@bart’s XKPASSWD service helps you create long, strong, and yet memorable passwords. It’s being modernized by the amazing Helma and the open source community.
New and Improved XKPASSWD — Now in Beta podfeet.com/blog/2024/02/xkpas…
New and Improved XKPASSWD — Now in Beta - Podfeet Podcasts
If you’ve been a NosillaCast listener for any length of time, you’ve heard Bart and me talk about a service he created called XKPASSWD, This service helps you create long, strong, but memorable passwords.podfeet (Podfeet Podcasts)
Feel Good By Doing Good
If you're anything like me, the last several years have been a rough go. The overturning of Roe V. Wayde was a blow to women's rights here in America. Please don't tell me about how it was bad law. FrPlaying With Quicksilver
reshared this
I just went back to watch #Beyoncé and the Chicks on their surprise CMA performance of “Daddy Lessons” again to make sure I wasn’t imagining our first impressions when Mollie showed it to me back then.
First of all, it’s an amazing performance. There’s no way I wouldn’t have been on my feet dancing along to it if I’d been there. But watch the crowd shots. There’s a lot of men who are doing anything from perfunctory clapping, to looking confused or actively unhappy. B crashed their party and they don’t like it.
And of course the Grammys shoved “Lemonade”, the album it was on, in the Urban Contemporary category (?!) and then ignored it for album of the year. Leaving Adele (who won) to remark “What the !%#$! does she have to do to win album of the year?” People literally wrote syllabi on Black History from the songs on that album. It was brilliant, both musically and in terms content. And the fact that the song wasn’t considered Country is absolutely nuts.
youtu.be/Jj1T7uHdBcY?si=7570br…
en.wikipedia.org/wiki/Daddy_Le…
💝 Beyoncé & Dixie Chicks' 🎤 HQ SOUND LIVE - "Daddy Lessons" 🎸 🎷🎻🎺 🎶
Beyoncé 💝 and The Dixie Chicks⚡️ perform “Daddy Lessons” at the 2016 Country Music Awards. 💝⭐️ SPECTACULAR✨💫HQ remastered sound 🎧 Editing by sbc (setz...YouTube
NVDA 2024.1 Beta 8 is now available, with quite a few updates from Beta 7:
- A bug fix where emojis in Windows Terminals could cause a crash
- A bug fix for Native Selection mode in Word
- Bug fixes to the installer process and ensuring NVDA exits safely
- Improvements to documentation
- Updates to translations
To find out more about everything new in NVDA 2024.1 overall, and to download the latest beta, please visit: nvaccess.org/post/nvda-2024-1b…
#NVDA #NVDAsr #Beta #News #NewVersion
NVDA 2024.1beta8 available for testing
Beta8 of NVDA 2024.1 is now available for download and testing. For anyone who is interested in trying out what the next version of NVDA has to offer before it is officially released, we welcome yo…NV Access
Billy reshared this.
Lost in the mass sterilization and boringification of macOS UI design was the incredible diversity and uniqueness that user-created themes brought us. Is it really better for humanity that every window has clean, antiseptic lines decided on by a handful of folks at Apple Park?
To summarize: we used to be a proper society!!!
(Shout out to @girlie_mac, via: @osxthemes)
Another @MapComplete milestone on the horizon, and by far the most technical one:
This took:
- switching to vector tiles
- A donated server of 96GB RAM and >1TB HDD
- Lots of work to get this right
Will be coming to MapComplete within a few weeks
600,000 US cybersecurity jobs are unfilled. Cyber.org's Project Access trains blind & vision-impaired students in cybersecurity through camps & simulations, bridging the gap & empowering futures.
govtech.com/education/k-12/pro…
Project Access Trains Blind Students in Cybersecurity
Now in its second year, the program gives vision-impaired students Windows-based laptops with assistive technology to learn text-based coding and run through password-attack and credential-harvesting simulations.Brandon Paykamian (GovTech)
reshared this
Hey Fedi! We're hosting a panel at SCALE 21x with some of the major players in the Linux desktop ecosystem to discuss where we go from here, any big ideas you want us to discuss?
