Show more

On the bright side, at least is *dependably* bad.

I just don't get it. How can they be so incompetent? This isn't a one-off issue, either.

PSA: HEADS UP EVERYONE! Another project noticed they were being targeted with similar social engineering tactics as the xz-utils backdoor attack. Be on the lookout for random people demanding that you add someone new as a maintainer for vague but urgent "reasons". Google their emails, check their GitHub/GitLab histories, see if they are on Mastodon/Reddit/"X"/LinkedIn. If they do not have an internet footprint, they are probably a plant.
openssf.org/blog/2024/04/15/op
#opensource #opensourcesecurity

Reading Leviticus is a reminder that God has always taken sin seriously. Its effects are costly and so is the punishment.

But God wants a relationship with His people so in the Old Testament we can see He provided a way for them to atone for their sins.

Even better, He provided Jesus as a permanent sacrifice for sins, bringing forgiveness and reconciliation that is received by grace through faith in Him.

#jesus #god #bible #christian #christianity #sunday #church #faith

These direct solicitations to T-Mobile employees to participate in SIM-swaps are definitely not just limited to T-Mobile's employees. But T-Mob is probably the easiest still.

reddit.com/r/tmobile/comments/

BTW in case you need help with Chirp Systems products, here is their user guide:

"User
Guide

What do we want this to say? Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua."

chirpsystems.com/user-guide-co

Show thread

Hmm who’s going to be more annoyed about this? Rhondson or Addison?

#Zelda #TearsoftheKingdom

The fact that you can follow the president of the United States (@potus) from your Mastodon account instead of being forced to have an X or Threads account for it is a huge W in my book. Of course our team is fully available to help if they'd want to set up Mastodon on whitehouse.gov. I believe governments should not rely on 3rd party platforms to connect with their constituents.

My installation of has the vulnerable version of . Thankfully, it isn't affected, as the requires Linux, and has some other requirements. Phew! I guess that's one of the advantages of using a rare OS (even rarer than ).

P.S. found this after composing: masto.lema.org/@santiago/11219

@CM30 At least you have something to google! It is much better than the even more frustrating "Something went wrong."

I was doing some micro-benchmarking at the time, needed to quiesce the system to reduce noise. Saw sshd processes were using a surprising amount of CPU, despite immediately failing because of wrong usernames etc. Profiled sshd, showing lots of cpu time in liblzma, with perf unable to attribute it to a symbol. Got suspicious. Recalled that I had seen an odd valgrind complaint in automated testing of postgres, a few weeks earlier, after package updates.

Really required a lot of coincidences.

Show thread

This is the best timeline I've seen so far on what we know about the Xz backdoor. Some good info here for researchers: boehs.org/node/everything-i-kn

Besides making a sandwich, what's one thing you wish the 'sudo' command could do in real life? #linux #unix

@codrusofathens @bazkie @nixCraft @cafkafk Yeah, wishing people terminal cancer, in a lighthearted thread no less, is not what we're on Masto for. That junk's for Twitter.

@GreatBigTable @briankrebs It must be; surely 4m of Mastodon users aren't following him, not already anyway.

Show more

Ethan Black's choices:

Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml