Salta al contenuto principale



US Vice President J.D. Vance: Russia is not working against a possible peace with Ukraine


US Vice President J.D. Vance does not believe Moscow is obstructing a potential peace agreement in Ukraine, as Russia has made "significant concessions" to President Donald Trump. He also says there will be no US troops in Ukraine if peace is reached.

In an interview with NBC News, Vance said the Russians have "made significant concessions for the first time in three and a half years." This reportedly occurred when Trump and his Russian counterpart Vladimir Putin met earlier this month in Alaska. "They are willing to be flexible on some of their key demands," Vance said.

He said, among other things, that Moscow has recognized "that Ukraine will have territorial integrity after the war" and that it "cannot install a puppet government in Kyiv." "Have they made all the concessions? Of course not. But we are making progress," he added.

Claiming regions


Reuters reported Thursday, citing three Russian sources close to the Kremlin, that Moscow is prepared to freeze the front line in Zaporizhia and Kherson. These are regions the country claimed in June 2024. The Russians are also reportedly willing to withdraw from the Ukrainian regions of Kharkiv, Sumy, and Dnepropetrovsk.

But Moscow is reportedly sticking to its demands that Ukraine relinquish the eastern Donbas region, abandon its ambition to join NATO, and keep Western troops out of the country. Russia is also reportedly unwilling to return the Crimean peninsula, annexed in 2014.

Vance said today that Washington wants to offer Ukraine security guarantees, but he emphasized: "There will be no American troops in Ukraine."

'Troops important'


That is precisely what is important for Ukraine. Ukrainian President Volodymyr Zelenskyy said today that he hopes the country will receive security guarantees from the United States and other Western allies if a deal is reached with Russia. Having troops present in the country, "or as they say, 'boots on the ground,' is important to us," Zelensky said.

US envoy Keith Kellogg is currently in Ukraine. Ukrainian Prime Minister Yulia Svyrydenko said during a meeting with him today in Kyiv that she had discussed security guarantees. "This is not just about military guarantees, but also about political stability and economic strength," she wrote on social media.

Translated source article

in reply to Tiger

vance doesnt have a mind of his own, he only does as the sayso of THIEL who has a short leash on him.


Trump says China has to give US magnets or face 200% tariff


cross-posted from: lemmy.zip/post/47176268

President Donald Trump told reporters on Monday that China has to give the United States magnets or "we have to charge them 200% tariff or something" amid a trade dispute between the two nations.

Archived version: archive.is/20250825175243/reut…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.



Trump says China has to give US magnets or face 200% tariff


President Donald Trump told reporters on Monday that China has to give the United States magnets or "we have to charge them 200% tariff or something" amid a trade dispute between the two nations.


Archived version: archive.is/20250825175243/reut…


Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.


in reply to schizoidman

How does the madman theory work when your head honcho is an actual, bona fide madman? Don't go anywhere, we'll find out right after this quick commercial war!
Questa voce è stata modificata (1 settimana fa)

in reply to zero

I remember the first time they hit a hospital and they spent so much time lying about how it was all Hamas. Once they realized no one gave a shit they started hitting all the hospitals.

Israel is a criminal enterprise that always pushes to see what it can get away with.

Questa voce è stata modificata (1 settimana fa)

in reply to Gravitywell

It is actually decentralized though? You can host your own pds and relay for pretty cheap now.
in reply to Blisterexe

So how many people are doing that? I doubt more then 5% of their users are actually using a pds or ever will.

How many times do we have to watch venture capitalists enshittify services before people learn. Do you really think bluesky doesnt have plans to extract every drop of ad revenue and data harvesting at some point, decentralization doesnt work with that business model, sure its fine now in the honeymoon phase but wait till Jack decides ita time to cash out.

Questa voce è stata modificata (1 settimana fa)
in reply to Gravitywell

wait till Jack decides ita time to cash out


I mean, you don't like BlueSky, fair. But Jack Dorsey left like...over a year ago.

in reply to EarlGrey

Sure, and the 14b he gave was with no strings attached.

Its not like Jay Garber is any better

in reply to Gravitywell

I agree. That's why I'm happy it's fully decentralised, so that by the time they try to do that, they'll be but one player on atproto, and won't be able to get away with it.
in reply to Blisterexe

Id love to be wrong, but much like how meta patched threads into AP, i see this primarily as a performative gesture to allow them to take credit for "federating" when they have no intention of allowing it to get out of their control.
Questa voce è stata modificata (1 settimana fa)
in reply to Gravitywell

I see why you think that, and I agree threads sucks. But bsky is actually fully open source and they are actively working to make federation better. I do think the current leadership genuinely cares about making a federated platform.

Will they enshittify? Yes, probably when the current ceo leaves. But by then other services will have popped up, and ATproto is built in such a way that you can move services without your current service's consent.

