ty

Bacharach Pitches Refrigeration Leak Safety

Bacharach has been in acquisition mode lately, and the company was showing off the new products and relationships that resulted from that at this year’s AHR Expo in Atlanta.




ty

Reducing Refrigerant Leaks Should Be Top Priority for HVACR Contractors

Refrigerant leaks in HVACR equipment – particularly commercial refrigeration systems -- are a significant problem.




ty

Project Files: Episode 67 — Variable-Speed A/C in Miami Humidity

The Endeavor Line provides tech-savvy and environmentally mindful consumers like the Horwitzes with smart home compatibility and sustainable features.




ty

Study Shows What City Uses A/C the Most

A recent survey done by Daikin shows what state leads the globe in a/c usage.




ty

HVAC Solutions Help Data Centers Achieve Sustainability

The rapid expansion of data centers has raised concerns about their massive energy use and carbon footprint. However, adopting sustainable HVAC solutions can reduce a data center’s environmental impact and energy consumption.




ty

Project Files: Episode 63 — University of Cincinnati Chiller Upgrade

Like many universities across America, the University of Cincinnati faced a major infrastructure challenge: having to operate aging central utility plants with older technology.




ty

Troubleshooting a Faulty HVAC Compressor Requires Patience

How does a tech know the a/c compressor he or she is diagnosing is actually failed and that the problem is not a crankcase heater, condenser fan, or rubbed out wire?




ty

Security and the Smart Thermostat: Prepare for Customer Questions

The path to temperature control through smart thermostat technology is more involved than many customers realize.




ty

Lennox Recognized for Corporate Responsibility and Sustainability

Lennox received a 2023 Green Builder Sustainable Product of the Year recognition.




ty

Community Church Benefits From Unitary Variable Refrigerant Flow Retrofit

With over 1,000 Sunday service attendees and many church activities throughout the week, energy efficiency for the sake of cost savings was critical.




ty

Ducted Mini-Split Air Handlers Offer Flexibility

Most of the rest of the world has relied on ductless mini-split systems for their heating and cooling needs for decades, but that has not been the case in the U.S. That may be changing with the advent of ducted mini-split systems.




ty

Geothermal Offers an Opportunity for HVAC Contractors

The moment for geothermal seemed to have arrived several times since the 1970s. A number of factors are forecasting wider use of this type of heating and cooling solution.




ty

The 9 Types of Heat Pumps

As the U.S. moves toward electrification, heat pumps are becoming more popular, which will likely increase sales in the coming years. The key is to know which type of heat pump will work best for an application, as there is a wide range of equipment from which to choose.




ty

Breaking the Code: Controlling Humidity and Particulate to Meet Building Standards

While balanced ventilation does have energy benefits, there is a misconception about its ability to reduce humidity.




ty

Guiding Customers through Indoor Air Quality and the Tips to Maintain IAQ

As HVAC providers, we have the ability to advise homeowners, builders, and property managers on ways to improve their indoor air quality.




ty

Maximizing Indoor Air Quality Without Sacrificing Energy Efficiency

The proper application of modern HVAC technologies can help maximize indoor air quality while minimizing losses in operational efficiency.




ty

Re: shell wildcard expansion (un)safety

Posted by Eli Schwartz on Nov 10

The earliest version of the Bash Pitfalls guide that includes a warning
about the topic, per the Wayback Machine:

https://web.archive.org/web/20090426020027/https://mywiki.wooledge.org/BashPitfalls#Filenames_with_leading_dashes

Overall, wildcards are just a classic "here is a programming language
footgun, we cannot fix it because the language is backwards compatible
to the 90s and earlier" which amounts to:

people love bash because...




ty

Re: shell wildcard expansion (un)safety

Posted by lists on Nov 10

That says nothing about the amusing character # either at the
start of a name or after whitespace.





ty

Re: shell wildcard expansion (un)safety

Posted by Fay Stegerman on Nov 10

* Eli Schwartz <eschwartz () gentoo org> [2024-11-10 00:59]:
[...]

[...]

