Show newer

I admit it. I hate Britain. I hate America too. I hate every country. I hate the arbitrary geopolitical borders that violently carve up our planet into the worthy and unworthy. I hate the way they’re secured. I hate the way our cultures have been infested with nationalism.

I hate the way people can be forced to move from one arbitrarily defined piece of land to another because they don’t have the correct piece of paper.

meta 

@smileodonicthys@jorts.horse @Shrigglepuss @KarenWyld That doesn't explain the shitposting of the instance more broadly. Why are *jorts users in general* putting the burden here on marginalized folks doing community safety work, and not on bad actors?

For a (critical) meta-review of dependency security, I'm looking for documented dependency security incidents!

Please reply with (a link to) any such incidents that you know of, in any language/ecosystem as long as it was from a public registry/source - I'm especially interested in the less well-known incidents.

The goal is not to write a sensationalist fearmongering article, but rather to place real-world attacks in perspective and talk about where the *real* dangers are, because almost everything people claim about dependency security today is wrong.

Boosts appreciated! :boost_requested:

Added some new Mastodon monitoring infrastructure for discuss.systems.

Sure, every good #MastoAdmin has a cool Grafana dashboard, but we're going a bit more old school here...

Ageing doesn't cause conservatism 

(begin quote)

"Let's get something straight. Growing old doesn't make people #conservative. In fact the more marginalized identity statuses a person has, the LESS conservative they grow over time.
The reason we equate "old" with "conservative" is that #marginalization kills people off younger.

Some of the most radical people you know are old.

It's just a lot of others died before they could get there, so there's a diminishing proportion. (2/5)

Show thread

re: rant, package management religion 

For those less familiar with dependency security: what happened here was that PyTorch depended on a package from *their own* package registry, and someone could inject malware by publishing a package of the same name on PyPI, which automatically got preferred by pip *even though it wasn't the correct repository*.

The problem here is that pip disregards origin repository, and instead has its own priority rules that always override private repositories. This means that literally *any* private repository entry could have been overridden, whether you have 1 or 100 entries.

Show thread

@KFuentesGeorge It's not just a preference. Text allows me to process information at my own speed. And text is usually way more accessible for someone who is visually impaired, because (almost) all information is available in plain text, which can be processed to suit one's needs (e.g. increase fonts, change colors, use a screen reader, etc.).

rant, package management religion 

Ah yes, I see that all the religious "use less dependencies" takes have arrived in response to the PyPI/PyTorch incident, with apparently none of these people realizing that that literally wouldn't have made a difference here, and that the actual security issue is in pip itself.

Reminder to my neurospicy folks: you are great. Every time I take an ADHD inventory it makes me sad, because it talks about the ways that this type of neurodivergence inconveniences *other people.* Heck em, your purpose is not to be convenient. You are valid and inherently valuable regardless of how psychiatry treats you and regardless of how the workplace etc treats you.

re: meta 

@Kye@tech.lgbt And the worst part is that that is not even the worst part

re: meta 

@zkat (Generally speaking whenever there's some bullshit going on with a defederated instance, the easiest way to find receipts is the FediBlock hashtag, deliberately leaving out the # here)

meta 

@zkat This is about equel.social, some of the original context is equel.social/@alasaarela/10955, but there's more insidious shit at equelsocial.com/story (and hellsite.site/@sys64738/109632 summarizes the problem very well)

@zkat @doot@glitterkitten.co.uk Nah, these folks are definitely worse than Hachyderm

meta, gripe, politics 

I am once again asking Americans to remember to tag your political commentary (shitpost or otherwise) with #USpol.

I really miss when people CW'ed their political posts. I used to appreciate seeing that so much, it's a big part of what made Mastodon so much easier to scroll than the other site.

@vultureculture Fully automated luxury space defederation of techbros! Excellent!

man, this is making me lament the sheer amount of access to other parts of humanity that I lack by being limited to the small subset of languages I know.

I really need to add Arabic to the pile at some point, at _least_, for example. Maybe Hindi (or Punjabi, which I think again is more relevant in my area).

I also don't want to focus so much on "big umbrella" languages, because there's so many other languages that are massively important to smaller communities, many of which have been historically (or even are still actively being) suppressed. I wish there were more learning resources for these. I'd love to learn Amerindian languages, if only "major" ones like Maya.

Show thread

Imagine you are a Game Designer...

and your boss wants you to design something against your moral, ideologic or personal standpoint and wont argue...

Do you...

#GameDesign #GameDevelopment #GameDeveloper @darkpatterns #GameDev #IndieGameDev #IndieDev

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.