Language Selection

English French German Italian Portuguese Spanish

July 2019

4 best Linux sticky-note apps

Filed under
GNU
Linux
Software

There are a lot of great sticky-note apps on the Linux platform that allows users to quickly paste thoughts, lists, and other important information to notes in the form of virtual Post-it notes. But what app is best? Let’s find out in this list of the 5 best Linux sticky-note apps for Linux!

Read more

today's leftovers

Filed under
Misc
  • Linux Pet Peeves: 5 Things That Really Grind my Gears
  • LHS Episode #293: Have Lawn Chair Will Broadcast

    Welcome to the 293rd installment of Linux in the Ham Shack! In the episode, the hosts tackle topics from upcoming RSGB contests on the new, hot FT-4 mode, the origin of "Mayday" as a distress call, magloop antennas, CoreCtrl, the vanishing floppy disk, DMR (Digital Mobile Radio) and much more. Thank you for tuning in and have a wonderful week.

  • DNS-over-HTTPS (DoH) Update – Detecting Managed Networks and User Choice

    At Mozilla, we are continuing to experiment with DNS-over-HTTPS (DoH), a new network protocol that encrypts Domain Name System (DNS) requests and responses. This post outlines a new study we will be conducting to gauge how many Firefox users in the United States are using parental controls or enterprise DNS configurations.

    With previous studies, we have tried to understand the performance impacts of DoH, and the results have been very promising. We found that DoH queries are typically the same speed or slightly slower than DNS queries, and in some cases can be significantly faster. Furthermore, we found that web pages that are hosted by Akamai–a content distribution network, or “CDN”–have similar performance when DoH is enabled. As such, DoH has the potential to improve user privacy on the internet without impeding user experience.

    Now that we’re satisfied with the performance of DoH, we are shifting our attention to how we will interact with existing DNS configurations that users have chosen.  For example, network operators often want to filter out various kinds of content. Parents and schools in particular may use “parental controls”, which block access to websites that are considered unsuitable for children. These controls may also block access to malware and phishing websites. DNS is commonly used to implement this kind of content filtering.

  • New CSS Features in Firefox 68

    Firefox 68 landed earlier this month with a bunch of CSS additions and changes. In this blog post we will take a look at some of the things you can expect to find, that might have been missed in earlier announcements.

  • How to Build a Career in Artificial Intelligence and Machine Learning?

    Math is just one of the skillsets that aspiring AI and ML professionals are expected to have. This is only one half the requirement, the other half is one’s expertise in programming languages, such as Java, C++, Python, and R.

    While C++ helps engineers increase the speed of their coding process, Python will help them understand and create complex algorithms. Python is also the go-to choice for ML developers, and also offers various libraries and frameworks to ease the process of creating an AI model. Similarly, R and Java help professionals understand stats and implement mappers, respectively. They are important considering the role of visualization in explaining AI.

Linux: Systemd, Graphics and Benchmarks

Filed under
Graphics/Benchmarks
Linux
  • Systemd 243 RC1 Brings Its PStore Service, Zen2/RdRand Workaround & More

    Lennart Poettering has made available the first release candidate of the upcoming systemd 243 update. Systemd 243 is a big one in seeing more than 1,700 commits since the April release of systemd 242. 

  • Radeon RADV Vulkan Driver Adds Navi Wave32 Support For Compute Shaders

    Thanks to Valve's open-source driver developer Samuel Pitoiset, there is now experimental support for using Wave32 support on Navi graphics cards for compute shaders. 

    Navi/RDNA brings support for single-cycle issue Wave32 execution as an alternative to Wave64 for better efficiency. Just over a week ago the initial patches landed adding Wave32 support to RadeonSI for their OpenGL driver while now Samuel has tackled the initial implementation in the RADV driver. 

