Please boost! #FediHire

I'm looking for my next role as a program manager, team lead, or senior developer.

- 20+ years in open source
- 6 years experience in web dev with #Python, #Django, HTML, bootstrap
- 7 years experience in C, Linux kernel, embedded systems

My passions lie at the intersection of open source software development and creating welcoming spaces for people to learn and grow.

I'm currently the program manager for a technical internship program. I work remotely with a team of 4 people in New York, Brazil, and Nigeria.

Looking for a fully remote role. I'm open to relocation outside the USA.

Resume here: sage.thesharps.us/hire-me/

DM me or send an email to sage at thesharps dot us

reshared this

The May 2025 update for the BT Speak is now live!!
Features include:
a more versatile clipboard that extends across traditional and desktop mode and which even back and forward translates what gets pasted, depending on the Braille table being used

More standard commands in the editor, such as ctrl+c for copy, ctrl+v for paste, etc.

an NFB Newsline app

Help files and the welcome screen now allow for headings and links, making them more interactive

and more!!

blazietech.com/may-2025-update

DG

in reply to Nick's world 🌎 πŸ‘¨β€πŸ¦― πŸ—½

@gocu54 First, we need to determine what your Braille input mode is set to by going to Options, Settings, Braille Settings, Change the Input Prompt mode and set it to "Expect Computer Braille" and see if that fixes the problem.

Also, we should determine what locale you are using.
You can go to Options, Operating System, System Administration, Customize This BT Speak, Change the Locale. When you do this, what locale option is it pointing to?

in reply to Harry Sintonen

This thing works by generating fake vulnerability reports. Here are some of the qualities of the HackerOne report 3125832 sent to #curl:
- It looks convincing at a glance, especially if you're not a subject matter expert.
- It's vague about actual repro steps. It makes it impossible for the victim project to reproduce the issue. For example, it makes up fake patches against non-existent, imaginary code.
- It refers to functions and methods that do not exist (in case someone tries to look for them). When confronted, the attacker refer to some old or new versions of components, using non-existent commit hashes.
- The report makes up some convincing functionality or names that are novel, but don't really exist.

An expert’s look at the report shows the number of discrepancies, but finding them takes time and effort. It requires attention from a subject matter expert, with limited resources.

The real exploit here is that the attacker (evilginx) exploits the fact that the victims (the orgs who paid the attacker money) don't have the capacity to perform thorough analysis and rather just pay up. TL;DR: It's cheaper to pay the bug bounty than hire an expert to perform true analysis.

Why didn't it work against the curl project? The attacker miscalculated badly. Curl project is not a company and has far greater capability in security response than your average org. Also they can smell #aislop miles away.

This entry was edited (7 months ago)

"Mir reicht's": #Curl-Entwickler spricht Machtwort gegen "KI-Schrott"

golem.de/news/mir-reicht-s-cur…

> Entwickler @bagder zeigt sich frustriert ΓΌber durch KI generierte Bug-Reports. Reporter werden kΓΌnftig einem Intelligenztest unterzogen.

Btw., #Golem garniert den Artikel mit einem KI generierten Bild 🀷

Aber das mit den Intelligenztest finde ich gut. Die Frage ist, ob man mit Captchas gegen LLMs ankommt.

#AI #LLM

AI vulnerability/bug founds and reports is a huge problem. Curl has banned the use of AI-generated submissions via HackerOne because none of it made any sense, and is a waste of resources and time. "We are effectively being DDoSed. If we could, we would charge them for this waste of our time" hackerone.com/reports/3125832

uspol, safety, on leaving

Sensitive content

reshared this

For over one year I've been harassed, threatened, doxxed, misgendered and abused by Luna the Foxgirl, author of Inochi2D.

Due to her attacks and manipulation of others, I no longer feel safe contributing to Linux GPU drivers, and I will be retiring my current model.

asahilina.net/luna-abuse/

Together with 39 orgs & 42 experts, our founder Matthias Pfau calls on the EU in an @edri open letter for a scientific evidence-based approach to #encryption πŸ”’

No government can change the laws of math.

