one of the most common security reports we get in #curl is claims of various CRLF injections where a user injects a CRLF into their own command lines and that's apparently "an attack".
We have documented this risk if you pass in junk in curl options but that doesn't stop the reporters from reporting this to us. Over and over.
Here's a recent one.
curl disclosed on HackerOne: SMTP CRLF Injection in curl/libcurl...
SMTP CRLF Injection Vulnerability in curl/libcurl ## Vulnerability ID: CURL-SMTP-CRLF-2024 ## CWE-93: Improper Neutralization of CRLF Sequences ### Executive Summary curl/libcurl contains a CRLF...HackerOne
StreetComplete is a really fun and accessible way to contribute to OpenStreetMap from an Android device - walk around in your local neighbourhood (or anywhere really) and solve 'quests' by answering questions about the things around you!
You don't need to learn anything about mapping conventions, or infrastructure, or about the more complex mapping tools that exist for OpenStreetMap. The app will explain everything to you that you need to know, when you need to know it, and ask easily understandable questions with reference pictures for the answers.
The only setup needed is to make an OSM account and log into it from the app, so that it can upload your answers - and you can also do that at any later time, after trying out the app without an account for a while first. You can just install it and go outside right away!
The app doesn't need any cellular internet connection; it can work offline and synchronize your answers once you reach a place with eg. WiFi. It's also quite performant, and should run well even on lower-end phones. There is also a 'multiplayer' option that lets you split up in teams and each tackle different quests in the area.
Part of the reason I’m so against LLM coding assistants is that it seems like it can do nothing but suck all of the joy and fulfilment out of work.
Like, for any task that requires skill, there’s some pleasure in using that skill and succeeding at it. Why would I want to automate it?
It’s like the thing of “automating my hobbies so I can spend more time doing the laundry”.
And obviously, yes, I do realise that my job doesn’t simply exist for the sake of me having fun. I don’t actually expect that to be a persuasive argument from a business perspective. But what makes the whole thing completely inexplicable to me is that this automation doesn’t even do a good job or speed things up at all.
All the code I’ve seen from LLMs has been total garbage. At best, it’s eventually come out with something as good as a human could do, except no faster, and through a process that’s far more annoying and unpleasant than simply doing the work manually.
There’s literally nothing in it for anybody (except the LLM companies, who get a subscription fee for doing something you could have easily done yourself, and who, when you complain that the results are bad, invent nonsense like “you have to have multiple LLMs all checking each other’s output” to wring more money out of you).
- Accessible Output (50%, 1 vote)
- Tolk (0%, 0 votes)
- SRAL (50%, 1 vote)
- Other (Specify In a Reply) (0%, 0 votes)
@jscholes Yes. And spoon-feeding text to a screen reader should not be what developers primarily think of when they think of accessibility. The actual GUi should be made accessible through platform APIs. I know you know this, of course; I'm just stating it for the benefit of anyone watching who is outside the cottage industry of apps developed specifically for and usually by blind people.
GitHub - AccessKit/the-intercept: Proof of concept for integrating screen reader accessibility into Unity; fork of Inkle's game The Intercept
Proof of concept for integrating screen reader accessibility into Unity; fork of Inkle's game The Intercept - AccessKit/the-interceptGitHub
🇨🇦Samuel Proulx🇨🇦 likes this.
@fastfinge There are different use cases with various constraints.
I used the word "primary" on purpose in my first post. Right now, screen reader libraries are the first and often only thing reached for by developers of these abstraction libraries.
I would like to see a better abstraction library that keeps the ease of use while supporting multiple techniques. It could opt for the most reliable and user-friendly pattern by default based on information glean from its operating environment and some gentle hints from the developer.
E.g. you don't supply a window handle? There's no window for a live region so it falls back to SR libs. @matt @tunmi13
@matt User control is one reason live regions are a better idea than screen reader libs at least, because I can turn them off.
If an app has decided to shove stuff down the NVDA Controller Client DLL, there's nothing I can do about it. Other than maybe deleting the DLL or restricting access to it, at which point it's anybody's guess whether the app in question will go silent, crash, or switch to SAPI.
Of course, this begs the question about why screen readers don't have a permissions system. @fastfinge @tunmi13
🇨🇦Samuel Proulx🇨🇦 likes this.
nbcnews.com/politics/supreme-c…
Supreme Court rejects long-shot effort to overturn same-sex marriage ruling
WASHINGTON — The Supreme Court on Monday turned away a long-shot attempt to overturn the landmark 2015 ruling that legalized same-sex marriage nationwideLawrence Hurley (NBC News)
Everyday discovering something brand new!
I really need a ruler and pencils to spear time at job... hold my beer.
edit: hold my ruler 😂
edit1: bartender ask me why im laughing.. u know Lexaurin uhm Mastodon and so on 😂
edit2: i didn't know how many people taking them btw
edit3: it wasn't one time this season to customers asking me for...
