@CatMaidLeugim@chaos.social Maybe an off-the-wall suggestion, but have you considered looking at a repair cafe? Policies vary widely in different places but AFAIK usually they're open to fixing anything as long as you're willing to be there and learn how to do it (with the guidance from someone more experienced), and they can help you find the parts affordably if any are needed.
I know that there are also some repair cafes where they can do the whole thing for you, but you can usually only find out that sort of thing by asking there in person...
Rijkswaterstaat houdt vast aan de plannen ondanks eerdere protesten. Daarom bezetten we de boerderij als laatste redmiddel en roepen iedereen op ons te steunen. Morgen hebben we extra hulp nodig in de strijd voor de Limburgse natuur. Meer info: https://stopa2verbreding.nl [4/4]
@hazelnot @schratze @gsuberland@chaos.social I mentioned this in more detail in https://social.pixie.town/@joepie91/113425246088814246 but the way I can make todo lists work for me is to reframe their purpose as one of "relieving me from chores" rather than "assigning me chores"
@hazelnot @schratze @gsuberland@chaos.social In the neurotypical way, yes, they absolutely do, they (among other things) create a loop of self-punishment for "not having done enough" which negatively affects executive function further, and can create an overwhelming sense of a never-ending list of stuff to do such that you can't even start on a single thing, to just name a couple of the ways in which (monolithic) todo lists (as often suggested) can make things worse for ADHD
details
@schratze @gsuberland@chaos.social I use day-specific todo lists as a way to have a hard cut-off; once I have completed tasks for the day, I am Done(tm) with chores, even if there's nominally more stuff to do. If I don't get all of them done, they simply get rescheduled onto another day. Prevents me from overexerting my spoons trying to do everything I am "supposed" to do in a single day...
@schratze @gsuberland@chaos.social I mean, todo lists *can* work to some degree.. just not in any way remotely resembling the way neurotypical people suggest using them...
Does anyone currently living in Germany follow me?
I'm in the UK, and I want to send my friend in Germany some backed goods as a present - what's the cheapest and most hassle free way to do so?
Something like a basket of muffins or a small fruit basket is what I'm after.
Thanks
On one hand I think it's naïve to expect that all medicine and disability care can be as straightforward as diy hrt but also I think there's definitely something to be sought out there with the kind of independence it affords us
uspol and election meta
Serious question: do you *need* to follow the elections in the US?
Don't get me wrong, you should do your part and do what you can to prevent a disastrous outcome. But you also need to recognize where "what you can do" ends, and where the doomscrolling loop begins.
We all know how bad things could end up being after this election, we're all aware. Reading up more on analyses and predictions is unlikely to improve our understanding, and even less likely to result in a concrete action that we can take against it - at least, one we didn't already think of.
Maybe it's better to just... detach from it, if you are not actively working on it already, let the chips fall where they may, and instead put your energy into building a sustainable society going forward, with or without the systems currently in place.
There are a lot more productive things you can do with your time and energy, than worrying more about something you already know is bad. And for a lot of those possibilities, it just doesn't really matter what the outcome of this election is.
✏️ Mark your calendars! In just two weeks, I’ll be offering a free Krita workshop (in French) at Capitole du Libre 2024. This session will be a perfect blend of exploring Krita’s features and sharing valuable drawing tips. I can’t wait to see you there and create together! 🎨
More info: https://cfp.capitoledulibre.org/cdl-2024/talk/KLHKLR/
password hashing advice, re: okta vulnerability, grumbling about security
@AFriendlyBeagle Sort of. In and of itself, bcrypt is fine, in that it does what it says on the tin - but it has an input limit (72 bytes if memory serves) that is not widely known, and easily missed. Usually that's only a problem if you have a very long password (since it's essentially quietly truncated to 72 bytes), but if you're using it for a cache key like Okta was... 😐
My go-to recommendation for new systems nowadays is either argon2id, argon2i, or scrypt (in order of preference, depending on what your environment supports). They're more resistant to GPU cracking than bcrypt is. But as long as you aren't prone to the truncation issue (ie. you either restrict the input length or you just don't have such long inputs) there's no need to change what's already using bcrypt, the crypto itself is still considered sound.
Really the only things that warrant immediate change are anything using MD5, SHA1, and (due to the risk of incorrect implementation) anything homegrown using SHA256/SHA512. Third-party implementations of eg. PKBDF based on SHA256/SHA512 should be treated with scrutiny.
CW-boost: election manipulation
okta vulnerability, grumbling about security (2)
I will give Okta a tiny bit of credit for having used a cryptographic hash for their cache, which is something that many people get wrong. But that doesn't really help you if you then use the *wrong* cryptographic hash...
re: okta vulnerability, grumbling about security
@riley I mean, this is true for basically every auth company I've seen, they're all snake oil, just some hide it better than others. But that hasn't stopped them from building an 'experts' reputation in the tech world.
re: okta vulnerability, grumbling about security
@Scmbradley Probably nothing illustrates this better than Stormpath, a now-acquired "security and authentication company" that published an article about JWTs, half of which was outright factually incorrect and would never pass even cursory review by a security expert.
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.