Show more

@royal What a time to be alive when a website shares data with "We and our 848 partners" 馃ゲ
(And the mouse thing too for sure! A mouse!?)

@Big_Diggity Wow that all looks very delicious! Happy birthday to your dad!

@COSMIC_desktop Dark mode is great... until a uncooperative website blasts your retinas out 馃お

#Ventoy Security Concerns (please boost for visibility)

Ventoy is a popular utility for making USB drives containing multiple operating systems in the form of bootable image files. While very useful in theory, the source tree contains numerous binary blobs without source code. This issue has been brought up to the authors multiple times, have not been corrected, and have even gotten worse (more blobs have been added to the code over time). This is a potential malware vector, similar to the "test files" in the xz-utils backdoor catastrophe.

Recently the author has ignored a very lengthy thread raising security concerns because of these binary blobs. Given the amount of attention the thread has gotten, this seems strange, especially given that the authors have been active since then. github.com/ventoy/Ventoy/issue

Stranger yet still, a video by Veronica Explains (@vkc) on how to create bootable USB flash drives got flooded by comments heavily suggesting the use of Ventoy and even being somewhat accusing because Veronica didn't advertise Ventoy. This is... not anything I've seen users of ANY open-source project do, and it feels similar to the social engineering done against Lasse Collin that convinced him to add Jia Tan as a maintainer, thus compromising xz-utils. See the comments of youtube.com/watch?v=QiSXClZauX

If you're using Ventoy, you may want to consider ceasing its use for the time being out of an abundance of caution. If you truly need its functionality, you might look into something like the IODD SSD Enclosure (iodd.shop/HDD/SSD-Enclosure) which can emulate an optical drive and allows you to select an ISO saved to the drive to boot from.

#linux #boot #security #malicious #backdoor

I will say, though, at least the highest GSP I've gotten (9.6mil) is with my main (Sheik) and not some rando like Ganondorf....

Show thread

@scribblemacher I'm getting into the Zelda series a bit and I'm liking it so far, but yeah, "Secret stones" and "Demon king" do make me cringe... sorry Nintendo D:

(But really, I think there's a thing with people around my level ranking online better with some random character as opposed to their actual main)

Show thread

Meanwhile, I go offline and play against a level-9 I used to struggle hard against, Terry, and succeed with two stocks to spare and no stress.

I used to try to climb the GSP ladder and used to be ranked better but I'm moreso just using online as practice. There's a SSBU club at my college, and a local not to far away from where I live while not at college; *that's* where I want to do well. And get to meet people IRL, make friends, and have fun together.

Show thread

So I've been practicing Sheik a lot lately. I generally don't like playing online, but I decided to go back online and play some and I feel like I'm getting better -- using more Sheik tech, having more toe-to-toe matches and holding my own a lot better -- but I'm only like at about 6mil -ish GSP. (We're not gonna even mention that my Ganondorf is above 7mil...)

@emeric @COSMIC_desktop I'm sure they see the inconsistent margin size, COSMIC is just pre-alpha right?

@fribbledom I'd say that about the language design. The implementations have to be advanced, though, to support that kind of ease of use, with garbage collection and built-in threading and all.
That's how it tends to be; an easier-to-implement language like C is harder to use, but a harder-to-implement language like is easier to use.

A man designs and builds a racecar that is supposed to win a particular race, and another man drives it and wins that particular race. Did the driver do the most to win or did the designer+builder do the most to win?

Well, rarely; it doesn't do it every time. It's pretty strange

Show thread

Waiting for the day Firefox fixes the bug where touchpad pinch-to-zoom on Wayland opens the search bar and changes your search engine... 馃檪 weird.

@sleepybisexual When fighting some of the DLC I find it very helpful to focus more on *not getting hit* rather than *hitting the opponent*, you know? At least I see advice for that mentality in the Sheik community; might not be as useful for other fighters.

@FiveEyeTea I like the idea of my devices requiring both a passcode *and* a fingerprint, since fingerprints can't be stolen by "shoulder-surfing" and security footage, and copies of your passcode aren't left on everything you touch (e.g. more or less like fingerprints), and it is hard to force someone to give up their passcode if they *really* don't want to (unlike with fingerprints).

@FiveEyeTea I had heard something like that. I'll remember that, thanks.

@FiveEyeTea Interesting - never use biometrics? I'd have mine require a passcode and my fingerprint, but Samsung doesn't seem to offer the option...

Show more

Ethan Black's choices:

Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml