Most breaches actually begin in corp:

Readers of my blog will note that while I believe Rust is an excellent tool for developers to leverage when building software, that there is a disconnect between the developers leveraging Rust features to improve their software and many of the advocates who talk about the language, which I believe is counterproductive when it comes to Rust advocacy.


ariadne.space/2023/12/07/most-…

Canard enchaîné : Olivier Dussopt, un ministre bien ménagé
Depuis que la direction du Canard enchaîné a sollicité ses services pour licencier son journaliste Christophe Nobili, le ministre du Travail Olivier Dussopt est quasiment absent des pages du journal. Malgré son procès pour favoritisme. Tout sauf un hasard.

blast-info.fr/articles/2023/ca…

Jako chápu tu hospodářskou linku (a její popis na Hospodářkách). Ale hlavně je nedůstojné v roce 2023 upírat lidem normální lidská práva. Ať se stydí všichni co se na tom podílí. #svoboda

🔓 archiv.hn.cz/c1-67273260-vice-…

🎅 Christmas surprise! 🎄 We're giving away secure email inboxes again! 🎁 The perfect opportunity to switch to secure and private email communication. Find out more in our blog! mailbox.org/en/post/christmas-…
#christmas #dataprotection #gifts

Firefox survey

Edit: follow up survey on what people use to block Google Analytics - mastodon.social/@lufthans/1115…

When using Firefox which of the following do you do?

See Esther's post for article about Firefox being at only 2.2% use per Google Analytics for US government sites:

mastodon.social/@estherschindl…

Feel free to boost for visibility

#Firefox #InternetPrivacy #WebPrivacy #DigitalPrivacy #GoogleAnalytics #InherentlyBoostable

  • use a DNS blackhole to block Google Analytics (36%, 152 votes)
  • use browser add on to block Google Analytics, ad b (80%, 330 votes)
  • don't block Google Analytics in any way (4%, 19 votes)
  • Pepper&Carrot ( see results w/o participating ) (5%, 23 votes)
412 voters. Poll end: 2 years ago


Firefox survey II

For those of you who block Google Analytics, which of the below do you use?

This is a follow up to last week's survey:

mastodon.social/@lufthans/1115…

Feel free to boost for visibility, comment for specific tool recommendations

#Firefox #InternetPrivacy #WebPrivacy #DigitalPrivacy #GoogleAnalytics

Edit: bah, survey fail, forgot to make multi-select


@openuk I'd love to see this Mastodon profile up here stateofopencon.com/advisory-bo…

Even better, I'd love to see the links to their Mastodon accounts.

We really have no idea how much longer Twitter (or X) will exist.

@fwd50 has already leveraged it this year.

Plus, #Mastodon is #OpenSource so ...

Detroit touts first wireless-charging public road for electric vehicles in US: freep.com/story/money/cars/202… #detroit #cars #ev #roads

What this article doesn't mention is that when a malicious app open a WebView to log into a website, that app can use JavaScript injection to steal the password even if you don’t use a password manager at all and type it in yourself.

techcrunch.com/2023/12/06/your…

The real problem here is that the entire mobile industry has fomented this incorrect belief that somehow it ought to be possible to run malicious apps on your phone without being affected by them.

in reply to HCJ

@hcj So, one discussion is about the apps we allow to run on our devices, and whether they are trustworthy. I would posit that having the source be open is a fundamental aspect of being able to trust such apps. Note that it is possible for the source code for an app to be available and for that app to not be trustworthy, as having the source code is only one of the requirements. But it isn’t possible to trust an app when the sourcr code is not available and you don’t know what it is doing.
@HCJ
in reply to Soren Stoutner

@hcj I don’t trust Google Authenticator because I have no way of knowing what it is doing with my data.

github.com/google/google-authe…

@HCJ
in reply to Soren Stoutner

@hcj Another discussion is about the cloud services our apps connect to. Ideally, those should also be open source. But, the problem is that, even if they are, we have no way of verifying that the code running on the server is the same as what is published. For security sensitive situations, the only SaaS we can trust are those that are federated, where we are running our own instances. I do that in a number of cases, like with Nextcloud and Matrix.
@HCJ
in reply to Soren Stoutner

F-Droid signs all their builds with their own key. However, if a developer sets up reproducible builds, the F-Droid version will be signed by both the developer key and F-Droid's key. This prevents either party from inserting malicious code into the app that is different from the publically available code.

f-droid.org/docs/Reproducible_…

This entry was edited (2 years ago)

Our latest release is now available both on @fdroidorg and #GooglePlay!

