I Miss You, Frances

May. 5th, 2016 06:08 pm
[syndicated profile] sumana_feed
You died ten years ago today. I wish I could show you what your kids and their spouses have been up to in the last ten years. I like to believe you'd be pretty proud. Like, Leonard is making it easier for people to check out ebooks from their public libraries. I'm building a business. I wish I could tell you, I wish I could see you. I never got to ask you so many questions about Leonard's childhood, and about your own.

I miss you. I wish you weren't gone.

Wellllp

May. 4th, 2016 08:13 am
shadowspar: Members of the band B'z, sitting down (b'z sitting)
[personal profile] shadowspar
So, uh. This happened at work.

The University's been facing a tough time with declining enrollment. To make the books balance for next year, they had to cut eight staff positions.

I got called into the Dreaded Uncomfortable Meeting with five other staff members yesterday afternoon, where we learned we were being laid off. They went to great lengths to say that these reductions were a strictly financial decision that had nothing to do with our individual performance.

While I'm understandably annoyed that my position is winding down, I'm not bitter about the situation. The current leadership at AlgomaU has a lot going for them, and I truly wish them well in meeting the challenges they face. The University has the potential to be a profoundly important institution for all of Canada, and a crown jewel of our local community. I hope I see them turn that vision into a reality.

That said, I'm taking this as an opportunity to springboard on to greater things. =)

Because of our family situation, I very strongly prefer to stay local (Sault Ste Marie, Ontario, Canada), but at this point I'm open to substantial travel -- say, 25%, possibly even 40% or more depending on how it's spread out? So if there are any cool places out there who could use a *nix nerd in Software Development, QA, or Systems Administration, right now I'm all ears. ^_^
[syndicated profile] hypatia_dot_ca_feed

Posted by Leigh Honeywell

A couple of years ago I wrote a call-to-arms about fighting sexism at Security Summer Camp. While there’s been some progress since then, recent conversations on really basic safety stuff at Defcon remind us of how far we have to go as a community.

Las Vegas 89
Yup, it’s happening again.
This summer, I’ll be teaching another Ally Skills Workshop on Saturday, August 6th from 2-4PM. It will be near the Defcon venue, but it is not an official Defcon event – nor will I be attending the con myself.

If you’re interested in attending, please sign up here. I’ll send additional details closer to the date of the workshop.

I’m not charging for the workshop, but if you appreciate the work I do please consider donating to Sexual Health Innovations. SHI is a great non-profit that is working to end sexual violence on US college campuses through improved reporting technology – I’m a volunteer advisor to that project, called Callisto.


Dragon Lord Ember

May. 2nd, 2016 11:20 pm
ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
dragon_lord_ember__by_starblaze25
Source: http://starblaze25.deviantart.com/art/Dragon-Lord-Ember-604378031

Very nicely done. Look at it full sized, every scale is clear and meticulously drawn. Otherwise, it's a plain portrait and the small skinny, beaked dragon isn't a particularly pretty subject.

Entertainment Benefits of IDNYC Card

Apr. 30th, 2016 06:21 pm
[syndicated profile] sumana_feed
The new IDNYC card is free, government-issued photo ID for New York City residents. "Immigration status does not matter." That is to say, people who are came to NYC from abroad, and currently don't have legal documentation to support that, can get this card. Which is great -- it gives everyone, including them, a way to start banking, get access to schools and have something to show to hospital receptionists. It also works as a library card, and has a bunch of other benefits. Also, the application's gender options are:
  • Female
  • Male
  • Not designated

Friends of mine are getting their cards for the free memberships at the New York Botanical Garden, American Museum of Natural History, MoMA, Museum of the Moving Image, and dozens of other museums.

I was curious about the entertainment benefits, specifically, cheaper movie and theater tickets ("Movie Tickets as low as $8.00"). In order to get those benefits, you have to register at MemberDeals.com, a for-profit website run by Entertainment Benefits Group, Inc. And the site does not give you specifics about what you can expect if you register; you have to register in order to browse deals. The IDNYC site is pretty specific about the other benefits, and I'd like to know more before I register. So, in another installment of "I make phone calls to closemouthed organizations and then blog the results", I phoned up their customer service line.

I think the privacy policy strongly implies but doesn't state that EBG keeps a record of the purchases you make; the customer service rep I spoke with specifically said that EBG does not hold onto your credit card number if you make a purchase. (Which is important for PCI compliance, of course.) It seems unclear to me whether they keep a record of the discounted tickets users buy through them.