  • Mining Monero Cryptocurrency On The Open-Source POWER9 Raptor Blackbird

    Unlike my POWER8 server, the Blackbird cannot measure its own system power consumption (only the processor's), so I used a simple watt meter to take measurements. When off, with just the BMC on, the system took so little power my meter could not measure it. It kept showing 0 W, so presumably it's under a Watt. At idle, 55 W.

    [...]

    For each SMT mode, I tried six thread options. The SMT scaling is as expected, at SMT1 there are eight threads, and performance drops after; at SMT2 16 threads, and a corresponding drop after. The "more resources for each thread" effect is also slightly visible, with SMT1 having the highest result at eight mining threads.
    In SMT4, the efficiency scaling is quite nice, showing that a mere eight-core is not even close to the bottleneck here.

Server: 'Cloud', virtualisation and IBM/Red Hat

Filed under
Server
  • Cloud Native Applications in AWS supporting Hybrid Cloud – Part 1

    Let us talk first about what is cloud native and the benefits of SUSE Cloud Application Platform and AWS when building cloud native applications.

  • Cloud Native Applications in AWS supporting Hybrid Cloud – Part 2

    In my previous post , I wrote about using SUSE Cloud Application Platform on AWS for cloud native application delivery. In this follow-up, I’ll discuss two ways to get SUSE Cloud Application Platform installed on AWS and configure the service broker:

  • 10 Top Data Virtualization Tools

    With the continuing expansion of data mining by enterprises, it's no longer possible or advisable for an organization to keep all data in a single location or silo. Yet having disparate data analytics stores of both structured and unstructured data, as well as Big Data, can be complex and seemingly chaotic.

    Data virtualization is one increasingly common approach for dealing with the challenge of ever-expanding data. Data virtualization integrates data from disparate big data software and data warehouses - among other sources – without copying or moving the data. Most helpful, it provides users with a single virtual layer that spans multiple applications, formats, and physical locations, making data more useful and easier to manage.

  • Running MongoDB with OCS3 and using different types of AWS storage options (part 3)

    In the previous post I explained how to performance test MongoDB pods on Red Hat OpenShift with OpenShift Container Storage 3 volumes as the persistent storage layer and Yahoo! Cloud System Benchmark (YCSB) as the workload generator.

    The cluster I’ve used in the prior posts was based on the AWS EC2 m5 instance series and using EBS storage of type gp2. In this blog I will compare these results with a similar cluster that is based on the AWS EC2 i3 instance family that is using local attached storage (sometimes referred as "instance storage" or "local instance store").

  • OpenShift 4.1 Bare Metal Install Quickstart

    In this blog we will go over how to get you up and running with a Red Hat OpenShift 4.1 Bare Metal install on pre-existing infrastructure. Although this quickstart focuses on the bare metal installer, this can also be seen as a “manual” way to install OpenShift 4.1. Moreover, this is also applicable to installing to any platform which doesn’t have the ability to provide ignition pre-boot. For more information about using this generic approach to install on untested platforms, please see this knowledge base article.

Proprietary: Microsoft, Apple and Google

Filed under
Google
Microsoft
Mac
  • Netherlands warns government employees not to use Microsoft's online Office apps

    In one example, it was found that some 300,000 top tier Office users, with the ‘365 Pro Plus' package were being sent back to the US for storage - exactly the sort of behaviour that got Dutch backs up.

    In a wider sense, this is a small but public battle in a much larger war, with the EU still leaning heavily on Microsoft to put its post-GDPR house in order.

  • The iPhone now makes up less than half of Apple’s business

    Apple today reported its fiscal third quarter 2019 earnings, earning $53.8 billion in revenue and earnings per share of $2.18. That revenue is a 1 percent jump year over year. iPhone revenue was $25.99 billion compared to $29.47 billion a year ago. That means the iPhone represented under half of Apple’s revenue for the first time since 2012.

