Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB) se zapojil do mezinárodní iniciativy vedené americkou agenturou CISA (Cybersecurity and Infrastructure Security Agency) a dalšími partnery, jejímž cílem je stanovit minimální náležitosti pro tzv. Software Bill of Materials (SBOM). Nový dokument přináší praktická doporučení, jak by měl vypadat přehled komponent softwaru a jak s ním v praxi pracovat. SBOM lze
… více »V aktuálním přehledu vývoje renderovacího jádra webového prohlížeče Servo (Wikipedie) bylo oznámeno vydání nové verze 0.4.0. Výrazně se zlepšilo vykreslování stránek jako lichess.org, Zulip nebo Speedtest.
Vládní CERT upozorňuje (𝕏) na kritické zranitelnosti v produktech VMware: CVE-2026-59309, CVE-2026-59310 a CVE-2026-47876. Zranitelnosti v VMware vCenter umožňují vzdálenému útočníkovi se síťovým přístupem obejít autentizaci a získat neoprávněný přístup k vCenter, případně zneužít directory traversal ke spuštění libovolného kódu na vCenter.
Společnost Coinkite upozorňuje na bezpečnostní chybu svých hardwarových kryptopeněženek Coldcard. Jedná se o kritickou chybu v generování náhodných čísel (RNG). Místo hardwarového generátoru náhodných čísel (TRNG) byl omylem používán softwarový fallback (PRNG).
Představena byla nová linuxová distribuce Shadowfetch Linux. Na rozdíl od mnoha nováčků, které nabízejí převážně jiné téma a výběr softwaru, tato distribuce založená na Debianu Testing s desktopovým prostředím KDE Plasma 6.6, klade lokálně běžící umělou inteligenci do centra svého desktopového zážitku.
Max Leiter v roce 2019 zkusil zprovoznit X server na iPadu (iOS). Nyní se k tématu vrátil a s pomocí LLM a balíčkovacích nástrojů Procursus rozběhl desktop s X11 i Waylandem. Jeho balíčky jsou dostupné v repozitáři xiOS.
Společnost Google Cloud dnes oznámila, že její infrastruktura a služby byly oficiálně zařazeny do Katalogu cloud computingu vedeného Digitální a informační agenturou (DIA). Tato certifikace potvrzuje, že infrastruktura a služby Google Cloud splňují přísné bezpečnostní a regulační požadavky České republiky pro provoz cloudových služeb ve veřejném sektoru.
Vůbec poprvé v historii se stát při testování digitálních služeb obrací na širokou veřejnost. Digitální a informační agentura (DIA) a Ministerstvo vnitra zvou občany k zapojení do zátěžového testu eDokladů, které od loňského podzimu prošly optimalizací aplikace a posílením infrastruktury. Test proběhne 13. srpna ve 13:00 a pro jeho úspěch bude potřeba zapojení několika desítek tisíc občanů. Zapojení do testu je zcela dobrovolné a úkol
… více »FireDragon je webový prohlížeč, doposud založený na Floorpu, jednom z forků Firefoxu s větším důrazem na ochranu soukromí a přizpůsobení uživatelského rozhraní. Spravuje ho člen komunity distribuce Garuda Linux. Nové vydání verze 13 opouští Floorp a přechází přímo na Firefox s patchi z LibreWolfu a vlastními úpravami. Dostupný je také na Flathubu.
picogame (GitHub) je malý 2D herní engine pro mikrokontroléry jako RP2040, čip uvnitř kapesní konzole Picopad. Hru napíšeš v Pythonu a vyzkoušíš ji v prohlížeči nebo desktopovém simulátoru. Až bude hotová, zkopíruješ ji na podporovanou desku. Na začátku nepotřebuješ C, sestavení firmwaru ani hardware.
