Skip to main content

silverwizard reshared this.


THIS IS WHY WE NEED REDUNDANCY IN OUR CIRCUMVENTION NETWORKS. It is not about who is better or worse, it is about threat modelling for when attacks happen because they will and we need to be ready as a COMMUNITY. #I2P
#I2P

reshared this



Coworkers often are confused why I maintain local copies of all our git repos.

The answer is:

grep -Ri "There was an error while loading announcements" .



Richard "mtfnpy" Harman reshared this.


My 4 year old has managed to find the UPnP endpoint for the Jellyfin server and added ska to his bedtime playlist...

I am going to need to put his tablet on a vlan before he watches Alien and can't sleep.

This entry was edited (7 months ago)


I spent two hours this morning discussing recovery strategies, and now I need to figure out how to write that two hour meeting into a single document
in reply to Jonathan Lamothe

@Jonathan Lamothe I mean seriously! Two hours, we got a functional definition of our goals, as well as a future plan! It's so rare I feel like I'm in this place.

silverwizard reshared this.


For a lot of us IT people, it feels like a losing battle lately. Overwhelmed, under budgeted and understaffed. An already burnt out single point of failure. We KNOW there's a shitload of controls we should be rolling out but we're stuck troubleshooting grumpy legacy hardware or Gertrude forgetting her password again. It's a struggle to get resources because $MGMT only sees us as a money pit until the shit hits the fan, then, if we're still here we can get a budget/help/etc.

I'm just tired, dudes.

silverwizard reshared this.



silverwizard reshared this.


reshared this


Bee O'Problem reshared this.


https://www.404media.co/we-must-never-forget-how-dumb-the-humane-ai-pin-is/ wrote:

I am now, of course, adding to this neverending discourse with this article. But I want to be clear: No one is under any obligation to be nice to the creators of the Humane pin or the product itself, which, even if it worked, is a gadget that relies on mass content theft and the scraping of huge amounts of human knowledge and creativity to make a product that is marketed as making us more “human.” The people making this argument are people who have a vested interest in the general public continuing to canonize, support, and spend money on a Silicon Valley vision of the future that involves the automation of everything, the displacement of huge numbers of workers, and a new, AI-led internet that has so far done little but flooded the web with low quality junk, been used to make fake porn to harass women, and has led eager beaver know nothing CEOs to prematurely lay off huge numbers of workers to replace them with AI tools built on the back of uncompensated human labor and training largely done by underpaid “ghost workers” in the developing world.

@404 Media is literally the single best tech media in the entire world. There are some other reporters out there who are amazing, but 404 Media has the full chain of support.


in reply to Zach Klipp (he/him) 🥥🌻🍉 FoolishOwl reshared this.

Just in case anyone has somehow missed the context for this thread, it's this:
theverge.com/2024/4/17/2413370…
in reply to Zach Klipp (he/him) 🥥🌻🍉

That comments section is appalling. Mostly bootlicking.
This entry was edited (7 months ago)


LLM answers are Mad Libs for Tech Bros

Prompt enginneering is the act of replacin "Adjective" with "A Colour" and then rerolling until you finally get one you like



Web Design is the art of removing accessibility until the page is as annoying as possible
in reply to silverwizard

I'm sure my site has accessibility-related atrocities 😭

I've been trying to remediate at least.

in reply to shellsharks

@shellsharks it's frustrating because if we just let the content be, screen readers and stuff would work so easily. We'd have all the standardized hinting there!


Is anyone else very angry that Animorphs has two different BIll Gates, one of whom plagiarized Yeerk tech, and the other that plagiarized Andalite tech?


Wait, fuck

I don't really eat hot sauce, but my uncle and I eat scorpion peppers he grows sometimes...

Should I be less worried about hot sauces?

in reply to silverwizard

@silverwizard: still the 3rd hottest pepper cultivar in the world 🤷‍♂️

silverwizard reshared this.


Our Director of Compliance is testifying tomorrow about Software Right to Repair for the DMCA in front of the Copyright Office. Supporting other Right to Repair organizations, and talking about the needs for copyleft and support of repairing our software.

If you want to tune in at 2:30 PM ET you can find more information here under the "Register to Watch Public Hearings": copyright.gov/1201/2024/ (warning, required use of proprietary software to view the hearing).

reshared this


in reply to silverwizard

If you only know the story from reading it in Highschool and thinking it made ants seem cool, please understand it was written in 1930s Germany about the dangers of communism by a Nazi.

