"Apps shouldn’t let users enter OpenSSL cipher-suite strings"
"Apps shouldn’t let users enter OpenSSL cipher-suite strings"
Learn using BigBlueButton, the trusted open-source web conferencing solution that enables seamless virtual collaboration and online learning experiences.bbb.metalab.at
75% of web traffic flows through Google's Chromium. Apple controls Safari. American companies control how billions access the web.
Building a competitive browser alternative: ~€50-70M annually, 3-4 years. @servo proves it's technically possible with a small team.
The challenge isn't technical, it's institutional: can democratic societies coordinate long-term tech projects?
Read more: tarakiyee.com/digital-sovereig…
#DigitalSovereignty
It is time for Linux to fully join the ✨AI✨ gravy train. Now you finally can ask our AI agent to answer the ultimate Linux questions: is Linux about choice?
To write this article, I went beyond the limits of my technical knowledge, which is that of an advanced user who has studied standard formats and their characteristics in depth, to understand why standard formats – one of the pillars of digital sover…Italo Vignoli (The Document Foundation)
Is "sovereign washing" the new "privacy washing"?
Microsoft, Google, and AWS recently published “sovereign clouds”.
❌ BUT digital sovereignty doesn’t come from shiny new product names such as these “sovereign clouds” - which still must hand out data to US without a warrant based on the CLOUD Act and FISA.
✅ Digital sovereignty comes from full European legal and technical control. Everything else is nothing more than sovereign washing.
👉 tuta.com/blog/sovereign-washin…
AWS, Microsoft, Google - they all launched "sovereign clouds" recently. But the truth is, all US companies are subject to US data sharing legislation. Let's explore whether it's safe to use US clouds or whether it's just "sovereign washing".Tuta
Tuta reshared this.
Ok. So why are you using Amazon nameservers for your tuta.com domain? Check: en.internet.nl/site/tuta.com/3…
Seems about time to switch to a EU-based DNS provider
For options see: european-alternatives.eu/categ…
A managed DNS provider can be used to set DNS records for domains.European Alternatives
@bartknubben Actually, we used to use a small German provider, but had to switch because they could not defend adequately against attacks, see here: tuta.com/blog/ddos-dns-attack
We don't like having to use AWS, but for the domain, we must use something big as for some reason we're a high-profile target for attacks. 🤔
What alternatives would you suggest (we'd love to switch to something better!)?
Multiple DNS providers were attacked to take down Tutanota.Tuta
There are certainly EU anycast DNS providers that could fix this for you. Might also be a good idea to use two of them. See for example:
- cloudns.net/
- rcodezero.at/en
- netnod.se/dns
See further: european-alternatives.eu/categ…
A managed DNS provider can be used to set DNS records for domains.European Alternatives
curl's handling of small transfers are now up to 30% faster (certain conditions apply)😌
Realistically, most of you will not really see this (that much). But should you need it, curl has become a little bit better.
github.com/icing/blog/blob/mai…
Contribute to icing/blog development by creating an account on GitHub.GitHub
On this day, June 29, 1964, NBC made a historic decision that would forever change the landscape of television and science fiction: the network greenlit Gene Roddenberry’s script for the pilot episode of Star Trek, titled The Cage.Luke Bouma (Cord Cutters News)
@Bruce Oh ... sorry; I didn't catch on.
I remember when the actual pilot aired sometime in the late 1980s; it was neat too hear it.
Need to let loose a primal scream without collecting footnotes first? Have a sneer percolating in your system but not enough time/energy to make a whole post about it? Go forth and be mid: Welcome to the Stubsack, your first port of call for learning fresh Awful you’ll near-instantly regret.
Any awful.systems sub may be subsneered in this subthread, techtakes or no.
If your sneer seems higher quality than you thought, feel free to cut’n’paste it into its own post — there’s no quota for posting and the bar really isn’t that high.
The post Xitter web has spawned soo many “esoteric” right wing freaks, but there’s no appropriate sneer-space for them. I’m talking redscare-ish, reality challenged “culture critics” who write about everything but understand nothing. I’m talking about reply-guys who make the same 6 tweets about the same 3 subjects. They’re inescapable at this point, yet I don’t see them mocked (as much as they should be)Like, there was one dude a while back who insisted that women couldn’t be surgeons because they didn’t believe in the moon or in stars? I think each and every one of these guys is uniquely fucked up and if I can’t escape them, I would love to sneer at them.
(Credit and/or blame to David Gerard for starting this. Also, happy 4th July in advance...I guess.)
reshared this
È stato un anno difficile per le finanze di GNOME.
Se GNOME ti è utile, abbiamo davvero bisogno di un tuo contributo: donate.gnome.org
Looks like the Jabber/XMPP community will have a booth at @FrOSCon this year.
