2 days ago I reported about a #security patch having been applied to the IzzyOnDroid F-Droid repo aka #IzzySoftRepo – but I didn't give much details. After it was tested now at the IoD test & staging area, and running smoothly for two days for the public one, I reported back to its author @obfusk that all seems smooth, and she decided to make POC & patch public. You can find the full details at github.com/obfusk/fdroid-fakes… & openwall.com/lists/oss-securit… now. @fdroidorg @eighthave be welcome using it!

1/2

in reply to Hans-Christoph Steiner

PS: Had that issue not been wide in the open for almost a year, giving the impression to be not important, we had of course approached @fdroidorg with a confidential issue first. But that signaled it would be ignored as well. As is gitlab.com/fdroid/fdroidserver… opened 10/2022, POC available (& linked there) since 1/2023. Affecting reproducible builds. A lot of evil stuff could be injected that way, as was outlined, also in my latest articles. So please don't call *US* irresponsible @obfusk
in reply to IzzyOnDroid ✅

Part of the bug was known 11 months ago. The new proof-of-concept shows key details that were not previously known nor reported in the issue. Those were just dumped to the public. We asked for that yesterday, and you didn't send it to us, but withheld it to now publicly dump it. That code was posted to GitHub yesterday: github.com/obfusk/fdroid-fakes…

You could have just sent us that link yesterday before tooting it, that would have been better.

in reply to Hans-Christoph Steiner

I see this was reported to #androguard yesterday github.com/androguard/androgua…

Did you give them any advanced warning?

in reply to Hans-Christoph Steiner

I totally get it that you're not happy with the current situation (for what it's worth, we haven't been for years). But now going to "dig up things" about @obfusk trying to put the blame on her after having ignored her and her advice for so long is not a nice thing to do. Please stop that. This is not about doing dirty laundry in public but about getting long standing issues solved. @fdroidorg
in reply to IzzyOnDroid ✅

All I'm asking is for #ResponsibleDisclosure. The tone you sense was my panic as I scrambled to figure out the proof-of-concept to ensure that #FDroid users are kept safe. Signature verification is a key part of that. I cleared my schedule this morning to deal with this.

Thanks to @obfusk to doing the hard work of the proof-of-concept and the patch. I posted my preliminary analysis of the issue on gitlab.com/fdroid/fdroidserver…

1/2

in reply to Hans-Christoph Steiner

and I am *very* happy having @obfusk and @SylvieLorxu supporting me and the #IzzySoftRepo – I couldn't think of anyone better. And haven't heard of anyone better known in the area of this and also of reproducible builds than Fay, or anyone who can hold a candle to Sylvia. Yes, both mostly worked in the background – but I guess you already got a clue what F-Droid lost having them leave.
in reply to Hans-Christoph Steiner

Pardon me? Not done yet with blaming? Now it's sloppy security on my end? "relies completely": did you ignore all my messages to you the past weeks? Including the blog posts at Kuketz and especially android.izzysoft.de/articles/n… outlining what security measures were just put into place at my repo *ADDITIONALLY* to those already in effect for years – which are still mostly missing at your end? So my key takeaway again is you don't listen, as so often in the past, sorry. @obfusk @fdroidorg

#AndroidAppRain at apt.izzysoft.de/fdroid today with 9 updated and 1 added apps:

* Bubble2: Comic Book Reader/Image Archive Viewer

Enjoy your #free #Android #apps with the #IzzySoftRepo :awesome:

I'm on an unrestricted variable electricity tarrif.
My price per kwh is about to go negative for 3 hours*

I can get my oven and air con unit to fight each other, and be paid for it!

*it's so windy that there's nowhere to put all the energy the turbines are generating, so they pay (mostly industry) to use it up. The price shoots up in the evening when everyone starts putting their heating on and cooking dinner. People on a fixed price tarriff are paying ~25p/kWh all day in the UK right now.

Alza na to jde rafinovaně. Má ocenění udržitelný e-shop, před pár dny zavedla Alzabox asi 200 m od baráku. I když člověk nemá rád jejího maskota, tak nakonec tam ještě rád nakoupí. Vlastně nemám důvod si stěžovat a nakupuju tam čím dál více. Cenu mi navíc vlastně vždycky srovnali na úroveň konkurence.

