Signal is a secure messenger, but there are interesting alternatives, such as @matrix , @session , @delta , @simplex or XMPP …

➡️ matrix.org

➡️ getsession.org

➡️ delta.chat

➡️ simplex.chat

➡️ xmpp.org

If you’d like to learn more about these options, have a look at the responses to this toot.

#matrix #session #signal #XMPP #messenger #decentralized #tech #technology #OpenSource #FOSS #WhatsApp #security #InfoSec #data #safety

Lest we forget the lessons of the XZ Utils backdoor, which was nearly a year ago now, I'll repost @ariadne's post about what we can learn from it: ariadne.space/2024/04/02/the-x…

I was thinking about this today because I happened to look at the transitive dependencies of a program that uses libxml2, and noticed that Debian's build of libxml2 depends on liblzma (the library in XZ Utils where the backdoor was inserted).

in reply to Matt Campbell

Then again, if a library is built with all unnecessary features and transitive dependencies eliminated, then depending on the library and the transitive dependencies, perhaps a lot of security updates become irrelevant.

Thinking about all this as I consider whether to build ffmpeg from source with minimal features. Perhaps ffmpeg is one of the worst offenders when it comes to "junk drawer" libraries as discussed in the article.

in reply to Josh Simmons

@dotstdy True. Still, the fact that a typical distro build of ffmpeg has lots of dependencies linked as shared libraries, even though one typically uses very few of them, means that someone could repeat an XZ-style attack via any one of them. If we don't at least modify our processes to avoid a repeat of the same kind of attack, then we've learned nothing.
in reply to Matt Campbell

@dotstdy I think ffmpeg lives in a different part of the ecosystem than openssh; specifically, the part where the code is big and complicated enough that you ought to be leaning hard into sandboxing and privilege reduction to limit its blast radius rather than trying to reduce its binary footprint (because even in the best possible case, the binary footprint is going to be huge, as josh points out)
in reply to Matt Campbell

"one typically uses very few of them" isn't really true though, you'll use different codecs for different media, and fundamentally that requires a wide range of support libraries. furthermore, the xz backdoor was interesting due to *which* process it injected into - the openssh daemon. unless you start linking ffmpeg into openssh you don't have anything close to the same threat model.
in reply to Matt Campbell

if that is your takeaway i think you missed the point.

the point is that application authors shouldn’t pull in junk drawer libraries for a few convenience functions, not that we should build multiple copies of the same library to support different apps.

or more directly to the point, the person who originated the patch all the linux distributions were using to integrate systemd’s readiness notifications and openssh should have just included a reimplementation of sd_notify(), which is a fairly trivial function to write.

in reply to Matt Campbell

(self-plug:) here's how removing a junk drawer libraries looks like: github.com/FRRouting/frr/pull/…

I also think we should maybe move the "modularize and use dlopen() a bit more" slider a bit further out; and maybe there's room there for DX improvement as well (dlopen/dlsym are… clunky…). If the decision to include features can be made by installing packages, Debian doesn't _need_ to do "just the features required", it's the end user doing that with more and smaller packages.

in reply to Matt Campbell

I like Gentoo for the fact, that you can decide if you want certain features, and can there by decide against certain dependencies. It's not perfect or complete, but it can remove the burden of updating everything by hand, and minimises the number of library copies. Not sure this will help you right now, but if you want to try something later, it may be interesting

Arrow Lake's had three months of Windows and BIOS updates to fix its performance, and my testing shows in some games, it's worse
pcgamer.com/hardware/processor…
This entry was edited (10 months ago)

In a community assembly, the Indigenous Ayuujk residents of Mogoñe Viejo, Oaxaca, decided to rebuild a resistance encampment on the path of the neoliberal Interoceanic Corridor megaproject in the northern part of the Isthmus of Tehuantepec.

avispa.org/pueblos-indigenas-d…

#Mexico #Oaxaca #Indigenous

On Wednesday night I managed to capture Comet 2024 G3 ATLAS again

jamesbarfoote.co.nz/blog/captu…

#comet #space #g3atlas #g3comet #astronomy #landscape #newzealand #nz #aotearoa #newzealandphotography #wellingtonnz #wellington #astrophotography

Happy 7th anniversary of becoming an official W3C standard, ActivityPub!

w3.org/news/2018/activitypub-i…

We're creating something truly special here with the fediverse, and I am so thankful for everyone who contributes to it, whether with your time, money, or just by sharing your thoughts, your creations, your silly little jokes. Keep it up!

