"We are happy to tell you that we accept your proposal "Tightening every bolt" in the Security room at FOSDEM 2025."
pretalx.fosdem.org/fosdem-2025…
Tightening every bolt FOSDEM 2025
Things to do in order to sleep well while having your C code in twenty billion installations. A talk about what the curl project does to minimize security risks: Security, Safety, Reproducibility, Vulnerability handling and the processes and tooling …pretalx.fosdem.org
Day 9 - #adventOfIOSAccessibility. If you have interactions that are hidden or require complex gestures to be performed or that may conflict with VoiceOver, you need to provide alternative ways of executing these actions. Custom actions can help a lot of times, but not always.
@Keev Zpovědní tajemství je církevním právem stanovený a církví těžkými tresty postihovaný závazek mlčenlivosti o věcech, které se kněz dozví v rámci svátosti smíření, což je obřad s jasně ohraničený začátkem a koncem. Na běžné pastorační rozhovory se zpovědní tajemství nevztahuje.
Nedává smysl, aby se zpovědní tajemství vztahovalo na jiné osoby než na duchovní se zpovědní juristikcí (právem udělovat svátost smíření). Není důvod pro nějaké tajemství obdobné zpovědnímu pro jáhny nebo pastorační asistenty a asistentky, kteří a které nemají žádnou jurisdikci obdobnou zpovědní jurisdikci.
Není důvod, proč by církev měla zavazovat stát k ochraně něčeho, co sama svými předpisy nechrání.
interested in helping with with #postmarketOS ? Have an interest in Freedesktop, #GNOME, or app development?
Check out the help wanted section at the bottom of our November status update
postmarketos.org/blog/2024/12/…
postmarketOS in 2024-11: pmbootstrap v3, RFC process and Seattle
Aiming for a 10 year life-cycle for smartphonespostmarketOS
#Slop is low-quality media - including writing and images - made using generative artificial intelligence technology.
Quelle: Wikipedia.
Open source projects have to deal with a growing number of low-quality vulnerability reports based on AI. See for example this comment from Daniel Stenberg, maintainer of #Curl:
I'm sorry you feel that way, but you need to realize your own role here. We receive AI slop like this regularly and at volume. You contribute to unnecessary load of curl maintainers and I refuse to take that lightly and I am determined to act swiftly against it. Now and going forward.You submitted what seems to be an obvious AI slop "report" where you say there is a security problem, probably because an AI tricked you into believing this. You then waste our time by not telling us that an AI did this for you and you then continue the discussion with even more crap responses - seemingly also generated by AI.
Weiterlesen bei HackerOne: Buffer Overflow Risk in Curl_inet_ntop and inet_ntop4.
#opensource #AI #LLM #Spam
curl disclosed on HackerOne: Buffer Overflow Risk in Curl_inet_ntop...
*Curl is a software that I love and is an important tool for the world. * *If my report doesn't align, I apologize for that.* The `Curl_inet_ntop` function is designed to convert IP addresses from...HackerOne
So a crazy thing happened. In a crime thriller film called Les chambres rouges (Red Rooms, 2023) there is a scene where the hacker protagonist is attempting to purchase a snuff film in online auction. The auction happens via IRC or IRC-like chatting environment and to my surprise there's actually me @rolle and my wife @mustikkasoppa who are one of the bidders.
1) The nickname of my wife is mistakenly written as "mustikasoppa" (with one k) but if I recall correctly she has used a mistakenly written nickname in the past
2) We are both operators and on the same IRC channel as we've been for the past 17 years
This is not a coincidence. One nickname can be made up by accident but not two with these features and definitely not in a French movie. My wife's nick "mustikkasoppa" is Finnish and means "blueberry soup".
Our IRC logs are more or less public because of open source and statistics so I presume the scene has been made with chatgpt which has scraped our nicks from the Internet so that they ended up in the movie. We still chat via IRC every day together.
The era of AI... Do your background check, folks. I'm glad this wasn't a dramatized documentary film but a complete fiction. However my wife and I are real. Mixed feelings.
reshared this
Just released a new version of wcurl:
github.com/curl/wcurl/releases…
There's 3 new exciting features:
* New option "-o|-O|--output" for those who would like to choose the output filename.
* Automatic percent-decoding of output filenames, especially handy for URLs which are not written in Latin-based languages.
* Default filename set to "index.html" for those cases where wcurl/curl couldn't identify an output filename from the URL. You can now download everything with wcurl!