Do you use AntennaPod while on the move? 🚴No more need for acrobatic (and in some places illegal) acts on the bike to skip those ads or go back to catch that comment. Or to take off your gloves to tap the screen while it's cold. 🥶

Version 3.2 now allows you to double/triple-press physical buttons to fast forward or rewind!

Get it here now:
f-droid.org/en/packages/de.dan…
play.google.com/store/apps/det…

github.com/rust-lang/rust/pull…

Soon you will be able to write c"Hello" in rust and get a valid UTF-8 encoded *NUL-terminated* string. This is amazing for people who work with C APIs.

No i skończyło się rumakowanie, bo zawiadomienie do UOKiK w sprawie Newagu składają parlamentarzyści, w tym Pola Matysiak @polamatysiak, która takich numerów na kolei nie odpuści. Widać to zresztą po bolesnym dla Newagu pytaniu:

"Chcemy, aby polski podatnik wiedział za co dopłacał. Pragniemy też, aby pasażerowie kolei usłyszeli, że mogą się czuć bezpiecznie w polskich pociągach bezpiecznie."

Jeśli polski podatnik dopłacał za nic, no to trzeba będzie kasę oddać, a liczyć się z karami. Kilka lat zakazu brania udziału w przetargach dla spółek państwowych i samorządowych to byłaby kara zapamiętana na długo.

Pytanie Adriana Zandberga (jest na mamucie?) wbrew pozorom też jest ciężkiego kalibru:

"Zwracam się do Pana Jakubasa o jasną odpowiedź: czy w firmie Newag dochodziło do praktyk, które zostały opisane w mediach?"

Oczywiście Jakubas może nie odpowiedzieć, ale to jak przyznanie się do winy. Z kolei zaprzeczanie może być bardzo słabe wizerunkowo, gdy zarzuty zostaną potwierdzone. A biorąc pod uwagę to, co już wiemy, to z ich potwierdzeniem nie będzie szczególnych problemów. Wiem, wiem, jest trzecia opcja, branie na klatę, no ale xD

Za oknem mróz, ale w siedzibie Newagu chyba zaczęło robić się ciepło.

🌐 klub-lewica.org.pl/aktualnosci…

#️⃣ #Newag #Kolej

Stay fresh: #LibreOffice 7.6.4 and 7.5.9 are now available for download. All users of the 7.6 and 7.5 branches are recommended to update: blog.documentfoundation.org/bl…

LibreOffice reshared this.

Wanted: Web Document/PDF Accessibility specialist - REMOTE [US?] linkedin.com/jobs/view/3780561… Make sure your résumé doc is accessible! #a11y #pdf #jobs #docs

V seznamu projektiku jsem se konecne dopracoval az k lbc wtf. Na to jsem se tesil uz od chvile, kdy jsem narazil na pruvodce po Liberci z roku 1966.

Ted to technicky zhmotnuju:
👉 Vezmu Leaflet a Protomaps vysek Liberecka.
👉 K memu hipsterskemu pribehu na Mastodonu pridam geotag.
👉 Magie zobrazi moje #lbc prispevky v mape na webu.

Lokalni influencer in the making! Dal jsem si vyzvu mit to cely staticky, ale editovat v Nextu DB je pohodlnejsi nez .json na CDN. Tak uvidime.