Which is why we assign it to be read in highschools.

Never Forget was always said ironically.


silverwizard reshared this.


Last week we (#ReplayWorkshop) received, free, a full trailer of 275 gallon IBC bottles, already washed, pure HDPE (white or natural), for #recycling with our #preciousplastic shredder. 90 of them in total, about 47 pounds each.

A local trucking company accumulates more than they can sell or reuse. Payment from previous recycler dropped to be less than the cost of labor and transportation. They were delighted to have a local place where they could just bring the trailer and see it emptied.

silverwizard reshared this.

in reply to John Nephew

i’m curious to see how small those become after shredding.

They’re so huge I’m not surprised they’re eager to get rid of them.

in reply to masukomi (🎲)

@masukomi it'll be three pallets tops in expect. Probably less. It's pretty thick so it yields nice chunks with food density.


@404 Media Hey! You require me to sign in to use your website! Cool! That's fine and good!

Can you give me the option to sign in with a password? My password manager is pretty easy for me to use, but I don't tend to have my personal email open on my work laptop and so your signin flow is really keeping me from using your stuff and is the biggest source of friction for me.

Also - holy shit - your journalism is amazing, thanks.

Unknown parent

@Neil Brown @404 Media Ug, I need to get a new good generic RSS reader rather than my weird specific purpose ones

silverwizard reshared this.


’m getting laid off. I’m gutted but need to land somewhere. If you’re hiring for Swift platforms, please consider me. I work hard and want to do some great work.

reshared this


silverwizard reshared this.


if your web site is nicer in reader mode than when using its defaults, you’re bad at web sites
in reply to Rob Isaac

Also, if your website refuses to render in reader mode you’re even worse!
in reply to JamesWords alcinnz reshared this.

Unfortunately targeting the dozen-or-so reader modes well is nigh-impossible, given their nonstandard evolving scraping rules optimized for unfriendly sites.

Bulleted list with links in your article? Gone in at least two Reader Modes (it resembles article inserts for related content).

Unfamiliar-looking section links? Gone from Chromium’s Screen2x/DOM-Distiller along with the section headers unless you use ARIA hacks to fool the Reader Mode heuristics.

figure elements with code snippets? Unless you want to deviate from semantic HTML, enjoy reading code snippets with tiny and centered text on Edge.

Using Microformats? Safari Reader Mode adds a random “None” after every h-entry name.



@Becky says my N95 Accent Disguising Machine isn't stopping the Quebecois from realizing I'm not a local
This entry was edited (7 months ago)

silverwizard reshared this.


Every internet of shit, phone, tablet, and other sorts of device manufacturers should be required to push/post a root unlock firmware for their devices before they can stop supporting them. There's too goddamn much ewaste from everything already. If they're going to abandon their devices, at least make it easy for people to unlock them and do whatever else they want with them.
in reply to Jess👾

more like forcing them to deposit unlock keys at state (or similar) actors

and auto-releasing those keys after $time without update

in reply to Cassandrich

Quite like how the good carriers give the PUK code with the sim card.
in reply to Cassandrich

It's shitty, but I do get that some manufacturers sell the device itself at below cost because people have to pay for the online services. Game console manufacturers have done that for years. If they sold it easy to unlock, people would just buy the hardware, unlock it, and never pay for the service. Which is a shitty and scammy business model, but at least it does make sorta sense.

@dalias
@drazraeltod

in reply to Jess👾

@dalias @drazraeltod true, which is why requiring the unlock on EOL is a more "reasonable" demand (as in, will receive a less extreme lobbyist pushback).

The problem is when EOL of a device corresponds to EOL of the manufacturer. Can't really force a bankrupt entity that has long fired its engineers to unlock anything.

Perhaps the requirement should be to provide secret unlock instructions as a part of a device certification process. But then of course the repository of these secrets becomes a massive attack target.

Still, the amount of e-waste that could easily serve a new purpose if there was any documentation at all is infuriating.

🤔

in reply to Meh as a Service

Most of the time, the update to unlock the firmware wouldn't be especially technically complicated. It just requires access to the source code, build pipeline, and signing keys. So even if it's not kept in a central repo, if codified in law that it is a priority liability against the company assets if they declare bankruptcy to provide access to that information and fund a consultant to compile the firmware update, it wouldn't take all that long per device to compete.