#fediverse #activitypub #standards #OpenWeb #anniversary

The Proliferation of Frivolous ADA Website Compliance Lawsuits: A Defense Perspective
lexology.com/library/detail.as…

Report: Microsoft to Launch Smaller Surface Pro and Laptop Models With Snapdragon Chips this Spring thurrott.com/mobile/316214/rep…

Najväčšou hrozbou pre #Slovensko je Robert #Fico

V jeho príbehu je logická diera. Nedokáže vysvetliť, v čom sú demonštrácie proti nášmu ústavnému zriadeniu, keď na nich ľudia žiadajú, aby sme neodchádzali z Európskej únie a NATO, aby sme nepodporovali vojnových zločincov.

Premiér, prezident aj vedenie parlamentu hovoria, že na Slovensku je ohrozená demokracia a republike hrozí prevrat. Snažia sa vyvolať zdanie, že je to vážne a že majú dôkazy. Akurát ich nechcú ukázať.

dennikn.sk/4425058/najvacsou-h…

in reply to Peter Hanecak

Tieto ich dnešné výpoty stačí interpretovať oveľa jednoduchšie. Pripusťme, že majú úplnú pravdu. Ale ak by ju mali, tak sa dá veľmi ľahko a logicky predpokladať, že práve teraz OČTK a kľudne aj NAKA (či ako to teraz premenovali) vykopáva dvere súbežne na viacerých miestach, robí prehliadky a zatýkačky.
Pretože to by v prípade, že nekecajú, muselo nastať, ináč by tie ich včerajšie a dnešné tančeky značne komplikovali, ba až ohrozovali prácu zodpovedných orgánov.

No a keďže zatiaľ takú správu nikde nevidím, tak jediný logický uzáver je, že sú to iba politické blúznenia a priznanie sa k zneužívaniu SIS na politické manipulácie.

🇬🇧 After running #IzzyOnDroid on my own for over 10 years, we became a small team over a year ago. All done in our spare time, no grants.

That finally changed this week.

We're excited that we're one of seven projects being accepted for the NGI #Mobifree grant! 🥳

Finally we will be able to focus on some more things on our wish list that we've wanted to do for the community for a long time. Stay tuned, we'll update you with details later!

nlnet.nl/project/IzzyOnDroid/

A hacker developed an "infinite maze" to trap web-crawlers/scrapers from AI companies

basically, if the server code detects that a web crawler from an AI firm is trying to scrape the site ...

... the code begins spinning up an infinite, nesting warren of new sham pages, filled with random text

so the crawler gets stuck crawling and scraping endless and meaningless pages

404media.co/email/7a39d947-4a4…

We're hiring a Senior Software Engineer on the @securedrop team at @freedomofpress.

SecureDrop is open source whistleblowing software. The project is at a critical inflection point as we get ready to build the next-gen version based on a modern cryptographic protocol.

100% remote, full-time, $110-$120K base salary with comprehensive benefits for US-based employees. (If you're not in the US, we can discuss consultancy models.)

Hmu for questions.

grnh.se/813b998c5us

#GetFediHired

We are looking for speakers interested in talking about gaming, cell phone app, a better design experience for apps, and advances in apps. #LAS2025 Call for Proposals is now open! Submit your talk proposal by February 15 at linuxappsummit.org/cfp/ and inspire the Linux app community.
This entry was edited (10 months ago)

Love this piece from @teenvogue.bsky.social on how gender has varied around the world, across time. LOADS of cultures recognize more than two genders. teenvogue.com/story/gender-var…

There may not be much good news around at the moment, so let's make sure we celebrate it when we see it.

Today is a great day for LGBT folk in Thailand. Really happy for all those who have finally been allowed to get married today.

bbc.co.uk/news/articles/cge7g9…

#Thailand #EqualMarriage #GoodNews

@Tutanota es un servicio de correo, calendario y contactos con #seguridad postcuántica y de vanguardia en #privacidad para proteger tus comunicaciones en línea.

En este artículo conocerás por qué es la alternativa a Gmail que necesitas.

zcashesp.com/tuta-correo-calen…

Beyond the Rollback: Why Disability Inclusion Will Survive the End of DEI Programs | Aaron Di Blasi | AT-Newswire.com
at-newswire.com/how-disability…

Despite the rollback of DEI programs, disability inclusion remains essential. Discover how legal protections, market demand, and technological advancements will sustain accessibility in business and beyond.