All posts by jzb

Hardening the Firefox frontend

Post Syndicated from jzb original https://lwn.net/Articles/1016978/

Tom Schuster, Frederik Braun, and Christoph Kerschbaumer have
published an article
on the Firefox Security team’s Attack & Defense
blog that explains recent work to harden Firefox’s frontend code.

We have rewritten over 600 JavaScript event handlers to mitigate XSS
and other injection attacks in the main Firefox user interface. This
mitigation will ship in Firefox 138. However, blocking the execution
of scripts in the parent process is not the end – we will expand this
technique to other contexts in the near future. There is still more
work to do as the UI requires JavaScript APIs with a high level of
privileges. However: We still eliminated a whole class of attacks,
significantly raising the bar for attackers to exploit Firefox.

[$] Debian Project Leader election 2025 edition

Post Syndicated from jzb original https://lwn.net/Articles/1016107/

Four candidates have stepped up to run in the 2025 Debian Project
Leader
(DPL) election. Andreas
Tille
, who is in his first term as DPL, is running again. Sruthi
Chandran
, Gianfranco
Costamagna
, and Julian Andres
Klode
are the other candidates running for a chance to serve a
term as DPL. The campaigning phase ended on April 5, and Debian
members began voting on April 6. Voting ends on
April 19. This year, the campaign period has been lively and
sometimes contentious, touching on problems with Debian team
delegations and finances.

OpenSSH 10.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1016924/

OpenSSH
10.0
has been released. Support for the DSA signature algorithm,
which was disabled by default beginning in 2015, has been
removed. Other notable changes include using the post-quantum algorithm mlkem768x25519-sha256
for key agreement by default, support for systemd-style socket
activation in Portable OpenSSH, and moving code for user
authentication from the sshd-session binary to the new
ssh-auth binary:

Splitting this code into a separate binary ensures that the crucial
pre-authentication attack surface has an entirely disjoint address
space from the code used for the rest of the connection. It also
yields a small runtime memory saving as the authentication code will
be unloaded after the authentication phase completes. This change
should be largely invisible to users, though some log messages may now
come from “sshd-auth” instead of “sshd-session”. Downstream
distributors of OpenSSH will need to package the sshd-auth binary.

The release notes also warn that “software that naively matches
versions using patterns like “OpenSSH_1*”
” may be confused by the
new version number.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1016923/

Security updates have been issued by Debian (lemonldap-ng, libbssolv-perl, and phpmyadmin), Fedora (augeas, mariadb10.11, and thunderbird), Oracle (gimp, libxslt, python3.11, python3.12, tomcat, and xorg-x11-server), Red Hat (expat, grafana, opentelemetry-collector, and webkit2gtk3), SUSE (azure-cli-core, doomsday, kernel, and poppler), and Ubuntu (dotnet8, dotnet9, erlang, and poppler).

FreeDOS 1.4 released

Post Syndicated from jzb original https://lwn.net/Articles/1016849/

Version
1.4
of FreeDOS has been
released. This is the first stable release since 2022, and
includes improvements to the Fdisk hard-disk-management program, and
reliability updates for the mTCP set of TCP/IP applications for
DOS.

This version was much smoother because Jerome Shidel, our
distribution manager, had an idea after FreeDOS 1.3 that we could have
a rolling test release that collected all of the changes that people
make over time. Previous to this, each new FreeDOS distribution (like
1.0, 1.1, 1.2, and 1.3) required bundling up packages into a “release
candidate,” and we would go through several iterations of updating the
release candidates.

Jerome’s method of building the FreeDOS distribution made it easier
to automate a test release, which we decided to update every month. As
the test releases accumulated enough changes to warrant a release, we
could then make the next test release a “release candidate” which
would iterate to the next version of the FreeDOS distribution. Since
2022, we’ve released monthly test releases. Thanks Jerome!

LWN covered FreeDOS
last year for its 30th anniversary.

[$] Taking notes with Joplin

Post Syndicated from jzb original https://lwn.net/Articles/1016400/

Joplin is an open-source
note-taking application designed to handle taking many kinds of notes,
whether it is managing code snippets, writing documentation, jotting
down lecture notes, or drafting a novel. Joplin has Markdown support,
a plugin system for extensibility, and accepts multimedia content,
allowing users to attach images, videos, and audio files to their
notes. It can provide synchronization of content across devices using
end-to-end encryption, or users can opt to stick to local storage
only. Joplin even offers a command-line
version
for terminal-based usage. Joplin
3.2
, the most recent feature release, brought long-awaited
multi-window support, multi-column layouts, enhanced accessibility,
and theme detection.

[$] Catching up with calibre

Post Syndicated from jzb original https://lwn.net/Articles/1015226/

Saying that calibre is
ebook-management software undersells the application by a fair
margin. Calibre is an open-source Swiss Army knife for ebooks that can
be used for everything from creating ebooks, converting ebooks from
obscure formats to modern formats like EPUB, to serving up an ebook
library over the web. The most recent major release, calibre 8.0,
brings a better text-to-speech engine, a tool for creating audio
overlays when authoring ebooks, support for profiles in the ebook
viewer, and more.

Thunderbird plans “Thundermail” email and other services

Post Syndicated from jzb original https://lwn.net/Articles/1016219/

Ryan Sipes has announced
efforts to expand Thunderbird’s offerings with web services to
“enhance the experience of using Thunderbird“.

The Why for offering these services is simple. Thunderbird loses users
each day to rich ecosystems that are both clients and services, such
as Gmail and Office365. These ecosystems have both hard vendor
lock-ins (through interoperability issues with 3rd-pary clients) and
soft lock-ins (through convenience and integration between their
clients and services). It is our goal to eventually have a similar
offering so that a 100% open source, freedom-respecting alternative
ecosystem is available for those who want it.

