in reply to Kevin Beaumont

Regarding the "unspecified Linux vulnerability" that the author has been "hyping the shit out of" (their words) all week -

It's accidentally leaked, due to an unpaid open source maintainer making a boo boo.

It's in CUPS, a printing subsystem. It isn't Linux specific.

CUPS isn't faced much to the internet, I've checked and done a Shodan Safari. It also isn't installed by default on Linux server installs for almost all distros.

It's not a big deal, update packages are dropping, don't panic.

Introducing the seamless Java/Swift interop effort!

Offering both:
- generated Swift macro based JNI wrappers
- Project Panama based Swift accessors generated with a jextract-swift tool for high performance use-cases

Early prototype is open source and we’ll share more about our plans and invite folks to collaborate early next week!

github.com/swiftlang/swift-jav…

#ServerSideSwift2024

in reply to Nick

@ratcatcher @thrilway While we'd love if K-9 Mail could regenerate automagically into Thunderbird, the Google Play Store doesn't like that. You'll need to download Thunderbird for Android separately, and we'll have instructions on how to transfer your information between the two apps. (For the immediate future, a separate K-9 Mail branded app will still exist.)

So this "CVSS 9.9" "unauthenticated RCE vs all GNU/Linux systems (plus others)" thing...

- Does NOT affect all GNU/Linux systems.
- Is not CVSS 9.9. I put it at a 6.3

It also requires:
1) The victim system has no active firewall to block incoming connections.
2) A user on the victim system must print something to a printer that mysteriously appears on the system that has never been there before.

If these two things happen, then command execution can happen as the "lp" user.

<yawn>

We get it. You found a vulnerability.
Lying about it to try to stir up interest in it is not appreciated by anybody who takes themselves seriously in this industry.

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned.

evilsocket.net/2024/09/26/Atta…

People on StackOverflow telling people to screw up #accessibility with the HTML dialog element defeats the purpose of using that element in the first place IMO. Please upvote my answer that corrects the numerous wrong answers, including the accepted answer, to this question if you have an SO account.

stackoverflow.com/a/79028606/2…

#webDev #a11y #html #css #javaScript

Reminder that the original Metatext third party app is no longer being maintained, as its lead developer had to step back due to health issues.

However, there is a new version of Metatext run by different people called Feditext which is currently in public beta testing. You can follow the official Feditext account at:

➡️ @Feditext

If you would like to join the public beta testing, it's on Apple TestFlight. There are more instructions here:

➡️ mastodon.social/@Feditext/1128…

#FediTips #Mastodon #iOS

reshared this

Kamarádi, jste úžasní. Strašně moc jste nakopli předprodej Syndikátu, knihy, u které vám nemůžeme říct, o čem je. Ale je skvělá. Je o budoucnosti. Blízké. A trochu detektivka. Trochu akční thriller. A trochu o lásce. Jinak by to nešlo.
Knihy z předprodeje jsou, samozřejmě, se slevou a podpisem. Když budete knihu číst mezi prvními, bude to rozhodně nejlepší. knihydobrovsky.cz/kniha/syndik…

Philosophy and mental health are deeply interconnected. The practical wisdom derived from philosophical reflection offers valuable insights and tools for navigating life's challenges. By integrating philosophical concepts into counseling, individuals can gain a deeper understanding of themselves and their experiences, fostering greater mental well-being.

#Philosophy #MentalHealth

psychologytoday.com/intl/blog/…

it would be very nice for the world and industry if what the C++ committee said here was true and if they actually cared about memory safety. but with a committee that writes nonsense like this, actively denying the problem, i don't see this happening.

> "Memory safety is a very small part of security."
-- C++ Committee submission to DOE laying out the language's memory safety strategy.

downloads.regulations.gov/ONCD…

1/2 "Na spiatočnej ceste vlakom sedeli vedľa mňa dve dámy. Rozprávali sa o niečo hlasnejšie, ako by sa patrilo, ale práve preto viem, že jedna z nich zarába v štátnej službe 900 eur – s príplatkami, keď je dobrý mesiac (august dobrý nebol).

Úprimne netuším, ako sa z 900 eur dá s aspoň nejakou mierou dôstojnosti prežiť, o nižších sumách nehovoriac, lebo aj tie mnohí ľudia dostávajú. A majú rodiny."

~ #SamoMarec

komentare.sme.sk/c/23387676/na…