a Better Bubble™

Aggregator

Ward Has Always Had Heart To Give Back: Her Fourth Annual Black Honors Awards Is Feb. 23, 2024

1 year 8 months ago
ALTON - Tameter Ward has her fourth annual Black Honors Awards event scheduled for 7 p.m., Feb. 23, 2024, at Deliverance Temple Church Of Christ. Jay'lon Harrison, Bradley Macon, Taylor McCrady, Lailah Price, Demyia Kelly, and Morgan Robinson are the award recipients for the Black Honors Awards commemoration. This year, Ward plans to shed light on the youth. "It brings me great joy to put a smile on someone's face," she said. Ward is a gifted and talented woman who wears many hats. She says she has always had the heart to help and give back to others. "I plan to keep this event going each year during Black History Month for as long as I can," she said. "I am a member of my father's church Living Word Church, with Bishop Jessie Prather and first lady Barbara Prather the pastor. "Again, the Black Honors Awards will be Friday night February 23, 2024, at Deliverance Temple Church of God in Christ at 1125 East Sixth Street Alton. Gregory Harrison is the pastor." Ward said the Black

Continue Reading

Letter To The Editor: Mt. Joy Missionary Baptist Church Honors Military Personnel and Veterans in Black History Month Program

1 year 8 months ago
EDWARDSVILLE – Mt. Joy Missionary Baptist Church is proud to announce its Black History Month program, entitled “Honoring Heroes: Recognizing Our Military Legacy.” This program is scheduled for Sunday, February 18, 2024, during the morning worship services at 11 a.m. In a Special Tribute, the Church will recognize active-duty military personnel and veterans for their dedicated service to the nation. The highlight of the program will be the acknowledgment of the church’s oldest living veteran, Mr. Burnest Orr, who will turn 103 on May 6, 2024. “We are honored and pleased to recognize Mr. Orr for his service to his God and Country,” expressed Paul Pitts, Chair of the Church Military Affairs Committee. Mr. Orr, a distinguished veteran, was honorably discharged from the Army Air Corps in 1946. Upon completion of his military service, he relocated to St. Louis Missouri, embarking on a remarkable 42 year-career with McDonnell Douglas (now Boeing) as

Continue Reading

Explore This Weekend's Upcoming Events

1 year 8 months ago
From captivating plays and insightful historical exhibitions to thrilling trivia nights and delightful live performances, the diverse range of upcoming events promises something for everyone's tastes and interests. For a comprehensive list of these engaging activities and more, be sure to visit Our Community Calendar and find the perfect event to make your days memorable. Featured Get ready for a nostalgic journey with the Alton Little Theater Presents: THE FOUR POSTER . From February 16th to 25th, the Alton Little Theater will stage a heartfelt story that chronicles the highs and lows of a 35-year marriage, all set within the room that housed their four-poster bed. Witness the laughter, tears, quarrels, and endearments of this couple's life together, and be reminded of the enduring beauty of lifelong love. Step back in time and view a piece of history with the Autographed Abraham Lincoln Letter On Display! On February 17, 2024, between 8:30 a.m. and 1:00 p.m., the Hayner Genealog

Continue Reading

Board Talk – February 2024

1 year 8 months ago
By Teresa Mayhew Hess HAIL AND FAREWELL! “Hail and Farewell” is an expression that tracks back to ancient Rome and is used by many groups, especially the military, to welcome … Continued
The Hill Board

Dangerzone receives favorable audit

1 year 8 months ago

Journalists encounter electronic documents in a variety of formats in the course of their work. Spreadsheets documenting a politician’s expenses might show evidence of a lavish party taking place during a health lockdown. A PDF file might contain a proposal for a controversial military operation.

However, these documents could be digital traps, sprung by adversaries to gain access to a newsroom’s files. Any electronic document may contain malware targeting the software that’s used to open it. In the worst case, a powerful attacker may exploit a vulnerability for which there aren’t yet any security updates.

To address those risks, Dangerzone was initially developed by Micah Lee, a journalist, security engineer, and software developer. It is a cross-platform application for Mac, Windows, Linux, and Qubes OS to help anyone review electronic documents with significantly reduced risk. It does this by essentially creating a “virtual photocopy” of the document in a secure sandbox.

