XWayland is actively developed.
XFree86, which is the "standalone DDX" you see on X11 desktops, is being actively maintained.
HN user
XWayland is actively developed.
XFree86, which is the "standalone DDX" you see on X11 desktops, is being actively maintained.
Nowhere (and everywhere).
It is my understanding that XACE doesn't actually provide any security features itself. It just provides the "hooks" to implement security extensions. Like LSM feature in Linux kernel. You have to install a additional X11 extension to do something useful with it.
So the most common X11 security extension is going to be xcsecurity which enables the SECURITY extension. It allows a course permission model were applications can be designated as "Trusted" or "Untrusted". That is going to show up in many Linux distributions.
However all applications default to "trusted" because if they are untrusted they tend to cause lots of other annoying problems and crashes a lot of apps, apparently.
In practice the only place it shows up is if you are using "ssh -X". That uses the security extension by default. Which is why there is also a "ssh -Y" that disables it for applications that it breaks.
This sort of thing is why to fix X11 security you have to give up backwards compatibility and create a new X version.
Oh, wait, that is what the X developers did with Wayland.
probably because there is a ton of open source projects out there with disabled tests in their training data.
Lobbyists turning into government regulator is a lot more common then people realize. It is normal regardless of what party occupies the Whitehouse.
This is one of those things were most people don't realize this goes on because it is rarely reported on. Also who is involved in running administrative agencies is largely irrelevant and very boring subject. It isn't like you get to vote for any of them.
Loabyist-as-head-regulator situation is a reflection of how the administrative state actually works and the role that large public corporations play in that administration.
The 'ELI5' explanation is...
Modern politicians are career politicians. Meaning most of them they start off by getting their law degrees and then immediately pursue a political career using whatever connections they have. This means that they have no real experience of the world outside of law and internal bureaucracy of their parties and governments.
This means they are extremely unqualified at regulating any sort of industry. They just don't know anything about 'the real world'. They know nothing about how to make cars, smelt steel, drill for oil or designing light switches.
It is a similar situation for career administrators in the 400+ administrative agencies in the Federal Government. They get degrees in public administrator or in fields related to their regulatory function. Many of the top administrators will have masters and PHDs. But as anybody with experience in the "private sector" there is a very significant gap between what you can learn in a University setting versus what gets applied in actual practice.
So to fill the gap they require the participation of the major corporations in these industries. They help draft legislation, they have representatives in regulatory committees, the provide the information necessary for economic analysis, and so on and so forth.
This, after 80 years of USA history of the modern administrative state, even involves having corporate representatives participate in party politics, sometimes even becoming politicians, and having positions in the agencies that regulate them.
The term for this is "regulatory capture".
There is a trade off for having highly regulated industries. The main one is that by accepting control of the government the government takes on the responsibility of making sure these corporations remain profitable.
The cost of regulatory overhead is very significant and forms a massive barrier of entry for new businesses. So the established corporations are likely the only corporations that are going to exist for some major industries. Once you lose them they are gone forever.
So the more regulation you have the more protective the government needs to be of these businesses and their profits.
Fixing X11's security would of broken window positioning as well. Since that is a security issue.
The deal here is that the only way to fix X11's security issues is by breaking all those types of workflows and forcing application rewrites to implement them in authenticated ways.
So if you are going have to go and break all that stuff, why not fix a crapload of other problems while you are at it?
Calling Wayland "X13" may have avoided a lot of misunderstandings, but it probably would of caused others.
Yes it was bit uncharitable, but I couldn't resist based on the way he phrased it. It was just a joke.
"Preventing" the vulnerability would indeed require going back to 1994. Since it is a vulnerability that has existed in every display server released since then.
The way X11 developers ended up fixing this is by creating Wayland. This way privileged operations (like keylogging, screen capture, etc) require the cooperation and authentication through the display server.
Microsoft is guilty of giving incompetent administrators enough rope to hang themselves.
That shpool looks like a good idea.
Modern science is derived from Christian Scholasticism from the middle ages so this way of talking and thinking about science as being divinely originated is only unusual in the past couple centuries or so.
It is from that era that they developed systems of rigorous debate, formal logic, and things like peered reviewed papers that we call "the scientific method".
As far as the history of these sorts of mathematical discussions the concept of negative numbers didn't exist until the 15 century. I am sure that each new concept was faced with some resistance and debate on its true nature before it became widely accepted.
So I am sure that somebody looking through the historical record could find all sorts of wild quotes from different theologians trying to grasp new concepts and reconcile them with existing mathmatical standards.
I think that using the term 'application containers' to reference docker and 'system containers' to reference LXC is a bit of a meaningless distinction.
You can 100% host "systems containers" on Docker and you can host "applications" on LXC.
Like if I want a entire OS with it's own init system and users and so on and so forth I can do it it OCI images.
