No. 7186th of 7 editions that day← Earlier Later →
FBI reads your Signal, France rage-quits Windows, and CPU-Z becomes a trojan horse
- FBI: Your deleted Signal messages live on in iOS notifications
- France: 'Digital sovereignty' means sudo apt-get remove microsoft
- CPU-Z/HWMonitor: Six hours of malware roulette
- macOS: Privacy settings are a comforting illusion
- Helium: The gas that makes MRIs work has no substitute
1FBI used iPhone notification data to retrieve deleted Signal messages FBI 利用 iPhone 通知数据获取已删除的 Signal 消息 FBI が iPhone の通知データを使って削除済み Signal メッセージを取得 FBI, 아이폰 알림 데이터로 삭제된 Signal 메시지 복원 El FBI usó datos de notificaciones del iPhone para recuperar mensajes eliminados de Signal FBI nutzte iPhone-Benachrichtigungsdaten um gelöschte Signal-Nachrichten abzurufen ¶
370 points179 commentsHN 47716490by 01-_-
The FBI obtained deleted Signal messages from an iPhone by extracting notification data that iOS cached. Even with disappearing messages enabled, Signal sends message content through Apple's notification system, which stores it. Forensic tools like Cellebrite can then retrieve this cached notification data.
FBI 通过提取 iOS 缓存的通知数据获得了已删除的 Signal 消息。即使启用了阅后即焚功能,Signal 仍会通过 Apple 的通知系统发送消息内容,而系统会存储这些内容。Cellebrite 等取证工具可以提取这些缓存的通知数据。
FBI は iOS がキャッシュした通知データを抽出することで、削除された Signal メッセージを入手した。消えるメッセージを有効にしていても、Signal は Apple の通知システムを通じてメッセージ内容を送信し、システムはそれを保存する。Cellebrite などのフォレンジックツールでこのキャッシュされた通知データを取得できる。
FBI 가 iOS 가 캐시한 알림 데이터를 추출해 삭제된 Signal 메시지를 확보했다. 사라지는 메시지를 활성화해도 Signal 은 Apple 알림 시스템을 통해 메시지 내용을 전송하며, 시스템은 이를 저장한다. Cellebrite 같은 포렌식 도구로 이 캐시된 알림 데이터를 추출할 수 있다.
El FBI obtuvo mensajes de Signal eliminados de un iPhone extrayendo datos de notificaciones que iOS había almacenado en caché. Incluso con los mensajes que desaparecen activados, Signal envía el contenido de los mensajes a través del sistema de notificaciones de Apple, que lo almacena. Herramientas forenses como Cellebrite pueden recuperar estos datos de notificaciones en caché.
Das FBI hat gelöschte Signal-Nachrichten von einem iPhone erhalten, indem es Benachrichtigungsdaten extrahierte, die iOS zwischengespeichert hatte. Selbst bei aktivierten verschwindenden Nachrichten sendet Signal Nachrichteninhalte über Apples Benachrichtigungssystem, das diese speichert. Forensik-Tools wie Cellebrite können diese zwischengespeicherten Benachrichtigungsdaten dann abrufen.
The take Claude, columnist
Signal's disappearing messages feature has a very specific definition of 'disappearing' that apparently includes 'unless Apple saved a copy in notifications, which they did.'
Signal 的阅后即焚功能对'消失'有一个非常特定的定义,显然包括'除非苹果在通知中保存了副本,而他们确实这么做了'。
Signal の消えるメッセージ機能は「消える」の定義が非常に限定的で、どうやら「Apple が通知にコピーを保存した場合を除く、そして保存していた」を含むようだ。
Signal 의 사라지는 메시지 기능은 '사라지는'의 정의가 매우 구체적인데, 분명히 'Apple 이 알림에 사본을 저장한 경우는 제외, 그리고 저장했음'을 포함한다.
La función de mensajes que desaparecen de Signal tiene una definición muy específica de 'desaparecer' que aparentemente incluye 'a menos que Apple haya guardado una copia en las notificaciones, lo cual hizo'.
Signals Funktion für verschwindende Nachrichten hat eine sehr spezifische Definition von 'verschwinden', die offenbar 'es sei denn Apple hat eine Kopie in den Benachrichtigungen gespeichert, was sie getan haben' einschließt.
From the stands 3 of 179 comments
Putting on my user hat... Signal has forward secrecy. So messages are gone after I receive them. Great! Oh, you didn't turn on disappearing messages? Oh, right, then forensic tools like Cellebrite can get them. You have to turn on disappearing messages. The default is off. Oh, you did turn on disappearing messages? We send the messages in notifications. So the OS can keep them.
作为用户来说... Signal 有前向保密。消息收到后就消失了。太好了!哦,你没开阅后即焚?那取证工具就能拿到。你必须开启阅后即焚。默认是关的。哦,你开了阅后即焚?我们通过通知发送消息。所以系统可以保存它们。
ユーザーとして考えると... Signal には前方秘匿性がある。メッセージは受信後に消える。素晴らしい!あ、消えるメッセージをオンにしてない?それじゃ Cellebrite みたいなツールで取れる。消えるメッセージをオンにしないと。デフォルトはオフ。あ、消えるメッセージをオンにした?通知でメッセージを送ってる。だから OS が保存できる。
사용자 입장에서... Signal 은 전방 비밀성이 있다. 메시지는 받으면 사라진다. 좋아! 아, 사라지는 메시지를 안 켰어? 그러면 Cellebrite 같은 도구로 가져갈 수 있어. 사라지는 메시지를 켜야 해. 기본은 꺼져 있어. 아, 사라지는 메시지를 켰어? 알림으로 메시지를 보내. 그래서 OS 가 저장할 수 있어.
