A new security fund opens up to help protect the fediverse
A new security fund opens up to help protect the fediverse | TechCrunch
A new security fund aims to help apps in the fediverse — like Mastodon, Threads, and Pixelfed — to pay researchers for disclosing security bugs.Sarah Perez (TechCrunch)
like this
Mammals were living on the ground several million years before the mass extinction
Mammals were living on the ground several million years before the mass extinction
More mammals were living on the ground several million years before the mass extinction event that wiped out the dinosaurs.Pranjal Malewar (Tech Explorist)
Toward the end of the Cretaceous, flowering plants (angiosperms) transformed ground habitats, making them more diverse. While it was known that tree-dwelling mammals faced challenges after the impact of the asteroid, it wasn’t clear if mammals adapted by becoming more ground-based. Earlier research primarily analyzed complete skeletons to study how ancient mammals moved.A recent University of Bristol study reveals that many mammals were transitioning to a ground-based lifestyle before the asteroid’s impact. By analyzing small bone fragments—an approach never used to study whole communities—the researchers examined fossils from museums in New York, California, and Calgary. Their findings show that a significant shift toward ground-dwelling occurred several million years before the mass extinction that ended the age of dinosaurs.
Why crocodiles have changed so little since the age of the dinosaurs?
New research by scientists at the University of Bristol explains how a ‘stop-start’ pattern of evolution, governed by environmental change, could explain why crocodiles have changed so little since the age of the dinosaurs.Pranjal Malewar (Tech Explorist)
A new security fund opens up to help protect the fediverse
A new security fund opens up to help protect the fediverse | TechCrunch
A new security fund aims to help apps in the fediverse — like Mastodon, Threads, and Pixelfed — to pay researchers for disclosing security bugs.Sarah Perez (TechCrunch)
like this
A new security fund opens up to help protect the fediverse | TechCrunch
Sarah Perez
4–5 minutes
The fediverse, also known as the open social web that includes Mastodon, Meta’s Threads, Pixelfed, and other apps, is ramping up its security. On Wednesday, a nonprofit focused on bringing governance to open source projects, the Nivenly Foundation, announced the launch of a new security fund that will pay those who responsibly disclose security vulnerabilities that affect fediverse apps and services.
While all software can have security issues, Mastodon — an open source and decentralized alternative to X — has fixed numerous bugs over the years, leading to the need for such a program. Another issue found in the fediverse is that many servers are run by independent operators who don’t necessarily have a security background or understand best practices.
Already, the Nivenly Foundation has helped a few fediverse projects set up their basic security vulnerability reporting process, and now it’s looking to distribute small payouts to anyone who responsibly discloses other security vulnerabilities that may still be in the wild.
The payouts will total $250 for vulnerabilities with a vulnerability severity score (known as CVSS) of 7.0-8.9 and $500 for more critical vulnerabilities with a CVSS score of 9.0 or greater. The funds for the payouts come from the foundation, which is supported directly by members — which includes individuals as well as other trade organizations.
The vulnerabilities themselves are validated by acceptance from the fediverse project leads as well as public records in vulnerability disclosure (CVE) databases.
The fund is currently in a limited trial after the discovery of a security vulnerability in the decentralized Instagram alternative, Pixelfed. Open source contributor Emelia Smith came across the issue, and the Nivenly Foundation paid her to fix it, she explains.
A more recent issue came about when Pixelfed’s creator, Daniel Supernault made the details of a vulnerability public before server operators had a chance to update, which would have left the fediverse vulnerable to bad actors, she says. (Supernault has already apologized publicly for his handling of the issue that had affected private accounts.)
“Part of the program is…education for project leads, helping them understand why responsible disclosure practices for security vulnerabilities are important,” Smith told TechCrunch. “We came across several projects that just said ‘file security vulnerabilities in our public issue tracker,’ which absolutely isn’t safe, as any malicious actor watching that repository would now be able to attack instances of that software,” she added.
Typically, the common practice is to disclose minimal information about a vulnerability, giving server operators time to upgrade, Smith said. However, this requires that project leads understand security best practices.
