Slashdot

News for nerds, stuff that matters

Oracle Signs 10-Year Software Contract With Pentagon Worth Up To $7 Billion

Oracle has signed a 10-year Pentagon contract worth up to $7 billion to provide on-premises software, licenses, maintenance, and consulting for branches of the military. CNBC reports: The contract covers the use of Oracle software in on-premises data centers for branches of the military, the U.S. intelligence community and the Coast Guard, according to a statement. The Central Intelligence Agency was Oracle's first customer. A five-year base period for the contract includes perpetual and subscription-based software licenses, maintenance and consulting, according to one description.

Kirsten Davies, the Department of Defense's chief information officer, said in the release that the agency is saving at least $441 million for taxpayers "by fundamentally improving how we procure on-premises Oracle capabilities."

Read more of this story at Slashdot.

Microsoft Responds to LG Monitors Installing McAfee Ads On Windows

LG is removing a McAfee pop-up ad from its LG Monitor App Installer after criticism that some LG monitors were silently installing the app through Windows Update and showing ads on every boot. Microsoft says LG agreed to disable the McAfee pop-up, but the broader issue remains: Windows allows certain peripheral companion apps to install automatically without notifying users. Ars Technica reports: Following Gamers Nexus' video, a Microsoft representative stated that the LG Monitor App Installer will no longer show pop-up ads for McAfee. In response to a social media post about the app, Pavan Davuluri, EVP of Windows and devices at Microsoft, said this week: "We've connected with the team at LG and as an immediate next step, they have agreed to disable the McAfee pop-up from their app. We appreciate LG working with us toward a shared goal of a better experience for our mutual customers. We will keep improving here with our ecosystem partners."

As mentioned, some LG monitors appear to have been installing LG Monitor App Installer onto Windows computers for months. Publication Windows Latest noted that the app recently got an update, "and its changelog mentions McAfee as an additional app," which could be what prompted more people to see the ads... and then complain about them. However, the removal of McAfee doesn't address the problem of a peripheral installing ad-pushing software onto people's computers.

Users have been finding LG Monitor App Installer and its ads on their systems without LG ever showing a prompt or asking for permission. LG has some of the most expensive computer monitors available. Paying, in some cases, over $1,000 for a monitor that ends up forcing ads onto Windows is disruptive and a privacy concern. Once the app is installed, "LG technically possesses permission to use 'all system resources,'" as well as to "collect geolocation, device data, online activity, contacts, user credentials, transactions, and more," [editor-in-chief of Gamers Nexus, Steve Burke] said.

Read more of this story at Slashdot.

EU Fines Google $1 Billion For Breaking Digital Antitrust Regulations

The European Union fined Google more than $1 billion for allegedly using Google Play and Search to steer users toward its own services and apps at the expense of competitors. The Associated Press reports: Google had recently lost its appeal of a $4.5 billion antitrust fine imposed by the EU for throttling competition and reducing consumer choice through the dominance of its mobile Android operating system. The European Commission, the bloc's executive branch and highest antitrust enforcer, said it was acting in the interest of consumers after an investigation of Google.

"The best products should succeed because they're better, not because they're owned by the company running the search engine. And European consumers have a right to be told by app developers where to sign up to the best offers, even when the app store owner does not get a cut," said Teresa Ribera, the commission's Executive Vice President for Clean, Just and Competitive Transition.

Google's President of Global Affairs Kent Walker blasted the fine as "product degradation driven by a small group of self-serving complainants" that will have a negative impact on European businesses and consumers. He said that the EU's Digital Markets Act forces Google "to strip away real-time search features Europeans love -- like instant pricing and direct availability for hotels, flights, and restaurants -- and dismantle safety protections on Google Play."

Read more of this story at Slashdot.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered." Security researchers Talal Haj Bakry and Tommy Mysk say they've identified a gap in Gatekeeper and associated code signing rituals that "allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges." The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties. Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store) and Gatekeeper failed to object. Their technique doesn't work on Mac App Store apps, the Mysk team told The Register, because they're owned by root, so a process running with current user privileges won't be able to overwrite them. But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. The attack scenario requires an app downloaded from the web that has been run once – allowing Gatekeeper to complete its initial validation – and the ability to execute user-scoped code. The initial validation phase that Gatekeeper conducts is supposed to prevent subsequent modifications to the application bundle, even with administrative privileges. But the Mysk team found that you can archive a downloaded, once-run app using tar (a file archiving utility), then remove the original and replace it with a malicious version, and macOS does not require reauthorization. They've recorded a video demonstrating how the attack works. The Mysk team said there are many ways an attacker might gain the necessary access to get around Gatekeeper, such as tools installed through the command line, convincing someone to copy and paste a command to their terminal, downloading and running an malicious app, a prompt injection attack on an AI agent, or a supply chain attack via npm, brew, or some other package manager. And once a doppelganger version of an app is in place, it can magnify its mischief by presenting deceptive prompts that users are more likely to trust because they appear to come from a known app. Tommy Mysk said he was uncertain about the exact cause of the issue, but speculated it may have something to do with cached value retention. "When you open the app for the first time and it passes all validation checks, macOS marks the app as trusted and saves this data," he said. "Later when I modify the executable, macOS detects a change in the bundle and tries to revalidate its integrity. It seems the cached value of the trust causes macOS to pass the validation even though the bundle has changed." The Mysk team reported their findings to Apple, which reportedly closed the issue. "Apple doesn't consider this attack to be 'modifying' the signed executable," the Mysk team explained. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. "Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Apple did not respond to a request for comment. ®

kottke.org

Jason Kottke's weblog, home of fine hypertext products

New orca behavior unlocked. They’ve been known to sink...

