Today in slop-or-not, I give you...
curl disclosed on HackerOne: TOCTOU Race Condition in HTTP/2...
I've discovered a Time-of-Check to Time-of-Use (TOCTOU) vulnerability in how `libcurl` handles persistent HTTP/2 connections. During the initial handshake, `libcurl` correctly validates the...HackerOne
I'm joining team slop.
Also I would close the report as works as intended. Certificates are meant to be checked at the beginning of a session, not in between.
Opinion: Exclusive TalkBack Features for Google TTS Are Doing More Harm Than Good - Accessible Android
TalkBack, a part of the Android accessibility suite, is the screen reader developed by Google and comes pre-installed on most Android phones and tablets.Kareen Kiwan (Accessible Android)
Are you part of an open source project with a community of users, contributors, and/or third party developers?
I want to interview people about their projects with particular attention to how codebases, documentation, project management tooling, and community spaces are constructed.
On these "project tours" we'll go through your project together, on video call, and talk about how the structure of the project influences, and is influenced by, your goals, culture, logistical constraints, etc.
Using images with alt text to represent code is not terribly helpful.
• A typical user would need to know about the alt text to copy it.
• A low-vis user cannot scale it, and it won’t honor their text preferences.
• A blind user has to parse a wall of text they cannot pause.
Just paste code. Maybe a URL to longer code.
Timery for Toggl
Enhance your Toggl time-tracking experience with Timery! Start your most-used timers with one click. Edit your time entries easily. See reports of your time tracked.App Store
Many moons ago, a friend ran an SSH honeypot that had a unique feature: when the attacker gained "access" to the system, he could then send responses to the interactive commands the attackers executed over an IRC channel.
One day, some attacker popped in, and he started to taunt them live. Often, the attackers were just throwing in some copypasta and weren't actually checking the responses. This one time, the attacker realised what was going on and was quite amused, and started to chat back, sending fake commands to see if he would get obvious human responses back (Note: that this was well before generative AI). This went on for some time, and some kind of a connection was formed. The attacker would come back to chat with my friend, logging in over SSH to this honeypot.
Eventually, the attacker divulged other means to communicate with him. He told my friend he was a bored Romanian guy who ran a kind of academy for young hacking talent. They'd gain access to some box, install their SSH bruteforcer (random IPv4 addresses and fixed password lists), and rinse and repeat.
Eventually, the attackers seemed to stop and disappear. My friend contacted them and asked what had happened: maybe they had been caught by authorities?
No such luck. Apparently, they had discovered some addictive online game that was more interesting.
Threat actor group defeated by Candy Crush.
Un point de vue d'hébergeurs de services à diffuser sans retenue.
chatons.org/news/2025-09-08-st…
Good morning my freinds,
I woke up today to loud gunfire and many explosions. As usual I checked that my family is ok. I succesfully completed the chemistry exam. I'll spend most of my time today preparing for the next exams. Hopefully nothing bad happens to us today.
I'm not a number. I'm human being. I have life details. I have a story. I have a dream. I love my life even if it's too difficult.
Re my last RT:
paying someone to do something they already enjoy can actually make them enjoy it less. I am absolutely living proof of this.
I once got advice as a teenager. Someone said "don't do what you love for a living. You'll hate it later." And, while that's not 100% true, my autistic burnout doesn't agree.
And I can really see how working in digital accessibility would burn me out for wanting to fix things on a personal or family level.
The number one reason for (at least) weekly changes to my site is to update the AI crawler/siphon blockers ... it never stops : there are 97 of them right now 😤
› github.com/ai-robots-txt/ai.ro…
#BlockAI #AI #LLM #NightmareOnLLMStreet #Webmaster
GitHub - ai-robots-txt/ai.robots.txt: A list of AI agents and robots to block.
A list of AI agents and robots to block. Contribute to ai-robots-txt/ai.robots.txt development by creating an account on GitHub.GitHub
Repeat after me.
Carbon capture is a scam conceived by the oil industry.
Carney recommending 5 'nation-building projects' for approval, including LNG expansion: sources
cbc.ca/news/politics/carney-ma…
Everything to subsidise private profit, nothing to benefit the average canadian. No transit, no high-speed rail. Nothing.
All about destroying the planet so the oligrarch can make more bucks.
"carbon capture project." <- and they are getting scammed on this. The only carbon capture is by keeping that shit in the ground. In solid or liquid form.
Archooooooos! Mam to lozbity! ;)
(Podarilo se mi nejak lognout a napsat ze safari na telefenku. Jinde to zlobi. Je chyba neprekvapive u mne, nebo se v tom vrtas?)
@archos
⚡ Google is killing Android freedom by stopping you from side-loading apps. What's your reaction?
Option 1: Stop call it side-loading: Google wants to stop us from INSTALLING apps on our OWN phones.
Option 2: Awesome, now I can hate Google and Apple equally for destroying freedom.
Option 3: I don't care as I'm using a different OS anyway (please comment which one!)
More info: tuta.com/blog/android-side-loa…
Sign the petition to stop Google from limiting APK file usage: change.org/p/stop-google-from-…
- Stop call it side-loading (54%, 206 votes)
- I can hate Google and Apple (22%, 87 votes)
- I'm using a different OS (22%, 87 votes)
- I'm using a different OS (0%, 0 votes)
I'm confused. I sideload 3 apps on my Pixel phone already. There's no problem.
It never stopped me. It just wants me to clarify that I understand the danger, and I need to give permission.
Loading apps outside the store can be dangerous, and many people don't know it, unfortunately. So, it seems to point it out, but allow it.
I'm not seeing the issue.
"Open Source as Europe’s Strategic Advantage" a 46-page report by the Linux Foundation
This is the message "host gmail-smtp-in.l.google.com[74.125.71.27]
said: 550-5.7.1 [185.205.69.213 12] Gmail has detected that this
message is 550-5.7.1 likely unsolicited mail. To reduce the amount of spam
sent to Gmail, 550-5.7.1 this message has been blocked. For more
information, go to 550 5.7.1
support.google.com/mail/?p=Uns…
5b1f17b1804b1-45df817e1fdsi13055195e9.31 - gsmtp (in reply to end of DATA
command)"
Seirdy
in reply to Rayne, Raging Misandrist Arc • • •