re: rant, package management religion
For those less familiar with dependency security: what happened here was that PyTorch depended on a package from *their own* package registry, and someone could inject malware by publishing a package of the same name on PyPI, which automatically got preferred by pip *even though it wasn't the correct repository*.
The problem here is that pip disregards origin repository, and instead has its own priority rules that always override private repositories. This means that literally *any* private repository entry could have been overridden, whether you have 1 or 100 entries.
@KFuentesGeorge It's not just a preference. Text allows me to process information at my own speed. And text is usually way more accessible for someone who is visually impaired, because (almost) all information is available in plain text, which can be processed to suit one's needs (e.g. increase fonts, change colors, use a screen reader, etc.).
rant, package management religion
Ah yes, I see that all the religious "use less dependencies" takes have arrived in response to the PyPI/PyTorch incident, with apparently none of these people realizing that that literally wouldn't have made a difference here, and that the actual security issue is in pip itself.
Reminder to my neurospicy folks: you are great. Every time I take an ADHD inventory it makes me sad, because it talks about the ways that this type of neurodivergence inconveniences *other people.* Heck em, your purpose is not to be convenient. You are valid and inherently valuable regardless of how psychiatry treats you and regardless of how the workplace etc treats you.
Logan Paul threatens to sue CoffeeZilla for exposing his (alleged) grift
January 4, 2023
https://web3isgoinggreat.com/?id=logan-paul-threatens-to-sue-coffeezilla-for-exposing-his-alleged-grift
meta, gripe, politics
I am once again asking Americans to remember to tag your political commentary (shitpost or otherwise) with #USpol.
man, this is making me lament the sheer amount of access to other parts of humanity that I lack by being limited to the small subset of languages I know.
I really need to add Arabic to the pile at some point, at _least_, for example. Maybe Hindi (or Punjabi, which I think again is more relevant in my area).
I also don't want to focus so much on "big umbrella" languages, because there's so many other languages that are massively important to smaller communities, many of which have been historically (or even are still actively being) suppressed. I wish there were more learning resources for these. I'd love to learn Amerindian languages, if only "major" ones like Maya.
Imagine you are a Game Designer...
and your boss wants you to design something against your moral, ideologic or personal standpoint and wont argue...
Do you...
#GameDesign #GameDevelopment #GameDeveloper @darkpatterns #GameDev #IndieGameDev #IndieDev
#fediblock equel.social
Administrated by and on behalf of tech entrepreneurs. advocating for a VC backed takeover including metrics driven feed algorithms. All accounts on this site are tied to LinkedIn accounts.
Receipts in thread:
https://equel.social/@alasaarela/109553882021683216
it would be an absolute shame if anybody misused this portal the german police set up exclusively for snitching on the people responsible for the NYE riots in #berlin #b3112 which the right and ofc also the center are now using to dig up their favorite racist stereotypes about migrant youth...
max 2GB per file... idk if there is a limit for how many files you can upload
Hey cis friends, have you ever fantasized about being a different gender? Any context: sex or cool clothes or whatever, no shame attached.
Some trans folks I've talked to think everyone questions their gender, but the few cis folks I've asked either say no, or only a tiny handful of times.
If none of these choices make sense for you, my DMs are open. (Edit: See also the secondary poll below, which has more options.)
Trans friends, please sit this one out, but please do boost for reach.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.