@Tusky how (if?) can I favourite languages in the toot-specific language selector?
The amount of languages I can write and thus realistically toot in is limited and thus easier to select than always scrolling to the language.
@Tusky how (if?) can I favourite languages in the toot-specific language selector?
The amount of languages I can write and thus realistically toot in is limited and thus easier to select than always scrolling to the language.
The route is the first directly linking the two capitals' city centres.Angela Symons (Euronews.com)
Úsměv na rtu, dobrou kartu,
k tomu dobrých lidí partu.
Zdraví, štěstí, hodně lásky,
žádnou starost, žádné vrásky!
Šťastné vykročení do nového roku vám všem, přátelé!🤞🍀🥂
I když naše cesty někdy vedou do neznáma, věřím, že za mlhou nejistoty svítí sluníčko každému. ♥️
#PF
"AntennaPod, en god, gratis podcast-afspiller til Android." Og hvordan man lytter til DR podcasts.
internetforbrugeren.dk/lyt-til…
Podcasts er (snakke)radioudsendelser du (typisk) lytter til med en særlig app på din mobil. AntennaPod er et af de bedre programmer.Internetforbrugeren
"Handing the reins to Harris in July, rather than sticking it out, wasn’t one of his mistakes. His mistake was that he didn’t do so sooner."
New from @wsaletan on the fantasy that Biden would have beaten Trump: thebulwark.com/p/biden-world-h…
The question is not whether he should have dropped out. It’s why he didn’t do so earlier.Will Saletan (The Bulwark)
🔐 Chcete více soukromí? Čím nahradit služby od Googlu, Applu, Mety a dalších?
Actor Tom Baker has been honoured by King Charles with a Member of the Order of the British Empire (MBE) award for services to television. The 90-year-old actor was chosen along with other recipients as part of the New Year Honours.Andrea Laford (CultBox)
China’s demo reactor could breed nuclear fuel from rare earth wasteEmily Waltz (IEEE Spectrum)
John @tuckner sent me on an interesting wild goose chase. He is investigating the Cyberhaven extension compromise, trying to find out more. And he found something that he considered another campaign compromising browser extensions, related to the sclpfybn[.]com domain: secureannex.com/blog/sclpfybn-…
Edit: Just to make sure this is clear: so far there is little indication that these two campaigns are somehow related. Both being present in one extension was most likely a coincidence.
One of the extensions that used to contain the code in question was Visual Effects for Google Meet – which brought him to me because I recently covered that extension in my Karma Connection article: palant.info/2024/10/30/the-kar…
I checked my data but couldn’t find sclpfybn[.]com domain mentioned in any extensions other than the ones @tuckner found already. I then looked for similar code and immediately found it in Urban VPN Proxy.
First thought: Urban VPN Proxy has the legitimate version of a library that was trojanized elsewhere. Taking a look at the communication of Urban VPN Proxy disproved that theory almost immediately – not only was it communicating in exactly the same way, but also to an unknown domain, namely ducunt[.]com. Yet the same endpoint existed on the official urban-vpn[.]com domain as well.
So not only did Urban VPN Proxy contain essentially the same code, it was likely added there by the developers themselves. Further investigation increased the suspicion that all these extensions haven’t been compromised, that this was rather some monetization SDK.
At which point @tuckner found the sales pitch for that SDK, detailing how it would add ad blocking functionality to the extension at the cost of exfiltrating very detailed browsing data (of course anonymized and aggregated before being sold to everyone asking for it, we know the drill). And explanations on how to make sure Google won’t object.
And that explains it all: before the Visual Effects for Google Meet developer sold their extension to Karma, they tried to monetize it with this “ad blocking library.” The sales pitch doesn’t mention who develops the library but everything points to Urban VPN.
According to Urban VPN privacy policy, they are selling the data they collect from their users via BIScience Ltd. Who are most likely the hidden owners of Urban Cyber Security Inc., a company registered to a virtual address in the USA.
Edit: Updated link to Tuckner’s blog post, he split it away from the original investigation.
