Today's threads (a thread)
Inside: Social media needs (dumpster) fire exits; and more!
Archived at: pluralistic.net/2024/12/14/fir…
1/
Today's threads (a thread)
Inside: Social media needs (dumpster) fire exits; and more!
Archived at: pluralistic.net/2024/12/14/fir…
1/
Apple's eventual goal of producing its Apple Glass smart glasses is still a long way from reality, with the challenges of making light and useful eyewear posing a problem. https://appleinsider.Mastodon
/>I do my best to always buy accessible appliances and electronics, but sometimes it's not possible. I had a run-in with one of these inaccessible appliances taccessaces.com
Pitermach reshared this.
It’s another silent, snowy December night within a secret digital den lit by shimmering code-lights and pixel-wreaths. Three infamous Android screenAmir Soleimani (Accessible Android)
Glenn Miller was the swing era's biggest star. Then, he vanished without a trace.apple.news
Important reminder, if you own a domain name and don't use it for sending email.
There is nothing to stop scammers from sending email claiming to be coming from your domain. And the older it gets, the more valuable it is for spoofing. It could eventually damage your domain's reputation and maybe get it blacklisted, unless you take the steps to notify email servers that any email received claiming to come from your domain should be trashed.
Just add these two TXT records to the DNS for your domain:
TXT v=spf1 -all
TXT v=DMARC1; p=reject;
The first says there is not a single SMTP server on earth authorized to send email on behalf of your domain. The second says that any email that says otherwise should be trashed.
If you do use your domain for sending email, be sure to add 3 records:
SPF record to indicate which SMTP server(s) are allowed to send your email.
DKIM records to add a digital signature to emails, allowing the receiving server to verify the sender and ensure message integrity.
DMARC record that tells the receiving email server how to handle email that fails either check.
You cannot stop scammers from sending email claiming to be from your domain, any more than you can prevent people from using your home address as a return address on a mailed letter. But, you can protect both your domain and intended scam victims by adding appropriate DNS records.
UPDATE: The spf and the dmarc records need to be appropriately named. The spf record should be named "@", and the dmarc record name should be "_dmarc".
Here's what I have for one domain.
One difference that I have is that I'm requesting that email providers email me a weekly aggregated report when they encounter a spoof. gmail and Microsoft send them, but most providers won't, but since most email goes to Gmail, it's enlightening when they come.
#cybersecurity #email #DomainSpoofing #EmailSecurity #phishing
This is art. 👌✨
Source: tumblr.com/therinly/7679152519…
CISA just took CVE-2024-11053 from 9.1 all the way down to 3.4!
github.com/cisagov/vulnrichmen…
A repo to conduct vulnerability enrichment. Contribute to cisagov/vulnrichment development by creating an account on GitHub.GitHub
@darakian I don't think it was good to do that thing in the first place. I think the ripple effects of that damage is still to come as news sites and databases will be slow to update.
Also, it was not a "mistake" they "discovered". It was done on purpose and we/I had to waste time and energy correcting it, for the sanity and safety of millions of curl users.
Rude and stupid it was.
@literalgrill paging @Seirdy
You were right bro
RE: sakurajima.moe/@literalgrill/1…
So Bluesky might have provided Jesse Singal with a user's information so that his lawyer could track them down and force them to issue an apology over things said on the platform? Yeah... Kill your bridges, get people over here if you can.Sakurajima (桜島)
Jieshuo screen reader comes in two versions: Jieshuo+ and Jieshuo Lite. The Lite version is sometimes referred to as the "International" version on the GitHubKareen Kiwan (Accessible Android)
With so many great pizza places, there's no need to grab a pie from one that is subpar. Keep an eye out for these signs to ensure you're at the right shop.Jay Wilson (The Daily Meal)
Automakers have been selling data about the driving behavior of millions of people to the insurance industry.
In the case of General Motors, affected drivers weren’t informed, and the tracking led insurance companies to charge some of them more for premiums.
I’m the reporter who broke the story.
