Sunday, November 28, 2021

‘Papi a la orden’: los candidatos prometen una nueva era, pero están atados al pasado


By BY ANATOLY KURMANAEV from NYT en Español https://ift.tt/3xv3dx1
via IFTTT

Los hondureños buscan un alivio de la desesperación en unas elecciones con repercusiones para Estados Unidos


By BY ANATOLY KURMANAEV from NYT en Español https://ift.tt/3rf6lvR
via IFTTT

Virgil Abloh, Bold Designer of Men’s Wear, Dies at 41


By BY VANESSA FRIEDMAN from NYT Style https://ift.tt/3liQfNM
via IFTTT

Elecciones presidenciales en Honduras: ¿qué está en juego hoy?


By BY OSCAR LOPEZ from NYT en Español https://ift.tt/3paVtwc
via IFTTT

Jennifer Nettles Had Sung ‘She Used to Be Mine.’ But Not While Crying.


By BY ELISABETH VINCENTELLI from NYT Theater https://ift.tt/3Iczi1F
via IFTTT

New top story on Hacker News: BMW removing touchscreen from a bunch of models due to chip shortage

BMW removing touchscreen from a bunch of models due to chip shortage
7 by edward | 0 comments on Hacker News.


New top story on Hacker News: A small Scheme implementation with AOT and incremental compilers that fits in 4K

A small Scheme implementation with AOT and incremental compilers that fits in 4K
4 by eatonphil | 0 comments on Hacker News.


New top story on Hacker News: Ask HN: What's the best way to secure your workstation?

Ask HN: What's the best way to secure your workstation?
18 by bccdee | 14 comments on Hacker News.
Here's a very plausible threat: Some developer with a left-pad package, some dependency-of-a-dependency, injects malware into their library. A developer (who is broadly trustworthy) updates their package's dependencies without auditing them properly, and the malware ends up in a VSCode plugin that you use. You open VSCode, your system is infected. We know this sort of malware is making its way onto package repositories [1]. We know people are falling for these attacks. How do we protect ourselves against this family of threats? [1]: https://ift.tt/3eIvIio We could trust nothing beyond our base system and our browser, and refuse to use any code we don't fully audit, but this would be an impossibly austere way to live. I expect most of us, when pressed, would admit that we're trusting much more code than we would like to. The alternative is sandboxing, using a lightweight option like firejail (which I use) or a totalizing system like QubesOS. But these systems are awkward to use, and have their own drawbacks. What's the bar for reasonable security, in your opinion? How do you secure your workstation without living like a monk?

Listen to Stephen Sondheim’s 20 Essential Songs


By BY ERIC GRODE from NYT Theater https://ift.tt/32KJU7H
via IFTTT

South Africa, whose scientists detected Omicron, is an outlier on the least vaccinated continent.


By BY DECLAN WALSH AND LYNSEY CHUTEL from NYT World https://ift.tt/3DWvuil
via IFTTT