Hello Mirek,
>> Hi, i would like to send donation (about 100 - 1000 euro) on madwifi
>> project to fully implement DFS and TPC futures, but i dont know what is
>> missing, or what is not working corectly and i dont know specifications
>> of DFS and TPC futures. Can you tell me what is missing, or what need to
>> be done to fully support those futures?
Well, a simple question, but a difficult answer.
An 802.11h compliant client has to implement
- Dynamic Frequency Control
- TPC (Power Control)
- Radar Detction
The behaviour of a client differs from that of an AP. And the Network
has to be managed on 5 GHz (not "AD-HOC" -> a card in this regulatory
domain must not allow to be set to AD-HOC mode).
DFC: When an AP is powered on, it has to choose a channel (randomly - for
e.g. not starting every time with "1"). It should chect for radar.
The time before he uses this channel (transmitting, broadcasting it's SSID)
is specified.
The AP has to scan ervery 24h for N seconds for a new channel (and
no radar should be detected - it has to wait 1 min, if i remember correctly).
Ideally it should find a channel which currently is not in use.
Problem: The specification insisists in waiting if there's radar. Thus a
Link which is up 24h/day, has a downtime by spec of 365 minutes a year(!).
RD: if radar is detected, the AP should "shut down" the channel immediately.
Thus it has to find a new channel. The channel where radar is detected,
should be marked persistantely for no-use for n hours (i think it was
1 hour). Persistantly means, the mark should be honourd even after reboot /
powercycle.
Problem: DOS Attack. If every channel is marked, the Link is dead.
A client searches for / follows the AP.
Ideally the client does not probe actively (MAC layer protocol), this means,
it is silent until it has seen "his" AP.
Imagine you have a link, not with AP and client, but with two APs and WDS.
And both APs have to do RadioRetection. Well, how they'll find each other?
How they both signalize that they've detected radar?
RD of a client: i do not remember exactly. I think it's a should, but not
a must. If a client detects RD and the AP honours: -> possible DOS attack
by a random client..
TPC: A client should to TPC. If not, the EIRP should be, if i remember
correctly, 3dB lesser than regulatory maximum.
But TPC should not be difficult to implement. 1W EIRP in Europe on 5GHz
is interesting, because it's better than 100mW on 2.4GHz (even when considering
FreeSpaceLoss).
For our link we've built, we first thought to use two WRAP Boards running linux.
But imhow, MadWifi does not match the requirements. Finaly, i decided
to buy a licensed 802.11h AP, and use the WRAP board as client.
With the half the max. EIRP (TPC for a client conforming to the spec);
RD is tested (but i do not know if it response "in time", due to the spec,
and there's a potential problem because it do not know if the client could
tell the AP that he had to shut down the channel. Fortunately, it did not
happen since the few weeks the link is already up).
As far as i think, a madwifi card could not be used as 802.11h AP, because
too much is missing.
For all those things (TPC, DFC, RD and some more) there are detailed
requirements in the spec. A fully compliant driver has to be conform to
them.
The regulations are a pain. Unfortunately, here in europe the 5GHz band
is in military use. And they are pedantic with everything..
Furthermore, this band is in use for Plane->Airport radar (the main reason
why RD is specified); thus it's understandable, why they insist on this
mechanism.
The spec we're talking about is
http://webapp.etsi.org/action/OP/OP20050729/en_301893v010301o.pdf
Our authority (BeNetzA (previously RegTP)) refers to this spec
(which is nerby still a draft) for further details.
I think the development should go in these steps:
- implement all the 802.11h client specs
- ideally: certify them with a decent card (for e.g. atheros wistron cm9,
which is widely in use)
- implement the 802.11h AP specs
- certify this one too
- think about WDS
Btw, A great problem i personaly had, was that it's not easy to make
messurements in this band. I configured the card to use n mW, and tried
to interprete the result with a wlan sniffer. A card which may be certified
for madwifi should be calibrated to the power settings as well.
And now, is it what you liked to hear? ;)
Regards,
- Thomas
Tiskni
Sdílej: