×
Security

0-Day GRUB2 Authentication Bypass Hits Linux (hmarco.org) 144

prisoninmate writes: A zero-day security flaw was discovered by developers Ismael Ripoll and Hector Marco in the upstream GRUB2 packages. GRUB2 did not correctly handle the backspace key when the bootloader was configured to use password protected authentication, thus allowing a local attacker to bypass GRUB's password protection. Versions from 1.98 (December, 2009) to 2.02 (December, 2015) are affected. At the moment, it looks like only a few distributions received the patched GRUB2 versions, including Ubuntu, Debian (Squeeze LTS only) and Red Hat Enterprise Linux 7.
Science

Galloping Gertie, Engineering's Most Misunderstood Failure (vice.com) 168

tedlistens writes: Generations of physics teachers, textbooks, and articles have taught that the spectacular collapse of the Tacoma Narrows Bridge, 75 years ago, in November 1940, was caused by resonance. But this explanation is inaccurate, and despite the fact that the collapse is not a mystery—that the bridge, in a sense, twisted itself apart—the fallacy continues to spread. Not only that: according to a new study by Don Olson and colleagues at Texas State University and East Carolina University, parts of the famous footage that immortalized it are misleading too. According to the most complete recent research, he and his co-authors write, "the failure of the bridge was related to a wind-driven amplification of the torsional oscillation that, unlike a resonance, increases monotonically with increasing wind speed." Each time the deck of the bridge twisted now, it sought to return to its original position (inertial forces). And as it did so, twisting back with a matching speed and direction (elastic forces), the wind and the vortices caught it each time, pushing the deck just a little bit more in that direction (aerodynamic forces). With each twist and each twist back, the size of the twisting slightly increased.
Ubuntu

Canonical Patches Two Kernel Vulnerabilities In Ubuntu 14.04 (softpedia.com) 33

jones_supa writes: Canonical has announced that a new kernel update is now live in the default software repositories for the Ubuntu 14.04 operating system. According to the security notice, two Linux kernel vulnerabilities have been fixed. The first security flaw was discovered in the SCTP (Stream Control Transmission Protocol) implementation, which conducted a wrong sequence of protocol-initialization steps. The second kernel vulnerability (discovered by Dmitry Vyukov) was in the Linux kernel's keyring handler, which tried to garbage collect incompletely instantiated keys. Both vulnerabilities allow a local attacker to crash the system by causing a denial of service. To fix the issues mentioned above, Canonical urges all users of Ubuntu 14.04 to update their kernel packages on all platforms.
Chrome

Google To Drop Chrome Support For 32-bit Linux 175

prisoninmate writes: Google announces that its Google Chrome web browser will no longer be available for 32-bit hardware platforms. Additionally, Google Chrome will no longer be supported on the Ubuntu 12.04 LTS (Precise Pangolin) and Debian GNU/Linux 7 (Wheezy) operating systems. Users are urged to update to the Ubuntu 14.04 LTS (Trusty Tahr) release and Debian GNU/Linux 8 (Jessie) respectively. Google will continue to support the 32-bit build configurations for those who want to build the open-source Chromium web browser on various Linux kernel-based operating systems. Reader SmartAboutThings writes, on a similar note, that: Microsoft is tolling the death knell for Internet Explorer with an announcement that it will end support for all older versions next year. Microsoft says that all versions older than the latest one will no longer be supported starting Jan. 12, 2016. After this date, Microsoft will no longer provide security updates or technical support for older Internet Explorer versions. Furthermore, Internet Explorer 11 will be the last version of Internet Explorer as Microsoft shifts its focus on its next web browser, Microsoft Edge.
Hardware

Hardware For a Cheap Linux Desktop (phoronix.com) 207

An anonymous reader writes: Outside of the limelight of Intel's Core "Skylake" processors is the cheapest model, a $60 Intel Pentium G4400 dual-core processor that runs at 3.3Gz and has built-in HD Graphics 510. Ubuntu Linux results for this CPU show the cut-down Skylake graphics are the worst aspect of this budget processor while the CPU performance is okay if speed isn't a big factor and your workloads don't mind the lack of AVX support. To pair with the cheap Skylake Pentium processors are more Intel H110-powered motherboards appearing, with some also retailing for under $60 while being basic yet functional as a severely cutdown version of the Intel Z170 chipset. If pursuing this route for a budget Linux PC, it's possible to build a socketed Skylake system for less than $200. Those of you who have recently built, or are planning out a new budget Linux machine, what internals do you recommend?
Operating Systems