In fact I use it every single day with distrobox on top of Podman using OCI container images.
And it works a hell of a lot better then if I tried to do it on LXC.
"Systems containers" are almost certainly isn't more secure since 'root' means things, even in a container.
Containers just leverage existing Linux namespace isolation techniques to isolate applications.
A good way to think about it is that they act like blinders on a horse. If applications can't "see stuff" or reference items outside of the container then they don't know it exists and don't know how to interact with it.
"application containers" can take advantage of more then just namespaces to isolate applications, such as running them as unprivileged users inside the container's context and thus limiting them from the sort of kernel features that get exposed inside the containers. Or cgroups to limit resource usage and other smaller things like that.
Regardless "Security" and "Containers" really shouldn't be written about in the same paragraph without MAC framework like SELinux in place or additional isolation techniques like VMs.
Although VMs are a lot more like containers then people realize.
Copyright exists to protect publishers, not the people actually doing the work.
Copyright was created for the specific purpose of censorship.
Generally speaking the cells that are welded on are designed to be welded on in the areas were you do the welding. Doing something other then welding on them properly is going to be more unsafe then welding.
The proper tools to do this are not that expensive anymore in the greater scheme of things. It is just a question of whether or not it is worth to do it at the scale you are doing it or pay somebody else to do it.
Of course if you buy cells that are designed to be bolted together then bolt them together.
Of course the bolts, or whatever else provides the threads, on those cells are welded on.
Replace well known, fast, and efficient image to text algorithms that can happily run on my ancient Kindle with a gigantic black box of ML mush that requires tens of thousands of dollars of GPU to run?
Sign me up!
Might as well claim that computer science is obsolete now since LLMs exist while you are at it.
Rabies anti-virus require very carefully handling and refrigeration and thus can be extremely expensive for hospitals to keep in stock.
And, yes, it needs to be applied before symptoms start to appear. Otherwise death is almost for certain.
I doubt this research will lead directly to a better vaccine, but having a better vaccine could save a lot of lives.
One of the effects of ISG15 deficiency is a disease called "Type I interferonopathy".
Among the symptoms of this disease includes things like necrotic lesions and severe multi-systemic damages.
From what I gather the fact that these people are not more susceptible to viral infections was a surprise. Which probably relates to why the doctors in the parent article were investigating its possible anti-viral properties.
AMDgpu is the driver for newer GPUs, radeon is for the older GPUs. This is like circa 7 or 10 years ago.
So it is both driver changes and architectural changes.
There is also AMDGPU-PRO, which is the proprietary version based on AMDGPU. Used to be you'd need it for ROCm, but that hasn't been true for a while not. There really isn't any reason to use the "pro" version anymore, unless you have a some special proprietary app that requires it.
Open source GPU drivers are based on Mesa stack. So they share a common code base and support for things like Vulkan.
So it is sorta similar to how DirectX works. With old-school OpenGL drivers each stack was proprietary to the GPU manufacturer so there was lots of quirks and extensions that applied to only one or another GPU. That is one of the reasons DirectX displaced OpenGL in gaming... Microsoft 'owned' DirectX/Direct3d stack.
Well the open source equivalent to that is Mesa. Mesa provides APi support in software and it is then ported to each GPU with "dri drivers".
For gaming things have improved tremendously with "Proton", which is essentially Wine with vastly improved Direct3D support.
This is accomplished with "DXVK", which is a Direct3D to Vulkan translator.
This way Linux essentially gets close to "native windows speed" for most games that support proton in one way or another.
Which means that most games run on Linux now. Probably over 75% that are available on Steam, although "running" doesn't mean it is perfect.
One of the biggest problems faced with Linux gaming nowadays is anti-cheat features for competitive online games. Most of the software anti-piracy and anti-cheating features games use can technically work on Linux, but it is really up to the game manufacturer to make it work and support it. Linux gamers can sometimes make it work, but also they get flagged and booted and even accounts locked for being suspected of cheating.
Things have changed a lot since Steam deck. Especially in the last 3 or 4 years.
Mobile users suffer more problems then people with dedicated desktop GPUs, but it still gotten a lot better.
The one thing to be careful about AMD GPUs is that for most GPU OEMs AMD is just a after thought. So they get sub-par QA and heatsinks compared to their more popular Nvidia models.
It is best to go with card makers that only sell AMD GPUs, like Sapphire, PowerColor, and XFX. I am partial to Sapphire.
With the advent of Steam deck and Valve putting time and effort into AMD GPU drivers the AMD GPU is really the best option for Linux when it comes to general desktop stuff and gaming.
The days of Nvidia proprietary drivers being a safe bet is long gone. Especially for any sort of Wayland desktop, but it still applies to X11.