Registered members can expect special offers emails about biweekly, and can always unsubscribe.

The customer service rep did not give any examples of specific amounts in current discounts EBG offers its members, e.g., "$50 for such-and-such a ski ticket." But she said that the EBG membership includes "countless" offers to various different things, including discounted hotel rates (not mentioned on their website). The sports teams they offer discounted tickets to see include the New York Yankees. And they have deals with several movie theater chains, including Regal, AMC, and United Artists (UA), to offer discounted movie tickets to their movies in general -- it's not just "special offer: see the new Zappa documentary for $6". (I assume that there are exceptions, e.g., you can't use the discounted tickets to see certain blockbusters on opening weekend; when I've gotten discounted movie passes in the past, that's how it's worked.)

I think my cell phone glitched and ended the call before I could probe further. I am kinda averse to deliberately signing up for a for-profit marketing-centric organization's services in the hopes of ill-defined rewards, so I poked around a bit more.

EBG owns a bunch of sites (why not? "Our Technology Delivers Fun Most Efficiently") so I decided to poke around those on the theory that they're probably giving all the members access to mostly the same experiences, just branded differently and segmented at slightly different price points. Like, their site NewYork.com (available to the public) has Les Misérables tickets for $83 and up, while Working Advantage (companies contract with EBG for member-only discounts) mentions Les Mis orchestra seats for $73 on their front page right now.

Some specific prices and offers: a video urging companies to sign up mentions The Lion King, Walt Disney World, Universal Studios, and Kennedy Space Center as attractions for your employees, and promises prices "up to 50% off what the public is paying". The Tickets At Work blog promises 50% off select Yankees games, or 20% off a luxury suite at a Yankees game. The Broadway shows NewYork.com handles have a lot of overlap with what you'd get at TKTS at (to my eyeballs) vaguely similar prices, so the member-only prices would probably also be fairly good. And the Working Advantage home page mentions several specific attractions, rental car companies, etc. It also enumerates movie chains they cover:

  • AMC Theatres
  • Regal Entertainment
  • Cinemark Theatres
  • Showcase Cinemas
  • Century Theatres
  • Edwards Theatres
  • Bow Tie Cinemas
  • Hollywood/Wallace Theatres
  • Harkins Theatres
  • Malco Theatres
  • Marcus Theatres
  • Pacific Theatres
  • United Artists Theatres
  • Angelika Film Center
  • Reading Cinemas
  • Landmark Theatres

(That's on the front page, under the "Movie Tickets" hover-to-display menu; not super accessible.)

So overall, I think most IDNYC cardholders who have a bit of disposable income, and who enjoy sports/theater/theme parks/etc. but would like to save a bit of money on those things, would find it useful enough to go ahead and register to get the discounts, despite the privacy/spam implications. Hope this helps others make the decision!

ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
sunrise

In the interest of Being Excellent and considerate of those who plan to watch this episode, all references to the content of this episode are stashed under the cut and will remain so hidden for at least a month. Someponies like to watch MLP:FIM in herds and it can be a while before they get all their ponies together. 8^) As spoilers are also likely to be in any comments: don't read if you haven't yet seen the episode unless you like being spoiled. When you're ready, drop in a comment and say what you thought of this episode!

After a month, I hope Episode Discuss posts will be so far off the top page that it'll probably take the tag to find them, so about a month after posting the cut will be removed. 8^) Sometimes I go back and drop in little extras into the posts, like comics and links to the music.

Broadcast starts at 11:30 am Eastern Daylight Savings Time, which should work out to 4:30 pm UTC, 8:30 am PST and maybe about 11:30 PM Down Under. Confused? Look at the PonyCountdown widget on the community page! At the moment there are just four hours left to go.

Somebody wrote this episode. I'll find out who soon.

For Twitter, try Meghan McCarthy, Jayson Thiessen (Supervising Director of MLP:FIM), Andrea Libman , Big Jim (storyboard work, voice of Troubleshoes and Director of MLP:FIM) and Josh Haber. The hashtag to watch should be #MLPseason6.


Review for episode 6, No Second Prances, below the cut. )


Catch the show and throw in your two bits in the comments! Copy/paste your reviews into the comments, spread the wealth!


Watch No Second Prances: so far, I've snagged one copy in 1080p on YouTube. More sources later.

Download links for No Second Prances: (soon).

Read all the transcripts, including that of No Second Prances over here on the MLP wiki of transcripts.

Clear, free, logoless screengrabs from the entire episode get uploaded to the episode wiki within days of broadcast on the MLP Wikia Gallery pages, here.

