Skip to main content

Gidi Kroon reshared this.


fun project idea: make a fake SCADA panel with an “Explode Facility” button, put it behind an unsecured VNC server, and then count how many times the exploding button is pressed

Gidi Kroon reshared this.




Gidi Kroon reshared this.


Tonight I'll be on the @SecurityWeekly podcast talking about DEF CON NEXT GEN!

Thats right, there is a track at DEF CON for your Jr. Hackers!

You should also follow @defconnextgen on all the platforms (defcon.social for you folks here on Mastodon)

Gidi Kroon reshared this.



Why would a K-pop star need to apologise that she has a boyfriend? Is the fandom so toxic that they can't accept her finding happiness outside of them? Apparently it is and she had to give in to that pressure.

Gidi Kroon reshared this.


if kde plasma is so cool why isn’t it kde gas or kde liquid or kde solid
This entry was edited (8 months ago)

Gidi Kroon reshared this.



I don't like bully culture.

Also, sites and software should not show remote content to unauthenticated visitors. You'll become an open proxy to unwanted material. I don't understand that so much fediverse software still does this.

And unauthenticated visitors should not be able to load anything onto your site, not even in a cache. These open search boxes on so many fediverse servers are a bad idea, as they load profiles and posts outside the control or knowledge of moderators.

If so much fediverse software and servers give a bad example, is it so weird newcomers make these mistakes?


It turns out, if people in an online community really don’t like what you’re doing, they can turn to harassment, threats, or worse to try to shut you down.

wedistribute.org/2024/03/conte…



Gidi Kroon reshared this.


Another clanger from Microsoft -

- zero day vulnerability being exploited in Windows OS for six months in the wild by North Korea

- They didn’t tell anybody, took six months to make a patch

- released the patch without saying what happened

- didn’t mark it as a zero day in Microsoft Vulnerability Management

You’d think having the largest market cap in the world and having $2bn a year in revenue from security alone would allow.. uh.. investment.

bleepingcomputer.com/news/secu…

reshared this


Gidi Kroon reshared this.


Automattic edited a developer page in September to explicitly allow for AI companies to buy access to a "firehose" of a million WordPress posts per day through a company called SocialGist. How does this work and what are the safeguards? Automattic will not say, will not talk.

404media.co/wordpress-firehose…

in reply to Jason Koebler Jason Lefkowitz reshared this.

Automattic just emailed me and said they are "deprecating" WP Firehose altogether and dropping SocialGist as a client.

"SocialGist is rolling off as a firehose customer this month and the remaining customers are winding down in the coming months, both things that were already in motion for different reasons. We’re in the process of updating our developer page to indicate that we have been deprecating the old firehose for several months."

404media.co/wordpress-firehose…


Gidi Kroon reshared this.


An interesting new wrinkle to the Automattic story from @404mediaco—the “firehose” has already been in play for years. 404media.co/wordpress-firehose…

reshared this


Gidi Kroon reshared this.


They're here.

Finally.

donotreply.cards/

Oh, and subscribe for when the stickers are out.

(You want the stickers.)

Made with @Ffangohr with a lot of fun.

reshared this




Hey, is it still February? I thought we would be done with that month by now.


I dislike apps that tell me that I have a problem with my internet, while other apps have no such issues. Maybe it's your side that has the problem?


To opt-out of being used for AI, in the tumblr app go to your profile (bottom right), select your blog (top left) open settings (top right) and scroll down to Visibility (my app is in Dutch where it is called Zichtbaarheid, can't double check the real English term). Then you get three toggles. The third is for opting out of your content being fed to a hungry AI monster.

Repeat this for each side blog (top left) because these settings are independent!


#tumblr

Javi A. reshared this.

in reply to Gidi Kroon

So if you trust that the toggle indeed opts out, there's no need to delete your blog.
in reply to Gidi Kroon

I'm totally trusting that toggling that setting will untrain any AI that has already ingested my content, readjusting the neurons, in essence adding to each prompt: 'but answer as if you've never seen my blog'.

(Not seriously)

in reply to Gidi Kroon

Idem for your wordpress.com blog as I understand it also has such a toggle.


Gidi Kroon reshared this.


