Windows

Microsoft Knew of Exchange Autodiscover Flaw Five Years Ago (theregister.com) 22

Thomas Claburn writes via The Register: Microsoft Exchange clients like Outlook have been supplying unprotected user credentials if you ask in a particular way since at least 2016. Though aware of this, Microsoft's advice continues to be that customers should communicate only with servers they trust. On August 10, 2016, Marco van Beek, managing director at UK-based IT consultancy Supporting Role, emailed the Microsoft Security Response Center to disclose an Autodiscover exploit that worked with multiple email clients, including Microsoft Outlook. "Basically, I have discovered that it is extremely easy to get access to Exchange (and therefore Active Directory) user passwords in plain text," he wrote. "It doesn't necessarily require any breach of corporate security, and at its most secure, is only as secure as file level access to the corporate website." His proof-of-concept exploit code, which affected Outlook (both Mac and PC), default email apps for Android and iOS, Apple Mail for Mac OS X, and others, consisted of 11 lines of PHP, though he insisted the exploit probably could have been reduced to three lines.

Microsoft acknowledged on August 11, 2016, that it had reproduced the issue in van Beek's report. Then on August 30, 2016, the Windows titan responded to van Beek by saying the report doesn't describe a genuine vulnerability: "Our security engineers and product team have reviewed this report and determined that it is not a security issue to be serviced as part of our monthly Patch Tuesday process. 'Never accept an SSL certificate without a matching host name' is already recommended for clients in the doc cited by your report: [link]. Before you send a request to a candidate, make sure it is trustworthy. Remember that you're sending the user's credentials, so it's important to make sure that you're only sharing them with a server you can trust. At a minimum, you should verify: That the endpoint is an HTTPS endpoint. Client applications should not authenticate or send data to a non-SSL endpoint. That the SSL certificate presented by the server is valid and from a trusted authority."

"This response casually forgets to consider that a hacked web server still retains a perfectly valid certificate -- it just happens to use that trusted tunnel to serve up problems," said van Beek. "Also, I have only found one Exchange client so far which actually checks the hostname against the certificate, which is Microsoft's own test tool." Van Beek said he thought it was incredible that Microsoft confirmed the behavior he reported within hours but does not consider it to be a problem. He suggested three mitigations: changing the order of operations so that DNS gets checked first; never accepting an SSL certificate without a matching host name; and reviewing why and when clients respond to authentication requests.
When asked if the company plans to take any steps to address credential exposure and whether it believes its guidance adequately addresses the problem, a Microsoft spokesperson said: "We are continuing to investigate the specific scenario shared by the researcher."
Google

Google Finally Shifting To 'Upstream First' Linux Kernel Approach For Android Features (phoronix.com) 9

Phoronix reports: Google's Android had been notorious for all of its downstream patches carried by the mobile operating system as well as various vendor/device kernel trees while in recent years more of that code has been upstreamed. Google has also been shifting to the Android Generic Kernel Image (GKI) as the basis for all their product kernels to further reduce the fragmentation. Looking ahead, Google is now talking of an "upstream first" approach for pushing new kernel features into mainline Linux before deploying them on Android. Google's Todd Kjos talked today during Linux Plumbers Conference (LPC2021) around their Generic Kernel Image initiative. With Android 12 and their Linux 5.10 based GKI image they have further cut down the fragmentation to the extent that it's "nearly eliminated."

With the Android 12 GKI, most of the vendor/OEM kernel features have now either been upstreamed into the Linux kernel, isolated to vendor modules/hooks, or merged into the Android Common Kernel. They are making good progress on the GKI front and also ensuring vendors adapt to the new approach to cut down on the kernel mess. But perhaps most exciting is their outlook for 2023 to 2024 for further reducing technical debt. They are going to pursue an "upstream first development model for new features" in making sure new code first lands into the mainline Linux kernel rather than aiming straight for lodging within the Android source tree.

Python

Is Python About to Become the Most Popular Programming Language? (zdnet.com) 176

"According to one measure, Python is potentially on the verge of becoming the most popular computer programming language," reports ZDNet, joining C and Java as the only other two languages to attain the #1 spot.

Of course, it depends on who's making the list... Python has been snapping at the heels of Java and C for the past few years on the 20-year-old Tiobe index and recently knocked Java off the second spot to rival C. Tiobe, a software testing company, bases its rankings on searches for programming languages on popular websites and search engines.