Read the open letter ‡️
tuta.com/blog/open-letter-agai…

treefit reshared this.

in reply to Tuta

Encryption ensures integrity of ANY communication. Literally whole internet is based on it. If you temper with it at any point, it's not secure anymore. There is no "good guys" in encryption that should have the keys to peek inside. It's just encryption from start to end uninterrupted. Literally the fundamental part of everything online, secure shopping, secure voting, secure communication, private or of business nature.

Thin Fonts Are a Usability Nightmareβ€”And Finally, Designers Are Waking Up

webdesignerdepot.com/thin-font…

#UIDesign #webdesign #a11y #fonts #usability #accessibility #typography

❗TakΕΎe vΓ‘ΕΎenΓ­, pondΔ›lΓ­ je po prodlouΕΎenΓ©m vΓ­kendu jeΕ‘tΔ› kritičtΔ›jΕ‘Γ­ neΕΎ obvykle.
Kdo si dΓ‘ po obΔ›dΔ› malou mentΓ‘lnΓ­ rozcvičku, rozhodnΔ› neprohloupΓ­! Ale nesmΓ­te na sebe moc chvΓ‘tat. Stačí tΕ™eba vyjmenovat herce v Sedmi statečnΓ½ch nebo tak nΔ›co. πŸ‘‡πŸ˜Š

youtube.com/watch?v=sC7PPA5qQs…

at politik

Sensitive content

DalΕ‘Γ­ rozhovor P. ProchΓ‘zkovΓ© s ekonomem emigrantem z Ruska. TentokrΓ‘t je to vΓ­ce data-based. #odemceno denikn.cz/1712638/prichazi-do-…
in reply to James H

If I use Gemini, which is how I'm transcribing stuff these days, it's different every time.

1. Build Shit, Fix You, and Sorry is Better and Body for you, for you.
2. Deal Sheet, Visual and solid, is better and body for you, for you
Let's try through Whisper:
They'll cheat this you and sorry it's better and party for you, for you.

A transcription I got earlier had something about "aesthetic", which I can actually hear if I listen now.

NΔ›co jsem vΔ›dΔ›l, nΔ›co jsem neznal. KaΕΎdopΓ‘dnΔ› (ne)pΔ›knΓ‘ historie USA z hlediska dopravy a ΓΊzemnΓ­ho plΓ‘novΓ‘nΓ­. smichovreviewofcities.substack… #links

at politik

Sensitive content

This entry was edited (7 months ago)

Good morning Fedi friends!

Please join me in giving a warm welcome to my interns Riyen (@patel.riyen) & Sam (@samaaberg). They will be working with me through the end of June on videos promoting the Fediverse. This is their #introduction.

Sam & Riyen are two talented film students who are #NewHere: a mere 7 days ago they had no idea what the Fediverse was. I have the immense honor of introducing them to it.

We are filming this week! Send us good vibes πŸŽ₯✨ #EleFediVideos

πŸ“£ Do-It-Blind (DIB) online Besprechung am Montag, 5. Mai, um 19:00 Uhr. Du bist eingeladen! bbb.metalab.at/rooms/joh-szv-o… WΓΆchentlich am Montag um 19:00 besprechen wir neue Formen der digitalen und inklusiven Zusammenarbeit. Mach mit! πŸ› οΈ #make #blind #inklusion

Get more out of #LibreOffice by downloading the free guidebooks created by our awesome documentation community! Here's a recap of what they did in 2024, from our Annual Report: blog.documentfoundation.org/bl… #foss #OpenSource

LibreOffice reshared this.

NVDA 2025.1 Beta 4 is now available! Changes from Beta 3 include:
- Updates to translations
- Fix security issue which allowed an arbitrary process to connect to a Remote Access session running on a secure screen
- Allow Remote Access leaders to regain control after the last follower has disconnected
- Improve focus handling in the Remote Access Connection dialog
- Don’t toggle Remote Access mute when not connected

Read the full details & download from: nvaccess.org/post/nvda-2025-1b…
#NVDA #NVDAsr

David Goldfield reshared this.

⇧