141 karma · joined March 26, 2023
They can't, because (responsible) security disclosures are private, _not public_. That's the whole point of the system: notify the developers in private ahead of time (usually 30, 60 or 90 days) so they can write, test and roll-out the fixes before you release the info to the whole world. This is to minimize the time between when bad actors gain access to the exploits vs. when users install the patch. So "keeping up on security disclosures" cannot ever be a 'pull' process.
Usually the maintainers of the big distros are part of (private) security mailinglists and receive such info. Just not in this case it seems.
Great games, but all you listed are barely 3 years old – can something that young already be considered a "classic"?
But there's a statue with that star (https://de.wikipedia.org/wiki/Carl_Friedrich_Gau%C3%9F#/medi...)
Later he proved that all n-gons with $n=2^k*p_1…*p_r$ where the p_i are Fermat-primes (2^(2^m)+1 prime, today we only know of 3, 5, 17, 257, 65537) are constructible. The opposite direction, i.e. all other n are not constructible, was only a few years later proved. Look up "Theorem of Gauss-Wantzel". I only skimmed the proof, but it seems to generalize the concept of constructing the cos of the angle with "Galois-Theory".
(edit: or see https://en.wikipedia.org/wiki/Constructible_polygon)
(I also don't think they should be allowed to cite things said 5 years ago as a reason to ban someone today. How could that still be relevant?)
Anyway, the 10c/page (A4 b/w) is still a good estimate, at least when I looked pre-pandemic (it might've increased slightly to 12 or 15c by now). A lot of cities, especially those with a University, have dedicated small "Copyshops" where you can walk in and get your 100+ pages thesis printed and bound within 20min. So the prices and service are aimed mostly at Students. It's true colored pages are significantly more expensive than b/w, but overall that's still cheaper.
edit: ah, the number of 8,535 is in the beginning of the notice itself, but due to the large number they did not list all of the forks, I guess the listed ones are the only non-forked repos.
edit: also this was heavily obfuscated in some binary files that were marked as test files ("good" and "bad" xz compressed test file). No way to spot this if you don't know what you're looking for.
> Apparently the backdoor reverts back to regular operation if the payload is malformed or *the signature from the attacker's key doesn't verify*.
emphasis mine, note the "signature of the attacker's key". So unless that key is leaked, or someone breaks the RSA algorithm (in which case we have far bigger problems), it's impossible for someone else (researcher or third-party) to exploit this backdoor.
A lot of that land is inhabited, or at least owned by citizens or companies. Pretty sure they would be against changing citizenship or losing their land.
And for government owned, uninhabited land: land is worth a lot more than its surface area. You can have natural resource of all kinds underneath – maybe some that are technically or financially not feasible to mine, yet, but may be in a few decades. (Just think of the massive oil fields in the arctic that'll soon be accessible to Canada and Russia) If it's a coastal area it massively extends your country's EEZ – that's why there are a lot of border conflicts around tiny rocks in the ocean. That's also the prime reason why Russia will forever hang onto Sakhalin island. (Plus Japan already is not doing much with Hokkaido, I doubt they'd do anything worthwhile on Sakhalin except forestery and military areas).
And then there's 'owner' in the software dev sense, i.e. the one that ultimately decides which direction the project takes, what patches to merge etc. is sometimes referred to as "product owner".
Unfortunately I don't know any numbers re theft, but it's still running 5 years later. Of course being in a suburban area helps.