Pre-disclosure: Upcoming coordinated security fix for all Matrix server implementations
Matrix, the open protocol for secure decentralised communicationsMatthew Hodgson (matrix.org)
Matrix, the open protocol for secure decentralised communicationsMatthew Hodgson (matrix.org)
Hyrum's Law: With a sufficient number of users of an API, it does not matter what you promise in the contract; all observable behaviors of your system will be depended on by somebody.
This means:
- Users depend on bugs
- Implementation details suddenly are the spec
- Breaking changes are always breaking for someone
- Documentation is a suggestion of intent rather than reality
Also, relevant XKCD: xkcd.com/1172/
Wednesday, time to switch coffee places for diversity's sake.
lokjo.com -> just type 'coffee' and select 'coffee break' and it'll show you all places, at once, except corporations, or advertising, or 'suggestions', and without taking your data, or anything.
It just shows you all coffee places, like a fair map should do. 😊
edit: explained a bit more clear
#lokjo #fair #coffee #positivenews #EU
Ah yes, low amount of places happens sometimeswith OSM, it might be a reason for some people to help out, if they have time of course.
They are sorted byplaces who are noted as coffee-places or those who noted down they serve coffee, like some bakeries, newspaper stands etc.
If you know some places you can add them through @MapComplete or through osm.org.
We’re proud to support @HowTheyVoteEU with our open source donation for their important work: making EU politics more transparent for everyone.
🔎💌 Open source + transparency = a perfect match!
👉 Learn more about this inspiring project & our support for open source: tuta.com/blog/open-source-spot…
#opensource #EU #Democracy #Privacy #Email #FOSS #Tuta
Open Source Spotlight: With its focus on open source, HowTheyVote.eu chose Tuta Mail to set up a professional mailbox. Let’s check what they do and why they need Tuta!Tuta
“All of the knowledge to generate the exploit already exists on the internet. AI could even build it for you,” the researcher told 404 Media.Matthew Gault (404 Media)
Poland has this too, and it's not really considered a vuln here. It's just how our "radio stop" system works. It's mandated by law even if I remember correctly.
You need physical access to exploit it, and it's not much different from just pulling on the emergency brake, setting fire to a depo or something of that sort.
Via Rail proudly announce an upgrade to the awful, awful Halifax - Montreal line.
They are going to modernise it by using carriages built in 1954.
1954.
When I lived in the UK, there was a heritage steam train line with carriages newer than that.
Mind you, the village of Corfe Castle (pop 1,355) has more rail passengers in Nov and Dec each year than Halifax (pop 530,167) has in a year. #CanadaFail
cbc.ca/news/canada/nova-scotia…
Donner votre avis pour faire progresser l’accessibilité numérique, ça vous tente ? 💬
Si vous êtes en situation de handicap, rejoignez notre panel de testeurs et testeuses !
En quoi ça consiste ? Vous allez sur un site web, vous naviguez dessus, vous nous dites ce que vous avez pensé.
Lors d'un échange individuel ou d'un atelier collectif, selon vos envies et disponibilités.
Vous recevez un bon d'achat d’au moins 20 € pour chaque activité réalisée.
Valve gets pressured by payment processors with a new rule for game devs and various adult games removed gamingonlinux.com/2025/07/valv…
#Steam #Valve #Gaming #PCGaming
Valve have added a new rule to the Onboarding guide for game developers, noting that payment processors get a say in what stays on Steam.Liam Dawe (GamingOnLinux)
NVDA 2025.2 Beta 3 is now available for testing: nvaccess.org/post/nvda-2025-2b…
Changes introduced in Beta 3:
- Added a WASAPI toggle to SAPI5.
- Added a confirmation dialog to update root certificates when downloading add-ons.
- When using NVDA Remote Access, speech from User Account Control screens on the remote computer now works reliably.
- Updates to translations.
#NVDA #NVDAsr #Beta #PreRelease #News #Update #Software #FLOSS #FOSS
Tamas G reshared this.
A while ago I received an email with this question. I've been subscribed to your weekly newsletter for a while now, receiving your weekly updates every Friday. I'm writing because I admire your consistency, focus, and perseverance.daniel.haxx.se
Seit gestern ist der TI-Messenger auch für Versicherte (zumindest bei manchen Krankenkassen) verfügbar
zm-online.de/news/detail/ti-me…
An sich ist das ein etabliertes Protokoll (Matrix), dass zur Kommunikation genutzt wird.
Bemerkenswert ist die Koppelung mit der ePA-App.
Müsste das so sein? Nein.
Mit der Funktion sollen Patienten sicher mit ihrer Arztpraxis chatten könnenZahnärztliche Mitteilungen
#curl creator mulls nixing bug bounty awards to stop AI slop
theregister.com/2025/07/15/cur…
: Maintainers struggle to handle growing flow of low-quality bug reports written by botsThomas Claburn (The Register)
in order to claim a bug bounty post slop, you must provide a modest yet significant escrow, your missile coordinates, selfie, true name and of course steps to reproduce without sacrificing a chicken.
Most of the former are to discourage sloppers with poverty and suffering, or at least attempt it.
…g and triggering via keyboard shortcut Link to issue number: Resolves #16281 Summary of the issue: NVDA currently lacks a built‑in, offline image captioning feature. Existing solutions require a ...GitHub
#curl 8.15.0
Daniel walks through the changes done in 8.15.0, a whole bunch of his "favorite" bugfixes and then some of the upcoming new things that might be merged and i...YouTube
daniel:// stenberg:// reshared this.
I'm Daniel Stenberg, maintainer and lead developer in the curl project. I stream curl related stuff. Release presentations, curl development and related topics.Twitch
I have previously blogged about the relatively new trend of AI slop in vulnerability reports submitted to curl and how it hurts and exhausts us. This trend does not seem to slow down.daniel.haxx.se
My gut feeling says you need a new #curl release. So here is curl 8.15.0 just for you.
daniel.haxx.se/blog/2025/07/16…
Welcome to another curl release. A shorter cycle this time so we did not have time to merge many changes: there is just one logged. See below. This is the 269th release featuring 269 command line options.daniel.haxx.se
daniel:// stenberg:// reshared this.
EU age verifier app was released today on github, saying it'll include remote attestation
Is it just me who finds this terrifying?
No more open operating systems for your phone if you want to be able to use it for age verification. For now, it sounds like this will be for porn, but social media (hello Mastodon) recently got a "recommendation" from our government to not be allowed below a certain age
Will we need a Google or Apple attested device to get around on the internet in a few years?
reshared this
That's terrifying but also... annoyingly stupid? The Netherlands released such an app without Play Integrity years ago called Yivi (formerly IRMA).
Regardless of thoughts on the verification, we have an existing government app showing that Google Play Integrity integration is not needed.
Wrote a tiny bit about that here: github.com/eu-digital-identity…
In the README, the following is listed: App and device verification based on Google Play Integrity API and Apple App Attestation I would like to strongly urge to abandon this plan. Requiring a depe...TheLastProject (GitHub)
Unfortunately our train hit a truck at a grade crossing this morning.
We’re fine, just delayed, but the truck driver is not.
denver7.com/news/local-news/at…
At least one person was injured after an Amtrak passenger train collided with a semi at a railroad crossing in Gilpin County Monday.Robert Garrison (Denver 7 Colorado News (KMGH))
On the last day of our 3.5-week train trip around the country, @Aubrie and I were interviewed about what it’s like to ride Amtrak as disabled people.
This sounds like an impressive project. Running a million-board chess MMO in a single process eieio.games/blog/a-million-rea…
The post says this game is running on a single $80/month DigitalOcean VM. I bet it could run on a Raspberry Pi or similar single-board computer. If I'm calculating correctly, the full game board takes about half a GB of RAM.
How one million chessboards workseieio.games
Join @manuq and @cassidy this Thursday at 1800 UTC (11 AM PDT) as we share a bit behind the scenes of Threadbare, our collaboratively-built open source game made in Godot Engine!
It's currently pre-alpha, but Threadbare is a story-driven game where players don’t just explore a world—they co-create it.
We hope to see you there!
#godot #GodotEngine #OpenSource #gameDev
Join Manuel and Cassidy as they share a bit behind the scenes of Threadbare, a collaboratively-built open source game made in Godot Engine. It's currently pr...YouTube
From the Disability Visibility Project:
"Immigrant Rights Are Disability Rights"
disabilityvisibilityproject.co…
"… a true commitment to justice for disabled people must recognize that many undocumented immigrants are themselves disabled and deserving of basic rights, not total erasure from the disability rights discourse."