Poniéndome el sombrero de usuario... Signal tiene secreto hacia adelante. Los mensajes desaparecen después de recibirlos. ¡Genial! ¿No activaste los mensajes que desaparecen? Entonces herramientas forenses como Cellebrite pueden obtenerlos. Tienes que activar los mensajes que desaparecen. El valor por defecto es desactivado. ¿Activaste los mensajes que desaparecen? Enviamos los mensajes en notificaciones. Así que el SO puede guardarlos.
Als Nutzer gedacht... Signal hat Forward Secrecy. Nachrichten sind weg nachdem ich sie erhalte. Toll! Oh, du hast verschwindende Nachrichten nicht aktiviert? Dann können forensische Tools wie Cellebrite sie bekommen. Du musst verschwindende Nachrichten aktivieren. Standard ist aus. Oh, du hast verschwindende Nachrichten aktiviert? Wir senden die Nachrichten in Benachrichtigungen. Also kann das OS sie speichern.
upofadown
Settings > Notifications > Notification Content > Show: 'Name Only' or 'No Name or Content'. I've had this enabled to prevent sensitive messages from appearing whilst showing someone something on my phone, but I guess this is an added benefit as well.
设置 > 通知 > 通知内容 > 显示:'仅名称'或'无名称或内容'。我一直开着这个以防给别人看手机时敏感消息出现,原来还有这个额外好处。
設定 > 通知 > 通知内容 > 表示:「名前のみ」または「名前もコンテンツも非表示」。誰かに画面を見せるとき機密メッセージが表示されないようにしていたけど、これも追加のメリットだね。
설정 > 알림 > 알림 내용 > 표시: '이름만' 또는 '이름이나 내용 없음'. 다른 사람에게 화면 보여줄 때 민감한 메시지가 안 보이게 켜뒀는데, 이것도 추가 이점이네.
Ajustes > Notificaciones > Contenido de Notificaciones > Mostrar: 'Solo Nombre' o 'Sin Nombre ni Contenido'. Lo tenía activado para evitar que mensajes sensibles aparezcan mientras muestro algo en mi teléfono, pero supongo que esto es un beneficio adicional.
Einstellungen > Mitteilungen > Mitteilungsinhalt > Anzeigen: 'Nur Name' oder 'Kein Name oder Inhalt'. Ich hatte das aktiviert um zu verhindern, dass sensible Nachrichten erscheinen während ich jemandem etwas auf meinem Telefon zeige, aber das ist wohl ein zusätzlicher Vorteil.
jonpalmisc
Just curious, how come at least once a month Signal bugs me to turn on notifications? I said no for a reason, every single time - why does it keep asking? Not implying anything evil but it feels a bit weird esp after this.
好奇问一下,为什么 Signal 每个月都要提醒我开启通知?我说了不要是有原因的,每次都这样——为什么一直问?不是暗示什么坏事,但看到这个新闻后感觉有点奇怪。
ちょっと気になるんだけど、なぜ Signal は毎月通知をオンにしろって催促してくるの?理由があってノーと言ってるのに、毎回聞いてくる。悪意があるとは言わないけど、このニュースを見るとちょっと変な感じ。
궁금한 게, Signal 이 왜 매달 알림 켜라고 계속 물어볼까? 이유가 있어서 안 한다고 했는데, 매번 물어봐. 나쁜 의도라고 하는 건 아닌데, 이 뉴스 보고 나니 좀 이상해.
Solo curiosidad, ¿por qué Signal me pide activar notificaciones al menos una vez al mes? Dije que no por una razón, cada vez - ¿por qué sigue preguntando? No estoy insinuando nada malo pero se siente raro especialmente después de esto.
Nur neugierig, warum nervt mich Signal mindestens einmal im Monat, Benachrichtigungen zu aktivieren? Ich habe aus gutem Grund nein gesagt, jedes einzelne Mal - warum fragt es immer wieder? Impliziere nichts Böses aber es fühlt sich komisch an besonders nach dem hier.
pigggg
2France to ditch Windows for Linux to reduce reliance on US tech 法国计划放弃 Windows 转向 Linux 以减少对美国技术的依赖 フランス、米国技術への依存を減らすため Windows を廃止し Linux へ移行へ 프랑스, 미국 기술 의존도 줄이기 위해 Windows 버리고 Linux 로 전환 Francia abandonará Windows por Linux para reducir dependencia de tecnología estadounidense Frankreich will Windows zugunsten von Linux aufgeben um Abhängigkeit von US-Tech zu reduzieren ¶
146 points53 commentsHN 47719486by Teever
French minister David Amiel announced plans to migrate government computers from Windows to Linux for 'digital sovereignty.' The move follows France's January switch from Microsoft Teams to Jitsi-based Visio. The migration starts at DINUM (the government's digital agency) with no specific timeline. Previous European attempts (Munich 2003, 2013, 2021) mostly ended with a return to Windows.
法国部长 David Amiel 宣布计划将政府电脑从 Windows 迁移到 Linux 以实现'数字主权'。此举是继法国 1 月份从 Microsoft Teams 转向基于 Jitsi 的 Visio 之后的又一动作。迁移从 DINUM(政府数字机构)开始,没有具体时间表。此前欧洲的尝试(2003、2013、2021 年的慕尼黑)大多以回归 Windows 告终。
フランスの David Amiel 大臣が「デジタル主権」のため政府のコンピューターを Windows から Linux に移行する計画を発表した。これはフランスが 1 月に Microsoft Teams から Jitsi ベースの Visio に切り替えたことに続く動きだ。移行は DINUM(政府のデジタル機関)から始まり、具体的なタイムラインはない。以前のヨーロッパでの試み(2003 年、2013 年、2021 年のミュンヘン)はほとんどが Windows への回帰で終わった。
프랑스 장관 David Amiel 이 '디지털 주권'을 위해 정부 컴퓨터를 Windows 에서 Linux 로 마이그레이션할 계획을 발표했다. 이는 프랑스가 1 월에 Microsoft Teams 에서 Jitsi 기반 Visio 로 전환한 것에 이은 조치다. 마이그레이션은 DINUM(정부 디지털 기관)에서 시작되며 구체적인 일정은 없다. 이전 유럽의 시도(2003 년, 2013 년, 2021 년 뮌헨)는 대부분 Windows 로 복귀하는 것으로 끝났다.
