As a result of a US Government directive, we are suspending access to Fable 5
Article URL: https://twitter.com/ClaudeDevs/status/2065597942602531163
Comments URL: https://news.ycombinator.com/item?id=48511168
Points: 10
# Comments: 1 â Read more
US Government directive to suspend access to Fable 5 and Mythos 5
Article URL: https://www.anthropic.com/news/fable-mythos-access
Comments URL: https://news.ycombinator.com/item?id=48511072
Points: 70
# Comments: 19 â Read more
MacOS 27 Golden Gate: Top New Features
Apple has announced the latest version of macOS. Itâs all about the reintroduction of Siri, which is now accessible from anywhere on the Mac desktop. â Read more
Show HN: ABC Classic 100 Rankings visualised
This weekend is the ABC Classic FM countdown, which prompted me to dust off an old un-published data visualisation of rankings from previous years.
Iâve considered adding a search function, but I also kind of like that it requires a bit of exploration in the current form.
Some of the code is a bit clunky and I wouldnât mind refactoring it. Iâm also not sure about browser compatibility - Iâve only got access to a couple of devices to test it on.
Comments URL: [https://news.yc ⊠â Read more
Launch HN: General Instinct (YC P26) â Frontier models on edge devices
Hey HN, Guanming and Bill here from General Instinct ( https://general-instinct.com/).
After years of working in robotics, we kept running into the same problem: the best models never fit the hardware we actually had available.
The models that performed best were usually designed around datacenter assumptions: large GPUs, lots of memory bandwidth, and reliable network access. But most physical systems have the opposit ⊠â Read more
Victorian taxpayers foot the bill for Ozempic in prison
Victorian taxpayers are footing the bill for prisoners to access weight loss drugs, including Ozempic. â Read more
Victorian taxpayers foot the bill for Ozempic in prison
Victorian taxpayers are footing the bill for prisoners to access weight loss drugs, including Ozempic. â Read more
DuckDuckGo makes its âno-AIâ search engine easier to access as its traffic booms
Article URL: https://techcrunch.com/2026/06/01/duckduckgo-makes-its-no-ai-search-engine-easier-to-access-as-its-traffic-booms/
Comments URL: https://news.ycombinator.com/item?id=48359130
Points: 36
# Comments ⊠â Read more
Hands-On With Gemini Spark: I Gave It Access to My Life and It Friend-Zoned My Boyfriend
Googleâs new AI agent combed through my emails, documents, and calendar to plan a birthday party and still didnât clock the person most important to me. â Read more
Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks
Customer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams. â Read more
The US Can Put People on the Moon. Why Canât It Get Iranians Online?
Jason Rezaian spent years reporting from Iran before being imprisoned by the regime. He says internet access is key to transforming the countryâif only the US government would do something about it. â Read more
The FBI Wants âNear Real-Timeâ Access to US License Plate Readers
Plus: Google publishes a live exploit for an unpatched flaw, the feds arrest two men accused of creating thousands of nonconsensual deepfake nudes, and more. â Read more
Amazon, Facebook, FBI have access to a private intelligence-sharing network
Article URL: https://prismreports.org/2026/05/20/seattle-shield-private-companies-surveillance/
Comments URL: https://news.ycombinator.com/item?id=48226588
Points: 41
# Comments: 4 â Read more
SpaceX IPO Filing Reveals Anthropic Is Paying $15 Billion a Year to Access Its Data Centers
The long-awaited documents SpaceX filed with US regulators Wednesday included details about a lucrative deal to lend GPUs to a major AI rival. â Read more
The US Built a Site to Ensure Fair Access to Public Lands. Then Everything Went Wrong
Recreation.gov was supposed to make access to public lands more equitable and streamlined. Instead, itâs rife with bots and inequality, while a government contractor benefits. â Read more
When I ask Claude Code to fix a bug but forgot to give it access to my repo â Read more
Your iPhone Gets Stolen. Then the Hacking Begins
A bustling underground ecosystem is providing criminals with the tools to unlock iPhonesâand wage phishing attacks against their contacts to access bank accounts and more. â Read more
WhatsApp Adds Meta AI Chats That Are Built to Be Fully Private
The company says its new Incognito Chat allows you to use its AI chatbot without anyone elseâincluding Metaâbeing able to access your conversations. â Read more
Telehealth Abortion Is Still Possible Without Mifepristone
Courts may restrict access to the popular abortion medication mifepristone in the United States. Telehealth providers have backup plans in place. â Read more
