Sergey Bobrov discovered that cookie parsing in Django and Google
Analytics interacted such a way that an attacker could set arbitrary
cookies. This allows other malicious web sites to bypass the
Cross-Site Request Forgery (CSRF) protections built into Django.
Several vulnerabilities were discovered in libarchive, a multi-format
archive and compression library, which may lead to denial of service
(memory consumption and application crash), bypass of sandboxing
restrictions and overwrite arbitrary files with arbitrary data from an
archive, or the execution of arbitrary code.
I'm incredibly excited that this morning at our Ignite conference in Atlanta we launched the newest release of our server operating system - Windows Server 2016! Now that we're ready to share it with the world, I want to take a moment to thank our customers who helped shape this exciting release. Windows Server 2016 is jam-packed with innovation and customer response has been overwhelming, with more than half a million devices running our final Technical Preview which we released five months ago. These customers range from large global enterprises to private cloud hosters to organizations of every size from every corner of the globe.
Update: more confirmation!
With Google's event fast approaching on 4 October, the rumour mill is in full swing. We know we're going to get new 'made by Google' phones, which will drop the Nexus brand in favour of Pixel. However, there's going to be more to watch out for - everything is lining up for 4 October being a major turning point in Android's relatively recent history.
If the rumours are to be believed - and with so many different sources all pointing towards the same thing, you can probably believe them - Google will unveil not just a few new phones, but a new operating system altogether, dubbed Andromeda. And, just like we've been talking about for a long time, this is the operating system that combines Android and Chrome OS into a desktop/laptop operating system.
As 9to5google reports:
Why so many mentions of Nexus 9 specifically in tandem with Andromeda? We asked the same question, and from what we can gather, Google is testing the Chrome OS/Android hybrid on the tablet. An anonymous source has told us of users running early builds of Andromeda on the Nexus 9, but we have not been able to obtain direct confirmation from those users. Why would Google be testing Andromeda on the Nexus 9? We don't know.
But we do know that Andromeda is aimed at making Android better suited for devices like laptops, as well as 2-in-1s (like the unfortunately mediocre Pixel C) and perhaps tablets. Another interesting tidbit to note: it seems that the hidden free form window management feature that popped up in Nougat (but isn't user-facing) could appropriately see its debut with Andromeda. "SurfaceCompositionMeasuringActivity.java" mentions "Detect Andromeda devices by having free-form window management feature."
The fact that Google is working on merging Android and Chrome OS is hardly news, but as more and more details come out, it seems to indeed be the case that Google is working on not just a smartphone operating system or a tablet operating system, but a full-fledged laptop/desktop operating system, complete with the kind of freeform window management we've come to expect from operating systems like MacOS and Windows.
This is further confirmed by AndroidPolice:
Two independent and reliable sources have confirmed to us that Google is planning a new Pixel laptop to be released in Q3 2017. The project, known internally as 'Bison' and by the informal nickname 'Pixel 3,' will likely be the first brand-new device to showcase Google's combined Android / Chrome OS 'Andromeda' operating system in a laptop form factor. Bison, then, would be the culmination of years of work by Google's Pixel team and Google's Android and Chrome OS teams.
We are extremely confident Google plans for the device to run Andromeda. We are also confident that Andromeda is a completely distinct effort from Google's current campaign to bring Android apps to Chromebooks, and that Bison would not be marketed as a Chromebook. Android apps on Chrome OS descended from the ARC project, while Andromeda is a much larger, more ambitious initiative that is being pursued via merging Chrome features into Android, not vice versa. As such, it would be more accurate to say Bison will run Android than Chrome OS, and could finally be Google's internal commitment to releasing Andromeda.
Taking all this into account, a tweet that came out late last week from Hiroshi Lockheimer, SVP of Android, Chrome and Google Play, is quite telling: "We announced the 1st version of Android 8 years ago today. I have a feeling 8 years from now we'll be talking about Oct 4, 2016."
Much like Apple's similar efforts, I'm excited about what's happening on the Android side of things. It's clear by now that Google has very ambitious plans about moving Android forward and scaling it up to work on not just phones and tablets, but on laptops and desktops as well. Up until relatively recently, such endeavours would've been futile, because 'new' operating systems could never challenge the hegemony of Windows and OS X, but in today's world, where more and more especially younger people no longer rely on staples like Microsoft Office, or could get by just fine with the surprisingly good Android and iOS versions of Office, there's an opening for the laptop/desktop world to be shaken up.
Now, a lot of this will, as always, depend on execution. I wouldn't be at all surprised to see Andromeda take a... Less laissez-faire approach to OEM and carrier customisations, and a more Chrome OS-like update policy (which is entirely free from meddling). There's also the question regarding Andromeda's relevance on phones - will it exist alongside 'classic' Android, or will Andromeda replace Android on phones and tablets as well? My guess would be yes - why unite Android and Chrome OS only to end up with another split - but that raises a whole bunch of other questions about possibly docking phones and using them with large screens and other input methods.
I'm ready for 4 October.
Well, file this in the "what the hell is going on" section. Chris Ziegler, long-time The Verge editor (and Engadget before that - he was part of the crew that started both Engadget and The Verge, if I'm not mistaken), had been missing from the site for a few months now - no posts, no tweets, nothing. Today, Nilay Patel revealed why.
First, Chris accepted a position at Apple. We wish him well.
Second, the circumstances of Chris' departure from The Verge raised ethical issues which are worth disclosing in the interests of transparency and respect for our audience. We're confident that there wasn't any material impact on our journalism from these issues, but they are still serious enough to merit disclosure.
Chris began working for Apple in July, but didn't tell anyone at The Verge that he'd taken a new job until we discovered and verified his dual-employment in early September. Chris continued actively working at The Verge in July, but was not in contact with us through most of August and into September. During that period, in the dark and concerned for Chris, we made every effort to contact him and to offer him help if needed. We ultimately terminated his employment at The Verge and Vox Media the same day we verified that he was employed at Apple.
So let me get this straight. One of The Verge's most prominent editors took a job at Apple - which is perfectly fine, we all change jobs - but then did not inform The Verge, continued to work for The Verge, then disappeared, still without informing The Verge, and then it took The Verge weeks to track him down and figure out what happened?
This story is completely bonkers, and I can assure you - this is not the whole story. According to John Gruber, Chris Ziegler is not listed in Apple's employee directory, and I personally have had this confirmed to me as well. Something really strange is going on here.
Black Lab Linux is a desktop distribution based on Ubuntu. The developers of the project have announced a new testing release, Black Lab Linux 8 beta 3. The new beta shifts the distribution's base from Ubuntu 14.04 to 16.04 and features three desktop flavours: GNOME, LXDE and MATE.....
This week in DistroWatch Weekly: Reviews: Uruk GNU/Linux 1.0 News: Snappy Ubuntu Core finds home on Nextcloud Box, Linux users have more video streaming options, Lenovo controversy Questions and answers: Blocking applications at the firewall Torrent corner: Apricity OS, SystemRescueCd, Tails Released last week: Absolute Linux 14.2, Tails....
The PrimTux distribution is a French-language, Debian-based project designed for school teachers and other professionals working in an educational environment. The project has released a new development snapshot, Primtux 2-2016-09-23-beta-2, which is now available for testing. The beta is based on Debian's Stable branch and features mostly changes....