I took the IRC game I wrote for the lisp game jam and submitted it to the Linux Game Jam kind of on a lark since they just happened to overlap in timing; turns out they seemed to really like it! placed 5th out of 47: https://itch.io/jam/linux-game-jam2023/rate/2091620
Because I'm not hearing a lot of chatter on the Fediverse about this here are the CVEs and their summaries for the issues fixed in today's release:
Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution.
Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a vector for cross-site scripting (XSS) payloads that can be rendered in the user's browser when a preview card for a malicious link is clicked through.
Code of the LVM module here: https://git.cryto.net/joepie91/cvm/src/branch/feature/node-rewrite/src/packages/sysquery-lvm/index.js
It feels super weird when people diss the fact that some people *like* the current state of the #Fediverse and don't necessarily care if it grows bigger or not.
Like…the very notion that growth is a *primary goal* of a social structure is in some ways problematic.
I used to be involved in a very evangelistic religion. A big part of the belief system was you need new converts all the time.
That belief often meant *existing social structures were harmed* in the name of growth.
Problematic.
RE: Evernote news on HN [firing all staff].
The story only seems to be Hacker News/Y. But just in case:
You can download & export your entire Evernote collection using evernote-backup: https://github.com/vzhd1701/evernote-backup
Can't do it in the official app anymore without a $paid$ plan.
Facebook's Threads will straight up DOX you.
https://twitter.com/mistressmatisse/status/1676763121330028544
@researchfairy Indeed!
BTW there's a precedent: this is essentially what the Dutch parliament did in 2015 through an amendment to copyright law ('amendement Taverne'). All publicly funded scientists connected to Dutch institutions are by law allowed to share and archive their papers in perpetual open access
I don't often get excited about laws or amendments but this is one of my faves
youtube when my ad blocker is on: "oooHHHH PWEEEEASE turn off your ad blocker PWETTY PWEASE 🥺🥺🥺 ooooaahhhh we simply can't pay cweatows without ads!!!! 🥺😭"
youtube the moment ad blocking is off: "hey check out this ad from the We Want To Eradicate You And Your Weird Friends Foundation. prettty neat 👍"
So... has anyone written a comprehensive article on the many governance failures of #Mozilla over the years yet?
(And I mean the actual governance failures, of which there are many, not the "Mozilla didn't want to support my specific obscure nerd feature request")
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.