@dalias @wyatt @tomrittervg "WE EXPLICITLY WENT OUT OF OUR WAY AND CHOSE NOT TO VOTE, THEN A CHOICE WAS MADE WE DISAGREE WITH, THIS IS UNETHICAL AND WRONG"
lol. lmao, even.
@dalias @wyatt @tomrittervg "WE EXPLICITLY WENT OUT OF OUR WAY AND CHOSE NOT TO VOTE, THEN A CHOICE WAS MADE WE DISAGREE WITH, THIS IS UNETHICAL AND WRONG"
lol. lmao, even.
@quad Even compared to other modern 7200rpm Seagates (less so those from pre-2010s) they're louder than you'd think. The price is right, but the clank is might.
@wolf480pl @quad I never heard any HGST drives live, and mic recordings are not normalized so can't compare them. They do get super crunchy while busy though.
POV: It is 2025 and you decide to watch the new season of your favorite animated shorts legally for once
@domi @wolf480pl @lanodan kinda same, for most of my boxes I just keep non-breaking repo upgrades running on autopilot, and for containers/etc subscribed to releases on GitHub (Watch -> Custom -> Releases) et al so that I get notification emails whenever they draft a new release, then update to the latest greatest ASAP. Keeping up with the entire firehose on oss-security etc seems like a full-time job, corporate scanners is just extremely expensive security cosplay.
A big, professional company having its 6-digit-priced firewall appliances getting free remote code execution with a single `X-PAN-AUTHCHECK: off` header makes me think OpenWrt et al is not that unprofessional after all
via https://twitter.com/shimaryu703/status/1772211822139240953
@q3k @marcan tbh the fact that it did trigger alarms in those systems, and despite that nobody noticed anything suspicious until a downstream user noticed the backdoor's side effects after upgrading is also telling.
I'm on the receiving end of some mandatory analyzers and due to the sheer volume of hits most of the time I don't really care about why something was found, rather just how to get rid of it. They could safely ignore these systems because of this behavior.
@q3k @marcan Not sure if I'm getting my point across... Not that these tools don't help, they absolutely do, but mine (and many others) reactions to Coverity, Valgrind, etc sounding all the alarms each and every week is "ughhhh, here we go again" and not "something's wrong here"
Why, naturally a library called python-gitlab has its canonical version hosted over at https://github.com/python-gitlab/python-gitlab
A tiny sliver of hell froze over: https://postmarketos.org/blog/2024/03/05/adding-systemd/
>Is Alpine cool with this?
(Most likely) absolutely not, but please keep going
...it appears I need to eat my words: https://social.treehouse.systems/@ariadne/112044941290779320
@domi ohh, alright, good luck then!
(As an aside, I just got an air sensor to measure home air CO2 et al, partially due to sleep issues, and uh it's not looking great here either - might wanna get some sensors too if you have some ESPs lying around)
@domi it's funnier when you see the graph though
@quad tbh I wouldn't mind if they named their products by the MD5 of their respective board gerbers
@quad I know, and they keep changing the systems every now and then to keep you on your guard, and instead of price stickers you get "contact us", and instead of publicly-available firmware files you have support contracts...
Enterprise hardware is so much fun :)
This is exploitable
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.