Questa voce è stata modificata (1 settimana fa)


‘For Russians, Nato is next to Satan’: Finnish guards on alert at Russia border


North Karelia force says fence dividing Finland and Russia is no Berlin Wall – but it is now a key geopolitical faultline

... In an attempt to strike a note of optimism, he added: “We found a solution in 1944 and I’m sure that we will be able to find a solution in 2025.”

Matti Pitkäniitty, the commander of the North Karelia border guard district, believes illegal border crossings involving Russian defectors are likely to become a growing problem. Pointing to a gap in the vegetation where an old Finnish country lane passed through before the border was redrawn in 1940 after the Russo-Finnish war, resulting in Helsinki ceding part of Karelia, Pitkäniitty said most civilians trying to cross illegally preferred to stick to roads, limiting the number of potential routes.

“People are afraid of those thick forests here,” he said. But this would not be an issue for a Russian military professional trying to flee the war in Ukraine. “Now, one of the risks we are facing are the military-trained personnel fleeing the war. They of course know how to navigate through the woods and how to survive there if they need to stay out of sight for a couple of days.”

in reply to Dasus

Maybe they remember 1918, when they did a revolution to stop war and then the other belligerents decided to stop fighting and attack them instead. The usual culprit (USA, Britain, Germany)
in reply to AskThemRight

I mean it's not like Germany just decided to stop fighting as part of some cabal, they completely collapsed and had to suffer one of the most punitive treaties in modern history.

in reply to MCasq_qsaCJ_234

Yeah, so Musk's argument is that even though OpenAI's product ChatGPT has more downloads, Apple should consider letting X's Grok take the top spot because... reasons, I guess? Grok is still listed despite its antisemitic and other disgusting actions. It might be #2 (yeah it's definitely shit, right?), it might be #5, but it's still on the list, and it's still available. Musk is just mad that Apple is not featuring it.

Meanwhile, Fortnite is the top downloaded free iOS game. It sits on top of the charts. Thusly, Apple has buried the chart and they refuse to feature Fortnite, instead choosing to feature Roblox and PUBG instead. It's petty and silly, but the rankings do show which one has more downloads. That's it. It's not even about quality or anything.

I tend to agree with Epic (Fortnite) over Apple, but in regards to X, I'm with Apple. I may be slightly biased in that I don't like Musk/X, but I'm with Apple strictly on the merits here. I don't need biases to influence my reasoning here.


in reply to return2ozma

Incorrect. They just know that the fake financial system is not linked to anything fundamental. That is what is going to collapse taking retirement savings with it.
in reply to return2ozma

I was on board with this article until they described all the power fantasies that techbros were having as facts. AI isn't going to kill us because it grows sentient and "gets ahold of nuclear codes"; AI will kill us through sheer, painful, ecological collapse as Techbros seek to scale their models ever larger with more datacenters. Either that, or the economy collapses first, killing the tech (and likely the Techbros), and leaving us to ecological collapse anyways because of 200 years of industrial ratfuckery on a planetary scale.

AI won't kill us because it's smart, it'll kill us because it's so, SO dumb.



fediverse/activitypub based linktree alternative


i'm wondering if there was a federated or activitypub based linktree alternative? i current use linktree obviously but i'm growing tired of his bloatedness and would love to support an open alternative.. mostly just since i have a collection of threadiverse accounts for different things and would love to have one place for them all 😀
in reply to katy ✨

Honestly, it would be kind of cool if you just had a simple app to log in with your Fediverse identity, and it rendered your existing profile on the page and allowed you to put additional links.

I don't think it necessarily needs to federate.



YouTube secretly tested AI video enhancement without notifying creators


Is it a conspiracy? For months, YouTubers have been quietly griping that something looked off in their recent video uploads. Following a deeper analysis by a popular music channel, Google has now confirmed that it has been testing a feature that uses AI to artificially enhance videos. The company claims this is part of its effort to "provide the best video quality," but it's odd that it began doing so without notifying creators or offering any way to opt out of the experiment.
in reply to gedaliyah

I have noticed that some of the regular creators I watch seem to look a little AI lately. I honestly have been questioning reality a bit; that’s probably the point.


80s Nostalgia AI Slop Is Boomerfying the Masses for a Past That Never Existed


Archive: archive.is/Lv4Xx


80s Nostalgia AI Slop Is Boomerfying the Masses for a Past That Never Existed


The latest bleak new AI slop niche are “nostalgia” videos about how good the 1980s and 1990s were. There are many accounts spamming these out, but the general format is all basically the same. A procession of young people with feathered hair wonder at how terrible 2025 is and tell the viewer they should come back to the 1980s, where things are better. This video is emblematic of the form:

@nostalgia_vsh
let's go back 🥺 #lestgoback #nostalgia #nostalgic #childhood #80sbaby #2000s
♬ snowfall - Øneheart & reidenshi

In a typical ‘80s slop video, a teenager from the era tells the viewer that there’s no Instagram 40 years ago and everyone played outside until the street lights came on. “It’s all real here, no filters, no screens.” In another, two women eat pizza in a mall and talk about how terrible the future will be. “I bet your malls don’t feel alive in 2025,” one says.

