in reply to daniel:// stenberg://

Issue filed with a reduced replication test!

github.com/curl/curl/issues/15…

While developing that test I discovered an interesting factor: the bug seems to only be triggered in combination with the `--netrc-optional` option, notwithstanding whether that option is passed directly on the command line or whether it appears in `~/.curlrc`.

I wish I could have strace'd into exactly what's happening at file parse time. Hopefully this is useful enough!

#curl 8.11.1 has been released. It includes a fix to #CVE_2024_11053 - a #vulnerability I discovered.

It is a logic flaw in the way curl parses .netrc file. In certain situations, the configured password can be sent to a incorrect host. Luckily the affected configurations should be quite rare and thus the situation is unlikely to occur often.

The issue has existed in the curl source code for almost twenty-five years.

curl.se/docs/CVE-2024-11053.ht…
hackerone.com/reports/2829063

No AI tools were used in discovering or reporting the vulnerability.

#noai #handcrafted #infosec #cybersecurity

OpenWrt přechází z opkg na balíčky apk – jaký je v tom vlastně rozdíl? root.cz/clanky/openwrt-prechaz…

Donald #Trump Controls a Publicly Traded Company. Now He Will Pick Its Regulator.

There have been internal concerns that Trump Media could be misleading investors, a source said. But with its largest shareholder about to be president, experts doubt the SEC is up to the job of investigating Truth Social’s parent company.

#News #Government #SEC #Regulation #USPolitics #TrumpMedia #Politics #Business #Finance #DonaldTrump

propub.li/41qRU9S

Is doom scrolling really rotting our brains? The evidence is getting harder to ignore | Siân Boyle theguardian.com/commentisfree/…

🏧Aira Access at Chase Banks, Nationwide 🏦

Aira is now available at every Chase Bank branch in the U.S.! Bank customers can connect with a visual interpreter on-demand while in any branch, using Chase Bank ATMs, or when accessing online banking services. All calls are free of charge with the Chase Bank access offer.

"As a Chase customer and Aira user, I'm excited at the added accessibility this offer gives me! I love that I can call in and get the support I need to use the ATM or navigate the store on my own terms." - Aira Explorer

This full roll-out follows a successful pilot at 46 Chase Bank Innovation Lab locations as Chase expands efforts to meet the needs of its blind and low vision members.

Full Article: aira.io/aira-at-chase/

#accessibility #disability #DisabilityAwareness #inclusion #AccessibleTechnology

reshared this

Welcome to the RB family, Neo Backup 🥳

apt.izzysoft.de/packages/com.m…

Neo Backup is a fork of OAndBackup bringing support for new Android versions & updated looks. It lets you make and restore backups of apps on your device and save app data to a user-accessible location. Needs root.

After figuring how to get the zlib-ng issue disappear (not me!) the app is now RB & the new release tomorrow will have the green shield up :awesome:

#reproducibleBuilds #IzzyOnDroid – now at 370 apps (30.2%) & growing

minimálne za vraždu a sexuálne zneužívanie by nemala byť premlčacia doba a nemal by byť možný podmienečný trest

🔓 dennikn.sk/4351412/riaditel-ch…

This entry was edited (1 year ago)

Questo è il dato storicamente preoccupante, molto più dei dati PISA dei 15enni. Ma presentarlo nell'ottica di nazioni più o meno virtuose, come se il problema fosse che da noi la gente non c'ha sbatti di studiare, non aiuta a capire la situazione
@poliverso @scuola@a.gup.pe @universitaly @scuola@poliverso.org @poliversity @notizie rainews.it/amp/articoli/2024/1…

Wait. Copilot will be taking over alt+space on Windows? That is not okay. How will we access the system menu that has existed since forever containing minimise, maximise, etc.? Also, wtf aren't they just using Windows+c or the Copilot key they forced upon us? theverge.com/2024/12/10/243182…

reshared this

#Catima 2.34.0 is out!

This release adds support for #Passbook (#pkpass) files, commonly used for event tickets and more!

It also contains some other minor fixes and better handling of image thumbnails (especially transparent ones).

On the end-user side, this release probably doesn't look that different, but it contains some major code refactoring. It is also the first release with #Kotlin code in it.

catima.app/

github.com/CatimaLoyalty/Andro…

#IzzyOnDroid #FDroid #GitHub #GooglePlay

Ich habe heute an @thunderbird gespendet #freetheinbox. Macht mit und unterstützt Datenschutz für die Online-Kommunikation. thunderbird.net/donate über @thunderbird updates.thunderbird.net/de/thu…

L'app ufficiale di PeerTube è ora disponibile:

@Che succede nel Fediverso?

All'app mancano molte funzionalità, ma non è colpa degli sviluppatori

framablog.org/2024/12/10/peert…

Il post di @Fedi.Tips 🎄
⬇️

Ich habe, bevor @k9mail von @mozilla für @thunderbird übernommen wurde, immer monatlich über GitHub unterstützt. Da ich k9 weiterhin nutze, ging die Spende dieses Jahr an Mozilla. Das ist echt einfach gemacht in der App, schwupps über G-Pay. Ich konnte endlich mal die Gutscheine einlösen.

Unterstützt Open Source - mich würde auch interessieren was für Chromium Derivate die ganzen Google Hasser nutzen, anstatt Gecko. 🤷

#spende #support #oss

This entry was edited (1 year ago)

China unveils all-terrain SPHERICAL robocops to chase down, bludgeon & catch criminals using net-launching cannons
"...The AI-powered bot beasts are capable of not only stopping crime, but somehow detecting it too."
the-sun.com/tech/13058237/chin…
This entry was edited (1 year ago)

Progresso e battaglie sociali dal microonde all’intelligenza artificiale”. Domani alle 17, con Diletta Huyskes


Sara è una donna, una madre. È disoccupata, single e migrante. La sua è un’identità stratificata, unica e irripetibile, eppure queste caratteristiche sociali la renderanno sospetta per tutta la vita. Perché per un modello matematico – e per il governo del suo paese – Sara è solo un insieme di indicatori che, sommati tra loro, generano un alto punteggio di rischio, una previsione statistica che la trasforma in una potenziale criminale. Ma la sua unica colpa è quella di essere se stessa, e di condividere un profilo simile ad altre persone esistite e accusate prima di lei.


nexa.polito.it/mercoledi-178/

@eticadigitale

A public sector funding initiative should pick up #Mozilla #Firefox and drive it as a community browser indepedent of #Google funding.

A browser is by far the single most impactful gateway to computing resources for people nowadays. (Right after a mobile OS.)

It must not be allowed to fail.

zdnet.com/home-and-office/netw…

#OpenSource #OpenWeb #PublicSector #PublicMoneyPublicCode

in reply to Lars Marowsky-Brée 😷

Without Google, Firefox and most WebKit distributions would lose far more than financing. Several non-Chromium browser components are made by the Chromium team.