The planned services include hosted email, appointment scheduling,
a revival of Firefox Send,
and (of course) an AI assistant based on a partnership with Flower AI. The AI features will
“always be optional for use by people who want them“. Sipes is
managing director of product for Thunderbird’s parent organization, MZLA
Technologies Corporation
. LWN covered his
GUADEC 2024 keynote last July.

Introducing Fedora Project Leader Jef Spaleta

Post Syndicated from jzb original https://lwn.net/Articles/1016217/

Outgoing Fedora Project Leader (FPL) Matthew Miller has announced
his successor, Jef Spaleta.

Some of you may remember Jef’s passionate voice in the early Fedora
community. He got involved all the way back in the days of fedora.us,
before Red Hat got involved. Jef served on the Fedora Board from July
2007 through the end of 2008. This was the critical time after Fedora
Extras and Fedora Core merged into one Fedora Linux where, with the
launch of the “Features” process, Fedora became a truly community-led
project.

Spaleta will be joining Red Hat full time in May and Miller will be
formally handing off FPL duties at the Flock conference in
June.

PorteuX 2.0 released

Post Syndicated from jzb original https://lwn.net/Articles/1016216/

Version
2.0
of PorteuX, a distribution based on Slackware Linux, has been
released. This release adds the ability to test experimental Wayland
sessions for the Cinnamon, LXQt, and Xfce desktops. PorteuX 2.0
updates the Linux kernel to 6.14 and includes many package updates and
bug fixes. Users have the choice of PorteuX stable or its rolling release
called current. See the install.txt
for instructions on installing PorteuX to disk.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1016205/

Security updates have been issued by Debian (firefox-esr, jetty9, openjpeg2, and tomcat9), Fedora (dokuwiki, firefox, php-kissifrot-php-ixr, php-phpseclib3, and rust-zincati), Red Hat (kernel and pki-core), Slackware (mozilla), SUSE (apparmor, atop, docker, docker-stable, firefox, govulncheck-vulndb, libmodsecurity3, openvpn, upx, and warewulf4), and Ubuntu (inspircd, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-ibm,
linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oem-6.8, linux-oracle,
linux-oracle-6.8, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure-6.8, linux-hwe-6.8, linux-raspi, linux-realtime, nginx, phpseclib, and vim).

[$] Fedora change aims for 99% package reproducibility

Post Syndicated from jzb original https://lwn.net/Articles/1014979/

The effort to ensure that open-source software is reproducible has been
gathering steam over the years, and gaining traction with major Linux
distributions. Debian, for example, has been working toward reproducible
builds
for more than a decade; it can now
produce official
live CDs
of the current stable release that are
reproducible. Fedora started on the path much later, but it has
progressed far enough that the project is now considering a change
proposal
for the Fedora 43 development cycle, expected to be
released in October, with a goal of
making 99% of Fedora’s package builds reproducible. So far, reaction
to the proposal seems favorable and focused primarily on how to
achieve the goal—with minimal pain for packagers—rather than whether to attempt it.

Edmundson: a modern Plasma Login Manager

Post Syndicated from jzb original https://lwn.net/Articles/1015763/

KDE contributor David Edmundson has published
a blog post about improving KDE Plasma’s login experience by
replacing SDDM
with a new Plasma Login Manager.

It’s worth stressing nothing is official or set in stone yet,
whilst it has come up in previous Plasma online meetings and in the
2023 Akademy. I’m posting this whilst starting a more official
discussion on the plasma-devel mailing list.

Oliver Beard and I have made a new mutli-process greeter, that uses
the same startup mechanism as the desktop session. It doesn’t have all
the features that we propose at the start of the blog, but an
architecture where features and services can be slowly and safely
added.

That discussion is here
for those who would like to follow along. The prototype is currently
in two repositories: plasma-login
for the frontend work, and plasma-login-manager,
which is a fork of SDDM.

Bypassing Ubuntu’s user-namespace restrictions

Post Syndicated from jzb original https://lwn.net/Articles/1015649/

Ubuntu 23.10 and 24.04 LTS introduced a feature using AppArmor to
restrict access to user namespaces. Qualys has reported
three ways to bypass AppArmor’s restrictions and enable local users to
gain full administrative capabilities within a user namespace. Ubuntu
has followed up with a post
that explains the namespace-restriction feature in detail, and says
these bypasses do not constitute security vulnerabilities.

While a superficial observation of the application of user namespaces may indicate privileged (root level) access, this is a fictitious state that is operating as expected, with access control still mapped to the real (root namespace) user’s permissions. As such, these bypasses do not enable more access than what the default Linux kernel
unprivileged user namespace feature allows in most Linux
distributions. They do, however, demonstrate limitations that we are
looking to address in order to strengthen existing protections against
as-of-yet-unknown Linux kernel vulnerabilities.

LWN covered Ubuntu 24.04 LTS last May.

Security updates for Thursday

Post Syndicated from jzb original https://lwn.net/Articles/1015589/

Security updates have been issued by Arch Linux (exim), Debian (exim4, ghostscript, and libcap2), Red Hat (container-tools:rhel8), SUSE (apache-commons-vfs2, argocd-cli, azure-cli-core, buildah, chromedriver, docker-stable, ed25519-java, kernel, kubernetes1.29-apiserver, kubernetes1.30-apiserver, kubernetes1.32-apiserver, libmbedcrypto7, microcode_ctl, php7, podman, proftpd, tomcat10, and webkit2gtk3), and Ubuntu (containerd, exim4, mariadb, opensaml, and org-mode).