🕛Z #NowPlaying at the top of the hour, 2 hours of relaxing #NewAge, #ambient, and #meditationmusic on Northern Lights: The New Age Show, #live with Kelly Sapergia. More information is at ksapergia.net/northernlights/. Tune in either by visiting theglobalvoice.info and clicking on the Listen Live link, or go directly to theglobalvoice.info:8443/broad… #TGVRadio #audio #radio 📺🗣️📻🎶🎙️🌌🌈🫣🫰🩵🪬🫶

"our commitment to an enterprise rooted in respect and inclusion is appropriate and necessary."

Diverse employees and suppliers have fostered

"creativity and innovation in the merchandise and services that we offer,"

- Costco Board.

98% of Costco shareholders agreed with the board.👍🏿

Segregationists denied.

axios.com/2025/01/23/costco-de…

Segregationists are going to test each and every one of you, to see where your heart is at.

If they haven't tested you already, they will test you soon.

Do you know what you are going to say?

reshared this

in reply to Hubert Figuière

uspoli, canpoli, trade

Sensitive content

"È il principale ipocrita al mondo della libertà di parola": la battaglia di Elon Musk con Wikipedia fa parte della sua guerra alla verità


Elon Musk è arrabbiato con Wikipedia per aver riportato il suo presunto "saluto nazista". Ma i suoi attacchi fanno parte di una lunga e inquietante storia di tentativi di sopprimere informazioni che ritiene scomode

the-independent.com/tech/elon-…

@pirati

For those of you on mastodon social, please be aware that your instance is becoming a real headache for other instances and their admins. mastodon social has attracted/not blocked too many trolls and disinformation bots.

It's up to you whether you stay there, but people are blocking the whole instance to avoid these bad actors.

If you are worried about how to migrate to a new instance, fedi tips is a great help, with instructions on how to do the switch.

If you need help finding an instance that is a good fit for you, there is help for that, too.

fedi.tips/transferring-your-ma…

fedi.tips/which-server-should-…

in reply to Dale Reardon

I'm fairly confident it will be Media Transfer Protocol (MTP), which is used widely by Android devices. Linux supports MTP, at least under the GNOME desktop environment, where it's mounted by default. Microsoft Windows supports it by default in File Explorer. However, macOS doesn't and you need to install additional tools that I haven't personally tried but which may work in this case.

Day three of Trump's term and the largest push for surveillance capitalism yet has been made: Project Stargate will be a $500.000.000.000 (500 billion USD) data center used for running a multitude of AIs with the purpose of spying on you.

Larry Ellison, the world's second richest man and CEO of Oracle, one of the main partners of Stargate, said:

“Citizens will be on their best behavior, because we're constantly recording and reporting everything that's going on [...]. We're using A.I. to monitor the video.”


— Larry Ellison, CEO of Oracle on how the company's A.I. systems will be used for in the future [Source: Business Insider]

This is who is in power now. This is the vision they have.

This entry was edited (10 months ago)

uspol

Sensitive content

This entry was edited (10 months ago)

reshared this

in reply to Zach Bennoui

re: uspol

Sensitive content

in reply to Tamas G

re: uspol

Sensitive content

in reply to Tamas G

re: uspol

Sensitive content

Twilio says its adjusted operating margin will reach 21%- 22% in 2027, exceeding est. and up from 16.1% in the most recent quarter; TWLO jumps 11%+ after hours (Jordan Novet/CNBC)

cnbc.com/2025/01/23/twilio-ann…
techmeme.com/250123/p46#a25012…

#AndroidAppRain at apt.izzysoft.de/fdroid today with 19 updated and 1 added apps:

* Remind Me! – Set alarms for a specific date in the future 🛡️

Enjoy your #free #Android #apps with the #IzzyOnDroid repo

And thanks for all your kind words and congratulations to our grant 😍

A calque is a word that has been loaned *and translated* from another language. Some English calques: flea market, potsticker, beer garden, iceberg, refried beans, superman, scapegoat, stormtrooper, killer whale. englishlanguagethoughts.com/20…

Voor onze veiligheid, vrijheid en welvaart hebben we meer grip & autonomie op onze digitale infrastructuur nodig. Ambities zijn er, maar dat wordt steeds meer zoals ‘wereldvrede’ roepen! Kabinet moet keuzes & een plan maken! Blij dat onze moties voor twee Zeekabels en een AI fabriek zijn aangenomen!

🐦 "Sans les étourneaux le chant des saisons s'éteint" : Faute d'étourneaux, #ExtinctionRebellion La Rochelle les placarde en tags dans leur ville.

