RT: cosocial.ca/users/evan/statuse…
Evan Prodromou (@evan@cosocial.ca)
Is it ok for people on the ActivityPub network to speak negatively about other distributed social networks? #EvanPoll #poll [ ] Yes [ ] Yes, but... [ ] No, but... [ ] NoCoSocial
Today I learned that Porche Headlights are great Grow Lights for your Weedz ...
The actual fuck?
@feld @SlicerDicer I don't know if you've been in a grow room (doo dee do) but they're hot (and humid).
If you're not in a place where it's legal to grow, IR is Often used (from the air) to find homes with Super Hot Spots.
The fun part Slicer is that it would seem they're STUPID easy to steal. (?!?)
Aside: When I was in Uni, every year they'd put sodium bulbs in the lamp posts over three or four bridges, and about two weeks after the quarter started, they would all disappear. A-MA-Zing.
On this day in 1966, Star Trek first beamed into living rooms across America. None of us could have imagined then the journey it would set us on. And not just the cast and crew, but the millions of fans who would find hope, inspiration, and community in its vision of the future.
Over the decades, I’ve been humbled and grateful for the love you’ve shown, not only to me, but to the ideals of Star Trek itself: diversity, unity, and the belief that together, humanity can boldly go where none have gone before. Thank you for your unwavering support and for keeping this dream alive all these years. Live long and prosper, always.
you can neuter what root can do, disallow a lot of things at the jail level.
Not sure if you can meaningfully segregate X11 apps just because of a jail though
Today's #AndroidAppRain at apt.izzysoft.de/fdroid brings you 19 updated and 2 added apps:
* Network Switch: enables you to toggle between 4G and 5G network modes 🛡️
* Screenlite Web Kiosk: a simple Android kiosk browser app that displays web content in full-screen mode 🛡️
RB status: 705 apps (53.9%)
5 #Magisk modules have been updated at apt.izzysoft.de/magisk
Enjoy your #free #Android #apps with the #IzzyOnDroid repo
IzzyOnDroid F-Droid Repository
This is a repository of apps to be used with your F-Droid client. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
(Funding is looking good currently btw!)
Delta Chat: A big user surge and funding for decentralized scale
Beginning June we witnessed a sudden surge of Delta Chat usage especially in the US and Cuba. We don’t know the social dynamics behind it but it probably helps that Delta Chat apps resiliently work...delta.chat
Peter Vágner reshared this.
💬 WECHSEL von #K9mail auf @thunderbird
UPDATE:
Es ist total easy. Die Daten müssen nicht vorher von K9 Mail exportiert werden
#Thunderbird installieren und dann den Weg gehen, wie in den Screenshots zu sehen. Das auswählen, was aus #K9mail importiert werden soll - fertig 👌
Thunderbird liest die Daten direkt aus K9 Mail aus
Me too, it's really easy 🙂
I finally switched yesterday after you announced the temporary bug in K9.
Sensitive content
color npm package compromised
On September 8 2025, around 13:00 UTC, someone compromised Josh Junon’s npm account (qix) and started publishing backdoored versions of his package. Someone noticed and let Josh know: Josh confirme...fasterthanli.me
try {
args = JSON.parse(JSON.stringify(argsIn));
} catch (e) {
args = [...argsIn];
}
Ah see? I'm not the only one who didn't know about structuredClone
Here's the NPM supply chain attack payload deobfuscated & cleaned up by hand as best I could: github.com/fasterthanlime/0x11…
...I'm not sure it would ever work in its current form, tbh
GitHub - fasterthanlime/0x112: De-obfuscated payload from the September 8 2025 npm supply chain attack
De-obfuscated payload from the September 8 2025 npm supply chain attack - fasterthanlime/0x112GitHub
You do a pull request to an #OpenSource project.
A hour or so later, a maintainer of the upstream does a pull request to _your_ fork. Is this...
- Not surprising. (0%, 0 votes)
- Surprising, but in a good way. (100%, 1 vote)
- Surprising, but in a bad way. (0%, 0 votes)
I have been pushing for #Inkscape to remove/decommission it's Twitter account. But I didn't want to do it unilaterally, bossing people about, but through reasoned policy that can be applied to other captured banana-pants social media platforms.
So I've drafted a policy, which I'm interested in having more people look at as it's going to be one of those gnarly things that's important to get right:
lists.inkscape.org/hyperkitty/…
What do you think? Worth while approach for a #foss project?
Until now, if you lost or broke your phone, your Signal message history was gone, a real challenge for everyone whose most important conversations happen in Signal. So, with careful design & development, we’re rolling out opt-in secure backups.
Secure backups will let you save an archive of your Signal messages remotely in privacy-preserving form, refreshed daily.
Now available in the latest Android beta release, rolling out to iOS & Desktop soon
signal.org/blog/introducing-se…
Introducing Signal Secure Backups
In the past, if you broke or lost your phone, your Signal message history was gone. This has been a challenge for people whose most important conversations happen on Signal.Signal Messenger
Indeed, it's a dire situation, and I think the world will be worse but for the vain aspirations of a small man. It's an unfortunate but common refrain these days.
Apologies, about the previous post, my subtle ironies are sometimes too subtle. 😅
@jszym aussi ils ont été les deux plus vieux Premiers Ministres de la Vème republique.
(Attal était le plus jeune)
Just because you add some ARIA and call something “accessible” doesn’t actually mean it is.
Looking at a self-described “Accessible, high-perf” infinite scroll (it really just starts over) that is janky as fuck, doesn’t take keyboard focus (in Safari), uses scroll snap to awful effect, and lets the scrollbar thumb become a liar.
