Formula 1 News

Formula 1® - The Official F1® Website

LIVE COVERAGE: Singapore Sprint set to start soon after rain delay

Live coverage of the F1 Sprint at the 2026 Singapore Grand Prix.

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Kabinet komt met extra onderzoeksgeld voor postcovid en wil ernstig zieken registreren

thexiffy

Last.fm last recent tracks from thexiffy.

Collective Soul - Love Lifted Me

Collective Soul

'Spoor van ellende in Nederlandse steden, Syrische jongeren blinken uit in extreem geweld'

Foto - 'jongeren' in Ter Apel, niet per se Syriërs

We schreven hier al: En hier zitten we dan, met al die psychisch getroebleerde en criminele Syriërs

We schreven hier al: Syriërs. Het is echt compleet krankzinnig

We schreven hier al: In dit land zijn we criminele, jonge, mannelijke asielzoekers uit Syrië en Marokko spuugzat

Zélfs NRC schreef er al iets over en vandaag heeft De Telegraaf dienst: "Uitgeprocedeerde Syriërs vechten, steken en stelen erop los: spoor van ellende in Nederlandse steden." Dan kunnen wij ook wel wéér inhaken. Want in Arnhem zwaaien ze met machetes, in Den Bosch doen ze alleen maar aan vechten en stelen en vrouwen lastigvallen, in Utrecht heeft zelfs Sharon Dijksma een delier, in Groningen plegen ze 'extreem geweld', enzovoorts. Ondernemers zijn de diefstallen spuugzat, vrouwen worden geïntimideerd en achterna gezeten, ouderen durven niet meer met het openbaar vervoer, kinderen mogen niet meer alleen naar buiten, iedereen wordt maar bespuugd of geïntimideerd of neergestoken. Asscher beloofde apothekers, we kregen verkrachters, jihadisten, uitkeringstrekkers, Jodenhaters, agressievelingen, nog meer verkrachters, knuffeldieven, nog meer verkrachters, PBC-klanten, nog meer verkrachters en hopeloze recidivisten, wiens familie we nog gaan ophalen ook. Grote groepen Syrische schooiers maken het leven in Nederland voor heel veel mensen echt een stuk minder leuk. 

Maar hey, zondag wappert de pridevlag op het gebouw van de Tweede Kamer. Misschien helpt het.

Blijven drukken, steun GeenStijl met maar 5 eurootjes per maand

Word onze held

Wel.nl

Minder lezen, Meer weten.

EU-voorzitter Ierland wil 140 miljard af van meerjarenbegroting

BRUSSEL (ANP) - Het Ierse voorzitterschap van de EU stelt voor om 140 miljard af te halen van de aankomende EU-meerjarenbegroting (2028-2034). Als tijdelijk voorzitter van de EU heeft Ierland de taak om een zogeheten onderhandelingsbox over de begroting te presenteren. Deze zal volgende week worden besproken op een top met EU-leiders.

De Ieren stellen voor dat de totale hoogte van de begroting 1,62 biljoen wordt, 8 procent minder dan het voorstel van de Europese Commissie van 1,76 biljoen. De huidige meerjarenbegroting is 1,2 biljoen.

Een groep van zes zogeheten zuinige landen, waaronder Nederland en Duitsland, wil dat er honderden miljarden van het Commissievoorstel afgaan; anders komt er dit jaar nog geen akkoord over de begroting. Het is de wens van voorzitter van de EU-leiders António Costa om de hoogte van de begroting nog voor het einde van het jaar vast te stellen met de EU-landen.

Fonds voor concurrentiekracht

Voor akkoord op de begroting is instemming van alle EU-landen nodig.

Ierland schrapt fors in zijn voorstel in een zogeheten fonds voor concurrentiekracht; daar haalt het 67 miljard vanaf. De zuinige landen hamerden er juist op dat in de begroting prioriteit moet worden gegeven aan dat soort investeringen, waaronder in defensie.

Verdere bezuinigingen

Van het zogeheten budget voor achtergestelde gebieden en landbouw gaat 32 miljard af in het Ierse voorstel. Een groep van zeventien EU-landen, waaronder Spanje en Italië, gaat er juist prat op dat hier geen geld vanaf zou gaan.

De Ieren stellen verder voor om zo'n 34 miljard af te halen voor een fonds voor onder meer buitenlandse hulp en ontwikkelingssamenwerking, Global Europe. Ook haalt het Ierse voorzitterschap ongeveer 9 miljard af van de begroting voor administratieve kosten, waaronder banen binnen de Europese instituties.

De Ierse minister Thomas Byrne (Europese Zaken) hoopt nog altijd op een akkoord voor de kerst. "Niet iedereen gaat krijgen wat ze willen in dit voorstel", zei hij op een persconferentie. Hij ziet het Ierse voorstel niet als het eindakkoord, maar wel als "een grote stap" in de richting daarvan.