In the case of the Pixelfed issue, for instance, the Hachyderm Mastodon server, which has over 9,500 members, decided it needed to defederate (or disconnect from) other Pixelfed servers that hadn’t been updated in order to protect their users.
With this new program designed to follow best practices around the disclosure of vulnerabilities, the need to defederate to protect users may become less common.
Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software.
[VEGER V0567] Miglior Power Bank per iPhone e Android con CAVO LIGHTNING INTEGRATO
Recensione VEGER V0567 Power Bank per iPhone e Android con CAVO LIGHTNING INTEGRATO 5000mAh 20W PD
Ritorniamo a parlare di accessori e power bank portatili , strumenti indispensabili per chi è sempre in movimento e ha bisogno di una fonte ...Tecnolovez (Blogger)
About - Tayto
https://www.tayto.com/wp-content/uploads/2022/05/Craic.mp4OUR STORY Founded by Thomas Hutchinson in 1956, our family owned business selects the finest potatoes and uses local ingredients to produce great tasting crisps and snacks for everyone to enjo…Tayto
sfaldamento universitario con il tempo rinstranito
Oggi è come se il piano di realtà a me circostante si stesse lentamente, ma inesorabilmente, sfaldando, tutto ai miei danni. Purtroppo, anche questo, ossia il farmi dubitare del mio stesso stato di esistenza, è uno dei metodi con cui gli spiriti esercitano l’ingiusto trollaggio secolare su di me, e io altro non posso fare […]
"Pentagon in shock": China's next-gen stealth drones are now leagues ahead of DARPA's, says explosive new study
“Pentagon in shock”: China’s next-gen stealth drones are now leagues ahead of DARPA’s, says explosive new study
IN A NUTSHELL 🚀 China has reportedly outpaced the US in developing next-gen stealth drones with superior energy efficiency. 💡 The drones utilize dual synthetic jet (DSJ) technology, which eliminates traditional control surfaces for enhanced stealth.Vitaliy Soloviy (Sustainability Times)
like this
This was all Greek to me, and it took a while for me to figure out how to google WTF you’re talking about.
I'm not sure why any of this is surprising. The US was perfectly fine letting China manufacture all the things. That manufacturing know-how leads to design know-how. The desire by US corporations to keep wages low or eliminate US labor entirely to use outsourced manufacturing leads to this.
It isn't just military hardware: it is products across entire industries. China is producing good ones, and even when they aren't, they're producing them at volumes the US could not dream of touching.
like this
And in the meantime Trump is destroying America at a record pace.
America is gonna blink and then China will be miles ahead.
Ukraine's NATO membership not included, never was in minerals deal, Zelensky says
"As for this agreement and the NATO question, there is no mention of NATO in this agreement, and there never was," President Volodymyr Zelensky said on April 1.
Archived version: archive.is/newest/kyivindepend…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Italy slams door on people hoping to claim citizenship through great-grandparents
A great-grandparent from Italy used to be all it took to guarantee Italian citizenship. A surprise decree has now changed all that, making it much harder for those with Italian ancestry to use blood line as a pathway to become Italian.
Archived version: archive.is/newest/edition.cnn.…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Dorazio Verna e Casentini in mostra presso il Progetto Arte Elm
Dorazio Verna e Casentini in mostra presso il Progetto Arte Elm
La Felicità dei Colori: un dialogo tra maestri cromatici presso Progetto Arte Elm Il Progetto Arte ELM di Milano ospita fino al 30 maggio 20...Antonio Marano (Blogger)
Gulf states refuse to be launching pad for any US attacks against Iran
US decision to amass B-2 bombers at Diego Garcia is result of Gulf Arab monarchs closing airspace to American warplanes in event of war with Iran
Archived version: archive.is/20250402034454/midd…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Gulf states refuse to be launching pad for any US attacks against Iran
Saudi Arabia and other Gulf states have imposed a ban on US warplanes using their air fields or skies to attack Iran after US President Donald Trump over the weekend threatened to bomb the country.Sean Mathews (Middle East Eye)
CTV Cancelled a Fact-Checking Segment in Response to Political Pressure From Pierre Poilievre’s Conservatives
Audio recording shows CTV cancelled an ‘election misinformation’ segment with journalist Rachel Gilmore after online backlash from conservatives
More Russian assets frozen in Switzerland
The value of frozen Russian assets in Switzerland currently stands at CHF7.4 billion ($8.4 billion), the Swiss government announced on Tuesday.
