in reply to Jan Antoš

každá občanka je dnes smart card, na kterou si můžeš nahrát elektronický podpis a přihlašovat se s ní do egovernmentu, ale používá to minimum lidí, protože potřebuješ čtečku a v Linuxu binární blob. Elektronický podpis mám ve formě certifikátu na disku. Není to ten nejvyšší level, ale pro normálního občana je to dostačující a v Linuxu není potřeba nic navíc. Do egovernmentu se zase přihlašuju přes FIDO klíč. Není třeba žádná čtečka, žádný binární blob. Můžu si vybrat, jestli chci GoTrust, Yubikey...
in reply to Jiří Eischmann

@sesivany no já to nedavno řešil: Nejdřív jsem koukal na poštu, pak na první certifikační a paxem se na to vykvajznul s tím, že nemám zájem zvyšovat beztak již vysokou úroveň entropie okolního vesmíru.

Čtečku na eObčanku mám. Jednou se mi s ní povedlo přihlásit do portálu občana.
Podruhé jsem nějak pomotal hesla a tak byla eObčanka zablokována.

Tím pro mě celá záležitost skončila, jelikož je to stejně efektivní jako dát kartičku do mikrovlnky, jen to není trestné 😈

(do datovky se přihlašuji přes bankovní identu. Inu trh rozhodnul ...)

in reply to Jan Antoš

@sesivany Pro státní správu typicky stačí poslat dokument datovkou (bere se jako podepsanej) a na soukromoprávní věci existuje tohle (na věci do 2 mega): bankid.cz/lide/podepisujte/
Ale jako jinak je to holt byznys Český pošty a tvoje rozhořčení plně sdílím: cztwitter.cz/@Razemix/11259858…
in reply to Radomír Žemlička

@Razemix No, to BankID bych snad ani nedoporučoval. Ty jejich certifikáty nemají žádnou kvalitu, nikdo jejich kořenové certifikáty neuznává, nikdo není schopen nezávisle ověřit pravost podpisů.
Nejvíc mě rozesmála ta jejich argumentace, že podpisy sice nejdou ověřit, ale to ještě neznamená, že nejsou pravé. 😂
Tohle má smysl, pokud člověk podepisuje dokument u nějakého subjektu, který má nějaký smluvní vztah s BankID, třeba pojišťovna, v rámci toho je nějaká důvěra zajištěná, ale jako prostředek pro podepisování dvěma nezávislými subjekty je to omyl.
in reply to Radomír Žemlička

podle mě to vzniklo jako ověřování integrity dokumentů v rámci služby BankID. Tam to samozřejmě funguje, nemusíš řešit, jak to může někdo nezávisle ověřit. Vlastně ti stačí soukromé certifikáty, protože ověřuješ jen ty sám. Problém nastal v momentě, kdy nějakou chytrou hlavu napadlo to nabízet veřejnosti k podepisování dokumentů mimo tu službu.
This entry was edited (10 months ago)
in reply to Radomír Žemlička

@Razemix @sesivany jo Bank ID Estonsko opustilo už před několika lety byl hrozný problém s bezpečnosti. Každá banka to implementovala po svém, hromada bugu úniky dat, až to ztratilo level důvěry a do egov se s tím už několik let nedá prohlásit. A přesně v té době to ČR implementovalo jako super věc.
in reply to Jan Antoš

@sesivany Tak v Česku se tím nepřihlásíš úplně ke všemu, možná právě ze stejnýho důvodu. Ale zas máme Mobilní klíč eGovernmentu (info.identita.gov.cz/mep/), ke kterýmu nepotřebuješ čtečku. 🤷‍♂️
in reply to Radomír Žemlička

@Razemix zase ta možnost vybrat si providera se mi líbí. BankID jsem nikdy moc nepoužíval, ale s MojeID jsem spokojený. Splňuje to všechny certifikace až na úroveň nejvyšší, můžu se přihlašovat přes hardwarový token nebo přes aplikaci v mobilu a střídat to (ne vždy mám ten token u sebe), používám stejného providera pro egovernment i pro další weby...
in reply to Jiří Eischmann

@sesivany jaky binární blob potřebuješ? V estonském případě potřebuješ CCID (opensource) a opensc (opět opensource) na podepisování dokumentu lokálně máme DigiDoc app opět opensource i s libs pro vlastní integrace, web browser podpora pomoci web-eid opět opensource (toto například kompatibilní s id následujících států Estonsko, Finsko, Litva, Lotyšsko, Belgie, Chorvatsko)
in reply to Jan Antoš

je k tomu potřeba nějaká aplikace od státu: forum.mojefedora.cz/t/eobcanka…
Když jsem dostal před 5 lety novou občanku, chtěl jsem to vyzkoušet, ale pak přišla Identita občana, která umožňuje přihlašování přes různé providery včetně MojeID, a elektronický podpis mám už roky jako certifikát na disku, takže jsem to neměl dál potřebu řešit a už to nikdy znovu nezkoušel.