Burgemeester Oldebroek aanwezig bij hijsen regenboogvlag

WEZEP (ANP) - In de Gelderse gemeente Oldebroek is zaterdag bij de Kruiskerk de regenboogvlag gehesen door de dominee. Dat gebeurde in het dorp Wezep, dat onder Oldebroek valt, in het bijzijn van burgemeester Tanja Haseloop-Amsing. "Iedereen is voor mij gelijk en daar wilde ik heel graag op deze manier uiting aan geven", zegt Haseloop-Amsing na afloop.

In Oldebroek is dit jaar een conservatief college aangetreden dat het lhbtq+-beleid heeft ingetrokken en afgesproken heeft dat het hijsen van de regenboogvlag door de gemeente niet meer gebeurt.

Dat de burgemeester besloot toch aanwezig te zijn bij het hijsen van de vlag bij de kerk leverde haar "positieve en negatieve reacties" op. "En die mogen er allemaal zijn. Het is aan mij om te proberen zoveel mogelijk van die meningen te begrijpen en te duiden." Ze benadrukt dat ze burgemeester is "van alle inwoners" en dus ook van mensen die tot de lhbtiq+-groep behoren.

Bij het hijsen van de vlag waren volgens initiatiefnemer Kjeld Mooi ongeveer tweehonderd mensen aanwezig.


Tesla geeft rijassistent in Europa een nieuwe naam na kritiek

DEN HAAG (ANP/DPA) - Tesla heeft de naam van zijn rijassistentiesysteem in Europa veranderd, na jarenlange kritiek dat het Amerikaanse bedrijf het systeem te veel zou hebben aangeprezen als volledig zelfrijdend. Op de websites van de fabrikant van elektrische auto's in Nederland en andere Europese landen heet het systeem nu 'Tesla Assisted Driving'. Daarmee wordt direct duidelijk dat het slechts om een rijassistentiesysteem gaat.

Tesla noemde het systeem voorheen 'Full Self-Driving (Supervised)'. Het bedrijf heeft jarenlang tegengesproken dat die naam de indruk wekt dat de auto volledig autonoom kan rijden, terwijl de bestuurder op elk moment klaar moet staan om de controle over te nemen en volledig aansprakelijk blijft.

Tesla schrapte eerder al de oorspronkelijke naam 'Autopilot' voor zijn basistechnologie voor rijassistentie, na juridische geschillen.


Politie onderzoekt of spoorbrand sabotage of kattenkwaad is

ROTTERDAM (ANP) - De politie hoopt onder meer op basis van camerabeelden meer te weten te komen over de brandstichting bij het spoor in de nacht van vrijdag op zaterdag. Waarom in een technische ruimte bij een spoorbrug brand is gesticht, is nog onduidelijk.

De politie houdt met meerdere scenario's rekening, waaronder sabotage en kattenkwaad. Vooralsnog zijn er geen verdachten in beeld. De recherche en de Forensische Opsporing doen onderzoek.

Ook ProRail moet nog onderzoeken hoe groot de schade is die de brand heeft veroorzaakt. Dan zal ook pas duidelijk worden hoelang de herstelwerkzaamheden gaan duren voordat er weer treinen over het traject kunnen.

Treinuitval

ProRail kreeg rond 02.30 uur een melding binnen van een storing aan de spoorbrug bij de Schuttevaerweg in Rotterdam Delfshaven. Toen een aannemer van de spoorbeheerder ter plaatse kwam, werd duidelijk dat er brand was gesticht.

Door de brand rijden in ieder geval heel de zaterdag geen treinen tussen de stations Rotterdam Centraal en Delft Campus.


The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Hurricane Isaias live updates: hundreds of thousands without power as storm batters US Gulf Coast

First Atlantic hurricane of the 2026 season makes landfall in the US

How storm surges are formed

As a hurricane approaches a coast, the churning winds force ocean water up on to land; atmospheric pressure from the storm also helps squeeze the water ashore. The shallower the continental shelf, the higher the threat of a dangerous surge. The water may take a couple of days to fully subside.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Two characters open up a world of typosquatting opportunities in Chromium browsers

