curl disclosed on HackerOne: Heap Out-of-Bounds Read in lib/http2.c...
Summary A heap-based out-of-bounds read vulnerability exists in libcurl's HTTP/2 implementation. The on_header callback in lib/http2.c incorrectly treats header names and values provided by nghttp2...HackerOne
That was a fun read, sorry you and all the others managing bug bounties have to deal with this now.
It was pretty fun 6 years ago when I ran a program for my company. I met lots of great pentesters that taught me a lot along the way.
Been seeing a survey going around fedi this morning about Discord's use of AI, but it's hosted on some other unrelated website, there's no mention of it on discord's blog and the first time I've heard of it is from mastodon, so, like, anybody got a source for this, or is this just someone playing games?
EDIT: The domain has been used by Discord in the past (see thread), which points to this survey being legit!
(I do still wonder why I heard it from Fedi rather than from Discord though)
The discord AI survey is down already.
Even asking people if they want AI is bad for business.
Khronos reshared this.
"I just came up with a weird constraint"
"You're hired"
Is it just me or does it feel super corrupt that all of these charities are paying their "leadership" seven (7) figure salaries?
The top one is making over $5 million USD / year.
charitywatch.org/nonprofit-com…
Nonprofit Compensation Packages of $1 Million or More
Which charities compensate their executives most highly. CharityWatch's salary information is calculated using the IRS Form 990.www.charitywatch.org
Migration from iCloud Photos to Immich in progress 
Things I like:
* Easy to get going and seems much faster than my experience with Nextcloud
* Seems to support both HEIC and Live Photos and even displays them nicely in the interface
* Seems able to upload the photos directly from iCloud without having to download them all (a real win when you have more than 256GB of iCloud Photos and a 256GB phone
* Machine learning & recognition seem decent
Waiting to see:
* I do seem to need to keep the app open to upload reliably — but I am uploading 32k items so I figure this is probably a one-time thing
* It seems to stop uploading after every few hundred imports and grind all 6 cores I gave it at 100% for a few min — I assume this is the ML running over recent uploads though and will also be one-time (plus the WebUI stays working during this)
(cc @neil )
#Playdate accounts to follow:
("Playdate" is a quirky handheld console with a physical crank on it: en.wikipedia.org/wiki/Playdate… )
➡️ @playdate - Official Playdate account
➡️ @UncrankdPD - Fanzine for the Playdate
➡️ @Xanialasagna - Indie dev & designer working on Playdate games
➡️ @dave - Playdate staff member & typewriter fan
➡️ @pawprints - Indie game dev making Playdate & web games
Nachdem ich Matcha Latte allgemein sehr geil finde, und im Teeladen letztens Matcha-Tee herumlag … dachte ich mir, den probierst du mal.
Stellt sich heraus: Matcha-Tee ist so gar nicht meines.
Aber hey, es ist Tee, nach guter britischer Art könnte man da noch Milch dazukippen, vielleicht wird's dann mehr Latte.
Stellt sich raus: Nope, auch das hilft nicht, ist immer noch nicht meines.
Jedenfalls … braucht jemand Matcha-Tee?
@Bubu Naja, streng genommen Match Genmaicha^^
Und zumindest der Duft davon (sowohl in trockener Form als auch aufgegossen) ist schon sehr angenehm. Aber der Tee selbst … ist nichts für mich, leider.
Ah, dann weiß ich was du meinst. :)
(Also ich mag den, aber hab auch zumindest Genmaicha, ohne Matcha, noch hier.)
Fellow *non*-Americans—are you using any or all of the U.S. support for Israeli wars and the Israeli genocide on Palestinians, the U.S. attack on Venezuela, the annexation threats against Greenland, or other U.S. policy decisions to move away from U.S. products and services?
(Responses are anonymous. Please reshare for reach!)
#usa #uspolitics #bigtech
- yes (58%, 32 votes)
- long in progress (20%, 11 votes)
- thinking about it (14%, 8 votes)
- no (7%, 4 votes)
Here's more music nobody asked for:). youtu.be/zlK89S7z0WU
ILLENIUM - Crashing (Stripped /Official Audio) ft. Bahari
Crashing Remixes – out now! https://Illenium.lnk.to/CrashingRmxCrashing ft. Bahari: https://Illenium.lnk.to/CrashingYDFollow ILLENIUM:https://soundcloud.com/...YouTube
Sensitive content
Who killed the world?
Servers described as "Glitch Mastodon" or "Hometown Mastodon" work just like Mastodon but have additional features such as larger post sizes, rich text formatting or local-only posts.