Here's our list as of now: outline.fyralabs.com/s/8f1ce88…
And the abstract: socallinuxexpo.org/scale/21x/p…
Post your ideas in the replies!
#foss #linux #oss #opensource #gnome #kde #stardustxr #stardust #vanillaos #xdg #scale21x
Topics
Most of the questions in the document will not be covered. The questions are meant to serve as discussion starters for each topic to be used as the conversation permits.outline.fyralabs.com
destructatron likes this.
destructatron reshared this.
Got flashbanged by a gory article photo on Wikipedia yesterday and it reminded me of seirdy's html spoiler tag proposal
seirdy.one/posts/2023/11/12/sp…
Proposal: an HTML element for spoilers
An informal proposal for dedicated elements for spoiler tags in HTML: use-cases, syntax, semantics, recommended UA behavior, and comparisons with “details”Seirdy’s Home
Apple Vision Pro: Comprehensive Review for the Blind and Visually Impaired #AccessibilityReview
In this video, I put the Apple Vision Pro to the test to determine if it's a viable device for individuals who are blind or visually impaired. Through a thor...YouTube
A lot has happened with Jami this past week 🌞
To start the week on the right foot, here is our 3rd Dev Update (1 min read)

jami.net/dev-update-2/
Jami - Dev Update #2
This is the third update about Jami's development by its developers. :) Testing/Stability These last weeks, the Jami team kept focusing on stability and automated testing! New automated tests (called smoke tests) were written for iOS and Andro…Loïc Bogino (Jami)
A new update has been released for the BT Speak® and BT Speak® Pro.
I was reading a discussion of the 2023 Rust Survey results [1], when I came across this comment that surprised me:
"Rust really needs a lot of IDE tooling to use productively, [...] without type hints and the like you end up spending more time looking up documentation than writing code."
1/?
*me writing tens of thousands of lines of clippy and rustc code in geany on a Chromebook*: Huh?
Now I'll gladly admit that I've since come around to enjoy the modern amenities of rust-analyzer, first through VSCode and more recently through Helix, but one can certainly be *quite* productive without them.
Debian Edu Documentation
Debian Edu Documentation is being translated into 28 languages using Weblate. Join the translation or start translating your own project.Hosted Weblate
Debian Edu Documentation
Debian Edu Documentation is being translated into 28 languages using Weblate. Join the translation or start translating your own project.Hosted Weblate
accessibleworld.org/events/eve…
Accrescent 0.17.1 released! This one fixes a bug where the download progress indicator was hidden and makes preparations for some upcoming server scaling improvements (follow for more info on that 😉).
Check out the release notes below!
github.com/accrescent/accresce…
#privacy #security #accrescent #appstore #android
Release 0.17.1 · accrescent/accrescent
This release fixes a UI bug where the download progress indicator was hidden and prepares for future server scaling improments by adding a backup pinned TLS certificate key. Bug fixes Fix download...GitHub
Someone on Reddit asked a question that showed honest interest in #3DPrinting but just didn't understand what you could meaningfully do with it. They also had a bunch of misconceptions about its limitations.
As a result, I've put together a blog post that should hopefully give curious folks a good idea of what you can really do with a 3D Printer other than make silly things to put on your desk. Includes many examples.
weblog.masukomi.org/2024/02/19…
Please share with anyone you think might benefit.
Allow me to introduce #trurl 0.10: github.com/curl/trurl/releases…
Your favorite URL parser and manipulation tool.
Release trurl 0.10 · curl/trurl
trurl 0.10 Changes since previous release o add --replace Bugfixes since previous release o fixed buffer overflows on %00 use o support compiling with old versions of Visual Studio o enable more C ...GitHub
daniel:// stenberg:// reshared this.