Friends! I’m looking for my next role after nearly three years at Stately. I’m a UX designer who is just as comfortable in front-end development. I also love writing, giving talks, and making videos, so I’m up for dev and design advocacy roles, too.

If I sound like someone you want on your team, please give me a shout!

reshared this



Windows 11 is the 'one more click' release, which is fitting since 11 is one more than 10.


There has been a security update to Pleroma a few days back that I didn't notice (git.pleroma.social/pleroma/ple…). Since it only updates the emoji-steal-policy which I don't use, there's no need for immediate action from me. Makes me appreciate github's email alerts though.


I've now reached season 2 of The Shannara Chronicles, the season where we get Melise as well as Ivana Baquero. Melise was at the time still using her stage name of Malese Jow. Both Melise and Ivana I had seen before (respectively in Big Time Rush and Pan's Labyrinth) and both are the reason for watching this series.

I love how someone like Melise can introduce a character into an existing world, with such impact and which you are interested in immediately.
imdb.com/name/nm1679802/
#Melise #TheShannaraChronicles #MaleseJow

This entry was edited (9 months ago)


I'm loving these pictures of Yusra Mardini by Felix Hoffmann. Visit his site via the link for more of them!
felixsamuelhoffmann.com/#/yusr…


#YusraMardini



How much will tumblr be worth by now? I'm sure we could buy it back.



I'm still watching my series from the boxsets, I'm now at the Roswell episode (1x17 Crazy) where Emilie de Ravin as Tess is introduced. I thought I had to wait for the second season for that, happy to already see her now.
#Roswell #EmilieDeRavin
This entry was edited (9 months ago)
in reply to Gidi Kroon

Roswell is where I saw her first, later of course as well in Lost and Once upon a Time. She may even have been the reason I started watching Lost.

Gidi Kroon reshared this.


As this is a leap year we go from February 28, 2024 to March 1, 2025.

Gidi Kroon reshared this.

in reply to Missing The Point

in Britain until like 1500 the year started on the 25th of march instead of Jan 1. So that's not too far off

(Source: Tom Scott computerphile video)



Are there any alternatives to Amazon for buying UK releases of blu-rays or dvds? Or books for that matter?


Miranda Cosgrove shared a video of her spotting a billboard of Drugstore June and also posted the trailer of the film, as the film of a friend of hers that she's excited to see getting released. But if you pay attention you see Miranda herself in the trailer, probably in a small role. The IMDb page lists her too.
#MirandaCosgrove #DrugstoreJune


Mastodon's default is now for registrations to be closed on servers. Great! And for servers with open registrations to automatically require moderator approval of new sign ups if the server has not seen a moderator/admin in a week. That should deal with these abandoned servers, I'm happy about these changes.

Gidi Kroon reshared this.


So Tumblr has been doing a thing where they have a Scarlett Letter to mark trans women. Well, any blogs containing "too much" mature content, but that seems to mainly mean trans women. So I looked into it, and it turns out it's weird and broken.

reshared this

in reply to Foone🏳️‍⚧️

It turns out the actual image is not square, despite being rendered as a square. Strange. But then I looked at the html: this isn't an img, it's a canvas.
in reply to Foone🏳️‍⚧️

Which'd make sense if they were trying to dynamically blur every scarlet-lettered user's profile image, but everyone with The Mark had this exact image. It doesn't change.

So I looked into the source and found where they're doing the canvas stuff, and yep, they're blurring the profile image. So why is the result always the same?

in reply to Foone🏳️‍⚧️

It turns out the backend team and front-end team are not talking to each other: when a user gets scarlet-lettered, the backend resets their profile image to the default "cone.png" image:
in reply to Foone🏳️‍⚧️

So everytime a scarlet-lettered user appears on your feed, it loads this same icon, dynamically blurs it down to 2x2 pixels, renders that out as a 350x150 image, then tells your browser to rescale that image to 65x65 for the profile picture.
in reply to Foone🏳️‍⚧️

So yeah. All this client-side scripting is unnecessary: they could have just made the backend switch to a properly sized version of the blurred image, but apparently no one communicated how the two halves were working, so it does these pointless steps every time someone flagged shows up in an activity tab or on your dashboard.
It's almost impressive!
in reply to Foone🏳️‍⚧️

a funny side-wrinkle of this is that tumblr has banned posting links to or images of their default site image.