Obviously, shell scripts and wildcards are one of the easiest ways to trip up
here. But the underlying issue is that CLI interfaces mix options and
arguments: the lack of a clean separation between data and code/commands
(another example is e.g. printing unescaped control characters to stdout,
something discussed on this list before, and far too common IME, as I...




ty

Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45819 / XSA-464
version 2

libxl leaks data to PVH guests via ACPI tables

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

PVH guests have their ACPI tables constructed by the toolstack. The
construction involves building the tables in local memory, which are
then copied into guest memory. While actually used...




ty

Xen Security Advisory 463 v2 (CVE-2024-45818) - Deadlock in x86 HVM standard VGA handling

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45818 / XSA-463
version 2

Deadlock in x86 HVM standard VGA handling

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

The hypervisor contains code to accelerate VGA memory accesses for HVM
guests, when the (virtual) VGA is in "standard" mode. Locking involved
there has an unusual discipline, leaving...




ty

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Andrew Cooper on Nov 12

Data are leaked into the PVShim guest, but it is the shim Xen
(exclusively) which has access to the ACPI tables.

The guest which has been shim'd can't architecturally access the leaked
data.

~Andrew





ty

Re: shell wildcard expansion (un)safety

Posted by Ali Polatel on Nov 12

Thank you. Around six months ago I added a restriction on filenames with
control characters to Sydbox[1] after I had read about a vulnerability
here on this list. I think it was about tar but my memory may not serve
me right. Sydbox is secure by default, so at first this feature was
enabled without any way to turn it off. After a few months of testing
with fellow Exherbo Linux developers, we have noticed some package tests
(nvim was one of them)...




ty

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Demi Marie Obenour on Nov 12

Is this unconditional (perhaps because the relevant data gets zeroed out
by the shim), or does it only apply when the PV guest can't extract data
from the shim's memory? For instance, 32-bit PV guests aren't security
supported anymore, but the PV shim isn't supposed to rely on the
security of the shim itself, only of the rest of the system.




ty

Panasonic Manages Consumer Comfort, Controllability, and Costs

Panasonic Corp. of North America is honing in on its focus to make it easier for both residential and commercial building owners to control the temperature and comfort level within the space. The company hit its targets with the introduction of two new products — the ECONAVI air conditioner and the Variable Refrigerant Flow (VRF) Smart Connectivity Controller.




ty

Aircuity is Approved Vendor for Real-Time Energy Management Program

Aircuity has been named a New York State Energy Research and Development Authority Qualified Vendor for the RTEM program.




ty

Honeywell Launches Autonomous Building Sustainability Solution To Fight Rising Global Energy Consumption

Honeywell announced the launch of Honeywell Forge Energy Optimization, a cloud-based, closed-loop, machine learning solution.




ty

Acuity Brands to Acquire KE2 Therm

The acquisition extends Distech Controls’ addressable market into commercial refrigeration.




ty

Serviceability, Flexibility Earn Aaon’s WH Series DDA Gold

Aaon’s focus on serviceability and performance helped the WH Series earn gold in The NEWS’ 2017 Dealer Design Awards HVAC Light Commercial Equipment category.




ty

Wireless, Connected Tools Surging in Popularity

There’s no doubt the connectivity of mobile devices has made our personal lives more convenient, but now they’re also helping make technicians more efficient, thanks to tool manufacturers developing wireless-enabled devices and test and measurement apps for download.




ty

A Case Study: Driving Energy Efficiency Through Utility Incentives

Is reducing a facility's energy consumption by over 130,000 kWh annually through HVAC optimization possible?




ty

Q&A: Does Building Automation Make a Difference in Air Quality?

Today’s commercial structures are full of sophisticated controls that have been changing building automation systems exponentially.




ty

Building Automation Systems Offer Comfort, Efficiency, and Security

HVAC has a critical role to play in the future of building automation and digitalization.




ty

Trane Outfits Community College’s New BAS Lab

The lab is designed to give students hands-on experience that will help them bridge the gap between classroom instruction and the needs of employers.




ty

Preparing For Emerging Cybersecurity Attacks Against Chillers

When it comes to this piece of critical infrastructure, operators need to be prepared to face new and sophisticated attacks.




ty

Comfort is the HVAC Contractor’s Top Commodity

Customer comfort is the top sales driver in the HVAC industry, or at least it should be.




ty

Future Proofing Your Building: Where HVAC and Sustainability Come Together

With cost reduction, sustainability enablement, increased comfort and performance benefits, VRF systems allow commercial buildings to gain a competitive advantage by reducing their carbon footprint and providing custom comfort to occupants.




ty

Air-to-Water Heat Pump Innovations Driving Efficiency, Safety, and Performance in Residential Heating and Cooling