These videos, like a lot of AI slop, do not try to hide that they are AI generated, and show that there is unfortunately a market for people endlessly scrolling social media looking to astral project themselves into a hallucinatory past that never existed. This is Mark Zuckerberg’s fucked up metaverse, living here and now on Mark Zuckerberg’s AI slop app.
playlist.megaphone.fm?p=TBIEA2…
The most popular current ones focus on 1980s nostalgia, but there are accounts that focus on the 70s, 90s, and early 2000s. These differ from standard internet nostalgia, which has been popular for many years—from BuzzFeed’s “Only 90s kids will remember this” listicles to “look at this old tech” Instagram accounts, the popularity of emo nights, “When We Were Young” music festivals—because they are primarily about aggrandizing a past that never existed or that was only good for specific segments of society.

These videos are awful AI-generated slop, yes, but it’s more than that. Reactionary nostalgia, a desire to return to a fake past or a time when you were young and things were better, is part of why the world is so fucked right now. It is, literally, the basis of MAGA. Worse, these videos about the “past” tell us a lot about our present and future: one where AI encourages our worst impulses and allows users to escape from reality into a slopified world that narrowly targets whatever reality we’d like to burrow into without dealing with the problems of the present.

1980s slop nostalgia is particularly popular at the moment, with these fake videos boomerfying Gen Xers and elder millennials in real time, though such nostalgia is coming for us all, and nostalgia for earlier releases of Roblox and Call of Duty—the ancient days of, like, 2021—are already going viral. It’s normal to look back at the time when you were young and your knees didn’t hurt with rose tinted glasses. It’s as if a generation read Ready Player One as an instruction manual instead of a warning (or instead of vapid surface-level nonsense that was one long reference rather than a coherent narrative).

These AI-generated slop videos are the latest expression of a common political theme: nostalgia for an imagined past. Dissatisfaction with the current moment is a normal reaction to the horrifying conditions under which we all live. The National Guard is occupying Washington DC, technology is dividing and surveling us in ways we never imagined, and our political leaders are feckless and corrupt. If you aren’t disturbed by where we are right now, you’re not paying attention.

A rejection of modernity and a call to return to the past has long been a feature of authoritarian and fascist political movements. So when we see an AI generated woman in stonewashed denim with hair by Aqua Net White tell us how good things were 40 years ago, we remember the political figures from the Reagan-era calling for a return to the 1950s.

Nostalgia is a poisonous political force. Things were not better “back then,” they were just different. Often they were worse. These 1980s AI slop videos have the same energy as online right weirdos with Roman bust avatars calling for us to “retvrn” and “embrace tradition.” Their political project uses the aesthetic of the past to sell a future where minorities are marginalized, women have no political power, and white guys are in charge. That’s how they think it all worked in the past and they’d love for it to happen again.

The ‘80s AI slop videos have a sinister air beyond their invocation of reactionary politics. “Dude, it’s 1985 and the release of the film The Goonies. Forget 2025 and come here. We want you here,” a strong-jawed white guy asks from his front lawn while a slowed down and distorted version of Aquatic Ambience from Donkey Kong Country plays. “Come to 1985, I miss ya,” a young man with feathered hair says in the back of a pickup truck as the sun sets. The surreal nature of these videos, this bizarre ask to time travel to the past, has cultish just-drink-the-Kool-Aid vibes.

What is the ask here, exactly? What does it mean for someone with dreams of an imagined past to go back to the 1980s where these ghoulish AI-crafted simulacrums dwell? In the Black Mirror episode San Junipero, Mackenzie Davis finds comfort in a simulation of a stereotypical 1980s southern California town. She loses herself in the fantasy. She’s also dying. For her, heaven was a place on earth, a data center where she could live until someone turned the lights off.

Those viewing these endless AI-generated TikToks and Reels are, however, very much alive. They can go outside. They can put the phone down and get to know their neighbors. They don’t have to doom scroll. They can log off and work for a better world in their community. They can reach out to an old friend or make new ones.Or they can load up another short form video and fill themselves with fuzzy feelings about how much better things were 40 years ago, back before all this technology, back when they were young, and where they think the world seemed to make more sense. AI allows us to sink into that nostalgic feeling. We have the technology, right now, to form digital wombs from a comforting and misremembered past.

It is worth mentioning that the people making these videos are also human beings with agency and goals, too. And their goals, universally, are to spam the internet for the purposes of making money. Over in the Discord communities where people talk about what types of AI slop works on social media, “nostalgia” is treated as a popular, moneymaking niche like any other. “Any EDITOR that can make Nostalgia videos?” one message we saw reads. “Need video editor to for nostalgia welcome back to 20xx videos.”

“Some ideas i got right now are nostalgia, money motivation, self improvement and maybe streamer clips,” another says.

A top purveyor of this nostalgia slop is the Instagram account “purestnostalgia,” which is full of these videos. That account is run by a guy named Josh Crowe who looks to be in his 20s and claims to live in Bali: “In the process of becoming a billionaire,” his profile reads.


in reply to Shamber

My take on boomerifying is getting other generations to behave like the stereotypical boomer, not that they are actual boomers by birthday.
in reply to Pulptastic

I agree with you, but it is a lot like Boomers calling everyone younger a Millenial.


Our Channel Could Be Deleted - Gamers Nexus


in reply to rustyredox

The actual title of the video is:

Our GPU Black Market Documentary Has Been Taken Down by Bloomberg


Way less Click Bait sounding. And while a shitty thing for Bloomberg to do it is not any different than what tons of channels have been dealing with for years. So the Youtube sky is not falling any faster now than it was last week.

in reply to flop_leash_973

It's not uncommon for titles to change over the first few hours after a release (A-B testing). I've seen the title as posted by the OP yesterday on my feed.


Google will require developer verification for Android apps outside the Play Store


Starting next year, Google will begin to verify the identities of developers distributing their apps on Android devices, not just those who distribute via the Play Store.
in reply to Mas

I sent Apple to hell because of dumb "you can't change UI to your liking", guess Google is next

*yes, this was seen miles away. I work with a laptop most of the time, so phone doesn't matter much for me, apart of a box that rings a few times a year

**Yes, both companies are run by greedy dumbfucks. I am getting tired and angry that finding companies that are different takes actual dedication. It should not be this way


in reply to Tony Bark

Gross politics and implications aside and just speaking as a full-stack, I’m curious if this would replace USWDS or overhaul it. Probably replace knowing these guys.
Questa voce è stata modificata (1 settimana fa)






in reply to tfowinder

"The seven-year-old startup, incubated at IIT Kanpur, has developed a proprietary zinc-bromine-based battery system as an alternative to lithium-ion technology. Called ZincGel, it delivers 80–90% of the energy efficiency of conventional lithium batteries, but at a significantly lower levelized cost of storage, the startup said."


KEA: ”En Gazao la afero estas tre klara kaj akuta”

Kataluna Esperanto-Asocio en aŭgusto faris oficialan komunikon pri la situacio en Gazao, kun la titolo ”Ĉesigu la genocidon”. Libera Folio petis la prezidanton de KEA klarigi, kial la asocio decidis fari deklaron ĝuste pri Gazao, sed ne ekzemple pri la milito en Ukrainio, kiu rekte tuŝas multajn esperantistojn.

liberafolio.org/2025/09/02/kea…



What is the URL for AudioBookBay?


As the title says, I was wondering what the URL is for AudioBookBay. Is it the one that ends in ".lu" ?
in reply to N.E.P.T.R

Seems to be. I like using fmhy.pages.dev to check things like what domain is correct:

fmhy.pages.dev/beginners-guide…

in reply to SqueakySpider

Hey I have a question if you don't mind, fmhy.pages.dev the same as fmhy.net?
Questa voce è stata modificata (4 giorni fa)
in reply to pugnaciousfarter

I believe so - I never know which is the "right" domain- if there is a right domain.
in reply to pugnaciousfarter

pages.dev is a Cloudflare domain. While they resolve to different IPv6 addresses, it still seems likely they point to the same hosted source - pages.dev being the Cloudflare host subdomain from the hoster and fmhy.net being a separate domain pointing to the same thing.




Republicans voted against independent redistricting in 2021




Sports Piracy in 3D


Has anyone here checked the 3D live in the usopen.org page?
usopen.org/en_US/scores/

I must say I was impressed. It is not perfect, but if what you to want to watch is just the sport being played, it might very well meet your needs. Add a little sound to it and I could watch a whole tennis match that way.

That made me think how one could convert any sports event to 3D and stream it. I don't know how many cameras IBM uses for that 3D stream, but a handful of volunteers recording the game with their phones and uploading it to a server that would process it could, in theory, generate a 3D version of the match. Maybe even the cameras of the official stream itself could be enough to create this.

The best part of this is that the 3D stream would be untraceable. It can't be watermarked, it's just the movement of the players and the ball, nothing else. And it also would have a ridiculously low bit rate. You could watch a match in 4K using a 100 kbps stream. You could even customize the assets to remove ads and make the players wear the uniform of your choice.