Archived version: archive.is/newest/swissinfo.ch…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
US officials object to European push to buy weapons locally
U.S. officials have told European allies they want them to keep buying American-made arms, amid recent moves by the European Union to limit U.S. manufacturers' participation in weapons tenders, five sources familiar with the matter told Reuters
Archived version: archive.is/20250402111837/reut…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Norway urged to scrap ban on $1.8 trillion wealth fund investing in weapons makers
The debate over how Norway's wealth fund should respond to the security landscape comes at a time of higher defense spending and soaring industry profits.
Archived version: archive.is/newest/cnbc.com/202…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
China Restricts Companies From Investing in US as Tensions Rise
China has taken steps to restrict local companies from investing in the US, according to people familiar with the matter, in a move that could give Beijing more leverage for potential trade negotiations with the Trump administration.
Archived version: archive.is/20250402135836/bloo…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
framamemes: your french meme generator
cross-posted from: jlai.lu/post/17374352
Go check this little meme generator by framasoft, one of the french references of foss softwares and culture. Not much, just nice 😀The URL links to a presentation article in french - feel free to use a translator, and here is the direct link to framameme.
Enjoy!
publication croisée depuis : lemmy.world/post/27658670
Tout chaud sorti du four, framamemes est un generateur de meme rancais et libre !Plus d'infos ici si ca vous interesse : framablog.org/2025/04/01/frama…
Hate de voir vos creations 👌
lgsp@feddit.it likes this.
For information, Framasoft is a french non profit that fights really hard to protect our privacy rights and the right to free software.
They have a bunch of FOSS apps to replace some of the FAANG services, they're also the creators of PeerTube if I recall correctly.
Framasoft
Framasoft is a not-for-profit popular educational organization, a group of friends convinced that an emancipatory digital world is possible, convinced that it will arise through actual actions on real world and online with and for you!framasoft.org
Two Irish citizens ordered to leave Germany over pro-Palestinian protests despite no convictions
Lawyers say the move undermines civil liberties for EU citizens
Archived version: archive.is/20250401153959/iris…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Macron weighs in on Le Pen verdict for first time: ‘The law is the same for everyone’
French president adds that “threats made against judges are absolutely unbearable and intolerable.”
Archived version: archive.is/newest/politico.eu/…
Disclaimer: The article linked is from a single source with a single perspective. Make sure to cross-check information against multiple sources to get a comprehensive view on the situation.
Open Letter: Open-Source Chips for Europe
The European Chips Act has set ambitious goals and its implementation is a significant pan-european effort. From an academic perspective, last year we published an open letter emphasizing the critical importance of open-source EDA for academia in Europe. We were excited and grateful to see that this initiative triggered the definition of a European roadmap in this area, and a matching Chips JU call for project funding. We believe that the projects funded by this call will have a significant impact. Moreover, we already see rising interest from many EU stakeholders, with increasing investments into open-source chip design, especially in open source IP development (e.g. RISC-V cores), and open source EDA tools.One additional critical barrier remains toward the end-goal of building real open-source chips, especially for prototyping and education: namely, streamlining the access to open source chip production facilities (foundries) is essential. Programs like ChipIgnite, Tiny Tapeout and IHP’s open source program have become “guiding stars” that demonstrate that everyone with a computer can build chips. We believe that having low-cost, regular and easy access to chip production is critical to create excitement and build up expertise, widening the pool of chip designers with tape-out experience: a true silicon democratization and a further de-mystification of chip design.
Agenda Prep for April 2025 WG Meeting
Agenda preparation for the April ForumWG meeting can be found at this public link (anyone can make comments for review.)
