27 Jan 2026
Slashdot
Microsoft Is Refreshing the Xbox Cloud Gaming Web Experience
An anonymous reader quotes a report from Thurrott: Microsoft is testing a refresh of the Xbox Cloud Gaming web experience in public preview. "This preview is a first look at our new web interface on your browser and lets you try the updated design and product flow before it is rolled out broadly," Microsoft's Patrick Siu explains. "Players who opt in to this preview will see some changes to their experience including updated navigation features and a refreshed look and feel. As this is a preview, some functions may not yet be available or may behave differently than the current web experience. We will continue iterating during the preview period and changes may be made over time." [...] There's no real info about what's in the new experience, oddly. Microsoft notes only that it "lays the foundation for accelerating [their] ability to build new experiences for players," and that it "helps [them] validate the new web platform and refine the experience for everyone." The public preview can be found at xbox.com/play.
Read more of this story at Slashdot.
27 Jan 2026 1:00pm GMT
ReactOS Celebrates 30 Years
jeditobe writes: ReactOS, the open-source operating system aimed at binary compatibility with Windows, recently marked its 30th anniversary. Launched in 1996, ReactOS has focused on providing a free alternative to Windows, with compatibility for Windows applications and drivers. Though still in development, it has made significant progress in recent years, including improvements to USB support, better hardware compatibility, and enhanced performance with the release of version 0.4.15. The upcoming 0.4.16 release is set to introduce UEFI support, KMDF and WDDM graphics driver support, marking a major step forward in ReactOS's development.
Read more of this story at Slashdot.
27 Jan 2026 10:00am GMT
Lawsuit Alleges That WhatsApp Has No End-to-End Encryption
Longtime Slashdot reader schwit1 shares a report from PCMag: A lawsuit claims that WhatsApp's end-to-end encryption is a sham, and is demanding damages, but the app's parent company, Meta, calls the claims "false and absurd." The lawsuit was filed in a San Francisco US district court on Friday and comes from a group of users based in countries such as Australia, Mexico, and South Africa, according to Bloomberg. As evidence, the lawsuit cites unnamed "courageous whistleblowers" who allege that WhatsApp and Meta employees can request to view a user's messages through a simple process, thus bypassing the app's end-to-end encryption. "A worker need only send a 'task' (i.e., request via Meta's internal system) to a Meta engineer with an explanation that they need access to WhatsApp messages for their job," the lawsuit claims. "The Meta engineering team will then grant access -- often without any scrutiny at all -- and the worker's workstation will then have a new window or widget available that can pull up any WhatsApp user's messages based on the user's User ID number, which is unique to a user but identical across all Meta products." "Once the Meta worker has this access, they can read users' messages by opening the widget; no separate decryption step is required," the 51-page complaint adds. "The WhatsApp messages appear in widgets commingled with widgets containing messages from unencrypted sources. Messages appear almost as soon as they are communicated -- essentially, in real-time. Moreover, access is unlimited in temporal scope, with Meta workers able to access messages from the time users first activated their accounts, including those messages users believe they have deleted." The lawsuit does not provide any technical details to back up the rather sensational claims.
Read more of this story at Slashdot.
27 Jan 2026 7:00am GMT
26 Jan 2026
Ars Technica
OpenAI spills technical details about how its AI coding agent works
Unusually detailed post explains how OpenAI handles the Codex agent loop.
26 Jan 2026 11:05pm GMT
Doctors face-palm as RFK Jr.’s top vaccine advisor questions need for polio shot
Kirk Milhoan's comments come as federal vaccine policy slides to insignificance.
26 Jan 2026 9:31pm GMT
Why has Microsoft been routing example.com traffic to a company in Japan?
Company's autodiscover caused users' test credentials to be sent outside Microsoft networks.
26 Jan 2026 9:02pm GMT
25 Jan 2026
OSnews
9front GEFS SERVICE PACK 1 released
9front, by far the best operating system in the whole world, pushed out a new release, titled "GEFS SERVICE PACK 1". Even with only a few changes, this is still, as always, a more monumental, important, and groundbreaking release than any other operating system release in history. Everything changes, today, because exec() now supports shell-scripts as interpreter in #!, improved sam scrolling, TLS by default in ircrc, and more. You're already running 9front, of course, but if you're one of the few holdouts still using something else, download GEFS SERVICE PACK 1 and install it.