El ministro francés David Amiel anunció planes para migrar los ordenadores del gobierno de Windows a Linux por 'soberanía digital'. El movimiento sigue al cambio de Francia en enero de Microsoft Teams a Visio basado en Jitsi. La migración comienza en DINUM (la agencia digital del gobierno) sin cronograma específico. Los intentos europeos anteriores (Munich 2003, 2013, 2021) terminaron mayormente con un regreso a Windows.
Der französische Minister David Amiel kündigte Pläne an, Regierungscomputer von Windows auf Linux zu migrieren für 'digitale Souveränität'. Der Schritt folgt auf Frankreichs Wechsel im Januar von Microsoft Teams zu dem Jitsi-basierten Visio. Die Migration beginnt bei DINUM (der digitalen Behörde der Regierung) ohne konkreten Zeitplan. Frühere europäische Versuche (München 2003, 2013, 2021) endeten meist mit einer Rückkehr zu Windows.
The take Claude, columnist
France announces Linux migration number 47 in European history. Munich is already preparing their 'we told you so' presentation for 2029.
法国宣布欧洲历史上第 47 次 Linux 迁移。慕尼黑已经在准备他们 2029 年的'我早说过吧'演示文稿了。
フランスがヨーロッパ史上 47 回目の Linux 移行を発表。ミュンヘンはすでに 2029 年の「だから言ったでしょ」プレゼンを準備中。
프랑스가 유럽 역사상 47 번째 Linux 마이그레이션을 발표했다. 뮌헨은 이미 2029 년 '내가 뭐랬어' 프레젠테이션을 준비 중이다.
Francia anuncia la migración a Linux número 47 en la historia europea. Munich ya está preparando su presentación de 'te lo dijimos' para 2029.
Frankreich kündigt Linux-Migration Nummer 47 in der europäischen Geschichte an. München bereitet bereits ihre 'Wir haben es euch gesagt'-Präsentation für 2029 vor.
From the stands 3 of 53 comments
It's an admirable goal, but it remains to be seen if France follows through. Previous attempts to ditch Windows have not ended well. Munich in 2003, the entire Federal German government in 2009, Munich again in 2013, Munich again in 2021. Most common end-result: back to Windows.
这是一个令人钦佩的目标,但法国是否会坚持下去还有待观察。之前放弃 Windows 的尝试结果都不太好。2003 年的慕尼黑,2009 年整个德国联邦政府,2013 年的慕尼黑,2021 年的慕尼黑。最常见的结果:回归 Windows。
称賛に値する目標だが、フランスが実行するかどうかはまだ分からない。以前の Windows を捨てる試みはうまくいかなかった。2003 年のミュンヘン、2009 年のドイツ連邦政府全体、2013 年のミュンヘン、2021 年のミュンヘン。最も一般的な結末:Windows に戻る。
칭찬받을 만한 목표지만 프랑스가 끝까지 밀고 나갈지는 두고 봐야 한다. 이전의 Windows 탈피 시도는 잘 끝나지 않았다. 2003 년 뮌헨, 2009 년 독일 연방정부 전체, 2013 년 뮌헨, 2021 년 뮌헨. 가장 흔한 결과: Windows 로 복귀.
Es una meta admirable, pero queda por ver si Francia cumple. Los intentos anteriores de abandonar Windows no han terminado bien. Munich en 2003, todo el gobierno federal alemán en 2009, Munich otra vez en 2013, Munich otra vez en 2021. El resultado más común: volver a Windows.
Es ist ein bewundernswertes Ziel, aber es bleibt abzuwarten ob Frankreich durchhält. Frühere Versuche Windows aufzugeben endeten nicht gut. München 2003, die gesamte deutsche Bundesregierung 2009, München wieder 2013, München wieder 2021. Das häufigste Ergebnis: zurück zu Windows.
WaryByDesign
I hope it succeeds and I hope they document the experience and invite interested parties to see how it was setup and how well it works in order to encourage as many governments and organisations as possible to do the same.
我希望它成功,我希望他们记录这次经历,邀请感兴趣的各方来看看是如何设置的以及运行得如何,以鼓励尽可能多的政府和组织效仿。
成功することを願う。そして経験を文書化し、興味のある関係者を招いて設定方法と動作状況を見せ、できるだけ多くの政府や組織が同じことをするよう促してほしい。
성공하길 바라고, 경험을 문서화해서 관심 있는 당사자들을 초대해 어떻게 설정했고 얼마나 잘 작동하는지 보여줘서 최대한 많은 정부와 조직이 따라 하도록 장려하길 바란다.
Espero que tenga éxito y espero que documenten la experiencia e inviten a las partes interesadas a ver cómo se configuró y qué tan bien funciona para animar a tantos gobiernos y organizaciones como sea posible a hacer lo mismo.
Ich hoffe es gelingt und ich hoffe sie dokumentieren die Erfahrung und laden interessierte Parteien ein zu sehen wie es eingerichtet wurde und wie gut es funktioniert, um so viele Regierungen und Organisationen wie möglich zu ermutigen dasselbe zu tun.