The Tiobe index is updated monthly, and it doesn't align with other language popularity rankings. For example, the electrical engineering magazine IEEE Spectrum has ranked Python as the most popular language since at least 2020, followed by Java, C, and JavaScript, while developer analyst RedMonk has JavaScript in top place, followed by Python and Java, and places C at tenth...

"Python has never been so close to the number 1 position of the TIOBE index," writes Paul Jansen, chief of Tiobe software. "It only needs to bridge 0.16% to surpass C. This might happen any time now..."

Python is hugely popular because of machine learning, but it has no place in mobile app development or web applications or development on mobile devices. It's also slow. Python's creator, Guido van Rossum, who works at Microsoft, recently conceded Python consumes too much memory and energy from hardware. He's working to improve Python's performance and reckons double is feasible...

Tiobe's top 10 programming languages in September 2021 were C, Python, Java, C++, C#, Visual Basic, JavaScript, Assembly language, PHP, and SQL. The top 20 languages also included Classic Visual Basic, Groovy, Ruby, Go, Swift, MATLAB, Fortran, R, Perl, and Delphi. Fortran's re-emergence as a top 20 language is notable. Just in July 2020, Tiobe ranked it as the 50th most popular language. But earlier this year, Fortran shot up to the 20th spot in Tiobe's index.

Paul Jansen, chief of Tiobe software, also called out some other interesting moves in this month's calculation. "Assembly gained 1 position from #9 to #8, Ruby gained 2 positions from #15 to #13, and Go went up even 4 positions from #18 to #14."
Space

Amateur Astronomer Spots Possible New Impact Flash At Jupiter (skyandtelescope.org) 32

RockDoctor writes: A recent flurry of posts to astronomy news sites points to an amateur astronomer spotting a new impact on Jupiter. Every such case documented improves our estimates of how many bodies are flying around in the (inner) solar system, and improves our estimates of how likely we are to get another hit in a year, a decade, or a century. Sky and Telescope has been pulling in more information. SpaceWeather.com has an image of the impact. (Note: some of these images have been "flipped" to an "on sky" orientation, and others haven't because astronomical telescopes generally produce an inverted image since it requires fewer reflections.) Estimates of the impactor size are unclear, but minimum sizes seem to be in the several kg range. Depending on how long the flash lasted, it could go up into the tons, which is important for estimating the number of potentially hazardous objects in the inner solar system. Space and Telescope's correspondents put the size at "up to" (important words!) the 30m range (100ft in Tudor measure), which would be around 10,000 tons -- a Chelyabinsk 2013-size body.
Medicine

High Ivermectin Overdosages Caused 1,143 Calls to America's Poison Control Centers This Year (npr.org) 440

America's poison control centers are getting more calls this year from people who tried self-medicating with ivermectin, NPR reports — with at least 592 calls coming since July 1: According to the National Poison Data System, which collects information from the nation's 55 poison control centers, there was a 245% jump in reported exposure cases from July to August — from 133 to 459. Meanwhile, emergency rooms across the country are treating more patients who have taken the drug... Most patients are overdosing on a [high-concentration] version of the drug that is formulated to treat parasites in cows and horses... The National Poison Data System says 1,143 ivermectin exposure cases were reported between Jan. 1 and Aug. 31. That marks an increase of 163% over the same period last year...

Minnesota's Poison Control System is dealing with the same problem. According to the department, only one ivermectin exposure case was reported in July, but in August, the figure jumped to nine. Kentucky has seen similar increases. Thirteen misuse calls have been reported this year, Ashley Webb, director of the Kentucky Poison Control Center, told the Louisville Courier-Journal. "Of the calls, 75% were from people who bought ivermectin from a feed store or farm supply store and treated themselves with the animal product," Webb said. The other 25% were people who had a prescription, she added.

"You are not a horse. You are not a cow. Seriously, y'all. Stop it," the FDA said in a renewed warning late last month.

Those with a prescription from a health care provider should only fill it "through a legitimate source such as a pharmacy, and take it exactly as prescribed," the agency instructs. It also cautioned that large doses of the drug are "dangerous and can cause serious harm" and said that doses of ivermectin produced for animals could contain ingredients harmful to humans. The agency added: "Even the levels of ivermectin for approved human uses can interact with other medications, like blood-thinners. You can also overdose on ivermectin, which can cause nausea, vomiting, diarrhea, hypotension (low blood pressure), allergic reactions (itching and hives), dizziness, ataxia (problems with balance), seizures, coma and even death."