In 2022, Freedom of the Press Foundation (FPF) took on the continued development and improvement of Dangerzone in partnership with Lee. When it comes to security, we believe that journalists shouldn’t just have to take our word for it. That’s why, with support from the Open Technology Fund, we requested an independent security audit of the software.

In December 2023, Include Security completed an audit of the Dangerzone application and website, in a span of 12 days. This included exploratory use of the tool, manual code review, manual dynamic testing, software scans, an architecture review, a sandbox configuration review, and a review of our preliminary support for Qubes OS.

Include Security identified the following categories and numbers of findings: “Critical-Risk”: 0; “High-Risk”: 0; “Medium-Risk”: 0; and “Low-Risk”: 3. The Dangerzone team has already prioritized work on the low-risk and informational findings. Please find the full report, and our assessment of selected findings, below.

Our work on Dangerzone is far from over. With help from OTF, we are currently undertaking a review of Dangerzone’s user experience. We are also making continued architectural improvements to lay the groundwork for simpler installation, quicker updates, and new functionality. To stay up-to-date, follow Dangerzone on Mastodon.

Audit findings and next steps

We encourage users to read the security assessment of Dangerzone (FPF copy · Include Security copy), which documents the findings in great detail. As developers of Dangerzone, we would like to highlight findings L1, L2, and I7, and mention our course of action.

L1: [macOS] Opportunities for macOS Client Entitlements Hardening

For macOS, Include Security suggested that we can further harden the Dangerzone application, i.e., the graphical user interface that users see. Note that attackers cannot directly target the Dangerzone application, but it's still important to protect it, since it interacts with the files that have been produced in the untrusted conversion sandbox. The proposed way to harden the Dangerzone application is via stricter macOS entitlements, which we are actively working on.

Next steps: We are tackling this issue. For technical details and progress updates, see https://github.com/freedomofpress/dangerzone/issues/638

L2: [macOS] [Windows] [Linux] [QubesOS] LibreOffice Security Hardening Options

Dangerzone uses the LibreOffice suite internally for opening some document types. Include Security pointed out a new LibreOffice setting that disables potentially security-sensitive features en masse. Dangerzone already opens documents with macro execution disabled, but disabling other unnecessary features is a very welcome addition.

Next steps: We plan to enable this security setting in a future release. For technical details and updates, see https://github.com/freedomofpress/dangerzone/issues/379

I7: [macOS] [Windows] [Linux] [QubesOS] Out-of-Date Libraries in Use

Dangerzone is designed under the assumption that, sooner or later, attackers will gain access to the untrusted sandbox. This can be achieved via a specially crafted document that targets a vulnerability within the sandbox. That's why we harden this sandbox to ensure that even in that case, the malware stays contained.

However, our goal is to ensure that the sandbox has no known vulnerabilities by keeping it as up-to-date as possible. Our container image is continuously scanned against known CVEs, or common vulnerabilities and exposures, and we are committed to releasing a new Dangerzone version whenever a CVE critically impacts the security of the sandbox. The 0.5.1 release, which happened during the security audit and addressed the CVE findings, is an example of our policy in action.

Next steps: We plan to make container updates more frequent and noninteractive, so that users are protected in depth. For technical details and news, see https://github.com/freedomofpress/dangerzone/issues/698

Breakdown of all findings

The following table provides background or a relevant tracking issue for all audit findings.

Finding in reportIssue or status L1: [macOS] Opportunities for macOS Client Entitlements Hardeninghttps://github.com/freedomofpress/dangerzone/issues/638L2: [macOS] [Windows] [Linux] [QubesOS] LibreOffice Security Hardening Options https://github.com/freedomofpress/dangerzone/issues/379L3: [Web] Deprecated TLS Ciphers SupportedAddressed during auditI1: [macOS] [Windows] [Linux] [QubesOS] Nonessential Binaries Included in Container Imageshttps://github.com/freedomofpress/dangerzone/issues/691I2: [macOS] [Windows] [Linux] [QubesOS] Missing Password Protection Featurehttps://github.com/freedomofpress/dangerzone/issues/692I3: [macOS] [Windows] [Linux] Missing Software Status Check of Docker and Docker Desktophttps://github.com/freedomofpress/dangerzone/issues/693I4: [CLI] dangerzone-cli Disclosed File Names to Shell Historyhttps://github.com/freedomofpress/dangerzone/issues/694I5: [macOS] [Windows] [Linux] [QubesOS] Limited User Feedback for File Conversion Processhttps://github.com/freedomofpress/dangerzone/issues/695I6: [macOS] [Windows] [Linux] [QubesOS] Possible Attack Vector via OCR Enginehttps://github.com/freedomofpress/dangerzone/issues/696I7: [macOS] [Windows] [Linux] [QubesOS] Out-of-Date Libraries in UseThe particular issue was resolved in v0.5.1. The wider issue had to do with how to ship faster updates. Part of that is being able to ship container-only updates and potentially moving the pixels-to-PDF part to the host.
Freedom of the Press Foundation

