social.gl-como.it

Andrey Konovalov mastodon (AP)

Wrote an article about turning a ThinkPad X1 Carbon 6th Gen laptop into a programmable USB device by enabling the xDCI controller 😯

Now I can emulate USB devices from the laptop without any external hardware, including via Raw Gadget or even Facedancer 😁

The overall process included fiddling with Linux kernel drivers, xHCI, DWC3, ACPI, BIOS/UEFI, Boot Guard, TPM, NVRAM, PCH, PMC, PSF, IOSF, and P2SB, and making a custom USB cable 😱

xairy.io/articles/thinkpad-xdc…

1
Trammell Hudson mastodon (AP)
the lock bits being reset during S3 sleep and not re-locked seems like an evergreen design failure. Thunderstrike 2 used a similar mistake (PRR lock bits not re-locked soon enough coming out of S3 sleep) and Prince Harming was a regression (PRR bits not re-locked at all on a new platform). trmm.net/Thunderstrike2_detail…

Marco d'Itri :debian: mastodon (AP)
Come chiunque aveva previsto, a meno di un mese dall'attivazione la piattaforma #antipezzotto di #AGCOM oggi ha illecitamente censurato l'IP 188.114.97.7 di Cloudflare che ospita centinaia di migliaia di siti che non c'entrano niente con lo streaming dello sport. Bravi tutti. #piracyshield
1 8
Marco d'Itri :debian: mastodon (AP)
Dopo diverse ore 188.114.97.7 è stato sbloccato, anche se non ho capito su quale base legale visto che i blocchi dovrebbero essere permanenti.
Piero Bosio mastodon (AP)

Purtroppo a rimetterci è anche la reputazione dell'Agcom.

dday.it/redazione/48554/piracy…

Il Gigante mastodon (AP)
ma non ci sono gli estremi per una class action per una cosa del genere?

Rozzychan mastodon (AP)

A podficcer posted this link about voice acting that is pretty hilarious.
#voices #voiceActing

tumblr.com/seananmcguire/74270…

1

Daniel Keys Moran mastodon (AP)
Isaac Asimov:
2

Fabio friendica
1

Rasmus Bååth mastodon (AP)

On my blog: Why pandas feels clunky when coming from R

sumsar.net/blog/pandas-feels-c…

4

Ada Palmer mastodon (AP)

"One price of free speech is eternal humility, recognizing that none of us is immune to becoming a tool of censorship if we fail to recognize its manipulative tactics."

“Tools for Thinking About Censorship”

reactormag.com/tools-for-think…

1
Marcos Abreu mastodon (AP)
I would like to say that your article is amaizing! And you are a great writer. Thx for sharing.
Questa voce è stata modificata (2 anni fa)

Since Reddit has now sold out to AI, a reminder if you're into #Linux / #LinuxGaming that Lemmy exists and it's open source.

I'm a mod here too: lemmy.ml/c/linux_gaming@lemmy.…

2

addie mastodon (AP)
Stop turning your Linux apps into Docker containers and removing the normal install methods.
3

1 1

Zand :arch: :terminal: mastodon (AP)
Mi preoccupa molto il Piracy Shield introdotto, anche se non vedo partite piratate o sia possessore di "pezzotto", ma per le implicazioni a corto/lungo termine che porta.
È notizia di un paio di giorni fa che insieme agli ip di alcuni siti di streaming video siano stati indiscriminatamente bloccati in toto gli ip di 2 CDN (cloud4c.com e parte di zenlayer), rendendo impossibile anche a chi avesse servizi leciti li sopra di essere raggiunti dall'Italia, l'organo che si occupa della faccenda (agcom) è un organo privato che si erge a "controllore", "multatore" e "bloccatore". Con il mer(d)aviglioso governo fascista che abbiamo ci vorrà poco affinché da un utilizzo anti pirateria si passi ai blocchi per fini politici adducendo motivazioni fantasiose (tipo il decreto antisemitismo di Salvini per gli artisti e le tv).
5
Tutto sacrosanto, ma non mi risulta che Agcom sia privato.
Zand :arch: :terminal: mastodon (AP)
@diegor si si è stata una mia inesattezza, ho travisato il privato con indipendente

Enoch mastodon (AP)
Happy caturday 🐈! Here’s a cat selfie I found somewhere on the www! 😂 i hope you all have a great weekend ☀️🥳🙌
1

Talen Lee mastodon (AP)

