link1s.site

Google extends Linux kernel support to 4 years

According to AndroidAuthority, the Linux kernel used by Android devices is mostly derived from Google's Android Universal Kernel (ACK) branch, which is created from the Android mainline kernel branch when new LTS versions are released upstream. For example, when kernel version 6.6 is announced as the latest LTS release, an ACK branch for Android15-6.6 appears shortly after, with the "android15" in the name referring to the Android version of the kernel (in this case, Android 15).

Google maintains its own set of LTS kernel branches for three main reasons. First, Google can integrate upstream features that have not yet been released into the ACK branch by backporting or picking, so as to meet the specific needs of Android. Second, Google can include some features that are being developed upstream in the ACK branch ahead of time, making it available for Android devices as early as possible. Finally, Google can add some vendor or original equipment manufacturer (OEM) features for other Android partners to use.

Once created, Google continues to update the ACK branch to include not only bug fixes for Android specific code, but also to integrate the LTS merge content of the upstream kernel branch. For example, the Linux kernel vulnerability disclosed in the July 2024 Android security bulletin will be fixed through these updates.

However, it is not easy to distinguish a bug fix from other bug fixes, as a patch that fixes a bug may also accidentally plug a security vulnerability that the submitter did not know about or chose not to disclose. Google does its best to recognize this, but it inevitably misses the mark, resulting in bug fixes for the upstream Linux kernel being released months before Android devices. As a result, Google has been urging Android vendors to regularly update the LTS kernel to avoid being caught off guard by unexpectedly disclosed security vulnerabilities.

Clearly, the LTS version of the Linux kernel is critical to the security of Android devices, helping Google and vendors deal with known and unknown security vulnerabilities. The longer the support period, the more timely security updates Google and vendors can provide to devices.