Think when a company that holds toxic waste goes under - there's still liability to remediate it that carries on to whomever buys up the assets, and beyond some point it becomes a Superfund site to remediate.

@virtulis
@dalias @drazraeltod

in reply to Jess👾 Ruben Schade 🇦🇺🇸🇬 reshared this.

@virtulis @dalias @drazraeltod either you provide the bankruptcy court with a copy of the unlock tooling or you pay a massive fine out the top of your bankruptcy proceeds, before any one else is paid.

Suddenly suppliers, insurance, banks, etc all start requiring that this stuff exists and is prove able, in their contracts so they have a chance of getting paid in cases of bankruptcy.

in reply to Jess👾

Unrooting is not enough. You need documentation and open-source firmwares when a device is abandoned by the manufacturer.

Also you need to define "abandoned". I am sure device makers will never acknowledge the device is EOL. They will always find a good reason why a device will not receive update :)



Create an Open Source Software Levy, like Canada's rewritable media levy
whenever someone pays for a software license, take a levy and send it to FLOSS foundations


Bah, why does no one sell electronics locally anymore. I just want to buy some cables and no one sells those locally. The argument is that I could get it cheaper shipped from somewhere, but I wanna finish this project before I go on a roadtrip tomorrow. Why?!

silverwizard reshared this.


America's first sustainable urban agrihood in Detroit.
"The three-acre development has vacant land, along with occupied and abandoned homes centered around a two-acre urban garden, with more than 300 organic vegetable varieties, like lettuce, kale, and carrots, as well as a 200-tree fruit orchard, with apples, pears, plums, and cherries, a children’s sensory garden, and more."

thegardenmagazine.com/this-are…

foodrevolution.org/blog/first-…

#HopePunk #EcoPunk #SolarPunk

This entry was edited (7 months ago)

reshared this

in reply to HopePunk FTW

I naively assumed this article would tell me how much (in money, time, and labor) it cost to produce this “free” food. I was mistaken.


Watching the wee little Quinton Youtube video, but I'm refusing to try to find all of these
This entry was edited (7 months ago)


Holy Shit
Holy Shit
The show The Order got a second season.

I want to be clear - this show did not deserve a first season. And I will be watching the hell out of it. Hermetic Order of the Blue Rose is the name for your secret society that you use to say "I know enough to only step on occult rakes"


silverwizard reshared this.


One of my closest friends, @craigmaloney, passed away this morning. He was diagnosed with stage four cancer a bit over two years ago. He spent that time fighting like hell for his life. His eternal optimism was almost indestructible and deeply admirable. He refused to give up, even in the face of dwindling treatment options. I was given the opportunity to visit him last week, and even as his body was shutting down, he was still full of smiles.

Craig has been there for me since we became friends, through the best and the worst times of my life. Even when he was sick, he was there for me. He affected my life in many positive ways. There are two major life paths I took because of him that have forever changed the arc of my life story for the better. One, I attended PyOhio in 2017 after only two weeks of programming experience, and it introduced me to a supportive, wonderful community, of which I am a major part today. It led to my career as a community leader, programmer, and technical writer. Two, when I left my job of six years in September 2023, he suggested I try content creation, which I had fleetingly considered once or twice over the years, but never realistically, and never in a way where I believed I actually could. He convinced me I had more than enough to share with the world, and that what I have to share is important.

I am forever grateful to Craig's wife for giving me the opportunity to say goodbye. And I am forever grateful to Craig for making my life better in so many ways. Craig is an amazing person who wanted more than anything to have a positive effect on the world. You succeeded, in so many ways, friend. Rest peacefully now.

This entry was edited (7 months ago)
Unknown parent

murph
@claudiom @mjj @thegibson
When I looked back in the wayback machine, I followed him back in 2008 on identi.ca .
in reply to Kattni

Never meet him but he was always excellent to me and others. May his memory be a blessing.

silverwizard reshared this.


They killed an activist while destroying an urban forest to replace it with a police training center. they are charging the survivors with terrorism. they are repressing the bail fund. they are throwing away signatures asking for a vote. people wonder why some resort to sabotage.

reshared this


Eva Winterschön reshared this.


We should be talking about how GitHub fucked up constantly during the XZ disaster

reshared this

in reply to silverwizard

they banned the original maintainer!
they locked the repo!

they did everything they could to make it slower to fix!


Bee O'Problem reshared this.


