Khronos reshared this.
Schwachstellenbewertung: Opensource-Entwickler erneuert Kritik an CVSS und CVE
cURL-Entwickler Daniel Stenberg stört, dass seine CVE-Einträge eigenmächtig von der CISA mit CVSS-Scores versehen werden. Er hat plausible Argumente.Olivia von Westernhagen (heise online)
We've got some exciting job openings at #Thunderbird! We're hiring for a Sr. UX Design Specialist, A #Rust /C++ Software Engineer for the desktop app, and......a Senior #iOS Engineer to join our mobile team to help us bring Thunderbird to your iPhone and iPad!
Help us spread the word!
mozilla.org/careers/listings/?…
Mozilla Careers — All open positions at Mozilla
We have a mighty mandate, serving hundreds of millions of people. Add a culture of exploration, and there is always a new way to learn and grow here.Mozilla
FediVerseExplorer likes this.
Federico Mena Quintero reshared this.
Maybe that could be mentioned in the OP?
It's a fairly big oversight when posting jobs to a global site, and all the details of restrictions end up being 3 clicks away.... you're not alone almost every job posting is the same.
There really needs to be a standard format for job postings that includes residency/eligibility.
This high-performance Ryzen 9 mini PC is on sale for just $399
At this price, the Acemagic AM08 Pro mini PC is a steal for both gaming and productivity.Gabriela Vatu (PCWorld)
Microsoft just killed the ability to look up words and phrases in Word
In a move to push users toward Copilot AI, Microsoft has deprecated this popular feature.Mikael Markander (PCWorld)
I don't know how many of these apps are accessible. I use Everything and it's quite accessible and super useful.
Another must-have for me is Winaero Tweaker.
Hidden gems: These 20 truly useful Windows apps are free, too! pcworld.com/article/2570670/hi…
Hidden gems: These 20 truly useful Windows apps are free, too!
So many great apps eventually cost money. These fantastic apps cost nothing. Don't overlook them because they're really useful!Jon Martindale (PCWorld)
reshared this
Glad to finally get to participate in the EU Open Source Policy Summit '25 in #Brussels. I was able to watch the morning presentation thanks to Fred Dixon's @bigbluebutton
We will have to meet again in #Ottawa. Great start to the #EuropeOpenSouceWeek & #FOSDEM.
#EUOpenSource #OpenSourcePolicySummit #EUOpenSourcePolicyForum #EUOSPF #EUOSPF25
Man who became a billionaire by erasing individual privacy annoyed his private words are becoming public.
404media.co/zuckerberg-says-ev…
'Everything I Say Leaks,' Zuckerberg Says in Leaked Meeting Audio
"There are a bunch of things that I think are value-destroying for me to talk about, so I’m not going to talk about those."Jason Koebler (404 Media)
8.3K likes and 633 comments 🤯
We're seeing unprecedented levels of activity and interactions on @PixelFed, and the community has been so kind to each other.
You love to see it ✨
-
A Sleeping Bat at The Next Page Bookshop in Calgary Becomes an Unlikely Star: streetartutopia.com/2025/01/30…
A Sleeping Bat at The Next Page Bookshop in Calgary Becomes an Unlikely Star | STREET ART UTOPIA
A small bat a few years ago chose the entrance of The Next Page bookshop in Calgary as its resting spot. The bookstore put up a sign: 'Please open the door carefully as there is a bat sleeping on it.streetartutopia.com
LibreOffice QA Team: Fixing a bug in three days - The Document Foundation Blog
LibreOffice is used by 200 million people around the world. Every major release goes through extensive testing, with Alpha, Beta and Release Candidate versions – and there are regular monthly minor updates to fix issues too.Mike Saunders (The Document Foundation)
@overunderlay There's no such thing as universal outlet. The one on the picture does not provide earthing for dominant european plugs nor accepts italian or swiss plugs.
I think having alternating scheme of BS 1363 and Schuko sockets is much better than that. Hopefully, during some future refresh, 60W USB-PD chagers would be installed which will make everyone's life much easier.
Leaked all-hands: Mark Zuckerberg said Meta sold more than 1M Ray-Ban smart glasses in 2024, revealing sales figures for the first time
From The Verge. View the full context on Techmeme.Techmeme
For 2025, here is a updated and hopefully-useful notice about Linux kernel security issues, as it seems like this knowledge isn't distributed very widely based on the number of emails I still get on a weekly basis:
- The Linux kernel security team does not have any "early notice" announcement list for security fixes for anyone, as that would only make things more insecure for everyone. The number of organizations that fail to understand this is way too high.