I updated my AutoHotkey Doom Launcher Script. It adds co-op as an option. Unfortunately I didn't get to actually test it with co-op, but it does run.

The zip file ccontains both the executable, .exe and the source code, .ahk.

All of the other components have been tested and they do work. The only thing I'm not quite sure about is the co-op option, but I know the hosting part of it actually opens things so that someone can join.

If you want to use the script, place it in your TobyAccessibilityMod_Version7-0 folder and run the .exe. It will spawn a menu which you can navigate with the arrow keys to select an option.

All of a sudden it starts raining handmaids in handcuffs:

erosblog.com/2024/04/06/its-ra…

#Facism #Handmaids #HandmaidsTale #Privacy #ReproductiveRights #BurnThePatriarchy #Technology #Patriarchy #Christofacism #Christianity #Ovulation #OvulationTracker #Ovia #Tech #Danger #ReproductiveFreedom

in reply to ErosBlog Bacchus

I assume that people who need to know this would already know it, but I am not such a person and did not know it, so I will pass this on from a correspondent who wishes to remain nameless: There's a FOSS menstrual cycle and fertility tracking app named "drip." created by feminist female developers with privacy at its foundation. I'm not qualified to opine about its safety or security but developers say everything stays on your device: f-droid.org/packages/com.drip/

@Tzipporah with their Eighth Generation "Two Spirit" wool blanket by Two Spirit artist Ryan Young (Lac du Flambeau Band of Lake Superior Chippewa) that calls out to their community's traditional story about crows.

eighthgeneration.com/collectio…
#Mvskoke #Chippewa #Crows #Native #Indigenous #TwoSpirit #2SLGBTQ

Calling all #LibreOffice users: Power up ⚡ and become a LibreOffice contributor, like Adam Seskunas! Learn new skills, build a portfolio of experience, and have fun on the way: blog.documentfoundation.org/bl… #foss #OpenSource

Speaking of #overlays, there is yet another one: #WebAbility

I have already made a PR to add it to the Overlay Fact Sheet:
github.com/karlgroves/overlayf…

As with other overlays, it makes WCAG/ADA promises, fails to fix stuff, replicates platform features (poorly) in CSS, and introduces WCAG violations just by adding it to a site.

Cool business model.

#accessibility #a11y

This entry was edited (1 year ago)

🚨 PRIVACY WIN 🚨

#Google must destroy $5 billion worth of user data illegally collected in Incognito Mode 💪

Because #privacy matters.

Read more on the court ruling:
👉 tuta.com/blog/google-incognito…

"I don’t take it. I don’t want it." Speaking to an INN Boston member yesterday, Rep. Jim McGovern said he rejects AIPAC and its toxic influence in Congress, as it prolongs the massacre in Gaza.

Help us #RejectAIPAC by joining a virtual phone bank on Thursday! mobilize.us/ifnotnow/event/615…

Twice in the past week I've read scholars who should know better repeat the urban legend that the QWERTY keyboard was designed to slow down typing, and thus, jamming, on early typewriters.

That'd be cool if it were true, but it's not, and the the truth is even cooler. The QWERTY keyboard evolved over time, shaped by two forces: (1) since the early machines were used by telegraph operators, the keys were arranged to avoid common transcription errors; and (2) competing patents of the typewriter slightly arranged the keyboard layout in order to qualify as new (and therefore patentable) designs.

Check out this research for more: repository.kulib.kyoto-u.ac.jp…

in reply to Mark Sample

I guess the urban legend is popular among people who struggled to learn to type. Steven Levy, one of many who propagated the legend, wrote in his book _Insanely Great_: "My own high-school instruction in typing was nightmarish. So fumble-fingered was I that after my mistakes were deducted from my word totals, my scores on the speed drills were usually gauged in negative numbers." FWIW, I can't relate; typing came naturally to me. But I started much earlier.

Welcome Jérôme Leclercq as #curl commit author 1256: github.com/curl/curl/pull/1326…
#curl

Who needs operating systems when you can IRC from the UEFI?

tomshardware.com/software/some…

This entry was edited (1 year ago)

A quick look back at Windows 3.1 which hit the RTM stage 32 years ago this week neowin.net/news/a-quick-look-b…

Today when #curl has just surpassed 32,000 commits it is *almost* at 34.000 stars on GitHub. github.com/curl/curl
#curl
This entry was edited (1 year ago)