Call me cynical or jaded, but I'm suspicious of anyone who tries to push something that is apparently "good for me" too hard. If it's truly so good for me, I'll come to understand that of my own volition and I'll choose to use it voluntarily. If someone has having to foist it upon me, they very likely have an ulterior motive which *isn't* "good for me". This is one of the things that bothers me so much about AI. The propaganda is all "it's going to make your life better". But if they truly believe that and they want to "bring people along", why do dodgy shit like override settings a user set previously, opt users into something that involves tracking them or accessing private data, etc.? Of course, we all know the reason, but it'd be great if they could at least be honest and transparent about it rather than disingenuous and deceiving. I'm actually far more likely to trust someone when they're at least honest about their motives, even if I don't agree with those motives.
Inspired by: neowin.net/guides/google-can-n…

Zach Bennoui reshared this.

in reply to Jamie Teh

I know there are concerns with AI, but in general Wish people would apply this to Microsoft just saying. It’s been happening for years and nobody seems to care. I am better off with AI well at least I can make myself a work around for stupid shit that is happening in operating systems. I also like being able to use plain language and have no programming language experience required to fix add-ons that have been abandoned, that I like using in command line windows.
This entry was edited (5 months ago)

PRIVACY WIN! Montana becomes the first state to close a data broker loophole for law enforcement 🎉

Police can no longer buy your private data from brokers to bypass warrant requirements. Good on Montana!

Source: EFF: eff.org/deeplinks/2025/05/mont…

KPBS: Worksite immigration raids are supposed to free up jobs for citizens. Here’s what really happens

(Personal commentary: there are extremely few US citizens who would take ANY of these jobs)

kpbs.org/news/border-immigrati…

#ice #politics #fear #immigration

in reply to AI6YR Ben

I was at the Main Street cafe a while back, and there were some yeehawdists at the table behind me going off about how Mexicans were taking their jobs, and I turned around and said, “Son, I know five farms that need help right now. I can make a phone call and you can be in the field in an hour. Now, bring a hat, it’s hot out here in the sun all day. And gloves, those plants will tear you up. To make minimum wage, you’ll have to hustle, you get paid by the bushel. You wanna finish lunch and go pick some maters, or you wanna shut the fuck up so I can eat my chicken fried steak in peace?”

They shut the fuck up. Silence until they left. And the cook sent me a peach cobbler. 🥳

reshared this

Webinar, July 30 at 12pm ET: It Takes All Three: How Hardware, Software, and Accessibility Experts Create Inclusive Airline Experiences - TPGi tpgi.com/webinar-july-30-at-12…

TIL that Tacos Al Pastor, the "Shepherd's Taco" that I can get at El Sol just down the street in Toronto's east end - elsol.ca/new-page-1 - is one of Mexico City's signature foods that was born of Shawarma origins and the Lebanese immigrants who moved to Mexico City in the late fifties.

Immigration and diversity are an unbridled good in this world.

mastodon.social/@allwelikeworm…

This entry was edited (5 months ago)

If Privacy and Security Matter—Choose the Librem 5, Powered by PureOS

In today’s hyper-connected world, protecting your data, privacy, and security isn’t optional—it’s essential.

That’s why professionals who demand digital sovereignty choose the Librem 5 from Purism.

This isn’t just another smartphone.

The Librem 5 is a statement—a bold move toward freedom from surveillance capitalism and intrusive ecosystems.

Buy here: puri.sm/products/librem-5/

« Guerre guerre, vente vent », interprété par Tri Yann #mastobada
(cc @Ash_Crow )

youtube.com/watch?v=7Sphi0t4i7…

🎶 Après sept années de guerre, sept années de bâtiment (bis)
Je reviens de Grande Terre, je reviens à Lorient
Je reviens de Grande Terre, Guerre, guerre, vente, vent

🎶J'ai passé des nuits entières debout au gaillard d'avant (bis)
Sous bon vent, sous vent contraire, sous la brise, sous les brisants
Sous bon vent, sous vent contraire, guerre, guerre, vente, vent

🎶Voyez mon sac de misère lourd de coups, vide d'argent (bis)
Allez dire au capitaine j'ai obéi trop souvent
Allez dire au capitaine, guerre, guerre, vente, vent

🎶Bonjour ma mie qui m'est chère revoilà ton cher aimant (bis)
Je suis las de trop de guerres sans voir grandir mes enfants
Je suis las de trop de guerres, guerre, guerre, vente, vent