👉 La population d'étourneaux décline depuis les années 70, les individus restant se concentrant dans les villes faute de haies bocagères / refuges et sur-usage de pesticides dans les champs nos campagnes 🌱

This post about I/O bound "ruby" apps applies equally well to Python, PHP, JS, or any other high-level backend language. We use tools with poor CPU performance and then self-soothe with fairy tales about things being "I/O bound" or "only a few critical loops being hot" and there is *some* truth to those tropes, but it's important not to let them become thought-terminating clichés about performance. Anyway, it's important reading: byroot.github.io/ruby/performa…

Mark Your Calendars and Join the Party!

We’re less than a week away from our 10th Anniversary Celebration on January 29th from 2:00-4:00pm PST! 🎉

Be part of this milestone event as we unveil our new mascot (a community-chosen favorite!) and celebrate a decade of innovation together. We'll be hearing from team members, both past and present, connecting with our incredible community, and reflecting on how far we’ve come.

We can’t wait to celebrate with you! 🎊

✨ Join the celebration in-app or on Zoom
aira.zoom.us/j/89073345341

Some fascinating research out on hacking a Subaru via STARLINK connected vehicle service.

"On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK connected vehicle service that gave us unrestricted targeted access to all vehicles and customer accounts in the United States, Canada, and Japan.

Using the access provided by the vulnerability, an attacker who only knew the victim’s last name and ZIP code, email address, phone number, or license plate could have done the following:

Remotely start, stop, lock, unlock, and retrieve the current location of any vehicle.

Retrieve any vehicle’s complete location history from the past year, accurate to within 5 meters and updated each time the engine starts.

Query and retrieve the personally identifiable information (PII) of any customer, including emergency contacts, authorized users, physical address, billing information (e.g., last 4 digits of credit card, excluding full card number), and vehicle PIN.

Access miscellaneous user data including support call history, previous owners, odometer reading, sales history, and more.

After reporting the vulnerability, the affected system was patched within 24 hours and never exploited maliciously."

samcurry.net/hacking-subaru#in…

#cars #security #subaru @starlink

Signal is a secure messenger, but there are interesting alternatives, such as @matrix , @session , @delta , @simplex or XMPP …

➡️ matrix.org

➡️ getsession.org

➡️ delta.chat

➡️ simplex.chat

➡️ xmpp.org

If you’d like to learn more about these options, have a look at the responses to this toot.

#matrix #session #signal #XMPP #messenger #decentralized #tech #technology #OpenSource #FOSS #WhatsApp #security #InfoSec #data #safety

Lest we forget the lessons of the XZ Utils backdoor, which was nearly a year ago now, I'll repost @ariadne's post about what we can learn from it: ariadne.space/2024/04/02/the-x…

I was thinking about this today because I happened to look at the transitive dependencies of a program that uses libxml2, and noticed that Debian's build of libxml2 depends on liblzma (the library in XZ Utils where the backdoor was inserted).

in reply to Matt Campbell

Then again, if a library is built with all unnecessary features and transitive dependencies eliminated, then depending on the library and the transitive dependencies, perhaps a lot of security updates become irrelevant.

Thinking about all this as I consider whether to build ffmpeg from source with minimal features. Perhaps ffmpeg is one of the worst offenders when it comes to "junk drawer" libraries as discussed in the article.

in reply to Josh Simmons

@dotstdy True. Still, the fact that a typical distro build of ffmpeg has lots of dependencies linked as shared libraries, even though one typically uses very few of them, means that someone could repeat an XZ-style attack via any one of them. If we don't at least modify our processes to avoid a repeat of the same kind of attack, then we've learned nothing.
in reply to Matt Campbell

@dotstdy I think ffmpeg lives in a different part of the ecosystem than openssh; specifically, the part where the code is big and complicated enough that you ought to be leaning hard into sandboxing and privilege reduction to limit its blast radius rather than trying to reduce its binary footprint (because even in the best possible case, the binary footprint is going to be huge, as josh points out)
in reply to Matt Campbell

"one typically uses very few of them" isn't really true though, you'll use different codecs for different media, and fundamentally that requires a wide range of support libraries. furthermore, the xz backdoor was interesting due to *which* process it injected into - the openssh daemon. unless you start linking ffmpeg into openssh you don't have anything close to the same threat model.
in reply to Matt Campbell

if that is your takeaway i think you missed the point.

the point is that application authors shouldn’t pull in junk drawer libraries for a few convenience functions, not that we should build multiple copies of the same library to support different apps.