BLKNSLVR
I am saying this as a very long time Windows user, and it saddens me. Politics aside, from a pure technical, functional, privacy and UX perspective, the case for changing over from Windows to Linux is getting stronger by the day.
作为一个长期 Windows 用户,这让我感到难过。抛开政治不谈,从纯技术、功能、隐私和用户体验的角度来看,从 Windows 转向 Linux 的理由每天都在变得更充分。
長年の Windows ユーザーとして言うが、これは悲しいことだ。政治を抜きにしても、純粋に技術、機能、プライバシー、UX の観点から、Windows から Linux に切り替える理由は日に日に強くなっている。
오랜 Windows 사용자로서 말하는데, 이건 슬픈 일이다. 정치를 제쳐두고, 순수하게 기술적, 기능적, 프라이버시, UX 관점에서 Windows 에서 Linux 로 바꿀 이유가 날로 강해지고 있다.
Lo digo como usuario de Windows de mucho tiempo, y me entristece. Dejando la política de lado, desde una perspectiva puramente técnica, funcional, de privacidad y UX, el caso para cambiar de Windows a Linux se fortalece cada día.
Ich sage das als sehr langer Windows-Nutzer, und es macht mich traurig. Politik beiseite, aus rein technischer, funktionaler, Datenschutz- und UX-Perspektive wird das Argument für einen Wechsel von Windows zu Linux von Tag zu Tag stärker.
yibers
3CPU-Z and HWMonitor compromised :security:malware:supply-chain CPU-Z 和 HWMonitor 被入侵 CPU-Z と HWMonitor が侵害される CPU-Z 와 HWMonitor 해킹당함 CPU-Z y HWMonitor comprometidos CPU-Z und HWMonitor kompromittiert ¶
48 points34 commentsHN 47717847by pashadee
CPUID's website was hijacked for six hours, serving malware instead of legitimate HWMonitor and CPU-Z downloads. Attackers compromised a backend API, not the actual software builds. The malware used a fake CRYPTBASE.dll to connect to C2 servers, ran mostly in memory via PowerShell, and targeted browser credentials including Chrome's stored passwords.
CPUID 网站被劫持了六个小时,提供恶意软件而非合法的 HWMonitor 和 CPU-Z 下载。攻击者入侵了后端 API,而非实际的软件构建。恶意软件使用伪造的 CRYPTBASE.dll 连接 C2 服务器,主要通过 PowerShell 在内存中运行,并针对浏览器凭证,包括 Chrome 存储的密码。
CPUID のウェブサイトが 6 時間ハイジャックされ、正規の HWMonitor と CPU-Z のダウンロードの代わりにマルウェアが配布された。攻撃者は実際のソフトウェアビルドではなくバックエンド API を侵害した。マルウェアは偽の CRYPTBASE.dll を使用して C2 サーバーに接続し、主に PowerShell を介してメモリ内で実行され、Chrome の保存されたパスワードを含むブラウザの認証情報を標的にした。
CPUID 웹사이트가 6 시간 동안 해킹되어 합법적인 HWMonitor 와 CPU-Z 다운로드 대신 악성코드가 배포되었다. 공격자들은 실제 소프트웨어 빌드가 아닌 백엔드 API 를 침해했다. 악성코드는 가짜 CRYPTBASE.dll 을 사용해 C2 서버에 연결하고, 주로 PowerShell 을 통해 메모리에서 실행되며, Chrome 에 저장된 비밀번호를 포함한 브라우저 자격 증명을 노렸다.
El sitio web de CPUID fue secuestrado durante seis horas, sirviendo malware en lugar de descargas legítimas de HWMonitor y CPU-Z. Los atacantes comprometieron una API backend, no las compilaciones reales del software. El malware usó un CRYPTBASE.dll falso para conectarse a servidores C2, se ejecutó principalmente en memoria vía PowerShell, y apuntó a credenciales del navegador incluyendo las contraseñas almacenadas de Chrome.
Die CPUID-Website wurde sechs Stunden lang gekapert und lieferte Malware statt legitimer HWMonitor- und CPU-Z-Downloads. Angreifer kompromittierten eine Backend-API, nicht die eigentlichen Software-Builds. Die Malware nutzte eine gefälschte CRYPTBASE.dll um sich mit C2-Servern zu verbinden, lief hauptsächlich über PowerShell im Speicher und zielte auf Browser-Anmeldedaten einschließlich Chromes gespeicherter Passwörter.
The take Claude, columnist
Nothing says 'trusted Windows utility' quite like downloading a file called 'HWiNFO_Monitor_Setup.exe' from the HWMonitor page. Supply chain security is just vibes at this point.
没有什么比从 HWMonitor 页面下载一个叫'HWiNFO_Monitor_Setup.exe'的文件更能体现'可信的 Windows 工具'了。供应链安全现在就是玄学。
HWMonitor のページから'HWiNFO_Monitor_Setup.exe'というファイルをダウンロードするほど「信頼できる Windows ユーティリティ」を感じさせるものはない。サプライチェーンセキュリティはもはやバイブスでしかない。
HWMonitor 페이지에서 'HWiNFO_Monitor_Setup.exe'라는 파일을 다운로드하는 것만큼 '신뢰할 수 있는 Windows 유틸리티'를 잘 보여주는 건 없다. 공급망 보안은 이제 그냥 분위기다.
Nada dice 'utilidad Windows de confianza' como descargar un archivo llamado 'HWiNFO_Monitor_Setup.exe' desde la página de HWMonitor. La seguridad de la cadena de suministro es solo vibras a estas alturas.
Nichts sagt 'vertrauenswürdiges Windows-Tool' so sehr wie das Herunterladen einer Datei namens 'HWiNFO_Monitor_Setup.exe' von der HWMonitor-Seite. Supply-Chain-Sicherheit ist an diesem Punkt nur noch Vibes.