The links to official channels and purchasing DVD's and episodes are now in the community sticky. A Cantonese dub of MLP:FIM season one is now being broadcast free-to-air in Hong Kong on ViuTV. Broadcast time is every Thursday and Friday at 5 PM. See http://viu.tv/epg/99
[syndicated profile] female_cs_feed

Posted by Gail Carmichael

A new professional development day was recently added to our local school board's calendar. One of my colleagues, John Duff, made the brilliant suggestion to have a 'take your kid to work day' instead of scrambling to find babysitting. Naturally, I suggested we also add a coding workshop.

Little did I know that most of the kids in attendance – my own included – were between 4 and 7 years old. Grade 4 or so was the youngest I'd ever worked with before, and the idea of teaching kindergartners was especially foreign. Thanks to the helpful advice of a few kind folks (especially Kate Arthur of kidsCODEjeunesse), the workshop turned out great!

To prepare, I read through a bunch of The Official ScratchJr Book from No Starch. The book is awesome, and I definitely plan to use it to continue working with Molly. One thing that I especially liked was the curriculum connections listed out at the end of each chapter. If you happen to be a kindergarten teacher, and have access to tablets, I highly recommend checking this book out.


In case you want to run a similar workshop, here's a bit of info on what we did. The workshop was held in our coffee shop. We moved away a bunch of tables and set up our bear beanbags in a semi-circle in front of the projector screen. I AirPlayed an iPad to the screen for demonstration purposes. To get the attention of the kids, we did a "hands on head" thing: everyone, parents included, had to have their hands on their heads before I talked about the next thing.


Before the workshop, I sent out a doc with information for parents containing the following key information.

 What we'll be doing
We will be working with ScratchJr, which is a visual block-based programming tool. While not required, you might like to learn a bit about the tool ahead of time. On the website, you can get an overview of the interface, the sprite editor, and what each block does. There are also videos with tips
ScratchJr is officially intended for ages 5-7, but the appeal for this workshop should be broader. That said, older children might prefer being a “helper” for a younger sibling and/or trying out the web-based Scratch instead. The older kids could get the basic ideas in ScratchJr first, and if they get bored, they should be able to pick up the main ideas of Scratch fairly easily. 
We have arranged to bring iPads for those who said they needed them.
We recommend bringing your laptop with you, both to look things up about ScratchJr, and to switch to Scratch if desired.
During the workshop
The assumption is that you, as the parent, will sit with your kid the whole time and work with them on their projects.  If you are bringing two kids, you may choose to have them work together or separately. We are hoping to have extra volunteers who would be able to help if they end up working separately. 
We hope to have those participating in the workshop up near the projector, “circle time” style. We should use comfy chairs and beanbags to sit on in a generally circular shape. 
One of the techniques we plan to use to gain attention of the kids is “hands on head” – when we ask kids to do this, it would be great if parents did it as well. Once everyone’s hands are on their heads (and therefore not touching the tablets/computers), we can starting talking up at the front. 
Super important: Try as much as possible to not do anything for your kid. Make sure that you guide them, ask them questions, perhaps even make suggestions, but not do it for them. 
Try to stop your kids from playing with other apps on the iPad at first (perhaps turning off wifi will help?). Later on, if they get bored of working on their own projects, they might enjoy sharing their favourite apps with the other kids.
General workshop plan
  1. How to add a new sprite and edit it.
  2. How to add a new background.
  3. Example blocks (will ask kids what they think the blocks do before showing them; time to play will be after all blocks):
    1. Move right (what does the number change?)
    2. Turn left (what does the number change?)
    3. Say (how could you have it say your name?)
    4. Play recorded sound (try recording your voice!)
  4. Example of snapping blocks together (can you guess what will happen?)
  5. Start on Green Flag:
    1. Have them add this block to the beginning of a script (suggest a bunch of movement blocks to make the character dance)
    2. Have them press the green flag button at the top
    3. What happens?
  6. Repeat forever
    1. What happens if you put a repeat forever at the end of the script, then press the green flag?
  7. Save your project! Go back to the home screen to save
--

I was pleasantly surprised that we managed to keep the attention of the youngest kids for a whole hour. Later, at lunch, several of the girls excitedly exclaimed how much they loved working on the iPads / playing with ScratchJr. Music to my ears!




We Are Softies

Apr. 28th, 2016 11:26 am
[syndicated profile] sumana_feed
At his job, Leonard is having trouble getting SQLAlchemy to do what he wants with regard to automated testing. Today he's going to construct a tiny app and test to validate his understanding of the problem so he can fix it or get help.

As I was seeing him out the door this morning:

"Good luck, honey, with SQLAlchemy! I hope you vanquish it!"
"That's what I hope too."
"Actually, I hope you learn to work together better, in a peaceable manner."
"That is, in fact, what I actually hope too."
"I love you, nonviolent Leonard."
"I love you, nonviolent Sumana."




Temps

Apr. 26th, 2016 05:12 pm
[syndicated profile] sumana_feed
As Leonard has blogged, he and I just returned from a weeklong anniversary trip to Paris, courtesy of my mom. I'm still a little jetlagged and I've said "Excusez-moi" when brushing past a stranger here in New York. But I'm awake enough to blog. In English.

Leonard's and my hands, joined on our wedding dayWe got engaged on April 18, 2006, and then married a few days later, on a spring day in the Shakespeare Garden in Central Park in New York City. That was ten years ago. It is the tritest thing in the world to be astonished at the passage of time, and yet, I remain astonished, because how can it possibly have been ten years ago that I went to that Macy's on 34th Street and bought those white trousers and camisole to wear, ten years since that Friday we came back home together and I felt like I could for the first time see decades away, as though atop a summit within my personal landscape and I could see the plains of middle age and old age stretching out beneath me?

Paris is a gratifying place to enjoy a vacation, gorgeous and delicious, and a humbling place for two Americans to celebrate Ten Whole Years of a marriage. The Celts and the Romans and Robespierre came and went before we ever paid a visit. The Arc de Triomphe has names carved into most of its sides, but then there are a couple of blank pillars, as though they're waiting. Versailles has a gallery of paintings celebrating French military victories that graciously includes a depiction of the Battle of Yorktown within the American Revolution.

I broke out my middle- and high-school French and found that French shopkeepers, bus drivers, and waiters and waitresses were friendly. They tried to speak with us in French and helped us get what we needed; one bus driver in particular went above and beyond in making sure I got on the right bus. Saying "Bonjour" upon walking in evidently sends the good-faith signal. Even the security personnel at the Paris (CDG) airport were friendlier than their counterparts at SFO or JFK.

I took a moment to visit a Hindu temple in an Indian neighborhood of Paris. The same smell of incense, the same chants, the same bellsong; a moment of home in a foreign land, even though I haven't been to a Hindu temple in the States since November. Familiarity is its own consolation, and a dangerous one. I can feel within me that impulse that would lash back against any change in the rituals, because even though of course there should be women priests and a less membrane-irritating alternative to incense smoke, I didn't grow up with them and the improvements would strike those synapses as jarring, off, ineffably wrong.

Paris's museum on the history of technology displayed not only a Jacquard loom but its predecessors; others had done programmable looms but their versions didn't auto-advance the program along with the weave, or didn't allow composability (replacing individual lines of code), and so on. Jacquard was Steve Jobs, integrating innovations. I need to remember that there are always predecessors. Leonard will probably blog more about our museum visits and meals and so on; I may not.

I now have almost three whole weeks at home before I leave to give my next conference talk. The summer's so full that I'm skipping Open Source Bridge for the first time since 2010, and even though CON.TXT and AndConf look amazing I will aim to attend them in future years.

I've been thinking about Ruth Coker Burks and role models, and Better Call Saul. I've been reading Missing Class: Strengthening Social Movement Groups by Seeing Class Cultures by Betsy Leondar-Wright, In Other Words by Jhumpa Lahiri and translated by Ann Goldstein, Sisters of the Revolution: A Feminist Speculative Fiction Anthology, edited by Ann VanderMeer and Jeff VanderMeer, Octavia's Brood: Science Fiction Stories from Social Justice Movements, edited by Walidah Imarisha and adrienne maree brown, and The Science of Herself by Karen Joy Fowler. That last one I read in the hotel room using the bedside lamp, next to my husband. Still such a strange word, "husband," or "wife" for that matter.

Kero Lantern Chronicles

Apr. 26th, 2016 12:38 am
shadowspar: A pixellated adventurer grooving in time to music (necrodancer: cadence)
[personal profile] shadowspar
So...our ski club hosts a lantern ski two evenings a year, so people can putter along enjoying the trails and the twilight. They used to use oldschool kerosene lanterns, but the club got rid of them a few years back. It sounds like they were getting dirty and rusty, and nobody was quite sure how to make them less so.

