a Better Bubble™

Aggregator

Woody Peterson Discusses Backpack Bandits, Homelessness, East Alton Trustee Campaign

2 years 2 months ago
EAST ALTON - Woody Peterson has seen firsthand the devastating effects of homelessness on community members, including one man who suffered severe frostbite and has undergone multiple amputations. As the leader of local charitable group The Backpack Bandits and a volunteer at his local Overnight Warming Location, Peterson is now running for East Alton Trustee. The Backpack Bandits have previously been involved in community cleanup efforts and providing NARCAN to everyone from unhoused individuals to local police departments . Peterson said they’ve had an incredible year this past year with several other charity events that have taken place throughout the East Alton-Wood River area. Unfortunately, the work Peterson does to help his community sometimes means seeing the worst case scenarios of homelessness up close and personal. He recently told the story on Our Daily Show! on Riverbender.com of a homeless man in the Alton and East Alton areas known as “Bear”

Continue Reading

Lunchtime Photo

2 years 2 months ago
A pair of dolphins swimming alongside our boat during my whale watching cruise last month.
Kevin Drum

Ward Has Always Had Heart To Give Back: Her Fourth Annual Black Honors Awards Is Feb. 23, 2024

2 years 2 months ago
ALTON - Tameter Ward has her fourth annual Black Honors Awards event scheduled for 7 p.m., Feb. 23, 2024, at Deliverance Temple Church Of Christ. Jay'lon Harrison, Bradley Macon, Taylor McCrady, Lailah Price, Demyia Kelly, and Morgan Robinson are the award recipients for the Black Honors Awards commemoration. This year, Ward plans to shed light on the youth. "It brings me great joy to put a smile on someone's face," she said. Ward is a gifted and talented woman who wears many hats. She says she has always had the heart to help and give back to others. "I plan to keep this event going each year during Black History Month for as long as I can," she said. "I am a member of my father's church Living Word Church, with Bishop Jessie Prather and first lady Barbara Prather the pastor. "Again, the Black Honors Awards will be Friday night February 23, 2024, at Deliverance Temple Church of God in Christ at 1125 East Sixth Street Alton. Gregory Harrison is the pastor." Ward said the Black

Continue Reading

Letter To The Editor: Mt. Joy Missionary Baptist Church Honors Military Personnel and Veterans in Black History Month Program

2 years 2 months ago
EDWARDSVILLE – Mt. Joy Missionary Baptist Church is proud to announce its Black History Month program, entitled “Honoring Heroes: Recognizing Our Military Legacy.” This program is scheduled for Sunday, February 18, 2024, during the morning worship services at 11 a.m. In a Special Tribute, the Church will recognize active-duty military personnel and veterans for their dedicated service to the nation. The highlight of the program will be the acknowledgment of the church’s oldest living veteran, Mr. Burnest Orr, who will turn 103 on May 6, 2024. “We are honored and pleased to recognize Mr. Orr for his service to his God and Country,” expressed Paul Pitts, Chair of the Church Military Affairs Committee. Mr. Orr, a distinguished veteran, was honorably discharged from the Army Air Corps in 1946. Upon completion of his military service, he relocated to St. Louis Missouri, embarking on a remarkable 42 year-career with McDonnell Douglas (now Boeing) as

Continue Reading

Explore This Weekend's Upcoming Events

2 years 2 months ago
From captivating plays and insightful historical exhibitions to thrilling trivia nights and delightful live performances, the diverse range of upcoming events promises something for everyone's tastes and interests. For a comprehensive list of these engaging activities and more, be sure to visit Our Community Calendar and find the perfect event to make your days memorable. Featured Get ready for a nostalgic journey with the Alton Little Theater Presents: THE FOUR POSTER . From February 16th to 25th, the Alton Little Theater will stage a heartfelt story that chronicles the highs and lows of a 35-year marriage, all set within the room that housed their four-poster bed. Witness the laughter, tears, quarrels, and endearments of this couple's life together, and be reminded of the enduring beauty of lifelong love. Step back in time and view a piece of history with the Autographed Abraham Lincoln Letter On Display! On February 17, 2024, between 8:30 a.m. and 1:00 p.m., the Hayner Genealog

Continue Reading

Board Talk – February 2024

2 years 2 months ago
By Teresa Mayhew Hess HAIL AND FAREWELL! “Hail and Farewell” is an expression that tracks back to ancient Rome and is used by many groups, especially the military, to welcome … Continued
The Hill Board

Dangerzone receives favorable audit

2 years 2 months ago

Journalists encounter electronic documents in a variety of formats in the course of their work. Spreadsheets documenting a politician’s expenses might show evidence of a lavish party taking place during a health lockdown. A PDF file might contain a proposal for a controversial military operation.

However, these documents could be digital traps, sprung by adversaries to gain access to a newsroom’s files. Any electronic document may contain malware targeting the software that’s used to open it. In the worst case, a powerful attacker may exploit a vulnerability for which there aren’t yet any security updates.

To address those risks, Dangerzone was initially developed by Micah Lee, a journalist, security engineer, and software developer. It is a cross-platform application for Mac, Windows, Linux, and Qubes OS to help anyone review electronic documents with significantly reduced risk. It does this by essentially creating a “virtual photocopy” of the document in a secure sandbox.

