GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by CyberFrog (froge@social.glitched.systems)

  1. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Thursday, 02-Jul-2026 06:59:44 JST CyberFrog CyberFrog

    fedi there is so much full force sloperating happening in open source accounting software...

    no, NO look at me fedi, I know it's boring but you need to look at the accounting software, it's bad ok, it's really fucking bad out there, and I don't think your financial situation should depend on whatever logic an LLM spat into a bunch of accounting software without review

    beancount developer fantasizing about running "5-8 agents" on the beancount codebase and babysitting them instead of writing code
    https://groups.google.com/g/beancount/c/cz8Xwnb7BLE/m/LSA3rTfMAgAJ

    ledger accepting LLM code and talking about vibe coded ports to Rust (as an experiment, at least, but lol)
    https://github.com/ledger/ledger/discussions/2474

    rustledger (seems almost entirely vibe coded)
    https://github.com/rustledger/rustledger

    paper by the american accounting association on "Applying Large Language Models in Accounting"
    https://publications.aaahq.org/jeta/article-abstract/21/2/133/12800/Applying-Large-Language-Models-in-Accounting-A

    In conversation about a month ago from social.glitched.systems permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Some words about LLMs and Agents
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Implementation language choice · ledger/ledger · Discussion #2474
      I see there are no discussions here, yet, but maybe this is a good one to start. I've read a Medium article about this project, looked at the code, made this overview below and was surprised to see...
    3. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - rustledger/rustledger: Modern plain text accounting. Beancount compatible.
      Modern plain text accounting. Beancount compatible. - rustledger/rustledger

  2. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Saturday, 24-Jan-2026 00:55:29 JST CyberFrog CyberFrog
    in reply to
    • Kevin Beaumont
    • Rich Felker

    @dalias@hachyderm.io @GossiTheDog@cyberplace.social secure encryption will unavoidably cause you to lose everything if you lose your keys, by default....

    but the real issue is that microsoft engineers know this, and didn't even so much as try to program a secure backup feature that doesn't expose the keys, or even give a popup in the installer warning people that their drives will be completely unencrypted and insecure by default without an MS account... or any of the 1000s other things they could do to communicate their security stance to users tbh

    In conversation about 6 months ago from social.glitched.systems permalink
  3. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Saturday, 24-Jan-2026 00:13:26 JST CyberFrog CyberFrog
    in reply to
    • Kevin Beaumont

    @GossiTheDog@cyberplace.social Windows charging people for a pro/enterprise license to encrypt more than the OS drive (while still uploading their keys to the cloud) is also just insane to me

    For a long time I think you had to pay for a pro license to even encrypt your drives at all, but luckily they stopped doing that, instead you get to encrypt the OS drive for free and everything else is gonna cost you a few hundred extra dollars 💀

    In conversation about 6 months ago from social.glitched.systems permalink
  4. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Saturday, 24-Jan-2026 00:13:24 JST CyberFrog CyberFrog
    in reply to
    • Kevin Beaumont

    @GossiTheDog@cyberplace.social oh also as a note to all the users who installed windows with a local system account instead of linking your microsoft account

    none of you have an encrypted OS drive, it just doesn't encrypt your drives by default if you do that because it can't back the keys up to MS cloud

    In conversation about 6 months ago from social.glitched.systems permalink
  5. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Thursday, 13-Nov-2025 07:11:29 JST CyberFrog CyberFrog
    in reply to
    • Adrianna Tan

    @skinnylatte@hachyderm.io to be fair in many parts of the world where people do this, healthcare and the social aspects aren't too bad to adjust to, getting a permanent work/residence VISA is fairly easy in places that aren't the western world, a lot of people go to Thailand or Vietnam or Singapore for this, access to healthcare and social services isn't so bad in many cases either

    I even knew someone who was actively living in Bali for a long time, and arguably that's just kind of a bad place to exist in, but the guy was so comparatively wealthy that he just bypassed all the issues with money and seemed to live a perfectly normal existence with a high quality of life for many years

    In conversation about 9 months ago from social.glitched.systems permalink
  6. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Saturday, 30-Aug-2025 11:00:52 JST CyberFrog CyberFrog
    in reply to
    • prettygood
    • Ⓑⓡⓔⓣⓣ