I recently discovered that I’m among the drivers who was spied on.
nytimes.com/2024/04/23/technol…
This privacy reporter and her husband bought a Chevrolet Bolt in December. Two risk-profiling companies had been getting detailed data about their driving ever since.Kashmir Hill (The New York Times)
reshared this
Where do I send my invoice?
github.com/cisagov/vulnrichmen…
The security problem this describes is mostly a risk that a user can accidentally stumble upon this. It is VERY hard for an attacker to exploit. "vectorString": "CVSS:3.1/AV:L/AC:H/...GitHub
Provided to YouTube by IDLAInfinitely Light Years · Steven PageExcelsior℗ Fresh Baked Goods IncReleased on: 2022-09-30Producer: Steven PageLead Vocals: Steve...YouTube
#UploadFilter #ResponsibleEncryption - politicians today use euphemisms when they want to break encryption. 🤯
We must keep fighting for our right to privacy! 💪
Learn here why #backdoors to #encryption must never be allowed: tutanota.com/blog/posts/why-a-…
61% of all Tuta emails are sent e2e encrypted - a huge success for privacy. But the authorities want to weaken encryption. We must stop them!Tuta
FYI: CVE-2024-11053 is *not* a critical security flaw, even if now several security related sites repeat that statement.
This is as good as any reminder that you should read the #curl advisories for #curl issues rather than trusting the scaremongers.
curl.se/docs/CVE-2024-11053.ht…
(edit: I wrote an extra '1' in there at first)
daniel:// stenberg:// reshared this.
We added your clarification in vulnerability-lookup.
vulnerability.circl.lu/cve/CVE…
Now I'm wondering if we should not add the ability to propose the author and maintainer to counter any element from a vulnerability description.
@cedric what do you think of it? Not sure how this could be efficiently implemented.
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.vulnerability.circl.lu
I get why it’s important to have an independent severity rating for security flaws. Vendors are incentivized to downplay the severity. Does anybody think Adobe would have appropriately rated even *half* of the bugs in Flash?
But for the independent ratings to be useful, they need to have high quality with extreme consistency. We certainly don’t seem to be getting that.
Apparently #CISA has rated #curl #vulnerability #CVE_2024_11053 as #CVSS v3 Base Score 9.1 "critical". This is wrong, and will lead to automation triggering unnecessary warnings and blocking use of perfectly fine systems until an update is installed (which can take months). nvd.nist.gov/vuln/detail/CVE-2…
Edit: In case you wonder my credentials for judging this: I found this vulnerability.
Edit2: This appears to be originating from CISA: cve.org/Media/News/item/blog/2…
Edit3: The score has now been fixed. Commit: github.com/cisagov/vulnrichmen…
A repo to conduct vulnerability enrichment. Contribute to cisagov/vulnrichment development by creating an account on GitHub.GitHub
Opt-Out von der "dunkelgrünen Schrumpel-Bananen Software" schon vorgenommen?
Elektronische Patientenakte: Sorge vor Verlust von Zeit und Vertrauen
heise.de/meinung/E-Patientenak…
Die "E-Patientenakte für alle" soll ab 2025 durchstarten. Ärzte und Ärztinnen wie unsere Autorin befürchten hohe Aufwände und Vertrauensverlust ihrer Patienten.heise online
"Die "E-Patientenakte für alle" soll ab 2025 durchstarten. Ärzte und Ärztinnen wie unsere Autorin befürchten hohe Aufwände und Vertrauensverlust ihrer Patienten."
Dafür ist es imho doch längst zu spät. Wer nicht völlig verblendet ist, misstraut dem Kram doch eh schon seit längerem.
@Cyb3rrunn3r "Dem Kram" ja, dem Arzt (hoffentlich) noch nicht. Und das ist es, was die Autorin da befürchtet: Verlust des Vertrauensverhältnisses zwischen Arzt und Patient. Patienten haben keine Kontrolle darüber, welche Daten in der Akte landen und was damit passiert – und Ärzte wundern sich, wenn jemand etwas nicht in die Akte eingetragen wissen will…
Für diese Datengier ("aber die (datengetriebene) Wirtschaft!11!") setzt man das also auf's Spiel.