    The all-important services unit took in $11.46 billion in revenue. Wearables saw a big boost, likely thanks to Apple’s second-generation AirPods. CEO Tim Cook said that when the services and wearables / home / accessories divisions are combined, they approach the size of a Fortune 50 company. Revenue from Mac sales was $5.82 billion, and iPads were $5.023 billion, up from $4.634 billion last year at this time.

  • Apple Finds Life After the iPhone While Still Banking on the iPhone

    Combined, Apple’s two major independent product lines not attached to the iPhone -- Mac computers and iPads -- made up only 20% of revenue in the fiscal third quarter, despite gains from the period a year ago, the Cupertino, California-based company reported Tuesday. Apple’s also working on a mixed augmented and virtual reality headset for the coming years, but that, too, is likely to be iPhone-reliant.

  • Chrome 76 for Mac, Windows rolling out: Flash blocked by default, Incognito loophole closed, Settings tweak

    As a big HTML5 proponent for the past decade, Google encouraged sites to switch away from Flash for faster, safer, and more battery-efficient browsing. In late 2016 and early 2017, Chrome blocked background Flash elements and defaulted to HTML5, with users having to manually enable the Adobe plug-in on a site-by-site basis.

  • Google Chrome 76 Released for Linux, Windows, and Mac with 43 Security Fixes

    Google promoted today the Chrome 76 web browser to the stable channel for all supported platforms, including GNU/Linux, Windows, and macOS.

    Google Chrome 76.0.3809.87 is now available as the latest stable version of the popular and cross-platform web browser from Google, based on the open source Chromium project. It contains various bug fixes and improvements, as well as no less than 43 security fixes for the latest vulnerabilities.

Devices: Orange Pi Zero, Avalue, RTL-SDR

Filed under
Linux
Hardware
  • Orange Pi Zero LTS SBC Launched for $8.49 and Up

    You can now buy Orange Pi Zero LTS Arm Linux SBC for $8.49 and up. The tiny board is ideal for headless applications with WiFI and Ethernet connectivity.

  • Toughened up embedded PC can run 8th or 9th Gen Coffee Lake CPUs

    Avalue’s rugged “EPS-CFS” computer runs Linux or Win 10 on Intel 8th or 9th Gen Coffee Lake CPUs up to an octa-core Core i7-9700TE, and supplies up to 32GB GB DDR4, 2x SATA bays, 2x GbE, 2x HDMI, and 4x USB 3.2 ports.

    Avalue announced an embedded computer with Intel’s 8th Gen Coffee Lake T-series or the new, but similarly 14nm-fabricated, 9th Gen Coffee Lake Refresh TE-series chips. The EPS-CFS computer, which is built around Avalue’s 3.5-inch ECM-CFS SBC, joins other 9th Gen-ready products including Kontron’s COMe-cWL6 (E2S) and Congatec’s Conga-TS370 COM Express modules.

  • RTL-SDR: Seven Years Later

    When I wrote that article in 2012, the RTL-SDR project and its community were still in their infancy. It took some real digging to find out which TV tuners based on the Realtek RTL2832U were supported, what adapters you needed to connect more capable antennas, and how to compile all the software necessary to get them listening outside of their advertised frequency range. It wasn’t exactly the most user-friendly experience, and when it was all said and done, you were left largely to your own devices. If you didn’t know how to create your own receivers in GNU Radio, there wasn’t a whole lot you could do other than eavesdrop on hams or tune into local FM broadcasts.

    Nearly a decade later, things have changed dramatically. The RTL-SDR hardware and software has itself improved enormously, but perhaps more importantly, the success of the project has kicked off something of a revolution in the software defined radio (SDR) world. Prior to 2012, SDRs were certainly not unobtainable, but they were considerably more expensive. Back then, the most comparable device on the market would have been the FUNcube dongle, a nearly $200 USD receiver that was actually designed for receiving data from CubeSats. Anything cheaper than that was likely to be a kit, and often operated within a narrower range of frequencies.