#USPol #Disability #DisabilityRights #Ableism #Immigration #HumanRights
Immigrant Rights Are Disability Rights Joe Stramondo In 2019, a White disability rights leader with a national reputation, Bruce Darling, had a spectacular fall from grace because of commen…Disability Visibility Project
: Maintainers struggle to handle growing flow of low-quality bug reports written by botsThomas Claburn (The Register)
PureOS Crimson Milestone Nears Completion
The PureOS team has made major progress toward delivering ready-to-flash Crimson images for the Librem 5.
May’s work focused on resolving core bootstrapping issues that prevented automatic image builds—particularly for arm64 builds from amd64 hosts.
Learn more at Purism: puri.sm/posts/pureos-crimson-d…
Purism makes premium phones, laptops, mini PCs and servers running free software on PureOS. Purism products respect people's privacy and freedom while protecting their security.Purism SPC
Made words about this AI phenomenon
Just got the following email from Orbit Research regarding the Orbit Player:
Hello List Members,
We are excited to announce that the Orbit Player will begin shipping on Monday, July 21, 2025!
Orders are now open and we encourage you to place yours early to ensure timely delivery from our initial batches.
Please note that initial production batches are limited and expected to sell out quickly. Therefore, we recommend placing your order as soon as possible.
Shipments will be fulfilled in the order they are received, with priority given to customers on the pre-order list.
You can place your order online here:
orbitresearch.com/product/orbi…
Or call us at 888-606-7248 to order by phone.
Thank you again for your continued support!
Best Regards,
Customer Care Team
Orbit Research
The Orbit Media Player is a versatile, user-friendly device designed to enhance accessibility for blind and visually impaired individuals. It features a compact, lightweight design with tactile buttons for easy navigation.Orbit Research
Well, Sameer finally got what he wanted: the end of an actually fast, actually secure counterpoint to Android.
CrOS can't make Android look like shit if CrOS also sucks:
theverge.com/news/706558/googl…
A merger of Android and ChromeOS has been rumored for months, desired for a decade, and now Android head Sameer Samat says it’s on the way.Dominic Preston (The Verge)
From creating games that instantly adapt to different devices to making styluses feel just like drawing on paper, here’s a wrap-up of the latest.chromeos.dev
#AndroidAppRain at apt.izzysoft.de/fdroid today with 20 updated and 1 added apps:
* DHBW Horb Student App: study life app for students at DHBW Stuttgart Campus Horb 🛡️
And it seems we make a spot landing at the 1st anniversary of our public RB GoLive on August 1st. Current RB status: 648 apps (49.8%) – just 0.2% missing for the 50% mark! 🥳
Enjoy your #free #Android #apps with the #IzzyOnDroid repo 
This is a repository of apps to be used with your F-Droid client. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
Shared for absolutely no reason at all.
"Ottawa rushes to build its own AI translator as government use of free tools soars
Demand for official translation services is falling despite a rise in content creation. As public servants turn to free online tools, the government is racing to build its own AI translator.
If PSPC Translate works for staff in the department of about 19,000 people, the tool will be used more widely. It’s the first “lighthouse project” under the federal government’s artificial intelligence strategy, meant to help the public service learn how to build and implement new AI tools and create something that can be scaled across government."
@hub I expect some errors happen from time to time already, and they blame the lawyers and translators, everyone gets sued a bit, and it all takes forever and costs a lot to fix.
Sounds like it will get worse.
Legally fleecing entities via unverified AI produced content is going to be a good business.

Attached: 1 image S2238 A bill to prevent the theft of catalytic converters and other precious metal car parts, and for other purposes. 📢 Introduced in Senate https://congress.Mastodon
famfo
in reply to The Matrix.org Foundation • • •> One of the other changes coming in v12 is that [...] room creators effectively have infinite power level.
What are the implications of this when creating new rooms and especially to who is doing the upgrade on existing rooms? Is the room creator essentially the BDFL of the new room?
The Matrix.org Foundation
in reply to famfo • • •Should room creators always be able to give themselves power? (SPEC-369)
matrixbot (GitHub)famfo
in reply to The Matrix.org Foundation • • •txt.file
in reply to The Matrix.org Foundation • • •@matrix
Stefan Baur 8 * 💉
in reply to The Matrix.org Foundation • • •