Mr_Figtree

joined 1 year ago
 

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

 

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

10
This Week in Rust 506 (this-week-in-rust.org)
4
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

Update on what happened across the GNOME project in the week from July 21 to July 28.

2
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

Update on what happened across the GNOME project in the week from July 21 to July 28.

19
This Week in Rust 505 (this-week-in-rust.org)
16
This Week in Rust 505 (this-week-in-rust.org)
 

Hello again from the Rust Leadership Council. In our first blog post, we laid out several immediate goals for the council and promised to report back on their progress. It has been about a month since our first update so we wanted to share how it's going and what we're working on now.

 

Update on what happened across the GNOME project in the week from July 15 to July 22.

 

Update on what happened across the GNOME project in the week from July 15 to July 22.

[–] [email protected] 2 points 1 year ago

so I can totally ditch chromium/electron

GNOME Web isn't Chromium-based and does support PWAs, so it might work for your usecase.

[–] [email protected] 11 points 1 year ago

Someone I know recently switched from automatic bathroom lights to manual ones. Remembering to turn them on isn't an issue, but months later everyone still forgets to turn them off.

[–] [email protected] 10 points 1 year ago (1 children)

And .box has been registered as a generic TLD now, so you could run into external .box domains.

[–] [email protected] 25 points 1 year ago (3 children)

They're not going to have open signups. It's government agencies only. Not that there's technically anything stopping Germans from joining the PR departments of our government agencies…

[–] [email protected] 12 points 1 year ago (4 children)

So what you're saying is that Twitter successfully kept out a bad actor.

It's a shame that most of the users they have left are also in that category, but hey, they seem to be working on it.

[–] [email protected] 2 points 1 year ago (1 children)

That's the real AI apocalypse:

  • People outsourcing decisions to predictive text because they believe it thinks
  • AI hallucinations becoming commonly accepted as truth, as generated articles bury actual knowledge in a flood of bull droppings
[–] [email protected] 3 points 1 year ago

You'll still have the people who are opposed to any telemetry at all, but I think that would do a lot to alleviate the concerns.

[–] [email protected] 1 points 1 year ago

A poll like this is never going to be representative, unfortunately.

[–] [email protected] 5 points 1 year ago (2 children)

I'm using kbin Magazine Style Toggle to disable the custom styling on certain magazines, but I had to modify line 36 to make it work:

36c36
<         let style = document.querySelector("head > style:nth-child(22)");
***
>         let style = document.querySelector("head > style:nth-of-type(1)");

view more: next ›