At least two more states — Louisiana and Washington — have also "issued alerts after an uptick in calls to poison control centers," according to a health writer for the Associated Press: By mid-August U.S. pharmacies were filling 88,000 weekly prescriptions for the medication, a 24-fold increase from pre-COVID levels, according to the Centers for Disease Control and Prevention.

Meanwhile, U.S. poison control centers have seen a five-fold increase in emergency calls related to the drug, with some incidents requiring hospitalization.

The Internet

The 'Dead Internet' Theory Posits Forums are Now Almost Entirely Overrun By AI (theatlantic.com) 147

Ideas from 4chan (including its paranormal section) have percolated into the "dead internet" theory, writes the Atlantic, with a seminal post on another forum by "IlluminatiPirate" now arguing that the internet is almost entirely overrun by artificial intelligence: Like lots of other online conspiracy theories, the audience for this one is growing because of discussion led by a mix of true believers, sarcastic trolls, and idly curious lovers of chitchat... Peppered with casually offensive language, the post suggests that the internet died in 2016 or early 2017, and that now it is "empty and devoid of people," as well as "entirely sterile." Much of the "supposedly human-produced content" you see online was actually created using AI, IlluminatiPirate claims, and was propagated by bots, possibly aided by a group of "influencers" on the payroll of various corporations that are in cahoots with the government. The conspiring group's intention is, of course, to control our thoughts and get us to purchase stuff... He argues that all modern entertainment is generated and recommended by an algorithm; gestures at the existence of deepfakes, which suggest that anything at all may be an illusion; and links to a New York story from 2018 titled "How Much of the Internet Is Fake? Turns Out, a Lot of It, Actually."

"I think it's entirely obvious what I'm subtly suggesting here given this setup," the post continues. "The U.S. government is engaging in an artificial intelligence powered gaslighting of the entire world population." So far, the original post has been viewed more than 73,000 times...

The theory has become fodder for dramatic YouTube explainers, including one that summarizes the original post in Spanish and has been viewed nearly 260,000 times. Speculation about the theory's validity has started appearing in the widely read Hacker News forum and among fans of the massively popular YouTube channel Linus Tech Tips. In a Reddit forum about the paranormal, the theory is discussed as a possible explanation for why threads about UFOs seem to be "hijacked" by bots so often. The theory's spread hasn't been entirely organic. IlluminatiPirate has posted a link to his manifesto in several Reddit forums that discuss conspiracy theories... Anyway ... dead-internet theory is pretty far out-there. But unlike the internet's many other conspiracy theorists, who are boring or really gullible or motivated by odd politics, the dead-internet people kind of have a point... [Y]ou could even say that the point of the theory is so obvious, it's cliché — people talk about longing for the days of weird web design and personal sites and listservs all the time. Even Facebook employees say they miss the "old" internet. The big platforms do encourage their users to make the same conversations and arcs of feeling and cycles of outrage happen over and over, so much so that people may find themselves acting like bots, responding on impulse in predictable ways to things that were created, in all likelihood, to elicit that very response.

That 2018 article in New York magazine had argued that (at that time) a majority of web traffic was probably coming from bots — including especially high bot traffic on YouTube — while even the engagement metrics for major sites like Facebook had been gamed or inflated.

But whether or not that's changed, the Atlantic shares a compelling argument from a forum poster arguing that their very presence in this discussion proves they must be a bot. "If I was real I'm pretty sure I'd be out there living each day to the fullest and experiencing everything I possibly could with every given moment of the relatively infinitesimal amount of time I'll exist for instead of posting on the internet about nonsense."
Linux

Linus Torvalds Jokes About Celebrations for Linux's 30th Anniversary (zdnet.com) 21

Despite Linux reaching its 30th anniversary, "most outside the tech industry will be unaware that Linux has reached such a milestone," writes ZDNet, "even though the project has had a huge impact on everything from smartphones to cloud computing."

They add that Linus Torvalds "poked fun at that lack of recognition in his usual Sunday release note for a new stable version of the Linux kernel." "So I realize you must all still be busy with all the galas and fancy balls and all the other 30th anniversary events, but at some point you must be getting tired of the constant glitz, the fireworks, and the champagne," Torvalds said. "That ball gown or tailcoat isn't the most comfortable thing, either. The celebrations will go on for a few more weeks yet, but you all may just need a breather from them."

Linux 5.14 includes additional features for Intel's Alder Lake mobile-ready CPUs, extra AMD support and better support for the Raspberry Pi 400 PC. "Because 5.14 is out there, just waiting for you to kick the tires and remind yourself what all the festivities are about," notes Torvalds...

