blazietech.com/may-2025-update
Please boost! #FediHire
I'm looking for my next role as a program manager, team lead, or senior developer.
- 20+ years in open source
- 6 years experience in web dev with #Python, #Django, HTML, bootstrap
- 7 years experience in C, Linux kernel, embedded systems
My passions lie at the intersection of open source software development and creating welcoming spaces for people to learn and grow.
I'm currently the program manager for a technical internship program. I work remotely with a team of 4 people in New York, Brazil, and Nigeria.
Looking for a fully remote role. I'm open to relocation outside the USA.
Resume here: sage.thesharps.us/hire-me/
DM me or send an email to sage at thesharps dot us
reshared this
The May 2025 update for the BT Speak is now live!!
Features include:
a more versatile clipboard that extends across traditional and desktop mode and which even back and forward translates what gets pasted, depending on the Braille table being used
More standard commands in the editor, such as ctrl+c for copy, ctrl+v for paste, etc.
an NFB Newsline app
Help files and the welcome screen now allow for headings and links, making them more interactive
and more!!
blazietech.com/may-2025-update
DG
Why does the #AISlop problem exist at #hackerone (and likely other bug bounty platforms)?
Because apparently it works: hackerone.com/evilginx/hacktiv…
It seems that some projects pay bounties for such AI Slop reports.
This thing works by generating fake vulnerability reports. Here are some of the qualities of the HackerOne report 3125832 sent to #curl:
- It looks convincing at a glance, especially if you're not a subject matter expert.
- It's vague about actual repro steps. It makes it impossible for the victim project to reproduce the issue. For example, it makes up fake patches against non-existent, imaginary code.
- It refers to functions and methods that do not exist (in case someone tries to look for them). When confronted, the attacker refer to some old or new versions of components, using non-existent commit hashes.
- The report makes up some convincing functionality or names that are novel, but don't really exist.
An expert’s look at the report shows the number of discrepancies, but finding them takes time and effort. It requires attention from a subject matter expert, with limited resources.
The real exploit here is that the attacker (evilginx) exploits the fact that the victims (the orgs who paid the attacker money) don't have the capacity to perform thorough analysis and rather just pay up. TL;DR: It's cheaper to pay the bug bounty than hire an expert to perform true analysis.
Why didn't it work against the curl project? The attacker miscalculated badly. Curl project is not a company and has far greater capability in security response than your average org. Also they can smell #aislop miles away.
"Mir reicht's": #Curl-Entwickler spricht Machtwort gegen "KI-Schrott"
golem.de/news/mir-reicht-s-cur…
> Entwickler @bagder zeigt sich frustriert über durch KI generierte Bug-Reports. Reporter werden künftig einem Intelligenztest unterzogen.
Btw., #Golem garniert den Artikel mit einem KI generierten Bild 🤷
Aber das mit den Intelligenztest finde ich gut. Die Frage ist, ob man mit Captchas gegen LLMs ankommt.
**Penetration Testing Report: HTTP/3 Stream Dependency Cycle Exploit** --- # **0x00 Overview** A novel exploit leveraging stream dependency cycles in the HTTP/3 protocol stack was discovered,...HackerOne
For over one year I've been harassed, threatened, doxxed, misgendered and abused by Luna the Foxgirl, author of Inochi2D.
Due to her attacks and manipulation of others, I no longer feel safe contributing to Linux GPU drivers, and I will be retiring my current model.
Together with 39 orgs & 42 experts, our founder Matthias Pfau calls on the EU in an @edri open letter for a scientific evidence-based approach to #encryption 🔒
No government can change the laws of math.
Read the open letter ⤵️
tuta.com/blog/open-letter-agai…
New name, same problems: The EU now calls Chat Control "ProtectEU", but it comes with the same issues as before.Tuta
treefit reshared this.
Made in America isn’t a slogan—it’s our mission.
The Liberty Phone by Purism is built in the U.S. to protect you from foreign or domestic surveillance.
✅ No spyware or ads
✅ Secure U.S. supply chain
Learn More & Purchase: puri.sm/products/liberty-phone…
Thin Fonts Are a Usability Nightmare—And Finally, Designers Are Waking Up
webdesignerdepot.com/thin-font…
#UIDesign #webdesign #a11y #fonts #usability #accessibility #typography
Thin fonts may look sleek, but they’re a usability nightmare—hard to read, inaccessible, and especially frustrating on mobile.Noah Davis (Web Designer Depot)
❗Takže vážení, pondělí je po prodlouženém víkendu ještě kritičtější než obvykle.