Musk is the billionaire who lost the most money in the first half of 2024: $5 billion a month
At the beginning of this year, Elon Musk had a fortune of $251 billion and could almost single-handedly solve world hunger. However, Tesla's stagnant sales, the endless struggle to buy Twitter, and the volatility of Tesla's stock price meant he lost a lot of money this year. According to Forbes, Musk is the billionaire with the most losses so far this year, with his wealth shrinking at a rate of about $5 billion a month. According to the website, his wealth shrank by more than 10% from the end of 2023 to June 28, 2024. As the website explains: Between December 31, 2023, and June 28, the last day of regular stock market trading for the first half of the year, Musk's net worth fell from $251.3 billion to $221.4 billion, a bigger drop than any other billionaire tracked by Forbes, but Musk remains the richest person on the planet. The main reason for the dip in Musk's pocketbook is that a Delaware judge in January canceled Musk's then-record Tesla compensation package worth $51 billion, which led Forbes to cut the value of the equity award by 50 percent because of uncertainty about whether Musk would receive those stock options. Excluding that bonus, Musk's wealth has remained volatile over the past six months, with the value of his 13 percent stake in Tesla shrinking by about $20 billion as falling profits and car deliveries sent the stock down 20 percent. But that was partly offset by the growth of Musk's stake in his generative artificial intelligence startup xAI to $14.4 billion (Musk also has a roughly $75 billion stake in private aerospace company SpaceX, a $7 billion stake in social media company X, And smaller stakes in other companies, such as brain experimentation startup Neuralink).
The largest password leak in history exposes nearly 10 billion credentials
The largest collection of stolen passwords ever has been leaked to a notorious crime marketplace, according to cybersecurity researchers at Cybernews. This leak, dubbed RockYou2024 by its original poster “ObamaCare,” holds a file containing nearly 10 billion unique plaintext passwords. Allegedly gathered from a series of data breaches and hacks accumulated over several years, the passwords were posted on July 4th and hailed as the most extensive collection of stolen and leaked credentials ever seen on the forum. “In its essence, the RockYou2024 leak is a compilation of real-world passwords used by individuals all over the world,” the researchers told Cybernews. “Revealing that many passwords for threat actors substantially heightens the risk of credential stuffing attacks.” Credential stuffing attacks are among the most common methods criminals, ransomware affiliates, and state-sponsored hackers use to access services and systems. Threat actors could exploit the RockYou2024 password collection to conduct brute-force attacks against any unprotected system and “gain unauthorized access to various online accounts used by individuals whose passwords are included in the dataset,” the research team said. This could affect online services, cameras and hardware This could affect various targets, from online services to internet-facing cameras and industrial hardware. “Moreover, combined with other leaked databases on hacker forums and marketplaces, which, for example, contain user email addresses and other credentials, RockYou2024 can contribute to a cascade of data breaches, financial frauds, and identity thefts,” the team concluded. However, despite the seriousness of the data leak, it is important to note that RockYou2024 is primarily a compilation of previous password leaks, estimated to contain entries from a total of 4,000 massive databases of stolen credentials, covering at least two decades. This new file notably includes an earlier credentials database known as RockYou2021, which featured 8.4 billion passwords. RockYou2024 added approximately 1.5 billion passwords to the collection, spanning from 2021 through 2024, which, though a massive figure, is only a fraction of the reported 9,948,575,739 passwords in the leak. Thus, users who have changed their passwords since 2021 may not have to panic about a potential breach of their information. That said, the research team at Cybernews stressed the importance of maintaining data security. In response to the leak, they recommend immediately changing the passwords for any accounts associated with the leaked credentials, ensuring each password is strong and unique and not reused across different platforms. Additionally, they advised enabling multi-factor authentication (MFA), which requires an extra form of verification beyond the password, wherever possible, to strengthen cyber security. Lastly, tech users should utilize password manager software, which securely generates and stores complex passwords, mitigating the risk of password reuse across multiple accounts.
Exclusive: Japan must strengthen NATO ties to safeguard global peace, PM says
TOKYO, July 9 (Reuters) - Russia's deepening military cooperation with North Korea has underlined the need for Japan to forge closer ties with NATO as regional security threats become increasingly intertwined, Prime Minister Fumio Kishida told Reuters. In written remarks ahead of his attendance at a NATO summit in Washington DC this week, Kishida also signalled concern over Beijing's alleged role in aiding Moscow's two-year-old war in Ukraine, although he did not name China. "The securities of the Euro-Atlantic and the Indo-Pacific are inseparable, and Russia’s aggression against Ukraine and its deepened military cooperation with North Korea are strong reminders of that," Kishida said. "Japan is determined to strengthen its cooperation with NATO and its partners," he added. The world, the Japanese leader said, should not tolerate attempts by some countries to disrupt the established international order and reiterated a warning that Ukraine today could be East Asia tomorrow. He also urged cooperation to confront new security threats that transcend geographical boundaries, such as cyber-attacks and conflicts in space. The U.S. and its allies have accused Pyongyang of