Ubuntu, the most popular Linux distribution, has pulled its Desktop release 23.10 after its Ukrainian translations were discovered to contain hate speech. According to the Ubuntu project, a malicious contributor is behind anti-Semitic, homophobic, and xenophobic slurs that were injected into the distro via a "third party tool."

bleepingcomputer.com/news/secu…

I just finished putting together a blog post about Byzantine microtonal scales. They don't call it Byzantine for nothing!
danieljohnson.name/blog/byzant…
/cc @cambraca @mcmullin @microtones

Hey @helpers or any helpful #Friendica users. I'm trying to understand the difference between Categories and Hashtags.

From what I'm seeing, categories never leave the server, but hashtags do get federated out. They kind of look the same in the timeline, with hashtags having a lightning bolt, and categories being green with "X's" that allow you to remove them.

So why choose one over the other? Or why combine them?

Thanks!

Mainstream social media and messaging apps (#Facebook, #WhatsApp, #Instagram etc) are a nightmare for our personal data and freedoms.

We have #FreeSoftware replacements for most of these services but maintaining these services has recurring cost and effort.

diasp.in is a community project supported by volunteers. We offer #diaspora, #matrix and #xmpp services.

If we don't find enough volunteers by October 31st, we will be forced to shut it down.

Please volunteer at diasp.in/volunteer

Fun yak shaving stack unwinded: needed to push my cap-std PR from the VM I have on an external drive ← needed to fsck the drive since it was refusing to mount ← needed to package exfat tools in @chimera_linux ← needed to patch some signed overflows out because we use UBSan to catch them by default.

Oh and the whole excursion into gcr-ssh-agent yesterday, also with undefined behavior involved—as it turns out, known issue but patch not landed—was also motivated by having to do that push. Because I needed some GUI agent to be able to use the agent-forwarded FIDO2 ssh key. Kinda have that working with a janky (for now) gcr patch, but there's a simpler way too…

in reply to Val Packett 🧉

So, this is the simplest ssh-askpass for current #GNOME (make sure to have gcr 4 installed):
#!/usr/bin/gjs -m<br>import System from 'system';<br>import GLib from 'gi://GLib';<br>import Gcr from 'gi://Gcr?version=4';<br>const prompt = Gcr.SystemPrompt.open(-1, null);<br>prompt.set_message(ARGV.join(''));<br>const res = prompt.password(null);<br>if (!res) System.exit(-1);<br>print(res);<br>

Save into a file, chmod +x, set SSH_ASKPASS_REQUIRE=force and SSH_ASKPASS=path/to/prompt.js (where you saved it) when running ssh (and ssh-agent itself?), enjoy working GUI prompt that allows unlocking fido2 security keys when using agent-forwarding.
in reply to daniel:// stenberg://

It's not, I just vented my frustration with browsers removing HTTP/1.1. We already mailed about it. It's relevant only if one believes in this quote:

“It is difficult to get a man to understand something, when his salary depends on his not understanding it.”

This is the wrong context for that though, I'm sorry to bring this up here, but unfortunately this is the most important censorship that happened to humanity so far.

This entry was edited (2 years ago)

Anyone happen to know anything about #FreeBSD (legacy) header files and wants to help us out with a #curl build issue?

github.com/curl/curl/pull/1210…

This entry was edited (2 years ago)

If you know someone at Microsoft who would be interested in the grand opportunity for #InteractiveFiction preservation that today's merger has—as a side effect!—granted the company, please get in touch with me, @zarfeblong, or another @IFTF person. (I stepped down from IFTF leadership earlier this year, but I'm still active within it.)

Here is Zarf's plea to Microsoft to do the right thing with its newly (if perhaps accidentally) acquired Infocom IP: blog.zarfhome.com/2023/10/micr…

In this talk by @ktoso he explains why and how they turned a significant C++ codebase into a hybrid Swift/C++ codebase.

In my copious spare time, I want to do this to assorted open source projects:

youtube.com/watch?v=ZQc9-seU-5…

Wow, the Ubuntu 23.10 download has been temporarily removed because someone slipped some hate speech onto some translations.