This youtube video does something I literally had no idea was possible with the subtitle system. Watch it without subtitles to get an idea for what the base video looks like, then watch it with the subtitles on.

youtube.com/watch?v=ZYlaUrj2Zk…

2

Very proud that the IEEE has published my article “Why Bloat Is Still Software’s Biggest Vulnerability - A 2024 plea for lean software”:

spectrum.ieee.org/lean-softwar…

2

Zand :arch: :terminal: mastodon (AP)
Filippone...
Ok che (come al solito dato che idee tue non ne hai mai avute), hai "copiato" l'impegno profuso da me e @kenobit sul progetto bookwyrm, ok che ti sei preso il dominio bookwyrm .it perché senza atteggiamenti predatori non ci sai stare, ok che hai mantenuto il logo ufficiale così puoi fare il paraculo e attirare gente spacciandoti per "istanza italiana" (tanto la descrizione non la legge nessuno), ma cazzo, copiare lettera per lettera (solo che non sai formattare il testo) il codice di condotta di bookwyrm.gatti.ninja... Dai su un po di fantasia, ce la puoi fare anche da solo no?
Nelle immagini in scuro gattininja in chiaro filippone.
:clapping:
#bookwyrm #gattininja
5
Yaku 🐗 mastodon (AP)
@guardaminfaccia Daje FilippONE facci sognare, accusa gattinija di aver copiato da te! :blobcatpopcornnom:
1

È strano che non abbia ancora registrato puntarella it.


[EDIT]Ah, capito… è GIÀ registrato.

Questa voce è stata modificata (2 anni fa)

Diego Roversi friendica

Erty hometown (AP)
Saw a meme and decided it needed a 4x4 taking it to the furthest extreme
1 3
Wynke Messaggio privato mastodon (AP)
Looks to me like Murphy understands the other ones pretty damn well...
brennen mastodon (AP)
ok, ok, but in the spirit of the original law, shouldn't murphy's razor be "anything that can be complicated, will be complicated"?

A locally exploitable glibc vulnerability lwn.net/Articles/960289/ #LWN
#LWN
2

Questa voce è stata modificata (2 anni fa)
2

Google announced that starting in June 2024, ad blockers such as uBlock Origin #uBO will be disabled in Chrome 127 and later with the rollout of Manifest V3 (#Mv3).

The new #Chrome manifest will prevent using custom filters and stops on demand updates of blocklist. Only #Google authorized updates to browser extension will be allowed in the future, which mean an automatic win for Google in their battle to stop YouTube #AdBlockers .

#ManifestV3 is deceitful and threatening to your privacy, and now is a good time to switch to #Firefox (@mozilla) and/or #TorBrowser (@torproject) if you haven't done so already!

EFF (@eff) on Google’s Manifest V3:

⚠️⁠eff.org/deeplinks/2021/12/chro…
⚠️⁠eff.org/deeplinks/2021/12/goog…


Chrome Manifest V3 Transition Timeline (2023-11-16)

🚩⁠developer.chrome.com/blog/resu…


EDIT for clarification: MV3 in Chrome will still allow some ad blocking extensions, but will severely limit their blocking ability and even restricts pre-set filters to 50 MAX.

13

Mozilla Firefox :firefox:


Desktop
📥⁠mozilla.org/en-US/firefox/

Android Play Store
📥⁠play.google.com/store/apps/det…

iOS App Store
📥⁠apps.apple.com/us/app/firefox-…


Tor Browser :tor:


Desktop
📥⁠torproject.org/download/

Android Play Store
📥⁠play.google.com/store/apps/det…

Fdroid Repo
📥⁠support.torproject.org/tormobi…

iOS App Store (try OnionBrowser)
📥⁠onionbrowser.com/


#Firefox #Mozilla #TorBrowser #Tor #Browser #Privacy

Questa voce è stata modificata (2 anni fa)
Mikko Tuumanen mastodon (AP)
@mozilla But where is the download link to get Firefox apk? I don't want Google Play in my phone.
Ah shoot I meant to write EU regulators but I keep forgetting. Like someone should investigate it and if there isn't a law to prevent it, write one.

Fabio friendica

Confy 0.7.1

Version 0.7.1 of #Confy, the #gtk4 / #libadwaita conference companion, has been tagged.