@MrMST wider Erwarten, teilweise ja. Ich bekam erst kürzlich Bescheid, dass dieses tolle Teil ab Januar für mich eingerichtet würde – ohne irgendwelche Aufklärung. Habe also meine Versicherung aufgeklärt. Das (per Fax) zugestellte Opt-Out hatten sie bereits in weniger als 24h eingetragen, auf die schriftliche Bestätigung warte aber nun ich seit 8 Tagen…
Opt-Out ist auf allen Kanälen möglich: Anruf (da hast Du aber nichts in der Hand), Fax, Mail, Web-Formular… Vorsorglich machen.
Microsoft just released a tool that lets you convert Office files to Markdown. Never thought I'd see the day.
Google also added Markdown export to Google Docs a few months ago.
github.com/microsoft/markitdow…
Python tool for converting files and office documents to Markdown. - microsoft/markitdownGitHub
I thought about this, and I think they only did it because there's no way to convert those files back to their original format, not without losing details.
This is probably intended for feeding your documents to an LLM to do RAG on them etc, but it can't be used to collaboratively work on files, which is where the real money for Office is.
A creepy Sora output of the streamer Pokimane shows that despite guardrails, the video generator is good at depicting real-life people.Noor Al-Sibai (Futurism)
Day 15 - #adventOfIOSAccessibility. Touch target sizes are recommended to be at least 44 x 44 points for better usability. Buttons in the navigation bar (especially when not using nav bar button items), dismiss buttons, and custom toolbars, are common examples that often fall below this size.
TIL, Pemerintah Indonesia selepas era orde baru tetap melarang penyebaran paham komunisme karena demokrasi negeri ini berkembang bersama dengan sistem oligarki dan kapitalisme. Karena itulah, ada upaya oleh orang-orang berpaham kapitalisme agar ajaran paham komunisme tidak dapat berkembang di negeri ini.
hukumonline.com/berita/a/kenap…
Catatan: Saya tidak condong atau bahkan mendukung penuh dari salah satu kedua ajaran itu yaa
Walaupun RKUHP membatasi kriminalisasi apabila dilakukan untuk kepentingan ilmu pengetahuan, tidak berarti setiap orang dengan leluasa mempelajarinya, apalagi mengembangkannya.Mulya Sarmono (PT Justika Siar Publika)
David Goldfield reshared this.
BeSTspeech T-T-S speech synthesizer speak window. Contribute to rommix0/BeSTspeak development by creating an account on GitHub.GitHub
Cory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Social media needs (dumpster) fire exits: No one wants to have a fire, but you need to plan for one anyway.
mamot.fr/@pluralistic/11365208…
2/
Cory Doctorow (@pluralistic@mamot.fr)
Mamot - Le Mastodon de La Quadrature du NetCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Hey look at this
* It's Time to Break Up Big Medicine thebignewsletter.com/p/its-tim…
* 'Kids for Cash' Judge has sentence commuted by President Biden wnep.com/article/news/investig…
* I have a cunning plan ... antipope.org/charlie/blog-stat…
3/
It's Time to Break Up Big Medicine
Matt Stoller (BIG by Matt Stoller)Cory Doctorow
in reply to Cory Doctorow • • •Sensitive content
#20yrsago Advertising techniques that Web-users hate nngroup.com/articles/most-hate…
#20yrsago Haunted Mansion’s cobwebbing-and-griming regimen web.archive.org/web/2004121611…
#15yrsago Danish police abuse climate-change demonstrators web.archive.org/web/2009121506…
#15yrsago Three strikes law reintroduced in New Zealand memex.craphound.com/2009/12/15…
#15yrsago SFPD won’t investigate hit-and-run car-v-bike accident web.archive.org/web/2009122011…
4/
The Most Hated Online Advertising Techniques
Therese Fessenden (Nielsen Norman Group)Cory Doctorow
in reply to Cory Doctorow • • •Sensitive content
#15yrsago Comical legal case names kevinunderhill.typepad.com/low…
#10yrsago Photographer beaten, detained in London for being “cocky” to policeman who implies she is a terrorist youtube.com/watch?v=GAs4gZY1br…
#10yrsago HOWTO: Make glue-gun sticks out of sugar for building gingerbread houses memex.craphound.com/2014/12/15…
#10yrsago New York City’s worst landlords web.archive.org/web/2014121601…
#10yrsago Macedonia helped CIA kidnap and torture a German they mistook for a terrorist thelocal.de/20141210/cia-tortu…
5/
CIA tortured German it mistook for a terrorist
DPA/The Local (The Local Germany)Cory Doctorow
in reply to Cory Doctorow • • •Sensitive content
#10yrsago Why it matters whether or not torture works theatlantic.com/health/archive…
#5yrsago Spain’s Xnet: leak-publishing corruption-fighters smh.com.au/world/spains-wikile…
#5yrsago DRM screws blind people wired.com/2014/12/e-books-for-…
#1yrago It all started with a mouse pluralistic.net/2023/12/15/mou…
6/
The Humane Interrogation Technique That Actually Works
Olga Khazan (The Atlantic)Cory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Yesterday's threads: The GOP is not the party of workers; and more!
