Skip to main content


in reply to Kevin Beaumont

Regarding the "unspecified Linux vulnerability" that the author has been "hyping the shit out of" (their words) all week -

It's accidentally leaked, due to an unpaid open source maintainer making a boo boo.

It's in CUPS, a printing subsystem. It isn't Linux specific.

CUPS isn't faced much to the internet, I've checked and done a Shodan Safari. It also isn't installed by default on Linux server installs for almost all distros.

It's not a big deal, update packages are dropping, don't panic.

reshared this



rPGP is an #OpenPGP implementation in pure #Rust (crates.io/crates/pgp).

It serves as the end-to-end encryption engine for Delta Chat:
@delta, a secure decentralized messager for all major platforms (and then some).

rPGP implements all generations of the OpenPGP standard, up to and including the new RFC 9580.

#RustLang #Cryptography #PGP



Introducing the seamless Java/Swift interop effort!

Offering both:
- generated Swift macro based JNI wrappers
- Project Panama based Swift accessors generated with a jextract-swift tool for high performance use-cases

Early prototype is open source and we’ll share more about our plans and invite folks to collaborate early next week!

github.com/swiftlang/swift-jav…

#ServerSideSwift2024



Doesn’t matter who’s right in the WordPress/WP Engine battle.

The damage to the open web has already been done. It took five days.

tedium.co/2024/09/25/wordpress…

new @tedium



Samsung Galaxy S24 FE Packs AI Features Into a Lower-Priced Phone cnet.com/tech/mobile/samsung-g…


I'm getting very swept up in all this #wordpress stuff.

From a developer/agency point of view the biggest thing appears to be that clients are viewing this not as a #wpengine problem but a #wordpress problem, and Matt Mullenweg is causing some irreparable damage.

This makes sense; as he even says WPEngine are the company people are paying, they're not the CMS developer and certainly not the ones cutting off essential services.

There are many threads talking about replacements too. It's probably too early for that kind of talk, but for simple sites or projects just getting off the ground it would be tempting to switch.

The issue there is, what is the alternative? Yes, there are many CMS/blog alternatives, but what about the plugins? It takes time to not only learn a new platform but also work out alternatives to eCommerce, SEO, image optimisation, membership platforms... and on and on.

It's a huge ecosystem not easily swapped out for another.

in reply to Alan

classicpress.net/ ClassicPress seems to be the next best thing after selfhosted Wordpress



We didn't need proof.
This entry was edited (1 month ago)


🚨 Once again, scientists are sounding the alarm bell about the severe dangers #ChatControl would bring, calling the highly controversial proposal “unacceptable”: homes.esat.kuleuven.be/~prenee…
This entry was edited (1 month ago)


Re last: I stopped using and recommending #WordPress after the infamous Gutenberg editor appeared. I suggest @classicpress for everyone who need jolly old WordPress without #accessibility struggles.


The announced server maintenance is complete and the OpenStreetMap web site and API are now operating normally again


they should have given this vuln a catchy name like iCup
in reply to Seirdy

the joke is that iCup is a reference to iCarly, but most computers in iCarly ran Windows XP. Windows XP did not run CUPS. this made the “iCup” name ironic, which also starts with “i”. only real iCarly fans understood this one.
This entry was edited (1 month ago)


In case you also haven't used WordPress in years and you're wondering what just happened:

techcrunch.com/2024/09/26/word…

#WordPress

reshared this



Who woulda thunk? Cleaning the air in a school (even before the pandemic) resulted in better test scores and performance. Clean and ventilated air isn't magic; it's just sensible.

vox.com/2020/1/8/21051869/indo…

This entry was edited (1 month ago)


Hey, @Tusky , any plans on getting this interesting feature in #Tusky? It'd great to integrate local feeds from other servers, in order to add interesting extra content to our Mastodon experience!


So... Has anyone on here actually talked with the people from the #SocialWebFoundation?

I can tell the #Mastodon Organization has, but #Threads is also listed there, while I don't see any other names that aren't some corporate entity. I'm all for groups that want to expand the #Fediverse, even for-profit ones, but it's a red flag when an organization that purports to be for a general movement doesn't have an open line of communication with rank-and-file server-runners and volunteers...

Edit:
I just realized that it was founded by @evan who is actually very active in mainstream Fedi, and one of the maintainers of the actual protocol. While that doesn't elaborate on actual intentions, it is good to know that at least it's someone who is directly involved, and not some random corporation. #EvanProdromou

This entry was edited (1 month ago)
in reply to Seirdy

re: sensitive topics, rant

Sensitive content

in reply to Amber

re: sensitive topics, rant
they are the biggest by an enormous margin. 60% of all certs in the Web PKI.





@thunderbird I just noticed that the thunderbird Appointments logo looks extremely similar to the NOAA logo (US Gov National Oceanic and Atmospheric Administration).

Is this gonna be an issue legally? Not sure how the bird silhouette sits as part of their logo.

in reply to Thunderbird: Free Your Inbox

Actually this version of the article is cached in my RSS reader, the article online has the regular thunderbird mail logo, so I guess they've already changed it.
in reply to Deijin

It was an old cache, so the logo had been changed some time ago.


“According to Mozilla, PPA involves websites asking Firefox to remember ads they show and to potentially generate an interest report. Firefox creates the data but then submits it to an aggregation service, where the report is combined with similar ones.”