A bunch of malicious extensions in Chrome Web Store have hidden affiliate fraud functionality, collect users’ browsing profiles, or both. These extensions appear to be connected to the Karma shopping assistant, developed by Karma Shopping Ltd.Almost Secure
In other words, screw pedestrians, especially blind and other disabled people!
Waymo robotaxis, which are now ubiquitous in parts of CA, will often not stop for pedestrians using crosswalks there, unless a pedestrian is far into the road.
Here are our favorite JavaScript-based web content management systems. They are all free and open source software.Steve Emms (LinuxLinks)
Another great podcast episode from @RyanAndrosoff this time with Andres Raieste from Estonia.
This is the second podcast from this year's #FWD50 conference in Ottawa. I would definitely recommend that folks in government listen to Trust is Everything | Ep 27
I liked the line about the importance of demonstrating incremental improvements. Starting with the tax department is also interesting.
youtube.com/watch?v=FzbyuwzRcr…
#Estonia #DigitalTransformation #Government #Trust #LetsThinkDigital
Trust is everything. It’s clear we’re in a moment in time where people do not trust their governments. There is skepticism about the impact of big technology...YouTube
#NCP
A reminder, a week on after this news broke, if you have the HONEY browser extension from PAYPAL installed, you should uninstall it immediately and delete all its cookies.
The extension + app owners
- does NOT find you the best coupons
- does backroom deals with big retailers to drive conversions, with less discounts
- steal(s) from creators
- harvests your data for resale and manipulation
- is classified as malware
Full details here (nb, the youtube display may not work because Youtube is actively blocking their cards / videos from displaying on Mastodon because of the MastoDDos effect)
Was Honey a legitimate money saving tool? Or just an affiliate marketing scam promoted by some of YouTube's biggest influencers?If you have any inside inform...YouTube
A look back, a look ahead: How was 2024 at IzzyOnDroid? What might 2025 bring you there, what are we working on?
android.izzysoft.de/articles/n…
And if anybody ever tells you #security or #reproducibleBuilds are "set-and-forget", laugh straight into their faces. Software evolves, and so do their threats and risks…
German readers: Die Deutsche Version folgt in Kürze…
2024 waves goodbye, 2025 knocks at the door: what did we achieve in 2024, and what are our plans and hopes for 2025? Join us to take a look back at security measures established, at progress with Reproducible Builds – and for a look ahead of what mig…IzzyOnDroid
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 likes this.
𝔻𝕚𝕖𝕘𝕠 🦝🧑🏻💻🍕 reshared this.
Jetzt ist auch die deutschsprachige Version unseres "Jahresberichts" online:
Ein Blick zurück, ein Blick voraus: Wie war 2024 bei #IzzyOnDroid? Was mag Euch 2025 hier bringen, woran arbeiten wir?
android.izzysoft.de/articles/n…
Und wenn Euch jemand sagt, #security oder #reproducibleBuilds wären (einmal aufgesetzt) reine Selbstläufer: Lacht sie laut aus. Software entwickelt sich weiter – und so auch ihre Risiken und Threats…
2024 winkt zum Abschied, 2025 klopft an die Tür: Was haben wir 2024 erreicht, und was sind unsere Pläne und Hoffnungen für 2025? Werft mit uns einen Blick zurück auf die eingeführten Sicherheitsmaßnahmen, auf die Fortschritte bei Reproducible Builds …IzzyOnDroid

As announced with our plans for 2025, here are the long awaited download stats for #IzzyOnDroid
codeberg.org/IzzyOnDroid/iodst…
Anyone going to write a front-end for visualization (e.g. a web page)? 
I'm giving away my pair of Envision Glasses (smart glasses for blind/low vision people):
letsenvision.com/glasses/home
Bought in 2020, titanium frames, in good working order, complete with case.
If interested and you're willing to cover the collection/shipping costs from the UK to wherever you are, DM me.
Envision Glasses are AI-powered smartglasses that articulate everyday visual information into speech. And, with this information, comes the feeling of independence and the perception of possibilities.www.letsenvision.com
@RaccoonForFriendica new version 0.4.0-beta04 available for testing!
