https://mwl.io/archives/23498 Michael W Lucas 发现 Vultr 的服务条款更新时做了一项重大变更,并决定拒绝接受。
You hereby grant to Vultr a non-exclusive, perpetual, irrevocable, royalty-free, fully paid-up, worldwide license (including the right to sublicense through multiple tiers) to use, reproduce, process, adapt, publicly perform, publicly display, modify, prepare derivative works, publish, transmit and distribute each of your User Content, or any portion thereof, in any form, medium or distribution method now known or hereafter existing, known or developed, and otherwise use and commercialize the User Content in any way that Vultr deems appropriate, without any further consent, notice and/or compensation to you or to any third parties, for purposes of providing the Services to you.
论仔细读小字的重要性。
You hereby grant to Vultr a non-exclusive, perpetual, irrevocable, royalty-free, fully paid-up, worldwide license (including the right to sublicense through multiple tiers) to use, reproduce, process, adapt, publicly perform, publicly display, modify, prepare derivative works, publish, transmit and distribute each of your User Content, or any portion thereof, in any form, medium or distribution method now known or hereafter existing, known or developed, and otherwise use and commercialize the User Content in any way that Vultr deems appropriate, without any further consent, notice and/or compensation to you or to any third parties, for purposes of providing the Services to you.
论仔细读小字的重要性。
delphij's shared chaos
https://mwl.io/archives/23498 Michael W Lucas 发现 Vultr 的服务条款更新时做了一项重大变更,并决定拒绝接受。 You hereby grant to Vultr a non-exclusive, perpetual, irrevocable, royalty-free, fully paid-up, worldwide license (including the right to sublicense through multiple tiers) to…
LowEndTalk
Vultr is now claiming full perpetual commercial rights over all hosted content - Page 2
There seems to be a bit of a disconnect between the legal language and our trust and safety’s team intention.
xz的上游被塞了后门。
这个人花了两年多的时间潜伏,慢慢地把攻击代码以测试用例数据作为掩盖塞进了代码库,然后在release时加料,从测试用例数据中抽出一个二进制文件。攻击payload会塞进liblzma,由于Linux上的二进制文件加载顺序,该库提供的某个不应提供的符号会进入sshd从而形成后门。
影响使用systemd的主流Linux发行版。
CVE-2024-3094。
https://www.openwall.com/lists/oss-security/2024/03/29/4
这个人花了两年多的时间潜伏,慢慢地把攻击代码以测试用例数据作为掩盖塞进了代码库,然后在release时加料,从测试用例数据中抽出一个二进制文件。攻击payload会塞进liblzma,由于Linux上的二进制文件加载顺序,该库提供的某个不应提供的符号会进入sshd从而形成后门。
影响使用systemd的主流Linux发行版。
CVE-2024-3094。
https://www.openwall.com/lists/oss-security/2024/03/29/4
🙏1
PSA:4月10日是加州地产税Installment 2的截止日期。提醒本频道读者注意及时去所在county税务官网站查询自己的房产税缴纳情况并及时缴纳地产税。
https://www.cst.cam.ac.uk/news/ross-anderson Security Engineering: A Guide to Building Dependable Distributed Systems的作者逝世
www.cst.cam.ac.uk
Ross Anderson, 1956 - 2024 | Department of Computer Science and Technology
Professor Ross Anderson FRS FRSE FREng, our friend and longtime colleague, died unexpectedly at home on Thursday 28th March, aged 67.