Post Top Ad

Showing posts with label news. Show all posts
Showing posts with label news. Show all posts

Monday, December 18, 2017

December 18, 2017

Lead singer of South Korean boyband Shinee dies

Kim Jong-hyun, the lead singer of the hugely popular and influential South Korean boyband Shinee, has died at the age of 27.

Image result for Kim Jong-hyun
The star, better known as Jonghyun, was found unconscious at his home in Seoul on Monday evening in an apparent suicide, South Korean media reported.
Shinee were formed in 2008 by the South Korean company SM Entertainment, and belong to the genre known as K-pop – a highly visual form of Korean pop that incorporates elements of western music. They went on to achieve great success in their home country, selling hundreds of thousands of albums and singles.
In 2011, they broke the Japanese market and went on to become one of the most successful South Korean acts in the country: the Japanese-language version of their single Replay sold more than 100,000 copies there.

Jonghyun, the lead singer of South Korean boy band Shinee, at a concert in Seoul in 2014.


News of Kim’s death prompted a flurry of messages on social media, with many fans voicing disbelief.
A Twitter account devoted to K-pop photos said: “Sending our deepest condolences to SHINee Jonghyun and those who known him well. If you’re going through a hard time, please do know that you never walk alone. Talk to someone and take care of yourself.”
Another Twitter user wrote: “Today we lost one of the most talented artists in Korea. I’m heartbroken and devastated by the news.”
Police arrived at Kim’s apartment after receiving an emergency call from his sister, according to South Korean media. The singer was taken to a nearby hospital and was later pronounced dead, police said.
The Yonhap agency reported that Kim’s sister had received a text message from her brother shortly before his death that read: “Please let me go. Tell me I did well. Final farewell.”
The five-member boyband, with Kim as their main vocalist, released their debut album, The Shinee World, in 2008. They have since released five more Korean albums and another five aimed at the Japanese market – the most recent in January this year. All of their Korean albums except their debut have topped the charts in their home country.
Shinee are considered among the best live performers in K-pop and have won multiple awards for their complex dance routines. They have also become known for setting trends in South Korea – including popularising skinny jeans. The group are frequently referred to by the moniker “the princes of K-pop”.
Kim also had a successful career as a solo singer-songwriter. He released three records: an album called She Is in 2016, which topped the Korean charts, and two compilations in 2015 and 2017. In 2015, he released a book called Skeleton Flower, which detailed the stories behind his songs. In 2010, along with other major Korean artists, he contributed vocals to Let’s Go, a campaign song for the G20 summit, which was held in Seoul.
Throughout his career he collaborated with numerous other Korean artists and also hosted his own radio show on the Korean station MBC.
Kim last appeared in public at a solo concert in Seoul this month.

Saturday, November 25, 2017

November 25, 2017

Linus Torvalds: 'I don't trust security people to do sane things'

Linus Torvalds has offered his thoughts on Linux security approaches, branding some security professionals as "f*cking morons" for focusing on process-killing rather than debugging. 

Torvalds, the creator and principal developer of the Linux kernel, does not often pull his punches when it comes to the kernel's behaviors and security.
The engineer carried on the tradition over the weekend, as Google Pixel developer Kees Cook submitted a pull request for hardened usercopy changes for v4.15-rc1, which according to Cook, narrows areas of memory "that can be copied to/from userspace in the face of usercopy bugs by adding explicit whitelisting for slab cache regions."
This has lived in -next for quite some time without major problems, but there were some late-discovered missing whitelists, so a fallback mode was added just to make sure we don't break anything," Cook said. "I expect to remove the fallback mode in a release or two."
In response, Torvalds said these kinds of pull requests "can be very painful" as time must be spent examining them as they touch core elements.
"When I pull 20+ other pull requests a day, I don't have _time_ to spend time on them," the engineer added. "They are scary because: they touch core stuff, [and] I don't trust security people to do sane things."
While Torvalds also cast doubt on the validity of the request, others urged for the suggestion to be considered.
This, in turn, prompted Cook to offer more information on the request, saying:
"This is why I introduced the fallback mode: with both kvm and sctp (ipv6) not noticed until late in the development cycle, I became much less satisfied it had gotten sufficient testing.
With the fallback mode, missed whitelists generate a WARN and are allowed, so this series effectively only introduces tight controls on the places where a whitelist is specifically introduced. And I went to great lengths to document each whitelist usage in the commit logs.
I would agree it would be nice to get at least a subset of this in, though. Linus, what would make you most comfortable?"
The question was not met lightly. Torvalds then made his position clear with some rather colorful language.
"So honestly, this is the kind of completely unacceptable "security person" behavior that we had with the original user access hardening too, and made that much more painful than it ever should have been," Torvalds said. "IT IS NOT ACCEPTABLE when security people set magical new rules, and then make the kernel panic when those new rules are violated."
"That is pure and utter bullsh*t," the engineer added. "We've had more than a quarter century _without_ those rules, you don't then suddenly waltz in and say "oh, everybody must do this, and if you haven't, we will kill the kernel."
The engineer continued, saying that the series was "incredibly broken" at the start, and security professionals need to realize that patches introduced for things such as hardening primarily serve as a debugging tool rather than anything else.
Should this be ignored and security developers see their hardening efforts primarily as a "let me kill the machine/process on bad behavior," Torvalds said he will "stop taking those sh*t patches" altogether.
"Some security people have scoffed at me when I say that security problems are primarily "just bugs," Torvalds added. "Those security people are f*cking morons."
The Linux kernel creator continued, suggesting that the primary focus should be on debugging and making sure that the version of the kernel released in the future is better than the one in use today.
However, in the engineer's view, the focus today is actually "let's kill things for bugs."
Torvalds said:
"The hardening efforts should instead _start_ from the standpoint of "let's warn about what looks dangerous, and maybe in a _year_ when we've warned for a long time, and we are confident that we've actually caught all the normal cases, _then_ we can start taking more drastic measures".
Stop this idiotic "kill on sight, ask questions later." Because it's wrong.
Right now, the biggest problem for me is that the whole thing makes me uncomfortable, because I think the people involved are coming from a completely unacceptable model to begin with."
Rather than retaliate in the same frustrated language, Cook acknowledged the commentary, saying that his "main flaw" was thinking that patches and changes could be fully tested during a single development series.
However, the developer said over the course of the latest cycle he realized this was a challenge, and made adjustments as a result.
"Well, I'd like to think I did learn something since I fixed up this series _before_ you yelled at me. :)," Cook concluded. "I'll make further adjustments and try again for v4.16."
No matter the language, however, it is good to see passionate people in both the Linux and security domains as a whole -- especially in a world where so many businesses consider security and user protection as an afterthought.