🎶J'ai reçu tes mille lettres par le rossignol chantant (bis)
Je t'écrivais moins peut-être, je t'envoyais des rubans
Je t'écrivais moins peut-être, guerre, guerre, vente, vent

🎶Mes amis plus que naguère vous me verrez bien souvent (bis)
Après tant d'années de guerre, j'aurai tant et tant de temps
Après tant d'années de guerre, guerre, guerre, vente, vent

🎶De Lorient à Grande Terre, vent arrière, vent avant (bis)
Les fleurs d'hiver étaient belles, elles annonçaient le printemps
Les fleurs d'hiver étaient belles, guerre, guerre, vente, vent

Il existe un film soviétique sorti en 1983 qui s'appelle « Mary Poppins, au revoir! », basé sur les livres de Pamela Travers.
Il finit par une scène où Mary Poppins avec sa magie retourne aux adultes leur enfance pour un bout de tmemps. Et là, à ce moment, il y a cette chanson sublime, si touchante et si profonde à la fois. Je ne suis pas trop fan de l'URSS, pour dire poliment, j'y suis né et je sais bien ce que c'était, mais ils savaient parfois faire des films pour enfants… de tous les âges.
J'ai trouvé une traduction, elle n'est pas à moi, mais on peut bien chanter dessus !

«La Terre tourne comme le carrousel,
Avec les vents qui soufflent au-dessus d'elle,
Les vents des pertes, des rancoeurs, du mal -
Incalculables.

Incalculables, ils viennent de tout part,
Ils brisent les portes en détruisant l'espoir,
La peur s'installe dans nos coeurs sans joie,
Les vents tournoient, les vents tournoient...

Nuit et jour, depuis des siècles, notre Terre
Tourne en avançant.
Nuit et jour, depuis des ans, des ères entières
Tournent en rond les vents.

Mais il existe le vent du changement,
Il arrivera, chassant les autres vents.
Le jour viendra où il dispersera
Les vents de haine, les vents d'effroi.

Nuit et jour, depuis des siècles, notre Terre
Tourne en avançant.
Nuit et jour, depuis des ans, des ères entières
Tournent en rond les vents.

Très bientôt, demain, le vent changera;
À la place de ceux d'avant,
Il viendra bientôt, gentil et bienveillant,
Le vent du changement. »
#Mastobada
youtube.com/watch?v=5gxs2hh68I…

July Mutual Aid. Goes towards bills, medical, personal care, and August rent. If you want to just support a disabled Native artist share or donate. Also have my etsy where I sell my art.
PayPal.me/kiagbear
Cashapp $kiagbear
Venmo kiagbear
ko-fi.com/mahtheyzhawey/goal?g…
My etsy where I sell my art
etsy.com/shop/MahtheyzhaweyArt…

My link🌲 where I have wishlists for medical stuff and other things.
linktr.ee/mahtheyzhawey

#MutualAid #DisabledArtist #NativeArtist #HelpFolksLive2025 #ChronicIllness

For our friends in the #USA from the #FCC: Updated Date for Comments Due: August 4, 2025
Updated Date for Reply Comments Due: September 17, 2025

On July 8, 2025, the FCC released an Order granting an extension of time for comments on the Further Notice of Proposed Rulemaking (FNPRM) proposing improvements to ensure the resiliency, reliability, interoperability, and accessibility of Next Generation 911 (NG911) networks. NG911 will provide improved support for the full range of 911 voice, text, data, and video communications, which will enable improved 911 access for individuals with disabilities. The original comment dates were July 21, 2025, and August 18, 2025.

With respect to accessibility of NG911 networks, the FNPRM seeks comment on:
• Ensuring that NG911 systems support interoperability for non-voice 911 services, with specific emphasis on text, video, and multimedia capabilities that support 911 access for people with disabilities.
• New interoperable text messaging protocols, such as Rich Communications Service (RCS), for text-to-911 calls.
• The accessibility of sign-language communications in NG911 environments, including through:
o Relay services, including video relay service (VRS);
o Three-way video relay services with the 911 caller, a sign language interpreter, and a 911 call handler; and
o Direct video calling (DVC) between a sign language user calling 911 and a 911 call center handler who is both fluent in sign language and trained in handling emergency calls.
• Expanding the capabilities of current Internet Protocol-based relay services to support video 911 calls.

Interested parties may file comments by accessing the FCC’s Electronic Comment Filing System at fcc.gov/ecfs/filings/. All filings must reference PS Docket Nos. 21-479 and 13-75. People with disabilities who need assistance to file comments online may request assistance by email to FCC504@fcc.gov.