To meet the ambitious environmental goals being proposed at all levels of government, residential air-to-water heat pumps are emerging as a transformative solution to lower carbon emissions, enhance energy efficiency, and reduce utility bills.




ty

Peterman Brothers Charity Showdown Supports Indianapolis-Area Community Organizations

Throughout March, voters will help the staff at Peterman Brothers select four charity partner organizations for 2023.




ty

[PATCH 0/1] Improved the legibility of Makefile

Posted by Ariel Otilibili on Sep 17

Hello committers,

The same patch is on this PR: https://github.com/nmap/nmap/pull/2938

Have a good weekend,
Ariel

Ariel Otilibili (1):
Improved the legibility of `Makefile`

Makefile.in | 14 +++-----------
1 file changed, 3 insertions(+), 11 deletions(-)




ty

[PATCH 1/1] Improved the legibility of `Makefile`

Posted by Ariel Otilibili on Sep 17

* source files obtained by a wildcard
* headers and objects generated by differences.

```
$ grep -P '(SRCS|HDRS|OBJS) =' Makefile.in |
sed -e 's/^export.*= //g; s/$.*//g; s/OBJS = //' |
sed -ne '2p' |
tr ' ' ' ' |
sed -e 's/.h//' |
sort -d |
grep -vP '^$' > headers

$ grep -P '(SRCS|HDRS|OBJS) =' Makefile.in |
sed -e...




ty

CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management

Posted by CISA on Mar 21

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information
has recently been updated, and is now available.

CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management [...




ty

Apple Releases Security Updates for Multiple Products

Posted by CISA on Mar 28

Cybersecurity and Infrastructure Security Agency (CISA) - Defend Today, Secure Tomorrow

You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information
has recently been updated and is now available.

Apple Releases Security Updates for Multiple Products [
https://www.cisa.gov/news-events/alerts/2023/03/28/apple-releases-security-updates-multiple-products ] 03/28/2023 01:00
PM EDT

Apple...




ty

Episode 28: Type Systems

In recent episodes we have discusses statically and dynamically typed languages and domain specific languages - topics that are much talked about in the community at the moment. In this episode we look at the foundation of programming languages : types. We explain what a type actually is, how type systems work and what polymorphism works.




ty

Episode 66: Gary McGraw on Security

This episode features an interview with the software security expert Gary McGraw. Gary explains why this topic is so important and gives several security deficiencies examples that he found in the past. The second half of the interview is about his latest book 'Exploiting Online Games' where he explains how online games are hacked and why this is relevant to everybody, not only gamers in their 'First Life'.




ty

Episode 88: The Singularity Research OS with Galen Hunt

In this episode we talk to Galen Hunt about the Singularity research OS. Galen is the head of Microsoft's OS Research Group and, together with a team of about 30 other researches, has built Singularity. We started our discussion by covering the basics of Singularity: why it was designed, what the goals of the project are as well as some of the architectural foundations of Singularity: software isolated processes, contract-based channels and manifest-based programs. In this context we also looked at the role of the Spec# and Sing# programming languages and the role of static analysis tools to statically verify important properties of a singularity application. We then looked a little bit more closely at the role of the kernel and how it is different from kernels in traditional OSes. In a second part of the discussion we looked at some of the experiments the group did based on the OS. These include compile-time reflection, using hardware protection domains, heterogenerous multiprocessing as well as the typed assembly language We closed the conversation with a look at some of the performance characteristics of Singularity, compatibility with traditional operating systems and a brief look at how the findings from Singularity influence product development at Microsoft.




ty

Episode 127: Usability with Joachim Machate

This episode is an introduction to user interface design with Joachim Machate of UID. We talk about the importance of user interface design, about its relationship to the overall software engineering process, as well as about UID's process for systematic user interface design.




ty

Episode 128: Web App Security with Bruce Sams

The majority of hacker attacks (70 %) are directed at weaknesses that are the result of problems in the implementation and/or architecture of the application. This session shows how you can protect your web applications (J2EE or .NET) against these attacks. The session covers lots of practical examples and techniques for attack. Furthermore, it shows strategies for defense, including a "Secure Software Development Lifecycle". A "Live Hacking" demo rounds it out. This is a session recorded live at OOP 2009. SE Radio thanks Bruce, SIGS Datacom and the programme chair, Frances Paulisch, for their great support!