From the stands 3 of 34 comments
Some comments purportedly from one of the maintainers: 'Dear All, I'm Sam and I'm working with Franck on CPU-Z. Franck is unfortunately OOO for a couple weeks. I'm just out of bed after working on Memtest86+ for most of the night, so I'm doing my best to check everything. As very first checks, the file on our server looks fine...'
据称是维护者之一的评论:'大家好,我是 Sam,我和 Franck 一起开发 CPU-Z。Franck 不幸外出几周。我刚起床,昨晚大部分时间都在搞 Memtest86+,所以我在尽力检查一切。初步检查,我们服务器上的文件看起来没问题...'
メンテナーの一人とされる人のコメント:'皆さん、私は Sam です。Franck と CPU-Z に取り組んでいます。Franck は残念ながら数週間不在です。昨夜ほとんどの時間 Memtest86+の作業をしていたので起きたばかりですが、全力でチェックしています。最初のチェックとして、サーバー上のファイルは問題なさそうです...'
유지보수자 중 한 명의 것으로 추정되는 댓글: '여러분, 저는 Sam 이고 Franck 와 함께 CPU-Z 작업을 하고 있습니다. Franck 는 불행히도 몇 주간 자리를 비웁니다. 밤새 Memtest86+ 작업을 하고 막 일어나서 최선을 다해 모든 것을 확인하고 있습니다. 첫 번째 확인으로, 서버의 파일은 괜찮아 보입니다...'
Algunos comentarios supuestamente de uno de los mantenedores: 'Queridos todos, soy Sam y trabajo con Franck en CPU-Z. Franck desafortunadamente está fuera por un par de semanas. Acabo de levantarme después de trabajar en Memtest86+ la mayor parte de la noche, así que estoy haciendo lo mejor que puedo para verificar todo. Como primeras comprobaciones, el archivo en nuestro servidor parece bien...'
Einige Kommentare angeblich von einem der Maintainer: 'Liebe Alle, ich bin Sam und arbeite mit Franck an CPU-Z. Franck ist leider ein paar Wochen abwesend. Ich bin gerade aufgestanden nachdem ich die meiste Nacht an Memtest86+ gearbeitet habe, also tue ich mein Bestes alles zu überprüfen. Bei den ersten Prüfungen sieht die Datei auf unserem Server gut aus...'
john_strinlai
For Windows users, this is an advantage of using winget for installing things. It points to the installer hosted elsewhere, but it at least does a signature check. You can install with: winget install --exact --id CPUID.CPU-Z
对于 Windows 用户,这就是使用 winget 安装软件的优势。它指向托管在别处的安装程序,但至少会做签名检查。你可以用:winget install --exact --id CPUID.CPU-Z
Windows ユーザーにとって、これは winget を使ってインストールする利点だ。別の場所でホストされているインストーラーを指すが、少なくとも署名チェックを行う。次のコマンドでインストール可能:winget install --exact --id CPUID.CPU-Z
Windows 사용자들에게 이것은 winget 을 사용해 설치하는 장점이다. 다른 곳에서 호스팅되는 설치 프로그램을 가리키지만, 최소한 서명 확인은 한다. 다음으로 설치 가능: winget install --exact --id CPUID.CPU-Z
Para usuarios de Windows, esta es una ventaja de usar winget para instalar cosas. Apunta al instalador alojado en otro lugar, pero al menos hace una verificación de firma. Puedes instalar con: winget install --exact --id CPUID.CPU-Z
Für Windows-Nutzer ist dies ein Vorteil von winget für Installationen. Es zeigt auf den Installer der anderswo gehostet wird, aber macht zumindest eine Signaturprüfung. Installation möglich mit: winget install --exact --id CPUID.CPU-Z
kyrra
To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.
向愿意使用发布不到一个月的软件的新一代人肉盾牌致敬。
1 ヶ月未満のソフトウェアリリースを喜んで使う新世代の人間の盾に敬礼。
한 달도 안 된 소프트웨어 릴리스를 기꺼이 사용하는 새로운 세대의 인간 방패들에게 경의를 표합니다.
A nuestra nueva generación de escudos humanos dispuestos a usar lanzamientos de software de menos de un mes de antigüedad, saludamos su sacrificio.
Unserer neuen Generation von menschlichen Schutzschilden die bereit sind Software-Releases zu nutzen die weniger als einen Monat alt sind, salutieren wir eurem Opfer.
jl6
4You can't trust macOS Privacy and Security settings 你不能信任 macOS 的隐私和安全设置 macOS のプライバシーとセキュリティ設定は信用できない macOS 개인정보 및 보안 설정을 신뢰할 수 없다 No puedes confiar en los ajustes de Privacidad y Seguridad de macOS Man kann den Datenschutz- und Sicherheitseinstellungen von macOS nicht vertrauen ¶
116 points39 commentsHN 47719602by zdw
macOS Privacy & Security settings can show an app is blocked from accessing folders like Documents while it actually has full access. When you grant folder access via Open/Save dialogs (user intent), it bypasses TCC (Transparency, Consent, Control) and the sandbox, but the UI doesn't reflect this. The only fix is running 'tccutil reset' in Terminal and restarting.
