Show newer

Researching mines in northern Spain I came across this curious object. It's a canary cage designed to keep the canary alive in the event of a gas leak. If a miner saw the canary laying at the bottom of the cage it was time to abandon everything and leave the mine, but not without first closing the latched glass door and opening the valve of the oxygen bottle to save the bird. A miner would do that on their way out and take the bird with them. It's a signifier of the miner's legendary sense of solidarity, no lives lost to the mine on a miners watch. A solidarity that was also crucial in the fight for workers rights, creating safer and more humane working conditions, achievements of unionization and solidarity that some of us still enjoy today.

Heads-up if you're using CircleCI: it got popped, and your stored credentials are compromised.
circleci.com/blog/january-4-20

Hi my jorts.horse friends. Your admin is being a complete and absolute shithead about other people on jorts abusing the fediblock hashtag. Please consider moving to another instance, as the admin and other people have a continued stance of not giving a shit about an actually useful and helpful aspect of Mastodon. Thanks.

Let's be very clear.

What jorts[dot]horse is doing is straight-up white supremacy. They are attacking a tool, specifically, created to help make the fedi safer for Black and POC users because they
feel it's bad and is laughing about it. That's unvarnished anti-blackness, and they are proud of it.

At this point, nothing separates them from any other racist instance like kiwi farms or gab.

They are actively working to make the fedi a less safe place and enjoying that effort.

#fediblock

@DanaBlankenhorn @rosalux @HandgunYoga @aral

Achieving a higher seat at the table of a deliberately unjust system, is not progress, it is a bribe.

Do other Mastodon admins see weird behaviour regarding instance suspensions?

Take "example.org", and subdomains "social" and "social2".

If you first block the root domain and then the subdomain, the block for the root domain disappears here. Is that the case for you too?

#MastoAdmin

I admit it. I hate Britain. I hate America too. I hate every country. I hate the arbitrary geopolitical borders that violently carve up our planet into the worthy and unworthy. I hate the way they’re secured. I hate the way our cultures have been infested with nationalism.

I hate the way people can be forced to move from one arbitrarily defined piece of land to another because they don’t have the correct piece of paper.

For a (critical) meta-review of dependency security, I'm looking for documented dependency security incidents!

Please reply with (a link to) any such incidents that you know of, in any language/ecosystem as long as it was from a public registry/source - I'm especially interested in the less well-known incidents.

The goal is not to write a sensationalist fearmongering article, but rather to place real-world attacks in perspective and talk about where the *real* dangers are, because almost everything people claim about dependency security today is wrong.

Boosts appreciated! :boost_requested:

Added some new Mastodon monitoring infrastructure for discuss.systems.

Sure, every good #MastoAdmin has a cool Grafana dashboard, but we're going a bit more old school here...

Ageing doesn't cause conservatism 

(begin quote)

"Let's get something straight. Growing old doesn't make people #conservative. In fact the more marginalized identity statuses a person has, the LESS conservative they grow over time.
The reason we equate "old" with "conservative" is that #marginalization kills people off younger.

Some of the most radical people you know are old.

It's just a lot of others died before they could get there, so there's a diminishing proportion. (2/5)

Show thread

re: rant, package management religion 

For those less familiar with dependency security: what happened here was that PyTorch depended on a package from *their own* package registry, and someone could inject malware by publishing a package of the same name on PyPI, which automatically got preferred by pip *even though it wasn't the correct repository*.

The problem here is that pip disregards origin repository, and instead has its own priority rules that always override private repositories. This means that literally *any* private repository entry could have been overridden, whether you have 1 or 100 entries.

Show thread

@KFuentesGeorge It's not just a preference. Text allows me to process information at my own speed. And text is usually way more accessible for someone who is visually impaired, because (almost) all information is available in plain text, which can be processed to suit one's needs (e.g. increase fonts, change colors, use a screen reader, etc.).

rant, package management religion 

Ah yes, I see that all the religious "use less dependencies" takes have arrived in response to the PyPI/PyTorch incident, with apparently none of these people realizing that that literally wouldn't have made a difference here, and that the actual security issue is in pip itself.

Reminder to my neurospicy folks: you are great. Every time I take an ADHD inventory it makes me sad, because it talks about the ways that this type of neurodivergence inconveniences *other people.* Heck em, your purpose is not to be convenient. You are valid and inherently valuable regardless of how psychiatry treats you and regardless of how the workplace etc treats you.

meta, gripe, politics 

I am once again asking Americans to remember to tag your political commentary (shitpost or otherwise) with #USpol.

I really miss when people CW'ed their political posts. I used to appreciate seeing that so much, it's a big part of what made Mastodon so much easier to scroll than the other site.

man, this is making me lament the sheer amount of access to other parts of humanity that I lack by being limited to the small subset of languages I know.

I really need to add Arabic to the pile at some point, at _least_, for example. Maybe Hindi (or Punjabi, which I think again is more relevant in my area).

I also don't want to focus so much on "big umbrella" languages, because there's so many other languages that are massively important to smaller communities, many of which have been historically (or even are still actively being) suppressed. I wish there were more learning resources for these. I'd love to learn Amerindian languages, if only "major" ones like Maya.

Show thread

Imagine you are a Game Designer...

and your boss wants you to design something against your moral, ideologic or personal standpoint and wont argue...

Do you...

#GameDesign #GameDevelopment #GameDeveloper @darkpatterns #GameDev #IndieGameDev #IndieDev

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.