Stories
Slash Boxes
Comments
typodupeerror delete not in

Slashdot stories can be listened to in audio form via an RSS feed, as read by our own robotic overlord.

Comments: 730 +-   Is Linux Documentation Lacking? on Thursday December 03, @10:18AM

Posted by CmdrTaco on Thursday December 03, @10:18AM
from the hackers-and-english-don't-always-mix dept.
programming
eldavojohn writes "A number of blog posts are surfacing that are calling out the helpful open source community on their documentation. No, not the documentation for the highly skilled technical people, but the documentation from beginner to apprentice. A two-part series by Carla Schroeder lists bad documentation as 'Linux Bug #1' and advises users to use Google as the documentation. We've discussed before some of open source's documentation being out of date. Is it really as bad as these blogs paint it? Has it come down to using Google before a man page?"
Read More... 730 comments story

Comments: 214 +-   What Google's Chromium OS Is Reaching For on Tuesday December 01, @05:17PM

Posted by kdawson on Tuesday December 01, @05:17PM
from the chrome-detailing dept.
google
MojoKid sends in a piece that takes a step back from Google's much-analyzed OS to look at what it is trying to accomplish. "Last week, Google open-sourced its Chromium OS project, more than a year before the operating system is scheduled for release. In doing so, Google hopes a variety of developers and companies will become involved in the project, and has pledged to release regular updates as well as a comprehensive log of bug reports and fixes. This article takes a look at Google's design vision for Chromium, the unique benefits it offers, and a bit of why Google is throwing its hat into this particular ring in the first place. Chromium, after all, is a Linux-based OS entering the smartbook/netbook market at a time when the product segment is already being well served by a variety of Linux distros, XP, and Windows 7. In the midst of all these options, do we need another operating system? We just might."
Read More... 214 comments story

Comments: 351 +-   Microsoft Investigates Windows 7 "Black Screen of Death" on Tuesday December 01, @12:38PM

Posted by timothy on Tuesday December 01, @12:38PM
from the appropriate-namespace-overload dept.
bug
duguk writes "Microsoft has confirmed that it is investigating a problem described as the 'black screen of death,' which affects Windows 7 — and reports suggest it affects Vista and XP, too. The firm said it was looking into reports that suggest its latest security update, released on Tuesday 25 November, caused the problem. The error means that users of Windows 7 and earlier operating systems see a totally black screen after logging on to the system." Update: 12/01 22:35 GMT by KD : Microsoft now says that its November Windows updates are not causing the BlackSOD: "The company has found those reports to be inaccurate and our comprehensive investigation has shown that none of the recently released updates are related to the behavior described in the reports."
Read More... 351 comments story

Comments: 313 +-   Dell Defect Turning 2.2GHz CPU Into 100MHz CPU? on Monday November 30, @04:04PM

Posted by ScuttleMonkey on Monday November 30, @04:04PM
from the making-the-pr-department-work-for-their-paycheck dept.
bug
jtavares2 writes "In what is being dubbed Throttlegate, scores of users on many message boards have been complaining about nexplicably aggressive throttling policies on their Dell Latitude E6500 and E6400 laptops which cause their CPUs to be throttled to less than 5% of their theoretical maximums even while at room temperatures. In many cases, the issue can be triggered just by playing a video or performing some other trivial, but CPU intensive, task. After being banned [PDF] from the Dell Forums for revealing 'non-public information,' one user went so far as to write and publish a 59-page report [PDF] explaining and diagnosing the throttling problem in incredible detail. Dell seems to be silent on the issue, but many users are hoping for a formal recall."
Read More... 313 comments story

Comments: 154 +-   Microsoft Advice Against Nehalem Xeons Snuffed Out on Saturday November 28, @01:33PM

Posted by Soulskill on Saturday November 28, @01:33PM
from the keep-that-under-your-hat dept.
intel
Eukariote writes "In an article outlining hidden strife in the processor world, Andreas Stiller has reported the scoop that Microsoft advised against the use of Intel Nehalem Xeon (Core i7/i5) processors under Windows Server 2008 R2, but was pressured by Intel to refrain from publishing this advisory. The issue concerns a bug causing spurious interrupts that locks up the Hypervisor of Server 2008. Though there is a hotfix, it is unattractive as it disables power savings and turbo boost states. (The original German-language version of the article is also available.)"
Read More... 154 comments story