Mozilla is not your friend.

engadget.com/big-tech/mozilla-…



My favorite video game of all time is currently on sale for $1.99 on the Switch—if you haven't played it yet, please please do yourself the favor:

nintendo.com/us/store/products…

in reply to Bubu

Yeah me too, after I finally finish Limbo. 😅
This entry was edited (1 month ago)


as soon as I saw the name of the bloke that has been hyping this vuln I knew it would be a nothingburger
in reply to Volt4ire

Kinda happy that in my mastodon feed I pretty much instantly hear about any public vuln which tells me what to update and preferably how fast to drop everything else but I get absolutely nothing about the advance hype.


Gagging, dysphoria, bondage, petplay

Sensitive content

in reply to Duct_tape 18+

Gagging, dysphoria, bondage, petplay

Sensitive content



The amount of much-needed work going into Firefox bug 1590215 for forced-colors support in DevTools is incredible to watch.

#accessibility #ForcedColors



Thunderbird for Android is coming soon! Find out how to get involved, from beta testing to localization to support and more, in our shiny new contributor guide!

(Seriously, by soon, we mean soon!)

#Thunderbird #Android #OpenSource

blog.thunderbird.net/2024/09/c…

Bubu reshared this.

in reply to Thunderbird: Free Your Inbox

Congratulations !
Nice to see you on Android.
Working well on android 9.
Look like, close to K-9 mail...
I hope soon on Harmony Os Next !
This entry was edited (2 weeks ago)


Hackers showed me (there's video) how a website vulnerability let them locate, unlock, honk the horn, start ignition of any of millions Kias in seconds, just by reading a car's license plate.

They found similar bugs for a dozen carmakers over the last two years.

wired.com/story/kia-web-vulner…



So this "CVSS 9.9" "unauthenticated RCE vs all GNU/Linux systems (plus others)" thing...

- Does NOT affect all GNU/Linux systems.
- Is not CVSS 9.9. I put it at a 6.3

It also requires:
1) The victim system has no active firewall to block incoming connections.
2) A user on the victim system must print something to a printer that mysteriously appears on the system that has never been there before.

If these two things happen, then command execution can happen as the "lp" user.

<yawn>

We get it. You found a vulnerability.
Lying about it to try to stir up interest in it is not appreciated by anybody who takes themselves seriously in this industry.

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned.

evilsocket.net/2024/09/26/Atta…



Passive income? I've seen today's rich. More like passive/aggressive income.


Github is telling me that because of my role in “the software supply chain” I am no longer allowed to disable 2FA on my account

and quite frankly there’s nothing else you could have said that would have given me a greater desire to remove 2FA from my GitHub account

Unknown parent

Matthew Lyon

the site basically enlisted everyone who used it into helping it become critical societal infrastructure, in the same way that Amber Alerts now include t.co links to x dot com accounts that require you to be signed in in order to read

and it was us who helped it get there, simply by participating

This entry was edited (1 month ago)
Unknown parent

Glyph

I have so much to quibble with here, but I just have to endorse your key insight that IT IS NOT A SUPPLY CHAIN and the "supply chain" verbiage and assumptions are corrosive and they chafe a little more every time I hear them.

However, you *should* turn on 2FA on Github (and everywhere else) because of the position of social and infrastructural trust that your packages place you into. I really want better language to describe this role that isn't "supply chain" based, but I don't have it



My All Systems Go talk, "busd: There is a new D-Bus broker in town" is going live in less than an hour.

cfp.all-systems-go.io/all-syst…

Live stream: streaming.media.ccc.de/asg2024



I wrote a benchmark of game engine performance primarily geared towards the types of 2D games that are popular these days.

Here are the results for Flutter, Flame, Unity and Godot. It's a long read with many caveats, so buckle up.

Here:
filiph.net/text/benchmarking-f…

#Flutter #gamedev



On elementary OS you can download #Flatpak apps from alt stores like @flathub or directly from developers like @1password while still getting automatic updates and with app sandboxing that helps keep you safe. And you can install them with just a couple mouse clicks, no Terminal, developer mode, or workarounds required 🎉
This entry was edited (1 month ago)


New app listing: Mirror Hall

Use Linux devices as virtual displays in a peer-to-peer fashion

linuxphoneapps.org/apps/eu.nok…



The National Weather Service is warning that flooding in Western North Carolina will be "one of the most significant weather events to happen ... in the modern era" and that it is comparable to the flood of record, which hit in 1916.

#NCwx #weather #hurricane #Helene



People on StackOverflow telling people to screw up #accessibility with the HTML dialog element defeats the purpose of using that element in the first place IMO. Please upvote my answer that corrects the numerous wrong answers, including the accepted answer, to this question if you have an SO account.

stackoverflow.com/a/79028606/2…

#webDev #a11y #html #css #javaScript



Order free at-home COVID-19 tests for Blind and Low Vision Users | ACL Administration for Community Living acl.gov/accessibletests acl.gov/accessibletests


Reminder that the original Metatext third party app is no longer being maintained, as its lead developer had to step back due to health issues.

However, there is a new version of Metatext run by different people called Feditext which is currently in public beta testing. You can follow the official Feditext account at:

➡️ @Feditext

If you would like to join the public beta testing, it's on Apple TestFlight. There are more instructions here:

➡️ mastodon.social/@Feditext/1128…

#FediTips #Mastodon #iOS

reshared this



Order Free At-Home COVID-19 Tests That Are More Accessible for People Who Are Blind/Low Vision or Who Have Low Dexterity
special.usps.com/testkits/acce…


Sutherland said the threshold for informing Canadians was deliberately set very high because of the risk that such an alert could disrupt an election.


[speechlessly confused/exasperated Mal.gif]

cbc.ca/news/politics/foreign-i…