Reading view

There are new articles available, click to refresh the page.

A bodybuilder pinches his bulging thigh – Sergio Purtell’s best photograph

‘This was taken at a small high school event. It was all about who could create the “perfect body” by working hard – and maybe becoming the next Arnold Schwarzenegger’

I’d been studying architectural design in Chile and thought I would do the same when I got to the US. But at university there, photography was one of my subjects – and the minute I put that first sheet of paper in the developer, it was magic to me. There is so much you can say in just one frame. I found it thrilling and overwhelming.

I’ve been living in the US for more than 50 years now and a lot of the pictures from my new book, Moral Minority, were made in the 1980s, when my notion of being a photographer was just beginning to form. The country was new to me and I wanted to figure out how to fit into it and how things worked.

Continue reading...

💾

© Photograph: Sergio Purtell

💾

© Photograph: Sergio Purtell

‘Bewilderingly evanescent’: how a darkroom allergy made Barbara Kasten see the light

The 88-year-old Chicago artist takes photography to a whole new level – as her new East Sussex show, which uses fluorescent panels to sculpt with colour, proves

Sunshine beams down on Bexhill’s De La Warr Pavilion for the first time since Barbara Kasten arrived to install her first institutional solo show in the UK. Standing outside, where the modernist building faces the wide sea front, the 88-year-old American artist is delighted. Ghostly pink shapes wriggle behind the huge windows. Devising the show, at home in Chicago, she’d feared the sunlight would be too strong, causing a photographic white-out, but no: “The light here is so gentle.”

Inside the exhibition hall, the wriggling pink light is revealed as reflections on fluorescent acrylic plexi-panels, which are clamped into what Kasten conceives as large stage flats. She has yet to decide on their final placement when I visit, but is clear that this is “the backstage area”. The expanse of windows facing the sea is the “proscenium arch”, which she has accentuated with columns of brightly coloured perspex. They lean up against the window frames, casting their own colours dramatically across the floor and each other, while mixing into something mysteriously different in the plexi-panels behind them.

Continue reading...

💾

© Photograph: Susanne Diesner/© Photo: Susanne Diesner. Courtesy Thomas Dane Gallery.

💾

© Photograph: Susanne Diesner/© Photo: Susanne Diesner. Courtesy Thomas Dane Gallery.

Francis Alÿs: Ricochets review – children of the world unite in a health and safety nightmare

Barbican, London
From Cuba to Mexico, from Hong Kong to Iraq, the Belgian artist has made 40 mesmerising films of kids at play, including three with guns up to no good in a war zone

Cries and laughter, clapping and calls and screams of delight fill the gallery. There are children everywhere on the multiple screens that fill the lower floor. Kids in Cuba careen round the streets of Havana on precarious trolleys fashioned from bits of wood and discarded junk. They rattle and slew on cobbles and jink round corners, under the amused and indulgent eyes of adults as they come hurtling past. The game is both exhilarating and frightening to watch, the young pilots and passengers inches away from hideous injury. Talk about health and safety.

Little girls on a London housing estate swipe at each other’s conkers in a game that’s been largely banished from British school playgrounds. Of course, there’s a lot more to the culture of conkers than whacking horse chestnuts on a bit of string. How careful you have to be – preparing the conker, drilling it and threading it on to a string. All games, like art, have their rules and conditions.

Continue reading...

💾

© Photograph: Francis Alÿs

💾

© Photograph: Francis Alÿs

‘Infectious enthusiasm’: Jonathan Yeo’s green portrait of David Attenborough unveiled

Painting of 98-year-old broadcaster, commissioned by Royal Society, goes on public display 2 July

Jonathan Yeo hopes he has communicated the sitter’s “wisdom and thoughtfulness” in his latest portrait, but also the “sort of childlike, infectious enthusiasm” that audiences know so well.

Yeo is talking about his new, strikingly green, portrait of Sir David Attenborough, a figure who has gone beyond being a national treasure to someone known globally, and someone people might listen to when it comes to the catastrophes facing the world.

Continue reading...