Link to the NG911 Networks FNPRM:
fcc.gov/document/fcc-proposes-…

Link to the Erratum with revised Appendix A of proposed rules:
docs.fcc.gov/public/attachment…

Link to the Order Granting Extension of Time:
fcc.gov/document/pshsb-extends…

Additional information on 911 services is available at: fcc.gov/general/9-1-1-and-e9-1…. For further information on this proceeding, contact Chris Fedeli at Christopher.Fedeli@fcc.gov or 202-418-1514, or Rachel Wehr at Rachel.Weir@fcc.gov or (202) 418-1138, of the Public Safety and Homeland Security Bureau, Policy and Licensing Division. Individuals who use videophones and are fluent in American Sign Language (ASL) may call the FCC’s ASL Consumer Support Line at (844) 432-2275 (videophone).

#USA #fcc

looks like its #PortfolioDay again! i’m Loren, a nature photographer and artist in northern illinois looking for work. i love taking pictures of #birds, #bugs, #mushrooms, #flowers and any other interesting organisms i come across.

i have prints available at loren.pics/store/

or you can support my work at ko-fi.com/loren_nature

Another Valérie Plante failure...

Montréal tenants only have unofficial rent registry at their disposal, after Valérie Plante backpedalled on her promise to institute a mandatory rent registry for the city. cbc.ca/news/canada/montreal/qu…

#notaleader #totaldisappointment #polMTL #MTLpoli #projetMTL #FAIL #BS

FTC has a reporting form. It actually can generate results when the party on the other end is actually honest about their identity. Arguably just wrist-slaps, but when Dave’s Home Repair (i.e. random small cold-caller) gets a phone call and warning letter from the FTC, they stop.

Of course, when it’s someone clearly running a scam, it’s a waste of time. ohai.social/@resuna/1148178162…

It's alive!

@Zloběna @Jan @Jan Dytrych🇨🇿🇺🇦 @Elena Rossini on GoToSocial ⁂


Úvod do Fediverse: Moderní podoby sociální sítě


Toto video je barvitým úvodem do sociální sítě Fediverse, natočené režisérkou a propagátorkou Fediverse Elenou Rossini. Objevte nový svět sociálních médií, kde je respektováno Vaše soukromí, klíčoví jsou uživatelé a velké technologické společnosti nemají žádný vliv.

Autor videa: Elena Rossini a tým
Produkce: Jan
Dabing: Zloběna
Časování audia: Schmaker
Skript: Jann


#AndroidAppRain at apt.izzysoft.de/fdroid today with 9 updated and 1 added apps:

* EnigmaDroid: control your Enigma2-based satellite or cable set-top box directly from your Android device 🛡️

2 #Magisk modules have been updated at apt.izzysoft.de/magisk

Enjoy your #free #Android #apps with the #IzzyOnDroid repo :awesome:

I discovered "CamelCamelCamel" by reading Popular Info's article "Amazon Prime Day is a Scam." I went to take a look. This was apparently a "popular product".

It is a $50 gift card whose price is, unsurprisingly, exactly $50. But apparently the "Average price" is $66.66? I am not surprised that this is labeled its "best price." I'm fairly certain this has been its ONLY price.

I have immediately become very skeptical of this web site.

The End Of The Hackintosh Is Upon Us
"...Getting a Hackintosh running generally involved pulling down special patches crafted by a dedicated community of hackers. Soon after Apple started building x86 machines, hackers rushed to circumvent security features in what was then called Mac OS X, allowing it to run on non-Apple approved machines. "
hackaday.com/2025/07/08/the-en…

I can't believe programmers out there let compilers write assembly for them and don't even check it, just trust that it's correct because it seems to work.

I just can't even
RT: hachyderm.io/users/thejpster/s…

in reply to feld

The author of that article had the full working source code of the plugin that he liked. The plugin totally worked correctly, but it had some kind of XSS vulnerability. It seems to me that the best approach is to fix that plugin. Want to use AI to do it? Fine. But fork it and fix it. It seems ridiculous to write an entire replacement plugin from scratch in an effort to avoid one bug in an otherwise working codebase. That bug was almost certainly localized to a handful of lines of code.

The author writes "I ... found that the plugin had been listed as having cross-site scripting vulnerabilities... It's not the sort of thing you take a chance on."

