hachyderm.io is one of the many independent Mastodon servers you can use to participate in the fediverse.
Hachyderm is a safe space, LGBTQIA+ and BLM, primarily comprised of tech industry professionals world wide. Note that many non-user account types have restrictions - please see our About page.

Administered by:

Server stats:

8.9K
active users

#securityupdates

2 posts2 participants0 posts today

Lilbits: A cyberdeck with a 2 inch CRT display, a 25.3 inch E Ink monitor, and the final nail in the coffin for LG’s smartphones

Cyberdecks are portable computers that often have a retro-futuristic design. Often that’s achieved by hobbyists who combine modern hardware (like a Raspberry Pi or a similar single-board computer) with vintage tech.

But one of the coolest… and possibly most useless cyberdeck’s I’ve seen so far takes things to another level by fusing a 2 inch black and white CRT display from 1980s-era Sony […]

#alderLakeN #crtDisplay #cyberdeck #intel #lg #lilbits #onyxBoox #onyxBooxMiraPro #osUpdates #raspberryPi #securityUpdates #sonyWatchman #twinLake #watchman

Read more: liliputing.com/lilbits-a-cyber

Welcome to our April 2025 .NET servicing updates! This month, we've addressed a key security vulnerability: CVE-2025-26682 affecting .NET 9.0 and 8.0.

Be sure to check our release notes for version updates including ASP.NET Core and Entity Framework Core among others.

For .NET Framework, there are no new security updates this month.

Don’t forget to update to the latest service release today! #DotNet #Framework #SecurityUpdates #TechCommunity

Replied in thread

@JessTheUnstill @bohwaz @punkfairie @ajsadauskas @tomiahonen @fuchsiii Exactly...

Coincidentially, that's why #Android (and #iOS) doesn't let users have #root access because billions of devices owned by mostly "#TechIlliterates" that hardly get #SecurityUpdates would be an even bigger risk if they didn't boot a locked-down #ROM image, thus only allowing for #malware in user-privilegued userspace!

Cuz having a mobile OS that shoves everything through #Tor and only allows #userspace-Apps in the form modern web technologies would be a big #security and #privacy gain.

  • Not to mention #amd64 is on it's way out and inevitably they gotta have to transition to supporting #arm64 and eventually #RISCv-#64bit at some point.
#amd64#arm64#riscv

We’re excited to announce the integration of CIRCL (Computer Incident Response Center Luxembourg) Vulnerability Lookup API into our ticura CTI Search Portal.

This powerful integration combines comprehensive vulnerability insights with ticura’s single pane of glass into the intelligence of more than 940 Threat Intelligence sources, enriched with our real-time analysis and noise categorization.

This enables users to instantly assess if threats, indicators, or CVEs are actively exploited, leveraging CIRCL’s API with features like exploitation status tracking (CISA KEV), relations to ransomware and more through a unified dashboard.

Try it out and share your feedback!

A big thanks to the CIRCL.LU team for their outstanding contribution to the cybersecurity community. Be sure to check their website to learn about additional vulnerability details and many helpful services.

Lilbits: 8 years of updates for (some) Android phones, Dasung’s 60 Hz E Ink display is going global, and more

A handful of Android smartphone makers have committed to offering major OS and security updates for at least seven years after the launch of a new phone. Soon we could see phones with up to eight years of guaranteed updates.

Qualcomm has announced it’s partnered with Google to begin supporting flagship and upper mid-range processors for that long by delivering OS, kernel, and security […]

#androidUpdates #cosmic #cosmicDesktop #crowdfunding #dasung #dasungPaperlike103 #google #lilbits #osUpdates #paperlike103 #qualcomm #sailfish #sailfishos #securityUpdates #snapdragon8Elite #system76

Read more: liliputing.com/lilbits-8-years

Replied in thread

@Starcade I'm still using #Win10 on an old laptop but I've got a #VPN w/security software built in & I have other #antivirus & #antimalware apps installed on my laptop as well.

So, I have no intention of paying #MSFT anything for any future #Securityupdates

Fact is, if I'm using software that already "works" for me, I avoid updating it, despite multiple notifications about available updates.

Part of this is laziness but part of it is also that I've experienced problems with installing #Updates that were #Buggy & caused me problems.

So, as far as software is concerned, live by the saying: "If it isn't broken, don't fix it." 🤷‍♂️

Replied in thread

@GrapheneOS Well, you've to ask #Google and #Fiarphone that and consider invoking #Regulators like @EUCommission, @kartellamt@social.bund.de and others in that matter.

Which again proves my point:

  1. #AllGAFAMsAreEvil and NOONE shoud've ever trusted them with anything!

  2. The #Android ecosystem is fucked up and there is a need for #vendors to refuse to bow before #Google and actually do #secure & #repairable devices.

Again: You seem angry at the wromg person if that means you're angry at me.

The question to me is how is #GrapheneOS gonna go about this?

  • Cuz we both know Google can afford to go "maximum asshole" on you [the Grpahnene OS Project] and even in the worst case their legal department won't even notice this whole shitshow even if miraculously by the wounders of everyone from @eff to @fsf to @noybeu and @CCC forcing Google to literally support and endore GrapheneOS, because by the time any binding court ruling would be enforced, Google would've choked the project out of the market.

So my question is when will you get forward and work with other #vendors instead of tying your project to Google-specific and thus sorta-proprietary implementations?

[...] Pixel targets have a lot of device-specific hardening in the AOSP base along with some in GrapheneOS which needs to be ported over too. For example, various security features in the kernel including type-based Control Flow Integrity (CFI) and the shadow call stack are currently specific to the kernels for these devices. [...]

To me that sounds like some very serious #VendorLockIn you're stuck in, and now it bites you in your rear...

I hate to say it, but #ToldYaSo sadly happened!

I guess you gotta have to bootstrap it from scratch starting with #toybox + musl / #linux sooner or later...

Not to seem like an asshole, but I do sincerely wish GrpaheneOS and it's team only the best of luck and that the issue gets fixed sooner than later, because this #Vendor #LockIn is a major issue [and yes I do blame the Device Vendors that shit out unmaintained garbage] so unless you can afford the legal cost of actuall enforcing #EU laws re: #SecurityUpdates and force Vendors like #Fairphone to actually follow their claims re: #Security and #Updates, this won't move anywhere.

  • Yes I know you don't have that money and I don't expect this to be the case!

I do however also don't expect you to find a magical solution. My point is that there needs to be a change of strategy, and relying on Hardware you neither own nor control in the sense of Stakeholding isn't going to provide you with the necessary stability.

  • Because Google is a [pulicly traded] #Corporation and Corporations are explicity nobody's friend!
GrapheneOSGrapheneOS build documentationBuilding instructions for GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.

pirg.org/oregon/take-action/te
End of '25 Microsoft will halt #Windows10 free security fixes & updates . As many as 400 million perfectly good computers that can't upgrade to Windows 11 might be thrown out.

~40% of PCs can't upgrade to #Windows11, even if users want to. So when MS stops providing #securityupdates, those computers will either be insecure to keep using, or else turn into junk and get thrown out. >1/4 of #electronicwaste is #recycled, so most of those machines will end up in landfills.

OSPIRGTell Microsoft to extend free support for Windows 10If Microsoft ends free support for Windows 10, as many as 400 million perfectly good computers might be thrown out.

Hey folks!

Heads up: we’ve rolled out security updates for Element X Android (0.4.12) & iOS (1.6.7) to address a High severity vulnerability.

Users’ privacy matters to us so we believe it’s important to be transparent when these things occur.

Check out our latest blog post to find out more details, and update your apps to stay secure.

element.io/blog/security-relea