Monthly meetings are held on the first Thursday of each month, at 13h00 to 14h00 Eastern Time (currently 17h00 to 18h00 UTC). You can find them listed in the SocialCG Calendar. The next meeting will be held on 3 April 2025.
We will be discussing:
- Review of brainstorm/whiteboarding session from March
- Context Ownership
- Brainstorm use cases/user stories
- Moving objects (between contexts) and moving contexts (between audiences)
- Relies on context ownership “FEP”
- Brainstorm use cases/user stories
- Support for multiple objects (forking)?
- Same origin only? Support moving objects/contexts between instances? Different FEP?
2025-04 Agenda
April 2025 Agenda Forum and Threaded Discussions Task Force Format Information gathering prior to the meeting will be held asynchronously via the fediverse, with topics posted on one of the following two locations: https://community.nodebb.Google Docs
like this
reshared this
Some notes for things I want to bring up regarding agenda items:
SIOC: Semantically Interlinked Online Communities as prior art
Predates ActivityPub, was submitted to the W3C, has evolved up until ~2018 in some form. Concepts that could be relevant for Forum TF work:
sioc:Item
is directly associated with a sioc:Container
, whereas as:Object
is included in an indirect list of items
within as:Collection
Containers vs Collections
For more on the difference between a Container and a Collection, see RDF Schema sections 5.1 and 5.2
A Container has open membership. There might always be more items in a container that are unknown:
<#Bag> <#red ball>.<#Bag> <#green ball>.<#Bag> <#blue ball>.# We do not know if the bag contains any other balls, such as a yellow ball.
A Collection can have closed membership. For example, Lists can be terminated with a nil element.
<#List> rdf:first <#A>.<#List> rdfs:rest rdf:nil.# We know that the list does not contain any more elements beyond A.
The way this is applied in SIOC is like so:
<#Item> sioc:has_container <#Container>.<#Container> sioc:container_of <#Item>.
The way this is applied in ActivityStreams is like so:
<#Collection> as:items (<#Item>).# There is no way to signal that the Item is part of the Collection, and it is not expected that collection items will expose links back to every single collection they are a part of.
sioc:UserAccount
, sioc:Post
, sioc:Thread
, sioc:Forum
, sioc:Site
- A Post
has_creator
UserAccount. - A Post
has_container
which can be directly a Forum, or it can be something like a Thread (which can itselfhas_container
of a Forum). - A Forum can
has_parent
of another Forum, if wishing to model subforums. - A Forum can
has_space
of a Space (like a desktop or file share), or in more concrete cases canhas_host
of a Site.
Mapping to AS2-Vocab?
If we roughly map this to AS2-Vocab we might get something like this:
@id: @type: [as:Person, sioc:UserAccount]@id: @type: [as:Person, sioc:UserAccount]@id: @type: [as:Note, sioc:Post]as:attributedTo: sioc:has_creator: as:content: "Hello"sioc:content: "Hello"as:context: sioc:has_container: @id: @type: [as:Collection, sioc:Thread] # caveat where as:Collection has spec issuesas:attributedTo: as:audience: # maybe?sioc:has_container: sioc:container_of: @id: @type: [as:Group, sioc:Forum]as:attributedTo: # i guess?sioc:has_moderator: sioc:has_host: @id: @type: [as:Service, sioc:Site] # idk about this onesioc:host_of:
Subtypes of forums and posts
From SIOC types module:
- Forum: ArgumentativeDiscussion, ChatChannel, MailingList, MessageBoard, Weblog.
- Post: BlogPost, BoardPost, Comment, InstantMessage, MailMessage, WikiArticle.
Protocol considerations
We probably want to separate eventually the idea of "i authored this" from "i have authority over this", especially if a forum "lives" somewhere on a host.
Comparison to NNTP / NetNews protocol / Usenet network
RFC 5536 defines an article format for sharing RFC 822/2822/5322 style Internet Messages with mandatory headers:
- Date (
as:published
) - From (
as:attributedTo
) - Message-ID (
@id
) - Newsgroups (
as:audience
??) - Path (no analogue, represents the path taken as the article is shared across newsgroups? so an ordered list of where it was shared/reshared from?)