August 16th and 17th. Save the date. See you there.
I promise we will bring stickers!
Nicoco reshared this.
ZimaCube is for those who value their data and put in long hours. Securely store, organize, and access your files from any device, anywhere.zimaspace
It's a busy day! NVDA 2025.2 Beta 1 is now out: nvaccess.org/post/nvda-2025-2b…
AND In-Process is also out: nvaccess.org/post/in-process-3… - covering all about NVDA 2025.1, NV Access in the Forbes Accessibility 100, five quick things to try with NVDA 2025.1, and a small end of financial year request: nvaccess.org/post/in-process-3…
#NVDA #NVDAsr #ScreenReader #Accessibility #Blog #News #NewVersion #PreRelease #Beta #FLOSS #FOSS
Someone on the Blind Vintage Tech list posted a zip file containing two folders of digitized recordings of two computer magazines from the 1990s: Computer Folks and Bitstream.
Both of these magazines were originally distributed on cassette tapes. Computer Folks was recorded by Rich and Donna Ring. Rich, I believe, is deceased but Donna is still with us. The archive starts out with the September 1991 issue. The next issue, which I haven’t heard all of yet, has an interview with Deane Blazie.
Bitstream was recorded by Peter Ciali. I don’t have information on whether he is still with us or not. These magazines are fascinating as they really give you an idea of where we were at that time with blindness technology and how it evolved and grew. The link to this zip file is
dropbox.com/scl/fi/l76fmy1bu39…
That link may not be around for much longer so if you want this archive, I recommend downloading it sooner than later.
If anyone would like to subscribe to the Blind Vintage Tech list, send email to
Bvtc+subscribe@groups.io
This list, as its name implies, is for the discussion of older blindness tech; Sharp calculators, DOS and early Windows screen readers, Braille ‘n Speak; you get the idea.
reshared this
A fediverse client with better support for Akkoma, glitch-soc, and Iceshrimp instances.enafore.social
Detailed price information for Nvidia Corp (NVDA-Q) from The Globe and Mail including charting and trades.United States
Tech giants aren't renowned for their honesty and openness. When it comes to making claims and pointing to benchmarks, it's not just Nvidia that plays fast and...Rob Thubron (TechSpot)
"As #space junk increases, more operators are choosing to launch without any #insurance at all. To compensate, companies are cutting back on the cost of satellites and launching more of them at faster rates, thus creating a feedback loop as the cheaper satellites break up more easily and add to the problem. Behind the predicament are two vectors moving in opposite directions: The cost of launching satellites is falling, while the cost of insuring them continues to soar.”
space.com/space-exploration/sa…
Cheap, uninsured satellites are creating more space junk — and it's starting to rain down on our heads.Tom Brown (Space)
Chris Van Hollen explains that tax cuts for the wealthy don't expire, but other provisions, e.g., no tax on tips, no tax on overtime, DO PHASE OUT.
Republicans are lying to you. Again, and again.
#BigFuglyBill #BBB #TrumpDidThis #RepublicansDidThis #Project2025 #NoRepublicansEverAgain #USPol
Eggs were somehow considered too expensive so Americans voted to totally destroy our disaster emergency response services, our National Parks, Medicaid, energy development, and cancer research services.
It’s completely and utterly insane.
“When is cancer political?" Medical researchers, patients decry Trump admin's layoffs, budget cuts - CBS News:
cbsnews.com/news/when-is-cance…
Scientists conducting medical research are facing an existential crisis: Layoffs and budget cuts pushed by President Trump that, they say, jeopardize finding a cure for cancer.CBS News
#Nautilus #AMC #AMCplus #Disney.
The troubled series Nautilus has finally made it's way onto TV here. It will be broadcast tonight June 29 at 9pm Eastern on AMC and stream on AMC+. It's 10 episodes and has been cancelled. Disney+ produced it and passed after filming.
Nautilus | Official Trailer | Premieres June 29 | AMC+
youtu.be/6AjVpIqK6U8?si=Qla0S5…
Inspired by Jules Verne’s beloved Twenty Thousand Leagues Under the Sea, Nautilus follows Nemo’s mission to enact revenge on the East India Mercantile Compan...YouTube
#Nautilus #AMC #AMCplus #Disney
The reviews for Nautilus aren't that bad. It's a reimagining of 20,000 Leagues Under the Sea and apparently a much darker Indiana Jones. I might give it a try and just know that it's not coming back.