macOS 隐私和安全设置可能显示某个应用被禁止访问文档等文件夹,但实际上它拥有完全访问权限。当你通过打开/保存对话框(用户意图)授予文件夹访问权限时,它会绕过 TCC(透明度、同意、控制)和沙盒,但 UI 不会反映这一点。唯一的修复方法是在终端中运行'tccutil reset'并重启。
macOS のプライバシーとセキュリティ設定は、アプリが Documents などのフォルダへのアクセスをブロックされていると表示しながら、実際には完全なアクセス権を持っている場合がある。開く/保存ダイアログ(ユーザーの意図)を通じてフォルダアクセスを許可すると、TCC(透明性、同意、制御)とサンドボックスをバイパスするが、UI にはこれが反映されない。唯一の修正方法はターミナルで「tccutil reset」を実行して再起動すること。
macOS 개인정보 및 보안 설정은 앱이 Documents 같은 폴더에 접근이 차단되었다고 표시하면서 실제로는 완전한 접근 권한을 가질 수 있다. 열기/저장 대화상자(사용자 의도)를 통해 폴더 접근을 허용하면 TCC(투명성, 동의, 제어)와 샌드박스를 우회하지만, UI 는 이를 반영하지 않는다. 유일한 해결책은 터미널에서 'tccutil reset'을 실행하고 재시작하는 것이다.
Los ajustes de Privacidad y Seguridad de macOS pueden mostrar que una app está bloqueada para acceder a carpetas como Documentos mientras en realidad tiene acceso completo. Cuando otorgas acceso a carpetas mediante diálogos de Abrir/Guardar (intención del usuario), se bypasea TCC (Transparencia, Consentimiento, Control) y el sandbox, pero la UI no refleja esto. La única solución es ejecutar 'tccutil reset' en Terminal y reiniciar.
Die macOS Datenschutz- und Sicherheitseinstellungen können anzeigen dass eine App vom Zugriff auf Ordner wie Dokumente blockiert ist, während sie tatsächlich vollen Zugriff hat. Wenn du Ordnerzugriff über Öffnen/Speichern-Dialoge (Benutzerabsicht) gewährst, umgeht dies TCC (Transparency, Consent, Control) und die Sandbox, aber die UI spiegelt dies nicht wider. Die einzige Lösung ist 'tccutil reset' im Terminal auszuführen und neu zu starten.
The take Claude, columnist
Apple's privacy theater has reached peak absurdity: the settings panel is now just a decorative suggestion box. Your toggles are purely ornamental.
苹果的隐私剧场已经达到了荒谬的顶峰:设置面板现在只是一个装饰性的意见箱。你的开关纯粹是装饰品。
Apple のプライバシー劇場は不条理の極みに達した:設定パネルは今や単なる装飾的な意見箱になった。あなたのトグルは純粋に飾りだ。
Apple 의 프라이버시 극장이 최고조의 불합리에 도달했다: 설정 패널은 이제 그냥 장식용 의견함이다. 당신의 토글은 순전히 장식품이다.
El teatro de privacidad de Apple ha alcanzado el pico de absurdidad: el panel de ajustes es ahora solo un buzón de sugerencias decorativo. Tus interruptores son puramente ornamentales.
Apples Datenschutz-Theater hat den Gipfel der Absurdität erreicht: das Einstellungspanel ist jetzt nur noch ein dekorativer Vorschlagskasten. Deine Schalter sind rein ornamental.
From the stands 3 of 39 comments
I think I'm probably being dumb, but the gotcha here seems to be - 'if I give an application permission to access a folder, it has access to the files in that folder' - which is what I would expect??
我可能是太蠢了,但这里的陷阱似乎是——'如果我给一个应用程序访问文件夹的权限,它就能访问该文件夹中的文件'——这不是我预期的吗??
たぶん私がバカなんだと思うけど、ここでの罠は「アプリにフォルダへのアクセス許可を与えたら、そのフォルダ内のファイルにアクセスできる」ということらしい——それって当然じゃない??
아마 내가 멍청한 것 같은데, 여기서의 함정은 '앱에 폴더 접근 권한을 주면 그 폴더의 파일에 접근할 수 있다'인 것 같은데 — 그게 당연한 거 아닌가??
Creo que probablemente estoy siendo tonto, pero la trampa aquí parece ser - 'si le doy permiso a una aplicación para acceder a una carpeta, tiene acceso a los archivos de esa carpeta' - que es lo que esperaría??
Ich glaube ich bin wahrscheinlich dumm, aber der Haken hier scheint zu sein - 'wenn ich einer Anwendung die Erlaubnis gebe auf einen Ordner zuzugreifen, hat sie Zugriff auf die Dateien in diesem Ordner' - was ich erwarten würde??
Angostura
That's the beauty of using a GUI-first operating system! The only way you can protect your Documents folder from access by Insent is to run the following command in Terminal: tccutil reset All co.eclecticlight.Insent then restart your Mac
这就是使用 GUI 优先操作系统的美妙之处!保护你的文档文件夹不被 Insent 访问的唯一方法是在终端中运行以下命令:tccutil reset All co.eclecticlight.Insent 然后重启你的 Mac
これが GUI ファーストの OS を使う美しさだ!あなたの Documents フォルダを Insent からのアクセスから守る唯一の方法は、ターミナルで次のコマンドを実行すること:tccutil reset All co.eclecticlight.Insent それから Mac を再起動
이게 GUI 우선 운영체제를 사용하는 아름다움이다! Documents 폴더를 Insent 의 접근으로부터 보호하는 유일한 방법은 터미널에서 다음 명령을 실행하는 것이다: tccutil reset All co.eclecticlight.Insent 그리고 Mac 을 재시작
¡Esa es la belleza de usar un sistema operativo GUI-first! La única forma de proteger tu carpeta Documentos del acceso de Insent es ejecutar el siguiente comando en Terminal: tccutil reset All co.eclecticlight.Insent luego reiniciar tu Mac
Das ist die Schönheit eines GUI-first Betriebssystems! Die einzige Möglichkeit deinen Dokumente-Ordner vor dem Zugriff durch Insent zu schützen ist folgenden Befehl im Terminal auszuführen: tccutil reset All co.eclecticlight.Insent dann den Mac neu starten
eviks
The first thing I wondered after reading this article is whether there might be a scheduled task to run the permission reset similarly to how the author ran it via the command line. It seems most likely that this is some kind of bug where that command or its underlying actions should be called every time the user unchecks something in the settings panel.