- Subject (
as:name
oras:summary
, but probably not required for AP Forum TF)
RFC 5537 describes architecture for distributing such articles as Internet Messages:
- A "posting agent" passes an article to an "injecting agent"
- The "injecting agent" injects the article into a group
- A "reading agent" can then fetch articles from a group
RFC 3977 describes NNTP protocol:
<pre><code class="lang-auto"> Example of a successful posting: [C] POST [S] 340 Input article; end with <cr-lf>.<cr-lf> [C] From: "Demo User" <nobody@example.net> [C] Newsgroups: misc.test [C] Subject: I am just a test article [C] Organization: An Example Net [C] [C] This is just a test article. [C] . [S] 240 Article received OK Example of an unsuccessful posting: [C] POST [S] 340 Input article; end with <cr-lf>.<cr-lf> [C] From: "Demo User" <nobody@example.net> [C] Newsgroups: misc.test [C] Subject: I am just a test article [C] Organization: An Example Net [C] [C] This is just a test article. [C] . [S] 441 Posting failed Example of an attempt to post when posting is not allowed: [Initial connection set-up completed.] [S] 201 NNTP Service Ready, posting prohibited [C] POST [S] 440 Posting not permitted</nobody@example.net></cr-lf></cr-lf></nobody@example.net></cr-lf></cr-lf></code></pre>
We could probably do something with Announce and/or Offer or similar?
In a simple model where there are only groups and posts, no threads (a la FEP-1b12)
- Offer Note to Group
- Group can then accept/reject the post and issue an Announce?
Once we introduce threads, we will want to have more control not at the group level but at the thread level.
There is a bit of a philosophical question of approach here -- given that the core mechanism here is fundamentally notification messages via LDN (POST to inbox
), although it is arguable that Activity payloads gets used as a sort of JSON-RPC more than as a notification... should we therefore optimize for a notification-oriented flow or a more procedural flow instead?
In a notification flow, we just want some resource to be aware that we have made a new post, and they can then distribute it or not. Say something simple like this:
id: actor: type: Announceobject: to/cc/audience/bto/bcc: id: actor: type: Announceobject: audience: [, ]cc:
but instead of addressing or targeting you might instead address or target ? whichever application is listening to the thread's inbox then handles the cascade of distribution upward:
id: context: id: context: # ?audience: # ?attributedTo: followers: id: audience: followers: id: members: # extension property/collectionfollowers:
what is desired is roughly this:
- Announce to the
- the Announces to...
- ?
- ?
- the might also Announce to and to
the challenge is in avoiding duplicate traffic, so ideally this would be under the control of a single controller who issues a single Announce to the sum total of the accumulated audience:
id: actor: type: Announceobject: to/cc/audience/bto/bcc: # ... some chain of events later...actor: type: Announceobject: to/cc/audience/bto/bcc: - # - is already aware? - - - - - -
this is essentially an event driven architecture. you'd need to choose between "exactly once" and "at least once" delivery.
concerns:
- what ends up in
shares
collection? for a single share action, do we end up with multiple Announce activities in there? - who gets addressed? inbox forwarding? this probably shouldn't be the responsibility of to have to be aware of every single downstream/upstream recipient, right?
RDF 1.2 Schema
RDF Schema provides a data-modelling vocabulary for RDF data. RDF Schema is an extension of the basic RDF vocabulary.www.w3.org
like this
Re: Agenda Prep for April 2025 WG Meeting
like this
Nintendo Switch 2 details: Screen size, controllers, storage, microphone chat and games
Nintendo Switch 2 details: Price, screen size, controllers, microphone chat and games
Nintendo will launch game titles including "Mario Kart World" and "Street Fighter 6" alongside the new hardware.Kif Leswing (CNBC)
Luca likes this.
