Long-lost chat with John Lennon to be broadcast by the BBC
A long-lost chat with John Lennon is to be broadcast by the BBC tonight for the first time in more than fifty yearsRoy Martin (RadioToday)
A long-lost chat with John Lennon is to be broadcast by the BBC tonight for the first time in more than fifty yearsRoy Martin (RadioToday)
Age of the Racecar Driver Stevey's Drunken Blog Rants™ I have an absolutely fascinating interview story to tell you. The other day I phone-screened a guy who claimed he has an undergrad degree in Computer Science from a high-profile school.sites.google.com
@esoteric_programmer As for this:
> egui has unpatched holes when it comes to edit boxes and afew other things
Please say more. I did the egui AccessKit integration, and developed it together with AccessKit's text support, so I need to know what's missing or broken.
Deciphering Glyph, the blog of Glyph Lefkowitz.blog.glyph.im
@TheQuinbox AFAIK, that's not how .NET works any more.
With .NET core, you distribute the (potentially stripped) framework with your app.
@TheQuinbox You're not wrong.
I wonder how good the built-in web engines of modern OSes are at this point; I looked at this a few years ago, but MS still shipped trident with some Windows versions back then.
This way, you could do something very similar to Electron, but without actually shipping a runtime.
I feel like the situation around desktop app development is just sad as hell. Win32 isn't a panacea any more, even if you're willing to put in the work, as it apparently looks quite dated by now, from what sighted people have told me. AppKit is slowly getting abandoned in favor of SwiftUI and Catalyst, and they both suck, so the situation on that front isn't much better.
@TheQuinbox I feel like doing this in 2024 is just asking for an RCE, though.
If you're religious about only running your own code, no scripts loaded from a CDN, no Google Analytics, no way to accidentally go to an external domain, an UI framework instead of rawdogging the DOM to ensure no XSS, maaaybe, just maybe.
On iPhone, listening to YouTube audio in the background usually requires paying for a YouTube Premium subscription, but there is a simple workaround...MacRumors.com
Catholic #priest in Belarus sentenced to 11 years - for criticising the government, as crackdown tightens
In the first case of politically-driven charges against #Catholic clergy since #Belarus became independent after the Soviet Union collapsed in 1991.
euronews.com/2024/12/30/cathol…
'The harsh sentence is intended to intimidate and silence hundreds of other priests ahead of January's presidential election,' human rights activist Pavel Sapelka said.Daniel Bellamy (Euronews.com)
See Vatican News to discover the life-story and message of St. Sylvester I, Pope, the Saint of the Day 31 Decemberwww.vaticannews.va
Hiermit sind jetzt auch die letzten Bilder vom Congress online. Insgesamt 214 Bilder :) Viel Spaß damit! #38C3
A new study offers hope for people who are blind or have low vision (pBLV) through an innovative navigation system that was tested using virtual reality.ScienceDaily
Apparently Musk fired US workers and replaced some of them with H1B visa holders, at lower salaries.
electrek.co/2024/12/30/tesla-r…
Tesla has replaced some of its US employees who were let go as part of a big wave of layoffs...Fred Lambert (Electrek)
Falls ihr noch etwas Geld zum Jahresende übrig habt, denkt daran an eure liebsten Open-Source-Projekte zu spenden.
Bei mir sind dieses Jahr geworden:
– StreetComplete (streetcomplete.app/)
– DAVx5 @davx5app
– tchncs.de @milan
– F-Droid @fdroidorg
Thank you for being a part of our journey. Here’s to another impactful year ahead! 🌟Editorial Staff (Accessible Android)
@Tusky how (if?) can I favourite languages in the toot-specific language selector?
The amount of languages I can write and thus realistically toot in is limited and thus easier to select than always scrolling to the language.
The route is the first directly linking the two capitals' city centres.Angela Symons (Euronews.com)
Úsměv na rtu, dobrou kartu,
k tomu dobrých lidí partu.
Zdraví, štěstí, hodně lásky,
žádnou starost, žádné vrásky!
Šťastné vykročení do nového roku vám všem, přátelé!🤞🍀🥂
I když naše cesty někdy vedou do neznáma, věřím, že za mlhou nejistoty svítí sluníčko každému. ♥️
#PF
"AntennaPod, en god, gratis podcast-afspiller til Android." Og hvordan man lytter til DR podcasts.
internetforbrugeren.dk/lyt-til…
Podcasts er (snakke)radioudsendelser du (typisk) lytter til med en særlig app på din mobil. AntennaPod er et af de bedre programmer.Internetforbrugeren
"Handing the reins to Harris in July, rather than sticking it out, wasn’t one of his mistakes. His mistake was that he didn’t do so sooner."
New from @wsaletan on the fantasy that Biden would have beaten Trump: thebulwark.com/p/biden-world-h…
The question is not whether he should have dropped out. It’s why he didn’t do so earlier.Will Saletan (The Bulwark)
🔐 Chcete více soukromí? Čím nahradit služby od Googlu, Applu, Mety a dalších?
Actor Tom Baker has been honoured by King Charles with a Member of the Order of the British Empire (MBE) award for services to television. The 90-year-old actor was chosen along with other recipients as part of the New Year Honours.Andrea Laford (CultBox)
China’s demo reactor could breed nuclear fuel from rare earth wasteEmily Waltz (IEEE Spectrum)
John @tuckner sent me on an interesting wild goose chase. He is investigating the Cyberhaven extension compromise, trying to find out more. And he found something that he considered another campaign compromising browser extensions, related to the sclpfybn[.]com domain: secureannex.com/blog/sclpfybn-…
Edit: Just to make sure this is clear: so far there is little indication that these two campaigns are somehow related. Both being present in one extension was most likely a coincidence.