I'm probably dreaming too much, but a man can dream, right?

in reply to Joejoe582

Usually at these events there are staff who constantly look around for people who might be recording, and they don’t hesitate to kick you out if you’re caught more than once. So it’s possible if you have a decent number of people who are good about being sneaky and have covert equipment, but not easy.

It makes you wonder what will happen when more people start wearing smart AR glasses that can record everything and barely look any different than regular glasses.



How to use PeerTube for Podcasting


Created a guide over the weekend on hosting a podcast with PeerTube. Going with Spotify/YouTube is tempting for many, but they may not have realized how easy/affordable PeerTube has become for hosting and maintaining complete control of a feed.
Questa voce è stata modificata (5 giorni fa)

reshared this

in reply to Paige

So .. I've been making a weekly podcast for over 14 years. For all that time I've had complete control over my own content by hosting all the audio, the transcripts, the website and the RSS feeds on an AWS S3 bucket for a couple of dollars per month.

I submitted the RSS feed to several aggregators like iTunes, Spotify, YouTube and others. There's eBooks, I send out weekly email, post on Mastodon and Lemmy (previously on Xitter and Reddit) and it's included in other podcasts, news broadcasts and magazines.

How is adding PeerTube adding anything except more cost to me? What is the benefit of this that goes beyond people using their preferred podcast player downloading the audio from my own existing platform?

in reply to Onno (VK6FLAB)

I perfectly agree, RSS has always worked, and is federated, in a better way than even activitypub, as pretty much each podcast is on the servers of the owners, and that the clients do the aggregation.
in reply to int32

If you actually read the OP, PeerTube podcasts are ALSO distributed via RSS.
in reply to Onno (VK6FLAB)

It adds video. If you don't care about video, and you already have a system that works, it's probably not for you.

If potentially a new person wanted somewhere to host a podcast, they could do that using PeerTube. Along with all the other video services it offers.

in reply to Onno (VK6FLAB)

This guide outlines how to start a podcast for people who are already running PeerTube.
in reply to Paige

Hello Paige Saunders! I'm a big fan you smarmy kiwi yimby.
Questa voce è stata modificata (4 giorni fa)


Nadler, Pillar of Democratic Party’s Old Guard, Will Retire Next Year


In a recent interview in his downtown Manhattan office, Mr. Nadler, 78, said he hesitated to step aside when he believes that President Trump is threatening the foundations of democracy. But he said he had been persuaded it was time for a changing of the guard.

https://www.nytimes.com/2025/09/01/nyregion/jerrold-nadler-congress-retires.html?unlocked_article_code=1.ik8.mNVO.nNHc5LziH6oQ



A Compact for American Workers to Share This Labor Day





Leda Battisti – Sole, mare, e vento


“L’AIDS ti batte – è velenosa morte”

odesli.co/embed/?url=https%3A%…

#nowplaying #musica #ironia #satira #FediRadio #UnoRadio

in reply to anagrams

il programma usato per condividere post dai client mastodon a WordPress, Non prende i content warning e non prende i link... Altro bug su "enable mastodon apps" plugin WordPress.

Leda Battisti - sole, mare, e vento

LINK:

song.link/it/i/1816126735

#NowPlaying #musica #FediRadio #UnoRadio

Questa voce è stata modificata (5 giorni fa)

in reply to ☆ Yσɠƚԋσʂ ☆

Good, he's not US based.

Dominick Skinner, a Netherlands-based immigration activist, estimates he and a group of volunteers have publicly identified at least 20 ICE officials recorded wearing masks during arrests. He told POLITICO his experts are “able to reveal a face using AI, if they have 35 percent or more of the face visible.”
in reply to ☆ Yσɠƚԋσʂ ☆

"Some Democrats concerned about the masking are pushing for regulations to make it easier to identify law enforcement officials — but they still say they’re uneasy that vigilante campaigns have begun using technology to do it."

Luckily we have Dems clutching their pearls because people have taken action.



in reply to faythofdragons

The closest we can get to that in reality is Singapore. They have built buildings convered with green plants. So far, it had been cost efficient way to cool buildings during summer.



Who is dab.yeet.su


This is such a great music service but I'm wondering who is behind it and why they provide it? It must be costing them something to host the site. Interesting that Cloudflare stats show its biggest user base is India.
in reply to 10x10

It must be costing them


From their Terms:

DAB Music Player does not host any copyrighted content. Our Service acts as a search and streaming interface that connects to publicly available APIs. We do not store or distribute copyrighted material.


When you open the Webbrowser Developer Tools, Network tab, you can see where it streams from.

When I check on a song, it streams it from a CDN of qobuz (qobuz.com).

in reply to Kissaki

I was thinking of the cost of hosting the site rather than paying for the media. Thanks thoigh for the comment about checking the stream source.



