Show newer

@eloy I don't think that captures it fully either - there were also a lot of known mitigations against known threats that simply weren't implemented for business-related reasons, even though they *could* have been (capability security would be one example).

alt-right rhetoric, youtube 

"So rather than being a soy JS dev pretending to know stuff about security..."

Well, at least it's helpful when video creators on YouTube signal how shitty they are within the first minute or so. Saved me a watch, I guess.

Quote of the day (from the Fedora devel list):

We have no mechanism to flag when J. Random Packager adds "Supplements: glibc" to their random leaf node package. As a reminder, *we are a project that allows 1,601 minimally-vetted people to deliver arbitrary code executed as root on hundreds of thousands of systems*, and this mechanism allows any one of those people to cause the package they have complete control over to be automatically pulled in as a dependency on virtually every single one of those systems.

Adam Williamson

april fools has just become a day where every company does an elaborate joke about making a change nobody wants, as if they don't do that unironically the other 364 days of the year

just a PSA to anyone going to watch the eclipse, The American Astronomical Society says under no circumstances should you buy glasses from Amazon aas.org/press/american-astrono

Every time I say generative AI is bad at everything, software engineers crawl out of the woodwork to "well actually" me about how great it is for writing code.

So, about that ...

theregister.com/2024/03/28/ai_

*evaluates Omnivore as a read-later tool*

"We're planning to add AI integration in the future as a paid option"

"Self-hosting currently requires the use of Google Cloud, we are working on making it more portable"

*closes tab*

This is your annual reminder that many autistic people consider groups seeking to prevent or cure autism to be eugenicist hate groups and would strongly prefer that any donations you make go to groups that seek to improve the lives of autistic people instead

@thelastpsion Ah right, that makes sense - possibly inspired by the xz maintainer getting hounded for updates on the mailing list?

Personally I decided some time ago that I don't think licenses are the right tool for this sort of thing, deciding to use an effectively public domain license so as to minimally interfere with legitimate uses; and instead just making corporations and other demanding folks unwelcome on a social and sometimes technical level.

The premise here being that you don't realistically have any recourse if a corporation decides to ignore your licensing constraints (because lawyers cost money) but something becomes uninteresting to people and especially companies very quickly if they are told that they are unwelcome and all their bug reports are unceremoniously closed.

@jacksonchen666 Turns out someone did think of the domain name: the registry scalpers :(

@julialuna@chaos.social welcome to the club / my condolences / congratulations! (strike those which do not apply)

@navi Last I did this (years ago) there was a 'custom ISO' option somewhere in their VNC thingem

@thelastpsion (Out of interest, was there a specific incident that led you to reconsider licensing? Wondering if I missed something)

Very few people add content warnings to their politics posts now (or any kind of post, while I'm grumbling). Super disappointed.
Should I start flooding the timeline with UK politics hot takes that make 0 sense to anyone outside of the UK all day? Apparently that's a reasonable and enjoyable thing to do

Hey so I decided to make a website documenting a bunch of the common fedi content warnings! It’s definitely not perfect but it’s very open to contribution, and I’ve seen a good handful of posts listing content warnings for newcomers so hopefully this can be a helpful single resource!

Update! Namecheap acknowledged that I’m real so I have the actual domain now!:

https://fedicw.info/

Since originally posting, It now looks much better on mobile, it has a light theme, I’ve added a handful of entries, and I’ve fixed a few typos

Also boosts would be very much appreciated on this one

One of the answers to the question, "Why are there so few Black people on the fediverse?" And no, it's not just that there are racist users. 

Every once in awhile, I see a white person ask the question of why there aren't more Black folks on the fediverse. I don't see this that often, as I go out of my way to follow white folks who are a little more clued in, but occasionally it comes up.

There are a lot of reasons, which any Black person who has been here for more than 5 minutes could easily explain to you, but for the moment let me take you on a short journey to examine one of the primary reasons.

Imagine, if you will, that I am a random Black person interested in joining the fediverse. Now assuming I don't just go straight for mastodon.social (different scenario, but similar outcome for the most part) I'm curious to see what server I should join.

If I'm coming from any other major social network I've probably heard something, accurate or not, about the fediverse and choosing a server. Maybe that idea has turned me off before, but the Muskrat or Zuck or whoever has just done another egregious thing and I'm getting fed up with their shit. I'm stubborn, too, so I look into an option that's going to take some work.

So I do some poking around Mastodon since that's the service I've heard about. joinmastodon.org has an easy to peruse list of hundreds of servers (419 last I checked). This seems overwhelming, but they are sorted by language and region and topic, which helps.

Now keep in mind, I'm coming from another social network, so very likely I've heard how white the fediverse is. So, I start browsing through the servers on joinmastodon.org to find other Black folks because if I'm gonna try this new thing, I'm not looking to deal with users who may just be hostile by default for no good reason.

If I am especially thorough, I will find two servers for South Africans, a server for folks from Madagascar, and/or a server for Nigerians. If I am not from one of those three countries, guess what happens? I don't find anyone like me. I leave and I don't come back again.

Okay, story over. And here comes the moral of the tale: It's not that non-regional Black-centered servers don't exist. They're simply not included in the directory. And for the record, it's not as if none of us have asked.

Therefore, the next time you see someone asking the question of why there aren't more Black folks on the fedi, you can now feel free to tell them: we aren't wanted here.

Go look for yourself if you don't believe me.

:boost_requested:

#BlackMastodon #BlackFedi #BlackFediverse #WhiteSupremacy

Reminder today, a joke isn’t funny unless both people feel it is harmless and funny. If only one person finds it funny, congratulations. It’s no longer a fun joke, it's rude and upsetting. Keep this in mind and do your best to keep things harmless, because others may not find things as funny as you do

Jewish mourning customs 

I was at the pub with friends today and mentioned that I was not buying clothes for a year because I'm in mourning for my dad.

(See Chabad's explainer on this: chabad.org/library/article_cdo )

They were shocked. What if my underwear all suddenly met with disaster? Would I just go without (under)pants?

I'm reform, so I could just buy new pants, but what I would probably do is get somebody else to buy pants and "borrow" them.

What then, they wanted to know if the point? Why do this at all?

To which I say: it's custom and it's how I'm mourning and if it doesn't sound like Christianity, then baruch Hashem because Christianity fucking sucks at death, grief and mourning.

But also, yes, there's a loophole. But it's not a mindless get out clause. If I take a loophole, I need to have a conversation with somebody I care about that's going to involve acknowledgement of grief.

The technicalities can be dealt with, but this requires some amount of thought. Of being aware. Of being mindful. Of acknowledging that although it's been several months, this loss is still new.

Of having a year where I don't have to pretend things are normal and everything is fine. Of being in some ways stuck in a moment of catastrophe, several months ago. This weird singularity in my life, at the end of his.

the lesson *I'm* choosing to take from xz, as an oss maintainer, is that anyone trying to pressure or guilt me into doing something should immediately be told no, for security reasons

I would like to thank Jia Tan for authoring the best CTF challenge of the past decade.

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.