Drawing is a Promising ‘Microsoft Paint’ Alternative for Linux

Filed under
Software

Looking for a program like Microsoft Paint but for the Linux desktop? Check out the aptly named ‘Drawing‘, a new GTK app that ably fills the gap.

This simple image editor for Linux desktops is made in the mould of the Microsoft Paint. That mean it isn’t trying to out-do The GIMP, pitch itself as an alternative to Photoshop, or pick up where Pinta left off.

What Drawing can’t do is almost as important as what it can do; that’s to say, it’s a simply designed app designed for simple use-cases.

Think meme making, screenshot annotations, wobbly sketched moustaches on selfies, and that sort of thing.

Read more

Security: Small Airplanes, Hutchins, Updates, Windows XP and WireGuard

Filed under
Security
  • US issues hacking security alert for small planes [iophk: as planes become networked, attacks will no longer require physical access, such a thing has happened in cars.]

    The cybersecurity firm, Rapid7, found that an attacker could potentially disrupt electronic messages transmitted across a small plane’s network, for example by attaching a small device to its wiring, that would affect aircraft systems.

    Engine readings, compass data, altitude and other readings “could all be manipulated to provide false measurements to the pilot,” according to the DHS alert.

  • Small Airplanes Can Be Hacked to Display False Data in Flight

    However, the [attack] requires physical access.

    [...]

    Rapid7 verified the findings by investigating two commercially available avionics systems. It determined that only "some level of physical access" to the aircraft's wiring was needed to pull of the hack, which could be delivered by attaching a small device to the plane's Controller Area Network (CAN) bus to send the false commands.

    The key problem is that the CAN bus is integrated into the plane's other components without any firewalls or authentication systems in place. This means untrusted connections over a USB adapter hooked up to the plane can send commands to its electronic systems.

  • No Jail Time for “WannaCry Hero” [iophk: the plea "bargain" still means he has become a convicted felon]

    Hutchins’ conviction means he will no longer be allowed to stay in or visit the United States, although Judge Stadtmeuller reportedly suggested Hutchins should seek a presidential pardon, which would enable him to return and work here.

  • Security updates for Wednesday

    Security updates have been issued by CentOS (389-ds-base, curl, and kernel), Debian (libssh2), Fedora (kernel, kernel-headers, and oniguruma), openSUSE (chromium, openexr, thunderbird, and virtualbox), Oracle (389-ds-base, curl, httpd, kernel, and libssh2), Red Hat (nss and nspr and ruby:2.5), Scientific Linux (httpd and kernel), SUSE (java-1_8_0-openjdk, mariadb, mariadb-connector-c, polkit, and python-requests), and Ubuntu (openjdk-8, openldap, and sox).

  • It's 2019, and one third of businesses still have active Windows XP deployments [Ed: The problem is that they use Windows (back doors in all versions), not that they use "XP". They should move corporate data to something secure like BSD and GNU/Linux.]

    Zero-day attacks were the second-most cited concern among IT decision makers, according to SpiceWorks, with 18% of respondents citing that as their primary concern. Insider data leaks were the most cited, at 27%, while attacks on IoT devices was third (17%), followed by supply-chain attacks (15%), DDoS attacks (15%), and cryptojacking (15%). Fewer than 20% of respondents indicated their business was "completely prepared" for common security threats.

    Considering the risks that accompany unsupported software generally, and the larger attack surface that results from an unsupported (or otherwise unpatched) operating system, there is a relative lack of urgency to migrate from Windows 7. Certainly, while paid support for volume licenses is a possibility for some, smaller organizations ineligible for volume licensing will be left out in the cold. To date, Microsoft has shown no signs of wavering in their intent to grant a reprieve to the remaining users of Windows 7. Without a major shift, or a reprieve from Redmond, the prospect of unpatched, internet-connected systems is fertile ground for botnet creation.

