NitroPhone 1 is a security-hardend Pixel 4a for $750

Nitrokey is an open source security hardware maker based in Germany known for devices like USB keys that can be used for multi-factor authentication and flash drives with encrypted storage. But the company also sells security-hardened laptop and deskt…

Nitrokey is an open source security hardware maker based in Germany known for devices like USB keys that can be used for multi-factor authentication and flash drives with encrypted storage. But the company also sells security-hardened laptop and desktop computers. Now Nitrokey is selling its first smartphone. The NitroPhone 1 is available for 630 €, or […]

The post NitroPhone 1 is a security-hardend Pixel 4a for $750 appeared first on Liliputing.

NPM package with 3 million weekly downloads had a severe vulnerability

Untrusted JavaScript config file can execute arbitrary code.

NPM package with 3 million weekly downloads had a severe vulnerability

Enlarge (credit: Getty Images)

Popular NPM package "pac-resolver" has fixed a severe remote code execution (RCE) flaw.

The pac-resolver package receives over 3 million weekly downloads, extending this vulnerability to Node.js applications relying on the open source dependency. Pac-resolver touts itself as a module that accepts JavaScript proxy configuration files and generates a function for your app to map certain domains to use a proxy.

To proxy or not to proxy

This week, developer Tim Perry disclosed a high-severity flaw in pac-resolver that can enable threat actors on the local network to run arbitrary code within your Node.js process whenever it attempts to make an HTTP request.

Read 15 remaining paragraphs | Comments

NPM package with 3 million weekly downloads had a severe vulnerability

Untrusted JavaScript config file can execute arbitrary code.

NPM package with 3 million weekly downloads had a severe vulnerability

Enlarge (credit: Getty Images)

Popular NPM package "pac-resolver" has fixed a severe remote code execution (RCE) flaw.

The pac-resolver package receives over 3 million weekly downloads, extending this vulnerability to Node.js applications relying on the open source dependency. Pac-resolver touts itself as a module that accepts JavaScript proxy configuration files and generates a function for your app to map certain domains to use a proxy.

To proxy or not to proxy

This week, developer Tim Perry disclosed a high-severity flaw in pac-resolver that can enable threat actors on the local network to run arbitrary code within your Node.js process whenever it attempts to make an HTTP request.

Read 15 remaining paragraphs | Comments

China may use an existing rocket to speed up plans for a human Moon mission

China may seek to leapfrog NASA in its return to the Moon.

China's Long March 5 rocket made its debut in November, 2016.

Enlarge / China's Long March 5 rocket made its debut in November, 2016. (credit: Xinhua/Sun Hao)

China appears to be accelerating its plans to land on the Moon by 2030 and would use a modified version of an existing rocket to do so.

The chief designer of the Long March family of rockets, Long Lehao, said China could use two modified Long March 5 rockets to accomplish a lunar landing in less than a decade, according to the Hong Kong-based online news site, HK01. He spoke earlier this week at the 35th National Youth Science and Technology Innovation Competition in China. The full video can be found here.

During Lehao's speech, he said one of these large rockets would launch a lunar lander into orbit around the Moon, and the second would send the crew to meet it. The crew would then transfer to the lander, go down to the Moon's surface, and spend about six hours walking on its surface. Then part of the lunar lander would ascend back to meet the spacecraft and return to Earth.

Read 8 remaining paragraphs | Comments