Kdo si dá po obědě malou mentální rozcvičku, rozhodně neprohloupí! Ale nesmíte na sebe moc chvátat. Stačí třeba vyjmenovat herce v Sedmi statečných nebo tak něco. 👇😊
Re-igniting the oldest nerd war in existence? On Star Wars day? The gall.Simon Batt (XDA)
A review of the PowerTech S1 Portable Power Station from a blindness perspectiveYouTube
Kladno, mačky, Naďa, kytky, Covid.. krásne časy
youtube.com/watch?v=PSLsfwTbo4…
Johnny Cash live in San Quentin prison 1969 full videoYouTube
Ekonom Igor Lipsic není moc velký optimista, nemá rád úvahy nepodložené čísly a daty a na svět se dívá velmi pragmaticky. V brzký konec ruské války nevěří, a to přesto, že Rusy podle něj čekají fronty před obchody i potravinové lístky.Petra Procházková (Deník N)
If I use Gemini, which is how I'm transcribing stuff these days, it's different every time.
1. Build Shit, Fix You, and Sorry is Better and Body for you, for you.
2. Deal Sheet, Visual and solid, is better and body for you, for you
Let's try through Whisper:
They'll cheat this you and sorry it's better and party for you, for you.
A transcription I got earlier had something about "aesthetic", which I can actually hear if I listen now.
One thing's for certain, you will never hear these songs in the same way again! Do you have any other misheard lyrics to add to the list? Let us know in the ...YouTube
These are the most misheard song lyrics according to an online pollLeonie Cooper (NME)
Milníky a poznámky k americké (sub)urbanizaci, v časové osePeter Bednár (Smíchov Review of Cities)
Good morning Fedi friends!
Please join me in giving a warm welcome to my interns Riyen (@patel.riyen) & Sam (@samaaberg). They will be working with me through the end of June on videos promoting the Fediverse. This is their #introduction.
Sam & Riyen are two talented film students who are #NewHere: a mere 7 days ago they had no idea what the Fediverse was. I have the immense honor of introducing them to it.
We are filming this week! Send us good vibes 🎥✨ #EleFediVideos
Learn using BigBlueButton, the trusted open-source web conferencing solution that enables seamless virtual collaboration and online learning experiences.bbb.metalab.at
F4 is literally the key to excellence in Excel.Tony Phillips (How-To Geek)
Save lots of time when browsing online.Tony Phillips (How-To Geek)
Marriages and families are falling apart as people are sucked into fantasy worlds of spiritual prophecy by AI tools like OpenAI's ChatGPTMiles Klee (Rolling Stone)
In 2024, the documentation community continued to update LibreOffice guidebooks, and the Help application (This is part of The Document Foundation’s Annual Report for 2024 – we’ll post the full version here soon.Mike Saunders (The Document Foundation)
LibreOffice reshared this.
NVDA 2025.1 Beta 4 is now available! Changes from Beta 3 include:
- Updates to translations
- Fix security issue which allowed an arbitrary process to connect to a Remote Access session running on a secure screen
- Allow Remote Access leaders to regain control after the last follower has disconnected
- Improve focus handling in the Remote Access Connection dialog
- Don’t toggle Remote Access mute when not connected
Read the full details & download from: nvaccess.org/post/nvda-2025-1b…
#NVDA #NVDAsr
David Goldfield reshared this.
Nick's world 🌎 👨🦯 🗽
in reply to Blazie Technologies • • •Blazie Technologies
in reply to Nick's world 🌎 👨🦯 🗽 • • •How you enter numbers depends on what locale you're using and whether or not you have your BT Speak set to enter Braille using literary or computer Braille. The default is computer Braille input, which is using the lower numbers in the Braille cell, such as dot 2 for 1, dots 2-3 for 2, dots 2-5 for 3, etc.
Try that but let us know if you run into issues.
DG
Nick's world 🌎 👨🦯 🗽
in reply to Blazie Technologies • • •Blazie Technologies
in reply to Nick's world 🌎 👨🦯 🗽 • • •@gocu54 First, we need to determine what your Braille input mode is set to by going to Options, Settings, Braille Settings, Change the Input Prompt mode and set it to "Expect Computer Braille" and see if that fixes the problem.
Also, we should determine what locale you are using.
You can go to Options, Operating System, System Administration, Customize This BT Speak, Change the Locale. When you do this, what locale option is it pointing to?
Nick's world 🌎 👨🦯 🗽
in reply to Blazie Technologies • • •