Release v2024.12.08 · curl/wcurl
New parameter -o|-O|--output|output= which allows the user to choose the output filename. Default to index.html as filename if none can be inferred from the URL. Percent-decode output filenames by ...GitHub
#wcurl v2024.12.08 is here!
github.com/curl/wcurl/releases…
Release v2024.12.08 · curl/wcurl
New parameter -o|-O|--output|output= which allows the user to choose the output filename. Default to index.html as filename if none can be inferred from the URL. Percent-decode output filenames by ...GitHub
Chi è andato su Bluesky sull’onda dell’hype, per bandwagon effect o per l’istintiva tendenza a fare il pecorone, sappia che i suoi testi sono sfruttati a scopo di lucro per attività informatiche dal pesante impatto ambientale.
hdblog.it/tecnologia/articoli/…
Bluesky: i tuoi post vengono usati per addestrare le AI, senza permesso
Su Hugging Face spopolano i dataset con milioni di post degli utenti di Bluesky, raccolti senza il loro permesso. Per ora non sembra esserci una soluzione.Umberto Stentella (HDblog.it)
Nová studie vědců Floridské státní univerzity ukazuje, že přidávání olova do benzínu způsobilo jen v USA deprese, úzkosti nebo hyperaktivitu u více než poloviny populace. V roce 2015 mělo více než 170 milionů Američanů vysoké hladiny olova v krvi během klíčových fází vývoje mozku. Důsledky zahrnovaly nejen pokles IQ a nižší příjmy, ale také rozsáhlé problémy s duševním zdravím.
"Given the fact that NVDA has an extremely light computer resource foot print the portable version is a blessing" - Squire, South Africa / NVDA negates the barriers many face when accessing a PC, as a free and light-weight screen reader translated into more than 50 languages.
#NVDA #NVDAsr #ScreenReader #GoodNews #FOSS #Free #Lightweight #A11y
1. A week-long goalball camp that took place in a school during the summer. The library computers were locked down and had no screen reader on them. I helped a few people get NVDA running. I think it was version 0.5 at the time.
2. All throughout high school the blind school had hilariously old computers running a six-year-old version of JAWS. I basically ran my own portable software suite with NVDA as the screen reader. I can confirm it ran much, much better than JAWS ever has ... and possibly ever will.
Sean Randall reshared this.
Katie Steckles (@stecks@mathstodon.xyz)
Attached: 1 image Having now talked about my 'finding your hotel room' game at multiple events, I'm being sent enjoyable photos of hotel room direction signs, including this one in which 404: room not foundMathstodon
The little switch between the tone and volume knob gave it away. That, and I have a 24-08, myself, and absolutely love it!
pixelfed.social/i/web/post/617…
Scott Williams (@vwbusguy@pixelfed.social)
My new axe! A Paul Reed Smith SE Custom 24-08! #guitarPixelfed
Learning Blind Tech Episode 19: Basics on Meta Glasses
In this episode, I discuss reasons why I use the Meta Glasses. I demonstrate using them to identify items, call Be My Eyes, and find content in Metaview Gallery.Desiree Renae's Website
The official Doctor Who YouTube channel has posted the entire Genesis of the Daleks serial - one of the most highly regarded Classic Who stories.
If you want to see what the big deal is with Classic Who, it's a good example.
youtube.com/watch?v=4FHvvm5CCs…
Genesis of the Daleks | FULL EPISODES | Season 12 | Doctor Who
Watch the complete story of Genesis of the Daleks - the Fourth Doctor's first encounter with Davros and the Daleks from 1975. Subscribe to Doctor Who for mor...YouTube
onlineconverter.com/add-image-…
Add Image to MP3: Create MP3 With Cover Or MP4 Music Video (Free)
Add image as album art cover of MP3 audio, or create an MP4 music video.www.onlineconverter.com
Mungkin ada yang tertarik:
Lowongan Pemagang Komunikasi dan Media Sosial di Wikimedia Indonesia
Boleh direpost.
Lowongan Pemagang Komunikasi dan Media Sosial
Wikimedia Indonesia merupakan organisasi nirlaba dan mitra lokal dari Wikimedia Foundation, pengelola situs populer dunia Wikipedia dan proyek-proyek Wikimedia lainnya. Wikimedia Indonesia berdedik…Wikimedia Indonesia
[Satire] National grid could be entirely powered by Peter Dutton’s bullshit, CSIRO finds
National Grid Could Be Entirely Powered by Peter Dutton’s Bullshit, CSIRO Finds — The Shovel
"It is abundant, free and 100% renewable"The Shovel
Right-wing shitheads are posting photos of the signs advertising the Midwest Furfest HIV testing center, as if that's a slam dunk on furries or something.