Inflation Panic

1 year 8 months ago
Actual consumer prices are well behaved. Financial commentators and central bankers are not.
Robert Kuttner

Chinese Nationals Sentenced for Trafficking Counterfeit Gift Cards Across Country and Even Belleville

1 year 8 months ago
EAST ST. LOUIS – U.S. Attorney Rachelle Aud Crowe released information today that a U.S. District judge sentenced two Chinese nationals to more than 12 months imprisonment for their involvement in a gift card scheme directed at Target shoppers across the Midwest, including Belleville. Hongying Wang, 53, and Guangwei Gao, 38, pleaded guilty to one felony count of using and trafficking in a counterfeit access device. The pair have been incarcerated since Jan. 21, 2023, and so have served their full prison time. In January 2023, a Target security officer observed Wang and Gao placing gift cards onto the racks in the Belleville store for customers to purchase. Upon further review, the gift cards were altered with the codes scratched off and covered by stickers to appear untouched. “The defendants placed fake gift cards onto sales racks with the intention of stealing the loaded funds once purchased by patrons,” said U.S. Attorney Rachelle Aud Crowe. “The investigation

Continue Reading

Glow-in-the-Dark Bingo Night Shines a Light on Local Autism Services

1 year 8 months ago
EDWARDSVILLE/GLEN CARBON - On Feb. 22, 2024, the Autism Clinic at Hope invites you to “play with purpose” and enjoy ten rounds of glow-in-the-dark bingo to help fund the programs sponsored through Hope. With over $1,000 in cash prizes available and a glow hat included with every ticket, the night promises to be a fun way to help out. Jodi Ogilvy, Chief Communications and Development Officer at Hope, explained that the organization is expanding, with plans to offer more programs and clinics in the future. The fundraiser will help them to do this. “Being a nonprofit, it’s difficult to really have the funds to expand as quickly as we need to,” Ogilvy said. “But that’s where some of these fundraising events that we have come into play. It helps us to further our mission more and to meet the needs in the communities that we serve.” Located at the Moose Lodge in Edwardsville, the fundraiser invites attendees to play bingo with

Continue Reading

Tourists dead in crash after downtown concert: Report

1 year 8 months ago
A multicar crash left at least two people dead and several others injured early Wednesday in St. Louis' Downtown West neighborhood. A car struck multiple vehicles and pedestrians at about 12:30 a.m. Wednesday in the middle of the intersection at North 18th and Olive streets, according to the St. Louis Metropolitan Police Department. It happened just blocks away from the Enterprise Center, where thousands of people were leaving the Drake and J. Cole concert minutes before. A law enforcement source…
Jennifer Somers and Hunter Bassler

Alton Symphony Orchestra to Host Free Broadway Hits Concert at Hatheway Hall

1 year 8 months ago
ALTON - Calling all Broadway fans. The Alton Symphony Orchestra will host a free Afternoon of Musical Pops concert on Sunday, Feb. 18, 2024, at Hatheway Hall on the Lewis and Clark Community College campus. The concert will begin at 3 p.m. with selections from theater favorites like “Swan Lake,” “The Sound of Music," “Hamilton,” “The Phantom of the Opera,” “West Side Story” and more. The senior students from the Alton Youth Symphony will also perform, along with up-and-coming violinist Aiden Moon, the Marie Stillwell Concerto Competition Winner. Shane Williams, the maestro of the Alton Symphony Orchestra (ASO), promises a fun time for all community members who come to listen. “At the Alton Symphony, we want to make the music come alive for all, and that means everybody in the community come and enjoy and just have a great experience,” Williams said. As a performer and conductor, Williams has an impressive musical

Continue Reading