Mr_Figtree

joined 2 years ago
 

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

1
This Week in Rust 506 (this-week-in-rust.org)
18
This Week in Rust 505 (this-week-in-rust.org)
[–] [email protected] 11 points 2 years ago

Someone I know recently switched from automatic bathroom lights to manual ones. Remembering to turn them on isn't an issue, but months later everyone still forgets to turn them off.

 

The Rust team is happy to announce a new version of Rust, 1.71.0. Rust is a programming language empowering everyone to build reliable and efficient software.

What's in 1.71.0 stable

  • C-unwind ABI
  • Debugger visualization attributes
  • raw-dylib linking
  • Upgrade to musl 1.2
  • Const-initialized thread locals
[–] [email protected] 5 points 2 years ago (1 children)

And .box has been registered as a generic TLD now, so you could run into external .box domains.

[–] [email protected] 2 points 2 years ago

They're not going to have open signups. It's government agencies only. Not that there's technically anything stopping Germans from joining the PR departments of our government agencies…

[–] [email protected] 1 points 2 years ago (4 children)

So what you're saying is that Twitter successfully kept out a bad actor.

It's a shame that most of the users they have left are also in that category, but hey, they seem to be working on it.

[–] [email protected] 63 points 2 years ago (5 children)

These are all fine in the US, but in other countries not carrying proof of identity can get you into some trouble, as can refusing to talk to the police. Know your local laws.

[–] [email protected] 1 points 2 years ago (1 children)

Looking at it optimistically, maybe we'll start seeing some improvements in documentation as everything else becomes useless.

[–] [email protected] 0 points 2 years ago (1 children)

Both of the RHEL clones, Rocky Linux and AlmaLinux, build images for the Raspberry Pi 4. Those should fit your needs nicely if you're looking for something familiar and stable.

[–] [email protected] 1 points 2 years ago
[–] [email protected] 4 points 2 years ago

Ah, I see. Maybe one of the offices they're actually using and also not paying the rent on next? A man can dream.

[–] [email protected] 18 points 2 years ago (5 children)

So far it doesn't look like he's getting away with it. Ad revenue is down 60% compared to last year, it doesn't look like there is enough revenue from subscriptions to make up for that, and they're being evicted from one of their offices.