Torvalds is upbeat about Linux's future, predicting decades more work for the kernel's several thousand contributors who help shape the Linux kernel and drivers. "Of course, the poor tireless kernel maintainers won't have time for the festivities, because for them, this just means that the merge window will start tomorrow. We have another 30 years to look forward to, after all. But for the rest of you, take a breather, build a kernel, test it out, and then you can go back to the seemingly endless party that I'm sure you just crawled out of," he wrote.

Bug

Linux Glibc Security Fix Created a Nastier Linux Bug (zdnet.com) 74

A fix that was made in early June to the GNU C Library (glibc) introduced a new and nastier problem. Steven J. Vaughan-Nichols writes via ZDNet: The first problem wasn't that bad. As Siddhesh Poyarekar, a Red Hat principal software engineer wrote, "In order to mount a minimal attack using this flaw, an attacker needs many pre-requisites to be able to even crash a program using this mq_notify bug." Still, it needed patching and so it was fixed. Alas, the fix contained an even nastier bug. While checking the patch, Nikita Popov, a member of the CloudLinux TuxCare Team, found the problem. It turns out that it is possible to cause a situation where a segmentation fault could be triggered within the library. This can lead to any application using the library crashing. This, of course, would cause a Denial-of-Service (DoS) issue. This problem, unlike the earlier one, would be much easier to trigger. Whoops.

Red Hat gives the problem in its Common Vulnerability Scoring System (CVSS) a score of 7.5, which is "high." An attack using it would be easy to build and requires no privileges to be made. In short, it's bad news. Popov himself thinks "every Linux application including interpreters of other languages (python, PHP) is linked with glibc. It's the second important thing after the kernel itself, so the impact is quite high." [...] The good news is both the vulnerability and code fix have been submitted to the glibc development team. It has already been incorporated into upstream glibc.

In addition, a new test has been submitted to glibc's automated test suite to pick up this situation and prevent it from happening in the future. The bottom line is sometimes changed in unrelated code paths can lead to behaviors changing elsewhere without the programmer realizing what's going on. This test will catch this situation. The Linux distributors are still working out the best way to deploy the fix. In the meantime, if you want to be extra careful -- and I think you should be -- you should upgrade to the newest stable version of glibc 2.34 or higher.

Debian

Debian 11 'Bullseye' Released As Stable (debian.org) 40

"One of the oldest and most renowned distributions of Linux has been released!" âwrites Slashdot reader Washuu2. Phoronix reports it took "just over two years in development." Debian 11 brings many new features as outlined this morning with the big upgrade to Linux 5.10 LTS, exFAT file-system support, control groups v2, yescrypt for password hashing, and a plethora of updated packages. GNOME 3.38, KDE Plasma 5.20, and Xfce 4.16 are among the desktop options for Debian 11.
Debian.org adds: Do you want to celebrate the release? We provide some bullseye artwork that you can share or use as base for your own creations. Follow the conversation about bullseye in social media via the #ReleasingDebianBullseye and #Debian11Bullseye hashtags...
Around the world, there were even several in-person and online release parties — with a few more upcoming!
Star Wars Prequels

At Disney World's Star Wars-Themed Hotel, a Weekend for Two Costs $4,800 (sfgate.com) 91

"If you've ever dreamed of living 'a long time ago in a galaxy far, far away,' now is your chance — as long as you've got a spare four to six thousand dollars sitting around," writes SFGate: This week, Walt Disney World announced more details about its new Galactic Starcruiser hotel opening in the spring, an immersive, two-day "Star Wars" experience that evokes the feeling of being in the movies. The tech will be more advanced than any other Disney experience, including Rise of the Resistance at Disneyland and the Star Wars: Galaxy's Edge lands... "Star Wars: Galactic Starcruiser is a revolutionary new 2-night experience where you are the hero," according to Walt Disney World's website. "You and your group will embark on a first-of-its-kind Star Wars adventure that's your own. It's the most immersive Star Wars story ever created — one where you live a bespoke experience and journey further into a Star Wars adventure than you ever dreamed possible."

There are lightsaber experiences, interstellar entertainment, characters hanging around and an overall feeling that you're closer to being in Star Wars than you've ever been in your life. The idea is that you're staying on a luxury space cruise, so immersive that the hotel's windows look out into "space" and you never leave the property unless it's to "board a transport" to Batuu, the land where Star Wars: Galaxy's Edge takes place. Admission to Hollywood Studios is included in the price, as is all of your food and non-alcoholic beverages. But really, for $4,809 for two nights' accommodations for two guests in a studio, they could throw in a space beer or two...