💾

© Photograph: Richard Valencia Photography/Jonathan Yeo

💾

© Photograph: Richard Valencia Photography/Jonathan Yeo

Lesbians unleashed! The joyous, sexually explicit photographer no publisher would touch

Tee A Corinne took fearless shots of same-sex lovers in a 1980s Oregon commune – and published a notoriously intimate colouring book that became a minor classic. Has her time come at last?

In 1993, Tee A Corinne wrote that she was “close to being finished with sexual imagery”. Corinne was a prolific multimedia artist, activist, photographer and writer of erotica and autobiography. Much of her work involved what she called “labia imagery and … images of women making love with other women or with themselves”. After three decades of this, however, she was thinking about moving on. “I have thought this before but changed my mind,” she wrote. “Why? Because no one else was making the images I wanted to see.”

The images Corinne made, in part because nobody else was doing it, remain extraordinary, invigorating and quietly radical. Her Artist’s Statement: On Sexual Art is just one of many documents, posters, essays and letters gathered together by Charlotte Flint, editor of A Forest Fire Between Us, a new book collecting some of Corinne’s considerable body of work and the ephemera surrounding it.

Continue reading...

💾

© Photograph: © Tee A. Corinne / Tee A. Corinne Papers, Coll. 263. Special Collections and University Archives, University of Oregon Archives, from Tee A. Corinne: A forest fire between us (MACK, 2024). Courtesy of MACK and University of Oregon Archives.

💾

© Photograph: © Tee A. Corinne / Tee A. Corinne Papers, Coll. 263. Special Collections and University Archives, University of Oregon Archives, from Tee A. Corinne: A forest fire between us (MACK, 2024). Courtesy of MACK and University of Oregon Archives.

‘Hey pigeon-keeper, flip me on the grill rack!’ The spicy guide to queer Arab slang

Scorpions, grill racks, pigeons – if you want to know what these terms also mean, look up The Queer Arab Glossary, a playfully illustrated new compendium of words running from the affectionate to the derogatory

Do you know what yrabbī ḥamām means? It is one of 330 slang terms that Lebanese artist Marwan Kaabour has put in his debut book, The Queer Arab Glossary. Yrabbī ḥamām is a colloquial term that means “pigeon keeper”, with the word ḥamām (pigeon) a common euphemism for penis. It’s Kaabour’s favourite entry and, he says, ḥamām is used “in an endearing way, like in a way a mum and child would joke about”. The term can also refer to someone who engages in gay sex, and it is accompanied by an illustration by Palestinian graphic designer Haitham Haddad, showing a cheerful gay man with a moustache feeding pigeons depicted as flying penises.

The book provides a snapshot of the linguistic landscape of queerness in Arabic-speaking regions, with examples from Levantine, Iraqi, Gulf, Egyptian, Sudanese and Maghrebi dialects. “I am waging a battle on two fronts with this book,” says Kaabour, who is based in London. “The first is directed towards the authorities of my own people, those who claim that queerness is a western import. I am debunking that. I’m showing them how we have been a big part of Arab society since day one. The second is facing westwards, particularly to those who have rightwing politics, who say that Arabs are somehow innately homophobic or sexist.”

Continue reading...

💾

© Photograph: Haitham Haddad

💾

© Photograph: Haitham Haddad

Every elevator in the Myst series, ranked

Every elevator in the Myst series, ranked An hour long deep dive into the environment and puzzle design in the Myst series, centered upon its elevators. (Warning: Contains spoilers for all 5 games in the Myst series)

This might be the nerdiest thing I've seen in this fandom in a long long time! I love the little digressions like exactly what counts as an elevator, and the creator's obvious affection for the games.

‘Fraught with danger’: wild honey gathering in Nepal – in pictures

For generations the Gurung community in Taap, about 175km (110 miles) west of the capital, Kathmandu, and other villages in the districts of Lamjung and Kaski, have scoured the steep Himalayan cliffs for honey. The villagers say the proceeds, split among them, are drying up as the number of hives has declined over the past decade, although some also earn a living from growing crops of rice, corn, millet and wheat

Continue reading...