Comments: 410 +-   Moving Decimal Bug Loses Money on Wednesday November 25, @10:13AM

Posted by CmdrTaco on Wednesday November 25, @10:13AM
from the test-your-code-people dept.
humor
mario.m7 writes "Poste Italiane, the Italian postal service, suffered yesterday from an abnormal computation in ATM and credit card operations, since the decimal comma was not taken into account. The whole sum was therefore multiplied by 100, resulting in a 115,00 Euro transaction being debited as 11.500 Euro! Thousands of accounts are deep in the red and locked (link pumped through translator), so that no more operations are possible. Poste Italiane is gradually recovering the problem, fixing the error and re-crediting the sum debited in excess. Consumer associations have offered support to clients in case this lasts longer and causes damage."
Read More... 410 comments story

Comments: 225 +-   Inkscape 0.47 Released on Wednesday November 25, @02:10AM

Posted by kdawson on Wednesday November 25, @02:10AM
from the drawing-not-quartering dept.
software
derrida writes "After over a year of intensive development and refactoring, Inkscape 0.47 is out. This version of the SVG-based vector graphics editor brings improved performance and tons of new features, including: timed autosave, Spiro splines, auto-smooth nodes, Eraser tool, new modes in Tweak tool, snapping options toolbar & greater snapping abilities, new live path effects (including Envelope), over 200 preset SVG filters, new Cairo-based PS and EPS export, spell checker, many new extensions, optimized SVG code options, and much more. Additionally, it would be wrong to not mention the hundreds of bug fixes. Check out the full release notes for more information about what has changed, enjoy the screenshots, or just jump right to downloading your package for Windows, Linux, or Mac OS X." We've been following the progress of Inkscape for years (2006, 2005, 2004).
Read More... 225 comments story

Comments: 208 +-   Zero-Day Vulnerabilities In Firefox Extensions on Friday November 20, @10:14AM

Posted by kdawson on Friday November 20, @10:14AM
from the wild-in-the-playground dept.
bug
An anonymous reader writes "Researchers have found several security holes in popular Firefox extensions that have an estimated total of 30 million downloads from AMO (the Addons Mozilla community site). Three 0-days were also released. Mozilla doesn't have a security model for extensions and Firefox fully trusts the code of the extensions. There are no security boundaries between extensions and, to make things even worse, an extension can silently modify another extension." The affected extensions are Sage version 1.4.3, InfoRSS 1.1.4.2, and Yoono 6.1.1 (and earlier versions). Clearly the problem is larger than just these three extensions.
Read More... 208 comments story

Comments: 133 +-   FAA Computer Glitch Causes Widespread Airline Delays on Thursday November 19, @10:42AM

Posted by Soulskill on Thursday November 19, @10:42AM
from the reports-confirm-toothpaste-was-not-involved dept.
bug
seven of five writes with this excerpt from an Associated Press report: "A problem with the FAA system that collects airlines' flight plans caused widespread flight cancellations and delays nationwide Thursday. It was the second time in 15 months that a glitch in the flight plan system caused delays. The FAA said in a statement that it is having a problem processing flight plan information. 'We are investigating the cause of the problem,' the agency said. 'We are processing flight plans manually and expect some delays. We have radar coverage and communications with planes.'"
Read More... 133 comments story

Comments: 275 +-   Bizarre Droid Auto-Focus Bug Revealed on Wednesday November 18, @02:59PM

Posted by timothy on Wednesday November 18, @02:59PM
from the each-droid-has-a-moth-enclosed dept.
bug
itwbennett writes "Pity the poor engineer who had to find this one. One of the more interesting of the handful of bugs that have appeared since the launch of Verizon's Droid smartphone has to do with the on-board camera's auto-focus. Apparently it just didn't work. And then suddenly it did. Naturally, this off-again, on-again made the theories fly. But the real reason for the bug was revealed in a comment on an Engadget post by someone claiming to be Google engineer Dan Morrill: 'There's a rounding-error bug in the camera driver's autofocus routine (which uses a timestamp) that causes autofocus to behave poorly on a 24.5-day cycle,' said Morrill. 'That is, it'll work for 24.5 days, then have poor performance for 24.5 days, then work again. The 17th is the start of a new 'works correctly' cycle, so the devices will be fine for a while. A permanent fix is in the works.'"
Read More... 275 comments story