Boost the fibre with a staple in it to make a network admin twitch

silverwizard reshared this.


BTW, am I the only one who sees the connection between trojaning the autocrap process for generating tar-balls and "Reflections on Trusting Trust" ?

reshared this

in reply to trademark

@trademark

I'm mostly thinking of the "making the compiler do something to the source" aspect.

I'm not sure if it is self-perpetuating, but I would be surprised if that was not the goal.

in reply to Poul-Henning Kamp

I think that's the missing step. The configure script is kinda like the output from a compiler except it was manually edited with a normal text-editor and not a hex-editor.

silverwizard reshared this.


the game I've been involved in developing was just released! it was a challenging journey, but I gathered experience across different aspects of development, such as UI, tech art, and game design. if you like detective puzzles like me, Between Horizons (store.steampowered.com/app/192…) is for you! a free demo is also available :)
if you enjoy it, please leave a review, it’s the best support!

reshared this



Dug out an old laptop I want to try to mod the screen on last night and started it up, and kicked off a freebsd-upgrade to 14 (last update was 2019, probably before the kids were born)

I stayed up til 1 am waiting for the upgrade to finish, but then crashed, I am now yawning through the Easter Eggs hunt and the laptop is still updating


silverwizard reshared this.


also in general if your advice to the average server owner is “audit every piece of every piece of code you’ll ever run” then it seems very possible you’ve lost your sense of scale and perspective
in reply to Kate Temkin

@Pashhur (honestly can't be sure if a bayesian of frequentialist joke would be funnier here)


Being a vendor sucks. So many of the companies I work with don't have contacts for their ISP or their DLP/CASB/EDR providers, because that contact is with the IT team. So they just call us being like "Your product is slow" and I need to dig through data and come back with "Uh, yeah, you're sending all your traffic to a vendor in Iowa with an rtt of 100 seconds?"
in reply to silverwizard

And this is after two escalations on both sides, and the customer being hilariously angry at us because "it's slow" and we're not helping.
in reply to silverwizard

this is also extra shitty because it 100% stems from people not being able to take their frustrations out on their IT team so they take them out on my support team, and fuck that
This entry was edited (7 months ago)



Just got #InFUNity Tiles, and my 4yo is excited and I'm excited
This entry was edited (8 months ago)

silverwizard reshared this.


I'm gonna level with you guys.

This weekend, cybersecurity journalist Brian Krebs supportively posted a quote on his Mastodon account, by a politician who suggested LGBTQ people commit false-flag bomb threats against themselves and their own drag story hours.

A few trans people including myself called him out on it. He didn't address any of our concerns. Instead, he tone-shamed and muted us.

I got pissed and wrote several toots, tagging him in some and not others. Thank you, anyone who read and boosted them.

Where was everyone else?

I can't help but feel if Krebs had quoted a politician suggesting Jews threatened their own synagogues for attention, or POC swatted themselves to "raise awareness" of racism, the response against him would be MUCH louder and carried by more than just a few trans people's voices.

99.9% of the time, attacks and threats against LGBTQ+ people -- particularly trans people -- are not "disinformation ops".

Is it because he's a tech bro, and one of the infosec field's designated mascots or what? Where are you at, cisgender mufos? Some words of support or acknowledgment of this hurt would go a long way.

Where are the reports against his instance, all the outcry I've seen on here for five years when someone egregiously fucks up and doubles down? I thought this place was trans-supportive.

I'm not hurt that he shamed and muted me, that part is just how it goes.

What hurts is the silence and inaction of mutuals on here. Disinformation, prejudice, and abuse of a journalistic platform just slid on by, already mostly buried in the timeline.

Trans people remember shit like that. We know what it means. My question is, do you know?

@jerry
@briankrebs
#infosec
#cybersecurity

in reply to Mystery Babylon

I don't follow Krebs, so I didn't understand what was going on. Thank you for taking the time to explain.

in reply to screwlisp

@screwtape @iacore

See, I use the ASFO (Wordpress) Web site to create pages for each of my episodes, with a little synopsis and a link to the recording. Like so :

anonradio.net/asfo-2024-03-23/

in reply to publius

@publius
Yeah, I should actually use that. But I like the tootversations that happen pro/retro spectively as well as the damgud cyberchatting.

I guess I'll use shinmera's tooter to textify the show plans. I was planning to start talking about the topics at the beginning of the week, rather than just a few hours before the show as well.
@iacore