Researchers say two characters available to typosquatters and phisherfolk can trick Chromium browsers into displaying lookalike URLs as genuine web addresses. Wangling a domain name to look an awful lot like that of a popular website is nothing new. We’ve all encountered phishing sites such as macrosoft[.]com and applle[.]com before in our daily struggles against spam. However, as browsers mature, new characters are always being made available for use. This opens up new opportunities for those whose languages contain characters/homoglyphs that aren’t ASCII-compliant, but it also introduces new ways for attackers to abuse display logic quirks in programs like Chrome and Edge. According to Ian Muscat and Leanne Briffa of Have I Been Squatted, there are still characters available to cyber-imposters that can reliably fool web users into trusting URLs that they certainly should not. The latest glyphs bypassing browser safety checks allow tricksters to run websites from a clearly fake domain name (when displayed in Punycode), although they appear just like the real deal in Unicode. The characters of note, in this case, are ө, which is found in various Cyrillic languages such as Kazakh, Mongolian, and Tatar, and the Latin K with hook, ƙ, used in Hausa and Karai-karai. Both are visually similar to the letters e/o, i, and k, respectively, and allowed the researchers to register 20 lookalike domain names. These included: aррӏө[.]com sрасөх[.]com oƙta[.]com niƙe[.]com Below are the URLs’ Punycode equivalents – how browsers should display them safely: xn--80a6aa68c8d.com xn--80a5aeq0fr0c.com xn--ota-f6a.com xn--nie-g6a.com You can try them out; they’re registered by Have I Been Squatted and are safe to visit. They take you to research demo pages set up by the researchers, and each page explains how exactly they bypass browser protections. Crucially, they all bypass the key security measures deployed by Chromium-based browsers. How the bypasses work Browsers deploy two main defense layers. The first is a set of seven sequential checks run by Chromium’s SafeToDisplayAsUnicode function, which check for a range of common spoofing methods. Vendors began introducing these checks in 2017 after researcher Xudong Zheng registered аррӏе.com – a domain consisting of all-Cyrillic characters. Chromium’s checks, which factor in a hardcoded list of known Cyrillic characters known to be used in place of Latin letters, can be seen as "all or nothing." Built to detect all-Cyrillic strings, the measure only takes action against domain names if every character in the string is on its hardcoded list. If one character is missing, the check is bypassed. Characters such as ө, ї, and ү, are known as “breakers,” as these are not present in the lookalike list, as of Chrome 154 (released to stable channel on September 22). Failing any of the seven display checks tells the browser that the characters are unsafe to display as Unicode and to instead display the Punycode, revealing just how dissimilar they are to the genuine domains they try to imitate. The second measure browsers take is to compare the domain name against a list of popular websites to see if it is trying to imitate one of them. In Chromium, these checks are handled by the GetSimilarTopDomain() function. This step converts a supplied domain name into a "skeleton," stripping its characters of diacritics, such as accents (ó becomes o), and checking the skeleton URL against a hardcoded list of popular websites. Chromium checks against almost 8,500, and if the skeleton matches any of them, then it displays Punycode. However, the Latin K with hook, ƙ, does not have an accent, and is added to the skeleton as a Latin k with an added combining mark, bypassing the security check. In this case, the skeleton is formed as: [o k ‘ t a . c o r n]. (The skeleton maps "m" to "rn"). Likewise, with аррӏө.com, the Cyrillic barred o retains its bar in the skeleton as a combining mark, meaning it does not match the genuine Apple domain. Its skeleton is formed as: [a p p l o - . c o r n]. Browsers are always working to stymie these tools of imposterment. Chrome 148 put an end to attackers being able to use ҏ and ӿ as breakers to imitate their Latin lookalikes, for example. The two main security checks are not the only lines of defense. Chromium also deploys warnings at the time of navigation called Safety Tips. An example domain that would bypass the two main checks is ínstagarm[.]com. The inflection on the beginning character is removed and what’s left is essentially the real Instagram domain with two letters swapped. The Instagarm domain does not match any of the hardcoded sites, nor does it contain any banned characters. In this case, Chrome will display one of two popups, asking the user if they meant to visit the genuine domain, warning that the current direction of travel appears fake. However, there are limits to this extra security layer. The warnings only trigger when an imitation domain is an exact-character match, a one-edit match, or a match with an adjacent swap from the genuine URL. Two or more changes, like with аррӏө[.]com, which has all-Cyrillic characters preceding the ".com," will not trigger these warnings. The warnings will also not trigger with domains consisting of fewer than five characters. Domains such as oƙta.com, which is only one edit from the real Okta, may not trigger defenses because of the one-edit rule and the fact that it is only four characters. Safety Tips also checks the skeleton against the sites users visit regularly, not just the hardcoded list of trusted sites. Frequently visited sites may trigger the same warnings, but for users who do not have a comprehensive visit history, the defense layer may fail. The defenses described here only apply to browsers. Email clients are even less picky with imitation domain strings. Websites like Gmail displayed each of the 20 domains HIBS fed the clients, which were a mix of lookalikes and genuine internationalized domain names (IDNs), as an attacker would want it to, all in Unicode. Outlook Web showed all 20 as Punycode, even the harmless ones, suggesting neither apply the right checks to properly inform users. To quantify the scale of the issue, the researchers looked at ICANN’s list of every .com domain. There are around 167 million of them, approximately 733,000 of which are IDNs, those that contain non-ASCII characters and are stored in Punycode form. The researchers took each of the IDNs and swapped their non-ASCII characters for ASCII equivalents to determine how many matches there were. They found around 162,000 pairs – IDNs that resemble plain ASCII domains. It should be said that this does not mean there are circa 162,000 typosquatted domains, just that many yield lookalikes. Some may be registered by businesses for defensive purposes; others may be owned by the same business that wants to operate multiple websites catering to different languages. However, organizations should be aware of the means available to typosquatters, and monitor registered domains accordingly. ®