December 31, 2024 – iPhone 17 rumors, iPhone in the EU
Listen to a recap of the top stories of the day from 9to5Mac. 9to5Mac Daily is available on iTunes and Apple’s Podcasts...Seth Kurkowski (9to5Mac)
Listen to a recap of the top stories of the day from 9to5Mac. 9to5Mac Daily is available on iTunes and Apple’s Podcasts...Seth Kurkowski (9to5Mac)
Happy new year from Dionysos 😄
#winter #frost #image #nature #WinterGarden #bloomscrolling #ivy #plants #Dionysus
GitHub has a problem with inauthentic "stars" used to artificially inflate the popularity of scam and malware distribution repositories to appear more popular, helping them reach more unsuspecting users.
Sometimes I have suggested that OSMAND is a quite useful tool, among other things to move cycling (as it is based in OpenStreetMap and besides being free it is much better than GMaps when cycling, walking, hiking, etc.). But i want to suggest two useful tools:
1) A link to OpenStreetMap showing it as CyclOSM: openstreetmap.org/#map=16/37.6…
OpenStreetMap is a map of the world, created by people like you and free to use under an open license.OpenStreetMap
2) And sometimes i found useful to have maps like this showing only bicycle parkings characteristics (represented as 🔵 in the previous one): mapcomplete.org/bicycle_parkin…
It is more intended to edit map (have you an OSM account you can help mapping them or uploading pictures) but I think it is also useful to be used. There are many other different thematic maps in @MapComplete
Another day I will also show and link how to have an offline CyclOSM-like style in OSMAnd.
A long-lost chat with John Lennon is to be broadcast by the BBC tonight for the first time in more than fifty yearsRoy Martin (RadioToday)
Age of the Racecar Driver Stevey's Drunken Blog Rants™ I have an absolutely fascinating interview story to tell you. The other day I phone-screened a guy who claimed he has an undergrad degree in Computer Science from a high-profile school.sites.google.com
@esoteric_programmer As for this:
> egui has unpatched holes when it comes to edit boxes and afew other things
Please say more. I did the egui AccessKit integration, and developed it together with AccessKit's text support, so I need to know what's missing or broken.
Deciphering Glyph, the blog of Glyph Lefkowitz.blog.glyph.im
@TheQuinbox AFAIK, that's not how .NET works any more.
With .NET core, you distribute the (potentially stripped) framework with your app.
@TheQuinbox You're not wrong.
I wonder how good the built-in web engines of modern OSes are at this point; I looked at this a few years ago, but MS still shipped trident with some Windows versions back then.
This way, you could do something very similar to Electron, but without actually shipping a runtime.
I feel like the situation around desktop app development is just sad as hell. Win32 isn't a panacea any more, even if you're willing to put in the work, as it apparently looks quite dated by now, from what sighted people have told me. AppKit is slowly getting abandoned in favor of SwiftUI and Catalyst, and they both suck, so the situation on that front isn't much better.
@TheQuinbox I feel like doing this in 2024 is just asking for an RCE, though.
If you're religious about only running your own code, no scripts loaded from a CDN, no Google Analytics, no way to accidentally go to an external domain, an UI framework instead of rawdogging the DOM to ensure no XSS, maaaybe, just maybe.
On iPhone, listening to YouTube audio in the background usually requires paying for a YouTube Premium subscription, but there is a simple workaround...MacRumors.com
Catholic #priest in Belarus sentenced to 11 years - for criticising the government, as crackdown tightens
In the first case of politically-driven charges against #Catholic clergy since #Belarus became independent after the Soviet Union collapsed in 1991.
euronews.com/2024/12/30/cathol…
'The harsh sentence is intended to intimidate and silence hundreds of other priests ahead of January's presidential election,' human rights activist Pavel Sapelka said.Daniel Bellamy (Euronews.com)
See Vatican News to discover the life-story and message of St. Sylvester I, Pope, the Saint of the Day 31 Decemberwww.vaticannews.va
Hiermit sind jetzt auch die letzten Bilder vom Congress online. Insgesamt 214 Bilder :) Viel Spaß damit! #38C3
A new study offers hope for people who are blind or have low vision (pBLV) through an innovative navigation system that was tested using virtual reality.ScienceDaily
Apparently Musk fired US workers and replaced some of them with H1B visa holders, at lower salaries.
electrek.co/2024/12/30/tesla-r…
Tesla has replaced some of its US employees who were let go as part of a big wave of layoffs...Fred Lambert (Electrek)
Falls ihr noch etwas Geld zum Jahresende übrig habt, denkt daran an eure liebsten Open-Source-Projekte zu spenden.
