So... Has anyone on here actually talked with the people from the #SocialWebFoundation?
I can tell the #Mastodon Organization has, but #Threads is also listed there, while I don't see any other names that aren't some corporate entity. I'm all for groups that want to expand the #Fediverse, even for-profit ones, but it's a red flag when an organization that purports to be for a general movement doesn't have an open line of communication with rank-and-file server-runners and volunteers...
Edit:
I just realized that it was founded by @evan who is actually very active in mainstream Fedi, and one of the maintainers of the actual protocol. While that doesn't elaborate on actual intentions, it is good to know that at least it's someone who is directly involved, and not some random corporation. #EvanProdromou
Rents Fall and Listings Increase After Milei Ends Rent Control in Argentina
Link: msn.com/en-us/money/realestate…
Discussion: news.ycombinator.com/item?id=4…
@thunderbird I just noticed that the thunderbird Appointments logo looks extremely similar to the NOAA logo (US Gov National Oceanic and Atmospheric Administration).
Is this gonna be an issue legally? Not sure how the bird silhouette sits as part of their logo.
“According to Mozilla, PPA involves websites asking Firefox to remember ads they show and to potentially generate an interest report. Firefox creates the data but then submits it to an aggregation service, where the report is combined with similar ones.”
Mozilla is not your friend.
My favorite video game of all time is currently on sale for $1.99 on the Switch—if you haven't played it yet, please please do yourself the favor:
The amount of much-needed work going into Firefox bug 1590215 for forced-colors support in DevTools is incredible to watch.
Thunderbird for Android is coming soon! Find out how to get involved, from beta testing to localization to support and more, in our shiny new contributor guide!
(Seriously, by soon, we mean soon!)
Bubu reshared this.
Nice to see you on Android.
Working well on android 9.
Look like, close to K-9 mail...
I hope soon on Harmony Os Next !
Hackers showed me (there's video) how a website vulnerability let them locate, unlock, honk the horn, start ignition of any of millions Kias in seconds, just by reading a car's license plate.
They found similar bugs for a dozen carmakers over the last two years.
So this "CVSS 9.9" "unauthenticated RCE vs all GNU/Linux systems (plus others)" thing...
- Does NOT affect all GNU/Linux systems.
- Is not CVSS 9.9. I put it at a 6.3
It also requires:
1) The victim system has no active firewall to block incoming connections.
2) A user on the victim system must print something to a printer that mysteriously appears on the system that has never been there before.
If these two things happen, then command execution can happen as the "lp" user.
<yawn>
We get it. You found a vulnerability.
Lying about it to try to stir up interest in it is not appreciated by anybody who takes themselves seriously in this industry.
CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned.
evilsocket.net/2024/09/26/Atta…
Github is telling me that because of my role in “the software supply chain” I am no longer allowed to disable 2FA on my account
and quite frankly there’s nothing else you could have said that would have given me a greater desire to remove 2FA from my GitHub account
the site basically enlisted everyone who used it into helping it become critical societal infrastructure, in the same way that Amber Alerts now include t.co links to x dot com accounts that require you to be signed in in order to read
and it was us who helped it get there, simply by participating
I have so much to quibble with here, but I just have to endorse your key insight that IT IS NOT A SUPPLY CHAIN and the "supply chain" verbiage and assumptions are corrosive and they chafe a little more every time I hear them.
However, you *should* turn on 2FA on Github (and everywhere else) because of the position of social and infrastructural trust that your packages place you into. I really want better language to describe this role that isn't "supply chain" based, but I don't have it
My All Systems Go talk, "busd: There is a new D-Bus broker in town" is going live in less than an hour.
cfp.all-systems-go.io/all-syst…
Live stream: streaming.media.ccc.de/asg2024
I wrote a benchmark of game engine performance primarily geared towards the types of 2D games that are popular these days.
Here are the results for Flutter, Flame, Unity and Godot. It's a long read with many caveats, so buckle up.
New app listing: Mirror Hall
Use Linux devices as virtual displays in a peer-to-peer fashion
People on StackOverflow telling people to screw up #accessibility with the HTML dialog element defeats the purpose of using that element in the first place IMO. Please upvote my answer that corrects the numerous wrong answers, including the accepted answer, to this question if you have an SO account.
stackoverflow.com/a/79028606/2…
#webDev #a11y #html #css #javaScript
Reminder that the original Metatext third party app is no longer being maintained, as its lead developer had to step back due to health issues.
However, there is a new version of Metatext run by different people called Feditext which is currently in public beta testing. You can follow the official Feditext account at:
➡️ @Feditext
If you would like to join the public beta testing, it's on Apple TestFlight. There are more instructions here:
reshared this
special.usps.com/testkits/acce…
Sutherland said the threshold for informing Canadians was deliberately set very high because of the risk that such an alert could disrupt an election.