New orca behavior unlocked. They’ve been known to sink boats and wear salmon for hats; now they’re ramming fish so hard they explode. “Orcas were observed to hold sunfish in their jaws while a second whale smashed into the target at high speed…”

It’s our ethical duty to understand large numbers ....

It’s our ethical duty to understand large numbers. “Our world is increasingly moving towards extreme values: Damages from climate change, deaths due to genocide, wealth that knows no bounds. We can’t tackle them if we can’t wrap our heads around [them].”

Found Kodachrome Slide

Thomas Hawk posted a photo:

Found Kodachrome Slide

Flamingo Bowl

Thomas Hawk posted a photo:

Flamingo Bowl

BART

Thomas Hawk posted a photo:

BART

Bliss Dance

Thomas Hawk posted a photo:

Bliss Dance

Until the Sun Turns Black

Thomas Hawk posted a photo:

Until the Sun Turns Black

The Watertower Guarding the Golden Hour

BertvB posted a photo:

The Watertower Guarding the Golden Hour

A striking wide-angle landscape shot taken from Surfeiland in Aalsmeer on the evening of June 19th. The iconic Art Deco Watertower stands as a commanding silhouette against a fiery, copper-tinted sky, while the low setting sun reflects brilliantly across the gentle ripples of the Westeinderplassen. Faint curtains of rain in the distance hint at the approaching summer thunderstorm, creating a serene yet dramatic atmosphere.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Charli xcx: Music, Fashion, Film review – slippery search into selfhood that hits just as hard as Brat

(Atlantic)
How do you follow up the album that made you a star – and a caricature? In classic Charli style: with a pivot to guitar and a meta masterpiece about the instability of identity

After a decade spent trailblazing a unique kind of pop freedom from the genre’s fringes, A-list success seemed like the thing that might finally trap Charli xcx. Her 2024 club-rat opus Brat spawned memes, embarrassing political bandwagoning, Collins’ word of the year and possibly terminal damage to the bra industry. Its ludicrous cultural impact looked set to pickle her as a caricature of a Parliament-toting bad girl; the question of whether “Brat summer” could last – whether Charli could sustain the interest – was so rife she turned it into a mockumentary, The Moment. It made success look miserable: your creation turned cringe by execs wanting to milk their prize cow dry of every last acid-green drop.

Even for a pop star renowned for reinvention, it put a higher price on her next move. Pivot and risk losing new fans and looking wilfully contrarian. When Charli released the sub-two-minute single Rock Music, many heard it as a middle finger. “I think the dancefloor is dead,” she drawls over guitars that buzzed like speakers weathering interference from a Nokia 5110, “so now we’re making rock music.” There were boring thinkpieces about the dancefloor being very much alive, actually (as if Charli had ever ridden culture for clout then binned it off), and about whether she was trying to eject fair-weather new fans. But the key to this cheeky song is surprisingly earnest: “Jump off the stage / I hope they catch you today / But if they don’t it’s OK,” she sings naively, an affirmation to take creative leaps, and to come with Charli – or not, as you like – as she takes this one.

Continue reading...

UK ‘ready to defend itself’ after Iranian threat over US bases

IRGC claims base in south-west England was used by US to launch bombing missions, making it ‘legitimate target’

The government has said the UK is “ready to defend itself” after Iran’s military warned that any bases being used by the US were “legitimate targets”.

The UK has allowed the US to launch “defensive” operations from British bases hosting American planes since the start of its war on Iran but has refused to help in offensive operations.

Continue reading...

The king emerges from Tardis as Commonwealth Games face battle for time and space

The troubled Games looked doomed until Glasgow stepped in but this opening ceremony had plenty of feelgood factor

The Commonwealth Games in Glasgow opened on Thursday evening to the surreal sight of King Charles and Queen Camilla stepping out of a Tardis – and a mechanical Loch Ness monster roaring the first few bars of Flower of Scotland.

The Tardis was a nod to the fact that police boxes were designed by the Scottish architect Gilbert MacKenzie Trench. But the Doctor Who reference proved to be doubly apt given the Games faced being exterminated until Glasgow stepped in after Victoria pulled out due to financial pressures.

Continue reading...

MetaFilter

The past 24 hours of MetaFilter

The expensive monitors that also serve you ads

The Register: Expensive LG Monitors are using Windows 11 driver installation to serve McAfee ads without even a security prompt (and seem to have been doing this for years) — Ars Technica, today: Microsoft responds and states that LG will no longer be allowed to do this.

Em dash included just to annoy people who assume that's a sign of generative AI.

Wel.nl

Minder lezen, Meer weten.

