#curl is RFC 9116 compliant
curl.se/.well-known/security.t…
https :// curl.se / .well-known / security.txt
#curl is RFC 9116 compliant
curl.se/.well-known/security.t…
https :// curl.se / .well-known / security.txt
Heute hatte ich wieder sehr viele sehenswerte Videos ohne Untertitel in der Timeline. Diese like & booste ich aus Prinzip nicht, denn es ist frustrierend, nicht nachvollziehen zu können, worum es geht & was gesagt wird. Das tue ich Follower*innen nicht absichtlich an.
Könnten wir daher bitte auch bei Videos verstärkt darauf achten, dass möglichst alle teilhaben können? Gerade bei offiziellen Statements gibt es in der Regel mehrere Quellen, wählt bitte die mit UT.
We seem to have data that confirms that the #curl bug-bounty has received a steep increased submission rate through 2025, while several other Open Source programs also hosted on Hackerone have not. (There's a graph coming in my pending blog post.)
What could possibly be the reason for us taking more heat and more junk than others? Why oh why?
With the four new ones from my blog post yesterday, we are at 98 graphs on the #curl dashboard.
I think I might go wild and celebrate reaching the mythical 100 graphs with a blog post if we get there.
Kejora dropped last week, and I really don’t want it to fall through the cracks.
This is a hand-drawn narrative puzzle-platformer about a little Indonesian girl who realizes her village is living the same day again and again. Everyone else is acting like it’s normal. She’s the only one clocking the loop. Which is a special kind of nightmare, if you’ve ever been the only sane person in a room.
It starts off deceptively cozy. Early 1990s rural village life. Rice fields. Forest paths. Errands. Kids being kids. Then it pivots into “oh, we’re doing this now” territory. An eldritch-looking monster shows up near the forest and starts hunting children like it’s part of the daily schedule. Suddenly you’re sneaking, solving environmental puzzles, and running for your life through caves and abandoned structures, trying to figure out what the village is burying.
The best part is you’re not alone. You’ve got two friends with you, and it’s basically a party system without pretending it’s co-op. You swap between them and use their abilities to get through obstacles, distract threats, and access areas Kejora can’t reach. It feels like childhood teamwork, except the stakes are “don’t get eaten by whatever that thing is.”
And I have to talk about the animation. It’s gorgeous. Full hand-drawn 2D characters, backgrounds, and cutscenes. It absolutely gives Studio Ghibli vibes, but it’s not Japan doing Japan. It’s Berangin Creative, an Indonesian studio, making something that looks familiar at first glance and then quietly reminds you it’s coming from a different cultural gravity.
This is why I love games as an art form. The art is beautiful, but the real hook is that you get to step inside it. You’re not watching a time-loop mystery in a rural Indonesian village. You’re exploring it firsthand, learning its rhythms, and uncovering what the town is hiding. That’s the magic.
"Jean-Baptiste Fressoz’s dizzying history of energy consumption argues that no energy transition has ever occurred: each generation consumes more of past fuels. Not only are his claims ahistorical but they justify an unwarranted pessimism about the future."

Buenos días desde la Administración Pública.
Todo bien por aquí, salvo los problemas de Outlook. Como me gustaría que me dejasen usar thunderbird.
We’re on a journey to advance and democratize artificial intelligence through open source and open science.huggingface.co
Spotify won court order against Anna’s Archive, taking down .org domain - Ars Technica
arstechnica.com/tech-policy/20…
#spotify #censorship #decentralization
Lawsuit was filed under seal; Anna's Archive wasn't notified until after takedown.Jon Brodkin (Ars Technica)
Another Trump regime accomplice falls: Lindsey Halligan is out.
Trump tried to use her to prosecute former FBI Director James Comey and New York Attorney General Letitia James, even though Lindsey Halligan had no experience as a prosecutor.
Judges ruled she had to be approved by the Senate or a district court.
She was not. Game over.
We must uncouple our attention from the tech-bro, elitist, narrative-controlling monopolies1 and get back to building individual, independant website presences. The indieweb.
Sites that are shared and aggregated by RSS feeds, collected into like-minded groups by webrings, boosted with decentralised social media platforms such as Mastodon, and cross-pollinated with interlinks and cross site conversations from individual posts.