How’s your day?
would that our local police were as committed to arresting asshole pickup truck drivers as the Prince George RCMP was to arresting this guy driving a toy Barbie jeep
New Privacy Guides article ⛔
by me:
Chat Control is one of the
most terrifying proposal for dystopian authoritarianism the Western world has seen in years.
We need your help to fight it ✊🇪🇺
For democracy,
For privacy,
And for all other human rights,
We cannot afford to lose this battle.
📩 If you are European (EU):
Contact your MEPs this week before Friday, September 12th, to tell them to oppose Chat Control (more information in the linked article).
🗣️ If you are outside of the EU:
Spread the word! Tell your friends and family in the EU about it! Make noise on social media! This will affect you too.
privacyguides.org/articles/202…
#PrivacyGuides #ChatControl #StopScanningMe #Privacy #HumanRights #Democracy #EUpol
Chat Control Must Be Stopped, Act Now!
Chat Control is back to undermine everyone's privacy. There's an important deadline this Friday on September 12th. We must act now to stop it!Privacy Guides
reshared this
Strasbourg, Blick von der Kathedrale Notre Dame
#Strasbourg #France #photographie #photography #urban_photography #architecture #europe
I didn't look into it yet but I heard that the replacement for the Dept of Labor after Trump fired the last one for "fake jobs numbers" released their report and it was the same numbers essentially
When I heard this I started uncontrollably laughing. He couldn't even find a patsy to give him fake numbers?!
To me, the worst part of what is being called the "largest supply chain attack in history" is the fact that there are over "2.6 billion weekly downloads of those NPM packages"
What the actual fuck?! [says a guy who used to curate SQL queries because the results took too long to deliver over 9600bd]
The Debian repository for Helm had 7TB of downloads per month. For a 20mb package.
github.com/helm/helm/issues/31…
That's what happens in CI pipelines when everyone starts from scratch on each run...
Moving Debian repository to new service
I maintain the Debian package/repo for Helm here https://helm.sh/docs/intro/install/#from-apt-debianubuntu . The bandwidth has gotten to be enough that it's no longer feasible to host it myself (~7...mattfox (GitHub)
Ban the leaf blower.
They’re not just loud—they unleash a jagged mechanical howl, a pitch that swings between jet engine and chainsaw, cutting through walls and windows. It’s a sound that never settles, a rising and falling whine that forces itself into your head until you can’t think. Noise pollution at its most aggressive.
Then there’s the exhaust. Two-stroke engines that spit out more pollution in an hour than a car does all day. All so someone can clear leaves a little faster.
The only reason they’re still legal is because politicians chose the landscaping lobby over the public. That’s it.
reshared this
Sensitive content
- well, there we go, folks. Vibe coding for lunch done. I added two new features to my CLI tool: A feature that does custom URLs, so you can type in a radio station URL not listed in that Radio-browser database, and the ability to import an M3u8 playlist. I debated on splittinng out functions. Making it better, since the new helpers for custom URL and playlist handling are perfect to do it with. But then I thought to myself, "Why not just make more spaghetti code and lengthen the strands of pasta instead!" So that is what I did. Yep yep. It's an 85 KB file now, 2317 lines of code. Woah what a dump of Python! Ahahahaha I love it. Also not, but at least function blocks are denoted well with comments so you know what's going where. That will make a job of a later split way easier.
github.com/tgeczy/radio-browse…
GitHub - tgeczy/radio-browser-whiptail-cli: A Cli package for the public Radio browser API, built to be lightweight , accessible and easy to use from the ground up.
A Cli package for the public Radio browser API, built to be lightweight , accessible and easy to use from the ground up. - GitHub - tgeczy/radio-browser-whiptail-cli: A Cli package for the public ...GitHub
Malicious javascript compromise on npmjs.com
These packages, about a billion downloads prior
supports-hyperlinks
chalk-template
simple-swizzle
slice-ansi
error-ex
is-arrayish
wrap-ansi
backslash
color-string
color-convert
color
color-name
Thread follows.
Weekly download stats for impacted packages prior to incident
ansi-styles (371.41m)
debug (357.6m)
backslash (0.26m)
chalk-template (3.9m)
supports-hyperlinks (19.2m)
has-ansi (12.1m)
simple-swizzle (26.26m)
color-string (27.48m)
error-ex (47.17m)
color-name (191.71m)
is-arrayish (73.8m)
slice-ansi (59.8m)
color-convert (193.5m)
wrap-ansi (197.99m)
ansi-regex (243.64m)
supports-color (287.1m)
strip-ansi (261.17m)
chalk (299.99m)
Total 2674m
FreeBSD jails have an annoying quirk where if you don't specify jail_list in /etc/rc.conf it doesn't show you the jail names as they're starting.
This is not a solvable problem without a fairly large overhaul of how the jails are started. When no jails_list is provided, it assumes "_ALL" as the default value and this makes the jail(8) command parse all the jail config files and start them all up.
Then after startup, it prints all their names.
And then after printing their names, it writes their pidfiles.
This also means that if the startup crashes part way through it leaves jails running with no pid files which means the next time you try to start the jails you'll get errors about jails already running.
Live: Bayrou government toppled in confidence vote, plunging France into renewed crisis
France’s parliament voted to topple the government of Prime Minister François Bayrou on Monday after the PM surprised even his own allies by calling a confidence vote to resolve a months-long deadlock over his austerity budget.FRANCE 24
feld
in reply to Dan Langille • • •