People wonder why I am always so harsh on #LastPass. Thing is, I’ve been watching them ignore security risks for years. Yes, things that they are being warned about again and again, yet they choose not to address them.

You think unencrypted URLs are bad? Take a look at this seven years old presentation by Martin Vigo and Alberto Garcia Illera: blackhat.com/docs/eu-15/materi…. Starting with page 69 it explains how the custom_js feature could be abused to extract users’ passwords.

Guess what, this feature is still present and used on PayPal for example. Still no encryption and nothing to protect the users. No change whatsoever in at least seven years that LastPass was made aware of this issue.

Instead, when disclosing #LastPassBreach they again lie that they don’t have access to your passwords. But they do. Anyone with access to their server does. NSA could order them to extract your passwords. Hackers who gain access to their server could abuse this to get your passwords. Or just to run their JavaScript code on any website, and then they don’t even need your passwords.

And that’s only one out of the many documented backdoors that LastPass chooses to ignore, both in terms of implementation and their public communication.

#infosec #ApplicationSecurity

If you want to gift all Delta Chat users something you may boost or forward delta.chat/en/2022-12-15-uidev… to somebody who might be interested to help with Android/iOS or other developments. We wish you all some good last days of this year!

Hey folks!
As part of my new year resolutions, I decided it's time to pass the torch for the @crossposter maintenance to someone else.
This is not about maintaining the service, but the tool itself, the dev side of it.

If you're into #ruby, #RoR and you used the crossposter, reach out: github.com/renatolond/mastodon…

Please boost for reach :)

#crossposter

audiogame-manager
stormdragon2976 pushed changes to the testing branch of the audiogame-manager project: git.stormux.org/storm/audiogam…
All wine bottles are now sandboxed. I think I have everything working like it should, but there certainly could be bugs. If you would like to help test, please install your favorite games and make sure they work just as well as before.

Sprachfilter


@Friendica Support Ich habe jetzt diesen Sprachfilter gesetzt, weil mir die englischsprachigen Beiträge mittlerweile überhand nehmen:
1. Muss ich "Den Sprachfilter verwenden" noch aktivieren, damit diese Einstellung wirksam wird?
2. Was konkret bedeutet Vertrauenslevel in die Spracherkennung? Den erläuternden Text verstehe ich nicht.
This entry was edited (3 years ago)
in reply to Gerhard Hallstein

1. Sprache, die Du sehen willst in die "Lesbar"-Zeile eintragen (zB "de" wie gezeigt)
2. "Den Sprachfilter verwenden" durch Haken setzen aktivieren
3. Der "Vertrauenslevel"-Schieber setzt die Zuverlässigkeit, mit der alle übrigen Sprachen erkannt und ausgeblendet werden. Im Beispiel muss sich der Algorithmus mindestens 32(%-ig (?)) sicher sein, um den Text einzuklappen. Es wäre unklug, einen sehr hohen Wert zu wählen, weil dann zu viele Sprachen nicht "sicher" erkannt würden und daher sichtbar blieben. Zu geringe Werte hingegen blenden ggf zu viele unsicher erkannte Texte aus. Musst Du ausprobieren und den für Dich akzeptablen Wert selbst finden.
Und am Ende nicht vergessen, die geänderten Einstellungen unterhalb des Dialogs zu speichern.

Putting this together was lots of fun. Thank you for all of your interactions and encouragement. I was glad to see that I made some of you happy. Here's to hoping I can come up with something creative in the future.
It was suggested to me that I should archive all of what I posted in the series. I wouldn't like to promise anything at this point but I'll look into options.
And now, speaking of charts, I leave you with Martin Garrix's "Animals", a chart-topping track from, I believe, 2014, remixed to the tune of a traditional Polish Christmas carol. Enjoy! and have a merry celebration of the festivity close to your heart. If you don't celebrate anything, have a great day as well!
youtube.com/watch?v=J_Ks0EkRsy…
in reply to Boring Nondescript Little Worm

One thing I want to note--given my wrist situation, almost all of the game's art was drawn by voice.

The software itself gave me a lot of trouble though, so I've decided to make a fork and do further dev & maintenance on it.

While I don't know how many people would use it, I think idea of a #PixelArt editor designed for hands-free #accessibility might have legs and I want to explore that further.

With a delay, we arrive at the last window of the accessibility for the blind advent calendar.
This one might be known to some of you as the news has reached quite some peak in media outlets worldwide. Accessible Christmas was an app developed to let blind people enjoy the Christmas lights of Madrit through a geolocation-based audiodescription experience. The great thing about it was, you could also access these descriptions wherever you were. Many blind people do not have the privilege of worldwide mobility so bringing bits of the world closer to them is what I call an extension of accessible tourism. Describing the world you experience through textual blogs, social media postings, audio recordings and sharing interesting highlights of life in different countries is what you can do next year to make others travel even if they physically can't. If you're the one unable to travel, here are a couple of things that help me personally when I wish I could be elsewhere but can't:
1. Play a random radio station in a language you understand nothing of or find the music that you like coming from somewhere obscure or far away. I enjoy checking out local charts in other countries just to see how different languages fit into the music trends of today.
2. Try to find recordings of places on sites like Freesound or Soundcloud; close your eyes and imagine.
3. Read travel blogs, watch or listen to content on the Internet of others travelling where descriptions are abundant; research how topics that interest you are managed elsewhere.
4. Try to find penpals, somebody to exchange occasional packages with and simply make friends; if that's possible, try to find a local language conversation group, groups for people who have moved to your city etc. meet, ask questions but most of all, listen!
5. Maybe one day make your own advent calendar.
coolblindtech.com/this-app-all…
#Accessibility #Blind AdventCalendar #Spain #Travel #Tourism

reshared this

in reply to Ashwin Baindur

@ashwin_baindur @Nuno
I think that will go down in the history books as a gross mistake: to dismiss outright even exploring the possibility of Russian membership of NATO.

There will be inevitably be some within the American Industrial War machine that are not fans of making peace with their enemies and thereby put themselves out of a job.

en.wikipedia.org/wiki/Russia%E…

in reply to blogscot 🏴󠁧󠁢󠁳󠁣󠁴󠁿

@blogscot @ashwin_baindur I think that its reversed. That only some units in the USA terrorist war machine want to make peace with their enemies, and most of them doesn't. 99% of their economy is based on murder, blood and suffering. If not for the Nazi scientists after WW II they would be subdued by now

15 Famous Black Architects - First African-American Architects

Most people can’t name one black architect, here’s a list of 15 great black pioneering architects, including Beverly Loraine Greene, first black female architect.

#BlackHistoryEveryDay #BlackMastodon #BlackTwitter

veranda.com/home-decorators/g3…

Hello #Fediverse! #Pinetta is a decentralized FOSS social pinboard in the style of Pinterest. After a month of planning, we've settled on a basic game plan and are opening up our @Codeberg repo for contributions from devs and designers!

We'll be working on a prototype that uses #Python and #Django to get the basic functionality working. We'll also be hosting weekly sharing sessions on #CommunityBuilding principles to develop our Code of Conduct and a larger framework for community wellness. 🥳

Peter Vágner reshared this.

Current status:

WebExtension to post current tab URL to the Fediverse

github.com/hfiguiere/toot-that

This is actually posted with it. I archived Tweet-that.

Before a release I need to make an icon (this use the bird's).

And this is Firefox only for now.

Meson 1.0 is out!

Congratulations to Jussi and everyone who contributed to Meson over the past 10 years, and here's to 10 more years of improvements.

nibblestew.blogspot.com/2022/1…