Pornhub Restores Access for UK Adults Who Use Appleâs Age Verification
The porn giant blocked its content from new UK users in February but says device-based age verification is more secure than third-party sites. â Read more
The Chinese Government Just Got the Worldâs Largest Digital Rights Conference Canceled
Access Now, the group that organizes RightsCon, says Zambian officials asked it to exclude Taiwanese participants if it wanted the event to proceed as planned. â Read more
The Summer the American Water Crisis Turned Real
Concern over water access are poised to consume summer in the US, as crises in Corpus Christi and across the Colorado River threaten to boil over. â Read more
Exposed Data Illustrates the Nightmare Scenario for a Stalkerware Victim
Extremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure. â Read more
Sanctioned Chinese AI Firm SenseTime Releases Image Model Built for Speed
With US restrictions limiting its access to advanced tech, SenseTime is doubling down on open source with a new model optimized to run on Chinese-made chips. â Read more
Discord Sleuths Gained Unauthorized Access to Anthropicâs Mythos
Plus: Spy firms tap into a global telecom weakness to track targets, 500,000 UK health records go up for sale on Alibaba, Apple patches a revealing notification bug, and more. â Read more
These New Smart Glasses From Ex-OnePlus Engineers Have a Hidden Cost
The Kickstarter-funded glasses from LâAtitude 52°N have AI features bundled for 1 year, but the company doesnât know yet how much it will charge for access after that. â Read more
When my access to the production machine gets revoked â Read more
Farmers rubbish âworst everâ EU free trade agreement
The National Farmersâ Federation says the deal will leave farmers without meaningful access to the EU market. â Read more
UFO disclosure advocate granted access to secretive US bases
President Trump has reportedly given permission for US Congressman Eric Burlison to access the facilities. Burlison, who has long called for more tran⊠â Read more
I built Audiofern to make it simple to turn PDFs into audiobooks. Upload a document, get clean, chapterized narration with natural voices, and share it via a hosted playerâor download M4A/M4B and keep it forever. Files are private by default, and pricing is transparent: pay once by audio hour or subscribe to build a listening library.
Iâm contemplating the idea of switching my activity pub instance from Gootosocial to a Pleroma one. While GTS is kinda cute (lightweight and easy to manage) of a software, the inability to fetch/scroll through peopleâs past toots when visiting a profile or having access to a federated timeline and a proper search functionality âŠetc felt like handicap for the past N months.
@movq@www.uninformativ.de Lots of things stop me đ€Ł crappy wifi, no international roaming, no remote access (by design) just to name a few đ
@prologic@twtxt.net yeah, Iâve had even requested access to it in order to give it a try and report whatever I can but, Sorry I never got to do any of it. 2025 slam dunked a massive pile of đ© over my life (hence the disappearance, trying to avoid talking about any of it) and Iâm just starting to recover (or at least trying to).
@prologic@twtxt.net Iâll create one manually and send you the creds so you can change them as soon as you log in (my instance isnât set up to send emails). Not sure how you could get access to logs, not even my admin account has that on the admin panel. I just snoop trough the /var/log/* when needed.
@aelaraji@aelaraji.com Ahh that would be awesome!!! Iâd also somehow need read access to logs so i can figure shit out on my own đ§
The last few days Iâve been converting some charts to grayscale and adding letters to them in order to improve accessibility. Inskscapeâs âReplace Colourâ extension made things much easier.
I wonder if I could one day try my hand at making an improved variation of that extension that could save and reload a dictionary of replacements to help apply them to multiple filesâŠ
Another idea would be to allow replacement color fills with patterns and vice versa!
Let me save this on vault of ideas for the future :)
@bender@twtxt.net Hmm, didnât find anything. But you mean a giant bucketload of access_log /home/$USER/logs/access.log if=⊠where the condition matches the requested path for said user? Yeah, that gets annoying very quickly. :-D
@bender@twtxt.net Sounds about right.
I had a brainfart yesterday, though. For whatever reason I thought of subdomains, which are modeled with server entries in nginx. So, each could define its own access_log location. However, there are no subdomains in place! Searching around, I didnât find any solution to give each user their own access log file.
