Show newer

re: rant, package management religion 

For those less familiar with dependency security: what happened here was that PyTorch depended on a package from *their own* package registry, and someone could inject malware by publishing a package of the same name on PyPI, which automatically got preferred by pip *even though it wasn't the correct repository*.

The problem here is that pip disregards origin repository, and instead has its own priority rules that always override private repositories. This means that literally *any* private repository entry could have been overridden, whether you have 1 or 100 entries.

Show thread

@KFuentesGeorge It's not just a preference. Text allows me to process information at my own speed. And text is usually way more accessible for someone who is visually impaired, because (almost) all information is available in plain text, which can be processed to suit one's needs (e.g. increase fonts, change colors, use a screen reader, etc.).

rant, package management religion 

Ah yes, I see that all the religious "use less dependencies" takes have arrived in response to the PyPI/PyTorch incident, with apparently none of these people realizing that that literally wouldn't have made a difference here, and that the actual security issue is in pip itself.

Reminder to my neurospicy folks: you are great. Every time I take an ADHD inventory it makes me sad, because it talks about the ways that this type of neurodivergence inconveniences *other people.* Heck em, your purpose is not to be convenient. You are valid and inherently valuable regardless of how psychiatry treats you and regardless of how the workplace etc treats you.

meta, gripe, politics 

I am once again asking Americans to remember to tag your political commentary (shitpost or otherwise) with #USpol.

I really miss when people CW'ed their political posts. I used to appreciate seeing that so much, it's a big part of what made Mastodon so much easier to scroll than the other site.

man, this is making me lament the sheer amount of access to other parts of humanity that I lack by being limited to the small subset of languages I know.

I really need to add Arabic to the pile at some point, at _least_, for example. Maybe Hindi (or Punjabi, which I think again is more relevant in my area).

I also don't want to focus so much on "big umbrella" languages, because there's so many other languages that are massively important to smaller communities, many of which have been historically (or even are still actively being) suppressed. I wish there were more learning resources for these. I'd love to learn Amerindian languages, if only "major" ones like Maya.

Show thread

Imagine you are a Game Designer...

and your boss wants you to design something against your moral, ideologic or personal standpoint and wont argue...

Do you...

#GameDesign #GameDevelopment #GameDeveloper @darkpatterns #GameDev #IndieGameDev #IndieDev

every single notification sound that a piece of software makes should be fully customizable. ideally this would be a feature provided by the OS

These Second Life scripting functions are so funny to me. Making a second version of a function with "Correct" in the name sure does give off vibes of needing to maintain backwards compatibility. And then I guess the corrected function still wasn't correct enough so there's a third one.

2037 will be the year of Amazon Linux on the Firearm

grocery store chains: we set record profits this year

retail chains: we've never made so much money

energy companies: we just posted our best quarter on record

news article: who is to blame for inflation? you peasants wanting wages, probably

#fediblock equel.social

Administrated by and on behalf of tech entrepreneurs. advocating for a VC backed takeover including metrics driven feed algorithms. All accounts on this site are tied to LinkedIn accounts.

Receipts in thread:
equel.social/@alasaarela/10955

rimworld shitpost 

mod that randomly makes pawns realize they are trans after psychic drones don't affect them as expected

it would be an absolute shame if anybody misused this portal the german police set up exclusively for snitching on the people responsible for the NYE riots in #berlin #b3112 which the right and ofc also the center are now using to dig up their favorite racist stereotypes about migrant youth...

max 2GB per file... idk if there is a limit for how many files you can upload

be.hinweisportal.de

@joepie91 @amberage @mmin I've used an analogy that seems apt: tourists coming to a small town with a rich history, and saying all it needs is freeway access, some starbucks, and a walmart and maybe people can start living here

can you all CW your posts on US electoral politics? not because they're disturbing, but because they're boring as fuck and I don't care about them at all

Hey cis friends, have you ever fantasized about being a different gender? Any context: sex or cool clothes or whatever, no shame attached.

Some trans folks I've talked to think everyone questions their gender, but the few cis folks I've asked either say no, or only a tiny handful of times.

If none of these choices make sense for you, my DMs are open. (Edit: See also the secondary poll below, which has more options.)

Trans friends, please sit this one out, but please do boost for reach.

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.