Show newer

@Cmastication @gabek

To these (and all developers) keep up the good work, you're doing a great job.

I remember the ssh bug thing a few years ago, turned out the dev could not fix it due to a broken computer,

Don’t forget the very real human side of the xz debacle. Some well intentioned and unpaid folks are having the worst day of their lives (so far)

From: @gabek
social.gabekangas.com/objects/

"Isn't that a bit alarmist?" No!

xz is a base-system package in literally every distro I know of. It's everywhere.

Compromised releases have been out for five weeks and we didn't notice. We only noticed because someone caught openssh taking 10x as long to do DH exchanges and auth. If the attacker had been sneakier we wouldn't have noticed at all.

The compromised xz was in Fedora's testing versions and they didn't notice. You had the compromised version in Arch for a month (and arguably still do, but a combination of build method and source acquisition method likely renders it safe).

If some random guy didn't go "Why is openssh so slow?" and dig really deep into that, it would have hit stable/live distros and then what? We don't know.

Show thread

So, kids, what's the moral of the XZ story?

If you're going to backdoor something, make sure that your changes don't impact its performance. Nobody cares about security - but if your backdoor makes the thing half a second slower, some nerd is going to dig it up.

@RickiTarr @coffeepine@beige.party

Where there are community spaces, as I said before, USE IT OR LOSE IT.

@coffeepine Community spaces are disappearing it's a real issue especially for younger and older people, but really everyone. I don't think it's an accident either. People who don't connect, can't organize.

@MissingThePt

Two days too early, April Fools' Day is Monday.

Imagine writing an open source twitter alternative

One that is federated and built on open protocols

Then having to deal with users who are upset you are working with an established walled garden social platform to support those very open protocols

Girl, you can't have it both ways

We can build better mod/safety tools

But

You can't moderate who gets to participate in an open protocol

Maybe let's focus on the important aspect, better mod/safety tools

signed,
fedi developer

@NumbersCanBeFun@shonk.socia

I wonder if anyone back in the days of Monochrome monitors said this when they upgrade to a colour monitor :)

Did you know that the government of Kerala included free software in the school curriculum inspired by protests from free software enthusiasts and a favorable stance taken by a school teachers association? gnu.org/education/edu-system-i Help the free software community achieve the same for other states, countries, and regions worldwide by donating to support the FSF's advocacy for free software. donate.fsf.org/ #LearnLibre #FreeSoftware #SoftwareFreedom

The title of this song should be on the next Tory Manifesto publication

youtu.be/LQiOA7euaYA?si=qTGb8D

The road to nowhere.

@zleap @aral

BBC Monitoring also nowadays scrapes social media (and probably has access to data from Meta either officially or by posing as normal users) and feeds into GCHQ (they've been doing this since the Cold War, except previously it was more often done over the radio airwaves, but they were early adopters of online surveillance)

@aral
Unlike the NAZI holocaust this genocide is being played out in front of the world media and internet, with evidence being shared and corroborated daily.

Should not be THAT hard to bring charges.

“If the International Criminal Court wants to investigate what Israel has done in Gaza only since the 7th of October, it will be busy for decades.”

– UN Special Rapporteur Francesca Albanese

youtube.com/shorts/0ZhGCHnEfuQ

#israel #usa #UnitedStates #genocide #gaza #palestine #un #FrancescaAlbanese #warCrimes #ethnicCleansing #apartheid

@aral

Who needs the NSA / GCHQ when you can get Meta to spy on people.

Meta (Facebook, Instagram, #Threads, etc.):

1. Doesn’t moderate anti-transgender hate on its platforms.

glaad.org/smsi/report-meta-fai

2. Secretly pays teenagers to use their VPN service so they can access all their web activity, gets busted, then uses same app to man-in-the-middle attack Snapchat users to get their encrypted data.

techcrunch.com/2024/03/26/face

3. Lets Netflix see user DMs.

arstechnica.com/gadgets/2024/0

Mastodon, gGmbH to Meta:

🤗 Let’s be besties!

platformer.news/mastodon-inter

#mastodon #meta

@amszmidt

It may be interesting to get a talk at a free software conference about this sort of thing at some point

15:00 - 15:45 EDT (19:00 UTC)

Exploring free software entrepreneurship: Navigating the opportunities and obstacles
: Jupiter -- in-person
: Social context
Shivanand Edrami

Free software legislation: How we win
: Saturn -- in-person
: Free software in government
Ciarán O'Riordan

Empowering youth in the digital age: A path to success
: Neptune -- online
: Education
Leonardo Champion

Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.