Copyright: original text from zdnet.com
November 25, 2017

Linus Torvalds: This is what drives me nuts about IT security




Developers are often accused of not thinking about security, but Linux kernel founder Linus Torvalds has had enough of security people who don't think about developers and end-users.

After blasting some kernel developers last week for killing processes in the name of hardening the kernel, Torvalds has offered a more measured explanation for his frustration with security myopia.

While he agrees that having multiple layers of security in the kernel is a good idea, certain ways of implementing it are not, in particular if it annoys users and developers by killing processes that break users' machines and wreck core kernel code. Because ultimately, if there are no users, there's not much point in having a supremely secure kernel, Torvalds contends.

"'Do no harm' should be your mantra for any new hardening work," Torvalds instructed security developers, reminding them to see the bigger picture.

"Keep your eye on the endpoint, and that this is just the first step. You need to not p**s off users, and you need to not p**s off developers," he said.

"Because in the end, those users really do matter. Without those users, your system may be 'secure', but all your security work was still just masturbation. You didn't do anything useful at all in the end."

In last week's message regarding a Google Pixel developer's hardening-focused pull request, he was annoyed that it wasn't tested properly, which he guessed was due to the attitude that "security is so important that nothing else matters".

He offered a reminder of what it means from different perspectives when a security person has found an invalid access. For the security person, the job's done, but for the developer "the bad access was just a symptom, and it needs to be reported, and debugged, and fixed, so that the bug actually gets corrected".

Torvalds' advice to security-focused contributors is to just report the bug rather than killing a process.

"As a developer, I do want the report. But if you killed the user program in the process, I'm actually _less_ likely to get the report, because the latent access was most likely in some really rare and nasty case, or we would have found it already. In the kernel, there's a high likelihood that it was in a driver, for example," Torvalds explained.

"Because it's the kernel, and because it's a driver, it's quite likely that killing the offender will do bad things to various random locks that were held, or maybe it happens in an interrupt and the whole machine is now dead if we're unlucky because there really were some very core locks being held."

Source: zdnet 

Monday, October 16, 2017

October 16, 2017

AirAsia flight returns to Perth after mid-air scare

An AirAsia Indonesia flight has been forced to turn back to Australia after pilots were alerted to a possible loss of cabin pressure, airport officials say.


Flight QZ535, bound for the Indonesian island of Bali, changed course about 25 minutes after take-off on Sunday.
The Airbus A320, carrying 151 people, landed safely at Perth Airport.
AirAsia said the flight experienced a "technical issue". Australian media said it had appeared to lose altitude.
"We were all pretty much saying goodbye to each other. It was really upsetting," one passenger told the local Nine network.
A video taken on the plane, broadcast by local media, shows oxygen masks hanging from the ceiling and one person shouting "passengers get down, passengers get down".
Another passenger, Claire Askew, told the Seven network that "panic was escalated" by airline staff who were screaming and appeared to be in tears.
In a statement, AirAsia said it was "fully committed" to the safety of passengers. It did not elaborate on the problem.


"AirAsia apologises to passengers for any inconvenience caused," the statement said.
In June, an AirAsia X flight on its way to Bali was also forced to turn back to Perth after an engine problem left it "shaking like a washing machine".
In December 2014, an AirAsia plane crashed into the Java Sea, killing all 162 people on board after the aircraft's rudder control system malfunctioned during the flight.

