Show newer
Shamar boosted

@loke

One might argue that having a job there is a good way to kill the monster from the inside, through leaks, bugs and so on...

But to me the risk I could somehow help them is too disgusting.

@dredmorbius @rysiek@mastodon.technology

@oleksiy

Why? What's wrong with feeds? Or you are talking of RSS specifically (and not Atom, for example)?

@loke

So you mean it wasn't a phishing attempt?

If so, I guess they wrote a bot to annoy every programmer on github or something... because someone from mailed ME too.

And I mean... me.

One who hate whole heartly and think is a against all of us to distract from their business model and make us forget .

A bot from wouldn't have wasted such bandwidth... but from Facebook... they are just spammers on steroids.

@dredmorbius @rysiek@mastodon.technology

Shamar boosted

The Assange trial thread is on Twitter, but it's worth following: nitter.unixfox.eu/SMaurizi/sta ♻ @SMaurizi: 23. it really keeps me awake at night how in the last 11 years we journalists,activists,intellectuals haven't been able to stop this upside down world in which courageous whistleblowers and publishers go to prison while war criminals and torturers sleep peacefully in their beds

@gubi

La complessità di un browser non la ordina il dottore.

Un browser (o un sistema operativo o..) non è un fenomeno naturale come la gravità, che possiamo studiare, ma dobbiamo accettare come è.

È un artefatto umano.

Esistono browser che un programmatore può studiare e comprendere completamente in una settimana o un mese¹.

Ma software come o sono intenzionalmente progettati per vanificare le 4 libertà.

NON È VERO che puoi pagare qualcuno per studiarlo se non ti fidi di Google (che controlla entrambi, Mozilla è solo la loro PR geek-friendly).

NON puoi.
NON hai i fondi necessari.

E anche se hai le competenza (io le ho), non avrai mai il tempo (a meno di essere assunto per 2 o 3 anni da terzi per farlo, ma è estremamente improbabile)

Di fatto dunque i browser ed i sistemi operativi mainstream sono indistinguibili da software proprietari per la stragrande maggioranza delle persone.

Perché non PUOI scegliere di fidarti: sei COSTRETTO a fidarti.

E di chi?

Di Google. 🤦‍♂️

Che controlla (insieme a , , , ...) gli standard che regolano il web.

Una backdoor poi è del tutto indistinguibile da una vulnerabilità, soprattutto quando il software in questione esegue automaticamente codice arbitrario inviato da terze parti che possono personalizzarlo targettizzando un singolo utente.

Come fanno i browser mainstream, appunto.

Insomma, attenzione all'open washing: la situazione è molto peggiore di quanto sembri proprio perché le persone non hanno il coraggio o gli strumenti tecnici e critici per guardare in faccia la realtà.
____

¹ netsurf-browser.org/

@miriamgreco@mastodon.uno @informapirata

@gubi

Di fatto, da Hearthbleed in poi, tutti sanno che il mito (neoliberista) dei "mille occhi che scovano tutti i bug" è una favola della buona notte.

è open source e ogni anno ha più vulnerabilità annuali i livello 9+ che tutta l'offerta di .

Non cambia una fava se sono vulnerabilità introdotte scientemente o meno, sono backdoor in attesa di essere exploitate.

Il fatto che il software sia open source è condizione necessaria ma NON sufficiente affinché serva i cittadini: deve essere semplice, anche a costo di non essere facile.

Altrimenti le 4 libert๠si riducono a privilegi elitari.

____

¹ e nota: solo per i liberisti la libertà si riduce alla possibilità di scegliere fra le offerte disponibili. Per questo fingonobdi avercela con i monopoli: rendono evidente l'idiozia di questa riduzione.
In una società democratica esiste anche la libertà di creare, di esplorare, etc...

@miriamgreco@mastodon.uno @informapirata

@tomayac

also means no intermediate proxy. Nobody ever consider what this means in term of user vs large cdn and cloud providers?

We could have faster web contents (beware, not faster web apps or streamings, just web contents) with something as simple as cryptographically signed tar.gz containing website chunks (such as css+images+html):

- fast (RTT becomes totally irrelevant)
- fully cacheable
- authenticated (no MitM)

It would not be encrypted (and thus not good to send your credit card or transfer sensible data or contents) BUT it would make centrally spying on all people way more difficult.

Instead Google invented QUIC.

No way to cache contents and to ensure their authenticity without connecting to the TLS servers.

Well done, engineers, well done!

And yes, IETF QUIC is different from Google QUIC: it doesn't serve only the needs of but those of , and and friends.

You wrote that this "is a real concern", but I don't think you stressed enough what a huge issue geopolitical this is: it should be enough to ban QUIC traffic outside the .

Shamar boosted

18 anni precari: schiavitù accademica interna ed esterna - per ricercatori, pagati con (poco) denaro pubblico che dovrebbero essere liberi perché al servizio del sapere e non di aziende private e degli ordinari in carriera. E come d'uso gli ordinari in carriera si adegueranno: better to reign in Hell than to serve in Heaven. Ecco la riforma del reclutamento in discussione al Senato: roars.it/online/il-nuovo-dl-re

@informapirata

Nessuno ti vieta di crearti un'istanza per spammer, se ritieni.

Verrà probabilmente bloccata da tutti, ma tanto... i tuoi clienti mica lo sanno! 🤣

@miriamgreco@mastodon.uno @paolo

@informapirata@mastodon.uno

"semplice≠facile"

Vedo che mi copi le battute eh...

BRAVO continua!

@miriamgreco@mastodon.uno @informapirata@poliverso.org @paolo

Shamar boosted

@miriamgreco
Il fediverso oggi è composto da persone come me e da tanti che tirano fuori di tasca loro i soldi per affittare dei server.
Questo è sostenibile per alcuni finquando i volumi ed i costi non diventano troppo elevati poi devono fare delle scelte.
Durante un incontro con la commissione europea sul finanziamento dei progetti Open Source ho proposto di iniziare a far spostare obbligatoriamente una percentuale dei budget delle licenze proprio all'Open Source. @Shamar @informapirata

Shamar boosted

@lattera How did the attacker gain knowledge of the tools used? They asked. At a conference, during Q&A of a talk about infrastructure. A perfectly valid, good question. They then just needed to know if it was a vulnerable version. So they asked about distros too, how up-to-date one should stay. LTS or Stable or roll your own?

Show thread
Shamar boosted

@lattera The way that attack worked was that the attacker gained knowledge of what tools are used to view the logs, found a vulnerability in some of those tools. So they engineered messages that would trigger the bug when processed, and exploit the vulnerability in the tool, and compromise _that_ system. They chained that into other attacks, and eventually gained shell access to the computer. They could attack other systems from there.

(cont...)

Show thread
Shamar boosted
Shamar boosted

Is your school forcing you to use Zoom, Skype, or other proprietary videoconferencing software to learn or teach? That's a violation of your educational rights. Support #FreeSoftware fsf.org

Shamar boosted
Shamar boosted
Shamar boosted

Interesting fact of the day: The term "patching" software originates from the fact that you would literally patch holes in early hole punch input in order to fix an issue. Attached is a picture with such patches on it from the Harvard Mark I computer.

Show older
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.