Mastodon's server software is free and open source, so programmers can tweak it to make their own versions. (Untweaked Mastodon is often called "Vanilla Mastodon".)
You can find good Glitch and Hometown servers to join or move to at:
➡️ fedi.garden/tag/glitch-mastodo…
➡️ fedi.garden/tag/hometown-masto…
Glitch Mastodon | Fedi.Garden – An easy way to join Mastodon and the Fediverse
Highlighting nice servers on Mastodon and the Fediversefedi.garden
This master's thesis about fantasy genres in Chinese internet literature might be of interest here: is.muni.cz/th/s33qt/Fantasy_Ge…
Я все понимаю в том, как волшебно китайцы переодят названия товаров, но
Фигурка Yakuza протагонист Кирю Кадзума , Горо Маджима/ Like A Dragon Goro Majima action figure strong man doll (17см) Подарки для болельщиков
Заставило поржать снова. Для болельщиков.
БОЛЕЛЬЩИКОВ.
Although there won't be any dedicated devroom for #accessibility electronics at #fosdem , nothing prevents us from hooking up in the cafeteria or something. Anyone interested in adaptive technology for the disabled, it will be great to meet you.
Important would be that there is an App for at least iPhone/iPad and that things like smart playlists, multiuser etc ist supported so everybody could use the same big catalog but with its own playlists, favourits etc.
If have already found three projects which could be okay: Navidrome, Funkwhale and Koel.
Any thoughts about this? Which route would you go?
#homelab #selfhosting #spotify #navidrome #funkwhale #koel @homelab @homelab_de
GitHub - Viperinius/jellyfin-plugin-spotify-import: Import playlists from Spotify in Jellyfin
Import playlists from Spotify in Jellyfin. Contribute to Viperinius/jellyfin-plugin-spotify-import development by creating an account on GitHub.GitHub
Today's threads (a thread)
Inside: Predistribution vs redistribution (Big Tech edition); and more!
Archived at: pluralistic.net/2026/01/10/mar…
1/
Andre Louis reshared this.
"One night in Bangkok but it's a 16th century chanson"
youtube.com/watch?v=i3jHv0GZB9…
Note, performed by one single man, Jonas Wolf, he did all the voices.
#Music #Baroque #YouTube
One Night in Bangkok but it's a 16th century chanson
If Clément Janequin (ca. 1485 - 1558) was the songwriter for Murray Head...One Night in Bangkok, words and melody in their original form by Tim Rice, Björn U...YouTube
Khronos reshared this.
I got this mini PC a couple months ago for a home server. It comes with Windows pre-installed and has sufficient USB ports for the basics. I imagine it can handle what you need without issue.
RE: mastodon.social/@andrewstroehl…
When Musk fired the entire #accessibility team.
Andrew Stroehlein (@andrewstroehlein@mastodon.social)
When did you stop posting on X? Person A: When its owner made nazi salutes. Person B: When it became a production and distribution channel for images of child sexual abuse. Government: We're still posting there.Andrew Stroehlein (Mastodon)
That is, an old speech synthesizer made years ago and long since abandoned by its maker, which blind people tightly hold on to for one reason or another.
Two examples I'm familiar with are Neurosoft's SynTalk 1.6 in Poland, and IBM's ProTalker in Japan, and I'm curious if this happens in other places as well.
reshared this
saomaicenter.org/en/smsoft/vnv…
Sao Mai VNVoice | Sao Mai Center for the Blind (SMCB)
Sao Mai VNVoice is the first usable text-to-speech engine with screen reading software on Windows for Vietnamese language.Sao Mai Center for the Blind (SMCB)
Mohamed Al-Hajamy 💾 reshared this.
Mohamed Al-Hajamy 💾 reshared this.
Sensitive content
This is a survey all #Discord users need to fill out {edit - seems they closed it within a day?}. Discord wants to know if we want AI to run the app. It'd be using data from pictures, conversations, voice notes, live streams, art, 'learning' from us in the app if they don't get strong enough pushback.
Let them know how you feel before they ruin that app for everyone as well.
It's an [assumed - see replies] official survey and it doesn't even take 5 mins. Please boost and share in your servers too.
discord.sjc1.qualtrics.com/jfe…
#genAI #AIslop #AI #gaming #streaming #streamer #noToAI #gamer #gamers #womenWhoGame #resist
reshared this


Ethin Probst
in reply to Bri🥰 • • •Kyle Smith
in reply to Bri🥰 • • •We're sorry, but something went wrong on our end.
Bri🥰
in reply to Kyle Smith • • •