But then again, for some Star Wars fans, you can't put a price on total immersion in the fandom, from cast members acting as though they're really intergalactic travelers to the ability to make infinite Wookee jokes free from the harsh judgements of people who wouldn't spend $4,000 to sleep in a "spaceship."

Earth

A Critical Ocean System May Be Heading For Collapse Due to Climate Change (sfgate.com) 110

The Washington Post reports: Human-caused warming has led to an "almost complete loss of stability" in the system that drives Atlantic Ocean currents, a new study has found — raising the worrying prospect that this critical aquatic "conveyer belt" could be close to collapse.

In recent years, scientists have warned about a weakening of the Atlantic Meridional Overturning Circulation (AMOC), which transports warm, salty water from the tropics to northern Europe and then sends colder water back south along the ocean floor. Researchers who study ancient climate change have also uncovered evidence that the AMOC can turn off abruptly, causing wild temperature swings and other dramatic shifts in global weather systems. Scientists haven't directly observed the AMOC slowing down. But the new analysis, published Thursday in the journal Nature Climate Change, draws on more than a century of ocean temperature and salinity data to show significant changes in eight indirect measures of the circulation's strength. These indicators suggest that the AMOC is running out of steam, making it more susceptible to disruptions that might knock it out of equilibrium, says study author Niklas Boers, a researcher at the Potsdam Institute for Climate Impact Science in Germany.

If the circulation shuts down, it could bring extreme cold to Europe and parts of North America, raise sea levels along the east coast of the United States and disrupt seasonal monsoons that provide water to much of the world.

"This is an increase in understanding . . . of how close to a tipping point the AMOC might already be," said Levke Caesar, a climate physicist at Maynooth University who was not involved in the study. Boers' analysis doesn't suggest exactly when the switch might happen. But "the mere possibility that the AMOC tipping point is close should be motivation enough for us to take countermeasures," Caesar said. "The consequences of a collapse would likely be far-reaching..." The new analysis suggests "the critical threshold is most likely much closer than we would have expected," Boers said...

[T]he apparent consequences of the AMOC slowing are already being felt. A persistent "cold blob" in the ocean south of Greenland is thought to result from less warm water reaching that region. The lagging Gulf Stream has caused exceptionally high sea level rise along the east coast of the United States. Key fisheries have been upended by the rapid temperature swings, and beloved species are struggling to cope with the changes. If the AMOC does completely shut down, the change would be irreversible in human lifetimes, Boers said. The "bi-stable" nature of the phenomenon means it will find new equilibrium in its "off" state. Turning it back on would require a shift in the climate far greater than the changes that triggered the shutdown.

"It's one of those events that should not happen, and we should try all that we can to reduce greenhouse gas emissions as quickly as possible," Boers said. "This is a system we don't want to mess with."

Linux

Steam Survey Shows Linux Marketshare Hitting 1.0% (phoronix.com) 73

According to Steam Survey numbers for July 2021, Steam on Linux hit a 1.0% marketshare, or a +0.14% increase over the month prior. Phoronix reports: This is the highest we have seen the Steam on Linux marketshare in a number of years and well off the lows prior to introducing Steam Play (Proton) since which point there has been the gradual increase in marketshare. Back when Steam on Linux first debuted there was around a 2% marketshare for Linux before gradually declining. Back when Steam first debuted for Linux, the overall Steam customer base was also much smaller than it is today.

While many believe the Steam Survey is inaccurate or biased (or just buggy towards prompting Linux users to participate in the survey), these initial numbers for July are positive in hitting the 1.0% mark after largely floating around the 0.8~0.9% mark for most of the past three years. The Steam Deck isn't shipping until the end of the year so we'll see how the number fluctuates to that point.

AMD

AMD and Valve Working On New Linux CPU Performance Scaling Design (phoronix.com) 10

Along with other optimizations to benefit the Steam Deck, AMD and Valve have been jointly working on CPU frequency/power scaling improvements to enhance the Steam Play gaming experience on modern AMD platforms running Linux. Phoronix reports: It's no secret that the ACPI CPUFreq driver code has at times been less than ideal on recent AMD processors with delivering less than expected performance/behavior with being slow to ramp up to a higher performance state or otherwise coming up short of disabling the power management functionality outright. AMD hasn't traditionally worked on the Linux CPU frequency scaling code as much as Intel does to their P-State scaling driver and other areas of power management at large. AMD is ramping up efforts in these areas including around the Linux scheduler given their recent hiring spree while it now looks like thanks to the Steam Deck there is renewed interest in better optimizing the CPU frequency scaling under Linux.

