Mr_Figtree

joined 1 year ago
 

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

10
This Week in Rust 506 (this-week-in-rust.org)
[–] [email protected] 0 points 1 year ago (1 children)

Does the certificate have a basic constraints extension with CA:TRUE set? Firefox doesn't allow that for certificates used as ‘end entity’ certificates. You'll want to re-generate the certificate without the extension.

 

Update on what happened across the GNOME project in the week from July 21 to July 28.

19
This Week in Rust 505 (this-week-in-rust.org)
18
This Week in Rust 505 (this-week-in-rust.org)
 

Update on what happened across the GNOME project in the week from July 15 to July 22.

[–] [email protected] 2 points 1 year ago

so I can totally ditch chromium/electron

GNOME Web isn't Chromium-based and does support PWAs, so it might work for your usecase.

[–] [email protected] 11 points 1 year ago

Someone I know recently switched from automatic bathroom lights to manual ones. Remembering to turn them on isn't an issue, but months later everyone still forgets to turn them off.

 

The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software.

What's in 1.71.0 stable

  • C-unwind ABI
  • Debugger visualization attributes
  • raw-dylib linking
  • Upgrade to musl 1.2
  • Const-initialized thread locals
 

The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software.

What's in 1.71.0 stable

  • C-unwind ABI
  • Debugger visualization attributes
  • raw-dylib linking
  • Upgrade to musl 1.2
  • Const-initialized thread locals
[–] [email protected] 10 points 1 year ago (1 children)

And .box has been registered as a generic TLD now, so you could run into external .box domains.

[–] [email protected] 25 points 1 year ago (3 children)

They're not going to have open signups. It's government agencies only. Not that there's technically anything stopping Germans from joining the PR departments of our government agencies…

[–] [email protected] 11 points 1 year ago (4 children)

So what you're saying is that Twitter successfully kept out a bad actor.

It's a shame that most of the users they have left are also in that category, but hey, they seem to be working on it.

[–] [email protected] 1 points 1 year ago

As far as I know you can't set exceptions on mobile Firefox yet. It's rather annoying.

[–] [email protected] 63 points 1 year ago (5 children)

These are all fine in the US, but in other countries not carrying proof of identity can get you into some trouble, as can refusing to talk to the police. Know your local laws.

[–] [email protected] 2 points 1 year ago

Ah, I see. Looks like that should enable people to take individual domains off the list, too, if they want their extensions to work on just some of them.

 

One's a bit raw and touchy, but the other is vintage stuff, brought up to date

[–] [email protected] 3 points 1 year ago (2 children)

Is there a list somewhere of these “quarantined” domains?

 

One hundred weeks ago, on Friday 16 July 2021, “This Week in GNOME” was launched - the first post was "#1 Scrolling in the Dark".

Since then TWIG has grown into a vibrant community, and has become a weekly ritual for many people—both for developers who share their work, and for curious readers who want to follow the development of GNOME.

view more: next ›