One way would be a cronjob, aeh, systemd timer as I learned the other day, that greps the main access log and writes all user access log files with only the relevant stuff.
access.log files. Hence theyâll never see followers, unless we notify them out of band. đ«€
I mean, granting everyone read access, maybe?
access.log files. Hence theyâll never see followers, unless we notify them out of band. đ«€
@movq@www.uninformativ.de Actually, @threatcat@tilde.club popped up in my own access log first. Thatâs how I discovered the feed. :-) So I figured that this feed author actually sees my reply. The hope is that with the next mention of my feed in threatcatâs feed, the other tilde users, who are following threatcat, are then also informed of my existence. :-)
I donât know how tilde.club is set up. But it should be relatively easy to give all users access to their nginx access logs. Not sure if somebody already requested that or not. But Iâd encourage tilde users to ask for that. Maybe also just for twtxt.txt and/or in a custom, reduced log format.
@lyse@lyse.isobeef.org Thereâs a couple of new users on https://tilde.club, but since this is a shared host, I doubt that they have access to their access.log files. Hence theyâll never see followers, unless we notify them out of band. đ«€
Account Takeover via IDOR: From UserID to Full Access â Read more
@movq@www.uninformativ.de Gemini liked your opinion very much. Here is how it countered:
1. The User Perspective (Untrustworthiness)The criticism of AI as untrustworthy is a problem of misapplication, not capability.
- AI as a Force Multiplier: AI should be treated as a high-speed drafting and brainstorming tool, not an authority. For experts, it offers an immense speed gain, shifting the work from slow manual creation to fast critical editing and verification.
- The Rise of AI Literacy: Users must develop a new skillâAI literacyâto critically evaluate and verify AIâs probabilistic output. This skill, along with improving citation features in AI tools, mitigates the âgaslightingâ effect.
The fear of skill loss is based on a misunderstanding of how technology changes the nature of work; itâs skill evolution, not erosion.
- Shifting Focus to High-Level Skills: Just as the calculator shifted focus from manual math to complex problem-solving, AI shifts the focus from writing boilerplate code to architectural design and prompt engineering. It handles repetitive tasks, freeing humans for creative and complex challenges.
- Accessibility and Empowerment: AI serves as a powerful democratizing tool, offering personalized tutoring and automation to people who lack deep expertise. While dependency is a risk, this accessibility empowers a wider segment of the population previously limited by skill barriers.
The legal and technical flaws are issues of governance and ethical practice, not reasons to reject the core technology.
- Need for Better Bot Governance: Destructive scraping is a failure of ethical web behavior and can be solved with better bot identification, rate limits, and protocols (like enhanced
robots.txt). The solution is to demand digital citizenship from AI companies, not to stop AI development.
Design trends I think will take off in 2026
but tierlist

S - move from flat design to more detailed, 3D, more complex logos.
A - glass, not just liquid, Windows Vista, 7, 11,⊠accessibility concerns, but I like to see it.
B-/C+ - black and white icons, favicons. I did it before it was cool, but itâs getting overused.
E - gradientslop, barely started, already all blends together.