Comments: 122 +- Screenshot-sm   Drupal 6 Social Networking on Wednesday November 18, @02:10PM

Posted by samzenpus on Wednesday November 18, @02:10PM
from the read-all-about-it dept.
books
dag writes "Drupal 6 Social Networking is an interesting book about how to build social networks and why Drupal is a good choice as a platform for building communities. Even if you don't have any Drupal experience yet, this book explains what is needed when you start from scratch and looks at the different facets of a social network." Keep reading for the rest of Dag's review.
Read 5890 More Bytes... 122 comments story

Comments: 97 +-   SSL Renegotiation Attack Becomes Real on Monday November 16, @06:30PM

Posted by kdawson on Monday November 16, @06:30PM
from the laugh-a-while-you-can dept.
security
rastos1 and several other readers noted that the SSL vulnerability we discussed a couple of weeks back, which some researchers had claimed was too theoretical to worry about, has now been demonstrated by exploit. The attack description is available on securegoose.org. "A Turkish grad student has devised a serious, real-world attack on Twitter that targeted a recently discovered vulnerability in the SSL protocol. The exploit by Anil Kurmus is significant because it successfully targeted the so-called SSL renegotiation bug to steal Twitter login credentials that passed through encrypted data streams. All in all, a man in the middle is able to steal the credentials of a user authenticating himself through HTTPS to a trusted website."
Read More... 97 comments story

Comments: 289 +-   The First Windows 7 Zero-Day Exploit on Monday November 16, @04:54AM

Posted by kdawson on Monday November 16, @04:54AM
from the think-global-print-local dept.
security
xploraiswakco writes with the first Microsoft-confirmed Windows 7 zero-day vulnerability, with a demonstration exploit publicly available. The problem is in SMBv2 and SMBv1 and affects Windows 7 and Windows Server 2008 R2, but not Vista, XP, or Windows Server 2003. A maliciously crafted URI could hard-crash affected machines beyond any remedy besides pushing the white button. "Microsoft said it may patch the problem, but didn't spell out a timetable or commit to an out-of-cycle update before the next regularly-scheduled Patch Tuesday of December 8. Instead, the company suggested users block TCP ports 139 and 445 at the firewall." Reader xploraiswakco adds, "As important as this the mentioned article is, it should also be pointed out that any IT staff worth their pay packet should already have port 139 blocked at the firewall, and probably port 445, too."
Read More... 289 comments story

Comments: 69 +-   DNS Problem Linked To DDoS Attacks Gets Worse on Sunday November 15, @09:13AM

Posted by Soulskill on Sunday November 15, @09:13AM
from the i-blame-the-schools dept.
security
itwbennett writes "The percentage of devices on the Internet that are configured to accept DNS queries from anywhere — what networking experts call an 'open recursive' or 'open resolver' system — has jumped from around 50 percent in 2007 to nearly 80 percent this year, according to research sponsored by DNS appliance company Infoblox. As more consumers demand broadband Internet, service providers are rolling out modems configured this way to their customers, said Cricket Liu, vice president of architecture with Infoblox. Georgia Tech researcher David Dagon agreed that open recursive systems are on the rise, in part because of 'the increase in home network appliances that allow multiple computers on the Internet. ... Almost all ISPs distribute a home DSL/cable device. Many of the devices have built-in DNS servers. These can sometimes ship in "open by default" states.' What's worse, says Dagon, is that many of these devices do not include patches for a widely publicized DNS flaw discovered by researcher Dan Kaminsky last year."
Read More... 69 comments story

Comments: 6 +- Screenshot-sm   Bug Wears Armor Made of Poo on Thursday November 12, @11:38AM

Posted by samzenpus on Thursday November 12, @11:38AM
from the protection-you-can-smell dept.
idle
richardkelleher writes "It seems it doesn't always roll downhill, sometimes it is armor. The case-bearing leaf beetle apparently protects itself by constructing armor made from excrement. Females of these species typically construct bell-shaped receptacles made of feces around an egg immediately after they lay one."
Read More... 6 comments story

Comments: 130 +-   Shockwave Vulnerabilities Affect More Than 450 Million Systems on Thursday November 05, @02:14PM

