Who pays for fixes to open source software?
Log4Shell made visible how unpaid maintenance of critical open source building blocks creates global risks.
Read the full post27 posts
Projects, Linux, networks, systems, finds and internet standards from 2021.
Log4Shell made visible how unpaid maintenance of critical open source building blocks creates global risks.
Read the full postCodeParrot documents how a GPT-2-like code generator was built, from data collection to training. The article also shows how licence filtering and duplicates shape the data. The model was trained on publicly available Python code from GitHub.
Read the full postHackaday shows a palmtop conversion that combines the case and keyboard of the HP-95LX with a Raspberry Pi Zero, colour display and modern interfaces. The model is an HP-95LX. The new computer is based on a Raspberry Pi Zero W.
Read the full postThe article combines Transformers, oneCCL and Intel extensions for distributed CPU training. It shows that acceleration is not limited to GPUs but requires careful software tuning. oneCCL provides optimised collective communication for Intel systems.
Read the full postThe article describes the shift from isolated models to collaborative, versioned artefacts. Models, data sets and applications are meant to be developed with working methods similar to those for source code. The Hub uses Git-based repositories for models and data sets.
Read the full postThe review brings together projects from an open mentoring programme around NLP, audio, computer vision and tools. It shows how small, clearly defined projects lead new contributors into complex ecosystems. The programme brought students together with mentors from the Hugging Face ecosystem.
Read the full postRFC 9106 describes Argon2 as a memory-hard password derivation function and gives recommendations for secure parameters. Every implementation compliant with RFC 9106 must support Argon2id; Argon2d and Argon2i are optional. For password hashing, the RFC recommends an individual salt 16 bytes long.
Read the full postIn August 2021 John Binns claimed responsibility for the break-in at T-Mobile US, in which data of more than 50 million customers and prospects was leaked. According to the Wall Street Journal, the attacker used a publicly available scanner to find an unprotected router and penetrated the network from there. Stolen data included names, addresses, social security, driving licence and IMEI numbers.
Read the full postIn 2021 IBM closed three holes in the AIX kernel, including CVE-2021-29801, through which a local user without privileges could gain root access. Two further medium-risk holes allowed the kernel to be crashed. IBM listed the fixed AIX and VIOS versions in an advisory.
Read the full postIn August 2021 Intel published updates for several holes in drivers and hardware. The most dangerous was CVE-2021-0084 in the Linux RDMA driver for the X722 and 800 series Ethernet controllers, through which attackers could gain higher privileges. Further holes affected NUC laptop kits, graphics drivers, Optane PMem and the 800 series Ethernet adapters.
Read the full postThe integration brings spaCy pipelines into the Hub and gives them discoverable metadata. This makes classic NLP pipelines versionable and shareable alongside transformer models. spaCy packages can be distributed and installed via the Hub.
Read the full postSentence Transformer models get a shared home with metadata and a directly usable loading function. This makes semantic search and similarity comparison easier to reproduce. Sentence Transformers produce fixed vectors for sentences and texts.
Read the full postDIYP combines lithium cells, battery management, an inverter and USB-C into a powerful mobile energy source. The original video has the ID adY-S8AH_Jc. With high-current batteries, fusing and mechanics are an inseparable part of the circuit design.
Read the full postGradio 2.0 makes models interactively usable with a few lines of Python and allows chained demos. This lowers the hurdle for checking model behaviour visibly with real inputs. Gradio generates web interfaces directly from Python functions.
Read the full postKG shows how the accelerating expansion of the universe limits the cosmic space we can reach for good, however advanced our technology becomes. Physical limits remain real even when technical limits are pushed very far. Exploration that is not undertaken can become irreversible, because reachable matter disappears over time.
Read the full postManuel Schmitt adds FIDO U2F to the customer menu and thereby supports physical as well as virtual security keys. FIDO U2F was offered in addition to SMS and OATH-TOTP. The web hosting management itself had not yet been switched over at the time of publication.
Read the full postRFC 9000 defines QUIC with encrypted connections, multiple streams and path migration on top of UDP. Transport innovation can be rolled out over UDP without waiting for operating system kernels. Encrypted control data improves privacy and makes network diagnostics harder.
Read the full postAccelerate encapsulates device selection, mixed precision and distributed training behind a small interface. Existing PyTorch code is meant to scale without a complete framework rebuild. Accelerate supports CPU, single and multiple GPUs as well as TPU configurations.
Read the full postFlorian Winkler shows how SSH can be extended with a second factor via PAM and which configuration steps effectively secure your own Linux server. More factors only increase security if recovery and bypasses are designed just as carefully. A factor stored separately makes the theft of a single file less valuable.
Read the full postThe FreeBSD WireGuard port, initially funded for pfSense, had serious quality and integration problems.
Read the full postAnsible turns repeatable hardening steps into verifiable code for consistent Linux servers.
Read the full postThe literature review classifies methods that avoid the quadratic cost of full attention. Local windows, sparsity and compressed representations trade a global view for scalability. Full self-attention grows quadratically with the sequence length.
Read the full postThe article combines retrieval-augmented generation with Ray to scale index search and generation across several processes and devices. Knowledge retrieval thus becomes an independent, distributed part of inference. RAG combines a retriever with a generative sequence model.
Read the full postIn January 2021 AVM said it was prepared to give its new FRITZ!Box 5530 Fiber an adapted firmware for the Deutsche Glasfaser network if needed. The Broadband Forum had just certified the box for GPON, but there could be hurdles in practical use. However, a firmware update would not solve Deutsche Glasfaser’s actual problem with router freedom.
Read the full postIn 2021 Deutsche Glasfaser wanted to resolve the dispute over router freedom through talks with AVM and a FRITZ!Box firmware update. It installed an active, mains-powered fibre modem (ONT) at customers’ premises, although according to the law only passive network termination points are allowed. It charged 60 euros for removing it and threatened service restrictions.
Read the full postIn early 2021 Deutsche Glasfaser charged customers 60 euros if they wanted to connect their own router directly to the fibre instead of the operator’s ONT, and then refused contract changes. The online magazine Deskmodder reported on a complaint to the consumer advice centre and the Federal Network Agency. The operator understood router freedom to mean that customers may connect any devices via LAN behind its ONT.
Read the full postThe article describes an inference platform that combines batching, model optimisation and specialised hardware. What matters is not a single trick but tuning the entire processing chain. For certain workloads, Hugging Face reports up to a hundredfold acceleration.
Read the full post