thomask

joined 1 year ago
MODERATOR OF
[–] [email protected] 16 points 2 weeks ago (1 children)

What's the deal with the Google ad that shows a legit URL but takes users to another? That seems like the biggest issue here and the article just rolls past it like that's totally normal.

[–] [email protected] 8 points 3 weeks ago

Well damn. Thanks.

[–] [email protected] 9 points 3 weeks ago (2 children)

Is this a joke? I'm not clever enough to get it.

 

The following summary from Debian's security list:

The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd's SIGALRM handler is called asynchronously and calls various functions that are not async-signal-safe. A remote unauthenticated attacker can take advantage of this flaw to execute arbitrary code with root privileges. This flaw affects sshd in its default configuration.

 

Martin Kleppmann sets out a vision: "In local-first software, the availability of another computer should never prevent you from working."

He describes the evolution of how to classify local-first software, how it differs from offline-first, and proposes a bold future where data sync servers are a commodity working in tandem with peer-to-peer sync, freeing both developers and users from lock-in concerns.

[–] [email protected] 1 points 2 months ago

It's convenient until you want to upgrade the distro.

[–] [email protected] 13 points 3 months ago

Hmm wasn't there some kerfuffle recently about how the kernel was going to start self-issuing CVEs en masse? Is this the result of that plan?

[–] [email protected] 7 points 5 months ago (1 children)

Well this 100% illegal art makes me happy so good job

[–] [email protected] 9 points 5 months ago

If you can write correct C++ you'll be able to write Rust code that compiles first time. Don't stress, you're learning the good stuff.

[–] [email protected] 10 points 5 months ago

IrfanView, now that's the good stuff

[–] [email protected] 3 points 5 months ago

I probably wouldn't bother. I can think of two scenarios you might get spied on.

  1. Through your browser you've granted a website access to your webcam (Zoom etc.) and left a tab open. Maybe it could activate it when you weren't expecting?
  2. Someone has used a vulnerability to take control of your computer to the degree it can access your webcam directly. Desktop linux software doesn't usually have meaningful isolation between software running as the same user, so at this point they can grab all your data, passwords, take screenshots, etc. and the webcam is just the cherry on top.

I expect most people don't do (1) very often, let alone for sketchy websites, so IMO it doesn't make much difference either way.

[–] [email protected] -1 points 8 months ago

This is one scenario I proposed when we were last having this discussion: https://thomask.sdf.org/blog/2023/07/07/if-i-was-meta-and-wanted-to-make-fedi-implode.html

[–] [email protected] 4 points 8 months ago

N=1 but outbound federation just worked for me in a post. It seems some work was done just recently including an upgrade to -rc.8.

[–] [email protected] 5 points 9 months ago (3 children)

It's best not to think of SDF admins in binary terms like "present" or "absent". They are an undulating force which makes changes here and there and we're all along for the ride.

view more: next ›