I will be starting the installation of Mastodon v4.1.1 for all Masto.host servers.

Each instance will go down for about 30 seconds during the upgrade installation.

v4.1.1 introduces some fixes and improvements. You can read the full log here github.com/mastodon/mastodon/r…

One of the improvements has a compatibility issue with OpenStack Swift and I will be doing a temporary work around, as I describe here: github.com/mastodon/mastodon/i…

Any questions, please let me know.

I was joking with @johncarlosbaez recently about listening to intuitionistic music (instead of classical). Turns out it's real! "In the ... 1970s, a young composer working at the electronic music studio in Stockholm, named at the time Christer Hennix, found that Brouwer’s intuitionist mathematics had a practical yet rigorous philosophical application: for electronic music and the search for elevated experience". frieze.com/article/room-sound-… #CatherineChristerHennix #Brouwer #Intuitionism
This entry was edited (2 years ago)

Been dabbling a bit with the amazing #whisper port to C++ coded by @ggerganov. Very good results in both Dutch and English, amazing to see how fast progress has been made on speech to text in the last few years. For those who have got it running and are looking for some tooling: i wrote some Python terminal wrappers for easy use (including converting media using ffmpeg) and converting the SRT files to other formats: github.com/hay/audio2text/

Ihr nutzt ein solches Gerät?:
- Samsung Android der Serie S22, M33, M13, M12, A71, A53, A33, A21, A13, A12 und A04,
- Vivo-Smartphones der Reihen S16, S15, S6, X70, X60 und X30,
- Googles Pixel 6 und 7

Dann deaktiviert vorsichtshalber mal WLAN-Telefonie und VoLTE in den Einstellungen. Patches sind erst teilweise verfügbar.

Wir habe es hier mit einer "Internet-to-Baseband Remote Code Execution" (RCE) zu tun. Ausführung beliebigen Codes ohne dass der Nutzer das merkt. 👇

heise.de/news/Nicht-nur-Samsun…

Coming up live at 01:00 UTC (9:00 PM Eastern, 6:00 Pacific in the Americas) on The Global Voice Internet Radio: an hour of Smooth Jazz, Chillout, and Easy Listening music on Smooth and Easy with Kelly Sapergia. More information about the show is at ksapergia.net/smooth. Tune in at theglobalvoice.info and click on the Listen Live link, or put the following URL in your favorite media player: theglobalvoice.info:8000/broad… #TGVRadio #audio

Google's handling of the Samsung Exynos modem RCE vulnerability is frankly insane. Summary:

- Internet to baseband modem remote code execution, all that's required is knowing the target's phone number
- Fix has been published in March update, but this is not available on all affected phones
- Workaround is to disable VoLTE and Wifi Calling, but the ability to disable the former has itself been disabled

In other words, the only current defense is airplane mode.

9to5google.com/2023/03/16/goog…

L'outil #Mobilizon de l'association lyonnaise #Framasoft est une bonne alternative éthique aux événements #Facebook. Je suggère à celles et ceux qui voudraient organiser des mouvements de grève, des blocages et toutes sortes de manifestations contre la politique de notre gouvernement de s'en emparer sans attendre !

mobilizon.fr/

#logicielslibres #injustices
#reformedesretraites #liberté #egalite

#AndroidAppRain at apt.izzysoft.de/fdroid today with 14 updated and 2 new apps:

* Settings Database Provider: allow other apps to edit all parameters in android settings.db database
* Thumb-Key: A privacy-conscious keyboard made for your thumbs

Enjoy your #free #Android #apps with #FDroid and the #IzzySoftRepo :awesome:

We've just reached 400⭐ on Github and Castopod v1.2 is out 🚀

You can now host your podcast files on any S3 compatible storage!

+ download counts of episodes for better insight
+ health check route for monitoring

And bug fixes!

Grab your Castopod on castopod.org/

Here is how the Purism team is improving the Chats app. We want it to be the everyday “1 to 1” and “small groups” messaging app for both SMS/MMS and the more private end to end encrypted IP conversations🎉

puri.sm/posts/toward-matrix-su…

Jdu s kůží na trh. Na nové doméně jsem spáchala nový web.

rodokmen.info

Say what you want about Firefox, but this is the kind of good surprise after an update that comfort me in my opinion that Firefox is the greatest mainstream browser.

The translations quality is understandably not on par with Deepl or Google Translate, but it doesn't leak what I'm reading to a third party.

And most importantly: it also works for people who are not experts with computers.

One more reason to recommend it to friends & family.

Stick a fork in it, it's done. My network is finally rebuilt to a single physical server hosting a pile of VMs. After 2 days File History finally did its thing. I'll still almost certainly switch away, but at least I'm backing up to a remote ZFS volume in the meantime. Next up, probably in a week or two, is automating off-site backups to rsync.net using zfs send.