Oh Donald, Donald, why such a hurry? Trump’s blizzard of orders gets pushback, questions from GOP lawmakers - The Hill apple.news/AFU6n30OVR-uT9_TU4B…

More than 98% of Costco shareholders voted down an anti-DEI proposal at their annual meeting. The proposal had been filed by the National Center for Public Policy Research, a conservative think tank. In its Notice of Annual Meeting of Shareholders, Costco's board of directors had urged shareholders to reject the motion, saying: "Our efforts at diversity, equity and inclusion remind and reinforce with everyone at our Company the importance of creating opportunities for all." Here's more from @AxiosNews.

flip.it/AD2S.m

#DEI #DiversityEquityInclusion #Costco #Retail #Lifestyle

This entry was edited (11 months ago)

In 2022, someone who seems to have given up on the Fediverse posted a cool thing. It's a sequence inside a 3.14 kb executable, which, when run, takes a little bit of time to render, but produces this stupidly effective earworm.
I still have the executable file, which is clean, but I feel weird linking directly to it in a post.

Anyway, if you want to hear what can be squished into a tiny executable, here's the rendered audio from it.

The name of the executable is RedHeat_-_Meow x 3.14.exe

EDIT:
I found the original creator of this, and sadly, he passed away last year.
Red R. R. Tuby, amateur radio call PE1RRR.

This entry was edited (10 months ago)

reshared this

Unknown parent

mastodon - Link to source

Tamas G

wow, but it uses 109 MB of ram once run? That's insane. I wonder how a small 3 KB file can just, use that much Ram. I bet it might error out in something like Win95, unless it can work with less constraints on that.
This entry was edited (10 months ago)
Unknown parent

mastodon - Link to source

Tamas G

@rommix0 I guess unlike those annoying keygens, at least you can just press a single escape key and it closes. Ha. When I heard the initial tune I thought it sounded a bit keygen-esk and like chiptune music of course, but I've also seen those coded more lazy and just using a player lib with a data bit in the exe to then play it through that player, which they may or may not link inside of it. It also gets the job done but would be a lot quicker than the way this is made, with the downside of a larger file by a few hundred kilobytes.

I really enjoyed this #podcast. It is a critique of how the internet has affected democracy. Chris Hayes and Ezra Klein provide some interesting insights. They talk too about podcasts and how the format itself hasn't (yet) been captured by the attention economy. I was reminded about Aaron Swartz’s work to create the open standard build on RSS which is still the way people download podcasts. #democracy #EzraKlein

nytimes.com/2025/01/17/opinion…

Also available as a podcast:
podcasts.apple.com/na/podcast/…

I really enjoyed this #podcast. It is a critique of how the internet has affected democracy. Chris Hayes and Ezra Klein provide some interesting insights. They talk too about podcasts and how the format itself hasn't (yet) been captured by the attention economy. I was reminded about Aaron Swartz’s work to create the open standard build on RSS which is still the way people download podcasts. #democracy #EzraKlein

nytimes.com/2025/01/17/opinion…

Also available as a podcast:
podcasts.apple.com/na/podcast/…

in reply to Mike Gifford, CPWA

IMHO it's more a "war" on shifting attention *away from* important stuff and over to whatever narratives du jour suit the powers that be, including the New York TImes I might add, who spend a lot of time crafting them.

As long as podcasts are "available wherever you get your podcasts" and not only in walled gardens like Spotify and Audible, they will hopefully be ok.

You could not pay me to sign up to Spotify to get a podcast from them--it will never, ever happen.

