one of the worst ever "comprehensive security audits" ...
curl disclosed on HackerOne: Multiple Unsafe strcpy() Function...
## Summary: During a comprehensive security audit of the cURL codebase, multiple instances of unsafe strcpy() function usage were identified in critical code paths. These implementations violate...HackerOne
daniel:// stenberg:// reshared this.
newsie.social/@ProPublica/1151…
ProPublica (@ProPublica@newsie.social)
Citing concerns about DEI, the U.S. Department of Education has halted funding for programs that support students with combined hearing and vision loss in eight states. “How low can you go?” one advocate asked.Newsie
reshared this
China is ditching the dollar, fast
Officials believe that the yuan has finally come of ageThe Economist
Action movie 'Nobody 2' was shot in Canada, but it's really the Wisconsin Dells
The setting for the new action movie "Nobody 2" was inspired by star Bob Odenkirk's childhood trips to the Wisconsin Dells., Journal Sentinel (Journal Sentinel)
Montrealer plans to sue major grocers over false ‘made in Canada’ labels
ctvnews.ca/montreal/article/mo…
🍿
Montrealer plans to sue major grocers over false ‘made in Canada’ labels
One Montrealer is taking on major grocers after buying products thinking they were made in Canada when they weren't.Laurence Brisson Dubreuil (CTVNews)
At ProPublica, more than 80,000 individual members fuel our work. Not corporations, the government or advertisers.
Every donation, big or small, helps hold the powerful accountable.
Together, we’re stronger. Join ProPublica during our Fall Member Drive: propub.li/42iIc9c
Fake citations inside Education Accord don't impact its credibility, minister says
cbc.ca/news/canada/newfoundlan…
Riiiight.
Our product lineup is ready for Tahoe, but Tahoe may not be ready for you.
In 26.0, two distinct OS bugs can cause lost audio. You may wish to delaying upgrading your Mac.
See our post for more: weblog.rogueamoeba.com/2025/09…
Rogue Amoeba’s Apps Are Ready for MacOS 26 (Tahoe)
Tahoe may not be quite ready for you though.weblog.rogueamoeba.com
AudioRelay: Stream audio between your devices
Stream the audio of your PC or laptop to your phone. Use your phone as a microphone for your PCAudioRelay
My week: lists.haxx.se/pipermail/daniel…
award, 8.16.0, all headers, major incident, keynote, EuroBSDCon
I was #awarded Developer of the year yesterday (in Sweden).
daniel.haxx.se/blog/2025/09/13…
Developer of the year
Developers Day is a recent annual Swedish gala organized by the Stockholm-based company Developers Bay. This is its third year running.daniel.haxx.se
daniel:// stenberg:// reshared this.
ChatGPT added MCP support on Wednesday.
ChatGPT leaked private Gmail data to attackers by Friday. 🤦♂️
Because #promptinjection is not a problem these "PhD level" AI assistants have solved.
Look at that calendar invite. That text is all it took for taking over someone's #ChatGPT connected data. Allowing the attacker to use the same #MCP enabled tools that are supposed to make AI useful at work.
It really is as stupid as @davidgerard keeps telling in Pivot to AI.
Gosh, why doesn't he just shut up and take care of his failing businesses? :)
RIP pthread_cancel() in curl. It was an interesting adventure.
#curl
eissing.org/icing/posts/rip_pt…
RIP pthread_cancel
I posted about adding pthread_cancel use in curl about three weeks ago, we released this in curl 8.16.0 and it blew up right in our faces. Now, with #18540 we are ripping it out again.icing's blog
I think it's reasonable to declare that pthread_cancel() is effectively broken for any nontrivial use on contemporary OSes and it is unlikely to be fixed any time soon.
(I suspect it would actually be easier to cajole libc maintainers into adding an async friendly version of GAI() than to make GAI() cancellation safe.)
If you want a cancellable thing from which you can make blocking calls, the only near-universal option is subprocesses. Unfortunately there are reasons why in some ecosystems it is impolite for a library to start a subprocess.
cyberplace.social/@GossiTheDog…
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Kids nowadays get Chromebooks at college, MacBooks for uni, use Android or iOS on their phones and game on PlayStation 5 and Switch. Windows is this legacy thing forced on them by old people in business.Cyberplace
Sensitive content
In world political news that went under the radar over the past few days: the government of #Nepal has been overthrown by youths following a governmental move to block social media, and accusations of corruption.
A new PM was elected over #Discord, and has been accepted by the military. They aim to hold elections within 6 months.
I repeat:
THEY ELECTED A NEW GOVERNMENT
OVER
DISCORD.
And no second ammendment was needed to rise up against against tyranny.
gizmodo.com/nepal-currently-be…
Nepal Currently Being Run Via Discord After Gen Z Uprising
They went from banning social media to being run by it.AJ Dellinger (Gizmodo)
Apple Watch Series 11's Increased 24-Hour Battery Life Has a Catch
Apple's claim that the Apple Watch Series 11 offers 24 hours of battery life has drawn scrutiny as closer examination of Apple's own testing...Hartley Charlton (MacRumors.com)
Masquerade as the BCE Inc. Giga Hub with the WAS-110 or X-ONU-SFPP - PON dot WIKI
Masquerade as the BCE Inc. Giga Hub with the WAS-110 or X-ONU-SFPPpon.wiki
github.com/djGrrr/8311-was-110…
Although I'm not sure if that is what's running on your device. But its the custom firmware I'm running.
GitHub - djGrrr/8311-was-110-firmware-builder
Contribute to djGrrr/8311-was-110-firmware-builder development by creating an account on GitHub.GitHub
As for benefits over PPPoE passthrough, you'll probably notice a bit of a reduction in latency, perhaps 1 MS better. Minor, but a perk.