High-profile Republicans head for the exits amid House GOP dysfunction — CNN
House Republicans were shocked by some of the recent high-profile retirements announced by their colleagues, which have included powerful committee chairs and rising stars inside the GOP.apple.news
e15.cz/byznys/potraviny/rohlik…
Rohlík vyřadí z nabídky výrobky organizátora traktorové jízdy na Prahu
Z virtuálních regálů online prodejce potravin Rohlík v nejbližších dnech zmizí výrobky zemědělské a potravinářské skupiny Rabbit CZ, za níž stojí jeden z hlavních organizátorů aktuálních zemědělských protestů Zdeněk Jandejsek.bru (e15.cz)
zpravy.aktualne.cz/zahranici/o…
Krvavá Iwodžima. Bitva měla trvat pár dní, ostrov se ale změnil v "mlýnek na maso"
Před 79 lety Američané spustili bombardování japonského ostrova Iwodžima.Dan Poláček (Aktuálně.cz)
An interesting new data leak has emerged, reportedly involving a Chinese Ministry of Public Security (MPS) private industry contractor called iSoon (aka Anxun).
Wish I could read Mandarin. But it appears to describe a number of undisclosed data breaches. "An Xun infiltrated overseas government departments, including India, Thailand, Vietnam, South Korea, NATO..."
github.com/I-S00N/I-S00N/blob/…
twitter.com/BushidoToken/statu…
Edit: Some translations and helpful context here:
"2020-11-25 02:35:38 wxid_5390224027312 wxid_soekgggwnfgm21 One network security detachment cannot handle the whole case and we definitely still need cooperation"
Sucks when you don't have enough hackers to plunder all of the riches.
The translated chats are pretty wild. On the one hand, they paint a picture of a company that is typical of IT shops: Overworked and under-resourced.
But beyond that, they have various "clients" that appear to be different Chinese government agencies seeking access to foreign govt systems. The clients supply a list of targets they're interested in, and there appears to be something of a competitive industry that has sprung up to gain the access requested, of which this company is but one of many players.
In this discussion, they talk about the prices for various webshells (website backdoors) on different govt targets, mentioning a 100,000 - 150,000 bounty (currency?) for a webshell at the FBI.
Are you seeing spam? A poll
The fediverse is dealing with a major spam attack -- Heise has some coverage (in German).
But not everybody is seeing spam. Are you? If so how much?
@fediversenews #fediverse #spam
PS: if you are seeing spam, there's also afollowon poll asking where
Mastodon: Spamwelle zeigt Schwächen auf und weckt Sorge vor schlimmerer Methode
Seit Tagen klagen einige User auf Mastodon über eine Spamwelle. Der liegen automatisierte Angriffe auf unzureichend geschützte Teile des Fediverse zugrunde.Martin Holland (heise online)
- No spam -- lucky me! (83%, 10 votes)
- Just a bit (16%, 2 votes)
- A lot (0%, 0 votes)
- So much that I'm almost ready to log off (0%, 0 votes)
Sign-In-With-Big-Tech-Only or Sign-In-With-Whom-I-Prefer?
For the attention of federated systems developers, including Matrix, Fediverse and others.
It may be good to know about an issue going on with FedCM “Federated Credential Management” draft spec. Liquid Surf brings it to the attention of all federated systems fans in their blog post: Can FedCM improve the user experience of decentralized ecosystem ? . In short, the spec aims to make a slicker browser flow for the Sign-In-With-Xxx buttons.
To us who care about federated computer infrastructure, introduction of a new standard to streamline the sign-in flow might seem minor and remote, but there is a catch.
What Is FedCM?
FedCM, short for Federated Credential Management, is a new draft specification for web browsers, published by the Federated Identity Community Group and strongly driven by teams from Google. It represents an advancement in how websites manage user logins, when logging in through different identity providers (such as “Sign in with GitHub/Google/etc.”) while preserving user privacy... — Liquid Surf: Can FedCM improve the user experience of decentralized ecosystem ?
The Catch
The critical issue is, at present, the draft standard is likely to cement the monopolies of the big providers (like Google and Facebook) and leave out small providers. In short, the problem is the draft spec says the site we're logging into (called the RP) solely dictates what list of identity providers should be offered to the user. What will happen in that case? Most sites will offer only the BigTech identity providers. Read the blog post and the issue Allow IDP registration #240 for details.
What to do about it?
The proposal in Allow IDP registration #240 is, in short, not to have the RP site solely dictate what list of identity providers should be offered, but also to let the browser register the user's chosen identity providers and present those as options when a new login is requested.
Why Do We Need to Help?
(As I responded to '@thhck' in #fediverse:pixie.town)
The proposing team are saying lack of feedback from developers is holding back the acceptance of this extension.