AMD and Valve have been working to improve the performance/power efficiency for modern AMD platforms running on Steam Play (Proton / Wine) and have spearheaded "[The ACPI CPUFreq driver] was not very performance/power efficiency for modern AMD platforms...a new CPU performance scaling design for AMD platform which has better performance per watt scaling on such as 3D game like Horizon Zero Dawn with VKD3D-Proton on Steam." AMD will be presenting more about this effort next month at XDC. It's quite possible this new effort is focused on ACPI CPPC support with the previously proposed AMD_CPUFreq. Back when Zen 2 launched in 2019, AMD did post patches for their new CPUFreq driver that leveraged ACPI Collaborative Processor Performance Controls but the driver was never mainlined nor any further iterations of the patches posted. When inquiring about that work a few times since then, AMD has always said it's been basically due to resource constraints that it wasn't a focus at that time. Upstream kernel developers also voiced their preference to seeing AMD work to improve the generic ACPI CPPC CPUFreq driver code rather than having another vendor-specific solution. It's also possible AMD has been working on better improvements around the now-default Schedutil governor for scheduler utilization data in making CPU frequency scaling decisions.

IT

New Startup 'Sentral' Pushes High-End Rental/Homesharing Apartments (seattlepi.com) 56

A new $500 million startup is now offering high-end apartments for short- and long-term rentals in America's "most vibrant, walkable neighborhoods". (And long-term renters can also avail themselves of its "turn-key homesharing program" to offset some of their rent.)

The Seattle Post-Intelligencer says it's "aimed mainly at tech workers, nomadic independent contractors and other folks whose work is no longer tied to a specific location." [A]menities might include workspaces offering private and collaborative office space. Inside the units themselves, residents might find work-from-home perks like adjustable height desks and ergonomic chairs. And let's not forget that work-life balance: Sentral buildings offer rooftop pools, outdoor kitchens and fire pits, gyms, photo booths, theaters, and more — as well as offering a plethora of curated events to its residents...

The folks behind the idea are savvy: CEO Jon Slavet is formerly of WeWork and Rodan + Fields. Michael Curtis, formerly VP of Engineering at Airbnb is now a strategy advisor at Sentral...

The price to lease at Sentral, given the amenities, isn't much higher than regular rent prices in the major cities it serves. The LIVE program offers designer-furnished homes for stays over 30 days starting at $2,500 a month. For comparison purposes, a studio in downtown Seattle listed on Craigslist (with none of the bling offered at Sentral) is asking $1,890 a month.

Sentral operates now in seven cities: LA, Austin, Chicago, Seattle, Denver, Chicago, Miami. An Atlanta location is next up, with more growth planned.

Sentral's press release calls them seven "vibrant gateway cities... a launchpad to explore the country's most exciting neighborhoods" (assisted by "a world-class onsite team that fosters a true sense of community"). Sentral enables residents to live or visit stylish buildings in the nation's most coveted cities for any period of time, whether a night, a month, or multiple years. Qualifying residents can also monetize their homes through Sentral's managed homeshare program... From the city registration process to logistical details such as housekeeping, insurance, photography, contactless check-in, and around-the-clock service, Sentral's turn-key platform makes homesharing seamless for hosts, enhancing their financial freedom and fueling their ability to travel and explore.
A recent tweet calls it "the future of living," while the company's new web site promises it offers "The comforts you crave + the freedom to travel."

"There has been a massive shift to a 'work-from-anywhere' culture that is blurring the lines among home, work, and travel," argues CEO Jon Slavet in Sentral's press release. And the lavish press release ends by saying that the company "is creating a global community of modern adventurers with the freedom to monetize their homes, explore their passion for travel, and live life on their own terms."
Japan

Iconic Japanese Videogame Music Incorporated Into Olympic Opening Ceremony (huffpost.com) 23

"Fans of Japanese video games couldn't believe their ears as Olympic athletes paraded into Tokyo's National Stadium during the opening ceremony for the 2020 Games on Friday..." reports the Huffington Post. During the Parade of Nations section of the ceremony, "The orchestra was playing tunes from some of their favorite games." In a celebration of Japanese popular culture that is appreciated worldwide, the entry parade was set to tunes from games developed by Sega, Capcom and Square Enix. It kicked off with "Overture: Roto's Theme" from Dragon Quest. Next up was "Victory Fanfare" from Final Fantasy. The parade featured more tunes from Monster Hunter, Soulcaliber and Sonic the Hedgehog. According to Classic FM, the music from Kingdom Hearts was composed by Yoko Shimomura, who is responsible for the music for some of the biggest video games ever made. Fans were delighted to hear her work being incorporated into the ceremony.