[speechlessly confused/exasperated Mal.gif]
Knihy z předprodeje jsou, samozřejmě, se slevou a podpisem. Když budete knihu číst mezi prvními, bude to rozhodně nejlepší. knihydobrovsky.cz/kniha/syndik…
reuters.com/world/uk/britains-…
The least competent people on earth are burning all the resources they can get their hands on to maintain the illusion that this system is not completely on fire and collapsing.
There are a narrow set of cases where LLMs do provide value, and somehow "leaders" everywhere have decided instead to invest in the use cases where they are indistinguishable from magic.
Can someone please invent a new snake oil to sell these fucking people that doesn't require the power of a small nation?
Ok, so reading people who have cats they sound like a mixture between the devil incarnate and the spirit of contradiction.
Why do people even like them?
they're small and soft and warm, they love you and need you, and it's so easy to make them happy with treats or toys. It all adds up to making them ridiculously good at lighting up our parental reward circuits. They even have voices and faces like babies.
And cats mostly warn you before biting or scratching. That's why people joke that cats insist on consent. One of my friends who does kink education says that reading cats' non-verbal signals is really good practice for doms.
I'll admit the sounds can be quite cute, both the purring and meowing thing. The hissing... not so much. :)
Good catch with the consent issue though, you're the second person on my replies that highlights that side of it and it had never come to my mind.
aws.amazon.com/blogs/storage/s… #aws #blog
Samsung unveils the $649+ Galaxy S24 FE, a "Fan Edition" value-focused version of the S24 with a 6.7" display, Exynos 2400e, and 8GB of RAM, in five colors (Ben Schoon/9to5Google)
9to5google.com/2024/09/26/sams…
techmeme.com/240926/p26#a24092…
Philosophy and mental health are deeply interconnected. The practical wisdom derived from philosophical reflection offers valuable insights and tools for navigating life's challenges. By integrating philosophical concepts into counseling, individuals can gain a deeper understanding of themselves and their experiences, fostering greater mental well-being.
Amber
in reply to Raccoon at TechHub • • •Raccoon at TechHub
in reply to Amber • • •Amber
in reply to Raccoon at TechHub • • •Sensitive content
WHY PRIVATE MESSAGING OMG. That's fucking awful. Nobody needs E2EE haphazardly slapped on the protocol for a false sense of security with private messaging. You want encrypted private messaging? Go to literally any other platform fedi is not the place for that. I am actually pissed, there's no way in hell that I would want to administrate something like that. I have seen countless examples of Matrix home servers going wrong within this community due to a lack of moderation tooling. We're not talking just a couple racists we're talking about child sex trafficking, csam distribution... Ugh. That pisses me the fuck off. Rich text posts are a nicety to have, I'd really like for things to adopt markdown and not mfm (fuck mfm imo it's okay but it's not a markdown and it's definitely not something that's viable long term. it's a gimmick). I guess I missed their "mission" page. Now I'm even more furious, because none of this is going to help the fediverse be widely adopted.
We are at a turning point. Running an instance is a lot of fucking work, we lack moderation tooling (yes, every software currently out there has some sort of flaw when it comes to mod tools. Akkoma has some bulk moderation tooling but is also lacking in other areas). The last fucking thing we need is encrypted dms to be used as a tool for harassment. We already suffer enough with how you can't disable replies in a post. It is awful that this is used as a vector for harassment in combination with setting visibility to restricted modes (such as follower only, so that only the original author can see the bigoted comment and the fanbase of the bigot can also jump in). What the fuck were they thinking? This is some actual shit. Fuck .
Amber
in reply to Amber • • •Sensitive content
this is horrid. I am so glad I defederated them. Fuck that. All of it. This is not the type of "help" administrators such as you and I need. What we need is the ability to have legal counsel, something like the EFF to represent us. There’s so much unknown legally about having a fediverse instance. Starting with things like the media proxy. If it’s on your domain but pointing elsewhere is that still you hosting the content? This is important in places like Germany in which federated media can contain hate symbols such as swastikas. How about things like the requirements for running adult oriented communities? Of course they’d never touch on that. Meta and Automattic just ban them outright because it’s too much work. How about things like working on the underlying server implementations?