Γεια σε όλους! Είχαμε ένα αίτημα από έναν χρήστη που ρωτούσε αν γνωρίζουμε κάποια κοινότητα NVDA ή ομάδα email στην ελληνική γλώσσα, κ.λπ. Γνωρίζει κανείς κάτι που μπορούμε να τον παρακαλέσουμε;

Hi everyone! We had a request from a user asking if we know of a Greek-language NVDA community or email group, etc. Is anyone aware of anything we can direct them to please?

Earlier today, Google rejected a feature request asking for the option to use DNS-over-HTTPS servers other than Google’s and Cloudflare’s in Android: issuetracker.google.com/issues…

According to Google’s own testing, DoH is more private, secure, and performant than DoT on Android. There is no reason whatsoever to limit it to a handful of Google-approved servers.

Just like with Manifest V3 in Chrome, this arbitrary restriction on what DNS servers can use the most modern technologies in Android is a clear example of Google abusing their position to campaign against blocking invasive trackers. One of the clearest uses for custom DNS servers is the ability to block privacy-invasive services like Google’s at the DNS level.

Further details & discussion on our forum: discuss.privacyguides.net/t/go…

#android #google #privacy #dns

Unknown parent

mastodon - Link to source

Tamas G

@rommix0 @luiscarlosgonzalez oooh yeah. I guess that makes a lot more sense why I got a model trained for RVC in like 30-40 mins on Google Notebook at the time, that's actually not the worse performance difference. I'm hoping as more we get the optimized models and less epics required for training, that can improve for other things too. I've used the M1Pro GPU so far for the local LLM stuff and just being able to code in a massively wasteful way offline with still decent output return is hard to beat, so having that on Windows as well would tempt me for a GPU, for sure.

A sick sunfish stopped eating after its aquarium closed for renovations so the staff put cutouts of humans and pictures of smiling faces outside the tank and then it started eating the next day. apnews.com/article/japan-ailin…

Trump has unleashed a wave of fear among immigrant families by stripping away critical protections that kept ICE out of schools, hospitals, and places of worship.

The Safe Schools for Every Student campaign gives you the tools to demand that your local school board takes a stand and adopts policies that keep schools safe for all students, no matter their immigration status. indivisi.org/safe-schools

🕛Z #NowPlaying at the top of the hour, 2 hours of relaxing #NewAge, #ambient, and #meditationmusic on Northern Lights: The New Age Show, #live with Kelly Sapergia. More information is at ksapergia.net/northernlights/. Tune in either by visiting theglobalvoice.info and clicking on the Listen Live link, or go directly to theglobalvoice.info:8443/broad… #TGVRadio #audio #radio 📺🗣️📻🎶🎙️🌌🌈🫣🫰🩵🪬🫶

"our commitment to an enterprise rooted in respect and inclusion is appropriate and necessary."

Diverse employees and suppliers have fostered

"creativity and innovation in the merchandise and services that we offer,"

- Costco Board.

98% of Costco shareholders agreed with the board.👍🏿

Segregationists denied.

axios.com/2025/01/23/costco-de…

Segregationists are going to test each and every one of you, to see where your heart is at.

If they haven't tested you already, they will test you soon.

Do you know what you are going to say?

reshared this

in reply to Hubert Figuière

uspoli, canpoli, trade

Sensitive content

"È il principale ipocrita al mondo della libertà di parola": la battaglia di Elon Musk con Wikipedia fa parte della sua guerra alla verità


Elon Musk è arrabbiato con Wikipedia per aver riportato il suo presunto "saluto nazista". Ma i suoi attacchi fanno parte di una lunga e inquietante storia di tentativi di sopprimere informazioni che ritiene scomode

the-independent.com/tech/elon-…

@pirati

For those of you on mastodon social, please be aware that your instance is becoming a real headache for other instances and their admins. mastodon social has attracted/not blocked too many trolls and disinformation bots.

It's up to you whether you stay there, but people are blocking the whole instance to avoid these bad actors.

If you are worried about how to migrate to a new instance, fedi tips is a great help, with instructions on how to do the switch.

If you need help finding an instance that is a good fit for you, there is help for that, too.

fedi.tips/transferring-your-ma…

fedi.tips/which-server-should-…

in reply to Dale Reardon

I'm fairly confident it will be Media Transfer Protocol (MTP), which is used widely by Android devices. Linux supports MTP, at least under the GNOME desktop environment, where it's mounted by default. Microsoft Windows supports it by default in File Explorer. However, macOS doesn't and you need to install additional tools that I haven't personally tried but which may work in this case.

