LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Friday, May 23rd, 2014

    Time Event
    3:11p
    Friday's security updates

    CentOS has updated mysql55-mysql (C5; C6: multiple vulnerabilities).

    Debian has updated torque (code execution).

    Gentoo has updated libyaml (code execution).

    Mageia has updated chromium-browser-stable (multiple vulnerabilities) and webmin (multiple vulnerabilities).

    openSUSE has updated perl-LWP-Protocol-https (12.3, 13.1: certificate verification bypass), libXfont (12.3, 13.1: multiple vulnerabilities), libxml2 (11.4: denial of service), mumble (12.3, 13.1: denial of service), and strongswan (11.4: multiple vulnerabilities).

    Oracle has updated mysql55-mysql (O5: multiple vulnerabilities).

    Red Hat has updated mysql55-mysql (RHEL5; RHEL6: multiple vulnerabilities).

    Scientific Linux has updated mysql55-mysql (SL5: multiple vulnerabilities).

    10:37p
    Warner: The new Sync protocol

    At his blog, Mozilla's Brian Warner describes the revised Firefox Sync protocol that was rolled out with the recent Firefox 29 release, including the design decisions that the project learned from supporting the previous incarnation. In the old system, Mozilla discovered, "users *thought* their email and password would be sufficient to get their data back, but in fact you need access to a device that was already attached to your account. This made it unsuitable for people with a single device, and made it mostly impossible to recover from the all-too-common case of losing your only browser. It also confused people who thought email+password was the standard way to set up a new browser." This eventually led to the new "Firefox Accounts" system, which incorporates two tiers of data protection. Warner also describes various factors of migrating between the old Sync and the new Sync. "If you’re still running FF28, the FF24 ESR (Extended Support Release), or another pre-FF29 browser, you can still use the pairing flow to connect additional old browsers. We’ll support this flow until at least the end of the ESR maintenance period (14-Oct-2014), maybe a bit longer, but eventually we’ll shut down the servers necessary to support the old pairing flow, and pairing will stop working." It sounds like still more features may be in store further down the road.

    << Previous Day 2014/05/23
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org