or more directly to the point, the person who originated the patch all the linux distributions were using to integrate systemd’s readiness notifications and openssh should have just included a reimplementation of sd_notify(), which is a fairly trivial function to write.

in reply to Matt Campbell

(self-plug:) here's how removing a junk drawer libraries looks like: github.com/FRRouting/frr/pull/…

I also think we should maybe move the "modularize and use dlopen() a bit more" slider a bit further out; and maybe there's room there for DX improvement as well (dlopen/dlsym are… clunky…). If the decision to include features can be made by installing packages, Debian doesn't _need_ to do "just the features required", it's the end user doing that with more and smaller packages.

in reply to Matt Campbell

I like Gentoo for the fact, that you can decide if you want certain features, and can there by decide against certain dependencies. It's not perfect or complete, but it can remove the burden of updating everything by hand, and minimises the number of library copies. Not sure this will help you right now, but if you want to try something later, it may be interesting

Arrow Lake's had three months of Windows and BIOS updates to fix its performance, and my testing shows in some games, it's worse
pcgamer.com/hardware/processor…
This entry was edited (10 months ago)

In a community assembly, the Indigenous Ayuujk residents of Mogoñe Viejo, Oaxaca, decided to rebuild a resistance encampment on the path of the neoliberal Interoceanic Corridor megaproject in the northern part of the Isthmus of Tehuantepec.

avispa.org/pueblos-indigenas-d…

#Mexico #Oaxaca #Indigenous

On Wednesday night I managed to capture Comet 2024 G3 ATLAS again

jamesbarfoote.co.nz/blog/captu…

#comet #space #g3atlas #g3comet #astronomy #landscape #newzealand #nz #aotearoa #newzealandphotography #wellingtonnz #wellington #astrophotography

Happy 7th anniversary of becoming an official W3C standard, ActivityPub!

w3.org/news/2018/activitypub-i…

We're creating something truly special here with the fediverse, and I am so thankful for everyone who contributes to it, whether with your time, money, or just by sharing your thoughts, your creations, your silly little jokes. Keep it up!

#fediverse #activitypub #standards #OpenWeb #anniversary

The Proliferation of Frivolous ADA Website Compliance Lawsuits: A Defense Perspective
lexology.com/library/detail.as…

Report: Microsoft to Launch Smaller Surface Pro and Laptop Models With Snapdragon Chips this Spring thurrott.com/mobile/316214/rep…

Najväčšou hrozbou pre #Slovensko je Robert #Fico

V jeho príbehu je logická diera. Nedokáže vysvetliť, v čom sú demonštrácie proti nášmu ústavnému zriadeniu, keď na nich ľudia žiadajú, aby sme neodchádzali z Európskej únie a NATO, aby sme nepodporovali vojnových zločincov.

Premiér, prezident aj vedenie parlamentu hovoria, že na Slovensku je ohrozená demokracia a republike hrozí prevrat. Snažia sa vyvolať zdanie, že je to vážne a že majú dôkazy. Akurát ich nechcú ukázať.

dennikn.sk/4425058/najvacsou-h…

in reply to Peter Hanecak

Tieto ich dnešné výpoty stačí interpretovať oveľa jednoduchšie. Pripusťme, že majú úplnú pravdu. Ale ak by ju mali, tak sa dá veľmi ľahko a logicky predpokladať, že práve teraz OČTK a kľudne aj NAKA (či ako to teraz premenovali) vykopáva dvere súbežne na viacerých miestach, robí prehliadky a zatýkačky.
Pretože to by v prípade, že nekecajú, muselo nastať, ináč by tie ich včerajšie a dnešné tančeky značne komplikovali, ba až ohrozovali prácu zodpovedných orgánov.

No a keďže zatiaľ takú správu nikde nevidím, tak jediný logický uzáver je, že sú to iba politické blúznenia a priznanie sa k zneužívaniu SIS na politické manipulácie.

🇬🇧 After running #IzzyOnDroid on my own for over 10 years, we became a small team over a year ago. All done in our spare time, no grants.

That finally changed this week.

We're excited that we're one of seven projects being accepted for the NGI #Mobifree grant! 🥳

Finally we will be able to focus on some more things on our wish list that we've wanted to do for the community for a long time. Stay tuned, we'll update you with details later!

nlnet.nl/project/IzzyOnDroid/

A hacker developed an "infinite maze" to trap web-crawlers/scrapers from AI companies

basically, if the server code detects that a web crawler from an AI firm is trying to scrape the site ...

... the code begins spinning up an infinite, nesting warren of new sham pages, filled with random text

so the crawler gets stuck crawling and scraping endless and meaningless pages

404media.co/email/7a39d947-4a4…