- The kernel community DOES assign CVEs, as we are a CNA, please see kernel.org/doc/html/latest/pro… for how they are handled and assigned. Side note, we were #2 in quantity for CVE assignments in 2024 despite only doing so for 10 1/2 months, averaging about 10 CVEs per day. Any process you might have where you feel you need to research each CVE on an individual basis manually is going to be a major time suck, automate it! All CVE entries are provided with proper git commit ids for the vulnerable release ranges for you to check yourself, AND we have tools and other formats that you can use to check this yourself. See git.kernel.org/pub/scm/linux/s… for the tools and raw data for you to pull from directly if you don't want to deal with the cve.org json feed.
- Kernel CVE entries are constantly updated over time, you can not just look a them only when created, and then ignore all updates. Too many groups are missing revoked CVE entries and tightening of vulnerable kernel ranges that we are updating on a weekly basis. By ignoring the updates, you are causing yourself more work, not less. cve.org provides an "updated" feed in their git tree, use it!
- Along the lines of the huge number of recorded CVEs, you HAVE to take all of the stable/LTS releases in order to have a
secure and stable system. If you attempt to cherry-pick random patches you will NOT fix all of the known, and unknown, problems,
but rather you will end up with a potentially more insecure system, and one that contains known bugs. Reliance on an "enterprise"
distribution to provide this for your systems is up to you, discuss it with them as to how they achieve this result as this is what you are paying for. If you aren't paying for it, just use Debian, they know what they are doing and track the stable kernels and have a larger installed base than any other Linux distro. For embedded, use Yocto, they track the stable releases, or keep your own buildroot-based system up to date with the new releases.
- Test all stable/LTS releases on your workload and hardware before putting the kernel into "production" as everyone runs a different %
of the kernel source code from everyone else (servers run about 1.5mil lines of code, embedded runs about 3.5mil lines of code, your mileage will vary). If you can't test releases before moving them into production, you might want to solve that problem first.
- A fix for a known bug is better than the potential of a fix causing a future problem as future problems, when found, will be fixed then.
#XSF Summit 27
Today is the second day discussing diverse topics around the #XMPP #protocol! 
Participate: xmpp.org/2024/11/xmpp-summit-2…
#jabber #chat #interoperability #rtc
#opensource #decentralization #standard
ChatGPT's advanced AI costs $200/mo. Now it's free for Windows users
Microsoft is making waves in the AI space, giving Windows users free access to OpenAI's o1 model, while OpenAI charges up to $200/mo for it.Mark Hachman (PCWorld)
We Did the Math: How Much More Expensive Is Grocery Shopping With Instacart, Really?
The breakdown of the numbers might surprise you.Pamela Vachon (CNET)
Khronos reshared this.
reshared this
The pissant's executive order lead to 1 air traffic controller on duty, doing the job of 2 people, at least, b/c of the policy implemented more than 1 week ago. These deaths are a direct result of the pissant administration.
Collision between helicopter and plane kills 67 in nation’s deadliest air disaster since 2001: apnews.com/live/dc-plane-crash… #SHAMEFUL #USA
Live updates: Collision between helicopter and plane kills 67 in nation's deadliest air disaster since 2001
All 67 people aboard an American Airlines jet and Army helicopter at Reagan National Airport are dead after the two vehicles collided on Wednesday. It is the worst U.S. aviation disaster in almost a quarter century.THE ASSOCIATED PRESS (AP News)
FDA Approves the First Non-Opioid Pain Drug in 20 Years
https://time.com/7211657/fda-approves-non-opioid-pain-drug-suzetrigine/?utm_source=flipboard&utm_medium=activitypub
Posted into Health @health-time
FDA Approves the First Non-Opioid Pain Drug in 20 Years
Experts see suzetrigine's potential in treating acute pain without the risk of addiction.Alice Park (Time)
Apple Explains How to Keep Your Mac From Turning on When Opening Lid
Apple designed Macs with Apple silicon chips to automatically turn on and start up when the Mac's lid is opened or when the Mac is connected to...Juli Clover (MacRumors.com)
reshared this
reshared this
Want your fediverse project listed on fediverse.info/explore/project… and FediDB.org/software ?
Add your details to the CommunityDB repo:
I will merge and update so they are ready for #FOSDEM ✨
FediDB, Fediverse Network Statistics
FediDB is a cutting-edge service providing detailed statistics and insights into the Fediverse network.fedidb.org

Desiree Renae
in reply to David Goldfield • • •