Proxmox's web UI is a pile of inaccessible, but I'm super pleased with the command line so far. Yesterday I spun up a small virtual server for Audiobookshelf, and had the whole thing up and running in my network and integrated with backups in about 10 minutes. Next I need a couple small Windows VMs for CI which, well, at least I'll only have to set those up once and clone them, so there's that silver lining.

in reply to Dickson Tan

It probably isn't accessible, but I didn't try too hard to make it work. My sighted partner helped. It isn't too hard if you have someone able to read screens and process the weird ways console interfaces work. I think by default it assumes it should use all of whatever drive you point it at. For me it was just a matter of typing in my network config, enabling ZFS, checking the advanced options briefly (I didn't need to change any), setting a password, then booting up. The rest is accessible via SSH, and the admin guide has sections on the various command line tools with example usage: pve.proxmox.com/pve-docs/pve-a… Server was just my old desktop with 32 GB of RAM and 2 TB of built-in storage, plus an 8 TB spinning disk added as a second ZFS pool for Samba/backups.

Two things going on that may be related:

1) Mastodon new user count is up to about 1000 per hour for the last day. This is way up from the recent low hundreds.

2) Reddit r/Twitter is full of complaints that Twitter feeds are now not showing followed accounts, replaced by right wing politics and even porn.

Getting tweets... from people that i dont follow and dont know at all >>> reddit.com/r/Twitter/comments/…

Did twitter change its algorithm completely? >>> reddit.com/r/Twitter/comments/…

#twittermigration

!!! UPDATE YOUR PHONE NOW !!!

RCE exploit

Samsung Galaxy phones including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 series
Vivo phones including those in the S16, S15, S6, X70, X60, and X30 series
Google Pixel 6 and 6 Pro, Pixel 6a, Pixel 7 and 7 Pro
Any wearables that use the Exynos W920 chipset
Any vehicles that use the Exynos Auto T5123 chipset

Project Zero reported 18 vulnerabilities in Exynos modems in late 2022 and early 2023. Four of the vulnerabilities, including CVE-2023-24033, involve internet-to-baseband remote code execution
Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number. With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.

Project Zero is making a “policy exception to delay disclosure for the four vulnerabilities that allow for internet-to-baseband remote code execution.” This is “due to a very rare combination of level of access these vulnerabilities provide and the speed with which we believe a reliable operational exploit could be crafted.”

9to5google.com/2023/03/16/goog…

reshared this

Last weekend, we met #LibreOffice users and free software fans at the Chemnitzer Linux-Tage event @clt_news in Germany! And we're just getting started with 2023 – we'll be at many more events: blog.documentfoundation.org/bl…

LibreOffice reshared this.

"Peter Thiel started the bank run. All of his companies got their money out. Most of their competitors did not get their money out. Many of those competitors might not have survived the week of the FDIC hadn’t stepped in. ...

"I’m not saying he nefariously intended to bring the bank down in order to gain an advantage over his competitors. ... But the practical outcome would have been a massive, literal bank error in Peter Thiel’s favor."

davekarpf.substack.com/p/three…

Hey all, if you have a Google Pixel 6/7 or a Samsung phone: Disable VoLTE and Wi-Fi calling until this issue is patched: 9to5google.com/2023/03/16/goog…

tl;dr: Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number. With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.

Google's Project Zero usually makes vulnerability reports public after 90 days. This is an exception because it goes directly from internet to baseband-level (tl;dr: the second OS inside your phone that powers the LTE/5G modem) remote code execution. This is morally equivalent to getting code running on your WiFi card.

Here is a list of the most likely affected devices:

  • Samsung Galaxy phones including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 series
  • Vivo phones including those in the S16, S15, S6, X70, X60, and X30 series
  • Google Pixel 6 and 6 Pro, Pixel 6a, Pixel 7 and 7 Pro
  • Any wearables that use the Exynos W920 chipset
  • Any vehicles that use the Exynos Auto T5123 chipset

Helpfully, the baseband is a binary blob of uninspectable firmware that users can't inspect or prove hasn't been tampered with.

If you're an #iOS #developer, love #opensource, and have a certain passion for email, you should definitely keep an eye on the #Thunderbird careers page!

thunderbird.net/careers/

Within the next few months, we'll be hiring someone to help us lay the groundwork for Thunderbird on iOS. When that career opportunity goes live, we will announce it here.

(So yes, we can 100% confirm we plan to develop an iOS version)

This entry was edited (2 years ago)

The European Mathematical Society is delighted to announce the launch of its Young Academy (EMYA)! The first cohort of 30 early career mathematicians, spanning 18 countries and a broad spectrum of mathematical fields, had its inaugural meeting on 6th March.

euromathsoc.org/news/european-…

Who's checking out #MozFest next week? We'll be in virtual attendance, and this is one of the talks we're excited about (for obvious reasons):

▶️ Dialogues & Debates: Making the Fediverse | Mozilla is joining the Fediverse in 2023 to co-create its future. What are its greatest opportunities and limitations? How can we scale methodology and not solutions? What is the public discourse square of the future? Who is building it?

schedule.mozillafestival.org/s…

#Mozilla #Fediverse #Mastodon

modulux reshared this.

Benchmark: With two speakers (2 audio tracks), Mufidiwiwhi is faster than Whisper, to perform both transcription and diarisation!
👉️ blog.castopod.org/transcribe-y…