One of the extensions that used to contain the code in question was Visual Effects for Google Meet – which brought him to me because I recently covered that extension in my Karma Connection article: palant.info/2024/10/30/the-kar…
I checked my data but couldn’t find sclpfybn[.]com domain mentioned in any extensions other than the ones @tuckner found already. I then looked for similar code and immediately found it in Urban VPN Proxy.
First thought: Urban VPN Proxy has the legitimate version of a library that was trojanized elsewhere. Taking a look at the communication of Urban VPN Proxy disproved that theory almost immediately – not only was it communicating in exactly the same way, but also to an unknown domain, namely ducunt[.]com. Yet the same endpoint existed on the official urban-vpn[.]com domain as well.
So not only did Urban VPN Proxy contain essentially the same code, it was likely added there by the developers themselves. Further investigation increased the suspicion that all these extensions haven’t been compromised, that this was rather some monetization SDK.
At which point @tuckner found the sales pitch for that SDK, detailing how it would add ad blocking functionality to the extension at the cost of exfiltrating very detailed browsing data (of course anonymized and aggregated before being sold to everyone asking for it, we know the drill). And explanations on how to make sure Google won’t object.
And that explains it all: before the Visual Effects for Google Meet developer sold their extension to Karma, they tried to monetize it with this “ad blocking library.” The sales pitch doesn’t mention who develops the library but everything points to Urban VPN.
According to Urban VPN privacy policy, they are selling the data they collect from their users via BIScience Ltd. Who are most likely the hidden owners of Urban Cyber Security Inc., a company registered to a virtual address in the USA.
Edit: Updated link to Tuckner’s blog post, he split it away from the original investigation.
A bunch of malicious extensions in Chrome Web Store have hidden affiliate fraud functionality, collect users’ browsing profiles, or both. These extensions appear to be connected to the Karma shopping assistant, developed by Karma Shopping Ltd.Almost Secure
In other words, screw pedestrians, especially blind and other disabled people!
Waymo robotaxis, which are now ubiquitous in parts of CA, will often not stop for pedestrians using crosswalks there, unless a pedestrian is far into the road.
Here are our favorite JavaScript-based web content management systems. They are all free and open source software.Steve Emms (LinuxLinks)
Another great podcast episode from @RyanAndrosoff this time with Andres Raieste from Estonia.
This is the second podcast from this year's #FWD50 conference in Ottawa. I would definitely recommend that folks in government listen to Trust is Everything | Ep 27
I liked the line about the importance of demonstrating incremental improvements. Starting with the tax department is also interesting.
youtube.com/watch?v=FzbyuwzRcr…
#Estonia #DigitalTransformation #Government #Trust #LetsThinkDigital
Trust is everything. It’s clear we’re in a moment in time where people do not trust their governments. There is skepticism about the impact of big technology...YouTube
#NCP
A reminder, a week on after this news broke, if you have the HONEY browser extension from PAYPAL installed, you should uninstall it immediately and delete all its cookies.
The extension + app owners
- does NOT find you the best coupons
- does backroom deals with big retailers to drive conversions, with less discounts
- steal(s) from creators
- harvests your data for resale and manipulation
- is classified as malware
Full details here (nb, the youtube display may not work because Youtube is actively blocking their cards / videos from displaying on Mastodon because of the MastoDDos effect)
Was Honey a legitimate money saving tool? Or just an affiliate marketing scam promoted by some of YouTube's biggest influencers?If you have any inside inform...YouTube
A look back, a look ahead: How was 2024 at IzzyOnDroid? What might 2025 bring you there, what are we working on?
android.izzysoft.de/articles/n…
And if anybody ever tells you #security or #reproducibleBuilds are "set-and-forget", laugh straight into their faces. Software evolves, and so do their threats and risks…
German readers: Die Deutsche Version folgt in Kürze…
2024 waves goodbye, 2025 knocks at the door: what did we achieve in 2024, and what are our plans and hopes for 2025? Join us to take a look back at security measures established, at progress with Reproducible Builds – and for a look ahead of what mig…IzzyOnDroid
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 reshared this.
Jetzt ist auch die deutschsprachige Version unseres "Jahresberichts" online:
Ein Blick zurück, ein Blick voraus: Wie war 2024 bei #IzzyOnDroid? Was mag Euch 2025 hier bringen, woran arbeiten wir?
android.izzysoft.de/articles/n…
Und wenn Euch jemand sagt, #security oder #reproducibleBuilds wären (einmal aufgesetzt) reine Selbstläufer: Lacht sie laut aus. Software entwickelt sich weiter – und so auch ihre Risiken und Threats…
2024 winkt zum Abschied, 2025 klopft an die Tür: Was haben wir 2024 erreicht, und was sind unsere Pläne und Hoffnungen für 2025? Werft mit uns einen Blick zurück auf die eingeführten Sicherheitsmaßnahmen, auf die Fortschritte bei Reproducible Builds …IzzyOnDroid

As announced with our plans for 2025, here are the long awaited download stats for #IzzyOnDroid
codeberg.org/IzzyOnDroid/iodst…
Anyone going to write a front-end for visualization (e.g. a web page)? 
Angela2000
in reply to David Goldfield • • •David Goldfield
in reply to Angela2000 • • •