💾

© Photograph: Navesh Chitrakar/Reuters

💾

© Photograph: Navesh Chitrakar/Reuters

Enhancing Security Measures: Overcoming Barriers to Single Sign-On (SSO) Adoption Among SMBs

SSO tax

In the latest update of "Secure by Design”, the Cybersecurity and Infrastructure Security Agency (CISA) highlighted the critical importance of integrating security practices into basic services for software manufacturers. The paper highlights a notable concern: the imposition of an "SSO tax" where essential security features like Single Sign-On (SSO) are bundled as premium services, potentially hindering their adoption among Small and Medium-sized Businesses (SMBs).

Implementing Single Sign-On (SSO) into Small and Medium-sized Businesses (SMBs)

SSO simplifies access management by allowing users to authenticate once and gain access to multiple applications—a crucial feature for enhancing security postures across organizations. However, its adoption faces significant hurdles, primarily due to cost implications and perceived operational complexities. One of the primary challenges identified by CISA is pricing SSO capabilities as add-ons rather than including them in the base service. This "SSO tax" not only inflates costs but also creates a barrier for SMBs looking to bolster their security frameworks without incurring substantial expenses. By advocating for SSO to be a fundamental component of software packages, CISA aims to democratize access to essential security measures, positioning them as a customer right rather than a premium feature. Beyond financial considerations, the adoption of SSO is also influenced by varying perceptions among SMBs. While some view it as a critical enhancement to their security infrastructure, others question its cost-effectiveness and operational benefits. Addressing these concerns requires clearer communication on how SSO can streamline operations and improve overall security posture, thereby aligning perceived expenses with tangible returns on investment.

Improving User Experience and Support

Technical proficiency poses another hurdle. Despite vendors providing training materials, SMBs often face challenges in effectively deploying and maintaining SSO solutions. The complexity involved in integrating SSO into existing systems and the adequacy of support resources provided by vendors are critical factors influencing adoption rates. Streamlining deployment processes and enhancing support mechanisms can mitigate these challenges, making SSO more accessible and manageable for SMBs with limited technical resources. Moreover, the user experience with SSO implementation plays a pivotal role. Feedback from SMBs indicates discrepancies in the accuracy and comprehensiveness of support materials, necessitating multiple interactions with customer support—a time-consuming process for resource-constrained businesses. Simplifying user interfaces, refining support documentation, and offering responsive customer service are essential to improving the adoption experience and reducing operational friction. In light of these updates, there is a clear call to action for software manufacturers. Aligning with the principles of Secure by Design, manufacturers should integrate SSO into their core service offerings, thereby enhancing accessibility and affordability for SMBs. By addressing economic barriers, improving user interfaces, and providing robust technical support, manufacturers can foster a more conducive environment for SSO adoption among SMBs.

There's never been a better time to get into storytelling board games

"Storytelling has been a social activity since the dawn of time. Board games can add another level to it with nuanced strategies for decision-making and objectives with epic stakes."

People like to make lists of storytelling board games. Designing a narrative board game is a distinct form of game design. TV Tropes, weirdly, covers Narrative Board Games. There are, of course, books about the stories built into boardgames. Board games have a robust history of recreating and validating imperialism, genocide, and slavery, which David Massey takes on in "Slave Play, or the Imperial Logic of Board Game Narrative." [SLPDF] Flanagan and Jakobsson take on the future of the board game in their book Playing Oppression: The Legacy of Conquest and Empire in Colonialist Board Games. Storytelling has, of course, appeared on MetaFilter previously.

Adobe to update vague AI terms after users threaten to cancel subscriptions

Adobe to update vague AI terms after users threaten to cancel subscriptions

Enlarge (credit: bennymarty | iStock Editorial / Getty Images Plus)

Adobe has promised to update its terms of service to make it "abundantly clear" that the company will "never" train generative AI on creators' content after days of customer backlash, with some saying they would cancel Adobe subscriptions over its vague terms.

Users got upset last week when an Adobe pop-up informed them of updates to terms of use that seemed to give Adobe broad permissions to access user content, take ownership of that content, or train AI on that content. The pop-up forced users to agree to these terms to access Adobe apps, disrupting access to creatives' projects unless they immediately accepted them.