  • NordLynx: NordVPN Builds New Tech Around WireGuard

    Well known Panama-based VPN provider NordVPN has announced their NordLynx technology today that is based on the WireGuard protocol.

    NordLynx is the company's new "fast and secure" VPN solution built atop WireGuard. The company describes WireGuard as a "radical change" and "a breath of fresh air in the industry."

NetBSD 9.0 release process has started

Filed under
BSD

If you have been following source-changes, you may have noticed the creation of the netbsd-9 branch!

Read more

Also: NetBSD 9.0 Prepping For Release With AArch64 Support, Kernel ASLR & Better NVMe Perf

More in Tux Machines

SUSE and Red Hat Leftovers

  • Skuba on SUSE CaaS Platform 4

    With SUSE CaaS Platform 4 we heard our customers feedback and decided to change what the lifecycle of the platform looks like. Previous versions of SUSE CaaS Platform included an administrator node that despite being useful for managing the whole platform, was another component to take care of, and an extra machine to take into account when deploying the platform. This administrator node used Salt to set up and maintain the Kubernetes cluster among the different nodes comprising your cluster. During this time, your feedback has been that a little more flexibility on the deployment was appreciated, so you could experiment with slightly different setups, even if they were for proof of concepts while you were fleshing out the details of production clusters.

  • Kubernetes Rolling Update Strategy in our production infra

    Kubernetes rolling update strategy means suppose we are running pod (containers) in our live infra and we want to update new changes into our running pod like build update, confrontational changes etc. While deployment new pod with new changes suppose our containers got stuck or failed due to any reason. So, we have to redeploy old pod with old changes again to avoid downtime of our application. This complete process is called rolling update strategy in Kubernetes. Kubernetes rolling update strategy Before moving to next we should aware about new pod deployment strategy of Kubernetes means how many new pods it will deploy at a time without taking downtime. Because high availability of our website is our first priority. So, while deploying new pod Kubernetes will deploy 25% or you can say one fourth of the total pod. Suppose we are running four pods first it will terminate 25% of total pod means one pod. Then it will launch 25% new pod and so on.

  • Tackle OpenStack networking woes with SUSE OpenStack Cloud Crowbar

    By far, the most difficult aspect of successfully deploying OpenStack is getting the networking right, a challenge that has caused many a well-intentioned IT team to throw up its hands and toss in the towel. Fortunately, SUSE OpenStack Cloud removes much of that pain by automating most of the network deployment and dramatically simplifying custom network set-ups.

  • Grow your virtualization environments without breaking the bank

    An IT director at a large financial services company shares the benefits and cost reductions they’ve experienced by switching to Red Hat Virtualization. In just three years, it’s paved the way for an efficient, stable and cost-effective virtualization environment.

  • How to Handle OpenShift Worker Nodes Resources in Overcommitted State

    One of the benefits in adopting a system like OpenShift is facilitating burstable and scalable workload. Horizontal application scaling involves adding or removing instances of an application to match demand. When OpenShift schedules a Pod, it’s important that the nodes have enough resources to actually run it. If a user schedules a large application (in the form of Pod) on a node with limited resources , it is possible for the node to run out of memory or CPU resources and for things to stop working! It’s also possible for applications to take up more resources than they should. This could be caused by a team spinning up more replicas than they need to artificially decrease latency or simply because of a configuration change that causes a program to go out of control and try to use 100% of the available CPU resources. Regardless of whether the issue is caused by a bad developer, bad code, or bad luck, what’s important is how a cluster administrator can manage and maintain control of the resources. In this blog, let’s take a look at how you can solve these problems using best practices.

  • How the new Quarkus extension for Visual Studio Code improves the development experience

    Earlier this year, we were introduced to Quarkus, the next-generation, container-first framework for Java applications. As expected, such new frameworks and technologies make way for new developer tools focused on making the development experience even better. The recent Quarkus extension for Visual Studio Code release aims to do just that, by bringing features specific to Quarkus project development within VS Code. The new VS Code extension is dependent on a couple of Java extensions for VS Code, so it is recommended that you have the Java Extension Pack installed. This article outlines what the Quarkus extension for VS Code has to offer: convenient features for an already convenient Java framework.

