Martin Schobert

@nitram2342@chaos.social
213 Followers
393 Following
361 Posts
Kezboard Cowboy, Programming Robot & Functional Unit. Co-Founder of @pentagrid. All we are saying is give peace a chance.
Githubhttps://github.com/nitram2342
Workhttps://www.pentagrid.ch
Dead birdhttps://twitter.com/nitram2342
Soundcloudhttps://soundcloud.com/nitram2342
[oss-security] "the security policy of libxml2 has been changed to disclose vulnerabilities before fixes are available"

https://www.openwall.com/lists/oss-security/2025/06/16/6

CVE-2025-49794 CVE-2025-49795 CVE-2025-49796 CVE-2025-6021 CVE-2025-6170

CVE-2025-6021 looks like the most severe (integer overflow in xmlBuildQName())
oss-security - 5 security issues disclosed in libxml2

Öh? Der EU-Austritt scheint den Briten nicht gutzutun: Irgendeine Klitsche hostile-forked eine LGPL-lizenzierte Datenbank-Software und klebt eine neue Lizenz dran? Gab's für sowas nicht früher mal Klassenkeile und @LaF0rge 's feuchten Atem im Nacken?

https://exist-db.org/exist/apps/wiki/blogs/eXist/license-statement-2025-05
Atomic Wiki

TIL: The Guggenheim Bilbao got its warm metal texture only because it was constructed at a rare point in time when it was affordable to use titanium alloy cladding. The soviet navy was decommissioning a whole class of submarines which tanked global titanium prices, enabling the use of it as building material.
https://youtu.be/FnrPZuN0m-0?t=1100
The Guggenheim Bilbao Broke Engineering

YouTube

Warum Marokko im Westsahara-Konflikt auf Trump setzt

Seit Jahrzehnten erhebt Marokko Anspruch auf die Westsahara. Nun hofft Marokko, dass sich nach Frankreich auch die USA auf seine Seite schlagen. Beide Staaten haben dabei andere Konflikte und Mächte im Blick. Von Kai Küstner.

➡️ https://www.tagesschau.de/ausland/afrika/westsahara-trump-afrika-100.html?at_medium=mastodon&at_campaign=tagesschau.de

#Trump #Westsahara #Afrika

Warum Marokko im Westsahara-Konflikt auf Trump setzt

Seit Jahrzehnten erhebt Marokko Anspruch auf die Westsahara. Nun hofft Marokko, dass sich nach Frankreich auch die USA auf seine Seite schlagen. Beide Staaten haben dabei andere Konflikte und Mächte im Blick.

tagesschau.de

Wenn euer Unternehmen auf der #didacta ausstellt, dann habt ihr hoffentlich gerade euren Stand gekündigt, oder?

https://www.news4teachers.de/2025/02/eine-messe-ist-keine-zensurbehoerde-die-afd-ist-in-diesem-jahr-hauptaussteller-auf-der-didacta/

„Eine Messe ist keine Zensurbehörde“: Die AfD ist in diesem Jahr Hauptaussteller auf der didacta - Leitthema: Demokratiebildung - News4teachers

STUTTGART. Bis zu 100.000 Menschen, die meisten davon Lehrkräfte und Kita-Fachkräfte, werden auf der didacta, die übernächste Woche in Stuttgart

News4teachers
Wer keinen Bock hatte, seinen Großeltern bei den Vorkriegsstories zuzuhören, hat jetzt die Gelegenheit, das als Wiederholung nochmal in besserer Auflösung zu gucken.

Wir starten den Real-O-Mat!
Statt Wahlversprechen liefert der #RealOMat dir den Reality-Check zur #Bundestagswahl.
Mit dem Real-O-Mat erfährst du nicht, was dir Parteien vor der Wahl versprechen – sondern was sie tatsächlich tun. Positionier‘ dich zu 20 politischen Forderungen und vergleiche, wie die Parteien dazu wirklich im Bundestag abgestimmt haben.

Denn mit welcher Wahl wird’s auch real?
https://real-o-mat.de

Real-O-Mat

Reality-Check statt Wahlversprechen. Positionier’ dich zu 20 politischen Forderungen und finde raus: Mit welcher Wahl wird’s auch real?