Ubuntu 16.04 LTS Will Ship With Linux Kernel 4.4 LTS 101

prisoninmate writes: The current daily build of the Ubuntu 16.04 LTS (Xenial Xerus) remains based on the Linux 4.2 kernel packages of the stable Ubuntu 15.10 (Wily Werewolf) operating system, while the latest and most advanced Linux 4.3 kernel is tracked on the master-next branch of the upcoming operating system. In the meantime, the Ubuntu Kernel Team announced plans for moving to Linux kernel 4.4 for the final release of the Ubuntu 16.04 LTS (Xenial Xerus) operating system.
Games

Steam Has Brought 1,600 Games To Linux In the Past Three Years (phoronix.com) 110

An anonymous reader writes: Today marks three years since Valve's Steam client went into beta on Linux. In that time over 1,600 games have become natively available for Linux. Going beyond having many new Linux games, Phoronix recaps, "we've seen Valve make significant investments into the open-source graphics stack and other areas of Linux (in part through their sponsorship of Collabora and LunarG). Valve developers are significantly pushing SDL2. We've seen more mainstream interest in Linux gaming, and Valve has been heavily involved in the creation of the Vulkan graphics API. They have given away their entire game collection to the Mesa/Ubuntu/Debian upstream developers, and much more." The three-year anniversary is coincidentally just days before the release of Steam Machines.
Operating Systems

Ask Slashdot: Innovative Operating Systems/Distros In 2015? 206

iamacat writes: Back in 90s, we used Linux not only because of open source, but also for innovative features not found in commercial operating systems — better multitasking, network power features like slirp and masquerading, free developer tools for many languages. Nowadays OSX and Windows caught up in these areas and mainstream distros like Ubuntu dumbed down in default configuration. So where to go for active innovation like 3D/VR desktop, artificial intelligence, drag and drop ability to mash up UI of multiple apps or just drastically better performance? Something maybe rough around the edges but usable and exciting enough to use as daily desktop?
Graphics

Open-Source GPU Drivers Show Less Than Ideal Experience For SteamOS/Linux Gaming (phoronix.com) 109

An anonymous reader writes: Phoronix's recent 22-Way SteamOS Graphics Card Comparison showed that NVIDIA wins across the board when it comes to closed-source OpenGL driver performance. However, when it comes to the open-source driver performance for Steam Linux gaming, no one is really the winner. A new article, "Are The Open-Source Graphics Drivers Good Enough For Steam Linux Gaming?" answers that question with "heck no" by its author. While AMD is generally regarded as having better open-source support, their newer graphics cards still can't run at their rated clock frequencies due to lack of power management support, the lack of enough OpenGL 4.x support means many AAA Linux games simply cannot run yet, not enough QA means regressions are common, and other issues were noted when it comes to testing a number of modern graphics cards on the open-source drivers.
Ubuntu

Ubuntu 15.10 'Wily Werewolf' Released (omgubuntu.co.uk) 191

LichtSpektren writes: Ubuntu 15.10 "Wily Werewolf" is now released and available, along with its alternative desktop flavors (MATE, Xfce, LXDE, GNOME, KDE, Kylin). This release features Linux 4.2, GCC 5, Python 3.5, and LibreOffice 5. The default version is still using X.org display server and Unity7; Mark Shuttleworth has said that Mir and Unity8 won't arrive until Ubuntu 16.04 "Xenial Xerus." Not much has changed beyond package updates, other than replacing the invisible overlay scrollbars in Nautilus with the GNOME 3 scrollbars.