Event gives access to small wineries in Tasmania
The owners of around forty vineyards in the south of the state are hoping the weather holds out for the next few days as they prepare to open the gates for the annual Spring in the Vines. â Read more
Trump ends Canada access at shared border library â Read more
Salesforce defends security practices after Qantas hack
Hackers used AI-powered voice phishing to trick employees into granting database access. â Read more
How I was able to discover Broken Access Control â Read more
Sniffer dogs tested in real-world scenarios reveal need for wider access to explosives
Dogs arenât just our best friends, theyâre also key allies in the fight against terrorism. Thousands of teams of explosive detection dogs and their handlers work 24/7 at airports, transit systems, cargo facilities, and public events around the globe to keep us safe. But canine detection is an art as well as a science: success depends not only on the skill of both dog and human, but also on their bond, and may vary ⊠â Read more
Poorer health linked to more votes for Reform UK, 2024 voting patterns suggest
Poorer health is linked to a higher proportion of votes for the populist right wing political party, Reform UK, indicates an analysis of the 2024 general election voting patterns in England, published online in the open access journal BMJ Open Respiratory Research. â Read more
Bypass 403 Response Code by Adding Creative String | IRSYADSEC
HTTP 403 is a response code indicating that access to the requested resource is forbidden. This can happen due to various reasons, such asâŠ
[Continue reading on Inf ⊠â Read more
Docker Model Runner on the new NVIDIA DGX Spark: a new paradigm for developing AI locally
Weâre thrilled to bring NVIDIA DGXâą Spark support to Docker Model Runner. The new NVIDIA DGX Spark delivers incredible performance, and Docker Model Runner makes it accessible. With Model Runner, you can easily run and iterate on larger models right on your local machine, using the same intuitive Docker experience you already trust. In this⊠â Read more
** The Access Control Apocalypse: How Broken Permissions Gave Me Keys to Every Digital Door**
Hey theređ
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/th ⊠â Read more
Unlocking Local AI on Any GPU: Docker Model Runner Now with Vulkan Support
Running large language models (LLMs) on your local machine is one of the most exciting frontiers in AI development. At Docker, our goal is to make this process as simple and accessible as possible. Thatâs why we built Docker Model Runner, a tool to help you download and run LLMs with a single command. Until⊠â Read more
Stealing Part of a Production Language Model (2024)
We introduce the first model-stealing attack that extracts precise, nontrivial information from black-box production language models like OpenAIâs ChatGPT or Googleâs PaLM-2. Specifically, our attack recovers the embedding projection layer (up to symmetries) of a transformer model, given typical API access. For under $20 USD, our attack extracts the entire projection matrix of OpenAIâs ada and babbage language models. We thereby confirm, for the first time, that these black-box ⊠â Read more
iOS 26: See Your Full Call History With Any iPhone Contact
Buried within iOS 26 is a hidden history that lets you see every call youâve ever exchanged with a specific contact, potentially going back years. You might not know it, but you can access this detailed call history on your iPhone in seconds.
Viewing the new extended history screen can come in handy when you need to recall when you last spoke with someone. ⊠â Read more
How GitHub Copilot enabled accessibility governance process improvements in record time
See how we turned weekly accessibility grade signals into an automated, accountable remediation workflowâpowered by GitHub Copilot and crossâfunctional collaboration.
The post [How GitHub Copilot enabled accessibility governance process improvements in record time](https://github.blog/ai-and-ml/github-copilot/how-we-automated-accessibility-compliance-in-five-h ⊠â Read more
One iPhone led police to gang suspected of sending up to 40,000 stolen UK phones to China
BBC News is given access to what the Met Police says is the UKâs largest operation against mobile phone thefts. â Read more
My open letter, to the European Commission digital markets act team:
Hello,
I am joining other developers, concerned about Googles new plan, to approve every app and effectively destroy most of the competing 3rd party stores this way. The biggest one of these alternative stores, most known for their focus on user and developer privacy, already states, this would make it impossible for them to operate: https://f-droid.org/cs/2025/09/29/google-developer-registration-decree.html
Even communities like the XDA forum, where new developers are often introduced to the world of Android development, would likely be strongly impacted, as making, publishing and installing Android apps is made less accessible.
I am not just writing on their behalf, I run a small website myself (https://thecanine.ueuo.com/), that both provides legal modifications, for some android apps - for example adding an amoled dark theme, to the most popular XMPP chat client for Android, or increasing one of Androids keyboard apps height. This all comes after Googles previous changes to the Android operating system, that prevent users from installing old apps (old to Google, can mean only a couple of months, without an update - https://developer.android.com/google/play/requirements/target-sdk and the target version gets increased every year). I rely on apps developed by a single developer, even for things like making the pixel art presented on my website and sideloading as a way to make these apps work, before developers can catch up to Googleâs new requirements - if Google is allowed to slowly kill these options, us digital artists will soon lose the tools we need to create digital art.
