Salta al contenuto principale

Lapo Luchini ha ricondiviso questo.


This is fun, and relaxing:

grantkot.com/ll/

reshared this


Lapo Luchini ha ricondiviso questo.


We have *one* Silver Anthesis Necklace available for holiday delivery! Part of our Floraform collection, this design is inspired by the mathematics of how flowers unfurl—and it’s one of my personal favorites. n-e-r-v-o-u-s.com/shop/product…

Lapo Luchini reshared this.

in reply to Jessica Rosenkrantz

The necklace shape emerges from a simulation of differential growth. We start with a hemisphere which is growing fastest on its edge. As it grows, it evolves from a simple surface to a form that fills space with curves, folds, and ruffles


Lapo Luchini ha ricondiviso questo.


And now, a true volumetric aurora in #GaiaSky. This is the third approach to rendering auroras I implement in the past few weeks, and it looks like it's gonna be the definitive!

Lapo Luchini reshared this.

in reply to Jumping Langur

I used the 2010 work by Lawlor et al. as a base. The footprints are currently static (I drew them with Gimp). There's also an issue with a mirrored ghost aurora in the direction opposite to the view when inside the atmosphere.


I had a wild weekend trip down the rabbit hole of #tlog Transparency Logs (a theme I also use at work, but the urge was too much to wait for an off-time at work), resulting in having installed a Trillian Tessera server, an OmniWitness server, and creating a PR for the latter to let them understand each other… which might be totally unuseful, as the main author of both projects seems to be the same, and he certainly doesn't need help from me to let those understand each other, but you know… I had to see it working now!
#tlog
in reply to Lapo Luchini

PS: well it was merged, and it was a bit of a learning experience in Go too. So yay!

Lapo Luchini ha ricondiviso questo.


"Lights Out: Covertly turning off the ThinkPad webcam LED indicator":

powerofcommunity.net/poc2024/A…

(A 150-slide PowerPoint presentation converted to PDF - but, seriously, folks, check it out. This is NSA-level shit.)

reshared this

in reply to VessOnSecurity

I mean, seriously. He ran an implant in his webcam's firmware (written for some obscure CPU), in order to extract its boot ROM and fuzzed it, in order to find the USB request for controlling the light? WTF?!
in reply to VessOnSecurity

meanwhile, my webcam exposes "led blinking frequency" (including values for on and off) as UVC control 😁

Lapo Luchini ha ricondiviso questo.


Time-lapse of the Sun circling the horizon at the South Pole during early March.

Video credit: Robert Schwarz
Source: vimeo.com/208466944

reshared this




Future of Mozilla (and) Firefox


Please someone in here re-assure me #Firefox has a future, as I'm really cozy with my setup and really wouldn't want to migrate again. 🤣
… but I am also more and more worried each and every time a new article about #Mozilla hits the news. 😞
(I look forward to #Servo too, but that's a partly different issue)

Matteꙮ Italia reshared this.


Lapo Luchini ha ricondiviso questo.


Influencers hate this one small trick to encrypted internet traffic on public WiFi

reshared this


Lapo Luchini ha ricondiviso questo.


In my experience, most people model security issues as broken windows or loose locks, something easily fixed with some care and attention.

On the other hand, most security issues are better modelled as missing structural beams or sinking foundations, flaws that compromise the integrity of the entire structure and the safety people around and within.

reshared this

in reply to Sarah Jamie Lewis

Security design sometimes seems like a "Unwinnable by Design" scenario in a game where an early incorrect choice leads to a situation where it's impossible to win or rectify conditions in order to win.

Having to start all over from the ground up is rarely favored by management

Investors favor just patches that build technical debt & postpone the inevitable pain of the next data breach, system crash, or ransomware hack.

in reply to Sarah Jamie Lewis

I used a variant of this metaphor a fair bit at my last work - calling some of the problems with our modelling procedures (which were the core of what we were selling) "rotten foundations". It definitely clarified the situation for some people. But it also didn't make the approach to the problem change, as far as I could see.

Lapo Luchini ha ricondiviso questo.


rustls outperforms OpenSSL and BoringSSL.

