Show newer

mutual aid, please help if you can 

A pair of really sweet and wonderful disabled trans women are struggling terribly affording meds, food, etc and could use any financial support you could give. Really, anything would help

It would mean a lot to me. I love these two and they've never ever had the chance to get the life they deserve

ko-fi.com/diddgery

#mutualaid #mutual_aid #transmutualaid

I'm including some art Diddgery made because it's good

I just made a trailer for Quadratic Attack 1D, my April Fools' Day game!

Have a watch! (Unless you don't want to be spoiled on it at all I guess?)

youtube.com/watch?v=Dg2V5x7AXv

#aprilfools #gamedev #indiedev #indiegame

My favorite Ren Faire story:

I knew a guy who kept a Starfleet insignia pinned to the inside of his garb. A few times per season, some folks would come to the Faire cosplaying as a Star Trek landing party, investigating a “primitive” world.

He would take them aside, show his insignia, and identify himself as a Starfleet officer on a cultural research mission. He’d call them out for breaking the Prime Directive and ruining his research. Then he’d demand to know what ship they’re from, and threaten to get them court martialed if they didn’t change into something less conspicuous.

Let's talk about Natives on this Trans Day of Visibility, like Kauxuma Nupika (c.1780-1837), an Indigenous AFAB Kutenai who divorced his Canadian husband and then declared himself male. As a trans Native, Nupika became both a warrior and prophet, predicting the arrivals of Europeans to Kutenai lands and trying to forge peace between nations like the Salish and the Blackfeet

#indigenous #transdayofvisibility #trans #history

For this year's trans day of visibility, I am a very achey blanket lump because I spent most of the day cleaning after my easter dinner plans fell through due to family illness

the lesson *I'm* choosing to take from xz, as an oss maintainer, is that anyone trying to pressure or guilt me into doing something should immediately be told no, for security reasons

After a two month delay, the new chapter of my Iji/Undertale/Deltarune crossover fic "Null Driver" is up!

archiveofourown.org/works/5189

linux pro tip you can turn any rolling release into a LTS by never updating

found on a backup of my debian sid install from before I switched to fedora. it's definitely out there

Nasa are currently working to fix a computer error aboard Voyager 1. The probe's computer system runs at around 8000 instructions per second and has about 68kB of memory. Due to the interplanetary distances involved, even at light speed it takes 45 hours to send a signal and get a response. When asked about the unique challenges this poses, an engineer said "that's actually about average for a modern CI system".

@nilaypatel -- editor-in-chief of @theverge -- thinks there aren't girls on the fediverse 😂

boost this if you're a girl on the fediverse to scare him lmao

Show thread

I think at a baseline, we shouldn't be building critical official packages for distribution from release tarballs. A huge part of this was the tarball didn't match the repo and since we're talking a compression library, compressed archives shipped for "testing" concealed the payload.

Official builds should pull source and build/test scripts generate testing data in an auditable way rather than just trusting a tarball containing blobs.

Show thread

Anyway the entire ops/dev world just dodged (we think/hope we dodged, anyway but are not 100% sure) the biggest supply chain attack in history that would have screwed absolutely, literally, everyone.

This needs a giant f**king industry-wide post-mortem once we're sure we're not all doomed.

"Isn't that a bit alarmist?" No!

xz is a base-system package in literally every distro I know of. It's everywhere.

Compromised releases have been out for five weeks and we didn't notice. We only noticed because someone caught openssh taking 10x as long to do DH exchanges and auth. If the attacker had been sneakier we wouldn't have noticed at all.

The compromised xz was in Fedora's testing versions and they didn't notice. You had the compromised version in Arch for a month (and arguably still do, but a combination of build method and source acquisition method likely renders it safe).

If some random guy didn't go "Why is openssh so slow?" and dig really deep into that, it would have hit stable/live distros and then what? We don't know.

Show thread

Red Hat released an urgent security alert for Fedora 41 and Rawhide users:

> PLEASE IMMEDIATELY STOP USAGE OF ANY FEDORA 41 OR FEDORA RAWHIDE INSTANCES for work or personal activity.

redhat.com/en/blog/urgent-secu

> Although Fedora 40 beta contained the 5.6 version of xz in an update, the build environment prevents the injection from correctly occurring, and has not been shown to be compromised. Fedora 40 has now reverted to the 5.4.x versions of xz.

#RedHat #Fedora #FedoraRawhide #Fedora41

Show thread

you can fascinate a robot girl by showing her the room in your home with the checkered floor where you keep your reflective spheres

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.