Subvert, bypass, and starve the big platforms of their attention oxygen. Let them suffocate in a circle-jerk of AI generated slop.
There is now a growing movement of people dumping the scroll-gatekeepers, and building their own cheap, simple (often retro looking) independant websites.
Here is an example: Daryl Sun has a simple site that is packed with information and interesting links for anyone spending a little time to click rather than scroll (just like here).
In the spirit of re-wilding the web and creating interesting tendrils, I have updated my own ABOUT PAGE to let you know far more about me than you ever knew you wanted to know. It is a work in progress and will grow over time.
Another great example is Brennan, who writes some really interesting stuff and has recently begun moving his focus from posting on Medium to growing his independent site.
He always has tons of interesting outgoing links, is a member of a heap of webrings, as well as including a slash page of all his interests and projects.
I am gaining a lot of inspiration from this movement and urge you to consider dropping out of the shittosphere of big social media and spending that newfound scroll time creating your own independent online presence.
Let us tear the whole thing down and rebuild it fit for purpose.
If you already have a indie website drop me a link in the comments….I would love to follow and share.
#blackAndWhite #indieweb #photography #socialmedia
Everything you need to know about me: Who?A little about me.Contact.How to get hold of me.NOW.What I am up to in real time.Zen & me.My practice.Lens.My gear and a few of my favourite pics.AI &a…shojiwax.com
reshared this
Apply for a Xcode Performance Engineer job at Apple. Read about the role and find out if it’s right for you.jobs.apple.com
Renee Nicole Good’s family have released preliminary autopsy details.
It’s bad.
She was shot three times and the first two shots were non lethal.
One to her forearm and one to her right breast which missed all major organs.
She could have survived that.
Jonathan Ross was well outside the path of the vehicle at that point and leaned into the driver’s side window to deliver the third shot.
It went through her left temple and exited the right side of her head.
It was murder. Plain and simple.
Every ICE agent who failed to render aid should be charged as an accessory, and Ross should be arrested immediately.
The government must stop covering for killers.
Dotaz do pléna, než se obrátím na odborníky.
Mám kombinovaný plynový kotel (stará Destila DPL 25) a 150l bojler. Ten je propojen s vodou, která jde na ohřev radiátorů. Oba kohouty jsou otevřené. Bojler se spíná jen na tzv. noční proud.
Problém je v tom, že voda je v něm prostě vlažná. Jak to, co je špatně? Odtéká voda z bojleru do radiátorů a už se nestihne ohřát? Co mám jak ověřit?
Žena už je z toho nervní, asi zruším noční proud a budu platit o 10000 Kč ročně víc, ať mám klid.
#AndroidAppRain at apt.izzysoft.de/fdroid/?radd=1… tonight brought you 15 updated and 1 added apps:
* Compressor: a lightning fast, ad free, super lightweight native video compressor 🛡️
This toot comes delayed as a lot of RBs failed today. Luckily we were able to fix most of them already; for the remaining ones, issues are open with the corresponding devs.
Enjoy your #free #Android #apps with the #IzzyOnDroid repository 
This is a repository of apps to be used with your F-Droid client. Applications in this repository are official binaries built by the original application developers, taken from their resp. repositories (mostly Github, GitLab, Codeberg).IzzyOnDroid App Repo
It's not GNOME, it's not KDE, it's not the new Vanilla OS DE, it's new, uses <100M of memory, is accessible (for real) and uses GTK4 (but not libadwaita).
#Linux #Windows #OpenSource #FOSS
yes, what about it? That's still not a libadwaita-only direction given that the shell doesn't even use libadwaita
I'm not sure what you mean by GNOME OS "just existing", especially considering I use GNOME OS on my tablet and desktop nowadays and see plenty of reasons why it should exist (laptop is on Silverblue, but I plan to switch to GNOME OS some day)
I guess I'll wait to hear your detailed take on GNOME OS once you write the blog post ;). I've had a lot of issues with Vanilla OS with how outdated GNOME is, but also the unclear direction with how containers are pushed and the tooling around them, which were some of the reasons why I went straight to GNOME OS from Silverblue
@TheEvilSkeleton Maybe @mirkobrombin and I are misattributing GNOME’s vision for its ecosystem to its vision for the shell.