Intel drivers should be good as well, since they use the same Mesa code base.
With the ROCm stuff no longer depending on AMD Pro then there is not going to be any reason to step away from the default GPU drivers provided by your distro, provided they are relatively new.
While I am sure that there are still going to be professional-grade proprietary apps that recommend Nvidia... for most of us the only reason to actually go and choose Nvidia on Linux is because of CUDA. And, personally, I would rather lease time on the cloud or have a second GPU work horse PC separate from my desktop for that.
Unfortunately Nvidia is, by far, the most popular option for Windows users. Over 4:1 ratio according to Steam statistics.
So most new Linux users are still going to have to suffer through dealing with their GPU drivers.
There was a similar situation going on with Craigslist and a couple other websites. I don't remember the details.
But the basic gist is that people were selling illicit sex services on these websites, much of which was very unsavory. So there was a big push to make these websites liable for users engaging in that sort of communications.
It succeeded and these websites shutdown the services these people were using, which in turn destroyed or otherwise undermined numerous investigations going on all around the country to prosecute these criminals.
On a side note when people operate privaty-ran "to catch a predator" sting operations in the USA... One particularly successful group was asked why all their targets tend to be from more conservative leaning parts of the country. The non-obvious answer to that is that in many other places around they country they don't bother because they can't get the police to show up and arrest the people they find.
So when you have certain governments refusing to even investigate sexual crimes involving minors that they have happening in their own communities it seems to be a bit disingenuous when they claim they need to eliminate privacy to go after much more difficult targets on the internet.
Water rights is a huge deal in Colorado. It is in the state constitution and there has been a lot of government corruption around the issue.
It is common for people to buy up land just for the water rights, then transfer that water rights to other property. So if you search for land in Colorado it isn't unusually to find one plot of land in the millions and then another one a few miles away that is almost free in comparison. This is often due to the water rights associated with that property. The expensive land can be used commercially for things like farming, the other cannot.
And there have been cases of governments using tax money to buy up property just so they can use the water rights to help out private ventures, like building suburbs or golf courses without the knowledge or consent of tax payers.
Also it is pretty normal anywhere in the country that local governments react poorly from aggressive demands from people, especially when they are not voters.
All in all it is a nasty business and making sure you know exactly where your water is coming from, how you are going to pay for it, and what your rights are to it, and what you are allowed to use it for all need to be factored in heavily when moving out to the desert there.
If you are using podman "rootless" mode prior to 5.3 then typically you are going to be using the rootless networking, which is based around slirp4netns.
That is going to be slower and limited compared to rootful solutions like incus. The easy work around is to use 'host' networking.
If you are using rootful podman then normal Linux network stack gets used.
Otherwise they are all going to execute at native speed since they all use the same Linux facilities for creating containers.
Note that from Podman 5.3 (Nov 24) and newer they switched to "pasta" networking for rootless containers. Which is a lot better, performance wise.
edit:
There are various other tricks you can use for improving podman "rootless" networking, like using systemd socket activation. This way if you want to host services this way you can setup a reverse proxy and such things that runs at native speeds.
yeah Quadlets are a pretty reasonable improvement.
It was introduced in Podman 4.4 which is circa 2023.
And it takes a while for podman to get up to date in non-Redhat related distributions. Like Debian Stable was stuck on 4.3 until Trixie release this month.
So unless you are using Fedora and friends or something like Arch it is kinda hard time going for podman users. Which is unfortunate.
Docker has a bit of a advantage here because they encourage you to use their packages, not the distribution's.
Here is a example Quadlet configuration i use for syncthing that I run out of my home:
[Unit]
Description=syncthing
After=default.target
[Container]
ContainerName=syncthing
Image=docker://docker.io/syncthing/syncthing:latest
Volume=/home/lothar/.syncthing:/var/syncthing:z
Volume=/home/lothar:/var/home/:rslave
Network=host
Pull=always
Environment=PUID=1000
Environment=PGID=1000
Environment=STGUIADDRESS=''
UserNS=keep-id:uid=1000,gid=1000
SecurityLabelDisable=true
[Install]
WantedBy=multi-user.target default.target
This then gets dropped into ~/.config/containers/systemd/syncthing.containerAnd it is handled automatically.
This configures the syncthing container to always get updated on each startup, bypasses the "rootless" networking by using host networking (rootless networking is limited and slow), and the default Sync dir ends up in ~/.syncthing where as I can add more sync'd directories to my real home directory by directing it to /var/home/ in the syncthing web ui.
As you can see the arguments under "container" is just really capitalized versions of docker/podman arguments.
Also if you like GUIs the podman desktop has support for helping to generating quadlets. Although I haven't tried it out yet.
For me LLM is just a rubber duck that talks back.
