Here's the latest #curl hackerone issue I mentioned the other day: hackerone.com/reports/2871792 another one of those "we found a function call so therefore your program must be vulnerable".

Disclosed for educational purposes. Don't do this.

#curl

Welcome to Monday.
Daughter abed, off school with a migraine. The new preventatives are not yet living up to their names.

I did crack open the cream yesterday, which is one of the key moments in my personal march toward the holidays. So first coffee of the day this morn was a deliciously hot, strong jolt of 'Get your butt to work soon' with a spiral of creamy goodness. A busy day at work, and then a stupidly early start for a 5:21AM train tomorrow, so not sure how i'll be feeling about that when I get there.

I am sat warm and comfortable with coffee 2 while I fill in the school absence form and ponder my morning's schedule and tickets.

Ve avemo aumentato a pensione de โ‚ฌ1,8 AR MESE (!!!) pe sta ar passo co l'inflazzione

Un segnio de gli ottimi risurtati de sto governo ๐Ÿš€

Nun spendeteli tuttassieme ๐Ÿ˜‰

open.online/2024/12/02/pensionโ€ฆ

Back in 2021, we launched a series of stories documenting the key ways that the ultrawealthy โ€” #billionaires like #ElonMusk, Jeff Bezos, and Peter Thiel โ€” avoid #taxes. Here are 10 of their strategies.

#Finance #Law #Tech #Journalism

propub.li/4fQL3uY

Hi, @jcsteh. I'd like to report an issue. I would do it in Bugzilla, but it appears that I can't comment on closed bugs. bugzilla.mozilla.org/show_bug.โ€ฆ was marked as a duplicate of bugzilla.mozilla.org/show_bug.โ€ฆ which was marked as fixed 8 days ago. However, the issue from Bug 1927237 doesn't seem to be fixed in recent Nightlies.

Thanks for your time and all your hard work!!

TIL about #DecemberAdventure - what a lovely counterpoint to #AdventOfCode I tried the latter a couple of times, but found it stressful after a few days. This looks much more relaxing.

eli.li/december-adventure

New page on my website: My workouts.

Documenting my low-equipment at-home workout regiment. How I work out, why I work out, my workout split, my list of exercises, and advice Iโ€™m soliciting.

I figured that if I spend 5-6 hours a week doing something I care deeply about, I should probably mention it on my site.

Iโ€™m soliciting advice; see the โ€œCurrent questionsโ€ section at the end!


#fitness #WeightLifting

Today I woke up at a silly time and started playing around with my old midi files, remembering that Foobar 2000 has a plug-in that can play them through sound fonts. It's fun to listen to my music from back then, rendered by instruments that I did not intend. Some of it still sounds decent. Here's a sample.

modulux reshared this.

็œ‹ #็‰นๆ–ฏๆ‹‰ #TESLA ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ขๅœ–

็›ธๆฏ”ๆ–ผ #NVDA ็š„ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ข๏ผŒ็‰นๆ–ฏๆ‹‰ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ขๆ›ด้กฏๅพ—็ถญๆŒๆ™‚้–“ๅพˆ็Ÿญๅฐฑ็”ข็”Ÿๅฆไธ€ๆข่ถจๅ‹ข็ทšใ€‚็ขบๅฏฆๅฆ‚ๆญค!!

้™คไบ†ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ขๆŒ็บŒๆ™‚้–“็Ÿญ๏ผŒ็”ข็”Ÿๅคšๆข่ถจๅ‹ข็ทšๅค–๏ผŒๅญฃ็‡Ÿๆ”ถๆ‰ฃ้™ค้Šท่ฒจๆˆๆœฌๅ’Œ็‡Ÿๆฅญ่ฒป็”จๆ‰€็”ข็”Ÿ็š„ๆŒ‡ๆจ™ๅทฎ่ทไนŸ้žๅธธๅคง้Šท่ฒจๆˆๆœฌๅ ่ถ…้Ž70%๏ผŒ็‡Ÿๆฅญ่ฒป็”จไนŸๅ ไบ†่ถ…้Ž10%ใ€‚

ๆ›ๅฅ่ฉฑ่ชช๏ผŒ็‰นๆ–ฏๆ‹‰็š„ๅญฃ็‡Ÿๆ”ถๆŒ‡ๆจ™่ถจๅ‹ขๅƒ…ไพ›ๅƒ่€ƒ๏ผŒไธ่ƒฝๆˆ็‚บๆŠ•่ณ‡ไบบ็š„ไฟกไปป็š„ๆŒ‡ๆจ™ใ€‚ๅ› ็‚บ็•ถไฝ ็œ‹่‘—ๅญฃ็‡Ÿๆ”ถ๏ผŒไปฅ็‚บ็‰นๆ–ฏๆ‹‰ๅพˆ่ณบ้Œข๏ผŒๅ…ถๅฏฆๆ‰ฃ้™คๆˆๆœฌๅพŒ........