Some people are just the f**king worst.

omgubuntu.co.uk/2023/10/ubuntu…

Video que restaura la fe en los hombres

#Hombres
Como siempre, los comentarios amagan con total efectividad 🥹

vm.tiktok.com/ZMjQV4V2Q/

This entry was edited (2 years ago)

This week many engineering teams are looking for the immensely popular open source library 'curl' in order to get ahead of the CVE-2023-38545 vulnerability. Most of them are NOT going to see it in their SBOM even though they use it.

In this article I walk through why this is, places it might be hiding and questions to ask that can help uncover your use of it.

zebracatzebra.com/oss/curl-is-… #curl #sca #sbom

UX Principles that include Cognitive Accessibility ab11y.com/articles/ux-principl… by Gareth Ford Williams (2021) #ux #UXDesign #a11y #coga #cognitive #accessibility #UIDesign
This entry was edited (2 years ago)

Okay, big news for everyone with a WordPress blog, including people with a free blog on wordpress.com!

You can now turn *any* WordPress blog into a Fediverse server which can be followed from Mastodon etc.

I've updated the instructions on how to do this at:

➡️ fedi.tips/wordpress-turning-yo…

Just to repeat, this is now available to ALL WordPress blogs including free tier ones. The free tier has slightly different instructions, but effect is same.

(via wordpress.com/blog/2023/10/11/…)

#WordPress #Fediverse

Daniel Stenberg (@bagder) discusses CVE (cve.org/) issues, proposes fixes, and addresses concerns like DDOS attacks while Dan Lorenc (dlorenc.medium.com/) shares insights on NVD (nvd.nist.gov/) and improving CVE quality.

Listen at 🎙️ podcast.sustainoss.org/203

I watched “Mastering the curl command line with @bagder

It took me more than a week and it was totally worth it!

youtube.com/watch?v=V5vZWHP-Rq…

#curl

This entry was edited (2 years ago)

🇬🇧#ChatControl deal: Will EU governments bury private messaging and secure encryption next week?

In favour: 🇧🇬🇨🇾🇩🇰🇬🇷🇭🇺🇭🇷🇮🇪🇮🇹🇷🇴🇱🇹🇱🇻
Opposed: 🇩🇪🇦🇹🇵🇱🇪🇪
To be decided: 🇧🇪🇨🇿🇫🇮🇫🇷🇳🇱🇱🇺🇫🇷🇲🇹🇵🇹🇸🇰🇸🇪🇸🇮

Contact your government and parliaments now! Arguments: patrick-breyer.de/en/chat-cont…

in reply to LibreOffice

Hi, thanks for answering, thats great.

I mean the T-button in the ribbon, see?

Once I click that I can't select anything in the page anymore. How do I get back to the state before the T was pressed?

Version: 7.5.7.1 (X86_64) / LibreOffice Community
Build ID: 50(Build:1)
CPU threads: 12; OS: Linux 6.2; UI render: default; VCL: gtk3
Locale: nl-NL (en_US.UTF-8); UI: en-US
Ubuntu package version: 4:7.5.7-0ubuntu0.23.04.1
Calc: threaded

in reply to Jason Parker (he/they)

@north @sheogorath I think it's pretty far. It kinda depends on what you count (if a device has multiple curl installations, does that only counts once?), but considering that 8+ billion humans exist, and most of them have at least one device with curl installed, it's already above 3 billion.
I vaguely remember hearing something about there being 10+ billion installations of it, but can't remember the source, so take it with a grain of salt.

The #CSAM clusterfuck just became even more shitty:

Dutch researcher Danny Mekić has looked at #advertising data from #Twitter & says that the @EU_Commission's #DGHome has used #SurveillanceAds based on prohibited data categories to target people with #disinformation about the #ChatControl proposal.

#YlvaJohansson's department specifically targeted people in member states that had been critical of her proposal but excluded people who are likely to value #privacy.

dannymekic.com/202310/undermin…