Killing_Spark

@Killing_Spark@feddit.de

This profile is from a federated server and may be incomplete. View on remote instance

Killing_Spark ,

I think you are missing the part where the community also gives back to the project. At some point the project isn't really the creation of the original author anymore.

Killing_Spark ,

Apparently it differs between distributions

Killing_Spark ,

One good thing about zstd is that the main developer is full-time employed to work on it. Alas he's employed by meta to do that... But it's likely harder to social engineer your way into that project

Killing_Spark ,

No. I won't not do that. For security reasons.

Killing_Spark ,

Huh thanks for the link. I knew that just dd'ing doesn't work for windows Isos but I didn't know that it was the Linux distros doing the weird shenanigans this time around

Killing_Spark ,

The original email talks about a line that is in the release tar balls but not the repository itself that actually arms the exploit. This seems like something a maintainer should be able to verify.

Not saying that they should have immediately seen that that is an exploit, the exploit is obfuscated very well. But this should be a big red flag right?

Killing_Spark ,

I have to admit I have no practical experience as a package maintainer, but this case sounds like there is a diff between files checked into the repo and the ones provided by the tarball.

If the tarball contains new files that contain executable code that's still weird tbh, but I guess you have to trust the upstream maintainers to some degree. But a diff in a checked in file seems different to me.

Killing_Spark ,

That's pretty nitty although you can always just partition a long key and distribute the partitions to the different people

Killing_Spark ,

Don't forget to delete this comment before you call back to the original one. Otherwise the future people will know you aren't actually smart!

Edit: Also, hello there future people!

Killing_Spark ,

SHUT UP GOOGLE

(dunno why I am in a day-old thread)

Killing_Spark ,

Is this a regional thing? I don't know anyone that actually uses SMS anymore

Killing_Spark ,

I mean to be honest to only reason to use messengers is just costs, I wish SMS where as cheap as internet flatrates... But that might very well be a regional issue too

Killing_Spark ,

Internet protocols are better in so many ways

This is VERY debatable because statements that broad are almost always false. There is no need to have a cellular->IP->cellular bridge for 1:1 communication involving more servers, more service providers. If anyone wanted to they could implement at least the 1:1 signal protocol and probably even the messaging layer security protocol on top of SMS to get e2ee group communications.

Nobody wants to because cell providers sell SMS for horrendous prices compared to internet access.

[Question] How to correctly cleanup unknown filedescriptors received over unix socket

The context I came upon this question is dbus filedescriptor passing but the question is valid more broadly. Assume you are implementing some service that is supposed to receive some kind of filedescriptor for client processes. You get a message that is in some kind or another malformed but you have already received the...

Killing_Spark OP ,

Just not handling the filedescriptors isn't really an option though. They should at least be closed to ensure the process doesn't run out of filedescriptors which would be a pretty easy way of DOS'ing that service

Killing_Spark ,

Creating the bag would create a very big underpressure, immediately imploding the bag and probably killing the creator

Killing_Spark ,

Is there a link to the repo anywhere in the comments? Can’t read them on X

Killing_Spark ,

Which makes it 1% total. Which is a lot for one single change

Mastodon and today's fediverse are unsafe by design and unsafe by default ( privacy.thenexus.today )

Even though millions of people left Twitter in 2023 – and millions more are ready to move as soon as there’s a viable alternative – the fediverse isn’t growing.1 One reason why: today’s fediverse is unsafe by design and unsafe by default – especially for Black and Indigenous people, women of color, LGBTAIQ2S+...

Killing_Spark ,

I mean, I guess the point they are making: “Keeping the fediverse an enjoyable experience is hard work by design” is kind of true.

But I would be very interested in how you can exclude hate speech “by design”

Killing_Spark ,

Yeah that was kinda my point. There isn’t a “by design” solution to people being people

Killing_Spark ,

You could build something that prevents people from being offended. Let them answer simple questions like are you offenden by . If they answer yes, no allowed to join.

That would still require posts or communities to reliably label their contents correctly right?

Maybe the only solution is sulfuric acid. (or alcohol)

I strongly belief that if we all strived to get the maximum amount of alcohol into our bellies instead of the maximum amount of money into our accounts society would be much nicer.

Killing_Spark ,

Hah hahaha hahahahaha

Our school systems are admined by teachers with only half a clue of what they are doing with only a few hours per week as a budget. This isn’t meant as an offense, math teachers that like to fiddle with computers in their free time are just not qualified to run the infrastructure for schools

Source: am the son of such a teacher in Germany

Killing_Spark ,

It kinda limits the spectrum of playable characters though right? The others can notice that that’s going on and either go PvP or kick the person out of the party. It can actually be a cool character arc to teach the character to share loot.

Of the player themselves aren’t able to learn that though… do the same as above but irl?

Amazon CEO reportedly told remote employees: ‘It’s probably not going to work out’ - The Verge ( www.theverge.com )

Amazon CEO Andy Jassy recently told employees that those who do not want to return to the office at least three days a week should consider finding employment elsewhere. According to a recording obtained by Insider, Jassy stated “It’s past the time to disagree and commit,” adding that if employees cannot commit to the new...

Killing_Spark ,

Honestly as long as it’s not “Accrue money for bezos so he can shoot his phallic rockets into space” it’s probably better for the world.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • All magazines