The real question is why are admins not publishing SSHFP records? (And using dnssec to secure them).

Most admins don't even publish the fingerprints in a location that users could find even if they wanted to do the verification.

Ask yourself, how would you do the verification today?

Blaming users for a failure of the admins is just lame.

> hachyderm.io/users/simontatham…

in reply to John-Mark Gurney

if you control your infra end to end, why do you need SSHFP? You can have all your servers publish their keys into LDAP automatically and then those can all be injected into the known_hosts on every admin's workstation. This is how I've seen it done. You always know the correct public keys for every server and don't have to involve DNSSEC in the mix.

If the attacker can get enough control to mess with those LDAP records DNSSEC wouldn't have mattered, they probably could also gain access enough to change the SSHFP records too.

I could see SSHFP being useful for internet facing sshd, but just put it all behind a VPN and then I think it doesn't matter as much anymore except in the most extreme security-sensitive scenarios.

Если верить Платону, человечество потеряло способность мыслить, когда бог Тот подарил египтянам письменность. Не знаю, смог бы я с ним подружиться, но тут он точно не прав. Имхо, всё развитие человечества происходит скачкообразно — в моменты, когда мы находим новые способы обработки информации: изобретение письменности, книгопечатание, математическая нотация, компьютеры и вот теперь ИИ

Looks like I got parodied yet again a couple days ago. If you received a follow request from it, it was most definitely not from me, but rather a certain troll who is, I'm sure, very upset with me at the moment. Anyway, as a reminder, this account I'm writing from is genuine. You can look at my profile to be certain; it's got significantly higher numbers than the parody one.

I love Joplin so much. I set up the selfhosted Joplin Notes at some point, and I have never, not even one time, had to touch it. It updates itself, it doesn't crash, it doesn't take up enormous amounts of system resources for no reason, and all the apps just work with it on my Windows, Mac, and IOS computers. I've even got other users on it, and it works just fine. And the apps are also good. Offline? No problem! You can still look at the last version of your stuff. Need to publish a quick, well-formatted single page to the web? Done with a snap!

Peter Vágner reshared this.

in reply to Nick Giannak III

@nick@quinn You could also run cosmos-cloud.io. It'll run and update your dockers for you, configure your reverse proxies, manage your SSL certs, etc. But the nice thing is it uses the standard methods to do all of those things, so unlike other server management GUIs, you can do stuff via the command line or via cosmos-cloud and it doesn't matter.
in reply to Matt Campbell

@matt@nick@quinn to be fair, it's not something you should do in an enterprise environment. In general, updates for things that aren't your hobby need to be deployed to staging, tested, and only then pushed to production. Watchtower just does an in-place update of the containers. But that's fine, and probably even better, for hobby projects.

I've been using IndentNav for a while to write Python. Recently I installed BrowserNav and now get way more positional info about HTML elements. It took some getting used to, but now the beeps and tones help me get an idea of the physical layout of a site or electron interface.
It's similar to IndentNav, but it has more rules and works with web browsers instead of being focused on code in a text editor. Positioning is one of the pieces of information that I forgot how much I miss from my sighted days. It's especially helpful with API reference docs that rely on positional encoding. Since there's more info in the browser, I only have beeps instead of precise indentation levels to get a general idea of the structure
#blind #nvda #nvaccess #browsernav #indentnav #accessibility #code

reshared this

For a while now, I've been trying to figure out why certain VST plugins would completely crash Reaper, or at best, break the entire plugin stack, which would at least give me enough time to save a project.

Turns out the problem was a virtual display driver I installed a while back, which apparently has some weird conflict with the AMD graphics driver on this laptop.

When certain VST plugins attempted to render their on-screen interface, bad things happened, and error code 87 occurred.

Removing the virtual display driver fixed it.

Windows is dumb.

This entry was edited (1 week ago)

HumanWare’s Prototype AI Features for Ray-Ban Meta Glasses doubletaponair.com/humanwares-…

Good news! It's getting harder to keep track of new #chatmail relays :)

Recently several public relays were added to the chatmail.at/relays list, in Warsaw, Helsinki, Romania and Barcelona.🧡

If you have #deltachat installed on mobile, you can go to any chatmail relay website in the list and click on a link there to create a chat profile.

It's wonderful to hear about collectives setting up chat infrastructure like the recent xat.fedi.cat from @fedicat and @eXOfasia

Peter Vágner reshared this.

in reply to Tom

@pertho I have a public Chatmail server and people I don't know have made accounts on it. I also have another running in South Africa under the domain e2ee.wang

When multi-transport is finished basically everyone's public Chatmail server will be routing messages for anyone who needs it. I've also brought up the possibility of using LoRa or Meshtastic type radios connected to the server to allow people under censorship situations or during internet outages to still be able to route low bandwidth messages to another Chatmail server which can then forward it on and deliver to the intended recipient.