Security and performance: pick two!

memorysafety.org/blog/rustls-p…

Questa voce è stata modificata (2 mesi fa)

Lapo Luchini ha ricondiviso questo.


Remember, kids, the Caesar cipher was once "military grade" too.

Lapo Luchini reshared this.

in reply to VessOnSecurity

"Military grade" is just another expression for "built in the cheapest way by the lowest bidder'

Lapo Luchini ha ricondiviso questo.


The Archive is back! (In read only mode). Get to the things you love, and we will continue our quest to be dependable, clean up the mess left behind, and be there for you.

archive.org


Lapo Luchini ha ricondiviso questo.


LLMs can’t perform “genuine logical reasoning,” Apple researchers suggest

Irrelevant red herrings lead to "catastrophic" failure of logical inference.

arstechnica.com/ai/2024/10/llm…

Lapo Luchini reshared this.


Lapo Luchini ha ricondiviso questo.


There is a lot of alarmist stuff going around about .io ccTLD being "retired", fedi instances that use it having to move, etc. 👀

Keep calm. Here's the one thing you need to know about this right now:

👉 Even if .io ever gets "retired", it will take *years* for this to affect already delegated .io domains in any way at all.

I cannot stress this enough, we are talking years if not decades.

Soviet Union dissolved 33 years ago, but .su domains still resolve.

Deep breaths.
Carry on.

#Fediverse

Questa voce è stata modificata (2 mesi fa)

reshared this

in reply to Michał "rysiek" Woźniak · 🇺🇦

more importantly, who gives a shit?
fuck anyone who profiteered
off the backs of the Chagossians:
you aren't even a serious technologist
if you prioritized marketing vanity
over sustainability for your project.
you reap what you sow;
you get exactly what you deserve.


Just in case you need a NodeJS script to sort extended #ZSH history which doesn't break on multi-line entries:

#! /usr/bin/env node
const fs = require('fs');
const lines = fs.readFileSync(process.argv[2], 'utf8').split(/(?<=[^\\])\n/);
lines.sort((a, b) => a.split(/:/)[1] - b.split(/:/)[1]);
fs.writeFileSync(process.argv[2], lines.join('\n'), 'utf8');
#ZSH

Lapo Luchini ha ricondiviso questo.


In principle I could even see myself supporting Mozilla's advertising thing.

It would not be a bad idea, in general, to have a privacy-preserving, ethical advertising network. It would serve as an alternative for vendors, and as an example to regulators that this is possible – and that banning targeted advertising can be done without hurting organizations that rely on ads to stay afloat.

Problem is, I don't trust Mozilla to hold up their side of this.

I used to, but not anymore.

#Mozilla

Lapo Luchini reshared this.

in reply to Michał "rysiek" Woźniak · 🇺🇦

@BassRck5000 I'm not ignoring it, I just think that i prefer a lesser evil over more ones who've lost their moral compas decades ago.

Not agreeing with you, doesn't make me ignorant. It just means I evaluate it differently.

in reply to Dynom

@dynom @BassRck5000 it's not about agreeing or not, it's about throwing around clichés like "running a profit is not a bad thing".

And I did not call you ignorant. I said you seem to be ignoring the context. That's a different thing, please don't twist my words like that.


Lapo Luchini ha ricondiviso questo.


OUTDATED⚠️
Mozilla bought the Android email app K-9 (which didn’t include any trackers) and integrated trackers as part of #Mozilla‘s rebranding under the #Thunderbird name.

They even made it opt-out instead of opt-in. Their defense for breaking the law: ”we wouldn’t have enough data if we obeyed the law.“

It doesn’t matter whether you ”anonymized“ the data or not: If you want to extract data from someone’s device to yours, you may do so only if they knowingly consented.
sigmoid.social/@davidculley/11…


Gibt sogar ein GitHub-Issue dazu. Money quote:

»Unfortunately we cannot make this type of data collection opt-in because the limited data from voluntary reports wouldn’t provide enough insights to make informed product decisions. Opt-in data would come from a small, biased subset, leading to flawed conclusions.«

Datenschutz und Einwilligungen sind grundlegende Rechte der Nutzer, die respektiert werden müssen, selbst wenn dies die Datenerhebung erschwert.

github.com/thunderbird/thunder…


Questa voce è stata modificata (1 mese fa)
in reply to David Culley

I just hope somebody will have the will to keep an existing and working "K-9" unadulterated project alive and kicking.
in reply to David Culley

The Thunderbird developers listened to their users and removed tracking entirely. Only the beta version of version 8 contained the telemetry. The final release no longer does, at least for now.