This release brings small fixes.
Main highlights are:

  • New German translation.
  • Flatpak now will use GNOME Runtime 45

#Arch #AUR packages are updated, #flatpak on #Flathub should be on its way.

sr.ht/~fabrixxm/Confy/

1 1

Etienne Jacob mastodon (AP)
Haven't shared it on Mastodon, this page of my website is popular: bleuje.com/randomanimations/
It was on the frontpage of hackernews a week ago. 200+ of my animations in random order, next one with click or keypress.
1

3

Lucie / minute mastodon (AP)
"qalc" is a nice little calculator and simple equation solver for the terminal.
4
Light🐧 mastodon (AP)
qalc is rocks 🤘️, is good enough for most of thing I need, it's my go to minimal calculator app.
pandora mastodon (AP)
tested it a bit and it is amazing... how come it is soo unknown

Lysander il breve iceshrimp (AP)
Ahh, come migliora la vita l'AI.
1

Hard to get more clear-cut than this: "this is my own performance of Bach. Who died 300 years ago. I own all the rights", and yet...

eff.org/takedowns/sony-finally…

1
@LydiaConwell This is a pretty rampant issue, unfortunately. More than the various soundtrack pieces that I play where every composer is alive, I've had Greensleeves (composer unknown, traditional English piece), Londonderry Air (claimed as "Danny Boy" (which is the melody with lyrics added on), an Irish traditional piece), and Liebesleid (Fritz Kreisler (~1962)) all claimed numerous times :zerotwo_big_angry:
Questa voce è stata modificata (2 anni fa)

Olimex mastodon (AP)
ESP32-H2-DevKit-Lipo Open Source Hardware board with Zigbee, Threat, Matter, BLE5 is now available for pre-order olimex.wordpress.com/2024/01/1… #zigbee #iot #esp32-h2 #oshw #threat #matter
1
Olimex mastodon (AP)
@chrysn this is pUEXT 10 pin 1mm step connector
chrysn mastodon (AP)
Back when I started building hardware, UEXT was my go-to for extensibility because it was simple and well documented. Given there is now both mUEXT and pUEXT, please consider updating the specs.
1

Wookey mastodon (AP)
Is there anyone who lives near Bruxelles Midi station reading this today? I just came though Eurostar on way back to the UK and my friend's ice axe was confiscated, despite the letter from Eurostar saying "alpine equpiment (crampons and ice axe) _is_ permitted". We persuaded them to hold it for 24 hours before destroying it, so I am hoping to find someone very helpful who could go there to rescue it and give it to me at FOSDEM to post back to the UK.
4

Codeberg mastodon (AP)

We are currently having network issues. We are able to connect to our server's onboard recovery system, but the access is slow and unreliable.

We'll keep you updated.

2

againë

Forgive me if I'm stating a commonly asked question but why don't you guys use cloud flare. You just host code

Codeberg mastodon (AP)
@kirby cloudFlare is a privacy nightmare for many. And it costs a lot of $$$, see fosstodon.org/@drewdevault/111…
1

adamghill mastodon (AP)

An electrician had to cut a hole in our drywall and instead of just patching it up, my wife decided to make a little scene with miniatures embedded in the wall. 😂🖼️🤯

Edit: pixelfed.social/@thisfunhouse has some more pictures of the subway and I will post lots more quirky art over there.

#art #miniatures

Questa voce è stata modificata (1 anno fa)
6

Kristen Wixx mastodon (AP)
Then I'm going to be immortal.
2

Pseudo Nym mastodon (AP)

My million dollar idea I want someone to steal and do, so I can be a customer.

"Dumb Stuff" we sell electronic appliances that aren't Internet connected. That's all.

That's it. That's the pitch. I would buy the <bleep> out of this company if their electronic gadgets were even half way decent, and repairable.

Electronic, no wifi, regular screws to open it up. That's it. Do those three things, and you can be sold by this store.

I will pay this business to curate and find these devices for me.

1 9
would love this! Can merge with my long-time wish for a No-Frills brand/aggregator of electronics without unnecessary touch screens, touch buttons, RGB everywhere, etc. It requires some effort these days to buy decent computer parts that don’t light up the room for example!
Questa voce è stata modificata (2 anni fa)

Isn't buying a knife and getting a screwdriver, nail file and corkscrew the opposite of the simplicity requested here?

@clacke

Holir_ mastodon (AP)
@notclacke @clacke @taharez The Victronox brand has more than the Swiss army knife. Low frills, good quality and reasonably priced. The 8" chef knife is $60 and one of the best under $100. I've heard good things about their luggage as well.
@Pseudo Nym Renewed relevance today with the largest IT incident in history.