While the list didn't feature widely recognized tunes from cultural juggernauts like Mario Bros. or The Legend of Zelda, the music helped give a sense of atmosphere to the ceremony, which was held in almost an empty stadium due to coronavirus restrictions.

There's even an elaborate doodle at Google.com commemorating the Opening Ceremonies with an anime animation that leads to a multi-level 1980s-style videogame in which Lucky the cat competes in various sporting events. (Though the Huffington Post notes that in the real world, about 1,000 people sat in the 68,000-capacity stadium.)

The Washington Post reports the Japanese public "overwhelmingly opposed hosting the Olympics as a new wave of the pandemic hit the country." But unfortunately, host city Tokyo signed a contract agreeing the event could only be cancelled by the International Olympic Committee, and now "There's the possibility — once utterly remote — that Japanese voters could kick Prime Minister Yoshihide Suga out of power in parliamentary elections later this year."
Iphone

LG Might Sell iPhones In Its Stores After Quitting Android Devices (androidauthority.com) 20

LG will reportedly start selling iPhones and iPads in its South Korean stores this August -- mere months after the company quit making Android devices. Android Authority reports: According to MacRumors, the Herald Economic Daily claims LG has struck a deal with Apple to sell the iPhone and iPad in 400 stores across South Korea starting in August. LG may have to overcome some hurdles to make this happen. The company reportedly signed a "win-win" agreement with the country's National Mobile Communication Distribution Association that bars it from selling a direct competitor's phones in its stores. That deal was made in 2018, however, or well before LG signaled that it would quit making phones and tablets. LG is supposedly planning to renegotiate the agreement once it officially sells the iPhone and iPad in its shops. The deal unsurprisingly wouldn't include Macs, as systems like the MacBook Air compete directly with the Gram series and other LG computers where the iPhone and iPad are relatively safe.
Government

Tahoe's Workforce is Disappearing, As Many Can No Longer Afford to Live There (sfgate.com) 181

200 miles east of Silicon Valley, "A disproportionate number of people who purchased homes in Tahoe in 2020 are employees of some of the largest tech companies in the Bay Area," a real estate brokerage firm specializing in data analytics recently told Outside magazine.

Of the 2,280 new-home buyers Atlasa identified throughout the Tahoe region in 2020, roughly 30 percent worked at software companies. The top three employers were Google (54 buyers), Apple (46), and Facebook (34)... There is, however, one glaring issue with all this rapid, high-priced growth: the people who actually make a mountain town run — the ski instructors and patrollers, lift operators and shuttle drivers, housekeepers and snowcat mechanics, cooks and servers — can no longer afford to live there.
Just last year Sierra Sotheby's found more than 2,350 homes were sold across the Tahoe Basin, for a boggling $3.28 billion (up 86% from the $1.76 billion in 2019), according to the article, which calls the popular tele-working destination a "Zoom town."

Now the region's heading into its summer tourist season — but "with a shorthanded workforce, businesses are unraveling," like the restaurant that simply closed for a week because "We literally do not have enough cooks to operate..." The evidence is showing up in the ways businesses are cutting back during the peak of the busiest time of year, a time when small business owners in Tahoe typically are trying to make as much money as possible so they can survive the slower times of year...

While the hiring crisis spans far and wide across the nation, in Tahoe, the linchpin is housing. At Tahoe Dave's, Dave Wilderotter, the owner of Tahoe Dave's Skis and Boards, starts his employees at $20 an hour. Most of his employees make too much money to qualify for affordable housing. But they don't make enough money to pay Tahoe's rent prices, which have risen by 25% to 50% in the past year. Tahoe's workforce is disappearing because many of them cannot afford to live here any more... Making matters worse, Tahoe's already minimal long-term rental housing stock is getting eaten up by the very hot real estate market. Many landlords are selling homes they've been renting to local workers, leaving those tenants without many options...