Posted by timothy on Thursday November 05, @02:14PM
from the drug-resistant-infections dept.
security
Trinity writes "Researchers from VUPEN have discovered critical vulnerabilities in Adobe Shockwave, a technology installed on over 450 million Internet-enabled desktops. The vulnerabilities could allow remote code execution by tricking a user into visiting a web page using Internet Explorer or even Mozilla Firefox. Version 11.5.1.601 as well as earlier ones are affected. The vendor recommends upgrading to version 11.5.1.602." Especially sobering when you consider Adobe's current push to be essentially required as an intermediary player for anyone who wants to see certain government data.
Read More... 130 comments story

Comments: 106 +-   Facebook and MySpace Backdoors Found, Fixed on Thursday November 05, @11:29AM

Posted by Soulskill on Thursday November 05, @11:29AM
from the oh-adobe-you-card dept.
bug
jamie writes with news of a Facebook app developer who found a significant security hole while he was trying to get around function limitations for his application. Quoting: "Luckily — just with browser AJAX requests — a flash application hosted on domain X is unable to open a file on domain Y. If this would be possible, domain X [would be] able to access content on domain Y, and when the user is logged in on domain Y retrieve and post back any personal data. In certain cases this could limit a Flash application's capabilities. ... To resolve such issues, Adobe (Flash's developers) introduced a 'crossdomain.xml' file which could allow certain domains to access another domain, leading to cross-domain access by certain or all domains. While indeed Facebook locked the front door from any non-Facebook domain access via Flash, a simple subdomain change allowed any flash application (domain="*") to access its domain data." He found a similar problem in MySpace's crossdomain.xml. Both sites were notified, and they have implemented fixes.
Read More... 106 comments story

Comments: 281 +-   Bug In Most Linuxes Can Give Untrusted Users Root on Wednesday November 04, @08:51AM

Posted by kdawson on Wednesday November 04, @08:51AM
from the patchin'-place dept.
security
Red Midnight and other readers brought to our attention a bug in most deployed versions of Linux that could result in untrusted users getting root access. The bug was found by Brad Spengler last month. "The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable. While attacks can be prevented by implementing a common feature known as mmap_min_addr, the RHEL distribution... doesn't properly implement that protection... The... bug is mitigated by default on most Linux distributions, thanks to their correct implementation of the mmap_min_addr feature. ... [Spengler] said many other Linux users are also vulnerable because they run older versions or are forced to turn off [mmap_min_addr] to run certain types of applications." The register reprints a dialog from the OpenBSD-misc mailing list in which Theo De Raadt says, "For the record, this particular problem was resolved in OpenBSD a while back, in 2008. We are not super proud of the solution, but it is what seems best faced with a stupid Intel architectural choice. However, it seems that everyone else is slowly coming around to the same solution."
Read More... 281 comments story

Comments: 1146 +-   Toyotas Suddenly Accelerate; Owners Up In Arms on Tuesday November 03, @11:31PM

Posted by kdawson on Tuesday November 03, @11:31PM
from the off-to-a-bad-start dept.
transportation
cyclocommuter writes "Some Toyota owners are up in arms as they suspect that accidents have been caused by some kind of glitch in the electronic computer system used in Toyotas that controls the throttle. Refusing to accept the explanation of Toyota and the federal government (it involves the driver's-side floor mat), hundreds of Toyota owners are in rebellion after a series of accidents caused by what they call 'runaway cars.' Four people have died." The article notes: "The National Highway Traffic Safety Administration has done six separate investigations of such acceleration surges in Toyotas since 2003 and found no defect in Toyota's electronics."
Read More... 1146 comments story

Comments: 1231 +-   Some Early Adopters Stung By Ubuntu's Karmic Koala on Tuesday November 03, @05:29PM

Posted by kdawson on Tuesday November 03, @05:29PM
from the arrows-in-back dept.
upgrades
Norsefire writes to mention a Register piece reporting that early adopters are having a tough time with Karmic Koala, Ubuntu's latest release. "Ubuntu 9.10 is causing outrage and frustration, with early adopters wishing they'd stuck with previous versions of the Linux distro. Blank and flickering screens, failure to recognize hard drives, defaulting to the old 2.6.28 Linux kernel, and failure to get encryption running are taking their toll, as early adopters turn to the web for answers and log fresh bug reports in Ubuntu forums." What has been your experience if you've moved to Karmic?
Read More... 1231 comments story

Without love intelligence is dangerous; without intelligence love is not enough. -- Ashley Montagu