated perception of history and complete a persuasive storyline. This creates an information ecosystem in which truth and falsehood are sown together and become increasingly difficult to unravel.


#BookReview: “How #Tech #Billionaires on the Right Bought the Loudest Voices on the Left”

'Owned: How Tech Billionaires on the Right Bought the Loudest Voices on the Left, examines how new wealth has drawn some formerly progressive journalists. Owned looks at #MattTaibbi and #GlennGreenwald (who was always right wing libertarian with axes to grind that suited the left, as is snowden) once idealistic-sounding, left-leaning voices who shifted right'
https://accuracy.org/release/how-tech-billionaires-on-the-right-bought-the-loudest-voices-on-the-left/ #fakeleftists #proglibs


Looking to integrate Korifi with your Go applications? ✨ I've published a blog post that walks you through connecting to Korifi on a Kind cluster. It includes authentication tips and code examples for getting started. Check it out here: https://gciavarrini.github.io/blog/go_korifi/

#korifi #cloudfoundry #blog #go #golang #kubernetes #Tech #technology


A Game Boy Speedometer, just because you can.

The “world’s worst digital dash”, a Nintendo Game Boy as a digital speedometer. Interfacing the handheld with the vehicle’s CAN bus system, this project has something to offer.

🖇️Check my Image Description’s🖇️

https://github.com/JohnSutley/Worlds-Worst-Digital-Dash

#diy #retro #gameboy #speedometer #car #canbus #system #it #engineer #artist #media #maker #tech #art #progamming #news
Months of work have gone into decoding the Game Boy’s data bus and creating a schematic for the interface board. Tricking the Game Boy into thinking it was loading a game, while actually displaying incoming speed data. The screen’s low resolution and slow refresh rate rendered it barely readable in a moving vehicle. But [John]’s goal wasn’t practicality — it was just proving it could be done.
[ImageSource: John Sutley]

Showing real-time vehicle speed on the Game Boy sounds like it should be relatively easy, but the iconic game system wasn’t exactly built for such a task. Its 2 MHz CPU and 160×144 pixel dot-matrix screen were every kid’s dream in 1989, but using it as a car dashboard is pushing it. To bridge that gap, [John] designed two custom circuit boards.

One interfaces with the Game Boy, intercepting its memory requests and feeding it data from a microcontroller. The other processes the CAN bus signals, translating speed information into a form the Game Boy can display. [John] used inexpensive tools and software to read the CAN bus data, and used GBDK-2020 to write the software in C.


Saturday shoutout to those who wake up, open their browser, and it’s Vivaldi. 🏆🙇‍♂️

#Browser #Vivaldi #Apps #Tech


Hey everyone! The latest Dev Weekly of March just dropped! Be sure to check it out and share it with your friends.

https://blog.codeminer42.com/codeminer42-dev-weekly-54/

#blog #codeminer42 #tech #news #weekly


My #tech prediction:

Despite the hype from Silicon Valley, my belief is the generative #AI and LLM bubble is nearing its bursting point.

Like with the dot com crash, Wall Street and Investors are getting impatient and want to see profitability.

Most AI startups aren't even close. And mass adoption of AI tools still hasn't become ubiquitous among the general public - and probably never will.

Most "features" are over-hyped and AIs can still "hallucinate" (lie) when providing information - a very big issue the tech industry is trying to downplay.

Startups are going to either shut down or be acquired by the bigger players.

Also, like the dot com bust, only the biggest, most deep-pocketed players are going to remain standing after the shakeout.

I think the AI landscape is going to start imploding as early as the end of this year.

AI will still play a role, but not be as revolutionary as the tech industry wants us to believe.
#ai #tech


One of many notable takeaways from 'Careless People':

The creators and top execs of Meta do not allow their own children on it.

Think about that.

#carelesspeople #facebook #tech
Image of cover to book 'Careless People' by Sarah Wynn-Williams.


💡 GPT-4o riceve la generazione immagini integrata in ChatGPT

https://gomoot.com/gpt-4o-riceve-la-generazione-immagini-integrata-in-chatgpt

#ai #blog #gpt4o #ia #news #openai #picks #tech #tecnologia


New Mac Attack is tricking Users into thinking their Computer is locked.

According to LayerX Labs, who have been tracking this campaign for more than a year, the phishing attack attempts to trick Mac users into thinking that their computers have been “locked” via a fake security warning that pops up while users are browsing the web.

https://layerxsecurity.com/blog/layerx-identifies-new-phishing-campaign-targeted-at-mac-users/

#apple #macos #it #security #privacy #engineer #media #tech #news


:linux:📄 Minimal Linux OS runs in a 6MB PDF Document in Chrome.

A version of the Linux operating system can now be run inside a PDF opened by a Chromium-based browser. The developer [Ading2210] explains that Linux need a modified version of the TinyEMU RISC-V emulator.

https://github.com/ading2210/linuxpdf

#linux #pdf #chromium #based #browser #it #engineer #media #programming #art #tech #developer #artist #news
If you wish to try out the LinuxPDF, it requires a Chromium-based browser to work correctly (I checked, but it didn't work in Firefox on PC).

On the topic of speed and efficiency, [Ading2210] humbly admits that performance might be the largest problem with LinuxPDF. "The Linux kernel takes about 30-60 seconds to boot up within the PDF, which [is] over 100x slower than normal," notes the developer. With Chrome's current PDF engine having its Just-in-Time (JIT) compiler disabled, [Ading2210] sees no way of speeding up the code, for now.
[ImageSource: Ading2210]

The TinyEMU RISC-V emulator runs in the PDF thanks to a technique where its code is compiled "using an old version of Emscripten that targets asm.js instead of WebAssembly." This is embedded and loads in the PDF, subsequently auto-running a minimal Linux kernel targeting that architecture.