Unlimited access to Docker Hardened Images: Because security should be affordable, always
Every organization we speak with shares the same goal: to deliver software that is secure and free of CVEs. Near-zero CVEs is the ideal state. But achieving that ideal is harder than it sounds, because paradoxes exist at every step. Developers patch quickly, yet new CVEs appear faster than fixes can ship. Organizations standardize on⊠â Read more
One iPhone led police to gang suspected of sending up to 40,000 stolen UK phones to China
BBC News is given access to what the Met Police says is the UKâs largest operation against mobile phone thefts. â Read more
Australian acitivists allege physical, verbal abuse by Israeli authorities
The Israeli government is facing accusations of mistreatment, including allegations that some activists were denied access to their lawyers. â Read more
wafer.space Launches GF180MCU Run 1 for Custom Silicon Fabrication
wafer.space has launched its first pooled silicon fabrication run on Crowd Supply, known as GF180MCU Run 1. The campaign offers designers the opportunity to fabricate 1,000 chips of their own design using GlobalFoundriesâ 180 nm mixed-signal process. The initiative is aimed at providing accessible, structured access to custom silicon, with dies expected to ship in [âŠ] â Read more
Watch on iPlayer: Access All Areas - When Country Comes to Town
Go behind the scenes as country music takes over the Royal Albert Hall. â Read more
Fine-Tuning Local Models with Docker Offload and Unsloth
Iâve been experimenting with local models for a while now, and the progress in making them accessible has been exciting. Initial experiences are often fantastic, many models, like Gemma 3 270M, are lightweight enough to run on common hardware. This potential for broad deployment is a major draw. However, as Iâve tried to build meaningful,⊠â Read more
Docker MCP Toolkit: MCP Servers That Just Work
Today, we want to highlight Docker MCP Toolkit, a free feature in Docker Desktop that gives you access to more than 200 MCP servers. Itâs the easiest and most secure way to run MCP servers locally for your AI agents and workflows. The MCP toolkit allows you to isolate MCP servers in containers, securely configure⊠â Read more
Tiny RISC-V Development Board with WCH CH32V317WCU6 Available from $6.80
The nanoCH32V317 is a compact development board created by MuseLab to simplify prototyping and embedded system development. It integrates USB connectivity, Ethernet support, and a straightforward programming interface through USB Type-C, providing an accessible platform for engineers and hobbyists working with RISC-V microcontrollers. The board is powered by the WCH CH32V317WCU6, a RISC-V microcontro ⊠â Read more
DietPi September 2025 Update Brings Faster Backups and Roon Server Early Access
The September 20th release of DietPi v9.17 introduces smaller and more efficient system images, faster backups with reduced disk usage, and a new toggle for Roon Serverâs early access builds. The update also addresses SPI bootloader flashing issues on Rockchip devices, improves Raspberry Pi sound card handling, and includes multiple bug fixes across tools and [âŠ] â Read more
Pretty happy with my zs-blog-template starter kit for creating and maintaining your own blog using zs đ Demo of what the starter kit looks like here â Basic features include:
- Clean layout & typography
- Chroma code highlighting (aligned to your site palette)
- Accessible copy-code button
- âOn this pageâ collapsible TOC
- RSS, sitemap, robots
- Archives, tags, tag cloud
- Draft support (hidden from lists/feeds)
- Open Graph (OG) & Twitter card meta (default image + per-post overrides)
- Ready-to-use 404 page
As well as custom routes (redirects, rewrites, etc) to support canonical URLs or redirecting old URLs as well as new zs external command capability itself that now lets you do things like:
$ zs newpost
to help kick-start the creation of a new post with all the right âstuffââą ready to go and then pop open your $EEDITOR đ€
«Welcome to the #AutomatingGIS processes course! Through interactive lessons and hands-on exercises, this course introduces you to #GeographicDataAnalysis using the #Python programming language. If you are new to Python, we recommend you first start with the Geo-Python course (geo-python.readthedocs.io) before diving into using it for GIS analyses in this course.
Geo-Python and Automating GIS Processes (â#AutoGISâ) have been developed by the Department of Geosciences and Geography at the University of Helsinki, Finland. The course has been planned and organized by the #DigitalGeographyLab. The teaching materials are openly accessible for anyone interested in learning.»
«Welcome to the #AutomatingGIS processes course! Through interactive lessons and hands-on exercises, this course introduces you to #GeographicDataAnalysis using the #Python programming language. If you are new to Python, we recommend you first start with the Geo-Python course (geo-python.readthedocs.io) before diving into using it for GIS analyses in this course.