Certainly the fact that you're in control of everything up to the fiber connector, you can choose when firmware updaes happen, and not Bell. No more modem reboots over night, and even randomly during the day. Oh yeah, and no more incidents of pushing bad configs to a million modems causing them to be down for 8 plus hours, LOL.
I was enjoying the net all through that incident.
Also, may be a good reason to revisit some VLAN snooping to see if IPv6 can be found anywhere.
So you will note that the connector is square, and if you feel along the sides of the square that naturally face your fingers as you grip the connector, you will feel narrow slits, that should feel like they're for finger usage to loosen or unlock the connector. And this is what happens. You squeeze these tabs inward, and the lock is released. You then pull very gently, very slowly, and very straight with your entire hand, and the connector should slide off the SFP+ module, or out of the modem. The modem will likely be a bit trickier in handling, and may require some effort to unplug the connector. Do your best in gaging if you think you're overdoing something, but at the same time, the modem connector may be stubborn. Most of all, always pull or push connectors straight.
Also, never, under any circumstances that you can control, touch or point the end of the fiber connector at your face or any one elses. Touch should be absolutely limited to necessities, or purposefully destroying a connector. To plug the connector back in, ensure it is aligned with the square receptical, and push gently. If aligned, it will slide a short distance, then lock into place with a bump and a slight click.
Hope this helps some.
"Apple is about to drop Accessibility Nutrition labels on the App Store, offering users transparency about which accessibility features apps support."
gerireid.com/blog/how-to-add-a…
#apple #a11y #apps #accessibility #appstore
Add an Accessibility Nutrition Label
I've just completed an app audit for an iOS accessibility nutrition label. Here's what I learned.gerireid.com
@Friendica Support @Michael 🇺🇦
Irgendwie ist bei meinem Server der Wurm drin: diese Seite ist nicht erreichbar friendica.a-zwenkau.de/profile…
Aber die normale Startseite ist erreichbar. friendica.a-zwenkau.de
Woran liegt das denn wieder ?
#serviceToot one of the mirrors at #IzzyOnDroid had a power outage, and is currently in recovery (file system repair) – the USV didn't like to be triggered 3 times in a row 🙈). Good thing there are multiple mirrors, so you shouldn't even notice it – unless you pinned your client to our US mirror…
You can watch the state at our monitor, and thus see when the mirror recovered:
(one of our builders was affected too – but as with the mirrors, we luckily have more than one)
IzzyOnDroid
Welcome to the official IzzyOnDroid Status Page. This page contains an overview of the status of various IzzyOnDroid services and the official mirrors. Imonitor.izzysoft.de
Sylvia reshared this.
Danke dir für den kurzen Einblick! Dann erweitere ich meine Wünsche für einen entspannten und erholsamen, sonnigen Sonntag für Andrew gleich mit. 😉
Wie so vieles im Leben, weiß man gewisse Dinge erst zu schätzen, wenn sie nicht mehr rund laufen.
Toi, toi, toi, dass quasi "im Schlaf" des Rätsels Lösung dich/euch finden wird! ✨
youtu.be/kaLeWfohrL4?si=dRAbzl…
10 důvodů, proč byste se měli VYHNOUT SILNIČNÍMU KOLU
Více informací o kole 👉 https://www.cyklopoint.cz/merida-scultura-endurance-8000-white-black-_d80108.html🛒 TRAIL HUNTER SHOP: https://shop.trailhunter.cz/ ...YouTube
Proton Mail Suspended Journalist Accounts at Request of Cybersecurity Agency
The journalists were reporting on suspected North Korean hackers. Proton only reinstated their accounts after a public outcry.Nikita Mazurov (The Intercept)
reshared this
Mary Trump: #Trump Rhetoric Ignites Violent Spiral in #America: youtube.com/watch?v=C6Zb4OgiSQ…
Chris Hedges: The Martyrdom of #CharlieKirk: youtube.com/watch?v=34_nScNLga…
Chris Hedges: The Martyrdom of Charlie Kirk
Martyrs are used by messianic movements to sanctify violence. To show any mercy or understanding toward the enemy is to betray the martyr and the cause the m...YouTube

))
Gregory
in reply to daniel:// stenberg:// • • •Götz Hoffart
in reply to daniel:// stenberg:// • • •🫂
Related, your examples are fodder for my explanations within friends & family on why “AI” isn’t a good idea to use if you don’t know what you’re doing.
Étienne Parmentier
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Étienne Parmentier • • •Alfonso Martínez de Lizarrondo
in reply to daniel:// stenberg:// • • •hackerone.com/anony_gaku?type=…
HackerOne profile - anony_gaku
HackerOneFrederik Braun �
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Frederik Braun � • • •Frederik Braun �
in reply to daniel:// stenberg:// • • •Kirils Solovjovs
in reply to daniel:// stenberg:// • • •Aljoscha Rittner (beandev)
in reply to daniel:// stenberg:// • • •Graeme 🏴
in reply to daniel:// stenberg:// • • •Richard Levitte
in reply to daniel:// stenberg:// • • •young man yells at the cloud
in reply to daniel:// stenberg:// • • •Tim Ward ⭐🇪🇺🔶 #FBPE
in reply to daniel:// stenberg:// • • •Trouble is, it's like that in the real world.
Customer runs some security tools. Comes up with hundreds of "vulnerabilities". They aren't interested in your proof that the code path they're worried about can never actually occur, all they care about is clean output from their tools. Which they've been sold by a "security consultant" and quite likely don't understand.
Numerfolt
in reply to daniel:// stenberg:// • • •Bygone12
in reply to daniel:// stenberg:// • • •Bredroll
in reply to daniel:// stenberg:// • • •Viss
in reply to daniel:// stenberg:// • • •Billy O'Neal
in reply to daniel:// stenberg:// • • •