John Goerzen mastodon (AP)
My advice to consider #security first when evaluating systems: changelog.complete.org/archive… This is part of my decision to migrate my #RaspberryPi devices to running pure #Debian.
1
John Goerzen mastodon (AP)

I have a new post: Live Migrating from #RaspberryPiOs #bullseye to #Debian #bookworm. changelog.complete.org/archive…

I got annoyed that #Raspbian officially has no upgrade path, the security situation, the lag behind Debian, lack of backports, and lack of initramfs in its custom kernel. So I managed to live migrate some Pis to Debian.

1
John Goerzen mastodon (AP)
@gregoa_ I hear you. I have also generally upgraded my Pis in-place despite the warnings against it, but it seems the warnings were particularly strident this time. I don't follow testing, but I know the stable releases lag significantly. Debian Bookworm came out on June 10, and RPi Bookworm took 4 more months. It's pretty annoying having all my other systems on bookworm, having to deal with bullseye differences for months, and then warnings not to upgrade after that.

Compile your kernel (or whatever) withour wearing your ssd:

If you have /tmp on your SSD, instead of a tmpfs mount:

- create a new directory and mount it as tmpfs (1Gb)

# mkdir /tmp/tmp
# mount -t tmpfs -o size=1G tmpfs /tmp/tmp

- now tell gcc to use it:

# export TMPDIR=/tmp/tmp


Paolo Melchiorre mastodon (AP)

I highly recommend supporting the Standard Ebooks project. 📚

«Standard Ebooks is a volunteer-driven project that produces new editions of public domain e-books that are lovingly formatted, open source, free of copyright restrictions, and free of cost.»

Donate 👇
standardebooks.org/donate

Please boost 🙏

#standardebook #standardebooks #ebook #ebooks #publicdomain #book #books #reading #epub #standard

Questa voce è stata modificata (2 anni fa)
5

nixCraft 🐧 mastodon (AP)
The predictable network interface device names in #Linux 🤣
1

ChiefGyk3D mastodon (AP)
Happy Festivus everyone! youtu.be/1njzgXSzA-A?si=YuQnjV…
#festivus #holidays #miracle
2

Jonas Schäfer mastodon (AP)

postfix.org/smtp-smuggling.htm…

"SMTP Smuggling" vulnerability in Postfix allows to spoof senders even in the presence of some DMARC checks. Configuration workarounds exist.

Also, a wholehearted f* you to SEC Consult, who sat on this since June and disclosed it to some closed-source vendors and MSPs, but could apparently not be bothered to give e.g. Postfix a heads-up, publishing this close to the holidays.

Boosts for awareness welcome.

Edit: So this has kinda blown up. and especially because the author of the SEC advisory is going to have a slot at 37C3, I would like to add something important: I intentionally wrote "SEC Consult" above, not "$individual". Do not start harassing that person. For all we know, this is a corporate failure and the individual would actually appreciate guidance and tips. That does not mean to not ask the hard questions, but keep the framing in mind. They might genuinely have been told by their managers that that is how responsible disclosure works.

Questa voce è stata modificata (2 anni fa)
8
Deborah Pickett hometown (AP)

I see SEC Consult has amended their page sec-consult.com/blog/detail/sm… with something of an acknowledgment that they might have stuffed up disclosure a bit here. It does read a bit like "We contacted both vendors, Microsoft _and_ Cisco!"

A hearty Fuck You to SEC Consult for being bad at their one job, and a hearty side of Fuck You to Cisco for their arrogant "It's not a bug".

Now, after I have patched my Postfix server at $dayjob, back to my previously scheduled long weekend.


Mad Villain mastodon (AP)

The internet is a big place. We can all have our own fedi. Each of us can have whatever kind of experience, community, connections, etc, we want here.

That’s the beauty of this place. There is enough room for everyone.

Be wary of anyone who tries to force you to be in community with them because of their myopic view of what online spaces should be.

We can make different decisions. We can make better decisions.

1 1

2024 is the year of no more "sprints." for security reasons, "snprints" is recommended instead.
2
nuovi vecchi

Questo sito utilizza cookie per riconosce gli utenti loggati e quelli che tornano a visitare. Proseguendo la navigazione su questo sito, accetti l'utilizzo di questi cookie.