Here's a neat analysis of a subtle OpenZFS bug by @robn.

despairlabs.com/blog/posts/202…

I love reading thoughtful analyses of bugs and the factors that produced them. Nowadays I usually arrive somewhat resigned, and expecting a "zeroth order" C bug -- something like bad pointering or failure to initialize a variable.

This is more of a "second order" C bug, and the author goes through the potential tradeoffs and rightfully points out that the answer is not "git gud." I'll put my thoughts on the bug in a reply so as not to spoil it for you.

Anyway, it's a good short read.

in reply to daniel:// stenberg://

iirc the big vulnerabilities in these protocols were implementation problems (including downgrade dance). BEAST was one not mitigated that usually requires gigabytes of data to maybe break the cipher. I get the wide deprecation. It’s been painful over the decades to loose support for older protocols. I’ll know my stance probably long after it’s been removed. PCI-DSS has been aggressive about removal of TLS<1.2 yet it persists.

via @tbortels comes this excellent piece (unsurprisingly; Martin Fowler is always good) what articulates that I've been doing for the longest time now and puts a name to it. This article pairs well with David Epstein's book "Range". martinfowler.com/articles/expe…
This entry was edited (5 months ago)

Mobility isn’t just instinct—it’s training. Knowing how to use a white cane, feel your shoreline, and rely on your ears and feet takes time and guidance.
Until you’ve been taught, it’s hard to understand what you’re missing.
Double Tap: Where blind people talk tech! dltap.com/46rVTpe
#BlindTech #DoubleTap #Mobility #Orientation #CaneSkills #DisabilitySupport

#MutualAidRequest
#MutualAid

Please boost for reach!

Last update: July 18

Hi all, my family and I could really use your help! Extended illness, no income while sick. We have nothing saved; we are still trying to catch up on bills from unemployment most of last year.

Current total funds as of 7/18: $124
(Money previously sent to us for bills went to food & unexpected vehicle maintenance.)

Urgent expenses:

* Funds for meals for the coming week. We are feeding 2 adults and 2 preteens.
* Car Payment $567.83/mo × 3 (3 months past due, repossession efforts begin on 8/8)
* Electric Bill $143.51 (Overdue 7/7, disconnect 7/21)

Less urgent, but still important:

* Water Bill $137.99 (Due 7/22)
* Phone $229.04 (Payment arrangement, due 7/31)
* Back property taxes payment $726 (overdue amount from 6/26, next bill 7/26)

paypal.me/AaronHosford

Thank you for whatever help you can provide, even if it's just a boost!

#MutualAidRequest
#MutualAid

This entry was edited (5 months ago)

If you've ever seen a minidisk, you know how reasonably small it is. The Crucial X10 8TB drive I picked up recently is not the size of a minidisk, it's actually smaller than it.
I just find that incredibly impressive. I know technology is advancing so quickly, but I'm used to the size of standard NVME drives, which are long and ram-stick-like. The internals fascinate me but not enough to crack the thing open for well, reasons...
I wonder if they stacked the nand in some interesting config inside the casing to get it so small? Is it even NVME at all? I know they come in multiple sizes, so maybe it's a few of the smaller sized chips instead. Anyway, sometimes I can still be impressed by today's tech. It's not just all stinky AI slop, you know?

Peter Vágner reshared this.

in reply to Andre Louis

@Brynify @pixelate yeah, a lot of audio folks I know like to keep the raw uncompressed audio of each channel recording on the podcast, add those together for 2-3 people and you're counting around 4-6 GB per hour easily. Just 2-3 months of that and you've probably filled up close to a terabyte, poof. Not wrong though, having that raw copy is really good for going back or if ever needing to make a part more clear in edit or (less ideally) later.

> WireGuard uses the system time as a reliable monotonic counter. If this jumps forward, a user might DoS their own keys, by making it impossible to later have a value larger, or an adversary controlling system time could store a handshake initiation for use later. If it jumps backwards, handshakes will similarly be impossible. Thus, the system time should not be under the control of a hostile adversary.

oh good i'll make sure to remind the adversaries to not touch my time source

Peter Vágner reshared this.

there's a lot to like about Tiddlywiki but not if you want to use it in a way where you aren't just using some background html file sync between devices. If you want to access it *via a website*, every time you load it you're downloading a minimum of 2MB, much larger depending on how much data you have in there and possibly even file embeds (unless you use the File upload plugin thing and have it dump the files into S3/WebDav)

This sucks big time. If you have spotty data service you won't be able to open your "notes" reliably.

This is a huge red flag for me. If I only cared about using Tiddlywiki from one device it would be a pretty amazing solution though

Peter Vágner reshared this.

Ano, jsem starej a pomalej, ale dostala se mi do kidle knížka Mlhy Ölandu z roku 2011 a musím říct, že mě fakt chytila. Dávám 9.8*

databazeknih.cz/knihy/oland-ml…

in reply to Jiří Eischmann

@sesivany neudělej stejnou chybu jako já. Já to taky odsunul kvůli hodnocení, ale když jsem se k tomu teď dostal, jsem fakt nadšený. Není to rozhodně tuctova detektivka stylu Jo Nesbo, ale chytilo mě to fest a sjel jsem to prakticky na 2 večery, přes to že je to celkem velká kniha.
Chápu že ne každému to sedne, ale za mě fakt doporučuji tomu dát šanci.