Unfortunately, the candle lanterns that replaced them don't work very well. They don't provide any substantial illumination, and in the winter, the candles burn out quickly -- they don't retain enough heat to melt their own wax well, and burn down the middle instead of across their entire width.

I went looking for a better solution, and was surprised to find that new kerosene lanterns are actually still a thing sold in North America. Like, ones for real use, as opposed to collectables or antiques that are just supposed to sit on a shelf and look nice. So I ordered one.
Read more... )
ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
pinkieRichardsmall
Source: http://sararichard.deviantart.com/gallery/

Humble Bundle, a fund raiser that bundles a bunch of items together and raises money through the sales of that bundle. Right now one such bundle is all the My Little Pony comics in electronic format, DRM-free. That means you can make copies and see the comics on any device, not just the device you downloaded to. Go to the MLP Humble Bundle to see the different tiers. The top tier also includes a physical copy that reprints two comics, the CMC plus Discord comic, and the Twilight raises baby Spike comic. In the mix of comics there is also the "art gallery" issue, the "cover gallery" issue and the "art is magic" issue. I'm not sure if that last one has come out it print yet or not.

You have until May the 4th to buy this bundle.

Monday 25 April 2016

Apr. 25th, 2016 09:22 am
[syndicated profile] lecta_feed

Posted by Mary

The golden light of autumn afternoons is the most beautiful time of year here. It’s also the only sign of autumn this year; it’s still warm, even, or especially, in the ocean. We just had our first break since I started my new job and went to visit Jen at Diamond Beach and then Andrew’s parents. We last visited Jen’s beach place in 2010 when V was a little baby, also for the ANZAC Day long weekend, and it had just turned too cold to swim. This time it was even an acceptable temperature to Andrew, and the weather was lovely. As a bonus, we didn’t have a terribly confused three month old baby with us who screamed in exhaustion for the first three hours we were there, although the trade-off is that instead of one child, we now have two.

I was thinking we’d had a quiet month, but I see we managed to squeeze in Deadpool, a trip to Luna Park, a visit to my parents for Easter, a whirlwind trip to the US for Andrew (left Sunday, visited Mountain View and New York, returned Sunday seven days later), a trip to Luna Park with Ben and Anna and then a visit to them at the beach and a trial of paddle-boarding, a tea party for A and her cousin C, and the trip this week. I’ve only been to Melbourne twice, which is a special unique to me version of quiet.

Deadpool was nearly a bust; it was the first time we’ve been rained out of the Moonlight Cinema. So we doubled down and got “luxe” tickets to see it at Hoyts, a cinema with a ceiling. The luxe cinemas are a new (to me) thing where you’re basically in a giant loungeroom: there are about eight sets of two seats. And there’s table service popcorn. A really strange feeling; private but not really. I will return to my dual approach of completely public or real loungeroom cinemas. I found the movie itself a bit frustrating; if you’re going to break the fourth wall and get all metafictional, critique your own plot and pacing, says me. We had dinner beforehand at Hartsyard, which is doing North America comfort food, up-market, strangely similar to going to a private-but-not-really cinema. But also really good.

I was warned (and believed) that paddle-boarding is harder than it looks, which isn’t much of a warning since it looks really peaceful and easy. The main issue is balance; it’s not impossible by any means, but the board moves from side to side as you’re paddling it forwards, so you’re unstable in at least four directions at once. They also have a very large turning circle, or at least they do when I’m steering them. I’d be happy to try it more regularly if I lived right on the beach but I think it would be hard to progress much without a week or two of pretty regular trying. I enjoyed giving it a go though; I miss having the freedom to try new physical things. Right now I tend to have A attached to me like a limpet when other people are having adventures.

Andrew having been away for one week is no longer really a noticeable blip in my life. I do notice that I don’t have any other adult interactions for the entire time he’s away, but I don’t so much notice that my workload is increased. It’s not as though I was kicking back those evenings anyway. He got to see Hamilton performed by (much of) the original cast, with an empty seat next to him and all. Clearly I was with him in spirit. On the other hand, I go away for two weeks on Wednesday. That’s a real dent in everyone’s lives. An empty seat or three next to me won’t be very helpful either. It will be very hard on everyone. I’ve had one or two little children for six years now, I will for another two or so. I’m more than ready for the emotional freedom that comes with a little bit of maturity.

Happy Birthday

Apr. 24th, 2016 09:30 pm
ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
happybirthday_by_carnivorouscaribou
Source: http://carnivorouscaribou.deviantart.com/art/Happy-Birthday-594961157

Now just hope she doesn't get cold and decide to teleport back!

