Posted by BeauHD from Slashdot
From the please-standby department: Mishaal Rahman reports via Android Authority: Earlier today, a Senior Staff Software Engineer at Google who, according to their LinkedIn, leads the Android Systems Team and works on Android's Linux kernel fork, submitted a series of patches to AOSP that "remove ACK's support for riscv64." The description of these patches states that "support for risc64 GKI kernels is discontinued."

ACK stands for Android Common Kernel and refers to the downstream branches of the official kernel.org Linux kernels that Google maintains. The ACK is basically Linux plus some "patches of interest to the Android community that haven't been merged into mainline or Long Term Supported (LTS) kernels." There are multiple ACK branches, including android-mainline, which is the primary development branch that is forked into "GKI" kernel branches that correspond to a particular combination of supported Linux kernel and Android OS version. GKI stands for Generic Kernel Image and refers to a kernel that's built from one of these branches. Every certified Android device ships with a kernel based on one of these GKI branches, as Google currently does not certify Android devices that ship with a mainline Linux kernel build.

< This article continues on their website >
Posted by BeauHD from Slashdot
From the social-wagering department: Arcade giant Dave & Buster's said it will begin allowing customers to bet on arcade games. "Customers can soon make a friendly $5 wager on a Hot Shots basketball game, a bet on a Skee-Ball competition or on another arcade game," reports CNBC. "The betting function, expected to launch in the next few months, will work through the company's app." From the report: Dave & Buster's, started in 1982, now has more than 222 venues in North America, offering everything from bowling to laser tag, plus virtual reality. The company says it has five million loyalty members and 30 million unique visitors to its locations each year. The company's stock is up more than 50% over the past year. As a boom in betting increases engagement among sports fans, digital gamification could have a similar effect within Dave & Buster's customer base by allowing loyalty members to compete with one another and earn rewards. Ultimately, it could mean people spend more time and money at the venues.

Dave and Buster's is using technology by gamification software company Lucra. [...] Lucra and Dave & Buster's said there will be a limit placed on the size of bets it will allow, but that they're not publicly disclosing that threshold just yet. Lucra said across its history the average bet size has been $10. "We're creating a new form of kind of a digital experience for folks inside of these ecosystems," said Madding, Lucra's chief operating officer. "We're getting them to engage in a new way and spend more time and money," he added. Lucra says its skills-based games are not subject to the same licenses and regulations gambling operators face with games of chance. Lucra is careful not to use the term "bet" or "wager" to describe its games. "We use real-money contests or challenges," Madding said. Lucra's contests are only available to players age 18 and older. The contests are available in 44 states.
Posted by BeauHD from Slashdot
From the currently-in-the-works department: An anonymous reader quotes a report from Foss Outpost: Systemd lead developer Lennart Poettering has posted on Mastodon about their upcoming v256 release of Systemd, which is expected to include a sudo replacement called "run0". The developer talks about the weaknesses of sudo, and how it has a large possible attack surface. For example, sudo supports network access, LDAP configurations, other types of plugins, and much more. But most importantly, its SUID binary provides a large attack service according to Lennart: "I personally think that the biggest problem with sudo is the fact it's a SUID binary though -- the big attack surface, the plugins, network access and so on that come after it it just make the key problem worse, but are not in themselves the main issue with sudo. SUID processes are weird concepts: they are invoked by unprivileged code and inherit the execution context intended for and controlled by unprivileged code. By execution context I mean the myriad of properties that a process has on Linux these days, from environment variables, process scheduling properties, cgroup assignments, security contexts, file descriptors passed, and so on and so on."

He's saying that sudo is a Unix concept from many decades ago, and a better privilege escalation system should be in place for 2024 security standards: "So, in my ideal world, we'd have an OS entirely without SUID. Let's throw out the concept of SUID on the dump of UNIX' bad ideas. An execution context for privileged code that is half under the control of unprivileged code and that needs careful manual clean-up is just not how security engineering should be done in 2024 anymore." [...]