Changelog:
- fix for a bug after adding/removing a post to favorites which led to lose custom emojis;
- fix spacing between post and reply placeholders when using the new Card layout;
- fix a minor accessibility issue with the new audio player;
- fix crash when rendering some HTML posts;
- fix "floating" (overlapping) images for embedded contents;
- localization updates (included support for upcoming Romanian translation);
- library updates.
I think we are almost ready for the 0.4 version. In the meantime I've submitted both Raccoon apps to Google Play so I may be needed some volunteers to participate in the closed testing program before the apps can be made available to the general public.
Happy New Year and remember to #livefasteatrash
#procyonproject #raccoonforfriendica #fediverseapp #friendica #friendicadev #mobileapp #mobiledev #kotlin #kmp #compose #opensource #foss #sideproject
like this
reshared this
🔵🔴🟢
ZÍNGARO O GITANO
La palabra “zíngaro” es una especie de red flag 🚩 para muchos gitanos. Cada vez que alguien, en nuestro territorio y en nuestras lenguas, escoge esta denominación en realidad a nosotros nos llega lo siguiente:
a) Evitas la palabra “gitano”. ¿Y por qué la evitas? Porque para ti “gitano” es una palabra connotada negativamente. Es decir, relacionada con elementos negativos. Quizá eres de los que dicen “gitanillos” o “de etnia” 🤮.
b) La palabra zíngaro te permite asociar elementos mágicos, místicos o espirituales especiales a las personas de las que hablas. Quieres hablar de una conexión especial con la naturaleza, una forma especial, casi mística de relacionarse entre ellos, los animales y el resto del mundo. Una visión muy similar a la que se fabrica de los pueblos indígenas de todas partes.
Todo ello contribuye a vernos como parte de un decorado de parque temático. Romantiza (sorry) la marginalización y exterminio, la prohibición de avanzar.
Para la supervivencia, algunos de nosotros hemos tenido que aprovechar estos estereotipos que podríamos considerar inofensivos (ciertamente son menos nocivos que otros). Pero también contribuyen a hacernos misteriosos, sospechosos y desagradables.
Somos gitanos. Si estás leyendo, puedes decir la palabra, dila sólo si es necesario pero siempre con normalidad, aunque la otra te parezca más poética.
Y si sigues sintiéndote incómodo, “romaní” no falla.
No seas como esos compañeros docentes con el síndrome del salvador blanco que bajan la voz para decir “gitano”. El término os lo inventasteis vosotros, pues ahora apechugad. 😅
Adjunto descripción gráfica de todo lo anterior. 🙈
I generated a 12-character commit SHA prefix collision with the start of Linux's git history. It took about 6 hours on an RTX 3080 GPU:
people.kernel.org/kees/collidi…
Or, how to break all the tools that parse the "Fixes:" tag Kees Cook There was a recent discussion about how Linux's "Fixes" tag, which ...kees
reshared this
#BabelOfCode 2024
Week 1
Language: Applesoft BASIC
"Advent of Code" is an online event where you're given 25 two-part code puzzles, which you're supposed to solve in 25 days in December. I was busy so instead I'm doing a slow-motion, one-puzzle-per-week version over the course of 2025, but with an added restriction: I have to do it in a different language each week.
@unjello proposed a hashtag, so maybe there are two of us on this
mastodon.gamedev.place/@unjell…
(1/2)
@mcc@mastodon.social Allrighty. Made my list in case anyone else cares ;) https://andrzej.lichnerowicz.Gamedev Mastodon
Pues aunque la noticia es de agosto, me acabo de enterar de que los estándares ISO de PDF accesible se pueden descargar gratuitamente… cc @jmdaweb
Announcing no-cost access to PDF’s accessibility standards – PDF Association
pdfa.org/announcing-no-cost-ac…
And, here are the products you should absolutely never use when cleaning your phone.Katie Teague (CNET)
Deterrence is the best defense: Here's how to prevent thieves and other home threats before they get inside.Tyler Lacoma (CNET)
The telecom companies say they're no longer detecting activity from foreign entities that were hacking their networks.Omar Gallaga (CNET)
h3i is a command line tool and Rust library designed for low-level testing and debugging of HTTP/3, which runs over QUIC.