In 2022, Freedom of the Press Foundation (FPF) took on the continued development and improvement of Dangerzone in partnership with Lee. When it comes to security, we believe that journalists shouldn’t just have to take our word for it. That’s why, with support from the Open Technology Fund, we requested an independent security audit of the software.

In December 2023, Include Security completed an audit of the Dangerzone application and website, in a span of 12 days. This included exploratory use of the tool, manual code review, manual dynamic testing, software scans, an architecture review, a sandbox configuration review, and a review of our preliminary support for Qubes OS.

Include Security identified the following categories and numbers of findings: “Critical-Risk”: 0; “High-Risk”: 0; “Medium-Risk”: 0; and “Low-Risk”: 3. The Dangerzone team has already prioritized work on the low-risk and informational findings. Please find the full report, and our assessment of selected findings, below.

Our work on Dangerzone is far from over. With help from OTF, we are currently undertaking a review of Dangerzone’s user experience. We are also making continued architectural improvements to lay the groundwork for simpler installation, quicker updates, and new functionality. To stay up-to-date, follow Dangerzone on Mastodon.

Audit findings and next steps

We encourage users to read the security assessment of Dangerzone (FPF copy · Include Security copy), which documents the findings in great detail. As developers of Dangerzone, we would like to highlight findings L1, L2, and I7, and mention our course of action.

L1: [macOS] Opportunities for macOS Client Entitlements Hardening

For macOS, Include Security suggested that we can further harden the Dangerzone application, i.e., the graphical user interface that users see. Note that attackers cannot directly target the Dangerzone application, but it's still important to protect it, since it interacts with the files that have been produced in the untrusted conversion sandbox. The proposed way to harden the Dangerzone application is via stricter macOS entitlements, which we are actively working on.

Next steps: We are tackling this issue. For technical details and progress updates, see https://github.com/freedomofpress/dangerzone/issues/638

L2: [macOS] [Windows] [Linux] [QubesOS] LibreOffice Security Hardening Options

Dangerzone uses the LibreOffice suite internally for opening some document types. Include Security pointed out a new LibreOffice setting that disables potentially security-sensitive features en masse. Dangerzone already opens documents with macro execution disabled, but disabling other unnecessary features is a very welcome addition.

Next steps: We plan to enable this security setting in a future release. For technical details and updates, see https://github.com/freedomofpress/dangerzone/issues/379

I7: [macOS] [Windows] [Linux] [QubesOS] Out-of-Date Libraries in Use

Dangerzone is designed under the assumption that, sooner or later, attackers will gain access to the untrusted sandbox. This can be achieved via a specially crafted document that targets a vulnerability within the sandbox. That's why we harden this sandbox to ensure that even in that case, the malware stays contained.

However, our goal is to ensure that the sandbox has no known vulnerabilities by keeping it as up-to-date as possible. Our container image is continuously scanned against known CVEs, or common vulnerabilities and exposures, and we are committed to releasing a new Dangerzone version whenever a CVE critically impacts the security of the sandbox. The 0.5.1 release, which happened during the security audit and addressed the CVE findings, is an example of our policy in action.

Next steps: We plan to make container updates more frequent and noninteractive, so that users are protected in depth. For technical details and news, see https://github.com/freedomofpress/dangerzone/issues/698

Breakdown of all findings

The following table provides background or a relevant tracking issue for all audit findings.

Finding in reportIssue or status L1: [macOS] Opportunities for macOS Client Entitlements Hardeninghttps://github.com/freedomofpress/dangerzone/issues/638L2: [macOS] [Windows] [Linux] [QubesOS] LibreOffice Security Hardening Options https://github.com/freedomofpress/dangerzone/issues/379L3: [Web] Deprecated TLS Ciphers SupportedAddressed during auditI1: [macOS] [Windows] [Linux] [QubesOS] Nonessential Binaries Included in Container Imageshttps://github.com/freedomofpress/dangerzone/issues/691I2: [macOS] [Windows] [Linux] [QubesOS] Missing Password Protection Featurehttps://github.com/freedomofpress/dangerzone/issues/692I3: [macOS] [Windows] [Linux] Missing Software Status Check of Docker and Docker Desktophttps://github.com/freedomofpress/dangerzone/issues/693I4: [CLI] dangerzone-cli Disclosed File Names to Shell Historyhttps://github.com/freedomofpress/dangerzone/issues/694I5: [macOS] [Windows] [Linux] [QubesOS] Limited User Feedback for File Conversion Processhttps://github.com/freedomofpress/dangerzone/issues/695I6: [macOS] [Windows] [Linux] [QubesOS] Possible Attack Vector via OCR Enginehttps://github.com/freedomofpress/dangerzone/issues/696I7: [macOS] [Windows] [Linux] [QubesOS] Out-of-Date Libraries in UseThe particular issue was resolved in v0.5.1. The wider issue had to do with how to ship faster updates. Part of that is being able to ship container-only updates and potentially moving the pixels-to-PDF part to the host.
Freedom of the Press Foundation

Inflation Panic

2 years 2 months ago
Actual consumer prices are well behaved. Financial commentators and central bankers are not.
Robert Kuttner