#curl 8.18.0 with Daniel Stenberg
curl 8.18.0 with Daniel Stenberg
Daniel talks about the six(!) new security advisories, the changes and the most important bugfixes from the curl 8.18.0 release.YouTube
#curl 8.18.0 with Daniel Stenberg
Daniel talks about the six(!) new security advisories, the changes and the most important bugfixes from the curl 8.18.0 release.YouTube
RE: social.heise.de/@macandi/11585…
Schade, dass Castro nicht Teil des Testfelds war. Den finde ich nämlich mit am übersichtlichsten. Und er bietet nämlich das Springen zwischen Kapiteln.
heise+ | Podcatcher: 10 Podcast-Apps für Apple-Geräte im Test Ob News, True Crime oder Comedy – Podcasts begleiten uns überall. Wir haben uns die wichtigen Clients für iPhone, iPad und Apple Watch angesehen. https://www.heise.Mac & i (Heise Medien on Mastodon)
to je pravda ale vraj sú tie procesy/technológia zdokumentované a ready na presťahovanie, lenže okupácia.. ja nevím. Nie je to logický sled udalostí ale očakávaný. Vyhodia tie továrne do vzduchu?
Čo ja viem to je moja konšpirácia.
edit: osobne neverím že medvedík pu sa o to za svoj život nepokúsi alebo jeho priami nasledovník. Otázka nie je či ale kedy.
One coworker -- who I'll call Xavier -- does everything through LLMs. He's the kind of developer that managers who have never been programmers adore: 3000 lines of code per day.
I just realized that Xavier cannot read code, even code that he submits for review. He "understands" code by running it against test files and seeing whether results are reasonable. He can only say what the code does, not what causes it to behave in a way.
But that has several problems. An obvious first issue is that if a problem doesn't show up in the test file, then it will never be fixed. A less obvious issue is that his code is brittle and it generalizes very poorly.
Because Xavier doesn't read code, he has a very tough time imagining "What might go wrong?" And because he relies on the LLM, he misses very broad solutions, like using well-established libraries that solve dozens of problems at once.
Programmers who dive deep are still very, very useful.
reshared this
De QR code van onze Colruyt Xtra kaart die ik in #catima had werkte niet meer aan de kassa.
En inderdaad, als ik ze vergelijk met de code in de xtra app dan is ze verschillend.
No problemo dacht ik, even opnieuw instellen.
Maar de content die ik scan van de xtra app QR code is dezelfde als ik in catima had, en als ik met een andere tool een QR code genereer met wat ik scan ziet die er ook anders uit, dus het ligt niet aan catima.
enige verschil: origineel 15% error, copy 7%
WTF?
2.41.1 blijkbaar, nu aan het updaten :)
edit: met 2.41.4 gescanned, code wordt nu gedetecteerd als ISO-8859-1 en ziet er anders uit dan vorige keer (in catima), maar nog altijd anders dan de code die ik scande
Maar dat ligt eerder aan iets wat Colruyt doet, weet alleen niet wat en hoe.
Zal binnenkort weten of het werkt, als ik nog eens winkel :)))
#curl 8.18.0 has been released. This release fixes 2 medium and 4 low level vulnerabilities:
- CVE-2025-13034: No QUIC certificate pinning with GnuTLS curl.se/docs/CVE-2025-13034.ht…
- CVE-2025-14017: broken TLS options for threaded LDAPS curl.se/docs/CVE-2025-14017.ht…
- CVE-2025-14524: bearer token leak on cross-protocol redirect curl.se/docs/CVE-2025-14524.ht…
- CVE-2025-14819: OpenSSL partial chain store policy bypass curl.se/docs/CVE-2025-14819.ht…
- CVE-2025-15079: libssh global knownhost override curl.se/docs/CVE-2025-15079.ht…
- CVE-2025-15224: libssh key passphrase bypass without agent set curl.se/docs/CVE-2025-15224.ht…
I discovered the last 2 vulnerabilities.
Download curl 8.18.0 from curl.se/download.html
#vulnerabilityresearch #vulnerability #cybersecurity #infosec
I was quite surprised that I had to explain what I intend to use my mail address for. Hopefully, you can approve it soon.