mamot.fr/@pluralistic/11364721…
7/
Cory Doctorow (@pluralistic@mamot.fr)
Mamot - Le Mastodon de La Quadrature du NetCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
My latest nationally bestselling novel is "The Bezzle," an ice-cold revenge story of high-tech finance crime starring the forensic accountant Martin Hench:
us.macmillan.com/books/9781250…
Signed copies from Chevalier's Books:
chevaliersbooks.com/product-pa…
--
My latest nonfiction book is "The Internet Con: How to Seize the Means of Computation" from Verso Books:
seizethemeansofcomputation.org
Signed copies available from Book Soup:
booksoup.com/book/978180429124…
Both are national bestsellers!
8/
Book details - Macmillan Publishers
MacmillanCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
My ebooks and audiobooks (from Tor Books, Head of Zeus, McSweeneys, Beacon, Verso and others) are for sale all over the net, but I sell 'em too, and when you buy 'em from me, I earn twice as much and you get books with no DRM and no license "agreements."
craphound.com/shop/
9/
Shop | Cory Doctorow's craphound.com
craphound.comCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Upcoming appearances:
* Should a Public Telecom Be An Election Issue/Davenport NDP (Remote), Dec 15
davenportndp.ca/public_telecom…
* ISSA-LA Holiday Celebration keynote (Los Angeles), Dec 18
issala.org/event/issa-la-decem…
* Picks and Shovels with Charlie Jane Anders (Menlo Park), Feb 17
keplers.org/upcoming-events-in…
* Picks and Shovels with Wil Wheaton (Los Angeles), Feb 18
dieselbookstore.com/event/Cory…
* Picks and Shovels with Dan Savage (Seattle), Feb 19
eventbrite.com/e/cory-doctorow…
10/
December 18 ISSA-LA, AITP, CSA, ISC2, and WSC Holiday Celebration
Information Systems Security Association - Los AngelesCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Upcoming appearances:
* Should a Public Telecom Be An Election Issue/Davenport NDP (Remote), Dec 15
davenportndp.ca/public_telecom…
* ISSA-LA Holiday Celebration keynote (Los Angeles), Dec 18
issala.org/event/issa-la-decem…
* Picks and Shovels with Charlie Jane Anders (Menlo Park), Feb 17
keplers.org/upcoming-events-in…
* Picks and Shovels with Wil Wheaton (Los Angeles), Feb 18
dieselbookstore.com/event/Cory…
* Picks and Shovels with Dan Savage (Seattle), Feb 19
eventbrite.com/e/cory-doctorow…
11/
December 18 ISSA-LA, AITP, CSA, ISC2, and WSC Holiday Celebration
Information Systems Security Association - Los AngelesCory Doctorow
in reply to Cory Doctorow • • •Sensitive content
Recent appearances:
* Can we avoid the enshittification of clean-energy tech? (Volts.wtf)
volts.wtf/p/can-we-avoid-the-e…
* Enshittification: Why Everything Suddenly Got Worse and What to Do About It (HOPE XV)
youtube.com/watch?v=YrciT_dc2s…
* How To Keep IoT From Becoming An IoTrash (@defcon)
youtube.com/watch?v=tA7bpp8qXx…
12/
Can we avoid the enshittification of clean-energy tech?
David Roberts (Volts)