Like, this url? assets.tumblr.com/images/defau…

if you try to paste that on tumblr, it'll try to expand it into a preview, then fail. If you go to that image and copy it, then try to paste that on tumblr, it'll fail.

in reply to Foone🏳️‍⚧️

download the PNG and try to upload it again, it'll fail.

they've banned the hash of their own default avatar image.

I don't know why they would do this.

in reply to Foone🏳️‍⚧️

Please tell me that the justification of "scarlet letter" on Tumbler isn't to make transpeople more easily identifiable.

Because that sounds a lot like "the star of David should be easily seen from distance on any Jew".

This entry was edited (9 months ago)


The spam wave seems to have stopped 16 hours ago, from all sources simultaneously.

Gidi Kroon reshared this.


I'm Keynoting at Sunshine Cyber Con!
"Past, Present, Predictions - A look into AI, Deep Fakes, PsyOps and the upcoming election cycle"
Hope to see you there!

Gidi Kroon reshared this.



I hadn't heard of any Streams repository (fka Zap, fka Osada, etc) people for about two months and thought it had just gotten quiet. Instead the forum and the people post quite regularly, but communication with them from my Friendica has broken down. When trying to reconnect I got all the errors about not being able to recognise the protocol (when it fails to load the actor definition). Not even individual posts load correctly when providing the url.

So I thought this could be a use for my Pleroma. But it also mainly fails to connect... :-( I can only load individual posts.

in reply to Gidi Kroon

At the same time I can't unfollow Guppe groups from my Friendica, only follow them. Even when they act as spam amplification...


Was wondering how you could consider communication using carrier pigeons secure, but of course it would be if you use IPoACs.

Clara Listensprechen reshared this.


Gidi Kroon reshared this.


Netflix releases full Nimona movie on YouTube
youtu.be/i4CFWTYFRlw
#vfxProductionFeed

reshared this


Gidi Kroon reshared this.


Owners of public Mastodon servers, you might want to set your signups to approval mode to prevent spammers:

1. Log in on your server's website
2. Go to Preferences
3. Go to Administration
4. Go to Server Settings
5. Click the Registrations tab at the top
6. In the "Who can sign up" menu select "Approval required for sign-up" (optionally also tick the box for requiring a reason)
7. Click "Save Changes" button

Spammers can exploit servers with instant signups.

#MastoAdmin #FediAdmin

This entry was edited (9 months ago)

reshared this

in reply to Grow Your Own Services 🌱

Okay, but how do you decide whether or not to approve a blank slate? A new user hasn't posted anything yet.
in reply to Humbird0 Fandom

@humbird0 it's a random decision, you have no means of knowing if it's a spammer registering or not. Seems nobody in this thread cares, though 😅
in reply to Bartek Krawczyk

If you tick the box asking for a reason with signups, that helps weed out automated accounts and troublemakers, especially on themed servers aimed at particular audiences.

There have also been cases where automated signups choose usernames that make it obvious they are part of a spam attack.

This entry was edited (9 months ago)
in reply to Grow Your Own Services 🌱

Ok so hear me out.

We make a bot to register accounts

We tell the accounts to send a daily message to the servers admin these instructions.

Profit.




Gidi Kroon reshared this.


Hmmm, every server I'm getting spam from has a new user in their public directory named yqqwe, and each one of these users is following mastodon_admin_yggwe on a single-user instance mastodon.tinynews.org. One can look at the 924 followers of this admin and they all are named yqqwe and they are all on servers I've been getting #spam from. #fediverse #moderation #administration

Gidi Kroon reshared this.



I love how you can see on Yusra Mardini's face how much she feels at home at a swimming pool. She stopped competitive swimming a while back, but she's here now in an ambassador role.


#YusraMardini




I'm starting to think no remote content should be stored at all, just maybe cached, but I understand how, currently, received text of posts can be stored similar to an email inbox.

But do I understand(*) correctly that Mastodon stores remote media as well, in their own media storage, even when from unsolicited sources? That can't be right.

(*) It is cited as a side effect of the spam wave that some are running out of media storage.