Anyway, I wrote about this a while ago. Here's a link you can share if you'd like to get ahead of this stupid conversation.
soatok.blog/2024/09/30/why-are…
Why are furry conventions offering HIV testing to attendees? - Dhole Moments
Spoiler: It’s nothing scandalous or bad. Every once in a while, someone posts this photo on Twitter to attempt to dunk on furries: Midwest FurFest 2018 Over the years, I’ve seen this di…Dhole Moments
curl disclosed on HackerOne: Buffer Overflow Risk in Curl_inet_ntop...
*Curl is a software that I love and is an important tool for the world. * *If my report doesn't align, I apologize for that.* The `Curl_inet_ntop` function is designed to convert IP addresses from...HackerOne
Looks like this made its way to The Register...
theregister.com/2024/12/10/ai_…
Open source maintainers are drowning in junk bug reports written by AI
Python security developer-in-residence decries use of bots that 'cannot understand code'Thomas Claburn (The Register)
Sehr spannende Doku über Gegenkartografie oder sensible Kartografie: Was Google Maps euch nicht zeigt.
Nach dem Titel hatte ich was anderes erwartet, aber dass worum es ging, war tatsächlich noch viel spannender...
Empfehlung. :)
arte.tv/de/videos/119473-020-A…
#doku #arte #empfehlung #guteideen
Tracks - Gegenkartografie: Was Google Maps euch nicht zeigt - Komplette Sendung | ARTE
Um den Weg zu finden, vorzugsweise den schnellsten, gibt es zahlreiche Apps. Sie können uns in Echtzeit lokalisieren und die zurückgelegten Entfernungen messen, aber keine von ihnen ist in der Lage, die Gefühle und Erlebnisse darzustellen, die mit un…ARTE
Vielen Dank für den Tipp!
Ich finde es schön, dass man bei #OpenStreetMap auch selbst beitragen und auch viele Details kartographieren kann.
@openstreetmap@en.osm.town
FediVerseExplorer likes this.
sootoday.com/local-news/missio…
Mission impossible: finding a snowblower shear pin in the Sault
Snow shovels, roof rakes and snowblowers are also in short supplyKenneth Armstrong (SooToday.com)
Today's #AndroidAppRain at apt.izzysoft.de/fdroid brings you 17 updated and 1 added apps:
* Global Icon Pack: An Xposed module for applying icon packs globally 🛡️
Enjoy your #free #Android #apps with the #IzzyOnDroid repo 
IzzyOnDroid F-Droid Repository
This is a repository of apps to be used with your F-Droid client. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
Naughty or nice? Santa doesn’t need to know. 🎅❌
Tuta’s encrypted calendar keeps your events so private, even Santa stays in the dark. 🔒🗓️
I don't know how many times we have to say this. Last I counted it was 1.2 million times and almost 20 years.
"Developers should always prefer using the correct semantic HTML element over using ARIA."
developer.mozilla.org/en-US/do…
#webdev #javascript #html #webdevelopment #a11y #aria
An overview of accessible web applications and widgets - Accessibility | MDN
Most JavaScript libraries offer a library of client-side widgets that mimic the behavior of familiar desktop interfaces. Sliders, menu bars, file list views, and more can be built with a combination of JavaScript, CSS, and HTML.MDN Web Docs
grapheneos.social/@GrapheneOS/…
GrapheneOS (@GrapheneOS@grapheneos.social)
Unfortunately, Revolut has banned GrapheneOS users from logging into the app because of an incorrectly implemented device integrity check based on the anti-competitive Play Integrity API.GrapheneOS Mastodon
The future of Syria is a matter for the Syrians to determine, and my Special Envoy will be working with them towards that end." - UN Sect'y Gen. António Guterres
Speaking Freely: Anriette Esterhuysen
Anriette Esterhuysen is a human rights defender and computer networking trailblazer from South Africa.Electronic Frontier Foundation
Oh, that didn't take long for OpenAI. From developing AI for the good of humanity to developing AI for kill-drones. I wonder if they keep their disclaimer: "ChatGPT can make mistakes. Check important info."
arstechnica.com/ai/2024/12/ope…
Soon, the tech behind ChatGPT may help drone operators decide which enemies to kill
OpenAI and Palmer Luckey’s weapons company sign agreement to explore lethal drone defense for military use.Benj Edwards (Ars Technica)

SuspiciousDuck
in reply to Robin Bedrunka 🐞 • • •