็ธฝๆญธๆฏ”ๅฐๅป ็š„ๆฏ›ไธ‰ๅˆฐๅ››้‚„่ฆๅฅฝๅพˆๅคš ๐Ÿคฃ

#็ถ“ๆฟŸ #่ฒก็ถ“ #็พŽๅœ‹ #่ฒกๅ ฑ #ๆ•ธๆ“šๅˆ†ๆž #่ณ‡ๆ–™ๅˆ†ๆž #AIๆ•ธๆ“šๅˆ†ๆž #AI #MathAI

in reply to AIๆ•ธๅญ—ๅˆ†ๆž้ ˜่ˆช่€… AIๅบ•ๅฑคๆ•ธๆ“šๅปบๆจก

็•ถๆ‚จๆŒ‡็š„ๆ˜ฏ้€™ๅฎถๅ…ฌๅธๆ™‚๏ผŒๆˆ‘ๅ€‘ๆ˜ฏๅฆๆœ‰ๆฉŸๆœƒ้ผ“ๅ‹ตๆ‚จ้—œๆณจ #NVIDIA ็š„่ถจๅ‹ข๏ผŸ ๆˆ‘็Ÿฅ้“ไป–ๅ€‘็š„ NASDAQ ๅฅๆŸ„ๆ˜ฏไป€้บผ๏ผŒไฝ† #NVDA ไฝœ็‚บๆˆ‘ๅ€‘่ฃฝ้€ ็š„่žขๅน•้–ฑ่ฎ€ๅ™จ็š„ๅ็จฑๆ›ดๅปฃ็‚บไบบ็Ÿฅ๏ผŒไธฆไธ” #NVDA ไธป้กŒๆจ™็ฑค้žๅธธๅปฃๆณ›ๅœฐ็”จๆ–ผ่žขๅน•้–ฑ่ฎ€ๅ™จใ€‚ ๅฎƒๅฐ‡้ฟๅ…ๆˆ‘ๅ€‘ๅ…ฉๅ€‹็คพๅ€ไบ’็›ธๆฑกๆŸ“ๅฐๆ–น็š„้ฃผๆ–™ใ€‚ ๅฆ‚ๆžœๆ‚จๆƒณไบ†่งฃๆœ‰้—œ่žขๅน•้–ฑ่ฎ€ๅ™จ็š„ๆ›ดๅคšไฟกๆฏ๏ผŒๆˆ‘ๅ€‘็š„็ถฒ็ซ™ๆ˜ฏ nvaccess.org/ - ่ฌ่ฌ๏ผ
in reply to AIๆ•ธๅญ—ๅˆ†ๆž้ ˜่ˆช่€… AIๅบ•ๅฑคๆ•ธๆ“šๅปบๆจก

Is there any chance we can encourage you to trend #NVIDIA when that's the company you mean, please? I know what their NASDAQ handle is, but #NVDA is much more widely known as the name of the screen reader we make and the #NVDA hashtag is very widely used for the screen reader. It will save both our communities polluting each other's feeds. If you'd like to find out more about the screen reader, our website is nvaccess.org/ - Thank you!

็œ‹่ผ้” #NVIDIA ็š„ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ขๅœ–
ๆธ…ๆฅš็š„ไธ‰ๆข่ถจๅ‹ข็ทš๏ผŒๅพˆ็ฉฉๅฎšใ€‚ๆœ€ๆ–ฐ่ถจๅ‹ขไธŠๅ‡้€Ÿๅบฆ้žๅธธๅฟซ๏ผŒไปฃ่กจ็”ข่ƒฝ็ฉฉๅฎšๆ“ดๅผตไธฆไธ”ๅฟซ้€Ÿๆ“ดๅผตใ€‚

