LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Thursday, January 9th, 2014

    Time Event
    3:13a
    [$] LWN.net Weekly Edition for January 9, 2014
    The LWN.net Weekly Edition for January 9, 2014 is available.
    4:20p
    Security updates for Thursday

    CentOS has updated gnupg (C5: acoustic side channel) and openssl (C6: multiple vulnerabilities).

    Oracle has updated gnupg (OL5: acoustic side channel) and openssl (OL6: multiple vulnerabilities).

    Red Hat has updated gnupg (RHEL5: acoustic side channel) and openssl (RHEL6: multiple vulnerabilities).

    Scientific Linux has updated gnupg (SL5: acoustic side channel) and openssl (SL6: multiple vulnerabilities).

    10:08p
    Stable kernels 3.12.7 and 3.10.26
    Greg Kroah-Hartman has released the 3.12.7
    and 3.10.26 stable kernels. As usual,
    there are lots of changes throughout the tree and users should upgrade.
    11:40p
    Security and the "Internet of Things"
    Two recent articles look at embedded devices and the "Internet of Things" with an eye toward the security problems that abound in that space. Bruce Schneier worries about updates, especially for devices like internet routers: "We have to put pressure on embedded system vendors to design their systems better. We need open-source driver software -- no more binary blobs! -- so third-party vendors and ISPs can provide security tools and software updates for as long as the device is in use. We need automatic update mechanisms to ensure they get installed." Peter Bright at ars technica is more focused on smart TVs, refrigerators, and cars, but sees the same basic problem: "As such, there are only two ways in which smart devices make sense. Manufacturers either need to commit to a lifetime of updates, or the devices need to be very cheap so they can be replaced every couple years.

    If manufacturers won't commit to providing a lifetime of updates—and again, the experience with smartphones is, I think, instructive here—then these smart devices are a liability.
    " Food for thought on a quiet Thursday.

    << Previous Day 2014/01/09
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org