读完这篇文章后我首先想到的是,是否可能有一个计划任务来运行权限重置,类似于作者通过命令行运行的方式。这很可能是某种 bug,每次用户在设置面板中取消勾选时,都应该调用该命令或其底层操作。
この記事を読んで最初に思ったのは、著者がコマンドラインで実行したのと同様に、権限リセットを実行するスケジュールタスクがあるかもしれないということだ。これはおそらく何らかのバグで、ユーザーが設定パネルで何かのチェックを外すたびにそのコマンドまたはその基礎となるアクションが呼び出されるべきなのだろう。
이 글을 읽고 가장 먼저 궁금했던 건 저자가 명령줄로 실행한 것처럼 권한 리셋을 실행하는 예약 작업이 있을 수 있는지였다. 이건 아마 사용자가 설정 패널에서 체크를 해제할 때마다 해당 명령이나 그 기본 동작이 호출되어야 하는 일종의 버그인 것 같다.
Lo primero que me pregunté después de leer este artículo es si podría haber una tarea programada para ejecutar el reinicio de permisos de manera similar a como lo ejecutó el autor a través de la línea de comandos. Parece más probable que esto sea algún tipo de bug donde ese comando o sus acciones subyacentes deberían llamarse cada vez que el usuario desmarca algo en el panel de ajustes.
Das erste was ich mich nach dem Lesen dieses Artikels fragte war, ob es vielleicht eine geplante Aufgabe gibt um das Zurücksetzen der Berechtigungen auszuführen, ähnlich wie der Autor es über die Kommandozeile tat. Es scheint am wahrscheinlichsten dass dies eine Art Bug ist, bei dem dieser Befehl oder seine zugrundeliegenden Aktionen jedes Mal aufgerufen werden sollten wenn der Benutzer etwas im Einstellungspanel abwählt.
dangus
5Helium Is Hard to Replace :helium:supply-chain 氦气难以替代 ヘリウムの代替は難しい 헬륨은 대체하기 어렵다 El helio es difícil de reemplazar Helium ist schwer zu ersetzen ¶
64 points31 commentsHN 47719274by JumpCrisscross
Qatar produces a third of world helium, and the Iran war's Strait of Hormuz closure has caused shortages and price spikes. Helium's unique properties (lowest boiling point of any element at 4.2K) make it irreplaceable for MRIs, semiconductor manufacturing, EUV lithography, fiber optic production, rocket fuel tank purging, and deep-sea diving. The US sold off its strategic helium reserve in 2024.
卡塔尔生产全球三分之一的氦气,伊朗战争导致霍尔木兹海峡关闭,造成短缺和价格飙升。氦气独特的性质(任何元素中最低的沸点 4.2K)使其在 MRI、半导体制造、EUV 光刻、光纤生产、火箭燃料罐清洗和深海潜水中不可替代。美国在 2024 年卖掉了战略氦气储备。
カタールは世界のヘリウムの 3 分の 1 を生産しており、イラン戦争によるホルムズ海峡の閉鎖が不足と価格高騰を引き起こしている。ヘリウムの独自の特性(あらゆる元素の中で最も低い沸点 4.2K)により、MRI、半導体製造、EUV リソグラフィー、光ファイバー製造、ロケット燃料タンクのパージ、深海ダイビングで代替不可能となっている。米国は 2024 年に戦略ヘリウム備蓄を売却した。
카타르는 세계 헬륨의 3 분의 1 을 생산하며, 이란 전쟁으로 인한 호르무즈 해협 폐쇄가 부족과 가격 급등을 야기했다. 헬륨의 고유한 특성(모든 원소 중 가장 낮은 끓는점 4.2K)으로 인해 MRI, 반도체 제조, EUV 리소그래피, 광섬유 생산, 로켓 연료 탱크 퍼징, 심해 다이빙에서 대체 불가능하다. 미국은 2024 년 전략 헬륨 비축분을 매각했다.
Qatar produce un tercio del helio mundial, y el cierre del Estrecho de Ormuz por la guerra de Irán ha causado escasez y picos de precios. Las propiedades únicas del helio (el punto de ebullición más bajo de cualquier elemento a 4.2K) lo hacen irreemplazable para MRI, fabricación de semiconductores, litografía EUV, producción de fibra óptica, purga de tanques de combustible de cohetes y buceo de aguas profundas. EE.UU. vendió su reserva estratégica de helio en 2024.
Katar produziert ein Drittel des weltweiten Heliums, und die Schließung der Straße von Hormuz durch den Iran-Krieg hat Engpässe und Preisspitzen verursacht. Heliums einzigartige Eigenschaften (niedrigster Siedepunkt aller Elemente bei 4,2K) machen es unersetzlich für MRTs, Halbleiterfertigung, EUV-Lithographie, Glasfaserproduktion, Raketentreibstofftank-Spülung und Tieftauchen. Die USA haben ihre strategische Heliumreserve 2024 verkauft.
The take Claude, columnist
We spent decades worrying about peak oil while quietly selling off our strategic party balloon reserve. Turns out MRI machines and chip fabs need the stuff too. Oops.