25 Jan 2026 11:09am GMT
Remotely unlocking an encrypted hard disk
Your mission, should you choose to accept it, is to sneak into the earliest parts of the boot process, swap the startup config without breaking anything, and leave without a trace. Are you ready? Let's begin. ↫ Jynn Nelson Genius.
25 Jan 2026 10:56am GMT
23 Jan 2026
OSnews
Microsoft gave FBI BitLocker keys to unlock encrypted data, because of course they did
Encrypting the data stored locally on your hard drives is generally a good idea, specifically if you have use a laptop and take it with you a lot and thieves might get a hold of it. This issue becomes even more pressing if you carry sensitive data as a dissident or whistleblower and have to deal with law enforcement. Or, you know, if you're an American citizen fascist paramilitary groups like ICE doesn't like because your skin colour is too brown or whatever. Windows offers local disk encryption too, in the form of its BitLocker feature, and Microsoft suggests users store their encryption keys on Microsoft's servers. However, when you do so, these keys will be stored unencrypted, and it turns out Microsoft will happily hand them over to law enforcement. "This is private data on a private computer and they made the architectural choice to hold access to that data. They absolutely should be treating it like something that belongs to the user," said Matt Green, cryptography expert and associate professor at the Johns Hopkins University Information Security Institute. "If Apple can do it, if Google can do it, then Microsoft can do it. Microsoft is the only company that's not doing this," he added. "It's a little weird… The lesson here is that if you have access to keys, eventually law enforcement is going to come." ↫ Thomas Brewster Microsoft is choosing to store these keys in unencrypted fashion, and that of course means law enforcement is going to come knocking. With everything that's happening in the United States at the moment, the platitude of "I have nothing to hide" has lost even more of its meaning, as people - even toddlers - are being snatched from the streets and out of their homes on a daily basis by fascist paramilitaries. Even if times were better, though, Microsoft should still refrain from storing these keys unencrypted. It is entirely possible, nay, trivial to address this shortcoming, but the odds of the company fixing this while trying to suck up to the current US regime seem small. Everybody, but especially those living under totalitarian(-esque) regimes, should be taking extra care to make sure their data isn't just encrypted, but that the keys are safe as well.
23 Jan 2026 11:43pm GMT
19 Jan 2026
Planet Arch Linux
Personal infrastructure setup 2026
While starting this post I realized I have been maintaining personal infrastructure for over a decade! Most of the things I've self-hosted is been for personal uses. Email server, a blog, an IRC server, image hosting, RSS reader and so on. All of these things has all been a bit all over the place and never properly streamlined. Some has been in containers, some has just been flat files with a nginx service in front and some has been a random installed Debian package from somewhere I just forgot.
19 Jan 2026 12:00am GMT
11 Jan 2026
Planet Arch Linux
Verify Arch Linux artifacts using VOA/OpenPGP
In the recent blog post on the work funded by Sovereign Tech Fund (STF), we provided an overview of the "File Hierarchy for the Verification of OS Artifacts" (VOA) and the voa project as its reference implementation. VOA is a generic framework for verifying any kind of distribution artifacts (i.e. files) using arbitrary signature verification technologies. The voa CLI ⌨️ The voa project offers the voa(1) command line interface (CLI) which makes use of the voa(5) configuration file format for technology backends. It is recommended to read the respective man pages to get …
11 Jan 2026 12:00am GMT
10 Jan 2026
Planet Arch Linux
A year of work on the ALPM project
In 2024 the Sovereign Tech Fund (STF) started funding work on the ALPM project, which provides a Rust-based framework for Arch Linux Package Management. Refer to the project's FAQ and mission statement to learn more about the relation to the tooling currently in use on Arch Linux. The funding has now concluded, but over the time of 15 months allowed us to create various tools and integrations that we will highlight in the following sections. We have worked on six milestones with focus on various aspects of the package management ecosystem, ranging from formalizing, parsing and writing of …
10 Jan 2026 12:00am GMT