Naturally the shell can’t be going LibAdwaita-only, as (looking from the outside in) I would figure many shell elements, like widgets/the dock/etc, are just using GTK4—not to mention non-LibAdwaita apps still run on it. The ecosystem is what seems to be going LibAdwaita-only, both in GNOME shell, and elsewhere. I figure?
@moshimotsu ah, that clarifies it, thanks :)
Just a small correction: Shell does not use GTK; it uses another toolkit called "Shell Toolkit" - see gnome.pages.gitlab.gnome.org/g…
RE: fosstodon.org/@arcanechat/1159…
there is no backups for arcanechat.me no user data is kept in backups not even if it is already encrypted data, if the server is wipped all data is gone, but here is the twist, you will barely notice! your account will be magically restored as soon as you connect, and all your data is safely stored in your devices, in your pockets, not in some cloud a.k.a "someone else's computer"
as a #chatmail relay operator this gives peace of mind you don't get with other selfhosted chat solutions
RE: mindly.social/@Tamasg/11593603…
I concur; YAML is more readable; you chose right.
Test your damn backup scripts.
Don't just assume everything is working. Unplug servers and test it then. How will you know it's broken?
If you aren't testing your backups, you don't have backups.
I am currently using Airpods Pro 2 as hearing aids, with everything cranked as much as it can be cranked. It's probably not the best thing for my particular condition, but it works, mostly, until I can do something better, which is not now.
I have a clock in this room, which chimes every hour through a speaker.
Something about that sound freaks them out a little, and, when I also have screen reader speech or something else going at the same time, I get an almost ghost vocoder effect, where certain frequencies get modulated by the chiming clock.
It makes it almost sound like the clock is speaking, or ghost aspects of it are, anyway.
It's a bit weird.
I don't hate YAML entirely. What bugs me about it are:
* either my IDE defaults to two spaces, or that's the expected indent, because I can't use my normal tabs with it
* I still don't know when to put a hyphen before something
* I can't skip sections by using jump to matching symbol commands
* to me, it feels more fragile and harder to lint
I'm getting used to it, because Gitlab runners, Docker Compose, and other tools demand it. But I still don't really like it. JMO.
Jonathan reshared this.
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Klaus Frank
in reply to daniel:// stenberg:// • • •Alerta! Alerta!
in reply to daniel:// stenberg:// • • •From my experience: No.
Most of the sloptimists don't - for whatever reason - know about that.
In my experience most sloptimists don't even bother to read the bug-bounty docs - otherwise we'd receive much less reports as they are clearly about things exempt from a bug-bounty...
It'S fire&forget...
Every minute spent reading is lost revenue
Bruno Cesar Rocha ★ rochacbruno
in reply to daniel:// stenberg:// • • •I see why that is needed, but at the same time I think there is a thin line here, what if someone simply is not sure, a false positive, is that a waste of time to perform investigation?
That ban/ridiculation threat demotivates the report, the message simply says that if you are not a high level engineer or a big company with resources to have identified something in the field, please don't report, individuals with limited knowledge not encouraged to report and that's when the person simply chooses the easiest path: Post the report publicly to some forum or microblog and then there is a disclosure of something that should have been embargoed.
I got the motivation but I don't feel good about the wording.
daniel:// stenberg://
in reply to Bruno Cesar Rocha ★ rochacbruno • • •Wolf480pl
in reply to daniel:// stenberg:// • • •it links to curl.se/dev/vuln-disclosure.ht… which still mentions HackerOne.
I thought you were no longer using HackerOne? Or do you still use it, just with no bounties?
curl - Vulnerability Disclosure Policy
curl.sedaniel:// stenberg://
in reply to Wolf480pl • • •BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder · Pull Request #20312 · curl/curl
GitHubdaniel:// stenberg://
in reply to daniel:// stenberg:// • • •Neil Craig
in reply to daniel:// stenberg:// • • •💯
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •We will ban you and ridicule you in public if you waste our time on crap reports | Hacker News
news.ycombinator.comgary
in reply to daniel:// stenberg:// • • •