@Tom

Lawsuit alleges games gathering children’s personal data

ctvnews.ca/montreal/article/qu…

If only there was a federal Government that could put forth some privacy legislation to protect Canadians. But I guess the industry lobby doesn't want it.

#cdnpoli

If only the #CAQ was concerned about such things, eh. Nah, let's have more wars against fabric and jewellry.

Lawsuit filed in Québec and targets more than 40 gaming companies, including Gameloft, Bandai, Nintendo, Microsoft, Ubisoft, etc. ctvnews.ca/montreal/article/qu… #gaming #children #privacy #personaldata #polQC #QCpoli #CAQASTROPHE

Idea that just popped into my head: A cloud storage service or application which transparently makes use of lossless compression, potentially offloaded at least partially to the user's machine, and only bills you for the space taken up by the compressed file, while leaving all files uncompressed on the user's own file system. If compression and decompression take place at the client end, this reduces bandwidth. Obviously compressed data like zip files, and anything already using lossy compression like mp3s, is passed through unchanged. Known good compression algorithms and lossless transforms are used for certain kinds of data, E.G. WavPack for wav and some AIFF files, or flac if it can give bit-exact copies of every chunk, BMP automatically converted to/from PNG, etc. Something like brotli or zstandard for the rest, potentially with user-specific dictionaries which build up over time with their file history. For some users, it has no benefit at all as they're likely to already be handling compressed files, JPEGs, MPEG4 videos etc, but for others, it provides primarily a method of convenience, they don't have to manually get all these tools involved to maximize their storage potential with certain files, and they don't have to constantly convert back and forth with a copy elsewhere if they need to, say, actually work with the raw wav file for whatever reason.

Mastodon is quite silly. It almost looks to me like looking at a trunk line of conversations. Or perhaps a trunk radio system. There is little to no flow to anything, parts and snips of conversation are everywhere, and a lot of things are unrelatable, even with the fetch all replies feature. Sometimes it works, sometimes it doesn't. Not to mention the annoyance of having to open each thread to check what's available, every, single, time...
And even when it appears to be working, and you've opened the thread, and you're seeing replies, you're still left scratching your head, well did it really fetch everything? Is there more to the story?
However, the Mastodon project sure is actively and vibrantly being maintained and enhanced, so I am hoping threading becomes a greater focus and increased reliability comes in the near future.
#AmusedAnnoyedRamblings #Mastodon
This entry was edited (1 week ago)

“Look. What do you see?”

“Nothing.”

“Billions of atoms, spinning at random, expending energy, running down, achieving nothing.

“Entropy, like the stars. But what is the one thing that stands against entropy, against random decay? Life. See how the atoms are arranged here? They have meaning, purpose.”

— Skagra and Romana, in “Shada”

#DoctorWho #quote #quotation

Toronto friends: The Rocky Horror Picture Show with live audio description
The Disability Collective presents!
Let's do the time warp again! Back by popular demand, don't miss a screening of the cult classic The Rocky Horror Picture Show featuring audio description by JJ Hunt, and an all-Deaf shadow cast at Buddies in Bad Times Theatre on October 28th and 29th at 8 pm! Come sing, dance, and sign along to kick off your Halloween!
Damnit, Janet! Let's make Halloween accessible!
You can visit this link for pay what you can tickets, and or email Ali Hand ali@thedisabilitycollective.com to reserve an audio description device or for further support.
showpass.com/the-rocky-horror-…

I wrote this with a bunch of good folks in the #Drupal community

A New Era of Digital #Accessibility: The #EAA and its Implications for Drupal drupal.org/association/blog/a-…

/c @drupalassoc

If you want to understand how untenable, radically new, and ridiculous the anti-trans idea of gender is, just consider Laker Jackson. He's an eighth grader in Arizona that is no longer allowed to participate in sports with his peers or use the boys facilities, despite having done so his entire life up until now without issue. He's a kid just trying to play sports with his friends and pee in peace.

He's also not trans.

Laker is a cis boy, but his birth certificate listed his assigned gender at birth as female. Because of anti-trans laws, his family can't correct the problem. Literally just a clerical error is all it takes for the government to decide, against all reason, that Laker is a boy.

Congratulations, the government now gets to decide your gender. That's a new power that the far right has decided the government should have over the past few years.

#AndroidAppRain at apt.izzysoft.de/fdroid/?radd=1… today brings you 10 updated and 1 added apps:

* PrivacyFlip: automatically manages your device's privacy features based on screen lock/unlock state 🛡️

1 #Magisk module was added to apt.izzysoft.de/magisk

* ReZygisk: standalone implementation of Zygisk

Enjoy your #free #Android #apps with the #IzzyOnDroid repo :awesome: