Want to try a new distributor ? Nothing to setup, you just need to open the app and grant the requested permissions. It follows the last version of the UnifiedPush specifications: Sunup !
IzzyOnDroid ✅ reshared this.
Want to try a new distributor ? Nothing to setup, you just need to open the app and grant the requested permissions. It follows the last version of the UnifiedPush specifications: Sunup !
IzzyOnDroid ✅ reshared this.
Now that 2025 is here, it's time to wind down the #osspodcast
It was a fun run, but it was time to be done.
I have a new project I'm calling "Open Source Security" (the domain is too good to not do something with it)
I want to chat with people securing the use and creating of open source. I explain a lot more in the blog post (which also has audio)
If you're one of these people, let me know! There are a lot of lessons for us all, and the people doing the best work aren't being listened to
opensourcesecurity.io/posts/20…
https://traffic.libsyn.com/opensourcesecuritypodcast/2025-01-the_future_of_open_source_security.mp3 It’s a new year and time for some changes to the opensourcesecurity.io website.Josh Bressers (Open Source Security)
thanks for a lovely podcast, it was great!
You know where I am if I can assist.
Ten Things I’m Carrying into the New Year
1. The understanding that no one is coming to save me—and that’s empowering.
2. The quiet truth that my happiness is my responsibility.
3. The commitment to meet my own expectations before worrying about anyone else’s.
4. The ability to let go without needing to replace.
5. The patience to be where I am instead of rushing where I’m going.
6. The freedom to say no to anything that doesn’t feel like care.
7. The practice of asking, “What does the world need from me right now?”
8. The joy of loving something without needing to own it.
9. The joy of realizing that the best days weren’t meant to last forever—they’re meant to be remembered.
10. The realization that my inner voice should sound like someone who loves me.
Happy New Year, friends!
A year ago I blogged about the AI slop increase in bug and security reporting:
daniel.haxx.se/blog/2024/01/02…
It has only gotten worse since then, but I wouldn't call it a serious problem just yet. The trajectory does not look good though.
I have held back on writing anything about AI or how we (not) use AI for development in the curl factory. Now I can't hold back anymore. Let me show you the most significant effect of AI on curl as of today - with examples.daniel.haxx.se
This dumb password rule is from Xfinity Modem.
Only letters and numbers are valid. No spaces or special characters.
Seen on model TG3482G. ARRIS Group, Inc. Firmware: TG3482PC2_3.5p17s1_PROD_sey
dumbpasswordrules.com/sites/xf…
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Only letters and numbers are valid. No spaces or special characters. Seen on model TG3482G. ARRIS Group, Inc. Firmware: TG3482PC2_3.5p17s1_PROD_seydumbpasswordrules.com
✨ Uf, trochu bylo delší to vlákno! ✨
Tak snad vám to nevadilo.
Pokud jste to nestihli celé, nebo se k němu chcete kdykoliv vrátit, vlákno je připnuté na mém profilu. 🎯
🔗 Mrkněte na připnutý příspěvek.
mastodon.arch-linux.cz/@archos…
🧵 1/15
🌟 I v roce 2025 můžete používat naše aplikace na OSCloud @oscloud! 🌟
🔍 Naše hlavní aplikace:
👉 Talk: Videohovory přímo z prohlížeče – talk.oscloud.cz
👉 MxChat: Bezpečný chat založený na Matrixu – mxchat.cz
👉 CryptPad: Soukromá kancelář pro spolupráci – cryptpad.arch-linux.cz
👉 Mastodon: Naše instance pro otevřenou komunikaci – mamutovo.cz
👉 Pixelfed: Sdílení fotografií – pixelfed.cz
👉 Vikunja: Všechny vaše úkoly na jednom místě – todo.oscloud.cz
👉 Wallabag: Ukládání článků na později – read.oscloud.cz
👉 Tiny Tiny RSS: Sledujte novinky s vlastní RSS čtečkou – rss.oscloud.cz
👉 PairDrop: Sdílení souborů bez cloudových úložišť – pair.oscloud.cz
👉 SearXNG: Anonymní vyhledávání – searxng.cz
👉 PeerTube: Svobodné sdílení videí – vhsky.cz
👉 Bitwarden: Bezpečný správce hesel – bitwarden.archoslinux.cz
👉 Nextcloud: Cloudové úložiště s OnlyOffice – oscloud.cz
👉 PrivateBin: Sdílení šifrovaných poznámek – privatebin.arch-linux.cz
👉 HedgeDoc: Spolupráce na dokumentech v reálném čase – hedgedoc.arch-linux.cz
📢 Na co se můžete těšit?