้€™ๅฏไปฅ่ชชๆ˜ฏ่ฃฝ้€ ๆฅญ็š„็‰นๆ€ง๏ผŒ็ฉฉๅฎš๏ผŒๅฆ‚ๆžœ่จ‚ๅ–ฎๆปฟๅ“ก๏ผŒ้‚ฃ้บผๅฐฑ็œ‹็”ข่ƒฝๆ“ดๅผต้€Ÿๅบฆใ€‚ๆ‰€ไปฅ้€™ๆจฃ็š„ๅญฃ็‡Ÿๆ”ถ่ถจๅ‹ขๅ…ถๅฏฆๆ˜ฏ็”ข่ƒฝๆ“ดๅผต้€Ÿๅบฆใ€‚

#็ถ“ๆฟŸ #่ฒก็ถ“ #AIๆ•ธๆ“šๅˆ†ๆž #่ณ‡ๆ–™ๅˆ†ๆž #AI #MathAI #NVDA #่‹ฑๅ‰้”

in reply to AIๆ•ธๅญ—ๅˆ†ๆž้ ˜่ˆช่€… AIๅบ•ๅฑคๆ•ธๆ“šๅปบๆจก

ไธ๏ผŒๆˆ‘่ฉฆๅœ–ๅฐ‡ #NVDA ๆจ™็ฑค็š„ไธป่ฆ็”จ้€”๏ผˆ็”จๆ–ผๅ็‚บ NVDA ็š„่žขๅน•้–ฑ่ฎ€ๅ™จ๏ผ‰่ˆ‡ๆ‡‰ไฝฟ็”จ #NVIDIA ๆจ™็ฑค็š„ AI ้‡‘่žๅ…งๅฎนๅ€ๅˆ†้–‹ไพ†:) / No, I was trying to separate the main use of the #NVDA hashtag - which is for the screen reader called NVDA, from your AI finance stuff which should use the #NVIDIA hashtag :)

TIL the Brave browser is a literal crypto scam. They claim to compensate website owners and content creators with their BAT token, but if you don't or can't claim the rewards within 90 days they pocket the tokens themselves. Apparently it's extremely difficult to signup and claim your BAT tokens...
news.ycombinator.com/item?id=1โ€ฆ

#cryptoscam #bravebrowser #bravebrowserisbad

I spent the last two days playing BG3 and learning Godot and I now have a working player for text adventures written in Ink. ๐ŸŽ‰

Ink is a scripting (as in code) language for writing scripts (as in story) for narrative-driven games. It's built as middleware for game engines, but it can *mostly* be used on its own for text based interactive fiction: inklestudios.com/ink/

I say "mostly" because while there's a web-based engine for running ink games, the feature-set is understandably limited.

Another great episode of the #2Bobs #pocast - Questions, Not Answers.

Blair Enns and David C. Baker cover some interesting territory. Being able to ask good questions, listen to what is said (and not said), then incorporate that into more questions is powerful. Being curious about people and their problems is such a critical part of being able to help others. This is true as a consultant or as a friend.

2bobs.com/podcast/questions-noโ€ฆ

Another great podcast episode by @drvolts -
Dan Savage on blue America in the age of Trump - it was an interesting reflection of urban politics. volts.wtf/p/dan-savage-on-blueโ€ฆ

"Despite the fact that Threads users canโ€™t follow or see mentions from people on other instances, Threads has already opted to block a slew of instances where gay & leather people congregate.... If Threads were a taxi service, it wouldnโ€™t take you South of Market."

aphyr.com/posts/371-threads-woโ€ฆ

This entry was edited (1 year ago)

Carlos Tavares, le patron de Stellantis (Peugeot, Fiat et plein dโ€™autres marques) vient dโ€™รชtre virรฉ. Jโ€™aurais fait une petite danse de la joie, mais il a รฉtรฉ virรฉ pour les mauvaises raisons, comme expliquรฉ dans lโ€™article.

Stellantis annonce la dรฉmission ยซ avec effet immรฉdiat ยป de son patron Carlos Tavares

lemonde.fr/economie/article/20โ€ฆ

#AndroidAppRain at apt.izzysoft.de/fdroid today with 15 updated and 2 added apps:

* Photos: a no non-sense, smooth, and performant gallery app
* KeePassDX Libre: on special request, the "Libre" variant of this well-known and great FOSS Password Safe was added here in addition to the "Free" one.