Ouch. I was really happy to discover LibreOffice Impress Remote app for iOS - but the last update was in 2014 and it doesn't run on current iOS :(
Not reflected in the current docs it seems, ping @libreoffice
Any iOS developers with spare time wanting to get it up to speed? :)
Long-term archiving with ODF: a future-proof strategy - The Document Foundation Blog
Digital documents in proprietary formats often become inaccessible within a few years due to undocumented changes to the XML schema that are intentionally employed for lock-in purposes.Italo Vignoli (The Document Foundation)
Hello mr Slop, so we meet again...
curl disclosed on HackerOne: Unsafe use of strcpy in...
I've provided the detailed description and clear steps previously, but it seems you need the content tailored directly for the submission form's fields. I will present the complete, professional,...HackerOne
The Louvre’s surveillance password was literally… “Louvre.” 😳
Here are 3 password manager tips from Tuta you need to hear 👇
Tip 1: Use strong, unique passwords
Tip 2: Never reuse passwords
Tip 3: Enable 2FA (two-factor authentication)
#CyberSecurity #JewelryLourve #Lourvepassword
Finally got a chance to read @sundress's thoughtful post outlining the "Why" behind the state of accessibility on the web and it is spot on! If you haven't already, please give it a read: alice.boxhall.au/articles/a-th….
A threat model for accessibility on the web - Alice
A explanation of the primary threat to accessibility on the web, and a call to action for the web standards communityalice.boxhall.au
Frage an @librechurch @luki und die sozialengagierte Welt:
Gibt es eine Art kirchliche oder sonstwie alternative #Etherpad-Installation, wo man den Zugriff auf die Dokumente einschränken kann? Also, nicht nur "wer den Link weiß", sondern mit persönlicher Anfrage oder Passwort? Und nein: googledrive soll es nicht sein.
pad.churchx.de/ kann es wohl nicht.
Für eine #Cryptpad-Instanz können die Teilnehmenden sich registrieren und ein Team bilden. In der Dateiablage für das Team kannst du gemeinsam genutzte Dokumente ablegen.
cryptpad.luki.org/teams/
siehe auch die Abschnitte Zusammenarbeit und Teilen/Zugriff in der Userdokumentation
docs.cryptpad.org/de/user_guid…
FediVerseExplorer likes this.
mňa nie ja zatiaľ verím v sám seba ale chápem akože
aktuality.sk/clanok/Zia11n2/sl…
Slovákov opäť valcuje pesimizmus. Odborníci vysvetľujú, prečo sa bojíme o prácu aj peniaze
Alarmujúce čísla: Dôvera v slovenskú ekonomiku padá a v októbri dosiahla 15-mesačné minimum. Hlavné ťahúne, ako je automobilový priemysel, hlásia problémyMartin Odkladal (Aktuality.sk)
bathing
I use @OpenBSDAms btw
#unix_surrealism #openbsd #vmm #vmd #poster #comic #linux #plan9 #glenda
reshared this
In the #curl security team, we get to exercise deep protocol knowledge into the bits for many protocols including version variations and exploring funny quirks we have for adapting to many 3rd party libraries as well as a thorough understanding of the C language, how ABIs work, OS/platform variations and the occasional CPU peculiarity. Did I mention build systems?
And that's only for the issues we received this weekend.
Ken Thompson, Reflections on Trusting Trust, 1984
If Brodie can't stop sending harassment against our developers, I think we should just ignore him.
He hasn't taken any responsibility yet and if you have build such a community around your videos you are accountable for it.
Period.
Could at least delete all the haters comments and actually start moderating, but apparently that's too much work.
as a regular viewer, I don't remember him sending harassment towards anyone. If anything, I remember him specifically (and seriously) telling people not to harass anyone, on multiple occasions.
I'm not happy about his comment section / community either, but let's at least not throw around such accusations.
@mks_h there is responsibility for owns viewers and community as well.
"do not harass anybody" means nothing in practice. Otherwise would it make bigots be non bigots if they just say it every video but their viewers constantly are transphobic/racist/etc..?
Harassment is allowed in the comment section, therefore it's also allowed elsewhere.
The people harassing our community are welcomed in his community with open arms, because apparently doing it there is better than.. not?
João Santos
in reply to daniel:// stenberg:// • • •Adam Katz
in reply to daniel:// stenberg:// • • •SMTP Smuggling - Spoofing E-Mails Worldwide
SEC Consult Unternehmensberatung GmbHRon Bowes
in reply to daniel:// stenberg:// • • •nilclass
in reply to daniel:// stenberg:// • • •I found that if I pass the URL of a website to curl, and the website contains private information, it prints private data to my terminal, which is clearly a GDPR violation!
/s
Multi
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Multi • • •xinit ☕
in reply to daniel:// stenberg:// • • •