Brzy přidáme s @cynik_obecny další služby, které rozšíří možnosti OSCloud. Již dnes ale můžete využít:
✨ Fórum pro diskuse a podporu komunity.
📸 Aplikace pro fotografy jako Piwigo, Immich a Lychee – ideální pro ukládání a sdílení vašich fotografií.
🌐 Webhosting pro vaše stránky a projekty – od WordPressu po statické weby.
🏡 To vše na vaší vlastní doméně!
🔐 Bezpečnost na prvním místě:
Všechny naše aplikace provozujeme na dedikovaném serveru u společnosti Hetzner. Přístup k serveru máme pouze my, takže vaše data jsou v bezpečí.
📋 Vše na jednom místě:
U nás máte všechny služby aktuální a přehledně na jednom místě díky OSCloud dashboardu.
Pro registraci stačí napsat na helpdesk.oscloud.cz/help/30202…
📢 V tomto vlákně si jednotlivé aplikace představíme!
🔐 OSCloud: Ochrana soukromí, otevřený software a bezpečnost na prvním místě.
Emailová adresa hepldesk@oscloud.cz
nefunguje.
Při reply z Gmailu dostanu:
The response from the remote server was:
550 No such address
vše funguje, jen jsem nevěděl kam napsat, že se mi vrací email, když jsem posílal odpověď.
Jen jsem chtěl v emailu potvrdit, že jsem se přihlásil do obou služeb.
Díky.
*È stata rilasciata la nuova versione stabile di Friendica "Interrupted Fern" 2024.12*
@fediverso@a.gup.pe
poliverso.org/display/0477a01e…
È stata rilasciata la nuova versione stabile di Friendica "Interrupted Fern" 2024.12@Che succede nel Fediverso?Siamo molto lieti di annunciare la disponibilità della nuova versione stabile di Friendica "Interrupted Fern" 2024.12. Oltre a diversi miglioramenti e nuove funzionalità, questa versione contiene la correzione
*È stata rilasciata la nuova versione stabile di Friendica "Interrupted Fern" 2024.12* @Che succede nel Fediverso? > Siamo molto lieti di annunciare la dis...poliverso.org
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
Enjoy a more flexible outlet array with this surge protector power strip.Ingrid Cruz (CNET)
Accessibility Jan-Mar Assistive Technology Industry Association ATiA (Orlando/virtual) Axe-con (virtual) ZeroCon (Vienna) CSUN Assistive Technology (California) TechAccess Oklahoma (Oklahoma/virtual) Microsoft Ability Summit (Alabama/virtual) Busines…Kate Kalcevich (www.linkedin.com)
The online hub launching next year will offer practical courses on how to deliver high-quality instruction to students who are blind or low vision.Emily Piper-Vallillo (WBUR)
"Zero drag queens have been arrested in Tennessee this year for raping or sexually abusing children.
Over 30 faith leaders have. wsmv.com/2023/09/20/evangelist… "
reshared this
I have spent a week writing a massive article about Windows 2. It has sexy screenshots and is full of incredible trivia. Why not spend the New Year's Eve reading it? ;)
On this day in 1983, the ARPANET network officially switched to using the TCP/IP protocol, effectively creating the Internet.
"January 1, 1983 is considered the official birthday of the Internet. Prior to this, the various computer networks did not have a standard way to communicate with each other."
I am here to announce that I have decreased #spam on my web contact form from 1 message every 15 minutes (for months straight) to 0 messages in the last week by adding a "I am a spam bot" radio button.
I am not joking.
No I am not using something like ReCaptcha, I literally just added a radio button to the list.
The world's richest man sparks speculation after changing his name and using a picture of Pepe the Frog.apple.news
🔴 Happy Public Domain Day!
Popeye, ‘Rhapsody in Blue,’ ‘The Sound and the Fury’ and Thousands of Other Captivating Creations Are Finally Free for Everyone to Use
by Ellen Wexler at @Smithsonianmag
#PublicDomain #Tintin #FarewellToArms #Popeye
smithsonianmag.com/smart-news/…
On January 1, 2025, copyrights will expire for books, films, comic strips, musical compositions and other creative works from 1929, as well as sound recordings from 1924Ellen Wexler (Smithsonian Magazine)
A look at what I have in my Blind Tech Setup 2025. What hhave I stopped using, what have I added? Did I stick with the Mac?Tim Dixon (TIM DIXON)
Several iconic characters from 1929 are headed to the public domain this year, including the earliest versions of Popeye and Tintin.Emma Roth (The Verge)
On December 10, 2024, Google TTS, officially branded as Speech Recognition & Synthesis on the Play Store, rolled out its latest update:Amir Soleimani (Accessible Android)
#AndroidAppRain at apt.izzysoft.de/fdroid today brings you 6 updated and 4 added apps:
* Fossify Paint: the 15th app in the Fossify collection 🛡️
* Memorize Your Classics: Memorize poems, songs, etc. 🛡️
* Habit-Maker: a reward-based habit tracker 🛡️
* Close Circuit: create a PAN surveillance system using WiFi IP Webcams 🛡️
RB status: 383 apps (31.1%)
Enjoy your #free #Android #apps with the #IzzyOnDroid repo 
1/2
This is a repository of apps to be used with your F-Droid client. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
2/2
apt.izzysoft.de/magisk had 1 #Magisk module added, now serving 125 modules altogether:
* DisableFPSLimit: turns VSync off to allow the maximum FPS your device can reach
Enjoy your #free #Android #apps with the #IzzyOnDroid repo 
This is a repository of open-source Magisk modules run by IzzyOnDroid.IzzyOnDroid App Repo
Thank you for being a part of our journey. Here’s to another impactful year ahead! 🌟Editorial Staff (Accessible Android)
I have published the 2024 Security and Privacy Canary.
Motherfucking religious fanatical barbarians.
Religion kills and erases women.
"Taliban bans windows to stop women from being seen at home"
independent.co.uk/asia/south-a…
Buildings should not have windows looking into places where women could be sitting or standing, Taliban leader ordersMaya Oppenheim (The Independent)
An Algol 68 front end for GCC
I conservatori critici nei confronti di Elon Musk accusano la piattaforma da lui gestita di censurarli, riporta la CNN .
L'attivista politica Laura Loomer ha scatenato un dibattito online all'interno della destra sui visti di lavoro noti come H-1B, che Musk sostiene. Loomer ora sostiene che il suo account è stato non verificato e demonetizzato, accusando Musk di essere una "frode della libertà di parola".
techcrunch.com/2024/12/31/elon…
Conservative activists claim X is censoring them for being critical of its owner, Elon Musk.Charles Rollet (TechCrunch)
Khronos reshared this.
Khronos reshared this.
An update on the latest legal accessibility developments. Learn about the Wilkins v. Starbucks case and its impact on website accessibility.Ken Nakata (Converge Accessibility LLC)
These foods boast blood sugar-leveling macronutrients like fiber, protein, and healthy fats to keep sugar cravings to a minimum.Julie Upton (Eat This Not That)
Khronos reshared this.
UnifiedPush
in reply to UnifiedPush • • •UnifiedPush
in reply to UnifiedPush • • •Regarding Matrix, a workaround has been implemented until webpush is supported by their specifications. Element-X has a patch going on to fix the default gateway (but Schildinext works), all other clients already supporting UnifiedPush should work
#Matrix #Element #Schildichat
charlag
in reply to UnifiedPush • • •UnifiedPush
in reply to charlag • • •shadowwwind
in reply to UnifiedPush • • •Really awesome!
UnifiedPush
in reply to shadowwwind • • •IzzyOnDroid ✅
in reply to UnifiedPush • • •And to make finding, installing and updating easier, Sunup will become available at #IzzyOnDroid with the next sync around 7 pm. Congrats @unifiedpush – it has the "green shield up", meaning it's reproducible
But if you could get rid of that DEPENDENCY_INFO_BLOCK (a binary blob), that would be great. Easy to do, reach out to us for instructions, which do not fit into a toot – but wait, there are attachments, right? So for your build.gradle, see screenshot.
#reproducibleBuilds
UnifiedPush reshared this.
S1m
in reply to IzzyOnDroid ✅ • • •S1m
in reply to S1m • • •@IzzyOnDroid There is one thing I'm not sure about that frosting chunk. It looks like a signed field used by playstore and other anti-virus to control the legitimacy of the application. I don't know how efficient it is but removing that may make the app more "suspicious" for their detecting tools
Wouldn't it be better to control that chunk's content instead of removing it ? If you prefer, we can use a matrix chan for this
IzzyOnDroid ✅
in reply to S1m • • •Zusätzliche APK-Checks im IzzyOnDroid Repo
IzzyOnDroidS1m
in reply to IzzyOnDroid ✅ • • •Easter Egg in APK Files: What Is Frosting - BI.ZONE - Medium
BI.ZONE (Medium)IzzyOnDroid ✅
in reply to S1m • • •S1m
in reply to IzzyOnDroid ✅ • • •@IzzyOnDroid I see, thanks for the clarification. I don't share my apps on the Playstore, I guess that's OK to remove that block.
On the other side, they are pretty small apps and they are reproducible so everybody can verify nothing suspicious is hidden in this block :)
Fay 🏳️🌈
in reply to S1m • • •@S1m @IzzyOnDroid No one but Google can verify nothing is hidden in there as it's encrypted.
You'd have to audit the code that generates it as well as all the inputs and then verify you get an exact match, since you cannot look at the data from the block itself: it's a completely opaque encrypted binary blob (which means it's not exactly FOSS either).
But you can't currently do that since it's not even reproducible: issuetracker.google.com/issues…
At IzzyOnDroid, our scans try to flag what we can: gist.github.com/obfusk/a993b1b…
But there are plenty of places to hide something; e.g. F-Droid would not catch this at all since they only flag a handful of specific blocks instead of anything unexpected: github.com/obfusk/sigblock-cod…
check APK Signing Block for Google/unknown blocks
GistFay 🏳️🌈
in reply to Fay 🏳️🌈 • • •S1m
in reply to Fay 🏳️🌈 • • •Fay 🏳️🌈
in reply to S1m • • •IzzyOnDroid ✅
in reply to Fay 🏳️🌈 • • •S1m
in reply to S1m • • •agp-sources/8.1.3/com.android.tools.build/gradle/com/android/build/gradle/internal/tasks/SdkDependencyDataGeneratorTask.kt at ed83b73500e037a15bfda72c8f72a77984b03ebb · jrodbx/agp-sources
GitHubIzzyOnDroid ✅
in reply to S1m • • •S1m
in reply to IzzyOnDroid ✅ • • •@IzzyOnDroid It will be removed for the next release 👍
BTW, I've added the badge for IzzyOnDroid on unifiedpush.org/users/distribu…
Sunup - Android
UnifiedPushIzzyOnDroid ✅
in reply to S1m • • •S1m
in reply to IzzyOnDroid ✅ • • •@IzzyOnDroid I've never really looked into IzzyOnDroid repo, that's pretty cool :)
I'd love to use your repository with an option to filter only "FOSS and RB apps" (or even with target SDK>XX). I think all the metadata required is there, so that must be a client thing to be implemented
I now have some questions 😄
Is it worth adding NextPush and UP-Example to your repo ? 3 MB each, but they are already in the main F-Droid repo
What do you think about adding an open search xml to the repo ?
I also wonder if I can use some of your scripts to maintain a minimal f-droid repo (See this, codeberg.org/s1m/my-fdroid-rep… but it is broken right now, because of an outdated dependency in F-Droid container), I am not sure how what the different scripts do. Do you have documentation about how things run ?
my-fdroid-repo
Codeberg.orgIzzyOnDroid ✅
in reply to S1m • • •GitHub - obfusk/apkrepotool: apkrepotool - manage APK repos
GitHubS1m
in reply to IzzyOnDroid ✅ • • •IzzyOnDroid ✅
in reply to S1m • • •IzzyOnDroid ✅
in reply to IzzyOnDroid ✅ • • •Fastlane · Wiki · IzzyOnDroid / repo · GitLab
GitLabS1m
in reply to IzzyOnDroid ✅ • • •IzzyOnDroid ✅
in reply to S1m • • •Push Clients/Manager - Android App Übersicht
IzzyOnDroidBlort™ 🐀Ⓥ🥋☣️
in reply to UnifiedPush • • •UnifiedPush
in reply to Blort™ 🐀Ⓥ🥋☣️ • • •