Friday, October 13, 2017

October 13, 2017

Xi Jinping has more clout than Donald Trump. The world should be wary

AMERICAN presidents have a habit of describing their Chinese counterparts in terms of awe. A fawning Richard Nixon said to Mao Zedong that the chairman’s writings had “changed the world”. To Jimmy Carter, Deng Xiaoping was a string of flattering adjectives: “smart, tough, intelligent, frank, courageous, personable, self-assured, friendly”. Bill Clinton described China’s then president, Jiang Zemin, as a “visionary” and “a man of extraordinary intellect”. Donald Trump is no less wowed. The Washington Post quotes him as saying that China’s current leader, Xi Jinping, is “probably the most powerful” China has had in a century


Mr Trump may be right. And were it not political suicide for an American president to say so, he might plausibly have added: “Xi Jinping is the world’s most powerful leader.” To be sure, China’s economy is still second in size to America’s and its army, though rapidly gaining muscle, pales in comparison. But economic heft and military hardware are not everything. The leader of the free world has a narrow, transactional approach to foreigners and seems unable to enact his agenda at home. The United States is still the world’s most powerful country, but its leader is weaker at home and less effective abroad than any of his recent predecessors, not least because he scorns the values and alliances that underpin American influence.

The president of the world’s largest authoritarian state, by contrast, walks with swagger abroad. His grip on China is tighter than any leader’s since Mao. And whereas Mao’s China was chaotic and miserably poor, Mr Xi’s is a dominant engine of global growth. His clout will soon be on full display. On October 18th China’s ruling Communist Party will convene a five-yearly congress in Beijing (see Briefing). It will be the first one presided over by Mr Xi. Its 2,300 delegates will sing his praises to the skies. More sceptical observers might ask whether Mr Xi will use his extraordinary power for good or ill.

World, take note
On his numerous foreign tours, Mr Xi presents himself as an apostle of peace and friendship, a voice of reason in a confused and troubled world. Mr Trump’s failings have made this much easier. At Davos in January Mr Xi promised the global elite that he would be a champion of globalisation, free trade and the Paris accord on climate change. Members of his audience were delighted and relieved. At least, they thought, one great power was willing to stand up for what was right, even if Mr Trump (then president-elect) would not.
Mr Xi’s words are heeded partly because he has the world’s largest stockpile of foreign currency to back them up. His “Belt and Road Initiative” may be puzzlingly named, but its message is clear—hundreds of billions of dollars of Chinese money are to be invested abroad in railways, ports, power stations and other infrastructure that will help vast swathes of the world to prosper. That is the kind of leadership America has not shown since the post-war days of the Marshall Plan in western Europe (which was considerably smaller).
Mr Xi is also projecting what for China is unprecedented military power abroad. This year he opened the country’s first foreign military base, in Djibouti. He has sent the Chinese navy on manoeuvres ever farther afield, including in July on NATO’s doorstep in the Baltic Sea alongside Russia’s fleet. China says it would never invade other countries to impose its will (apart from Taiwan, which it does not consider a country). Its base-building efforts are to support peacekeeping, anti-piracy and humanitarian missions, it says. As for the artificial islands with military-grade runways it is building in the South China Sea, these are purely defensive.
Unlike Vladimir Putin, Russia’s president, Mr Xi is not a global troublemaker who seeks to subvert democracy and destabilise the West. Still, he is too tolerant of troublemaking by his nuke-brandishing ally, North Korea (see Schumpeter). And some of China’s military behaviour alarms its neighbours, not only in South-East Asia but also in India and Japan.
At home, Mr Xi’s instincts are at least as illiberal as those of his Russian counterpart. He believes that even a little political permissiveness could prove not only his own undoing, but that of his regime. The fate of the Soviet Union haunts him, and that insecurity has consequences. He mistrusts not only the enemies his purges have created but also China’s fast-growing, smartphone-wielding middle class, and the shoots of civil society that were sprouting when he took over. He seems determined to tighten control over Chinese society, not least by enhancing the state’s powers of surveillance, and to keep the commanding heights of the economy firmly under the party’s thumb. All this will make China less rich than it should be, and a more stifling place to live. Human-rights abuses have grown worse under Mr Xi, with barely a murmur of complaint from other world leaders.
Liberals once mourned the “ten lost years” of reform under Mr Xi’s predecessor, Hu Jintao. Those ten years have become 15, and may exceed 20. Some optimists argue that we have not yet seen the real Mr Xi—that the congress will help him consolidate his power, and after that he will begin social and economic reforms in earnest, building on his relative success in curbing corruption. If he is a closet pluralist, however, he disguises it well. And alarmingly for those who believe that all leaders have a sell-by date, Mr Xi is thought to be reluctant to step down in 2022, when precedent suggests he should.
Reasons to be fearful
Mr Xi may think that concentrating more or less unchecked power over 1.4bn Chinese in the hands of one man is, to borrow one of his favourite terms, the “new normal” of Chinese politics. But it is not normal; it is dangerous. No one should have that much power. One-man rule is ultimately a recipe for instability in China, as it has been in the past—think of Mao and his Cultural Revolution. It is also a recipe for arbitrary behaviour abroad, which is especially worrying at a time when Mr Trump’s America is pulling back and creating a power vacuum. The world does not want an isolationist United States or a dictatorship in China. Alas, it may get both.