Geo-Python and Automating GIS Processes (â#AutoGISâ) have been developed by the Department of Geosciences and Geography at the University of Helsinki, Finland. The course has been planned and organized by the #DigitalGeographyLab. The teaching materials are openly accessible for anyone interested in learning.»
https://autogis-site.readthedocs.io/en/latest/
(via Paul Walter no linkedin)
Hello everyone! đ
After a long while away, Iâm back on twtxt with this new feed.
Some of you might remember me as justamoment@twtxt.net, that was a test account I made for trying things out, but I ended up keeping it more than planned.
I also tried other social platforms in search of a place that felt right for me.
In the end twtxt was the one that ticked all of my boxes:
- Slow social: it act more like a feed reader and I really appreciate that thereâs no flood of content that I canât keep up with.
- No server needed: I absolutely love to have total control over my content, I tend to avoid having moving parts that might break, plus you can put your feed under version control and itâs all backed up.
- Ownership: I can put my feed anywhere I want and nobody can decide if I can access it or not.
- For hackers: a single .txt file allows me to join a community, how cool is that!
This is why I decided to build my own twtxt client, one that allows you to decide how the feed is presented on your âinstanceâ.
Itâs still in the making but Iâll try to share a bit of it once I defined how things should work.
Coincidentally, I discovered that @itsericwoodward@itsericwoodward.com and @zvava@twtxt.net were also building a twtxt client, seems like twtxt is set to grow!
Aussie apple exports to Canada easier as restrictions relaxed
Australia apple growers will have easier access to the Canadian export market following trade negotiations between the nations. â Read more
This probably means that I can no longer host my own website. I donât want to deploy something like Anubis, because that ruins the whole thing: I want it to be accessible from ancient browsers, like OS/2 or Windows 3.11.
Iâll keep an eye on it for a while. Maybe try to block some IPs.
Sooner or later, Iâll take the website down and shift everything to Gopher.
The bots have begun to access my website way more often. Iâm getting about 120k hits on https://www.uninformativ.de/git/ now in a couple of hours.
They donât cache anything, probably on purpose.
It comes in waves. I get about 100 hits (all at once) on that /git endpoint, all from different IPs. Then it takes a moment until I get another wave of about 500-1000 requests (all at once) where they do HEAD requests on some of the paths below /git. I assume they did a GET earlier and are now checking if something has changed.
We use all the Microsoft programs at work - Teams and Outlook especially.
After all kinds of technical problems with Teams, that sometimes go unresolved for over a year, Microsoft shifted their priorities away from fixing things and towards adding an annoying AI Copilot button, that just takes up space and all it does, is loads the website in Teams, so I disabled it. Soon they just add it back, but in a different row of icons, therefore itâs now a different button, you have to disable (I think they added yet another one, to the Teams, on my work phone and I had to disabled that too). Not too long after, the desktop one just enabled itself, because of âan errorâ and I can disable it, but doing so activates a popup, that begs you to turn it back on, every once in a while. You canât disable the popup and can only click âYesâ or âNot nowâ on it. I still keep it disabled, out of principle, but yesterday I noticed yet another Copilot button, this time in the top right corner of my Outlook and this one cannot be disabled, on the business version of Outlook and even on the personal one, itâs only possible to do it through hidden privacy settings, by prohibiting the program from connecting to Microsoft servers, for extra âfeaturesâ.
Thereâs people complaining about it online, so itâs clear nobody really wants it, but at this point Microsofts position is that you will have at least one useless AI button on your screen, at any given time, and you will be happy. And yes, their AI sucks and if I absolutely have to use AI for something, thereâs already 2 better options, we have access to, at work.
I just saw that these motherfuckers also query my twtxt feed. I have to enable access logs for everything again and see who else wants some napalm response. :-(
In 1996, they came up with the X11 âSECURITYâ extension:
https://www.reddit.com/r/linux/comments/4w548u/what_is_up_with_the_x11_security_extension/
This is what could have (eventually) solved the security issues that weâre currently seeing with X11. Those issues are cited as one of the reasons for switching to Wayland.
That extension never took off. The person on reddit wonders why â I think itâs simple: Containers and sandboxes werenât a thing in 1996. It hardly mattered if X11 was âinsecureâ. If you could run an X11 client, you probably already had access to the machine and could just do all kinds of other nasty things.
Today, sandboxing is a thing. Today, this matters.