So what did he do to make sure his AI generated code didn't have XSS vulnerabilities itself? He doesn't say. It sounds like taking a big chance to me. The driving motivation for this entire exercise—security—is a concept he only mentions in the intro. He doesn't make claims about security. He doesn't appear to have had ChatGPT write tests for security. He never mentions XSS again.

How does he know that his plugin doesn't have an XSS vulnerability just like the plugin he was replacing? I don't think he has any evidence one way or another. The LLM spit out 16 pages of security vulnerabilities supposedly present in the old plugin. Did the author validate any of them? He doesn't say. Did the author ask ChatGPT to inspect his code the same way, to make sure it didn't have similar vulnerabilities? He doesn't say he did.

It sounds absolutely foolhardy to me. I guess he will find out the hard way whether his vibe coded plugin has XSS (or worse).

If the code is so amazing, why is the repo not on his github? He neither names the plugin that he abandoned, nor does he share the plugin that he proudly authored.

in reply to Paco Ho Ho Hope 🎄

I just read the article and I think everything he did was completely fine. Not only did he identify that the plugin had more features than he needed, but it had a lot more security vulnerabilities than just XSS. So he made a plugin with the assistance of ChatGPT that only did these 3 things:

1. has a honeypot hidden form field to trick bots and stop them from registering
2. looks up the MX record of the email domain being used to make sure it's legit
3. checks an API for the reputation of the username / IP address

I see no possible way this is going to have an XSS as it's all done server-side.

And then he had this simple plugin written with these guidelines:

Guard every file with defined( 'ABSPATH' ) || exit;.
Escape all admin-facing text with esc_html().
Wrap the clear-log action in check_admin_referer( 'rsg_clear_log' ).
Use wp_remote_get() with [ 'timeout' => 5 ]; on WP_Error treat as not spam (fail-open).
Never call eval(), unserialize(), or store base64 blobs (mitigates CVEs noted in original plugin).
Adhere to WordPress coding standards (spacing, naming, i18n).

So what is the risk here? Why are people losing their mind over this? The risk here is basically zero and he very clearly spelled that out, but everyone shuts off their brains when they hear that he didn't write every line of code himself.

If he did write it himself, is that good enough? Or now does he need to also be a credentialed security expert before it's OK for him to write the plugin?

This entry was edited (5 months ago)
in reply to feld

@eriner Yeah, it's gonna be something like that. Obviously there are some big cities in the orange area, but there are definitely a lot missing. You're telling me the only cities in all of California are on that strip to the south east? I'm guessing there's stuff further north, those cities are just a lot poorer. Definitely some more notable urban areas are left out, just don't know exactly which without looking it up.
in reply to Matt Hamilton

@eriner @besserwisser if I have correctly identified all the areas on my original map, it's these:

New York–Newark–Jersey City – 20,140,470
Los Angeles–Long Beach–Anaheim – 13,200,998
Chicago–Naperville–Elgin – 9,618,502
San Francisco–Oakland–Berkeley – 4,749,008
Washington–Arlington–Alexandria – approx. 6.3 million
Dallas–Fort Worth–Arlington – 7,637,387
Houston–The Woodlands–Sugar Land – approx. 7.1 million
Boston–Cambridge–Newton – approx. 4.9 million
Seattle–Tacoma–Bellevue – approx. 4.0 million
Philadelphia–Camden–Wilmington – approx. 6.1 million
Miami–Fort Lauderdale – approx. 6.1 million
Phoenix–Mesa–Scottsdale – 4,845,832
Minneapolis–Saint Paul – 3,690,261
Detroit–Warren–Dearborn – approx. 4.3 million
San Diego–Chula Vista–Carlsbad – approx. 3.3 million
Denver–Aurora–Lakewood – approx. 2.9 million
Baltimore–Columbia–Towson – approx. 2.8 million
Charlotte–Concord–Gastonia – approx. 2.6 million
Portland–Vancouver–Hillsboro (OR–WA) – approx. 2.5 million
St. Louis – approx. 2.8 million
Riverside–San Bernardino–Ontario – approx. 4.7 million
San Antonio–New Braunfels – approx. 2.6 million
Tampa–St. Petersburg–Clearwater – approx. 3.1 million

which only adds up to 120 million, which is only 35% of the US population

Your regular reminder to not use/visit the nazi bar that is Substack:

Substack faces user revolt over anti-censorship stance on neo-Nazis

theguardian.com/media/2024/jan…

(from Jan 2024)

This entry was edited (5 months ago)