Tuesday, November 30, 2021

How do you say ‘Omicron’?


By BY CHRISTINE HAUSER from NYT World https://ift.tt/3xG1qVG
via IFTTT

The Gator Finds a Place at the Tailgate


By BY CHRISTINA MORALES from NYT Food https://ift.tt/32AoE4b
via IFTTT

Amid Variant Fears, U.K. Discovers Limits to Its Virus Strategy


By BY MARK LANDLER AND MEGAN SPECIA from NYT World https://ift.tt/3D8LLQ5
via IFTTT

On the Trans-Atlantic Price Gap


By BY PAUL KRUGMAN from NYT Opinion https://ift.tt/3phsHKo
via IFTTT

Andrea Bowers: Her Activism Animates Her Art


By BY SIDDHARTHA MITTER from NYT Arts https://ift.tt/3lnXeVJ
via IFTTT

Sweden Elects Its First Female Leader — for Second Time in a Week


By BY CORA ENGELBRECHT AND CHRISTINA ANDERSON from NYT World https://ift.tt/3lj3NsT
via IFTTT

November Subscriber Digest


By Unknown Author from NYT Admin https://ift.tt/3llmiN7
via IFTTT

Sunday, November 28, 2021

New top story on Hacker News: Ask HN: What's the best way to secure your workstation?

Ask HN: What's the best way to secure your workstation?
16 by bccdee | 11 comments on Hacker News.
Here's a very plausible threat: Some developer with a left-pad package, some dependency-of-a-dependency, injects malware into their library. A developer (who is broadly trustworthy) updates their package's dependencies without auditing them properly, and the malware ends up in a VSCode plugin that you use. You open VSCode, your system is infected. We know this sort of malware is making its way onto package repositories [1]. We know people are falling for these attacks. How do we protect ourselves against this family of threats? [1]: https://ift.tt/3eIvIio We could trust nothing beyond our base system and our browser, and refuse to use any code we don't fully audit, but this would be an impossibly austere way to live. I expect most of us, when pressed, would admit that we're trusting much more code than we would like to. The alternative is sandboxing, using a lightweight option like firejail (which I use) or a totalizing system like QubesOS. But these systems are awkward to use, and have their own drawbacks. What's the bar for reasonable security, in your opinion? How do you secure your workstation without living like a monk?

Saturday, November 27, 2021

Democrats Struggle to Energize Their Base as Frustrations Mount


By BY LISA LERER, ASTEAD W. HERNDON, NICK CORASANITI AND JENNIFER MEDINA from NYT U.S. https://ift.tt/3FJXoP8
via IFTTT