< This article continues on their website >
Posted by BeauHD from Slashdot
From the don't-do-the-crime-if-you-can't-do-the-time department: Binance founder Changpeng Zhao has been sentenced to four months in prison after pleading guilty to charges related to enabling money laundering through his cryptocurrency exchange. CNBC reports: The sentence handed down to Zhao in Seattle federal court was significantly less than the three years that federal prosecutors had been seeking for him. The defense had asked for five months of probation. The sentencing guidelines called for a prison term of 12 to 18 months. In November, Zhao struck a deal with the U.S. government to resolve a multiyear investigation into Binance, the world's largest cryptocurrency exchange. As part of the settlement, Zhao stepped down as the company's CEO.

Zhao, who wore a dark navy suit with a light blue tie to court, is accused of willfully failing to implement an effective anti-money laundering program as required by the Bank Secrecy Act, and of allowing Binance to process transactions involving proceeds of unlawful activity, including between Americans and individuals in sanctions jurisdictions. The U.S. ordered Binance to pay $4.3 billion in fines and forfeiture. Zhao agreed to pay a $50 million fine.
Posted by BeauHD from Slashdot
From the doing-the-impossible department: After convincing the world to buy open source and give up the Morse Code test for ham radio licenses, Bruce Perens has a new gambit: develop a license that ensures software developers receive compensation from large corporations using their work. The new Post-Open Zero Cost License seeks to address the financial disparities in open source software use and includes provisions against using content to train AI models, aligning its enforcement with non-profit performing rights organizations like ASCAP. Here's an excerpt from an interview The Register conducted with Perens: The license is one component among several -- the paid license needs to be hammered out -- that he hopes will support his proposed Post-Open paradigm to help software developers get paid when their work gets used by large corporations. "There are two paradigms that you can use for this," he explains in an interview. "One is Spotify and the other is ASCAP, BMI, and SESAC. The difference is that Spotify is a for-profit corporation. And they have to distribute profits to their stockholders before they pay the musicians. And as a result, the musicians complain that they're not getting very much at all."

"There are two paradigms that you can use for this," he explains in an interview. "One is Spotify and the other is ASCAP, BMI, and SESAC. The difference is that Spotify is a for-profit corporation. And they have to distribute profits to their stockholders before they pay the musicians. And as a result, the musicians complain that they're not getting very much at all." Perens wants his new license -- intended to complement open source licensing rather than replace it -- to be administered by a 501(c)(6) non-profit. This entity would handle payments to developers. He points to the music performing rights organizations as a template, although among ASCAP, BMI, SECAC, and GMR, only ASCAP remains non-profit. [...]

< This article continues on their website >
Posted by BeauHD from Slashdot
From the behind-the-scenes department: An anonymous reader quotes a report from TechCrunch: The ransomware gang that hacked into U.S. health tech giant Change Healthcare used a set of stolen credentials to remotely access the company's systems that weren't protected by multifactor authentication (MFA), according to the chief executive of its parent company, UnitedHealth Group (UHG). UnitedHealth CEO Andrew Witty provided the written testimony ahead of a House subcommittee hearing on Wednesday into the February ransomware attack that caused months of disruption across the U.S. healthcare system. This is the first time the health insurance giant has given an assessment of how hackers broke into Change Healthcare's systems, during which massive amounts of health data were exfiltrated from its systems. UnitedHealth said last week that the hackers stole health data on a "substantial proportion of people in America."

< This article continues on their website >
Posted by Ethan Gach from Kotaku
Fans of the original Dragon’s Dogma never dreamed the wonky fantasy RPG might get a sequel. Over a decade later, Capcom delivered a successor that improved on the flaws of the first without shaving off the sharp edges that earned it a cult following to begin with.

< This article continues on their website >
Posted by Zack Zwiezen from Kotaku
A new trailer is here for Funko Fusion, a game that looks more and more like a fever-dream mess of giant-headed characters from popular movies and shows. The game is out this September, so get excited, because our monoculture future is getting closer and closer!

< This article continues on their website >
Posted by msmash from Slashdot
From the concerning-developments department: Large swathes of Asia are sweltering through a heatwave that has topped temperature records from Myanmar to the Philippines and forced millions of children to stay home from school. From a report: In India, record temperatures have triggered a deadly heatwave and concerns about voter turnout in the nation's marathon election. Extreme heat has also forced Bangladesh to close all schools across the country. Extreme temperatures have also been recorded in Myanmar and Thailand, while huge areas of the Philippines are suffering from a drought. Experts say climate change has made heatwaves more frequent, longer and more intense, while the El Nino weather phenomenon is also driving this year's exceptionally warm weather.