Iâve heard so many times that âX11 is beyond fixable, itâs hopeless.â I donât believe that. I believe that these problems are solveable with X11 and some devs have said âyeah, we could have kept working on itâ. Itâs that people donât want to do it:
Why not extend the X server?
Because for the first time we have a realistic chance of not having to do that.
https://wayland.freedesktop.org/faq.html
Iâm not in a position to judge the devs. Maybe the X.Org code really is so bad that you want to run away, screaming in horror. I donât know.
But all this was a choice. I donât buy the argument that we never would have gotten rid of things like core fonts.
All the toolkits and programs had to be ported to Wayland. A huge, still unfinished effort. If that was an acceptable thing to do, then it would have been acceptable to make an âX12â that keeps all the good things about X11, remains compatible where feasible, eliminates the problems, and requires some clients to be adjusted. (You could have still made âX11X12â like âXWaylandâ for actual legacy programs.)
Maybe someone can explain this to me.
An #EU citizen trying to access Facebook today faces the following choices (see screenshots).
In there, they say that they are asking this again to comply with #EU rules, and yet the question - and the options to choose from - are the same they had in the past.
So, hm, how does this make them comply with something they werenât complying before? Whatâs the detail Iâm missing?
setpriv on Linux supports Landlock.
Another example:
$ setpriv \
--landlock-access fs \
--landlock-rule path-beneath:execute,read-file:/bin/ls-static \
--landlock-rule path-beneath:read-dir:/tmp \
/bin/ls-static /tmp/tmp/xorg.atom
The first argument --landlock-access fs says that nothing is allowed.
--landlock-rule path-beneath:execute,read-file:/bin/ls-static says that reading and executing that file is allowed. Itâs a statically linked ls program (not GNU ls).
--landlock-rule path-beneath:read-dir:/tmp says that reading the /tmp directory and everything below it is allowed.
The output of the ls-static program is this line:
ârwârâârââââx 3000 200 07-12 09:19 22'491 â /tmp/tmp/xorg.atom
It was able to read the directory, see the file, do stat() on it and everything, the little x indicates that getting xattrs also worked.
3000 and 200 are user name and group name â they are shown as numeric, because the program does not have access to /etc/passwd and /etc/group.
Adding --landlock-rule path-beneath:read-file:/etc/passwd, for example, allows resolving users and yields this:
ârwârâârââââx cathy 200 07-12 09:19 22'491 â /tmp/tmp/xorg.atom
hey! i asked this a while ago but i have to ask again â is anyone willing to offer space on their yarn pod to my friend? i would love to invite her to my own but sheâs unable to access my site for personal reasons. sheâs really interested in seeing what yarn is about so if anyone is willing and able, let me know!
Okay, hereâs a thing I like about Rust: Returning things as Option and error handling. (Or the more complex Result, but itâs easier to explain with Option.)
fn mydiv(num: f64, denom: f64) -> Option<f64> {
// (Letâs ignore precision issues for a second.)
if denom == 0.0 {
return None;
} else {
return Some(num / denom);
}
}
fn main() {
// Explicit, verbose version:
let num: f64 = 123.0;
let denom: f64 = 456.0;
let wrapped_res = mydiv(num, denom);
if wrapped_res.is_some() {
println!("Unwrapped result: {}", wrapped_res.unwrap());
}
// Shorter version using "if let":
if let Some(res) = mydiv(123.0, 456.0) {
println!("Hereâs a result: {}", res);
}
if let Some(res) = mydiv(123.0, 0.0) {
println!("Huh, we divided by zero? This never happens. {}", res);
}
}
You canât divide by zero, so the function returns an âerrorâ in that case. (Option isnât really used for errors, IIUC, but the basic idea is the same for Result.)
Option is an enum. It can have the value Some or None. In the case of Some, you can attach additional data to the enum. In this case, we are attaching a floating point value.
The caller then has to decide: Is the value None or Some? Did the function succeed or not? If it is Some, the caller can do .unwrap() on this enum to get the inner value (the floating point value). If you do .unwrap() on a None value, the program will panic and die.
The if let version using destructuring is much shorter and, once you got used to it, actually quite nice.
Now the trick is that you must somehow handle these two cases. You must either call something like .unwrap() or do destructuring or something, otherwise you canât access the attached value at all. As I understand it, it is impossible to just completely ignore error cases. And the compiler enforces it.