    @prettygood@socially.drinkingatmy.computer @brettm@swarm.coiloptic.org the software explicitly lets me decide to use an arbitrary location, it should just ignore that my desktop isn't following spec in that case... if I had just slammed "save" and not chosen a specific directory the browser can feel free to create the default one from the xdg desktop spec

    but like, unless I do that it should fuck off tbh

    In conversation about a year ago from social.glitched.systems permalink
  7. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Friday, 25-Jul-2025 13:15:21 JST CyberFrog CyberFrog
    in reply to
    • SuperDicq
    • T man :sex: :puffgiga: :puffpowerroll:
    • Blurry Moon

    @SuperDicq@minidisc.tokyo @memdmp@catgirl.center @sun@shitposter.world @theorytoe@ak.kyaruc.moe GNU taler is specifically not a currency by itself, it literally says that on the website, it will just never be a currency

    https://www.taler.net/Not a new currency!

    In conversation about a year ago from social.glitched.systems permalink

    Attachments


  8. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Thursday, 24-Jul-2025 19:28:37 JST CyberFrog CyberFrog
    in reply to

    @icedquinn@blob.cat @SuperDicq@minidisc.tokyo @theorytoe@ak.kyaruc.moe @sun@shitposter.world AML/KYC has stacks and stacks of reports about how it entirely failed as a system to prevent fraud or harmful financing, the banking sector itself reports that less than 1% of AML/KYC checks prevent any kind of "harmful financing"

    the USD is still the most widely used criminal currency on earth as a result
    https://www.cato.org/blog/money-laundering-laws-ineffective-expensive

    In conversation about a year ago from social.glitched.systems permalink
  9. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Sunday, 20-Jul-2025 09:55:18 JST CyberFrog CyberFrog

    TIL that the rsa crate for Rust has a timing sidechannel attack in the implementation and it's just... unfixed since 2023

    very cool
    https://rustsec.org/advisories/RUSTSEC-2023-0071

    In conversation about a year ago from social.glitched.systems permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      RUSTSEC-2023-0071: rsa: Marvin Attack: potential key recovery through timing sidechannels › RustSec Advisory Database
      from Rust Project Developers
      Security advisory database for Rust crates published through https://crates.io
  10. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Monday, 14-Jul-2025 16:41:33 JST CyberFrog CyberFrog
    in reply to
    • ✧✦Catherine✦✧
    • Risotto Bias

    @whitequark@mastodon.social @ireneista@adhd.irenes.space @risottobias@toot.risottobias.org I actually agree, 2fa is very easy via TOTP, but I was hedging my bets because a common complaint is still "it's inconvenient" lol

    In conversation about a year ago from social.glitched.systems permalink
  11. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Monday, 14-Jul-2025 16:37:25 JST CyberFrog CyberFrog
    in reply to
    • ✧✦Catherine✦✧
    • Risotto Bias

    @whitequark@mastodon.social @risottobias@toot.risottobias.org @ireneista@adhd.irenes.space the quality of your code and project is bad if you're not implementing 2fa in the modern world, users don't like to do security, it ruins UX most of the time, but it's a necessary thing to do otherwise people will just keep getting hacked and that's far worse for everyone (including the individuals) than inconvenience tbh

    In conversation about a year ago from social.glitched.systems permalink
  12. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Monday, 14-Jul-2025 16:03:15 JST CyberFrog CyberFrog
    in reply to
    • gigabecquerel
    • ✧✦Catherine✦✧

    @whitequark@mastodon.social @gigabecquerel@chaos.social hasn't that been in force for months now? I thought all the groups that were going to comply already did so... or got blocked by ofcom

    I did see a spam campaign on mastodon about 2 days ago which was DMing people about fake ID verification, maybe it was that too

    In conversation about a year ago from social.glitched.systems permalink
  13. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Sunday, 13-Jul-2025 07:23:38 JST CyberFrog CyberFrog
    in reply to
    • David Chisnall (*Now with 50% more sarcasm!*)

    @david_chisnall@infosec.exchange I’m starting to think that the concerns about LLMs hurting critical thinking ability might have been seriously underrated.yes, absolutely