Bei mir sind dieses Jahr geworden:
– StreetComplete (streetcomplete.app/)
– DAVx5 @davx5app
– tchncs.de @milan
– F-Droid @fdroidorg
Thank you for being a part of our journey. Here’s to another impactful year ahead! 🌟Editorial Staff (Accessible Android)
@Tusky how (if?) can I favourite languages in the toot-specific language selector?
The amount of languages I can write and thus realistically toot in is limited and thus easier to select than always scrolling to the language.
The route is the first directly linking the two capitals' city centres.Angela Symons (Euronews.com)
Úsměv na rtu, dobrou kartu,
k tomu dobrých lidí partu.
Zdraví, štěstí, hodně lásky,
žádnou starost, žádné vrásky!
Šťastné vykročení do nového roku vám všem, přátelé!🤞🍀🥂
I když naše cesty někdy vedou do neznáma, věřím, že za mlhou nejistoty svítí sluníčko každému. ♥️
#PF
"AntennaPod, en god, gratis podcast-afspiller til Android." Og hvordan man lytter til DR podcasts.
internetforbrugeren.dk/lyt-til…
Podcasts er (snakke)radioudsendelser du (typisk) lytter til med en særlig app på din mobil. AntennaPod er et af de bedre programmer.Internetforbrugeren
"Handing the reins to Harris in July, rather than sticking it out, wasn’t one of his mistakes. His mistake was that he didn’t do so sooner."
New from @wsaletan on the fantasy that Biden would have beaten Trump: thebulwark.com/p/biden-world-h…
The question is not whether he should have dropped out. It’s why he didn’t do so earlier.Will Saletan (The Bulwark)
🔐 Chcete více soukromí? Čím nahradit služby od Googlu, Applu, Mety a dalších?
Actor Tom Baker has been honoured by King Charles with a Member of the Order of the British Empire (MBE) award for services to television. The 90-year-old actor was chosen along with other recipients as part of the New Year Honours.Andrea Laford (CultBox)
China’s demo reactor could breed nuclear fuel from rare earth wasteEmily Waltz (IEEE Spectrum)
John @tuckner sent me on an interesting wild goose chase. He is investigating the Cyberhaven extension compromise, trying to find out more. And he found something that he considered another campaign compromising browser extensions, related to the sclpfybn[.]com domain: secureannex.com/blog/sclpfybn-…
Edit: Just to make sure this is clear: so far there is little indication that these two campaigns are somehow related. Both being present in one extension was most likely a coincidence.
One of the extensions that used to contain the code in question was Visual Effects for Google Meet – which brought him to me because I recently covered that extension in my Karma Connection article: palant.info/2024/10/30/the-kar…
I checked my data but couldn’t find sclpfybn[.]com domain mentioned in any extensions other than the ones @tuckner found already. I then looked for similar code and immediately found it in Urban VPN Proxy.
First thought: Urban VPN Proxy has the legitimate version of a library that was trojanized elsewhere. Taking a look at the communication of Urban VPN Proxy disproved that theory almost immediately – not only was it communicating in exactly the same way, but also to an unknown domain, namely ducunt[.]com. Yet the same endpoint existed on the official urban-vpn[.]com domain as well.
So not only did Urban VPN Proxy contain essentially the same code, it was likely added there by the developers themselves. Further investigation increased the suspicion that all these extensions haven’t been compromised, that this was rather some monetization SDK.
At which point @tuckner found the sales pitch for that SDK, detailing how it would add ad blocking functionality to the extension at the cost of exfiltrating very detailed browsing data (of course anonymized and aggregated before being sold to everyone asking for it, we know the drill). And explanations on how to make sure Google won’t object.
And that explains it all: before the Visual Effects for Google Meet developer sold their extension to Karma, they tried to monetize it with this “ad blocking library.” The sales pitch doesn’t mention who develops the library but everything points to Urban VPN.
According to Urban VPN privacy policy, they are selling the data they collect from their users via BIScience Ltd. Who are most likely the hidden owners of Urban Cyber Security Inc., a company registered to a virtual address in the USA.
Edit: Updated link to Tuckner’s blog post, he split it away from the original investigation.
A bunch of malicious extensions in Chrome Web Store have hidden affiliate fraud functionality, collect users’ browsing profiles, or both. These extensions appear to be connected to the Karma shopping assistant, developed by Karma Shopping Ltd.Almost Secure
Bubu
in reply to Karl Fredrik 🦊 🔜 39c3 📞QFOX • • •