[PDF] Over 16,000 compromised servers uncovered using Secure Shell key probing method


cross-posted from: programming.dev/post/36708596

Main.
Attackers regularly use SSH (Secure SHell) to compromise systems, e.g., via brute-force attacks, establishing persistence by deploying SSH public keys. This ranges from IoT botnets like Mirai, over loader and dropper systems, to the back-ends of malicious operations. Identifying compromised systems at the Internet scale would be a major break-through for combatting malicious activity by enabling targeted clean-up efforts.

In this paper, we present a method to identify compromised SSH servers at scale. For this, we use SSH's behavior to only send a challenge during public key authentication, to check if the key is present on the system. Our technique neither allows us to access compromised systems (unlike, e.g., testing known attacker passwords), nor does it require access for auditing.

With our methodology used at an Internet-wide scan, we identify more than 21,700 unique systems (1,649 ASes, 144 countries) where attackers installed at least one of 52 verified malicious keys provided by a threat intelligence company, including critical Internet infrastructure. Furthermore, we find new context on the activities of malicious campaigns like, e.g., the 'fritzfrog' IoT botnet, malicious actors like 'teamtnt', and even the presence of state-actor associated keys within sensitive ASes. Comparing to honeypot data, we find these to under-/over-represent attackers' activity, even underestimating some APTs' activities. Finally, we collaborate with a national CSIRT and the Shadowserver Foundation to notify and remediate compromised systems. We run our measurements continuously and automatically share notifications.




[PDF] Over 16,000 compromised servers uncovered using Secure Shell key probing method


Main.

Attackers regularly use SSH (Secure SHell) to compromise systems, e.g., via brute-force attacks, establishing persistence by deploying SSH public keys. This ranges from IoT botnets like Mirai, over loader and dropper systems, to the back-ends of malicious operations. Identifying compromised systems at the Internet scale would be a major break-through for combatting malicious activity by enabling targeted clean-up efforts.

In this paper, we present a method to identify compromised SSH servers at scale. For this, we use SSH's behavior to only send a challenge during public key authentication, to check if the key is present on the system. Our technique neither allows us to access compromised systems (unlike, e.g., testing known attacker passwords), nor does it require access for auditing.

With our methodology used at an Internet-wide scan, we identify more than 21,700 unique systems (1,649 ASes, 144 countries) where attackers installed at least one of 52 verified malicious keys provided by a threat intelligence company, including critical Internet infrastructure. Furthermore, we find new context on the activities of malicious campaigns like, e.g., the 'fritzfrog' IoT botnet, malicious actors like 'teamtnt', and even the presence of state-actor associated keys within sensitive ASes. Comparing to honeypot data, we find these to under-/over-represent attackers' activity, even underestimating some APTs' activities. Finally, we collaborate with a national CSIRT and the Shadowserver Foundation to notify and remediate compromised systems. We run our measurements continuously and automatically share notifications.





[PDF] Over 16,000 compromised servers uncovered using Secure Shell key probing method


cross-posted from: programming.dev/post/36708596

Main.
Attackers regularly use SSH (Secure SHell) to compromise systems, e.g., via brute-force attacks, establishing persistence by deploying SSH public keys. This ranges from IoT botnets like Mirai, over loader and dropper systems, to the back-ends of malicious operations. Identifying compromised systems at the Internet scale would be a major break-through for combatting malicious activity by enabling targeted clean-up efforts.

In this paper, we present a method to identify compromised SSH servers at scale. For this, we use SSH's behavior to only send a challenge during public key authentication, to check if the key is present on the system. Our technique neither allows us to access compromised systems (unlike, e.g., testing known attacker passwords), nor does it require access for auditing.

With our methodology used at an Internet-wide scan, we identify more than 21,700 unique systems (1,649 ASes, 144 countries) where attackers installed at least one of 52 verified malicious keys provided by a threat intelligence company, including critical Internet infrastructure. Furthermore, we find new context on the activities of malicious campaigns like, e.g., the 'fritzfrog' IoT botnet, malicious actors like 'teamtnt', and even the presence of state-actor associated keys within sensitive ASes. Comparing to honeypot data, we find these to under-/over-represent attackers' activity, even underestimating some APTs' activities. Finally, we collaborate with a national CSIRT and the Shadowserver Foundation to notify and remediate compromised systems. We run our measurements continuously and automatically share notifications.




[PDF] Over 16,000 compromised servers uncovered using Secure Shell key probing method


Main.

Attackers regularly use SSH (Secure SHell) to compromise systems, e.g., via brute-force attacks, establishing persistence by deploying SSH public keys. This ranges from IoT botnets like Mirai, over loader and dropper systems, to the back-ends of malicious operations. Identifying compromised systems at the Internet scale would be a major break-through for combatting malicious activity by enabling targeted clean-up efforts.