I have drafted gitlab issues that touched on major problems within the fediverses' current implementation far more useful to read than whatever this shit is. activitypub.software/TransFem-… Right here. Right fucking here. How about instead of implementing E2EE we standardize rate limit headers for fediverse software so that instead of literally exploding instances with THOUSANDS OF REQUESTS at once we maximize throughput by using a leaky bucket abiding by the ratelimits given. That would do so much more than any of these other shitty proposals to the network. Talk about fixing some federation issues, and making it easier for smaller instances to federate media and other stuff without being overloaded to death forcing operators to move to hyper scale level hardware to run a small 100 user instance. Jfc. It is actually horrifying that I have given more advice to the fediverse that starts the ball rolling on conversations than the SWF such as talking with @hazelnoot@enby.life about server side modules and getting iceshrimp.NET to implement them. Fuckkk I hate this
Amber
in reply to Amber • • •Sensitive content
How about we brainstorm a way of doing signatures in a way that allows each instance to act as a relay. If I am on instance A, I write a post my instance has to send it out to B & C. If C is in fucking Europe, while B is on the coast a lot closer to Europe than me in Central US... why can we not just have my instance send a post to B, and B forwards it to C to minimize latency. I get that what you want for this to happen is an initial key exchange. ie instance A talks directly to instance C to exchange keys so C can verify the notes have not been modified or altered during transit... There's so many things about the fediverse that need to be addressed in order to reduce the large amounts of traffic between instances. I get that is a hard problem to solve, I have talked about this with other people but you're looking at MULTI BILLION DOLLAR INTERNATIONAL CORPORATIONS so if anyone has the money to shove towards an entire dedicated team of cryptographic researchers to accomplish this it would be them.
No, of course we're going to just get fancy markdown nobody asked for. I can display Wordpress blogs perfectly fine. I've seen the blogposts, they render in my client absolutely fine. Sure they're a bit long, but they don't just break my instance or my client. God forbid we look at things like shared inboxes (TO THIS DAY NOT EVERY INSTANCE SOFTWARE SUPPORTS IT!! THIS WAS SUPPOSED TO HELP REDUCE NETWORK TRAFFIC TO MORE MANAGEABLE SIZES). my god there's so many much low hanging fruit even prior to big alteration to how instances federate. you don't have to sit there hiring a team of cryptography experts to implement basic rate limiting on /inbox. content moderation tooling is something you can provide via a variety of ways. One of which... @hazelnoot@enby.life made a program that attaches to the database called "modshark" and it's used as our automod. I am writing a C# library for misskey api with the emphasis on client development & a bot framework (as additional optional dependencies you can install) to help make mod bots and other contraptions. this is awful.
mia
in reply to Amber • • •Sensitive content
Erin 💽✨
in reply to mia • • •Erin 💽✨
in reply to Erin 💽✨ • • •I'm not sure how much relays would help with anything, really - the only major issues I've seen with federation traffic overloading things are due to inefficient or overly heavyweight job queues (staring at Sidekiq in particular)
Oh, and the sheer size of media, but thats a traditional virality ddos
Amber
in reply to Erin 💽✨ • • •Sensitive content
Amber
in reply to Amber • • •Sensitive content
Amber
in reply to Amber • • •Sensitive content
kouhai, Breaker of Caches
in reply to Amber • • •Sensitive content
@puppygirlhornypost2 @erincandescent @mia @hazelnoot I don’t think that’s a particularly big issue?
cryptographic RNGs don’t just run out of entropy because they get reseeded periodically. this happens automatically [ref: docs.openssl.org/1.1.1/man3/RA…].
the cpu time for TLS/pk ops, sure, that’s a concern. but not that
honestly, wrt e2e, I’m more concerned that we’re going to get a design that’s objectively worse than soatok’s well thought out draft.
soatok.blog/2024/09/13/e2ee-fo…
kouhai, Breaker of Caches
in reply to kouhai, Breaker of Caches • • •Sensitive content
@puppygirlhornypost2 @erincandescent @mia @hazelnoot holy shit just give soatok $250,000 to spend a year doing this.
like. do we want matrix. I suspect we’re just going to get “Messages can't be decrypted by receiver (session key missing)” social whatever foundation edition, now with more Automattic Matt funding
Amber
in reply to kouhai, Breaker of Caches • • •Sensitive content
Erin 💽✨
in reply to Amber • • •entropy exhaustion is a stupid concept (you can't destroy entropy! This is basic thermodynamics!!) promulgated by the fact that the Linux RNG was badly designed for a long time and had stupid "entropy accounting"
The RNG no longer "depletes" entropy
Amber
in reply to Erin 💽✨ • • •Sensitive content
Seirdy
in reply to Amber • • •Amber
in reply to Seirdy • • •Sensitive content
Seirdy
in reply to Amber • • •Amber
in reply to Seirdy • • •Sensitive content
Seirdy
in reply to Amber • • •