Nos dice @santoral que hoy está de santo una forma de consumir drogas.
Santoral: Santo principal del día 7 de enero:
- San Raimundo de Peñafort
Otros santos:
- San Alderico
- Beato Ambrosio Fernández
- San Canuto Lavard
- San Ciro
- San Crispino Obispo
- San José Tuân
- San Luciano Mártir
- Beata María Teresa Haze
- Beato Mateo Guimerá
- San Polieuto
- San Tilón
- San Valentín obispo de Retia
- San Valentiniano
#dobréRáno přátelé #fediverse ☀️
Včera první jízda na Zwiftu přes Apple TV. Ať si o Applu myslí kdo chce co chce, ale propojení zařízení mají fakt zvládnuté skvěle.
První zapnutí Apple TV?
Chceš nastavit pomocí iPhonu — prostě ho přiložíš a nic dalšího neřešíš.
Pak už jen nainstalovat Zwift, přihlášení řešené přes iPhone, hesla pohodlně z Bitwardenu, žádné ťukání na dálkovém ovladači.
Apple TV jsem chtěl hlavně kvůli aplikaci Zwift pro chytrý trenažér.
Na Android TV Zwift není. Zrcadlení z Androidu do TV sice jde, ale obraz se seká nebo úplně zamrzne.
Zkoušel jsem i USB-C → HDMI kabel, jenže ten telefon vysaje hned baterku.Fairphone to ještě jakž takž zvládne — dvě hodiny dá.S Pixelem bych byl rád za hodinu.
Výsledek?
Za pět minut od zapnutí jsem seděl na kole. 🚴♂️
#zwift
#curl 8.18.0 has been released
daniel.haxx.se/blog/2026/01/07…
Download curl from curl.se! Release presentation On January 7 2026, at 10:00 CET (09:00 UTC), there is a live-streamed release presentation of curl 8.18.0 done on twitch. The YouTube recording will be made available afterwards.daniel.haxx.se
Periodic reminder to boost the posts you like to keep the Fediverse alive.
WE are the algorithm here 
This is in relation to that warning I received this morning. To make a long story short, it seems that some people have been offended by some of my posts, and rather than just blocking me or unfollowing me and moving on, they reported me. At no time did I personally insult anyone, promote violence or illegal activities, threaten anyone, etc. I respect the administrators for letting me know about this, and said that I wouldn't post such things in the future. They have every right to do what they did, or even to ban me, since it is their instance and I agreed to follow their rules. I must make that very clear.
However, I am seeking a less restrictive environment. I honestly didn't think I needed one, since most of my posts are about animals, science, technology, etc. But if I can't share an opinion, even a strongly-worded one, without receiving a warning just because some people were offended, this is probably not a great match for me. It's worth noting that I constantly see posts (from other instances) full of obscenities, negative opinions about politicians, the rich, corporations and their heads, users of various operating systems, etc.
Anyway, I would prefer to stay on Mastodon because it's fully accessible, and I would like an instance with a large number of characters (this one is 16,000). If it helps, I am not a gamer, programmer, activist, don't follow politics, etc. I certainly don't want to join a place full of hate, but I do want to join one where I am free to be myself. For now, enjoy the completely wholesome posts with no more personal opinions about anything except opera, though I'll probably limit those too, in case I don't like a given singer.
> leave Twitter to get away from the unaccountable content moderation team
> Mastodon wants you to not see posts without content moderators checking first
We did it everyone we finally achieved feature parity with the best microblogging platform, and this time people volunteer to make it worse instead!
RT: mastodon.social/users/staff/st…
We plan to disable the "live feeds" of the local and federated timelines on mastodon.social within in the next couple of weeks. They are already disabled on mastodon.online.Mastodon.social Staff (Mastodon)
Monal 6.4.17 (Build 1072, PR #1541) released.
- Removed christmas special again
- Added Estonian and Telugu translations
- Fixed random black video feed on video calls
- Make it harder for spammers to mention everybody: ignore mentions if more than 5 participants are mentioned per message
- Properly display Visitor role in Channels
- Add "Request Voice" button to contact details of moderated Channels
After my assembly #39c3 talk on the topic, here’s a more in-depth analysis on the #security of data and metadata in #XMPP : blog.mathieui.net/xmpp-and-met…
I’m sure I missed a lot of things, but since the only reference on the topic is the - now defunct - infosec handbook website with the "admin in the middle" article, I guess that could be useful to somebody.