providing ballistic missiles and artillery shells that Russia has used in its war in Ukraine and say they fear Moscow in return could provide support for North Korea's nuclear missile development. Washington has also said China is supplying droneWithout naming China, Kishida told Reuters "some countries" have allegedly transferred dual-use civilian-military goods to Russia which has served "as a lifeline" for its Ukraine war. "It is necessary to grapple with such situations in a multi-faceted and strategic manner, taking a panoramic view that considers the full range of international actors fuelling Russia’s attempt to change the status quo by force," he said. "The geographical boundary of 'Euro-Atlantic' or 'Indo-Pacific' is no longer relevant in safeguarding global peace and security. Japan and Indo-Pacific partners can play a great role for NATO allies from this perspective." Constrained by decades of pacifism, Tokyo has been reluctant to supply lethal aid to Ukraine. It has, however, provided financial aid to Kyiv, spearheaded efforts to prepare for its post-war reconstruction, and contributed to NATO’s fund to provide Ukraine with non-lethal equipment such as anti-drone detection systems. Tokyo has also repeatedly warned about the risks of a similar conflict emerging in East Asia, where China has been taking an increasingly muscular stance towards its territorial claims including the democratic island of Taiwan. "This summit is a critical opportunity for Japan, the U.S., and the other NATO allies to confront the ongoing challenges against the international order and to reaffirm values and principles that have shaped global peace and prosperity," he said. There may be limits, however, over how far NATO members are prepared to go in forging closer ties in Asia. A plan that surfaced last year for NATO to open a liaison office in Japan, its first in Asia, was blocked by France and criticised by China. and missile technology, satellite imagery and machine tools to Russia, items which fall short of lethal assistance but are helping Moscow build its military to sustain the Ukraine war. Beijing has said it has not provided any weaponry to any party.
Explainer: How Boeing's Starliner can bring its astronauts back to Earth
WASHINGTON, June 24 (Reuters) - Problems with Boeing's Starliner capsule, still docked at the International Space Station (ISS), have upended the original plans for its return of its two astronauts to Earth, as last-minute fixes and tests draw out a mission crucial to the future of Boeing's (BA.N), opens new tab space division. NASA has rescheduled the planned return three times, and now has no date set for it. Since its June 5 liftoff, the capsule has had five helium leaks, five maneuvering thrusters go dead and a propellant valve fail to close completely, prompting the crew in space and mission managers in Houston to spend more time than expected pursuing fixes mid-mission. Here is an explanation of potential paths forward for Starliner and its veteran NASA astronauts, Barry "Butch" Wilmore and Sunita "Suni" Williams. THE CURRENT SITUATION Starliner can stay docked at the ISS for up to 45 days, according to comments by NASA's commercial crew manager Steve Stich to reporters. But if absolutely necessary, such as if more problems arise that mission officials cannot fix in time, it could stay docked for up to 72 days, relying on various backup systems, according to a person familiar with flight planning. Internally at NASA, Starliner's latest targeted return date is July 6, according to this source, who spoke on condition of anonymity. Such a return date would mean that the mission, originally planned for eight days, instead would last a month. Starliner's expendable propulsion system is part of the craft's "service module." The current problems center on this system, which is needed to back the capsule away from the ISS and position it to dive through Earth's atmosphere. Many of Starliner's thrusters have overheated when fired, and the leaks of helium - used to pressurize the thrusters - appear to be connected to how frequently they are used, according to Stich.
Morning Bid: Eyes switch to inflation vs elections, Powell up
A look at the day ahead in U.S. and global markets from Mike Dolan After an intense month focused on election risk around the world, markets quickly switched back to the more prosaic matter of the cost of money - and whether disinflation is resuming to the extent it allows borrowing costs to finally fall. Thursday's U.S. consumer price update for June is the key moment of the week for many investors - with the headline rate expected to have fallen two tenths of a percentage point to 3.1% but with 'core' rates still stuck at 3.4%. With Federal Reserve chair Jerome Powell starting his two-pronged semi-annual congressional testimony later on Tuesday, the consensus CPI forecast probably reflects what the central bank thinks of the situation right now - encouraging but not there yet. But as the U.S. unemployment rate is now back above 4.0% for the first time since late 2021, markets may look for a more nuanced approach from the Fed chair that sees it increasingly wary of a sudden weakening of the labor market as real time quarterly GDP estimates ebb again to about 1.5%. There were some other reasons for Fed optimism in the lead up to the testimony. The path U.S. inflation is expected to follow over coming years generally softened in June, amid retreating projections of price increases for a wide array of consumer goods and services, a New York Fed survey showed on Monday. Inflation a year from now was seen at 3% as of June - down from the expected rise of 3.2% in May - and five-year expectations fell to 2.8% from 3%. Crude oil prices are better behaved this week, too, falling more than 3% from the 10-week highs hit late last week and halving the annual oil price gain to 10%. The losses on Tuesday came after a hurricane that hit a key U.S. oil-producing hub in Texas caused less damage than many in markets had expected - easing concerns over supply disruption. Before Powell starts speaking later, there will also be an update on U.S. small business confidence for last month.