Security: New Updates and "Optimizing KVM Virtualization Performance Stemming From Spectre"

  • Security updates for Monday

    Security updates have been issued by Debian (expat, php-pecl-http, and php7.0), Fedora (ImageMagick, jackson-annotations, jackson-bom, jackson-core, jackson-databind, and rubygem-rmagick), Mageia (chromium-browser-stable, ibus, kernel, samba, and thunderbird), openSUSE (chromium), Oracle (dovecot and kernel), Red Hat (dbus, kernel, kernel-alt, and kpatch-patch), Scientific Linux (dovecot and kernel), and SUSE (expat, ibus, kernel, kernel-source-rt, nmap, openssl, and webkit2gtk3).

  • Red Hat Working On Optimizing KVM Virtualization Performance Stemming From Spectre

    Red Hat's Andrea Arcangeli sent out an interesting patch series on Friday to micro-optimize the Kernel-based Virtual Machine (KVM) to enhance the VMEXIT performance in wake of Spectre mitigations. The "KVM monolithic" patch series ends up linking the KVM common code both into kvm-intel and kvm-amd so that the common "kvm" kernel module can be dropped. This occupies more disk space but should yield better run-time performance particularly for systems mitigated against Spectre Variant Two.

  • 10 Best Anonymous Browser Apps for Android to Stay Incognito

    Android isn’t the most secure platform out there, but with the 10 best apps for anonymous browsing, you can greatly enhance your privacy online. Today we’ll define what anonymous browsing actually entails, run through 10 essential Android apps, and present the 2 best Android VPNs for the ultimate mobile cybersecurity.

Kernel: AMD Navi 10 Firmware and Linux 5.4 Additions

  • AMD Navi 10 Firmware Finally Lands In The Linux-Firmware Tree

    While AMD has provided open-source Radeon RX 5700 series (Navi 10) support since launch and that code since worked into the various mainline code-bases from the Linux kernel to Mesa, one kink in their support has been their binary microcode images not being available from the reference linux-firmware.git location as needed to initialize the hardware. That Navi 10 firmware/microcode issue has finally been rectified with the images landing this morning. Up until now any Radeon RX 5700 series Linux customers or distribution/third-party driver packagers have had to pull these binary bits from this Navi10 directory on the personal site of AMDGPU lead maintainer Alex Deucher. Via his site is where he normally stages these binary microcode files until landing in linux-firmware.git as the de facto location for all Linux drivers' firmware files.

  • Linux 5.4 Brings Support For Wacom's MobileStudio Pro 13, Logitech Lightspeed Receivers

    Jiri Kosina on Sunday sent out the HID subsystem updates for the in-development Linux 5.4 kernel. The HID pull once again features support for several new devices particularly on the Logitech side.

  • Wireless USB + UWB Demotion Goes Ahead For Linux 5.4

    Back in August I noted that Wireless USB and Ultra Wideband would be deprecated within the Linux kernel and that is indeed happening for Linux 5.4. The Wireless USB (WUSB) and Ultra Wideband (UWB) subsystems within the Linux kernel were already orphaned for years with having no maintainer while now they are officially deprecated and demoted to the kernel's staging area. If no one steps up soon to maintain the code, it will be dropped in forthcoming kernel releases.

Videos from LibreOffice Conference 2019: OpenDocument Format

LibreOffice can open documents in many formats, including Microsoft Office files (.docx, .xlxs, .pptx). But it’s native file format is the fully open and standardised OpenDocument Format (ODF). At the recent LibreOffice Conference 2019 in Spain, community members gave presentations about news and updates for ODF. So, here are the first videos from the presentations (use headphones for best audio quality). Read more