Show newer

subtoot, security 

Argh. Why do people still keep doing string concatenation for SQL queries?!

Heads up: There's a critical (9.7 CVSS) vulnerability in certain Misskey (v12) forks

Misskey and Sharkey are NOT affected

We'll provide details later, follow this thread for more detail. Magnetar and Iceshrimp.js will receive immediate patches, for EoL forks we can only provide a link to a hot patch once fixes have been rolled out for server owners to use

We are not aware of any existing exploits of this vulnerability to date

RE:
https://astolfo.social/notes/01JNKHMB0G1PNAGC5FHQFYGSTS

holding the website down with my foot & pointing my sword at them as I check this box:

activism, infiltration, slightly vent-y 

Relatedly: maybe stop playing by the state's rules? Half the point of infiltration is to create paranoia in the group, and because cops always have more resources than your radical group does, they essentially have full control over how much of your energy gets spent chasing them.

You're not going to get an advantage there. Look for your advantage in strategies and areas that the state (fundamentally) cannot competently deal with, and that they do not have a lot of resources in.

Show thread

activism, infiltration, slightly vent-y 

I wish people in activist spaces would spend less time arguing about who is or isn't a cop, and more time figuring out strategies where it doesn't materially *matter* if some people are cops.

Like, you can try reading tea leaves until you're blue in the face but it's just going to cost you a lot of energy that's better spent driving effective change.

At what point does "can't sleep" become "couldn't sleep"?

Asking for a friend, who is my brain, who didn't sleep.

Findings on multiple instances conclude:

the moment a gay reaches their gay destination their fedi activity seizes for a given amount of time.

After a busy morning of unfurling and rigging work, we have sailed off our anchor and are making way towards Sint Maarten.

Show thread

New wind turbine blades in the U.K. will be painted black to help prevent bird deaths. While the country is committed to boosting clean energy sources, it’s also home to large populations of seabirds, and the new trial will build on studies that suggest black blades can reduce bird collisions by 70%.

Heya 👋
We from @SafeguardingResearch are looking for volunteers to work on our landing page (self-hosted ghost). We already got a basic page up, but it can use some improvement.

If you want to help/support (in any way), feel free to ping us :)

Top 10 connected roads in Baden-Würrtermberg without a sidewalk tag.

Quick map to demo. 2 largest blobs are in Würrtermberg, just saying. 😉

Just learned about "midlance" and wow that's a fucking scam.

Happy to announce that I've found a new IT assignment. Unironically, it happened via LinkedFUCKINGIn.

LMFAO!!!!

Blogged 👇

maaikebrinkhof.nl/thank-you/

github is the linkedin of git forges send toot

People don't fear technology, they fear what capitalism might do with it.

@luna I think it's valid to examine how this is disproportionally to the benefit of corporations and governments. They'll make sure we have memory safe DRM, memory safe back doors, and memory-safe regressive laws; and we'll keep getting hit by memory safe ad-network attacks, memory safe social engineering, and memory safe bulk data selling.

I don't want to live in the fully automated memory safe global crapitalism police state.

memory unsafety may cause a lot of software crashes, but it also helps a lot of people jailbreak their game consoles, so, it;s impossible to say if its bad or not,

@luna Honestly, this. Safety isn't neutral, especially when so much of tech treats users as the threat to be defended against.

I'm still pro-Rust, but I do think there's a nuance to what's meant to memory safety that gets missed in a lot of Discourse™.

This is not exactly news, but I should maybe say it explicitly: I do not have any remaining faith in the project pulling itself back together governance-wise.

There's been a consistent lack of urgency in addressing the increasing mountain of governance crises, some of them created by core developers(!), and that tells me that any formal solutions will *at best* be implemented reluctantly.

Any actual meaningful positive change is going to come from things organized outside of the formal structures in the project, like forks and specialist groups.

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.