For any users unwilling to accept, canceling annual plans could trigger fees amounting to 50 percent of their remaining subscription cost. Adobe justifies collecting these fees because a "yearly subscription comes with a significant discount."

Read 25 remaining paragraphs | Comments

April’s Patch Tuesday Brings Record Number of Fixes

If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.

Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office, Azure, .NET Framework, Visual Studio, SQL Server, DNS Server, Windows Defender, Bitlocker, and Windows Secure Boot.

“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs, from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Microsoft of all time.”

Tempering the sheer volume of this month’s patches is the middling severity of many of the bugs. Only three of April’s vulnerabilities earned Microsoft’s most-dire “critical” rating, meaning they can be abused by malware or malcontents to take remote control over unpatched systems with no help from users.

Most of the flaws that Microsoft deems “more likely to be exploited” this month are marked as “important,” which usually involve bugs that require a bit more user interaction (social engineering) but which nevertheless can result in system security bypass, compromise, and the theft of critical assets.

Ben McCarthy, lead cyber security engineer at Immersive Labs called attention to CVE-2024-20670, an Outlook for Windows spoofing vulnerability described as being easy to exploit. It involves convincing a user to click on a malicious link in an email, which can then steal the user’s password hash and authenticate as the user in another Microsoft service.

Another interesting bug McCarthy pointed to is CVE-2024-29063, which involves hard-coded credentials in Azure’s search backend infrastructure that could be gleaned by taking advantage of Azure AI search.

“This along with many other AI attacks in recent news shows a potential new attack surface that we are just learning how to mitigate against,” McCarthy said. “Microsoft has updated their backend and notified any customers who have been affected by the credential leakage.”

CVE-2024-29988 is a weakness that allows attackers to bypass Windows SmartScreen, a technology Microsoft designed to provide additional protections for end users against phishing and malware attacks. Childs said one of ZDI’s researchers found this vulnerability being exploited in the wild, although Microsoft doesn’t currently list CVE-2024-29988 as being exploited.

“I would treat this as in the wild until Microsoft clarifies,” Childs said. “The bug itself acts much like CVE-2024-21412 – a [zero-day threat from February] that bypassed the Mark of the Web feature and allows malware to execute on a target system. Threat actors are sending exploits in a zipped file to evade EDR/NDR detection and then using this bug (and others) to bypass Mark of the Web.”

Update, 7:46 p.m. ET: A previous version of this story said there were no zero-day vulnerabilities fixed this month. BleepingComputer reports that Microsoft has since confirmed that there are actually two zero-days. One is the flaw Childs just mentioned (CVE-2024-21412), and the other is CVE-2024-26234, described as a “proxy driver spoofing” weakness.

Satnam Narang at Tenable notes that this month’s release includes fixes for two dozen flaws in Windows Secure Boot, the majority of which are considered “Exploitation Less Likely” according to Microsoft.

“However, the last time Microsoft patched a flaw in Windows Secure Boot in May 2023 had a notable impact as it was exploited in the wild and linked to the BlackLotus UEFI bootkit, which was sold on dark web forums for $5,000,” Narang said. “BlackLotus can bypass functionality called secure boot, which is designed to block malware from being able to load when booting up. While none of these Secure Boot vulnerabilities addressed this month were exploited in the wild, they serve as a reminder that flaws in Secure Boot persist, and we could see more malicious activity related to Secure Boot in the future.”

For links to individual security advisories indexed by severity, check out ZDI’s blog and the Patch Tuesday post from the SANS Internet Storm Center. Please consider backing up your data or your drive before updating, and drop a note in the comments here if you experience any issues applying these fixes.

Adobe today released nine patches tackling at least two dozen vulnerabilities in a range of software products, including Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate.

KrebsOnSecurity needs to correct the record on a point mentioned at the end of March’s “Fat Patch Tuesday” post, which looked at new AI capabilities built into Adobe Acrobat that are turned on by default. Adobe has since clarified that its apps won’t use AI to auto-scan your documents, as the original language in its FAQ suggested.

“In practice, no document scanning or analysis occurs unless a user actively engages with the AI features by agreeing to the terms, opening a document, and selecting the AI Assistant or generative summary buttons for that specific document,” Adobe said earlier this month.

❌