Judge dismisses criminal case against New York Mayor Eric Adams
Judge dismisses criminal case against New York Mayor Eric Adams
The Trump administration argued that indictment against Adams should be tossed to avoid affecting the mayor's ability to cooperate with immigration policies.Dan Mangan (CNBC)
A surgeon in China successfully removed a lung tumor from a patient located 5,000 km away
A surgeon in China successfully removed a lung tumor from a patient located 5,000 km away
A surgeon in China successfully removed a lung tumor from a patient located 5,000 km away by operating a robot remotely from Shanghai. The innovative procedure took place with the patient in the ci...Mes Numériques
C’mon we all know what this is: Remote Uyghur organ harvesting. /s
I swear they’re just flexing now. Next thing you know it’ll be autonomous robotic surgery on the Moon.
Tesla suffers worst quarter since 2022 as deliveries tumble
Tesla suffers worst quarter since 2022 as deliveries tumble
Company loses crown of world’s best-selling electric-vehicle maker to China’s BYDKana Inagaki (Financial Times)
Scrollone likes this.
E.P.A. Hunt for Shady Deals and ‘Gold Bars’ Comes Up Empty
E.P.A. Hunt for Shady Deals and ‘Gold Bars’ Comes Up Empty
The agency head said a $20 billion Biden climate program was marred by fraud and abuse. Documents filed for a court hearing this week don’t support that.Lisa Friedman (The New York Times)
Gli Erbari in mostra al Castello di Miradolo
Gli Erbari in mostra al Castello di Miradolo
La Magia degli Erbari conquista l'arte contemporanea: una mostra al Castello di Miradolo L'arte e la natura si incontrano al Castell...Antonio Marano (Blogger)
Introducing Fedora Project Leader Jef Spaleta - Fedora Magazine
Introducing Fedora Project Leader Jef Spaleta - Fedora Magazine
Hello everyone! Current Fedora Project Leader Matthew Miller here, with some exciting news! A little while ago, I announced that it’s time for a change of hats. I’m going to be moving on to new things (still close to Fedora, of course).Matthew Miller (Fedora Project)
Open Letter: Open-Source Chips for Europe
cross-posted from: lemmy.ml/post/28025426
The European Chips Act has set ambitious goals and its implementation is a significant pan-european effort. From an academic perspective, last year we published an open letter emphasizing the critical importance of open-source EDA for academia in Europe. We were excited and grateful to see that this initiative triggered the definition of a European roadmap in this area, and a matching Chips JU call for project funding. We believe that the projects funded by this call will have a significant impact. Moreover, we already see rising interest from many EU stakeholders, with increasing investments into open-source chip design, especially in open source IP development (e.g. RISC-V cores), and open source EDA tools.One additional critical barrier remains toward the end-goal of building real open-source chips, especially for prototyping and education: namely, streamlining the access to open source chip production facilities (foundries) is essential. Programs like ChipIgnite, Tiny Tapeout and IHP’s open source program have become “guiding stars” that demonstrate that everyone with a computer can build chips. We believe that having low-cost, regular and easy access to chip production is critical to create excitement and build up expertise, widening the pool of chip designers with tape-out experience: a true silicon democratization and a further de-mystification of chip design.
[solved] How to backup a bunch of blu-rays?
Seeing that DVD are slowly going end-of-live and that you can't buy a lot of my childhood favorites in german anymore and streams are compressed-to-death (and DRMed), i had a streak of preservia. Which is why i rip a bunch of discs from the library on Linux (yes, legally not ok, but morally just ease of access, i wouldn't sell them). Since it's only to watch them when nostalgia hits, i want them in a ready-to-watch format, chose AV1 webm for small size. My burner is LibreDrive-ok ootb, meaning makemkv goes automatically in that mode.
I have the discs for a limited time, so i used to use dvdbackup
for DVD and later feed the folder to handbrake for conversion. Now i got a bunch of blu-ray:
- ripping one takes even longer; whole 25 hours; i don't have the time for the whole LotR series with bonus disks.
makemkvcon backup
needs only about 2 hours per disk, but the resulting folder is 80 GB big; i have only about 250 GB free space
** and the makemkv backup somehow has no audio streams, while handbrake does
While i write this, handbrake is loading the chapters (that alone needs more than 1 hour for blu-ray); i'm trying if a lossless FFV1 mkv conversion (for later re-conversion) takes less long.