In this implementation, once you agree to 'Start Emulator' in your browser, you will see the LinuxPDF UI load, and a welcome message in the Linux viewport, as you wait for the OS to boot.
[ImageSource: Ading2210]

Below the Linux viewport in the PDF is a soft keyboard created by an array of PDF buttons. However, it is likely quicker for everyone with a decent physical keyboard to input commands into the 'type here for keyboard inputs' field to the lower right of the keyboard UI area.


Trump Admin Threatens to Stop Social Security If DOGE Can’t Have Personal Data

Trump’s interim Social Security chief says he wants to turn off the program if #Musk & #DOGE can’t access #Americans’ most sensitive #data
https://www.rollingstone.com/politics/politics-news/trump-musk-stop-social-security-doge-data-1235300785/

"Dudek’s threat to block #SSA employees from using the agency’s #IT systems — a move that could halt #SocialSecurity payments — came in response to a judge’s temporary restraining order"

#ElonMusk #Coup #Corruption #Trump #GOP #USPol #Tech #News #US #USA
Headline from Rolling Stone:
Temper Tantrum
Trump Admin Threatens to Stop Social Security If DOGE Can’t Have Personal Data

Trump’s interim Social Security chief says he wants to turn off the program if Musk and DOGE can’t access Americans’ most sensitive data

by Andrew Perez
March 21, 2025


Google is buying Israeli tech company Wiz for $32 billions. This will bring in $4 billion in tax revenue to Israel. Israeli journalists are already commenting on how this will help fund "war-related costs and expenditures".

Using Israeli tech directly contributes to Israel's war on Palestinians.

#Israel #Palestine #Gaza #Tech #BDS
Screenshot of a Times of Israel article:

War costs since the October 7 onslaught have spiraled to NIS 112 billion ($31 billion) as of the end of 2024.

“A large amount of tax of about NIS 15 billion ($4 billion) is estimated to be paid by the founders and the Israel-resident investors, and by the Israeli employees who have received options, which is great news for Israel as the country grapples with war-related costs and expenditures,” said Guz-Lavi.

The estimated tax revenue Israel could earn from the transaction is equal to about 0.6 percent of the GDP and would help relieve government pressure to introduce measures to fund the war’s defense and civilian expenditures and bring down the budget deficit and high debt levels.


💡 Saturday tip for our Android users:

When you move the Tab and Address Bars to the bottom, the Navigation Bar disappears and you have more screen space. If you prefer to keep the Tab and Address Bars on top there’s still a way to hide the Navigation Bar.

To hide it:

Settings > Appearance & Theme > Disable “Show Navigation Bar”.

When hidden, the Tab Switcher button is moved to the Address Bar and other features are available from the main Vivaldi menu.

#Android #Browser #Tech #Apps
Image displays an Android phone with Vivaldi Browser open. An arrow points to a new setting that allows you to enable or disable the navigation bar.


Quake ported to Arduino Nano Matter. [Using only 276kb RAM]

Nicola Wrachien with Silicon Labs created this fun handheld, porting Quake using the Arduino Nano Matter. For easy playing a custom controller shaped board was designed with joysticks and a screen.

https://next-hack.com/index.php/2024/09/22/quake-port-to-sparkfun-and-arduino-nano-matter-boards-using-only-276-kb-ram/

#quake #arduino #nano #diy #handheld #port #retro #gaming #art #maker #engineer #artist #media #programming #tech #news
On a technical level, Quake was a dramatic improvement over DOOM, allowing for things like real-time 3D rendering, polygonal models instead of sprites and much more intricate level design. As a result, ports of this game tend to rely on much more powerful processors than DOOM ports and this team shows real mastery of their hardware to pull off a build with a system with these limitations.

Other Quake ports, like one running on an iPod Classic require a similar level of knowledge of the code and the ability to use assembly language to make optimizations.
[ImageSource: Nicola Wrachien]

For a much tougher challenge, a group from Silicon Labs decided to port DOOM‘s successor, Quake, to the Arduino Nano Matter Board platform instead even though this platform has some pretty significant limitations for a game as advanced as Quake.

<https://community.silabs.com/s/share/a5UVm000000Vi1ZMAS/quake-ported-to-arduino-nano-matter-and-sparkfun-thing-plus-matter-boards?language=en_US>

To begin work on the memory problem, the group began with a port of Quake originally designed for Windows, allowing them to use a modern Windows machine to whittle down the memory usage before moving over to hardware. They do have a flash memory module available as well, but there’s a speed penalty with this type of memory. To improve speed they did what any true gamer would do with their system: overclock the processor. This got them to around 10 frames per second, which is playable, but not particularly enjoyable.

The further optimizations to improve the FPS required a much deeper dive which included generating lookup tables instead of relying on computation, optimizing some of the original C programming, coding some functions in assembly and only refreshing certain sections of the screen when needed.


Hi there 👋

I'm new around these parts.

I'm a mid 20s woman from Denmark 🇩🇰

Mostly lurking but will be posting my random thoughts, #tech, #fashion, whenever I do any #travel, and whenever I do something around the web.

I'm also the (currently only blind) software engineer @bemyeyes

Looking forward to chat with you all around these parts