(In case of Result, the compiler would warn you if you ignore the return value entirely. So something like doing write() and then ignoring the return value would be caught as well.)
@bender@twtxt.net Yeah, well, itâs a bit like twtxt. There is a Gopher community, but itâs small. I actually donât like that HTTP is so easily accessible. I donât like it that much when people post links to my site on HackerNews or something like that. Too much exposure.
Gopher is a small world. Itâs slow and cozy.
And much like twtxt, the protocol is simpleÂź, so itâs easier to tinker with it.
Radxa UFS/eMMC Module Reader and Storage Solution Enables Fast Flashing and Scalable Embedded Storage
Radxaâs UFS/eMMC Module Reader is a compact USB 3.0 adapter for flashing OS images, accessing firmware, and transferring large files. It supports both eMMC v5.0 and UFS 2.1 modules with speeds up to 5âŻGbps The adapter is compatible with eMMC and UFS modules from Radxa, and also works with modules from platforms like PINE64 and [âŠ] â Read more
Restrictions frustrate residents reliant on flood-wrecked road
Residents in a small north Queensland community say they are struggling with a system that only allows access to their main road in daylight hours. â Read more
âHermitâ with sexual interest in children had eisteddfod times on fridge
A man who had been accessing child exploitation material since before the birth of the internet had a spreadsheet on his fridge detailing childrenâs events, a court has heard. â Read more
Woman forced to become a âreproductive refugeeâ to legally undergo IVF
Four years after freezing her eggs for the future option of motherhood, Jane was shocked to find she could not use them to access IVF in WA â sending her on an expensive and lonely interstate mission. â Read more
@lyse@lyse.isobeef.org Only 10% of the German population had Internet access in 1998: https://de.wikipedia.org/wiki/Internet_in_Deutschland#/media/Datei:Diagramm_Internetnutzer_in_Deutschland.svg I guess I was lucky in that regard.
(If todayâs tech wasnât constantly trying to track and scam you, I might still be an early adopter.)
Unsere GrĂŒne Glasfaser: UGG Ă€uĂert sich zu RĂŒckzugsgerĂŒchten
Unsere GrĂŒne Glasfaser, das Telefonica und der Allianz gehört, sieht sich nicht in der Krise. Doch es gab Entlassungen. ( TelefĂłnica, Open Access)
[$] Fending off unwanted file descriptors
One of the more obscure features provided by Unix-domain sockets is the
ability to pass a file descriptor from one process to another. This
feature is often used to provide access to a specific file or network
connection to a process running in a relatively unprivileged context. But
what if the recipient doesnât want a new file descriptor? A feature
added for the 6.16 release makes it possible to refuse that offer. â Read more
How âtraveller-friendlyâ is your credit or debit card?
When it comes to planning an overseas trip, deciding how youâre going to access your money can seem overwhelming. Experts outline your options. â Read more
Settings Management for Docker Desktop now generally available in the Admin Console
Weâre excited to announce that Settings Management for Docker Desktop is now Generally Available! Settings Management can be configured in the Admin Console for customers with a Docker Business subscription. After a successful Early Access period, this powerful administrative solution has been enhanced with new compliance reporting capabilities, completing our vision for ⊠â Read more
Settings Management for Docker Desktop now generally available in the Admin Console
Weâre excited to announce that Settings Management for Docker Desktop is now Generally Available! Settings Management can be configured in the Admin Console for customers with a Docker Business subscription. After a successful Early Access period, this powerful administrative solution has been enhanced with new compliance reporting capabilities, completing our vision for ⊠â Read more
When I chose the MIT license for all of my software, I thought:
âShould I use GPL, which I donât really understand? Is that worth it? Yeah, there is a theoretical possibility that some company might use my code in their proprietary product ⊠and then what? Should I sue them to enforce the GPL? Iâm not going to do that anyway, so Iâll just use the MIT license.â
And now we have those LLM scrapers and now itâs suddenly a reality that these companies (ab)use my code. I can see it in my logs. I didnât expect that back then.
GPL wouldnât help, either, of course. (Regardless, I now think that GPL would have been the better choice anyway.)
Iâm honestly considering taking my code and website offline. Maybe make it accessible through some obscure protocol like Gopher or Gemini, but no more HTTP.
(Yes, Anubis might help. Temporarily.)
Iâm just tired.