Approximate voter turnout data after polls closed on April 26 in India -- when stage two of the nation's seven-stage general election took place -- put voter turnout at 61 per cent. This was lower than the 65 per cent in the first phase, and 68 per cent in the second phase five years ago. Among the states that headed to the polls last week was Kerala in the south, where media reports on April 29 said that at least two people -- a 90-year-old woman and a 53-year-old man -- were suspected to have died of heatstroke. Temperatures in Kerala soared to 41.9 deg C, nearly 5.5 deg C above normal temperatures. At least two people have also died in India's eastern state of Odisha, where temperatures hit 44.9 deg C on April 28 -- the highest recorded in April. In neighbouring Bangladesh, students will continue to stay home this week, after schools across the country were ordered shut on April 29. A two-judge bench of the country's High Court passed an order directing all primary and secondary schools and madrasahs (Islamic schools) nationwide to remain closed till May 5, affecting an estimated 32 million students.
Posted by Moises Taveras from Kotaku
If you’re anything like me, you went looking for a Fallout game to play the second you were done with watching the well-received Amazon show. Despite the fact that the ending tees up a second season that will assuredly expound on New Vegas, a settlement from a similarly titled and beloved game, I zagged a bit and…

< This article continues on their website >
Posted by msmash from Slashdot
From the how-about-that department: The Supreme Court on Tuesday refused to block on free speech grounds a provision of Texas law aimed at preventing minors from accessing pornographic content online. From a report: The justices turned away a request made by the Free Speech Coalition, a pornography industry trade group, as well as several companies. The challengers said the 2023 law violates the Constitution's First Amendment by requiring anyone using the platforms in question, including adults, to submit personal information.

One provision of the law, known as H.B. 1181, mandates that platforms verify users' ages by requiring them to submit information about their identities. Although the law is aimed at limiting children's access to sexually explicit content, the lawsuit focuses on how those measures also affect adults. "Specifically, the act requires adults to comply with intrusive age verification measures that mandate the submission of personally identifying information over the internet in order to access websites containing sensitive and intimate content," the challengers wrote in court papers.
Posted by msmash from Slashdot
From the oops department: Maciej Pocwierz, a senior software engineer Semantive, writing on Medium: A few weeks ago, I began working on the PoC of a document indexing system for my client. I created a single S3 bucket in the eu-west-1 region and uploaded some files there for testing. Two days later, I checked my AWS billing page, primarily to make sure that what I was doing was well within the free-tier limits. Apparently, it wasn't. My bill was over $1,300, with the billing console showing nearly 100,000,000 S3 PUT requests executed within just one day! By default, AWS doesn't log requests executed against your S3 buckets. However, such logs can be enabled using AWS CloudTrail or S3 Server Access Logging. After enabling CloudTrail logs, I immediately observed thousands of write requests originating from multiple accounts or entirely outside of AWS.

Was it some kind of DDoS-like attack against my account? Against AWS? As it turns out, one of the popular open-source tools had a default configuration to store their backups in S3. And, as a placeholder for a bucket name, they used... the same name that I used for my bucket. This meant that every deployment of this tool with default configuration values attempted to store its backups in my S3 bucket! So, a horde of misconfigured systems is attempting to store their data in my private S3 bucket. But why should I be the one paying for this mistake? Here's why: S3 charges you for unauthorized incoming requests. This was confirmed in my exchange with AWS support. As they wrote: "Yes, S3 charges for unauthorized requests (4xx) as well[1]. That's expected behavior." So, if I were to open my terminal now and type: aws s3 cp ./file.txt s3://your-bucket-name/random_key. I would receive an AccessDenied error, but you would be the one to pay for that request. And I don't even need an AWS account to do so.