Finding a Food Truck in Boulder, CO

Apr. 23rd, 2016 02:48 pm
altamira16: Tall ship at dusk (Default)
[personal profile] altamira16
I am supposed to be finding a food truck for an HOA party in midsummer, and I am having a really difficult time with this. Midsummer is the busy season for festivals and weddings, and a lot of food trucks are booked.

I tried "The Butcher and The Blonde." We used them last year, but they have a wedding that day. People really liked their sliders which were small sandwiches full of some shredded meat.

I filled a form for "The Ginger Pig." I am not sure if they have started up yet, but they are going to be at a festival in Denver on the day of our event. They were really responsive with their email.

I filled the form for "The French Twist," and I never heard back from them. I have seen them at a number of events. They promote it as a family business run by the parents of home schoolers.

Today, at an event at Growing Gardens, I saw "The Wheel and the Whisk" and "Two Hands Mobile Kitchen." I may try to call them.

Here is a website that has a lot of food trucks, but it is not comprehensive. And it looks like one of the trucks that they have on their list may have shut down.

In Baltimore, the food trucks made good use of Twitter to let people know where they would be, and I am just not seeing that for the food trucks in Boulder.

GM Berrow and the Mares From SMILE

Apr. 22nd, 2016 09:04 pm
ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
gm_berrow_and_the_mares_from_smile_by_pixelkitties
Source: http://pixelkitties.deviantart.com/art/GM-Berrow-and-the-Mares-from-SMILE-604345176

Perhaps I ought to buy this book and read it.

P.S.: DON'T PANIC (in big friendly letters). There will not be an episode tomorrow (23/04/2016), the next new one is slated for the following Saturday. Consult the countdown! ^_^

Circumventing Ubuntu Snap confinement

Apr. 21st, 2016 06:31 pm
[personal profile] mjg59
Ubuntu 16.04 was released today, with one of the highlights being the new Snap package format. Snaps are intended to make it easier to distribute applications for Ubuntu - they include their dependencies rather than relying on the archive, they can be updated on a schedule that's separate from the distribution itself and they're confined by a strong security policy that makes it impossible for an app to steal your data.

At least, that's what Canonical assert. It's true in a sense - if you're using Snap packages on Mir (ie, Ubuntu mobile) then there's a genuine improvement in security. But if you're using X11 (ie, Ubuntu desktop) it's horribly, awfully misleading. Any Snap package you install is completely capable of copying all your private data to wherever it wants with very little difficulty.

The problem here is the X11 windowing system. X has no real concept of different levels of application trust. Any application can register to receive keystrokes from any other application. Any application can inject fake key events into the input stream. An application that is otherwise confined by strong security policies can simply type into another window. An application that has no access to any of your private data can wait until your session is idle, open an unconfined terminal and then use curl to send your data to a remote site. As long as Ubuntu desktop still uses X11, the Snap format provides you with very little meaningful security. Mir and Wayland both fix this, which is why Wayland is a prerequisite for the sandboxed xdg-app design.

I've produced a quick proof of concept of this. Grab XEvilTeddy from git, install Snapcraft (it's in 16.04), snapcraft snap, sudo snap install xevilteddy*.snap, /snap/bin/xevilteddy.xteddy . An adorable teddy bear! How cute. Now open Firefox and start typing, then check back in your terminal window. Oh no! All my secrets. Open another terminal window and give it focus. Oh no! An injected command that could instead have been a curl session that uploaded your private SSH keys to somewhere that's not going to respect your privacy.

The Snap format provides a lot of underlying technology that is a great step towards being able to protect systems against untrustworthy third-party applications, and once Ubuntu shifts to using Mir by default it'll be much better than the status quo. But right now the protections it provides are easily circumvented, and it's disingenuous to claim that it currently gives desktop users any real security.

Besieged

Apr. 21st, 2016 09:47 pm
ponyville_trot: Six cartoon ponies in a huddle (Default)
[personal profile] frith posting in [community profile] ponyville_trot
besieged_by_shamanguli
Source: http://shamanguli.deviantart.com/art/Besieged-604390330

Chrysalis is crownless and a bit wooden, but here there is balanced points of interest and story. Desolation, nightfall, implied intent or plotting.

Profile

terriko: (Default)
terriko

April 2016

S M T W T F S
     12
3 456789
10111213141516
17181920212223
24252627282930

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated May. 5th, 2016 09:55 pm
Powered by Dreamwidth Studios