Madrid vraagt regering om uitroepen noodtoestand bij bosbranden

MADRID (ANP) - De regio Madrid heeft de regering verzocht de nationale noodtoestand uit te roepen vanwege de ernstige bosbranden in drie autonome regio's. De president van de regio Isabel Díaz Ayuso heeft dit verzoek ingediend via X. Ze geeft daarbij aan dat er in Madrid "duizenden mensen zijn geëvacueerd" en dat de branden "niet meer te blussen zijn".

Concreet betekent dit dat de nationale regering de controle over de situatie moet overnemen en de leiding over de noodsituatie op zich moet nemen. De regio kan de bluswerkzaamheden van de drie woedende bosbranden - twee in Villa del Prado en een derde in het nabijgelegen San Martín de Valdeiglesias - niet meer op eigen kracht aan.

In een geluidsfragment dat naar onder meer de Spaanse krant El País is gestuurd, stelt de minister van Milieu, Landbouw en Binnenlandse Zaken van Madrid, Carlos Novillo, dat het om een situatie gaat "die de veiligheid bedreigt van meer dan 10.000 inwoners van Madrid die op dit moment zijn geëvacueerd". "Momenteel zijn eenheden van de brandweer van de regio Madrid, de gemeente Madrid en de militaire noodhulpeenheid [UME] druk doende met bluswerkzaamheden om levens en eigendommen te redden."


Witte Huis: Trump blokkeert uitlevering broers Tate niet

WASHINGTON (ANP/AFP) - Donald Trump gaat de uitlevering van influencer Andrew Tate en zijn broer Tristan aan Groot-Brittannië wegens zedendelicten niet tegenhouden, zo heeft het Witte Huis donderdag laten weten.

"Nee", antwoordde Witte Huis-woordvoerder Karoline Leavitt tijdens een persmoment op de vraag of Trump en zijn regering van plan waren in te grijpen in het uitleveringsproces van de broers. Ook minister van Buitenlandse Zaken Marco Rubio nam afstand van de zaak. "Er is voor ons geen enkele rol weggelegd op dit moment, en misschien ook wel nooit wat dit betreft", vertelde hij woensdag aan verslaggevers op de Filippijnen.

Tate en zijn jongere broer werden zaterdag in Miami opgepakt door de Amerikaanse autoriteiten, een stap die hun advocaat "politiek gemotiveerd" noemde. De broers vechten hun uitlevering aan.

De broers, die bekendstaan om hun extreem misogyne standpunten en miljoenen volgers op sociale media hebben, werden al gezocht in het Verenigd Koninkrijk. Daar wachten hen aanklachten voor verkrachting en mensenhandel.


Relatieve rust in Rotterdamse wijk waar gebiedsverbod geldt

ROTTERDAM (ANP) - Het lijkt vooralsnog rustig in het deel van de Rotterdamse wijk De Esch waar sinds donderdag 23.00 uur een nachtelijk gebiedsverbod geldt. Een ANP-fotograaf zag dat de politie twee mannen bekeurde, die daarna de wijk verlieten. Er zijn vrijwel geen mensen op straat.

Het gebiedsverbod voor een deel van De Esch, in het stadsdeel Kralingen-Crooswijk, geldt de komende drie maanden van 23.00 uur tot 05.00 uur. Tijdens die uren is de wijk verboden gebied voor mensen die er niet wonen, werken of op bezoek komen. Het verbod moet een eind maken aan hardnekkige overlast door bezoekers van buiten de wijk, die vooral in de avond en nacht de boel op stelten zetten.

Zo is er al jaren sprake van straatraces, ronkende motoren, drugs- en lachgasgebruik, harde muziek en geschreeuw.

Volgens burgemeester Carola Schouten staat "de leefbaarheid in de wijk onder druk. De rust moet terugkeren in De Esch en bewoners moeten zich prettig en veilig voelen. Daarom maak ik gebruik van deze bevoegdheid." Overtreders kunnen een boete krijgen.


Sankyo Bridge & Warehouse 山居橋と山居倉庫

banzainetsurfer has added a photo to the pool:

Sankyo Bridge & Warehouse 山居橋と山居倉庫

The Sankyo Warehouses (山居倉庫, Sankyo Sōko) are a complex of rice warehouses in Sakata that now also serves as a tourist spot with a rice museum, picturesque grounds and a shop selling local goods.
Japan's most important shipping trade route of the feudal ages connected northern Japan with Osaka via ports along the Sea of Japan and the Seto Inland Sea, with Sakata emerging as a major trade hub along the way. The Shonai Plain around Sakata is one of Japan's few large plains and is ideally suited to high-quality rice cultivation. The celebrated local rice became Sakata's most lucrative commodity, and the Sankyo Warehouses have historically been where the rice is shipped from the surrounding farmland and stored before being sent to the market
Originally dating to 1893, the complex is a long row of 15 storehouses, of which most are still in use as storehouses for the rice from the Shonai Plain. The area has become popular with visitors not only for its historical importance, but also for its picturesque surroundings that include a Zelkova tree-flanked path along the perimeter and nice views along the riverbank.
Source: www.japan-guide.com/e/e7994.html