Day three of Trump's term and the largest push for surveillance capitalism yet has been made: Project Stargate will be a $500.000.000.000 (500 billion USD) data center used for running a multitude of AIs with the purpose of spying on you.

Larry Ellison, the world's second richest man and CEO of Oracle, one of the main partners of Stargate, said:

“Citizens will be on their best behavior, because we're constantly recording and reporting everything that's going on [...]. We're using A.I. to monitor the video.”


— Larry Ellison, CEO of Oracle on how the company's A.I. systems will be used for in the future [Source: Business Insider]

This is who is in power now. This is the vision they have.

This entry was edited (10 months ago)

uspol

Sensitive content

This entry was edited (11 months ago)

reshared this

in reply to Zach Bennoui

re: uspol

Sensitive content

in reply to Tamas G

re: uspol

Sensitive content

in reply to Tamas G

re: uspol

Sensitive content

Twilio says its adjusted operating margin will reach 21%- 22% in 2027, exceeding est. and up from 16.1% in the most recent quarter; TWLO jumps 11%+ after hours (Jordan Novet/CNBC)

cnbc.com/2025/01/23/twilio-ann…
techmeme.com/250123/p46#a25012…

#AndroidAppRain at apt.izzysoft.de/fdroid today with 19 updated and 1 added apps:

* Remind Me! – Set alarms for a specific date in the future 🛡️

Enjoy your #free #Android #apps with the #IzzyOnDroid repo

And thanks for all your kind words and congratulations to our grant 😍

A calque is a word that has been loaned *and translated* from another language. Some English calques: flea market, potsticker, beer garden, iceberg, refried beans, superman, scapegoat, stormtrooper, killer whale. englishlanguagethoughts.com/20…

Voor onze veiligheid, vrijheid en welvaart hebben we meer grip & autonomie op onze digitale infrastructuur nodig. Ambities zijn er, maar dat wordt steeds meer zoals ‘wereldvrede’ roepen! Kabinet moet keuzes & een plan maken! Blij dat onze moties voor twee Zeekabels en een AI fabriek zijn aangenomen!

🐦 "Sans les étourneaux le chant des saisons s'éteint" : Faute d'étourneaux, #ExtinctionRebellion La Rochelle les placarde en tags dans leur ville.

👉 La population d'étourneaux décline depuis les années 70, les individus restant se concentrant dans les villes faute de haies bocagères / refuges et sur-usage de pesticides dans les champs nos campagnes 🌱

This post about I/O bound "ruby" apps applies equally well to Python, PHP, JS, or any other high-level backend language. We use tools with poor CPU performance and then self-soothe with fairy tales about things being "I/O bound" or "only a few critical loops being hot" and there is *some* truth to those tropes, but it's important not to let them become thought-terminating clichés about performance. Anyway, it's important reading: byroot.github.io/ruby/performa…

Mark Your Calendars and Join the Party!

We’re less than a week away from our 10th Anniversary Celebration on January 29th from 2:00-4:00pm PST! 🎉

Be part of this milestone event as we unveil our new mascot (a community-chosen favorite!) and celebrate a decade of innovation together. We'll be hearing from team members, both past and present, connecting with our incredible community, and reflecting on how far we’ve come.

We can’t wait to celebrate with you! 🎊

✨ Join the celebration in-app or on Zoom
aira.zoom.us/j/89073345341

Some fascinating research out on hacking a Subaru via STARLINK connected vehicle service.

"On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK connected vehicle service that gave us unrestricted targeted access to all vehicles and customer accounts in the United States, Canada, and Japan.

Using the access provided by the vulnerability, an attacker who only knew the victim’s last name and ZIP code, email address, phone number, or license plate could have done the following:

Remotely start, stop, lock, unlock, and retrieve the current location of any vehicle.

Retrieve any vehicle’s complete location history from the past year, accurate to within 5 meters and updated each time the engine starts.

Query and retrieve the personally identifiable information (PII) of any customer, including emergency contacts, authorized users, physical address, billing information (e.g., last 4 digits of credit card, excluding full card number), and vehicle PIN.

Access miscellaneous user data including support call history, previous owners, odometer reading, sales history, and more.

After reporting the vulnerability, the affected system was patched within 24 hours and never exploited maliciously."

samcurry.net/hacking-subaru#in…

#cars #security #subaru @starlink