We've replaced our hodgepodge of test tools with it and caught server bugs in the process.
Deep Dive at blog.cloudflare.com/h3i
Read about the motivation and background for h3i, along with practical examples that you can build upon for your own purposes.The Cloudflare Blog
reshared this
I started writing this post in October, when . I got distracted by the professoring business, and didn't finish it until now. It's not quite so salient (and,...Scott C. Richmond
as camus (via wikiquote) put it in 1970:
“Life continues, and some mornings, weary of the noise, discouraged by the prospect of the interminable work to keep after, sickened also by the madness of the world that leaps at you from the newspaper, finally convinced that I will not be equal to it and that I will disappoint everyone—all I want to do is sit down and wait for evening. This is what I feel like, and sometimes I yield to it.”
Rui Batista reshared this.
Targeting multiple operating systems has been an industry goal or non-goal depending on your perspective since some of the earliest days of computing. For both app developers and platform builders…Steven Sinofsky (Learning By Shipping)
In a word; yes. There were three major reasons:
1. Pomodouroboros is an unusually UX-sensitive app. It's designed to provide a very specific stimulus in a very specific way, and if it can't be provided that way, then the app is pointless. There's more than one possible way to deliver that stimulus but each distinct way is still *very* specific and sensitive to minor variations.
GTK has systematically removed all of the APIs that I need to implement Pomodouroboros, because Wayland has (for misguided, incorrect "security" reasons) removed the functionality those APIs depend upon, and GTK considers "Linux desktop" the most important least common denominator.
Of course since "security" is an excuse rather than an actual systemic property, I can still access all the functionality by forcing a fallback to X11 and then talking to it directly github.com/glyph/Pomodouroboro…
Pomodoro timer that acknowledges the inexorable, infinite passage of time - glyph/PomodouroborosGitHub
Version 5.0 of Microsoft’s flagship spreadsheet program Excel came out in 1993. It was positively huge: it required a whole 15 megabytes of hard drive space. In those days we could still reme…Joel on Software
@glyph Re: bloat, I'm ambivalent about the Spolsky article. His rebuttal of Linus Åkerlund's rant is correct, of course; demand paging has been a thing for a long time. And of course, more features are generally a good thing for users. And important things like accessibility and, as you said, automatic updates and security, make the code bigger.
And yet, why shouldn't a little utility like a registry cleaner be 50K instead of 1 MB? Is wanting that a mental health issue?
Lots of great stuff on open source & AI from Facebook's @yannlecun - As usual @karaswisher asks some great questions. Am I convinced that the bots aren't going to lead to our downfall, no. Do I think Yann's got it right on legislation no. But I liked his responses on open source, and frankly his openness to confront power.
youtube.com/watch?v=UmxlgLEscB…
#OpenSource #AI #Meta
Johns Hopkins University and Vox Media have teamed up to present the On with Kara Swisher podcast at the Johns Hopkins University Bloomberg Center. The partn...YouTube
🎉 The First 12 Castopod Plugins are Here! 🚀
We’ve hit a major milestone on the road to Castopod v2: the release of the first 12 Castopod plugins!
These plugins showcase the power of our new Plugins Architecture, enabling endless customization and exciting new features.
💡 What’s Next?
We’re working on a Plugins Repository for easy discovery and installation, plus UX improvements, async media uploads, PHP 8.4, better fediverse integration, compatibility and much more!
👉 blog.castopod.org/castopod-fir…
Explore the first 12 Castopod plugins, new features, Plugins Architecture enhancements, and upcoming improvements ahead of the final v2 release, including the Plugins Repository, an index for discovering and installing plugins.Yassine Doghri (Castopod Blog)
Tusky
in reply to saxnot @ 39C3 • • •