If anyone's looking for a fun illustration project or an opportunity to get into the GNOME artwork style: Crosswords needs some illustrations for the "How to Play" instructions :)
gitlab.gnome.org/jrb/crossword…
Example from Sudoku:
Currently, the hints dialog has no artwork, just the main icon repeated on each page. It would be good to get better artwork for this. Sudoku has some...GitLab
On the topic of bad takes against Flatpak, my personal favorite is "Flatpak is bad because it works badly with my NVIDIA GPU's drivers"
Consider the following: NVIDIA GPU's (proprietary) drivers work badly on Linux
Under no circumstances should volunteers in the FOSS community ever be placed in a position that forces them to bend over large corporations, even if it hurts the user experience. Besides, the ones who are actually hurting users is the corporations by making it hard for everyone.
This is also true with Fedora's hostility towards proprietary drivers. This kind of hostility should be encouraged. As a community, we should collectively shame entities that push proprietary garbage as a dependency on Linux, so long it doesn't harm security.
vt.social/users/trafotin/statu…
@bugaevc
I'll kindly disagree with you here. Considering both AMD and Intel can write drivers which doesn't infringe on any patents and doesn't expose any of their secret sauce (AMD Catalyst and AMDGPU are completely different codebases), NVIDIA is the only one who acts like this and creates a special firmware to cripple their cards so open drivers can't enable the whole GPU.
NVIDIA revised hardware to be able to lock them down further while AMD changed hardware to unlock it.
Peter Vágner reshared this.
Download Eye Yay - Public domain player by Bucket Brigade Software Limited on the App Store. See screenshots, ratings and reviews, user tips, and more games…App Store
reshared this
> “It’s hard to imagine increases beyond 300,000 to 400,000 barrels a day in the next year, just given the degraded state of the infrastructure, especially the upgraders,” Daan Struyven, co-head of global commodities research at Goldman Sachs, said at the Goldman Sachs Energy, CleanTech and Utilities Conference.
DING DING DING
You want the truth about this ask the investors who finance this shit and actually understand the risk. They aren't lying
Current projection is like 8 years to get an operation in New Mexico able to handle 2.5mbpd
Where we gonna store the other 47.5mbpd in the meantime
> U.S. Interior Secretary Doug Burgum said on Tuesday that an increased flow of Venezuelan heavy oil to the U.S. Gulf would be "great news" for job security, future gasoline prices in the U.S. and for Venezuela.
You don't make gasoline from heavy sour crude, why can't we have journalists that do their goddamn jobs and call these people out on their lies
My company is now taxed like an S-Corporation instead of a single member LLC to reduce my tax burden. Basically: I'm passing the tariff burden back to the gov't instead of customers.
I am now required by law to post a Worker's Comp certificate in a conspicuous place.
So, it's hanging on my fridge.
With a budget, colleagues and I would:
⚡️Reduce volunteer cash advances for events
⚡️Improve the #OpenZFS test suite and documentation
⚡️Organize East coast USA and European OpenZFS summits
⚡️Continue to improve #bhyve
⚡️Continue to improve community Audio/Video wisdom and equipment
⚡️Consider cloud service backup/export challenges (I got Google Drive mirroring to work!)
The money is out there but is firewalled.
If you believe in these same goals, please reach out to potential supporters.
In 2025 I introduced colleagues to over half a million USD in employment opportunities. Now I am forced to think about myself.
❤️
This is the document, Trump does not want you to see.
In 1916, under President Woodrow Wilson, the United States signed the purchase of the Virgin Islands from Denmark, in a convention in which the United States recognised Denmark's right to the whole of Greenland.
Danish MP's of The Defence Committee will convene in the Sensitive Compartmented Information Facility at 18:00 to discuss the defence of Greenland.
Full text: govinfo.gov/content/pkg/STATUT…
Jim Fuller
in reply to daniel:// stenberg:// • • •