A Behind-the-Scenes Look at Nautilus | Premieres June 29 | AMC+
youtu.be/X55WRUz9xE0?si=EOdZOH…
Nautilus premieres Sunday, June 29 on AMC and AMC+.#AMCPlus #Nautilus » Subscribe for More: https://bit.ly/3tz1yp9AMC+ ON SOCIAL:Instagram: https://www.insta...YouTube
Microsoft has confirmed that the next release of Windows is called Windows 11 25H2, and it’s going to be a minor update deployed via an enablement package.Mayank Parmar (Windows Latest)
reshared this
Ever wish Hebrew words would just stick? That’s exactly what happened to my student David—he surprised everyone at Shabbat dinner by effortlessly asking for the bread, salad, and rice…in Hebrew! 🥖🥗🍚
In this first video of my new Hebrew Food Series, I’ll show you how to make Hebrew vocabulary feel natural—starting with what’s in your kitchen.
Watch here: youtu.be/tDBp9zFc07g?si=UK46c3…
#Foods #LearnHebrew #LanguageLesson #Foodie #HebrewByInbal
#learnhebrew #food #israel #hebrewbyinbalExpand your culinary vocabulary with this first video in my Hebrew food series! Learn essential Hebrew words for com...YouTube
You no longer have to wonder whether some of the masked men with guns in unmarked cars taking people off the streets might not be real law enforcement officers. We now know that 𝗺𝗮𝗻𝘆 𝗮𝗿𝗲 𝗻𝗼𝘁.
theguardian.com/us-news/2025/j…
That includes a guy in NC who sexually assaulting a woman by threatening to deport her.
#ICE #Trump #USLaw #USPol #USPolitics
Experts say trend of agents detaining people while masking and wearing plainclothes increases riskJosé Olivares (The Guardian)
An important but inconvenient fact to remember about NYPD "work stoppages" and "quiet quitting."
When NYPD intentionally makes fewer arrests and does less police work in protest, violent crime goes *down*
🙂🙃
Read that again. Violent crime goes *down* when cops quit.
And we've known why since 1970
Once you understand a few things about US policing, this outcome becomes incredibly obvious and unavoidable.
First, understand that "Law and Order, SVU," is not how policing works, and not what police do.
What most police do, most of the time, is arrest and fine innocent Black people.
This makes it unsafe for Black people to call the cops in any circumstances. A Black person that has recently had a violent and racist encounter with the cops, will not call the cops to save you if they see you being assaulted.
So the more "policing" happens, the greater this depressive effect.
The irony:
As you ramp up "policing," it becomes impossible to catch and arrest any real, violent criminals... because you betrayed and violated all of the civilians in the communities that you were supposed to partner with.🤦🏿♂️
You created the pre-condition for ineffective and futile police work.
As an NYC resident, you pay $12B a year for a police force that is not good at what you want them to be good at: solving and preventing murder, theft, and sexual assault.
For example, the most stolen items in NYC are smartphones and bikes. NYPD doesn't even recognize the most recommended bike lock🤡
hachyderm.io/@mekkaokereke/112…
1/3
Attached: 1 image @NSalwen@mstdn.social @Jackiemauro@fosstodon.org NYPD budget is $12 billion a year. Billion. The most stolen 2 items in NYC, are 1) cell phone and 2) bike. NYPD is useless at preventing the theft, or recovering stolen bikes.Hachyderm.io
Let me bring it home for y'all using a topical example: ICE.
ICE has always been bad, but recently it's ramped up. It doesn't matter if an *individual* ICE agent is a good person or a bad person. The *system* of ICE now requires them to hit a deportation quota, so they are all targeting civilians.
There are dangerous undocumented immigrants. Very dangerous. Consider the 100 most dangerous undocumented immigrants in a population of 12 million undocumented people. People like "Big Dragon."
But you cannot find them.
Suppose the ICE Dangerous Fugitive Apprehension Team is looking for Big Dragon
tiktok.com/@adrianembrey/video…
Suppose the hypothetical Big Dragon threatened to shoot an undocumented taco cart vendor on Wilshire Blvd in LA, in front of over 100 people, 80 of whom were undocumented.
Then the ICE team shows up, looking for people to "come down to DHS and make a statement."
No one is talking. No one is going🙅🏽♀️
This is beyond "Stop snitching," and a cultural revulsion to cooperating with police.
This is beyond "Snitches get stitches," and fear of reprisal from the hypothetical Big Dragon or his associates.
This is a rational understanding that giving a statement holds a real risk of detention to CECOT.
Would the other taco vendors have been more likely to call Immigra on the hypothetical Big Dragon:
* In the 1990s, before the creation of ICE?
* In the 2000s, after ICE was created, but before this round of mass deportations?
* Now, in the full fascism and mass deportation era?
If ICE does an NYPD style "work stoppage" and doesn't deport a single person for a period of 6 months...
