Show newer

@schratze big bird window sticker when (split over 3 appartement windows on separate floors)

Haha, maybe having open registration without effective moderation isn’t the best idea.

Just putting it out there. Again.

@michael "You may wish to consider implementing hCAPTCHA yourself to protect your own instance,"
Please note that if you do this, it will prevent many blind people from signing up onto your instance. hCAPTCHA does not have an audio version; instead, if you cannot complete the visual version for whatever reason, you have to give them your email (!), so they can send you a link to a site for setting an accessibility cookie.
This cookie frequently does not work at all. It has a time limit before you can set it again, so if it fails to set, or if you close the browser and have automatic deletion of cookies enabled, as you should, you'll just have to wait. And of course, it only works within browsers, not applications; Discord is an excelent example of a non-passable captcha.
Enabling application signups is a much more accessible way of avoiding spam. If this is something the admin team cannot handle, it is time for going invite-only.

gore, Allegra/Corporate Memphis art style, fine art parody 

Oops, boost with CW because there's gore (but, given the art style…) @epilys chaos.social/@epilys/110383660

@vyr something something people prefer electric shocks over boredom anyways

thinking about the ancient Roman Tikkus Tokkus, and how everyone kept mindlessly swiping him

Easy to fix though, and would only be exploitable by a malicious Matrix homeserver affecting their own media, so no point. I was keying thumbnailed cache entries as $mxc-$crop-$widthx$height, but those are all characters that could be added to a (malicious) media id on the same homeserver

Show thread

lol lmao just realized there's a glaring cache poisoning vulnerability in my refactored code

@42GB most Matrix servers will set the max media size much lower, default is 50M iirc. For that kinda filesize you definitely want a dedicated application that takes expiry into account. webwormhole.io/ and magic wormhole are quite cool but need you to be online at the same time

very sudden urge to work on my fediverse client again even though I have so many more pressing things to work on

re: website boy 

@ConnyDuck@chaos.social @charlag also isn't devrel just PR but for techbro's

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.