96
submitted 3 days ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
132
submitted 5 days ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
279
29
submitted 6 days ago by KarnaSubarna@lemmy.ml to c/firefox@lemmy.ml

Summary

We have rewritten over 600 JavaScript event handlers to mitigate XSS and other injection attacks in the main Firefox user interface. This mitigation will ship in Firefox 138. However, blocking the execution of scripts in the parent process is not the end - we will expand this technique to other contexts in the near future. There is still more work to do as the UI requires JavaScript APIs with a high level of privileges. However: We still eliminated a whole class of attacks, significantly raising the bar for attackers to exploit Firefox. In fact, we hopefully just broke someone’s exploit chain.

522
189
submitted 2 weeks ago* (last edited 2 weeks ago) by KarnaSubarna@lemmy.ml to c/firefox@lemmy.ml
23
submitted 2 weeks ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
243
submitted 3 weeks ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
147
GNOME 48 Release Notes (release.gnome.org)
submitted 3 weeks ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
183
submitted 4 weeks ago by KarnaSubarna@lemmy.ml to c/firefox@lemmy.ml
86
submitted 1 month ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml

"some workloads saw improvements, overall system performance slightly declined, and binary sizes increased." So -O3 isn't paying off in the Ubuntu packaging world for now and will be reverted soon.

32
submitted 1 month ago by KarnaSubarna@lemmy.ml to c/firefox@lemmy.ml
[-] KarnaSubarna@lemmy.ml 45 points 8 months ago* (last edited 8 months ago)

In India, the share of Linux desktop became double just within one year (from 8% to 16%). I only hope this data is right.

https://gs.statcounter.com/os-market-share/desktop/india/#monthly-202301-202407

[-] KarnaSubarna@lemmy.ml 34 points 8 months ago

Yes, but then who will dare to buy from them in future?

[-] KarnaSubarna@lemmy.ml 39 points 9 months ago

I moved to Mozilla Thunderbird long ago https://www.thunderbird.net/en-US/

[-] KarnaSubarna@lemmy.ml 43 points 1 year ago

UX is a very subjective matter.

[-] KarnaSubarna@lemmy.ml 53 points 1 year ago

Bad news is that it is not clear at this point whether Mozilla is going to go forward with the implementation. A post on Reddit by one of the project members suggests that the build is a "rough proof-of-concept". Some features tested in the build "did not survive". It is unclear which did not, as they are not mentioned. Mozilla is, however, implementing those that survived the cut into Firefox. Again, the poster does not mention which those are. It is also not verified that the poster is actually a member of the project team, so take this with a grain of salt as well.

[-] KarnaSubarna@lemmy.ml 122 points 1 year ago
  • Careful choice of program to infect the whole Linux ecosystem
  • Time it took to gain trust
  • Level of sophistication in introducing backdoor in open source product

All of these are signs of persistent threat actors aka State sponsor hacker. Though the real motive we would never know as it's now a failed project.

[-] KarnaSubarna@lemmy.ml 48 points 1 year ago* (last edited 1 year ago)

There is a work-in-progress version of Firefox for iOS with Gecko engine.

But, there is also a challenge that Mozilla is facing as Apple is still trying to make life of developers of other browsers as difficult as possible.

So, not sure how the whole thing will turn out.

[-] KarnaSubarna@lemmy.ml 30 points 1 year ago

Known issues and limitations

Currently, Intel x86_64 is the only supported host platform.
    AMD will most likely work too but is considered experimental at the moment.
Linux is required as a host operating system for building and running VirtualBox KVM.
Starting with Intel Tiger Lake (11th Gen Core processors) or newer, split lock detection must be turned off in the host system. This can be achieved using the Linux kernel command line parameter split_lock_detect=off or using the split_lock_mitigate sysctl.

Source: https://github.com/cyberus-technology/virtualbox-kvm

[-] KarnaSubarna@lemmy.ml 36 points 1 year ago* (last edited 1 year ago)

This is how I explained it to one of my friends who is/was definitely a member of “I’ve got nothing to hide” club -

  • Suppose you are in a pay-to-use toilet minding your own Business.
  • That pay-to-use toilet is managed by a public/private entity called ToiletBook.
  • Suddenly you notice a (hidden) camera in the room.
  • When confronted, the owner confirms the only reason they took your picture to suggest you the perfect underwear based on your size. And, there is a legal guarantee that picture/data will never be used for any other purpose and only be processed by machine.
  • Will you still go to such toilet?

BTW, that friend stopped talking to me afterward; not sure why 🤔 (Edit: I should stop giving shitty examples to anyone, as it seems ) 🤐

view more: next ›

KarnaSubarna

joined 2 years ago