Lapo Luchini ha ricondiviso questo.


I hope this FreeBSD Foundation effort bears sweet ripe fruit: freebsdfoundation.org/blog/why… (I want a supported FreeBSD Laptop! EVEN IF IT IS A DELL)

reshared this


Lapo Luchini ha ricondiviso questo.


Around 2000, humankind split into two groups:

One who was convinced it needed expensive Content Management Systems to keep office documents.

And the other who had an unprecedented productive, global collaboration with repositories and text files.💁‍♂️

Questa voce è stata modificata (2 mesi fa)

Lapo Luchini reshared this.

in reply to Stefan Eissing

Which group is the one that can get images to display inline, even in drafts?
in reply to EndlessMason

@EndlessMason There was a third group which became capable of that. But it ascended shortly afterwards.

Lapo Luchini ha ricondiviso questo.


I read that the official Mastodon instance of the Swiss government will be closing down.

They say there are few active users, low engagement, and minimal interaction, which seems quite plausible. Additionally, they claim that "on platforms like X or Instagram, the Federal Council and the Federal Administration have many more followers." I believe that too, of course.

However, I do not agree with their decision. I think a government shouldn’t be overly concerned about follower counts and interactions, but rather about providing free, autonomous communication that is independent of third-party companies. In my view, a government shouldn’t operate like a business focused on "numbers."

Still, I appreciate their experiment - many governments, like the Italian one, haven’t even tried.

Regarding costs and management effort: an instance with 5 users and 3,500 followers (numbers provided by them) can run on a VPS for €3 a month and doesn't require heavy moderation. The cost for them is nearly zero. Yet, the freedom of information and discussion, especially for a Neutral Country, should always be a priority.

I believe that maintaining control over one’s information channels is crucial, especially in today's world. But, I fear that decision-makers only consider the numbers, which often favor the flashiest - but worse - solutions.

Encouraging citizens to use closed platforms is, in my opinion, a wrong choice.

Thanks to the Swiss government for at least giving it a shot.

admin.ch/gov/it/pagina-inizial…

#Mastodon #FreedomOfSpeech #Switzerland #Fediverse #SocialNetworks

reshared this

in reply to Stefano Marinelli

«I think a government shouldn’t be overly concerned about follower counts and interactions, but rather about providing free, autonomous communication that is independent of third-party companies. In my view, a government shouldn’t operate like a business focused on "numbers."»

Absolutely 👏

in reply to rolgalan

Exactly this. A closed platform should never be supported; Facebook and Twitter are now severely limited of you don't hav an account, to thr point where most posts are not viewable. "But creating an account is free" is not the solution, obviously.

They missed the point there, I think, and as stated they didn't really push it in any form.

CC: @stefano@bsd.cafe



Lapo Luchini ha ricondiviso questo.


"What were you asked, and offered?" the dragon said.

"To drive you off, to receive the hand of the princess and half the kingdom," the knight replied.

"Very well, I'll go."

"Wait, what?"

"There once was a huge empire, that was halved..." The dragon laughed. "I'll go. For now."

#MicroFiction #SmallStories #TootFic

Lapo Luchini reshared this.


in reply to April King

And they did it in TLS as well:

openssl s_client -connect signed.bad.horse:443 -servername signed.bad.horse

in reply to April King

I don't exactly know what or why this is, but I'm glad it exists anyway!


Lapo Luchini ha ricondiviso questo.


Commit to the bit, free the JavaScript™! javascript.tm/

reshared this


Lapo Luchini ha ricondiviso questo.


Hey folks, so the Quantum Witch demo has been released :) It lets you explore a few locations from the beginning of the story, and even get up to the first big story event!

I hope you enjoy it, and all boosts and very appreciated :)

store.steampowered.com/app/310…

#indiedev #indiegame #demo

reshared this


Lapo Luchini ha ricondiviso questo.