Decentralising ID providers is key to the whole decentralised movement, including Fediverse, Matrix, self-hosters as well as the ability for independent businesses to provide comprehensive IT services without one of the tech giants playing gatekeeper.
We, all of us who care about federated/decentralised infrastructure, now need to push the draft Federated Credential Management “FedCM” standard to support “Sign In With” the user's choice of identity provider (which may be small, local, independent, hosted by one's school or enterprise or self, and so on). If this extension to the proposal does not get enough support to be accepted, we might get a standard that perpetuates the status quo of sites only offering Sign In With the giants like Google/Github/Facebook, ugh. That would be another death blow for user agency and privacy and variety.
Fedi devs, let's demo this truly user-centric version of FedCM, show us how awesome it is! Fedi fans, this might seem remote from our viewpoint but it's important for our future. Let's share this issue more widely among Fedi projects!
Meeting on Tuesday
@thhck writes today (2024-02-16) in #fediverse:pixie.town:
We will have a Solid Special Topic on FedCM this tuesday at 14h00 UTC, it would be great if people from the fediverse can join too :) Please let me know if you are interested and I'll PM you the link to the visio
- Federated Credential Management API — W3C Draft Community Group Report, 19 January 2024
- Allow IDP registration #240
- issue #240 comment mentioning lack of feedback from developers
Follow/Feedback/Contact: RSS feed · Fedi follow this blog: @julian@wrily.foad.me.uk · use the Cactus Comments box above · matrix me · Fedi follow me · email me · julian.foad.me.ukDonate: via LiberapayAll posts © Julian Foad and licensed CC-BY-ND except quotes, translations, or where stated otherwise
Allow IDP registration · Issue #240 · fedidcg/FedCM
TL;DR there is a significant amount of context at the start of this issue before we get to the proposal, here is a google doc version for an alternative form. Background The origins of many federat...GitHub
At this years MiniDebCamp Hamburg, March 3 - 10, there will be a traditional Debian Cheese and Wine party! See wiki.debian.org/DebianEvents/de/2024/MiniDebCampHamburg
At this years MiniDebCamp Hamburg, March 3 - 10, there will be a traditional Debian Cheese and Wine party! See https://wiki.debian.org/DebianEvents/de/2024/MiniDebCampHamburgmicronews.debian.org
domov.sme.sk/c/23284695/jarosl…
...accurate...
Zrušili obvinenie Haščáka a ďalších v kauze Gorila. Advokát argumentuje protiprávnym konaním vyšetrovateľky
Jaroslav Haščák už nie je obvinený v kauze Gorila. Tvrdí to jeho obhajca Martin Škubla. Obvinenie zrušili aj ďalším šiestim osobám.Jakub Filo (SME.sk)
Is it stupid that I'm trying to raise one billion dollars to protect my cat? Some might say so. But it is infinitely stupider that people have raised over $480,000 to cover Trump's legal fees.
So, please help me raise one billion dollars to protect Fishy. It is objectively not the worst way you could spend your money.
gofund.me/40393797
Help Protect Fishy., organized by Low Quality Facts
Fishy was abandoned on the side of the road in the pouring rain. It looked like a child scratche… Low Quality Facts needs your support for Help Protect Fishy.gofundme.com
I believe I do, thanks!
... but is there a point to not just assume that's what the user wants IF AND ONLY IF the user is on a tty? There is already a warning before spamming the terminal with binary, so I figured if the response headers described some coding and curl knew how to decode it and the user is on a text terminal, then.....
Zum Ausprobieren empfohlen: HeliBoard-Tastatur für Android. Installation und Einstellungen habe ich zusammengefasst. 👇
kuketz-blog.de/heliboard-andro…
#heliboard #android #tastatur #swipe #keyboard #datenschutz #privacy
HeliBoard: Android Tastatur Empfehlung
HeliBoard ist eine auf AOSP / OpenBoard basierende Open-Source-Tastatur, die sowohl datenschutzfreundlich als auch anpassbar ist.Kuketz IT-Security Blog

Kee Hinckley
in reply to Kee Hinckley • • •Kee Hinckley
in reply to Kee Hinckley • • •