< This article continues on their website >
Posted by Levi Winslow from Kotaku
There are over 30 side missions for you to accept in Stellar Blade, the new PS5-exclusive character action game from South Korean developer Shift Up, each with their own outcomes and rewards. Some are simple fetch quests, while others are multi-part affairs that see Eve impacting the lives of other characters. One,…

< This article continues on their website >
Posted by Claire Jackson from Kotaku
Over the weekend I spent a fair bit of time playing Stellar Blade, enjoying the action while doing my best to ignore the Discourse™. But that fun was killed when the game asked me to start moving around random boxes to complete elementary school math puzzles. And not just once, but multiple times in various areas…

< This article continues on their website >
Posted by Zack Zwiezen from Kotaku
A Catholic priest in Pottstown, Pennsylvania allegedly used a church credit card to spend over $40,000 on “power-ups” in mobile games Mario Kart Tour and Candy Crush over a three-year span.

< This article continues on their website >
Posted by msmash from Slashdot
From the how-about-that department: The Biden administration on Tuesday released rules designed to speed up permits for clean energy while requiring federal agencies to more heavily weigh damaging effects on the climate and on low-income communities before approving projects like highways and oil wells. From a report: As part of a deal to raise the country's debt limit last year, Congress required changes to the National Environmental Policy Act, a 54-year-old bedrock law that requires the government to consider environmental effects and to seek public input before approving any project that necessitates federal permits. That bipartisan debt ceiling legislation included reforms to the environmental law designed to streamline the approval process for major construction projects, such as oil pipelines, highways and power lines for wind- and solar-generated electricity. The rules released Tuesday, by the White House Council on Environmental Quality, are intended to guide federal agencies in putting the reforms in place.

But they also lay out additional requirements created to prioritize projects with strong environmental benefits, while adding layers of review for projects that could harm the climate or their surrounding communities. "These reforms will deliver smarter decisions, quicker permitting, and projects that are built better and faster," said Brenda Mallory, chair of the council. "As we accelerate our clean energy future, we are also protecting communities from pollution and environmental harms that can result from poor planning and decision making while making sure we build projects in the right places."
Posted by Willa Rowe from Kotaku
During Honkai: Star Rail’s Cosmodessy event, players were treated to a little personality test. Over the course of the minigame you’d be asked a series of questions, and in the end, based on your answers, you’d be assigned a personality linked to a game character. But the characters in the test weren’t the game’s main

< This article continues on their website >
Posted by Kenneth Shepard from Kotaku
Looking at the original trailer for the live-action Sonic the Hedgehog movie is like looking into a portal to a different timeline, one where the film itself likely doesn’t herald the arrival of a massively successful film franchise that eventually spawns a bad Paramount+ spin-off. At best, it results in a Morbius-leve…

< This article continues on their website >
Posted by Zack Zwiezen from Kotaku
Starting later this year, popular family entertainment restaurant chain Dave & Buster’s will offer its customers (who are 18 years or older) the ability to place “friendly wagers” on various games using the company’s app.

< This article continues on their website >
Posted by from MMO Champion
Developer Thoughts - Plunderstorm Game Mode and Feedback

Lead Software Engineer Orlando Salvatore has shared his thoughts on the Plunderstorm Battle Royale Game Mode and community feedback.

Originally Posted by Orlando Salvatore

Thank you for playing Plunderstorm. Feedback was heard, Plunderlords have risen, fire whirls were nerfed, tournaments were conducted, W’s were shared. We tried something new with this, and it’s been a hell of a ride.

Working on and releasing Plunderstorm has been a dream come true. Starting from an early prototype, to not knowing exactly how a BR would work, to changing how healing worked in the mode about a million times before it launched, a lot of challenges that we needed to overcome.

The energy that our peers brought to Plunderstorm while it was in development was next level. We got so many great ideas and things changed around because of our internal playtests. Every discipline brought in their passion, from QA, to the design, to the music, to the engineering, to the art, to marketing, to many more involved. There was no shortage of good ideas thrown around.

The team working on Plunderstorm day to day was relentless, driven, and clearly cared about delivering a fun, quality experience. We had many discussions about what else we could do to juice up the game mode.

Plunderstorm’s point of entry was an important one for us. Though some may have been disappointed they couldn’t use their main characters, the low amount of clicks needed, no previous content clearing required and Dragonflight not being required was an important goal of ours. We wanted anyone, no matter who you are or what experience you have, to be able to load into a Plunderstorm match. No leveling needed, nothing. Just jump straight in and start playing.

< This article continues on their website >
© Z-R0E