In this paper, we present a method to identify compromised SSH servers at scale. For this, we use SSH's behavior to only send a challenge during public key authentication, to check if the key is present on the system. Our technique neither allows us to access compromised systems (unlike, e.g., testing known attacker passwords), nor does it require access for auditing.

With our methodology used at an Internet-wide scan, we identify more than 21,700 unique systems (1,649 ASes, 144 countries) where attackers installed at least one of 52 verified malicious keys provided by a threat intelligence company, including critical Internet infrastructure. Furthermore, we find new context on the activities of malicious campaigns like, e.g., the 'fritzfrog' IoT botnet, malicious actors like 'teamtnt', and even the presence of state-actor associated keys within sensitive ASes. Comparing to honeypot data, we find these to under-/over-represent attackers' activity, even underestimating some APTs' activities. Finally, we collaborate with a national CSIRT and the Shadowserver Foundation to notify and remediate compromised systems. We run our measurements continuously and automatically share notifications.






In the heart of the Miccosukee, the Native American tribe that shut down Alligator Alcatraz


But the Miccosukee don’t oppose the detention center just because it’s “a showcase of cruelty.” For decades, the tribe has been at the center of several legal disputes that have set precedents for how U.S. courts interpret tribal sovereignty, environmental law, and the taxation of Native Americans. In 1982, for example, the tribe sued the state of Florida for illegal land grabs, resulting in the Florida Indian Land Claims Settlement Act, a law that extinguished land claims in exchange for thousands of acres held in trust. In 2004, they challenged Miami’s pumping of sewage into the Everglades, a case that highlighted the Miccosukee’s role in defending the ecosystem and influenced the national debate on water transfers.

Water has been the focus of many of their conservation efforts. The fragile ecosystem has been altered since the last century by urbanization and agriculture, particularly by the diversion of water from its natural course from Lake Okeechobee, north of the peninsula, to Florida Bay, a process that can take months or years.



"Go to" link for comments stops working when a post has a lot of comments?


For posts that receive a lot comments, e.g. 50~100+

When I turn on notifications for a post, I receive the notifications for new comments but the "Go to" link just takes me to the top of the post, not to the specific comment. (Same problem in both Zen/Firefox browser on computer and Firefox/PWA on Android.)

E.g. piefed.social/notification/115…

Is this just me?

Questa voce è stata modificata (5 giorni fa)
in reply to klu9

Ah.

I fixed this for one type of reply but missed out a different one. It's fixed for all future notifications, now.



Falliscono i colloqui per il trattato globale sull'inquinamento da plastica


Dopo 11 giorni di negoziati a Ginevra, i delegati di 184 nazioni non sono riusciti a trovare un accordo su un trattato giuridicamente vincolante per affrontare la crisi globale della plastica.

I punti di disaccordo principali sono stati:

Limitazione della produzione: profonda spaccatura tra chi chiedeva limiti vincolanti alla produzione di nuova plastica e chi si opponeva.

Controlli chimici: stallo sull'imposizione di regole globali per le sostanze chimiche tossiche usate nella produzione.

Finanziamento: nessun consenso su come finanziare l'attuazione del trattato, specialmente per i paesi in via di sviluppo.

La ministra francese per la transizione ecologica, Agnès Pannier-Runacher, si è detta "arrabbiatissima" per la mancanza di risultati tangibili, sottolineando che "la plastica uccide". Il delegato della Colombia ha accusato "un piccolo numero di stati" di aver bloccato l'accordo, in un apparente riferimento alle nazioni produttrici di petrolio che spingevano per focalizzarsi solo sul riciclo e non sulla riduzione della produzione.

I colloqui sono sospesi e dovrebbero riprendere in futuro, ma il fallimento ritarda una cruciale soluzione coordinata alla crisi.

Perché riguarda anche la moda?

Il poliestere è plastica. Questo trattato avrebbe avuto un impatto diretto sull'industria della moda, regolamentando le sostanze chimiche tossiche e la produzione della fibra sintetica più utilizzata dal fast fashion.

(Fonti: Reuters, The Guardian)

Il fallimento ritarda una cruciale soluzione coordinata alla crisi.

Se vuoi approfondire / If you want to know more:

🇮🇹 🔗 Leggi qui.

🇬🇧 🔗 Read more here

reshared this



Esperanto malpermesita en Esperanto-kongreso

En kiu lingvo oni parolu en nacia Esperanto-aranĝo? La demando estas same malnova kiel la organizita Esperanto-movado. Ofte oni plendas pri troa krokodilado en la nacia lingvo, sed en la ĵusa asembleo de Itala-Esperanto okazis male: oni oficiale malpermesis al la vicprezidanto de la asocio paroli en Esperanto.

liberafolio.org/2025/09/01/esp…

Questa voce è stata modificata (5 giorni fa)
in reply to Verda Majorano ⁂

@VM Evidente la ĉefa parto de la programeroj ja estis en Esperanto. (En la artikolo estas ligilo al la programo de la kongreso.) La malpermeso paroli en Esperanto okazis dum la asembleo de Itala Esperanto-Federacio, kiu estis nur malgranda parto de la kongreso.
in reply to Libera Folio

Bone, mi komprenas, do nur dum la parto rezervita por la anoj de la itala asocio oni ne parolis Esperante.