We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI

labs.watchtowr.com/we-spent-20…

#IT

#IT

Lapo Luchini reshared this.

in reply to Stefano Marinelli

That is not only a fascinating exploit, but the article is extremely well-written. Who would expect an article on a subject this dull to be so suspenseful and, at the same time, humorous?

Lapo Luchini ha ricondiviso questo.


Reading about the computer you made... On the computer you made.

How meta.

reshared this



A short history about keeping your #ssh daemons up-to-date by checking their banners, unexpectedly short debugs, happenstance, #hpn, and #RFC definitions.
#ssh #RFC #hpn


Lapo Luchini ha ricondiviso questo.


I recently saw an amazing Navajo rug at the National Gallery of Art. It looks abstract at first, but it is a detailed representation of the Intel Pentium processor. Called "Replica of a Chip", it was created in 1994 by Marilou Schultz, a Navajo/Diné weaver and math teacher. Intel commissioned the weaving as a gift to the American Indian Science & Engineering Society. 1/6
in reply to Ken Shirriff

Marilou Schultz also created a weaving "Untitled (Unknown Chip)", 2008. Antoine Bercovici identified it for me as the AMD K6 III processor. These weavings are part of an exhibition "Woven Histories: Textiles and Modern Abstraction". The exhibition is no longer at the National Gallery of Art but will be at the National Gallery of Canada (Ottawa) in November and the Museum of Modern Art (New York) next April. 5/6
in reply to Ken Shirriff

For more information on the Pentium weaving, see my latest post: righto.com/2024/08/pentium-nav… 6/6

Lapo Luchini ha ricondiviso questo.


Two weeks ago I asked on here about indie developers and everyone told me I had to speak to @nikki so I did! Quantum Witch looks wonderful

theguardian.com/games/article/…

reshared this



!Friendica Support I read all of issue 13719 and I got the gist that URLs shown in the browsers are not the URLs I should paste in my search bar to import a message (to like it, or to boost it), but I don't understand how to do that.
I have seen Threads messages shared/boosted by others, but I can't manage to do it myself from my Friendica account.
Is that possible?

Lapo Luchini ha ricondiviso questo.


Fun fact: the code which took Apollo 11 to the moon is available on github github.com/chrislgarry/Apollo-…

And if you look through it you'll see that - joyfully - it also includes original comments.

My absolute favourite thing about the Moon Code is that it includes comments like this: "TEMPORARY - I HOPE HOPE HOPE"

in reply to Steve Loughran

I should add that for us software developers, having people look at your code 50 years later and muttering “what was that idiot thinking” is actually a success we can only dream of.
Usually the time limit is 18 months and the person being critical is your future self.
Questa voce è stata modificata (3 mesi fa)


#golang Fediverse please help a Go-noob: is it possible to get the `git describe` string from a `go install github.com…@latest` type installation?
In order to use for `--version` output, that in various projects report no version when installed that way.

E.g.:

% go install github.com/walles/moar@latest
% moar --version
Should be set when building, please use build.sh to build

Lapo Luchini ha ricondiviso questo.


My latest model! This is an IBM Series\1 with a 5251 terminal. This is a 1:12 scale model! Any of you worked with or on one if these back in the days? What was it used for where you worked?
Questa voce è stata modificata (4 mesi fa)

Lapo Luchini reshared this.


Lapo Luchini ha ricondiviso questo.


Priorities. So important.

- EU-Petition to keep video games playable by forcing the publishers to NOT remove essential functions: 302.000 signatures in less than a month.

[1]- EU-Petition to tax the rich and keep our planet inhabitable: 271.000 signatures after 10 months.

[2]If you care about playing your games, please also support the other petition to make sure you still can do that and many other things, ok? :)

[1] eci.ec.europa.eu/045/public/#/…
[2] eci.ec.europa.eu/038/public/#/…

Questa voce è stata modificata (4 mesi fa)

reshared this


Lapo Luchini ha ricondiviso questo.


LAN parties are not so common anymore in our hyper connected world of 2024 but at South Pole, when the satellites are down, it might as well be 1997 all over again.

reshared this