Enjoy your #free #Android #apps with the #IzzyOnDroid repo :awesome:

Here's a recent and interesting lecture from the LSE on social media regulation.
lse.ac.uk/lse-player?id=464a16โ€ฆ
#liberalism #constitutionalism #SocialMedia

In my opinion, Visual Studio Code is not in the same category of text editors as Emacs or Vim, especially for keyboard-intensive users. However, it has some highly attractive features and extensions. One such extension uses the languagetool spelling and grammar checker to create a tree widget populated by errors and warnings from languagetool and other sources, including markup validation.
The original Ltex extension for using languagetool no longer seems to be maintained, but this fork is.
ltex-plus.github.io/ltex-plus/
#TextEditing #VSCode #MarkupLanguages

The worldโ€™s 280 million electric bikes and mopeds are cutting demand for oil far more than electric cars
theconversation.com/the-worldsโ€ฆ

They also use massively fewer materials to achieve the same ends, " ...In the United States, a staggering 60% of all car trips cover less than 10km."

โœจ 62% OFF! Black Friday & Cyber Monday Deal โœจ

โณ Last Chance to Save BIG! โณ

Get a full year of Legend for just โ‚ฌ36 (down from โ‚ฌ96/year)

๐Ÿ“… Get your end-to-end mailbox here: tuta.com/black-friday

#BlackFriday #CyberMonday #LastChance

Ancora sulla fine del modello tedesco
@anarchia
Dopo il gruppo Wolkswagen tocca a Thyssen, storico nome della siderurgia tedesca tristemente nota qui a Torino per una strage di operai (morirono bruciati in 7), annunciare un drastico piano di tagli, si parla di 11000 esuberi e un drastico...

Vedi l'articolo

rivoluzioneanarchica.it/ancoraโ€ฆ

googleโ€™s latest fuckery: if you write online, read this


The Google app for iOS now adds THEIR links to YOUR posts from YOUR website unless you opt-out.

Their links lead people away from your site and back to Google. Because thatโ€™s definitely what you want, right? Thatโ€™s why you have a blog or portal or web site or whatever. You want people to leave your site and go back to Google.

Oh, itโ€™s not?

If you donโ€™t like it, you can โ€œOpt out.โ€ Opting out is a pain in the ass. Hereโ€™s where you go to do it. You have to enter every variation of each of your domains or it wonโ€™t work. It will take up to 30 days, during which time Google will continue to pollute your work and your writing and your website with their modifications and their added links to take people away from your site and back to themselves.

For example, hereโ€™s the list of what I need to opt-out just for this one blog:
solarbird.nethttp://solarbird.nethttps://solarbird.netwww.solarbird.nethttp://www.solarbird.nethttps://www.solarbird.netweb.solarbird.nethttp://web.solarbird.nethttps://web.solarbird.net
Yes, you explicitly have to file no prefix, http:, and https: variants separately. They say so.

Making it difficult like this is 100% intentional and entirely designed to make it as annoying as possible, and also, to make sure you slip up if at all possible and forget one or more combinations.

(Thoโ€™ I am just going to depreciate web. as a prefix right now, to bring down the load a little. Still gonna list โ€™em, though, because spite is why.)

Right now itโ€™s only in the Google app for iOS and itโ€™s probably a test to see whether they can get away with it without complaint, and how much revenue it generates. Letโ€™s make that a combination of no and as close to zero as possible. Because otherwise theyโ€™ll roll it out everywhere, and probably derank you if you donโ€™t go along.

Fucking hell, Google. Fuck you. Justโ€ฆ fuck you.

#art #t0000000000bs_ #writing

This entry was edited (1 year ago)

reshared this

in reply to solarbird

I agree wholeheartedly with Google's Page Annotations being an absolutely awful antifeature, and recommend that others opt-out and/or protest the feature. I want to make a clarification that doesn't invalidate your main points:

Clicking annotations doesn't navigate away from your site to a Google search; it triggers an overlay with infoboxes about the term you selected. It's similar to the iOS "Look Up" option for selected text. It's wrong to do because this obfuscates what is and isn't a link the author placed on the page. Inserting what appears to be links into the page crosses the line from user-agent interventions, such as adblocking or turning off certain unsafe features (acceptable) to editing an author's words in a way that isn't required for people to read them (unacceptable).

Editing page contents is fine if it's necessary for people to read them, e.g. translations or the WAI-Adapt standards. Both ideally inform the user that the page has been modified. Page Annotations go well beyond that.


Originally posted on seirdy.one: See Original (POSSE).

in reply to Europe Says

From their national anthem:

Deศ™teaptฤƒ-te, romรขne, din somnul cel de moarte / รŽn care te-adรขncirฤƒ barbarii de tirani

Translation:
Awaken thee, Romanian, wake up from thy deathly trance / Into which thou wert sucked by tyrannic barbarians.