Mi iel misinterpretis la vortojn «En la tuta kunveno ĝis tiam estis nur intervenoj en la itala, kun pluraj eksterlandanoj kiuj foriris iel malĝojaj.»

Nun mi komprenas ke per kunveno oni nur celis indiki la asembleo de la asocio, kiu, kredeble, ne havas multaj eksterlandajn anojn.




States fast-track wind, solar permits and contracts to beat Trump’s deadline • North Dakota Monitor


Federal clean energy tax credits have been essential to the financing of wind and solar projects across the country, and a key part of states’ plans to transition to wind and solar power.

Following President Donald Trump’s moves to quickly phase out those credits, pending projects have a tight time frame to start construction before their eligibility expires. But states have long struggled to speed up permitting decisions, reduce regulatory hurdles and add new power to the grid. And the clock is running out.

“Every month counts,” said Patty O’Keefe, Midwest regional director at Vote Solar, a clean energy advocacy nonprofit. “[The tax credits] are the financial backbone of nearly every renewable energy project that’s currently in the pipeline.”

https://northdakotamonitor.com/2025/08/31/states-fast-track-wind-solar-permits-and-contracts-to-beat-trumps-deadline/



Social Security whistleblower who claims DOGE mishandled Americans' sensitive data resigns from post


Charles Borges, the agency's chief data officer, alleged that more than 300 million Americans’ Social Security data was put at risk by DOGE officials who uploaded sensitive information to a cloud account not subject to oversight. His disclosure was submitted to the special counsel’s office on Tuesday.

“After reporting internally to management and externally to regulators, serious data and security and integrity concerns impacting our citizens’ most sensitive personal data, I have suffered exclusion, isolation, internal strife, and a culture of fear, creating a hostile work environment and making work conditions intolerable,” Borges added.

The Government Accountability Project, which is representing him in his whistleblower case, posted Borges' resignation letter on its website Friday evening. Borges declined to comment.

“He no longer felt that he could continue to work for the Social Security Administration in good conscience, given what he had witnessed,” his attorney Andrea Meza said in a statement. She added that Borges would continue to work with the proper oversight bodies on the matter.



House committee investigating the Jeffrey Epstein case has withdrawn a subpoena to Robert Mueller due to his health


The New York Times, citing a statement from Mueller's family and people close to him, reported Sunday night that Mueller had been diagnosed with Parkinson's disease in the summer of 2021 and has had difficulty speaking.


Report: Apple Demands Suppliers Switch to Robotics for Manufacturing


Apple's alleged automation mandate spans all major product categories, including the iPhone, iPad, Mac, and Apple Watch. Apple now purportedly expects suppliers to fund their own automation upgrades rather than rely on Apple to finance or subsidize the necessary capital equipment. This policy change diverges from Apple's previous approach, where the company frequently invested in tooling and machinery for contract manufacturers to meet its specifications.
#tech


We Deserve Way, Way More Time Off


There is much more to life than work. We all have families, friends, and a beautiful world to enjoy. We need more time off to enjoy it.


California’s Democratic governor leads the charge in expanding state repression


On August 28 and 29, California Governor Gavin Newsom unveiled two sweeping initiatives that together mark a sharp rightward turn in state policy and expose the Democratic Party’s deepening complicity in the destruction of democratic rights. As he portrays himself as a bulwark against President Trump, Newsom is in fact laying the foundation for a massive expansion of state power against the working class and the poor.

Under the guise of public safety and compassion, the Democratic governor has placed the California Highway Patrol (CHP) at the center of two major new enforcement regimes: a statewide “crime suppression” expansion and a “homeless encampment clearance” task force.

These measures are being marketed as alternatives to Trump’s deployments of federal forces into major U.S. cities, but in substance, they mirror their basic functions. Far from opposing the authoritarian measures emanating from Washington, Newsom’s actions mimic them, signaling a growing alignment between the Democratic Party and the Trump administration on the fundamental issue: the use of state repression to deal with the social crisis created by capitalism.



I setup a Mastodon relay - anyone want to help me test?


I setup a Mastodon relay - anyone want to help me test by adding it to their instance? Would help me know if the "Recent jobs" stat is working (I think it requires 2 instances at minimum to show jobs) and if adding to instances (outside of my own) is working properly and how traffic looks.


We are stopping shipments to the US - Kiwix


Guess why...

reshared this