Do you think that would increase or decrease the likelihood that an undocumented person would be willing to help ICE find and arrest the hypothetical Big Dragon?
Consider a kind, undocumented taco stand vendor in LA. In 20 years he has never even thought of carrying a gun before. He had always assumed that if he ran into trouble, he would just call 911.
Now he realises that he can't call 911. ICE.
And he just saw hypothetical Big Dragon threaten a man...
2/3
After advancing their Medicaid-slashing, billionaire-enriching megabill late last night, Senate Republicans are aiming for a final vote within the next 24 hours.
Tell your GOP senator to vote NO on Trump’s Tax Scam: indivisible.org/resource/call-…
Or send an email: act.indivisible.org/sign/no-cu…
Republicans in Congress are trying to ram through the Trump Tax Scam, a bill that makes extreme cuts to Medicaid, SNAP, and other essential programs to pay for tax breaks for the ultra-wealthy.Indivisible Guide
Get fresh meal delivery with HelloFresh & our weekly meal plans! Meat & Veggies ✅ Veggies ✅ Pescatarian ✅ Quick & Easy ✅ Fit & Wholesome ✅ Family Friendly ✅www.hellofresh.com
Visiting Aarhus and up for an art walk?
Here is a uMap showing the murals from the 17 Walls project – plus many other mural locations in the city (that are mapped in OpenStreetMap). A great way to explore Denmark’s second-largest city through public art.
👉 umap.openstreetmap.fr/da/map/1…
📍 Data from #OpenStreetMap
#OSM #aarhus #streetArt #umap #17Walls
Map of the 17 murals in Aarhus from the **17 Walls** project. Each mural is an interpretation of one of the 17 UN Sustainable Development Goals. [[https://www.17walls.uMap
🥵'Fait vraiment chaud, hein ! 🥵
Vite ! L'appli carto #CoMaps à la rescousse ! Elle indique points d'eau💧, bibliothèques📖❄️ et parcs🌳 !
Appli sans pub, sans traçage, fluide et jolie ! Bonus : fonctionne hors-ligne🫨 : téléchargez les cartes chez vous sur votre ordiphone et hop, vous avez accès aux cartes sans internet à l'extérieur !
N'hésitez pas à donner au projet♥️, l'appli est en accès gratuit et repose à 100% sur les dons : comaps.app/donate/
On this map, publicly accessible drinking water spots are shown and can be easily addedmapcomplete.org
Lord egeltje 🦔 🇪🇺
in reply to daniel:// stenberg:// • • •Howard Chu @ Symas
in reply to daniel:// stenberg:// • • •uh huh. I'm not spending the time to build those checkboxes and mapping tables for 3+ different TLS libraries. It's the admin's job to know their security requirements and how their chosen software meets those requirements. If they don't know them, they can keep the defaults.
In OpenLDAP we don't dictate which crypto library you use. We certainly aren't going to tell you which cipher suites to use, that's up to you.
daniel:// stenberg://
in reply to Howard Chu @ Symas • • •Kevin Lyda
in reply to daniel:// stenberg:// • • •@hyc I'm just amused to imagine an nginx configuration UI.
"And here in tab 7 of tab 38 of tab 10, scroll down and click these boxes. Now make the same settings in (long list). See, much easier than strings!"
Next up, a terraform UI!
mort
in reply to daniel:// stenberg:// • • •I wish I never had to think about cipher suites and could just rely on OpenSSL's defaults, but when an OpenSSL update happens and I can no longer connect to WiFi networks I need to connect to (but have no control over), I need to go around copy/pasting strings I find on StackOverlow into config files T_T
I wish security people didn't go around breaking people's systems all the time
Tom Bortels
in reply to daniel:// stenberg:// • • •Counterpoint:
Nobody is typing those strings in. They cut and paste, and the most often done modification is "remove this particular bit".
A string in a config is far superior to some sort of GUI for this, as some people will simply check or uncheck all the boxes. 99% of the time I've modified the cyphersuite I've been in a ssh session - please, no GUI.
The best alternative is a frequent patch cadence by the software provider, and maybe some ugly error messages ("you are using known-bad cipher XYZ - pausing 300 seconds" on startup) or even an abort if someone is trying to use known-bad ciphers. If people don't patch promptly, that's on them, the world needs people to serve as examples of what not to do...
The real issue here is obsolete blog posts and overly-trusting "admins" who treat the cyphersuite as voodoo - and checkboxes won't fix them.
Clemens
in reply to daniel:// stenberg:// • • •This is just crypto-policies (but others have already commented that).
It also claims Curve25519 is FIPS-approved, though, which it isn't. Ed25519 (the signature scheme) is, key exchange over curve25519 is not.