#projekt #tech

🚨Warnings from Sen. Ron Wyden reveal that governments around the world are #spying on #Google and #Apple push notifications. 🕵

Tuta introduced our own custom push notification system for #Android devices which are fully encrypted and #surveillance resistant. We include minimal information in #iOS push notifications to counter this threat.🔒

Surveillance requests should be transparently disclosed by Apple and Google, not silenced by a gag-order! 🤐

👉 tuta.com/blog/open-source-emai…

J'adore le rock nigérian (tuareg) !
youtu.be/GZvPoE0EH1o
Mdou Moctar - Tarhatazed (Live on KEXP)

En plus ça permet de faire des jeux de mots débiles tout en faisant connaître cette culture musicale.
"Tarhatazed" c'est un peu comme "Tahartagueule (à la récré)" mais en mieux que quand c'est Souchon...

#culture #musique #rock #Niger #Tuareg #MdouMoctar #pouetradio

in reply to Kuketz-Blog 🛡

Vielleicht magst Du ja auch FOSS Alternativen zu Firebase erwähnen? Für etliche proprietäre Bausteine habe ich solche in meinem Snippet gesammelt. Für Firebase hier: gitlab.com/-/snippets/1896503#…

* Appwrite: github.com/appwrite/appwrite (BSD-3-Clause)
* SupaBase: supabase.com/ (Apache-2.0)

Beide decken so ziemlich das Meiste ab, was Firebase bietet. Dazu dann noch UnifiedPush statt FCM, sowie alternative Analytics/CreashReporting Dinge, auch im Snippet aufgeführt.

In case anyone is wondering about how to "update" a valid certificate from #letsencrypt that for some reason #prosody states is already expired, just run:

prosodyctl --root cert import /etc/letsencrypt/live

Assuming you have a valid certificate in place already configured for your domain. Saved me some headache!

More info: prosody.im/doc/letsencrypt

#xmpp #selfhost

sledování bezpečnostními složkami

Že se push notifikace používají nejrůznějšími státy ke sledování lidí, to víme nejpozději od roku 2021. Teď se ale snad dozvíme, jak moc.

9to5mac.com/2023/12/06/push-no…

Wer eigene Mail-Server betreibt, weiß, dass das leider Alltag ist. Für die drei Mail-Monopolisten (Google, Apple und ganz speziell Microsoft) ist jede Mail, die sie nicht selbst versenden, per se verdächtig. Jede Kommunikation versandet. Wenn das Problem behoben wird, tritt es nach drei Monaten wieder auf usw.

Es wäre schön, wenn die EU da einmal drauf' schauen würde. Das wäre wichtiger als die Cookie-Regeln.

tuta.com/de/blog/outlook-false…

Už máte všechny dárky k Vánocům?

Tak tady je ještě nemají. Dopřej dětem v děcáku #Vánoce a #DarujHračku

#GLS to zdarma sváží už jen do 13.12.2023 17:30 - nevaž se, odvaž se! :)
app.daruj-hracku.cz

Neskromně žádám o boost, ať se to dostane co nejdál. I kdyby to mělo znamenat radost jen pro jednoho prcka, stojí to za to. Děkuju

This entry was edited (2 years ago)

How the first gen ipod was reverse engineered to run #Rockbox:

1. Someone figured out that when loading a particular HTML page (for viewing on the device), the device would reboot. It crashed. A buffer overflow in the HTML viewer!

2. The device remembered what it did before the crash, so it would reload the HTML page again after boot. Unless you connected to it over USB and removed the HTML file it would stick in this cycle.

(continues...)

This entry was edited (2 years ago)

reshared this

nemal som úplne dobrú náladu včera a kolegyňa

mi hovorí: čo?
hovorím: hovorí sa prosím
:kekw:

bola z toho trochu vykoľajená, pointa: youtube.com/watch?v=ydhf0JB4Y3… a všetci chcú ísť na výšku do zahraničia.. toto je horšie ako Fico si myslím

This entry was edited (2 years ago)

Exšéfa čínské banky odsoudili za úplatky k smrti, kolos CITIC operoval i v Česku ….

… ach, počkejte. CITIC? Jo, už si vzpomínám. Tvrdík! Místopředseda představenstva CITIC Europe Holding, poté člen představenstva

Asi nejlepší pro připomenutí prodejnosti některých jedinců je souhrn v hlidacipes.org/co-zbylo-z-cins…