Skip to main content

Fedora Targets 99% Package Reproducibility by October

3 months ago
Fedora has proposed a major change for its upcoming version 43 release that aims to achieve 99% package reproducibility, addressing growing concerns about supply-chain security. According to the change proposal announced March 31, Fedora has already reached 90% reproducibility through infrastructure changes including "clamping" file modification times and implementing a Rust-based "add-determinism" tool that standardizes metadata. The remaining 10% will require individual package maintainer involvement, treating reproducibility failures as bugs. The effort will use a public instance of rebuilderd to independently verify that binary packages can be reproduced from source code. Unlike Debian's bit-by-bit reproducibility definition, Fedora allows differences in package signatures and some metadata while requiring identical payloads. The initiative follows similar efforts by Debian and openSUSE, and comes amid heightened focus on supply-chain security after the recent XZ backdoor incident.

Read more of this story at Slashdot.

msmash

Germany To Create 'Super-High-Tech Ministry' For Research, Technology and Aerospace

3 months ago
Germany will get a new "super-high-tech ministry" responsible for research, technology, and aerospace, according to the coalition agreement published by the incoming government this week. From a report: The announcement is one of several nods to science in the 144-page agreement, unveiled on 9 April following weeks of negotiations between the center-right Christian Democrats (CDU) and its sister party, the Christian Social Union in Bavaria (CSU) -- who together won the most seats in February's federal elections -- and the center-left Social Democrats. The agreement is expected to be formally approved by the three parties by early May, paving the way for CDU leader Friedrich Merz to be elected chancellor. [...] The new agreement lists a number of scientific priorities for the new government, including support for artificial intelligence, quantum technologies, biotechnology, microchip development and production, and fusion energy. "Our goal is that the world's first fusion reactor should be realized in Germany," the text states. It also mentions personalized medicine, oceans research, and sustainability research as "strategic" areas. But the agreement does not include any budget estimates, and observers caution it is unclear where the money for new programs would come from. The agreement does affirm current commitments to increase the budgets of the country's main research organizations by 3% per year through 2030.

Read more of this story at Slashdot.

msmash

Wi-Fi Giant TP-Link's US Future Hinges on Its Claimed Split From China

3 months ago
The ubiquitous but often overlooked Wi-Fi router lies at the heart of one of Washington's biggest national security dilemmas -- and a rift between two brothers on opposite sides of the Pacific. From a report: US investigators are probing the China ties of TP-Link, the new American incarnation of a consumer Wi-Fi behemoth, following its rapid growth and a spate of cyber attacks by Chinese state-sponsored actors targeting many router brands. The inquiry is testing whether TP-Link's corporate makeover represents enough of a divorce from China to spare it from a ban in a crucial market. While TP-Link's recent restructuring split the company into separate US- and China-headquartered businesses, a Bloomberg News investigation found that the resulting American venture still has substantial operations in mainland China. If US officials conclude TP-Link's China connections pose an "unacceptable risk," they could use a powerful new authority to ban the company from the US. Such an outcome could also unravel plans by the owner of its US business, Jeffrey Chao, to start fresh in California following an estrangement from his older brother, who started the router business with him in Shenzhen nearly three decades ago. In an interview -- the first Jeffrey Chao said he has ever given -- he told Bloomberg he's quitting China. He opened a new headquarters in Irvine last year and said he will invest $700 million in the US to build a factory and jumpstart research and development on highly secure routers while awaiting the green card he said he applied for in January. He has also traded his perch in a Hong Kong skyscraper for a 1980s-era split-level near his office, joined a neighborhood evangelical church, and is now eyeing a Cadillac Escalade for road trips, he said, burnishing his American credentials. "I know the current relationship between the US and China is complex," Chao said in the interview last month. "I have chosen the US."

Read more of this story at Slashdot.

msmash