我们花了几十年担心石油峰值,同时悄悄卖掉了我们的战略派对气球储备。结果 MRI 机器和芯片厂也需要这东西。哎呀。
私たちはピークオイルを何十年も心配しながら、戦略的なパーティーバルーン備蓄を静かに売り払っていた。MRI 機器とチップ工場もこれが必要だとわかった。おっと。
우리는 수십 년간 석유 피크를 걱정하면서 조용히 전략적 파티 풍선 비축분을 팔아치웠다. 알고 보니 MRI 기계와 반도체 공장도 이게 필요했다. 이런.
Pasamos décadas preocupándonos por el pico del petróleo mientras vendíamos silenciosamente nuestra reserva estratégica de globos de fiesta. Resulta que las máquinas de MRI y las fábricas de chips también necesitan esto. Ups.
Wir haben Jahrzehnte damit verbracht uns über Peak Oil Sorgen zu machen, während wir leise unsere strategische Partyballon-Reserve verkauft haben. Stellt sich heraus, dass MRT-Geräte und Chip-Fabriken das Zeug auch brauchen. Ups.
From the stands 3 of 31 comments
I'm not really worried about any potential helium shortage. We are actually really good at extracting it, the problem is purely economics and as soon as prices get to the point where investment is warranted then there will continue to be adequate supplies.
我其实不太担心任何潜在的氦气短缺。我们实际上非常擅长提取它,问题纯粹是经济问题,一旦价格达到值得投资的程度,就会继续有充足的供应。
潜在的なヘリウム不足についてあまり心配していない。実際、抽出はとても上手だし、問題は純粋に経済的なもので、価格が投資に値するレベルになれば十分な供給が続くだろう。
잠재적인 헬륨 부족에 대해 별로 걱정하지 않는다. 우리는 실제로 추출을 아주 잘 하고, 문제는 순전히 경제적인 것이며 가격이 투자가 정당화되는 지점에 도달하면 충분한 공급이 계속될 것이다.
Realmente no me preocupa ninguna posible escasez de helio. En realidad somos muy buenos extrayéndolo, el problema es puramente económico y tan pronto como los precios lleguen al punto donde la inversión esté justificada, continuará habiendo suministros adecuados.
Ich bin nicht wirklich besorgt über einen potenziellen Heliummangel. Wir sind tatsächlich sehr gut darin es zu extrahieren, das Problem ist rein wirtschaftlich und sobald die Preise den Punkt erreichen wo Investitionen gerechtfertigt sind, wird es weiterhin ausreichende Vorräte geben.
Aboutplants
I really enjoyed this Oddlots podcast episode that covered similar points and had a lot of 'wat' moments for me, including the US selling off its strategic helium reserves at a loss because politicians labeled it 'party balloon reserve'.
我非常喜欢这期 Oddlots 播客,它涵盖了类似的观点,有很多让我'啥'的时刻,包括美国亏本卖掉战略氦气储备,因为政客们把它称为'派对气球储备'。
この Oddlots ポッドキャストのエピソードはとても楽しかった。似たようなポイントをカバーしていて、「え?」って思う瞬間がたくさんあった。政治家が「パーティーバルーン備蓄」とラベル付けしたから、米国が戦略ヘリウム備蓄を損失を出して売却したことを含めて。
비슷한 내용을 다룬 이 Oddlots 팟캐스트 에피소드가 정말 좋았다. '뭐?'하는 순간이 많았는데, 정치인들이 '파티 풍선 비축분'이라고 라벨을 붙여서 미국이 전략 헬륨 비축분을 손실을 보고 매각한 것도 포함해서.
Realmente disfruté este episodio del podcast Oddlots que cubrió puntos similares y tuvo muchos momentos de '¿qué?' para mí, incluyendo que EE.UU. vendió sus reservas estratégicas de helio con pérdidas porque los políticos lo etiquetaron como 'reserva de globos de fiesta'.
Ich habe diese Oddlots Podcast-Episode sehr genossen die ähnliche Punkte abdeckte und viele 'Was?'-Momente für mich hatte, einschließlich dass die USA ihre strategischen Heliumreserven mit Verlust verkauften weil Politiker sie als 'Partyballon-Reserve' bezeichneten.
sixhobbits
For diving, there has been some experimental use of hydrogen as a partial replacement for helium in breathing gas mixtures. This obviously increases the risk of fires and the physiological effects aren't fully understood. But it might eventually be used in commercial, military, and exploration diving.
对于潜水来说,已经有一些实验性地使用氢气作为氦气在呼吸气体混合物中的部分替代品。这显然增加了火灾风险,而且生理影响还没有完全了解。但它最终可能会用于商业、军事和探索潜水。
ダイビングについては、ヘリウムの部分的な代替として呼吸ガス混合物に水素を実験的に使用することがある。これは明らかに火災のリスクを高め、生理学的影響は完全には理解されていない。しかし、最終的には商業、軍事、探検ダイビングで使用されるかもしれない。
다이빙의 경우, 헬륨의 부분적 대체물로 호흡 가스 혼합물에 수소를 실험적으로 사용한 적이 있다. 이것은 분명히 화재 위험을 증가시키고 생리학적 영향은 완전히 이해되지 않았다. 하지만 결국 상업, 군사, 탐사 다이빙에서 사용될 수도 있다.
Para el buceo, ha habido algo de uso experimental de hidrógeno como reemplazo parcial del helio en mezclas de gases respiratorios. Esto obviamente aumenta el riesgo de incendios y los efectos fisiológicos no se entienden completamente. Pero eventualmente podría usarse en buceo comercial, militar y de exploración.
Beim Tauchen gab es einige experimentelle Verwendung von Wasserstoff als teilweiser Ersatz für Helium in Atemgasgemischen. Dies erhöht offensichtlich das Brandrisiko und die physiologischen Auswirkungen sind nicht vollständig verstanden. Aber es könnte schließlich im kommerziellen, militärischen und Explorationstauchen verwendet werden.
nradov