long, hachyderm meta, now with less snark
So when I warned against Hachyderm and its corporate-friendly atmosphere a few months ago, several people expressed concern, and felt that I was seeing ghosts and that "just because companies are allowed doesn't make Hachyderm itself bad".
Then recently, the Hachyderm admin casually posted a thread where, aside from problematically using slavery as a debate prop, they mentioned that they intended to monetize Hachyderm and their "FOSS governance" thing, Nivenly - and that they are, paraphrased, a "reasonable capitalist".
And here's the thing: this isn't a surprise to me at all. This is *always* what happens with corporate-friendly "communities". Every single time. It always becomes a vehicle for profit, either directly or indirectly. That is what capitalism does.
When we warn against an instance that's corporation-friendly, that's not because of some weird conspiracy theories or whatever. It's because we've seen time and time again where that leads, and how it harms the most vulnerable people - and crucially, *why* that happens, even despite the (appearance of) best intentions.
Instead of waving away our warnings as being "unrealistic", or "naive", or whatever this week's pejorative for anti-capitalists is, spend a moment to think about *why* we're issuing those warnings. Where they come from, what history they are based on.
Because I promise you that they aren't arbitrary, and that learning to recognize the signs will save you from a *lot* of ruined communities, and allow your communities to flourish like they couldn't before.
Heb recent m'n spamfilters bijgewerkt en ze werken best goed. Desondanks komt er nog spam-e-mail doorheen. Van de afgelopen 5 spamberichten die ik ontving, was er 1 van 'n overduidelijke spamserver, maar 4 waren gestuurd via de grote bekende maildiensten: Google, Microsoft, Sendgrid, Mailgun...
Die zijn zo groot dat je ze niet echt kunt blokkeren. Mede daarom hadden "we" dergelijke centralisatie nooit moeten laten gebeuren.
To absolutely no one's surprise, employees are feeding sensitive business data to ChatGPT👇🏾
good evening,
you're listening to the ADHD Internal Monologue F.M. with me, DJ subconscious,
speaking all your thoughts,
non-stop,
uninterrupted,
24 hours a day,
from classics like "why did i say that?",
and goldest oldies like "am i a horrible person?"
to today's hottest hits,
"what the hell am i doing with my life?"
and "am i hungry or am i bored?"
stay tuned,
24/7,
ADHD radio.
long, research, raid shadow legends (pc) privesc 0day (lol)
going to reverse plarium play (basically a required client for raid shadow legends)
...and their service running as SYSTEM appears to just give privesc by design, kinda?
it does IPC via localhost TCP socket with lots of memecrypto involved (salted SHA512 hash, where the salt is stored in the registry crypted by AES-CBC with hardcoded key and IV, and protocol messages are also AES-CBC crypted with a different hardcoded key + IV too)
when running a file, files are allowlisted by server-side check of sha512 hash, but there's a race condition and a path traversal, so you can place an allowed file there, tell the service to run it with whatever args, wait for it to read the file and then replace it...
alternatively you can make a download and install request, using the path traversal to replace a service binary or whatever, it'll write the file out as SYSTEM after all
and yes i just dropped a 0day but on the bright side i just gave everyone a reason to uninstall raid shadow legends on pc so...
Things are pretty bleak these days. I have curated my TL pretty tightly but the bad news is still unrelenting.
This is maybe a good time to remind folks YOU are the algorithm.
Instead of amplifying outrage (and there is plenty to be mad about, I get it. Holy fuck I get it) consider prioritizing the boosting of: resources, solutions, hope, even humour, and definitely anything that celebrates folks stepping up to make things better.
Huh. So apparently those battery-powered trains that Stadler were testing in Germany last year, are destined for Merseyrail. Which is interesting, I didn't realize it'd gotten beyond the proof-of-concept stage already!
Cannabis should be legal, all convictions for possession expunged, and all opportunities for legal licensure offered to the most harmed and marginalized, first.
But until then, here's a portal to get your fed-level simple possession convictions pardoned:
https://www.justice.gov/iqextranet/EForm.aspx?__cid=Pardon_prod&__fid=5&link_id=3&can_id=9353bf9204555509ae8c9aed63a01b16
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.