Show newer

I took the IRC game I wrote for the lisp game jam and submitted it to the Linux Game Jam kind of on a lark since they just happened to overlap in timing; turns out they seemed to really like it! placed 5th out of 47: https://itch.io/jam/linux-game-jam2023/rate/2091620

Because I'm not hearing a lot of chatter on the Fediverse about this here are the CVEs and their summaries for the issues fixed in today's release:

CVE-2023-36460

Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing Denial of Service and arbitrary Remote Code Execution.

CVE-2023-36459

Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in oEmbed preview cards. This introduces a vector for cross-site scripting (XSS) payloads that can be rendered in the user's browser when a preview card for a malicious link is clicked through.

#MastoAdmin

First real-world dlayer module successfully implemented \o/

The LVM part of my 'system query API' project now lives in its own separate module, and works!

It feels super weird when people diss the fact that some people *like* the current state of the #Fediverse and don't necessarily care if it grows bigger or not.

Like…the very notion that growth is a *primary goal* of a social structure is in some ways problematic.

I used to be involved in a very evangelistic religion. A big part of the belief system was you need new converts all the time.

That belief often meant *existing social structures were harmed* in the name of growth.

Problematic.

"Why are these two values getting swapped around in my code?"

... several minutes later ...

"... oh, they're not, I just swapped around the debug texts in my console.logs 🤦‍♂️ "

RE: Evernote news on HN [firing all staff].

The story only seems to be Hacker News/Y. But just in case:

You can download & export your entire Evernote collection using evernote-backup: github.com/vzhd1701/evernote-b

Can't do it in the official app anymore without a $paid$ plan.

Context: news.ycombinator.com/item?id=3

#evernote

:3 doubling post. send me some :3 and i will send you twice as many back

@tobi @vyr Come to GotoSocial. We have...

- Skeletons
- That weird smell in the corner of the code
- Sloths
- LAG!

@researchfairy Indeed!

BTW there's a precedent: this is essentially what the Dutch parliament did in 2015 through an amendment to copyright law ('amendement Taverne'). All publicly funded scientists connected to Dutch institutions are by law allowed to share and archive their papers in perpetual open access

I don't often get excited about laws or amendments but this is one of my faves

Facebook Twitter meta 

Rent: $0
Staff: $0
Suing Facebook: $1,000,000,000
Cloud: $0

Someone who's good at this economy please help me budget this my company is dying

youtube when my ad blocker is on: "oooHHHH PWEEEEASE turn off your ad blocker PWETTY PWEASE 🥺🥺🥺 ooooaahhhh we simply can't pay cweatows without ads!!!! 🥺😭"

youtube the moment ad blocking is off: "hey check out this ad from the We Want To Eradicate You And Your Weird Friends Foundation. prettty neat 👍"

So... has anyone written a comprehensive article on the many governance failures of over the years yet?

(And I mean the actual governance failures, of which there are many, not the "Mozilla didn't want to support my specific obscure nerd feature request")

Looking at Energylandia's coaster lineup, it kinda feels like they opened up the catalog of a couple of different manufacturers and went "yeah, one of everything please"

*resets the "days since I've had to tell someone that ChatGPT and similar LLMs are fundamentally not capable of providing reliable information and/or citing sources" counter to zero*
[it was at 1 before]

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.