🌞 Summer School 2025 is here!
Learn for free, get certified, and win prizes!

🧠 Take any RIPE NCC Academy course before 31 August 2025 and you'll receive a FREE exam voucher for RIPE NCC Certified Professionals. Pass the exam, earn a badge, and prove your expertise.

More details and how it works here: ripe.net/summer-school-2025/

#getcertified #freelearning #networking #SummerSchool2025 #certification

in reply to Maartje

I've also noticed that the braille - that blind people need to touch - are placed right _below_ the tab, i.e; where all the water spill onto...

How is the current version _not_ wheelchair accessible, especially when compared to the previous version?

At last: you can add it to openstreetmap with mapcomplete.org/drinking_water

Apache httpd 2.4.64 has just been released, fixing 8 vulnerabilities (5 moderate, 3 low).

Two HTTP/2 related CVEs also fixed in the latest mod_h2 release v2.0.33.

#apache #httpd

httpd.apache.org/security/vuln…
github.com/icing/mod_h2/releas…

What the fuck is it with #overlay companies and their apologists commenting on my blog?

I got two today (on the same post):
adrianroselli.com/2025/01/ftc-…

They are promoting their water-carrying shill-piece over on LinkedIn.

#accessibility #a11y

in reply to Adrian Roselli, pH0

Oh yay, the overlay shill is still spouting aspirational distractions on my site while failing to outline anything useful:
adrianroselli.com/2025/01/ftc-…

And one of the humans (not just a nameless sales person) responded to my comment on LinkedIn.

Linux users can install Mozilla VPN client from Flathub. The open source app was previously only available to install on Ubuntu-based distributions via the Mozilla APT repo.

omgubuntu.co.uk/2025/07/mozill…

#Mozilla #flathub #linux

This entry was edited (5 months ago)

Announcing the official, hyperoptimized Psalm docker image, +50% faster than Psalm on normal PHP!

I've also contributed the underlying deepbind patch to upstream PHP, and it will be available for everyone to use in PHP 8.5 (or right now, if you're using the Psalm docker image)!

blog.daniil.it/2025/07/10/offi…

You can now find the latest details about the Matrix Conf 2025 on our new website 🥳

Last year, more than 200 people attended in Berlin (we were totally sold out!) and this year, we’re taking the conference to new heights in Strasbourg!

Check out the website for more information about:

🎟️ Purchasing a ticket
🎉 Grabbing the last sponsorship package
💪 Volunteering for a free ticket (and a limited edition zipper hoodie)

conference.matrix.org/

in reply to Mike Gifford, CPWA

That was not easy to find, but I think by following a link to docs, and then via the Contributing page, I ended up at what might be it: codeberg.org/gnuhealth

Still, @gnuhealth might want to consider sharing the link elsewhere as well :)

Unknown parent

mastodon - Link to source

Mike Gifford, CPWA

@miah I remember Savanna from way back. Seems they also use codeberg.org/gnuhealth

Interesting choices. Thanks.

Alarming story about UN event organizers going slide by slide through @abebab’s talk and forcing her to remove mention of companies that might be made uncomfortable by her research.

thebulletin.org/2025/07/ai-for…

Our next major release is coming in August! #LibreOffice 25.8 will have better change tracking in Writer, new functions in Calc, performance boosts and more. The first release candidate is now available for testing: qa.blog.documentfoundation.org… #foss #OpenSource #freesoftware

LibreOffice reshared this.

charles-Valentin Alkan, un compositeur Français et Juif, l'une des plus mystérieuses figures de l'époque du romantisme. Il écrivait la musique la plus compliquée à jouer mais restant quand-même mélodieuse et intéressante.
Étude op. 39 nº1, « Comme le vent », interprété par Vincenzo Maltempo.
#Mastobada
youtube.com/watch?v=X3DKAsp6r_…

Wiped the test accounts. Resubmitted the app for another review.

I actually feel pretty bad for the individuals doing the app reviews. It’s well documented that the working conditions of the people who do content moderation for Meta or "AI" training for OpenAI are truly horrific. I can’t imagine that someone working for Google is much better off.

»The system is organized so that people with no power just have to pointlessly shout at each other.«¹

¹: youtube.com/watch?v=gJW4-cOZt8…

PureOS vs. Trump Phone Android OS- Patriot Branding Does Not Mean Privacy Protection

Trump Mobile launched the T1 Phone, boasting “Made in the USA” and “privacy-first” claims, yet the Android 15 supports data harvesting apps that enable the developer to monitor, track, and data mine the OS end user for profits.

Learn more at Purism: puri.sm/posts/trump-t1-phone-a…

Comment ai-je pu oublier l'une de mes chansons favorites que je chantonne toujours ayant bu un petit verre de vin ?
« Le vent s'engouffre dans ma valise, Et sur ma route il y a des trous… »
#Mastobada
youtube.com/watch?v=aD6erash33…