Show more

Starting 2023, four universities are pausing or ending their Elsevier subscription due to exorbitant pricing.

Elsevier's subscription was costing them ~10% of their Libraries' entire budget.

"Elsevier’s prices have increased each year and have outpaced inflation"...this is despite Elsevier having the highest profit margins of virtually any other industry or publisher.

via dailyemerald.com/news/pressing
Figure via @MatteoCarandini
#OpenScience #AcademicPublishing #Science @academicchatter

I'm sad to say that my new still needs non-free firmware blobs for working WiFi, Bluetooth, audio, and power management. Now will include those in the installer. Are we losing this fight? At least the graphics driver is and included in upstream Linux, that is progress. I specifically avoided for that purpose.

How are others feeling on the firmware blob fight?

Everything was clearly better in the past, we can't even get toothpaste anymore!

@mcopelov That is super scary to me because this is not a pivot away from supporting war, instead the EU will just be supporting the next etc

One effect of the is that it gives the etc a case to use to rehabilitate the idea they focus on: that military power is a force of good. provided a template for to follow. This is really not discussed enough because people want to support Ukraine in this difficult time, but it must always be part of any discussion of providing military support. Kudos to for running this political cartoon linking these.

If a major platform exploiting extensive personal data on most Europeans without a GDPR legal basis does not result in a max fine, then what does?

Processing orders are powerful too, I know. But almost 5 years into the GDPR we really should have seen multiple massive 4% fines.

What makes a program secure? 🤔

It has to be audited, checked, and corrected. Free Software allows more people to audit. More people are allowed to read the code and discover vulnerabilities.

Ultimately #FreeSoftware creates a culture where people are ready to answer to criticism on systems and software. However there is Free Software that is not audited too so its security is not confirmed. (2/3)

Show thread

@fribbledom @surendrajat A lot of us are running Google-free these days, unfortunately that means we have slimmer coverage for Google devices, though I'm guessing a majority of our users run Google devices. That could be a factor here.

@fribbledom @surendrajat the key is providing enough information that a developer can reproduce the issue locally. Granted, that's often difficult. Without reproducing the issue locally, fixing bugs is basically just guesswork. That issue is a good example of not having enough information to reproduce, though people have posted some info.

@fribbledom @surendrajat please file an issue so we can follow up on it: gitlab.com/fdroid/fdroidclient

For most bugs, 90% of the work of fixing it must come from the affected person, since it is about describing how to reproduce the bug, and providing follow up info. I rarely see bugs or crashes like this on my own devices since the ones I encounter over the years, I have fixed. We want to fix all the bugs, but we need people to report them, and provide detailed info.

@legind Yeah, I think the static site generator mode is useful only for content that is shown to users that are not logged into Wordpress. For it to work well, all info required for showing a page must be in the URL.

People from all over Europe want the right to install any software on any device! New signatures to our open letter:

🇮🇹 Italy

Wikimedia Italia @wikimediaitalia

LinuxTrent @linuxtrent

🇩🇪 Germany

Do-FOSS @do_foss

Werkkooperative der TechnikfreundInnen @HackerGeno@chaos.socia

🇪🇸 Spain

Pangea @pangea_org

🇳🇱 Netherlands

Open Nederland @opennl

🇫🇷 France

Fédération des Fournisseurs d'Accès Internet Associatifs @ffdn_channel

Sign now! fsfe.org/activities/upcyclinga

#righttorepair #UpcyclingAndroid #freesoftware

@legind I haven't used wordpress.org/plugins/simply-s but it sounds like it goes one better by generating the whole site as static files that can be hosted on any webserver or CDN. No database necessary.

"Medium has pivoted so many times it has now come full circle" cjr.org/the_media_today/medium

"Medium Pivots Again, Offers Voluntary Buyouts to Editorial Staff" thewrap.com/medium-pivots-agai

So I mean feel free to hop on that scorpion's back! You might have an awesome trip across the river and everyone will be super chill and friendly forever. But maybe check out the history before you hype up their new Mastodon experiment and keep your eye on the exits.

¯\_(ツ)_/¯

Show thread

@legind There seems to be some kind of "Wordpress as static site generator" mode now, it would be key to have that simple to use. This points to a reason why I think the GNU/Linux distro model is so important: shared maintenance of the long tail, so that many small orgs can maintain their services without going bust.

@a_sator In Österreich geht es viel besser als in andere Länder. Ich fähre regelmässig von Wien nach Semmering mit dem , esse an Bord Fruhstück als ich hinfahre, und Abendessen nachher. Ganz gemütlich. Ich bin auch mit den ÖBB nach Goldeck und Saalbach gefahren. Ich habe kein Auto. Viele Gebiete sind fast unmöglich mit den Öffis.

@ljacomet I just saw your slides for your talk "Protecting your organization
against attacks via the
build system", a great overview! I'm a dev who has worked on packaging . We'd love to make it as close to your version as possible. There is a proprietary build dependency that blocks that from happening. github.com/gradle/gradle/issue

Then compare this to getting package updates via the official repositories, which includes a wide array of proven techniques for securely shipping software packages and . In addition, Debian has good track record over decades. In most setups, I think it is safe to enable the "unattended-upgrades" package which automatically downloads and installs updates for the majority of packages in Debian. This is the best choice for users who do not have the means to do further examination

Another key discussion area for is a updating the libraries that they use in their app. Ideally the developer would review all source code changes that the lib update includes. This rarely happens in practice, and we see lots of apps inadvertantly include malware via libs that have been taken over. for example portswigger.net/daily-swig/pop This is where devs should be thinking about how much they trust lib authors to maintain secure accounts, domain names, upload processes, etc.

Show more
image/svg+xml Librem Chat image/svg+xml