It is very stupid and is usually wrong in some meaningful way, but it can help break logjams in my thinking. Giving me clues that might be missing. Sort of like how writing gibberish is sometimes effective for writers to break writer's block.
It is also nice for generating boiler plate code for languages that I am not super familiar with.
The biggest problems I have with current state of the art LLMs is that errors compound. Meaning that I only really get somewhat useful answers when starting out with the first few questions or the first couple times I ask it to review some code. The longer the session lasts the more la-la land answers I get.
It is a game of odds. I expect that with systemd and quadlets it is going to particularly useless because there just isn't that many examples out there. It can only regurgitate what it is trained with so if something isn't widely used and checked into code bases it is trained on then it can't really do anything with it.
Which is why it is nice for a lot of common coding tasks, because a lot of code is just same thing tens of thousands people did before for only slightly different contexts and is mostly boilerplate.
The biggest problem with Western Governments, and the reason this sort of thing is going on, is the result of the "professionalization" of the political classes.
Earlier in the 20th century politicians tended to be people established in their own right outside of government. Meaning that they tended to be well known and successful outside of government and decided to get involved in politics as a part time or second career. Get involved, represent their community interests, etc.
Which meant that they had experience outside of government they could bring in with them.
Nowadays politicians tend to be "professionals", meaning that they went to school and got law degrees and started their political careers at a young age. They got started in government due to political and family connections, and successful ones learned the bureaucracy of government and the rules (spoken and unspoken) established by their respective political parties and sort of wormed their way up the system from the "inside".
This has created a insular culture. They are "professionals" without any sort of professional regulation or professional organizations or professional standards. The only regulation comes from themselves and their own political parties.
This has created a class of "leaders" that are exceptionally good at understanding the internal beaucracy and party structure which their lives are based on, but are pretty much incapable of connection and communicating with normal people.
The people that make or break them as successful politicians is largely their peers, not the public.
This creates a sort of "ivory tower intellectual" type culture in government and in the top ranks of large corporations. There is the "inner party" of people that set the intellectual and cultural tones that other party members are expected to adhere to, and then a "outer party" that are their functionaries in big business, media, and government, that are expected to put policies and goals established by the "inner party" into motion.
And because of this they are really unable to communicate well with the public or engage in debates over important matters.
They take personal offense and look down on the public when they are questioned. Seeing themselves as experts and professionals while the rest of the public really are just kinda ignorant.
Sort of like how a Dentist must feel when a patient starts arguing loudly with them over whether or not they need a root canal.
Because of all of this, especially with the inability to communicate or relate deeply with the public, they tend to resort to tactics like name calling and censorship.
Which means that there is a strong tendency to label members of the public as "right wing" or "extremist" and try to work with social media companies to "quiet the rabble".
Sort of like how a frustrated and abusive mother resorts to yelling "just shut up already" repeatedly at their toddlers for endlessly crying.
This is one of those "when the only tool you have is a hammer every problem looks like a nail". The "protect the children" is just a excuse to get the regulatory ball rolling and help ensure that they can track and intimidate members of the public they see as obstacles or sources of discontent.
The proper way is to have a idea of what it normally is before you need to troubleshoot issues.
What is a 'good load' depends on the application and how it works. Some servers something close to 0 is a good thing. Other servers a 10 or lower means something is seriously wrong.
Of course if you don't know what is a 'good' number or you are trying to optimize a application and looking for bottlenecks then it is time to reach for different tools.
I think this is less AI and more PEBKAC
Don't worry.
If CIA ends up hurting for money they can go back to using Israel to sell weapons to Iran and selling cocaine to intercity youth.
Like the good old days.
The only desktop to have real meaningful large-ish/professional usability testing is Gnome. And that is only a couple times.
The first time was financed by Sun Microsystems in 2001 for Gnome 1.x and the result was Gnome 2.
The second time was financed by Novell around 2005 or so for their attempt to compete with Microsoft with Novell Linux Desktop. Unfortunately for them the real beneficiary of the improvements that results from their work was Canonical's Ubuntu.
Since then there have been numerous smaller/informal/ad-hoc attempts for both KDE and Gnome.
The results of all of this, of course, is that many "Linux users" believe that Gnome is the result of a conspiracy between IBM, Redhat, and maybe even Microsoft to "destroy the Linux desktop".
So that is fun.
The real success story, from what I can tell, is Blender.
They successfully revamped their user interface without a huge budget. Although it was still financed somewhat by some EU initiative, IIRC. They accomplished this by getting developers sat down next in a big room to actual 3D artists working together to produce a animated feature.
By physically placing users next to devs and having them work together, likely with a great deal of humility and openness, they managed to transform their UI into something that was actually decent.
This is probably a model that can be duplicated by other open source developers, although finding the right type of technical users not experienced in using said software willing to participate is going to always be a major challenge.