"This isn't just tourism that's being hit," says Alex Mourelatos, a business owner on Tahoe's North Shore who also serves on multiple boards for the North Tahoe Public Utility District and nonprofit groups. "It's every service industry. Every industry across people, dentistry, legal, everything, Planned Urban Developments, all the special districts, firemen, teachers, all of them." The hiring crisis has even affected critical services like public transportation. Bus drivers are so hard to come by that the Tahoe Transportation District made the unprecedented decision to shut down an entire bus route down the East Shore.

The district had shuttles but no one to steer the wheel.

Programming

New Study Verifies Safety of Rust (eurekalert.org) 132

Slashdot reader Beeftopia writes: Rust has two modes: its default, safe mode, and an unsafe mode. In its default, safe mode, Rust prevents memory errors, such as "use-after-free" errors. It also prevents "data races" which is unsynchronized access to shared memory. In its unsafe mode (via use of the "unsafe" block), in which some of its APIs are written, it allows the use of potentially unsafe C-style features. The key challenge in verifying Rust's safety claims is accounting for the interaction between its safe and unsafe code. This article from April's issue of Communications of the ACM provides an overview of Rust and investigates its safety claims.
The article is co-authored by Ralf Jung, a prominent postdoctoral researcher in the 'Foundations of Programming' research group at the Max Planck Institute for Software Systems. And (spoiler alert) Jung has just received one of two 'Honorable Mentions' for the 'Dissertation Award' of the 'Association for Computing Machinery' (ACM), reports a nonprofit site operated by the American Association for the Advancement of Science: In his dissertation, Ralf Jung now provides the first formal proof that the safety promises of Rust actually hold. "We were able to verify the safety of Rust's type system and thus show how Rust automatically and reliably prevents entire classes of programming errors," says Ralf Jung.

In doing so, he also successfully addressed a special aspect of the programming language: "The so-called 'type safety' goes hand in hand with the fact that Rust imposes restrictions on the programmer and does not allow everything that the programmer wants to do. Sometimes, however, it is necessary to write an operation into the code that Rust would not accept because of its type safety," the computer scientist continues. "This is where a special feature of Rust comes into play: programmers can mark their code as 'unsafe' if they want to achieve something that contradicts the programming language's safety precautions. Together with international collaborators, including my thesis advisor Derek Dreyer, we developed a theoretical framework that allows us to prove that Rust's safety claims hold despite the possibility of writing 'unsafe' code," Jung says.

This proof, called RustBelt, is complemented by Ralf Jung with a tool called Miri, with which 'unsafe' Rust code can be automatically tested for compliance with important rules of the Rust specification - a basic requirement for correctness and safety of this code. "While RustBelt was a great success, especially in academic circles, Miri is already established in industry as a tool for security testing of programs written in Rust," explains Ralf Jung.... The ACM states: "Through Jung's leadership and active engagement with the Rust Unsafe Code Guidelines working group, his work has already had profound impact on the design of Rust and laid essential foundations for its future."

Programming

Could Python Overtake C and Java as the Most Popular Programming Language? (zdnet.com) 170

The TIOBE index of programming language popularity celebrates 20 years of continuous publishing this month. Started as a hobbyist project back in 2001, the site estimates each programming language's popularity by counting search engine results for the phrase <language> programming (indirectly counting each listing for developers, courses, and third-party vendors).

When it was started 20 years ago, the top languages were Java, C, and C++.

20 years later, the top languages are now C, Java, Python, and C++

And "The difference between position 1 and position 3 is only 0.67%." This means that the next few months will be exciting. What language is going to win this battle? Python seems to have the best chances to become number 1, thanks to its market leadership in the booming field of data mining and artificial intelligence.
ZDNet also noted the trends: Searches for C were down 4.83 percentage points compared to last July. Java searches were down 3.93% over the period, while Python gained 1.86%.

The top 10 languages behind C, Java and Python are C++, C#, Visual Basic, Javascript, PHP, Assembly Language, and SQL.

But they also have this to say about TIOBE's calculations: It's a different methodology to developer analyst RedMonk, which looks at language usage on software projects hosted on GitHub and discussions on the developer Q&A site, Stack Overflow.

RedMonk's Q1 2021 rankings place JavaScript in top place, followed by Python and Java.


Other interesting moves this month:
  • C++ gained more than 0.5% getting closer to the top 3
  • Rust rose from #30 to #27
  • Go rose from #20 to #13
  • TypeScript rose from #45 to #37
  • Haskellrose rose from #49 to #39

Slashdot Top Deals