European Commission:
From baby-monitors to smart watches, from apps to computer programs, connectable hardware and software are omnipresent in our daily lives. Less apparent to many users is the security risk such products may present.
The Cyber Resilience Act (CRA) aims to safeguard consumers and businesses buying software or hardware products with digital elements. The CRA addresses the inadequate level of cybersecurity in many products, and the lack of timely security updates. It also tackles the challenges consumers and businesses currently face when trying to determining which products are cybersecure and in setting them up securely, making it easier to identify hardware and software with the proper cybersecurity features.
The CRA introduces mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of such products. These obligations must be met at every stage of the value chain. The CRA also requires manufacturers to handle vulnerabilities during the lifecycle of their products. Some products of particular relevance for cybersecurity may need to undergo a third-party assessment by a notified body before they are sold on the EU market.
Via Ron Elemans:
[…] the extremely heavy future requirements that are due on December 11, 2027.
For example, free security updates must be provided for at least five years without changes regarding the operating system requirements—a period that resets every time someone purchases an app of a particular version.
Here’s the text of it, which was approved in 2024.
Previously:
App Store Business European Union iOS Legal Mac Security
Omarchy:
Omarchy is an omakase Linux distribution based on Arch, the tiling window manager Hyprland, and the desktop construction-kit Quickshell. It ships with everything a modern, savvy computer user needs to be productive immediately. From Neovim (btw) to Chromium, Obsidian to LibreOffice, and Kdenlive to OBS Studio. Hell, even a retro Winamp-style music player is there!
This isn’t just a grab bag of preinstalled packages, though. It’s a complete system designed with both aesthetics and productivity in mind.
[…]
Omarchy isn’t like Windows and it’s not like macOS either. It’s not trying to be as familiar as possible. It’s trying to be beautiful and better.
I do not find this, or Linux on the desktop in general, very appealing. I don’t agree that it’s beautiful, though neither is current macOS. But I do find this effort interesting. The concept—preconfigure a well designed system and try to make it different and better—is good. This is not your average open-source project. It has $10M in backing from the founders of Shopify, Stripe, Dell, Twitter, Cloudflare, Sesame, and 37signals, and now (Hacker News):
Drew Houston, cofounder and co-CEO of Dropbox, and Peter Steinberger, creator of OpenClaw.
[…]
And OpenClaw has essentially provided the roadmap for how Omarchy should tackle its explosive growth. How do you deal with PR backlogs that suddenly go parabolic? What about security around plugins?
Many of these were/are Mac users.
Eduardo:
Run the upstream Omarchy desktop as a native, hardware-accelerated app on an Apple Silicon Mac.
Try Omarchy packages a project-built ARM64 Arch Linux image configured with Omarchy Quattro, a QEMU runtime using Apple Hypervisor Framework, and a small Swift/AppKit launcher into one macOS app.
One Happy Fellow (Hacker News):
Omarchy 4.0 shipped with a collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine.
All projects have security issues but not all projects have such predictable security issues. We know how to deal with untrusted inputs. We know we should not use AI-generated bash scripts for processing untrusted input, particularly with seemingly no review.
And you can’t get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited.
Previously:
Artificial Intelligence Business Dell Design Linux Mac Omarchy Open-source Software OpenClaw (Moltbot/Clawdbot)
Richard Speed (Hacker News 3):
XCancel’s home page now contains some minimal text stating: “On Monday 24th August at 8 PM EST, we received at [sic] letter from X Corp. asking to cease and desist the service XCancel.”
It says the service has been halted “until further notice.”
[…]
Nitter provided a way for users to read posts on X without requiring an account. There was no JavaScript or ads, a user’s IP could not be tracked, and it was generally a good deal snappier than the official X client, just read-only. It was the service behind platforms such as XCancel.
The only thing surprising about this is how long it took.
Nick Heer:
Companies like X and Meta are very happy to scrape the web at unprecedented scale and without permission, but have zero tolerance for the same to be done to them by, in effect, individual users. That is not because they are protective of the creative works users have contributed to these platforms. It is simply because users are not trusted to use the platforms. X does not permit third-party readers, and neither does Instagram, because their value does not come from us using these services as we wish, but from how they dictate we must.
Previously:
Legal Privacy Sunset Twitter Web