Phoronix brings us the only bit of drama regarding this release: Jonathan Riddell, long time overseer of Kubuntu, has resigned with claims that Canonical has "defrauded donors and broke the copyright licenses."
Another reader adds a link to a Q & A session with Riddell.
Intel

Intel's Core i5 6500 Shines As a $199 Skylake Processor, Works With Linux (phoronix.com) 119

An anonymous reader writes: Intel has begun releasing more "Skylake" processors that are cheaper than the launch SKUs of the i5-6600K and i7-6700K. One of the new processors that is now widely available is the Core i5 6500 and it costs just $199 USD — that puts it just a few dollars more than the AMD FX-8370 and significantly less than the higher-end Skylake and Haswell CPUs. At least with Ubuntu Linux, the Core i5 6500 is showing competitive performance that for some workloads puts it faster than Core i7 Haswell/Broadwell processors and much faster than any AMD processors. The Intel Skylake CPUs are fully supported under Linux but the caveat is needing the very latest kernel otherwise there's no graphics acceleration or sound support.
Ubuntu

Ubuntu Plans To Make ZFS File-System Support Standard On Linux 279

An anonymous reader writes: Canonical's Mark Shuttleworth revealed today that they're planning to make ZFS standard on Ubuntu. They are planning to include ZFS file-system as "standard in due course," but no details were revealed beyond that. However, ZFS On Linux contributor Richard Yao has said they do plan on including it in their kernel for 16.04 LTS and the GPL vs. CDDL license worries aren't actually a problem. Many Linux users have been wanting ZFS on Linux, but aside from the out of tree module there hasn't been any luck in including it in the mainline kernel or with tier-one Linux distributions due to license differences.
Open Source

XPRIZE's Jono Bacon On the Next Great Challenge 20

itwbennett writes: After just under 8 years at Canonical where he was Community Manager of Ubuntu, Jono Bacon left in search of a new challenge. Now, a year and a half into his tenure at the XPRIZE Foundation as Senior Director of Community, Bacon reflects on the changing nature of community and how he is working to bring the 'anybody can play a role in a bigger picture' aspect of open source to "solve the grand challenges facing humanity." Update: 09/17 00:20 GMT by T : Jono wants everyone to know that he's certainly not leaving the world of open source software, either; headline has been updated to reflect that.
Open Source

Ask Slashdot: Synchronizing Sound With Video, Using Open Source? 103

An anonymous reader writes: I have a decent video camera, but it lacks a terminal for using an external mic. However, I have a comparatively good audio recorder. What I'd like to do is "automagically" synchronize sound recorded on the audio recorder with video taken on the video camera, using Free / Open Source software on Linux, so I can dump in the files from each, hit "Go," and in the end I get my video, synched with the separately recorded audio, in some sane file format. This seems simple, but maybe it isn't: the 800-pound gorilla in the room is PluralEyes, which evidently lots of people pay $200 for --and which doesn't have a Linux version. Partly this is that I'm cheap, partly it's that I like open source software for being open source, and partly it's that I already use Linux as my usual desktop, and resent needing to switch OS to do what seems intuitively to be a simple task. (It seems like something VLC would do, considering its Swiss-Army-Knife approach, but after pulling down all the menus I could find, I don't think that's the case.) I don't see this feature in any of the Open Source video editing programs, so as a fallback question for anyone who's using LiVES, KDEnlive, or other free/Free option, do you have a useful workflow for synching up externally recorded sound? I'd be happy even to find a simple solution that's merely gratis rather than Free, as long as it runs on Ubuntu.
Education

Ask Slashdot: Cheapest Functional Computer For Students? 508

An anonymous reader writes: I've started a second career, teaching English at a High School in a middle class area. While the large majority of students have a computer and internet access at home, about 10-15% do not. I assign papers that must be typed, I have papers turned in online, and I plan to freely refer to texts, videos, and other resources that are available online. This gives an extra disadvantage to students that may be from the poorer end of the strata, and also means extra inefficiency for me, as I have to make allowances for students who don't have a computer available at home.

Right now, I have to tell them to either use school computers during the day, or to pick up a $170 laptop (more than enough — I administer the class using such a laptop). However, I was surprised at the lack of a super-cheap option for students. I'd love to see something for $20 that any student could afford easily, or perhaps I could just gift to a few students. I feel like something in this price range could be sufficiently powerful for basic word processing, youtube videos, and internet searches (internet access is a separate issue). But looking over my options I see:

1) The very cheapest Chromebooks are also in the $170 range.
2) Android Sticks have been around for a while, and do cost in the $20 range, but don't seem to have matured into a generally usable technology. Surprisingly, there doesn't seem to be a community effort to easily turn these Android sticks into Ubuntu/Mint sticks.
3) Students can't be assumed to have the technical know-how to fix up a Salvation Army computer (I wouldn't mind helping out a bit, but I don't want to turn into tech support)
4) A Raspberry Pi costs $70 once you include a case/power supply/etc, and students would receive a big bag of parts.
5) Cheap Windows Tablets have glitches, and don't have an HDMI out.
6) There isn't a good solution to using a cell phone as a desktop computer.

Are any of my assumptions wrong? Are there any other options I'm not considering?
Ubuntu

Shuttleworth Says Snappy Won't Replace .deb Linux Package Files In Ubuntu 15.10 232

darthcamaro writes: Mark Shuttleworth, BDFL of Ubuntu is clearing the air about how Ubuntu will make use of .deb packages even in an era where it is moving to its own Snappy ('snaps') format of rapid updates. Fundamentally it's a chicken and egg issue. From the serverwatch article: "'We build Snappy out of the built deb, so we can't build Snappy unless we first build the deb,' Shuttleworth said. Going forward, Shuttleworth said that Ubuntu users will still get access to an archive of .deb packages. That said, for users of a Snappy Ubuntu-based system, the apt-get command no longer applies. However, Shuttleworth explained that on a Snappy-based system there will be a container that contains all the deb packages. 'The nice thing about Snappy is that it's completely worry-free updates,' Shuttleworth said."
GUI

New Release of the Trinity Desktop Environment 197

mescobal writes: A new release of the Trinity Desktop Environment (TDE) is out. TDE is "a computer desktop environment for Unix-like operating systems with a primary goal of retaining the function and form of traditional desktop computers" which translates into a fully functional KDE 3 style Desktop. Something is missing in the new generation of desktop environments, since some people (perhaps more than "some") feel at home with Gnome 2 or KDE i3. They have repositories for Debian and Ubuntu-based distros. I'm now using it on Ubuntu 15.04, amazed about how well-planned things were in the previous generation of DE. We may have gained some things with Gnome 3 and Plasma 5, but we lost a lot of good features too. TDE brings them back.
Ubuntu

Ubuntu Is the Dominant Cloud OS 167

An anonymous reader writes: According to a new report by Cloud Market, Ubuntu is more than twice as popular on Amazon EC2 as all other operating systems combined. Given that Amazon Web Services has 57% of the public cloud market, Ubuntu is clearly the most popular OS for cloud systems. This is further bolstered by a recent OpenStack survey, which found that more than half of respondents used Ubuntu for cloud-based production environments. Centos was a distant second at 29%, and RHEL came in third at 11%. "In addition to AWS, Ubuntu has been available on HP Cloud, and Microsoft Azure since 2013. It's also now available on Google Cloud Platform, Fujitsu, and Joyent." The article concludes, "People still see Ubuntu as primarily a desktop operating system. It's not — and hasn't been for some time."
Cloud

Ubuntu Core Gets Support For Raspberry Pi 2 GPIO and I2C 59

An anonymous reader writes: Ubuntu Core is a tiny Ubuntu distribution aimed at the Internet of Things, using a new transactional packaging format called Snappy rather than the venerable Debian packaging format. It recently gained support for I2C and GPIO on the Raspberry Pi 2, and a quick demo is given here. Ubuntu's Core support site says that the support for Raspberry Pi 2 isn't yet official, but provides some handy tips for anyone who wants to try it out.
Government

City of Munich Struggling With Basic Linux Functionality 394

jones_supa writes: Just like the city planned a year ago, Munich is still calling for a switch back to Windows from LiMux, their Ubuntu derivative. The councilors from Munich's conservative CSU party have called the operating system installed on their laptops "cumbersome to use" and "of very limited use." The letter from the two senior members of the city's IT committee (PDF in German) asks the mayor to consider removing the Linux-based OS and to install Windows and Office. "There are no programs for text editing, Skype, Office etc. installed and that prevents normal use," the letter argues. Another complaint from councilors is that "the lack of user permissions makes them of limited use." These kind of arguments raise eyebrows, as all that functionality is certainly found on Linux.

Slashdot Top Deals