Now:
- Any better approach?
- Any way to fix makemkv having no audio? (i could juggle with external disks) I think i have all libraries and the KEYDB.cfg.
Edit: nope, handbrake suddenly has unable to decrypt unit (AACS)
like this
MakeMKV - Make MKV from Blu-ray and DVD
MakeMKV - software to convert blu-ray and dvd to mkvmakemkv.com
makemkvcon backup
command had missing audio, so i assumed, it was the case for the graphical interface too. But it works fine, about same speed and i just discovered, that you can open the resulting mkv on handbrake and choose audio channels and whatnot as if it was the disc itself. Only issue with duplicates (confirmed via video-compare
, great tool with dynamic move-mouse split) but that's what the checkmarks are for. I'll mark it as solved.
"Oh, well, that's because we currently have a fascist gov-"
The previous administration said the same thing.
FundMECFS
in reply to psychothumbs • • •PhilipTheBucket
in reply to FundMECFS • • •Yeah, there's also this:
It is weird to spend almost half the words in this, pretending that something in Pixelfed that wasn't a problem on Pixelfed's side was. This is the weirdest "vulnerability" in the world to pick if you want to pick one to hold up extensively as an example.
troed
in reply to PhilipTheBucket • • •PhilipTheBucket
in reply to troed • • •falseprophet likes this.
irelephant [he/him]🍭
in reply to PhilipTheBucket • • •Is any private post visible to people on servers that the poster doesn't have followers on?
Could I
curl
the uri of a post thats "private" and get the post's content?PhilipTheBucket
in reply to irelephant [he/him]🍭 • • •"Insecure" in this case simply means any server that doesn't implement Mastodon's custom handling for "private" posts. With that definition, the answer to your question is yes. It has been mentioned by Mastodon people that this is a significant problem for the ability to actually keep these private posts private in the real world. The chance of it going wrong is small (depending on your follower count) but the potential for harm is very large. I would therefore go further, and say that it's a very bad thing that Mastodon is telling people that these posts are "private" when the mechanism which is supposed to keep them private is so unreliable.
marrus-sh.github.io/mastodon-i…
github.com/mastodon/mastodon/i…
It is not. If you're sufficiently careful with approving your followers, making sure that each of them is on an instance that's going to handle private posts the way you expect, then you're probably fine.
If it's been federated to an insecure server then yes. If not then I think no.
custom federation levels (at the very least, for private posts) · Issue #712 · mastodon/mastodon
GitHubirelephant [he/him]🍭
in reply to PhilipTheBucket • • •Mastodon really is the internet explorer of the fediverse.
In any case, I don't think its that bad. I would compare it to an email provider accidentially leaking messages. Still bad, but its not a reason to abandon email as a means of communication.
We should encrypt posts, like diaspora does. Like how we should pgp encrypt emails, but no one will.
also, I just checked myself, a random "private" post I made isn't accessible over AP if I curl it unauthenticated.
Running
curl.exe https://calckey.world/notes/a63slz8j6l -H "Accept: application/activity+json"
returns nothing, but replacing the uri with a public post does show it.An insecure server's copy of the post isn't accessible over AP, only the original post's link should return anything.
Coelacanth
in reply to psychothumbs • • •Mention Lemmy for once 😠
irelephant [he/him]🍭
in reply to Coelacanth • • •r.EndTimes
in reply to irelephant [he/him]🍭 • • •irelephant [he/him]🍭
in reply to r.EndTimes • • •r.EndTimes
in reply to irelephant [he/him]🍭 • • •irelephant [he/him]🍭
in reply to r.EndTimes • • •cmgvd3lw
in reply to psychothumbs • • •FundMECFS likes this.
irelephant [he/him]🍭
in reply to cmgvd3lw • • •You cannot use a mastodon app as a lemmy client, but you can view lemmy communities by opening them as if they are profiles. For example, open @fediverse@lemmy.world and it will show up as a user, but it will be the communitiy's posts.
You can mention it in a post to forward the post to the community as well.
FundMECFS likes this.