So, this is a right to repair rant, I guess. Or a story? Anyway. Some timelines will be redacted for narrative purposes, but everything did really happen, just not in that exact order.

I have an old-ish LG TV. It's way out of warranty, and honestly holding up surprisingly well despite all the scary stories about OLED burn-in (yes, yes, technically burn-_out_, I don't care) on the internet. I like it, and have no real reason to replace it.

So, a month or two ago I see the TV randomly turn off by itself, then turn back on again. I shrug it off, probably a power spike or something. The next day it happens again. And again. And again. AND AGAIN.

OK, at this point I'm willing to admit the TV is not doing so good. Also, somehow it seems to be correlated to me turning the computer on. My first thought is power delivery, since they are on the same power rail. It's, again, a pretty old TV, and maybe there's a bad cap or something somewhere.

So I do what any engineer in my position would - I go online to look for a schematic. There is no schematic. I look for a service manual. There is no service manual. I look harder. There's a service manual for an adjacent model. It says:

- step 1: replace motherboard. did it help? if no, go to step 2
- step 2: replace power delivery board. did it help? if no, call your LG rep

OK, fuck you too, I guess. I call my LG rep, which in my case is just the customer service hotline. They say they'll send out a tech.

Fast forward two days. The tech comes in, pops open a service menu, shows me the error code. I now know there's a service menu with error codes. The error code is "CPU ABNORMAL". Very helpful. The tech says it happens to these TVs, and I need a motherboard replacement. OK, cool. I look up the error online and find a few Reddit threads that seem to corroborate that info.

Fast forward a day. The tech calls me and says they don't have spare parts, and need to order the part from LG HQ. They put in a request and we wait.

Fast forward three days. LG HQ calls me and says they don't have the part. I call the tech (who was kind enough to leave me his personal phone number). He says I should write a formal request for reimbursement (yay customer protection laws). I do that.

Fast forward a week. Somehow, LG HQ decides they don't want to reimburse me for the entire TV, so they dig up a spare part. It's $200, and the tech will be here next week to install it. OK, screw it, I'll pay, that's still a lot less than a new TV.

Fast forward... The techs are here, they install the part, things seem to work. Next day, TV reboots again. At this point, I'm starting to believe it's cursed. The techs drive out again, look at the TV, see the same error, call a higher level tech, I hijack the call, he basically says "we have no idea how those things actually work, if it breaks, we send it to HQ, but let's try another board replacement".

Fast forward to yesterday, when I accidentally stumble onto a new root exploit for the webOS versions these TVs run. I've got nothing to lose at this point, so let's dig. After a few attempts to root the TV, I have SSH in. itsaunixsystem.jpg. More specifically, it's a Linux 4.4.84 (oof) on a custom LG SoC (oofffff). I poke around a few things and what do I find? A kernel panic log. The traceback points to `stmmac`. I unplug Ethernet. The TV has been working fine since.

I don't really have a nice ending to this, especially since I'm not 100% confident that was the only issue yet, and I have not fully identified what exactly is causing the bug (though I found some suspicious looking patches in Linus' tree that are missing from LG's). However, probably an entire week's worth of person-hours has been wasted on a software bug that would have been trivial to identify if LG just gave the user enough information.

P.S. If someone from LG is reading this, DO BETTER. You lost SO MUCH fucking money on this. I lost SO MUCH fucking money on this. Hiding this information doesn't help you, and it sure as hell doesn't help me. I don't care about your giga proprietary AI picture improvement algorithm, just give me _something_ I can look at next time my computer (and yes it's a computer) shits itself.

Polizeiliche Entsperrung eines Mobiltelefons durch zwangsweises Auflegen des Fingers des Beschuldigten ist OK, sagt OLG Bremen

https://openjur.de/u/2500248.html

openJur

I hear Fortinet customers are having a lot of fun. Shall I repeat my rant about "cybersecurity" products from last time? If you run a Forti appliance: Will you stop doing so? Will you buy one from one of those other vendors that fucked up in recent years? Is there any situation in which you will admit that these things do more harm than good?