Krรกsnou 1๏ธโƒฃ. adventnรญ nedฤ›li vลกem! ๐ŸŽ„๐Ÿ•ฏ๏ธ
#NaStatku mรกme ozdobeno. Kromฤ› stavby je tu klid a mรญr. โ™ฅ๏ธ
#advent
This entry was edited (1 year ago)

Vฤera odeลกla za duhovรฝ most naลกe koฤiฤka Eliลกka. Byla to naลกe zvรญล™ecรญ kamarรกdka, รบลพasnรก spoleฤnice a velkรก bojovnice. Dฤ›kujeme jรญ za vลกechny krรกsnรฉ chvรญle a za vลกechnu radost, co nรกm dรกvala. Bude nรกm moc chybฤ›t. A teฤ uลพ konฤรญm, skoro nevidรญm na display ๐Ÿ˜ญ.

Accessible Android Investigates: Do Google Apps for Android Have Accessibility Actions? accessibleandroid.com/accessibโ€ฆ #Android #A11y #Google
in reply to Accessible Android

Thank you so much for this very informative article. After having read the whole article, I am feeling very disappointed with Google as a company who claimed to care about accessibility but in reality, they seem to forget about us and we are pushed to the side. It is like standing in a checkout line trying to reach the front of the queue but people keep pushing you backwards. Thereโ€™s nothing we can do because whenever you file accessibility feedback with Google, it is completely ignored and we are treated like second class citizens who do not matter to Google. What are the other frustrating points I wish to make is with the phone app. I really do not like the Phone app on the pixel eight device especially when trying to access the keypad and then if you do nothing with the keypad for awhile, that window goes away and you have to locate the keypad button again. It is a very clunky experience compared to the phone app on iOS. Sorry however, long live iOS in this instance.

Did you know that ISO27001 requires you to do threat modeling? A 8.27 Requires you to "regularly update threat models to reflect changes in the system and external threat landscape." see: www.isms.online/iso-27001/ch... Why not try out threat modeling at copi.owasp.org#appsec #cybersec #owasp

Copi ยท Play Cornucopia O...

Bilancio da secondo #CompleannoSegreto (giร  due anni!) riprendendo un discorso che avevo cominciato verso fine ottobre:

contiene una visione un pelo piรน disincantata del #Fediverso e qualche riflessione molto personale sulla situazione generale, un po' stagionata ma col cuore sempre giovane :ls007_madcat:

andreacorinti.com/posts/ita/duโ€ฆ

in reply to Ed

ma perchรฉ discord? Esistono giร  i gruppi nel fediverso! Io seguo le comunitร  Lemmy @news @gdr e @giochidatavolo e i gruppi friendica @scuola e @psicologia

Chi vuole creare nuovi gruppi Lemmy puร  chiedere a @macfranc o a @skariko e e cosรฌ per i gruppi friendica su poliverso (che addirittura ce li possiamo creare da soli!)

E da quando uso Raccoon i gruppi li riesco a consultare molto meglio. Provate a scaricarla da qui e ditemi

github.com/LiveFastEatTrashRacโ€ฆ

in reply to 0ut1ยฐยฐk

@outlook

E da quando uso Raccoon i gruppi li riesco a consultare molto meglio. Provate a scaricarla da qui e ditemi


Credo che quest'ultima frase farร  molto piacere a @dieguitux8623 che ha sviluppato l'app.
Quando ho saputo che aveva iniziato a sviluppare un'app per Friendica, mi sono permesso di chiedergli due cose:

  • fare un app che visualizzasse i gruppi Activitypub in modo agevole (e lui l'aveva giร  fatto perchรฉ aveva giร  creato un'app per Lemmy)
  • farla in modo che fosse perfettamente compatibile con Mastodon, perchรฉ gli utenti Mastodon (per colpa del crucco malefico ๐Ÿ˜‚) non sono erano in condizione di gestire in maniera intuitiva i gruppi Activitypub.

Infatti con delle app mastodon che ancora non riescono a emanciparsi dall'interfaccia twitter-like, i gruppi dl Fediverso non potranno MAI avere successo. Ma soprattutto, con un mastodon che crede ancora di essere un'alternativa a Twitter, coi sui 500 caratteri in solo testo, sarร  difficile creare vere e proprie comunitร . Lo strumento non รจ MAI neutro!

@ed @justintime @giorgetti @xabacadabra @news @gdr @giochidatavolo @scuola @psicologia @skariko

โ‡ง