    In conversation about a year ago from social.glitched.systems permalink
  14. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Wednesday, 02-Jul-2025 19:18:56 JST CyberFrog CyberFrog
    in reply to
    • SuperDicq

    @SuperDicq@minidisc.tokyo you should go use something with objectively worse encryption and security then, nobody is stopping you from making dumb choices because you don't like the way Signal works

    but everyone else will still recommend it because their tech is good, you shouldn't be confused about that LOL

    In conversation about a year ago from social.glitched.systems permalink
  15. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Wednesday, 02-Jul-2025 19:03:12 JST CyberFrog CyberFrog
    in reply to
    • SuperDicq

    @SuperDicq@minidisc.tokyo yeah, and they still require phone numbers for signs ups which is dumb garbage, but they also literally invented the double ratchet encryption algorithm for instant messaging, they implemented sealed sender for hiding user metadata, and in various ways have done legitimate research on defending against online surveillance

    you win some and lose some, Moxie isn't a perfect human being, but signal keeps getting recommended because it's genuinely doing better than 90% of other messaging platforms out there in terms of privacy for their users, even if it does have dumb shit like google play integration still

    In conversation about a year ago from social.glitched.systems permalink
  16. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Wednesday, 02-Jul-2025 18:58:33 JST CyberFrog CyberFrog
    in reply to
    • SuperDicq

    @SuperDicq@minidisc.tokyo despite the shitty aspects of their technology they're still genuinely a world leader in privacy preserving messaging protocols tbh

    In conversation about a year ago from social.glitched.systems permalink
  17. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Tuesday, 24-Jun-2025 03:18:27 JST CyberFrog CyberFrog
    in reply to
    • ✧✦Catherine✦✧

    @whitequark@mastodon.social I actually don't know of a single electronic component that isn't just a copy of nature on some level, humans are innovative in the sense that we take inspiration from what is around us and jam it into new shit to see if it works, and not much else lol

    In conversation about a year ago from social.glitched.systems permalink
  18. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Thursday, 19-Jun-2025 17:58:31 JST CyberFrog CyberFrog

    So... Steam offers this "shader pre-caching" service where the client will detect your hardware and download pre-compiled game shaders to increase your system performance, which is cool and all, but apparently these shaders are taken from other random people's computer when steam detects a matching set of hardware

    So now I'm wondering how much validation is actually done on these shaders, and how this works, and if I can actually just use steam to send random code to random people by pretending it's a shader lol

    In conversation about a year ago from social.glitched.systems permalink
  19. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Wednesday, 18-Jun-2025 09:53:05 JST CyberFrog CyberFrog
    in reply to
    • Tekniquelly correct
    • snickerbockers

    @tek@freeradical.zone @snickerbockers@freeradical.zone sure, AI is useful sometimes or we would just be ignoring it right now, but it's useful in the same way that an IDE helps you write code a little easier... you'd be stupid and insane to think an IDE could produce reasonable code without someone checking over it and running the system themselves

    my main issue with AI is that unlike an IDE the quality is so poor that even an intermediate programmer or user will outskill it considerably without much effort... AI is just sort of stupid, and bad at the jobs we use it for, it's like a self driving car that can't actually drive by itself (which makes it seem pretty damn useless)

    In conversation about a year ago from social.glitched.systems permalink
  20. Embed this notice
    CyberFrog (froge@social.glitched.systems)'s status on Thursday, 29-May-2025 21:00:11 JST CyberFrog CyberFrog
    in reply to
    • Rich Felker

    @dalias@hachyderm.io I actually do think the automated connections to a remote system for updates are bad and should be removed in this case, but it's just wild to me that you genuinely don't believe in mandatory security updates, and further that you actually seem to not understand that the network traffic from a VPN is itself attack surface... this means that even if you trust both ends of the connection you should still install security relevant patches to mitigate issues on the network or in the protocol itself, at the very least, not to mention bugs that can occur when an untrusted application runs locally

    most people don't actually completely trust all the applications on their device anyway, even if that application is granted network access to function, this is why defense-in-depth and sandboxing is such a big field of study still

    In conversation about a year ago from social.glitched.systems permalink
  • Before

User actions

    CyberFrog

    CyberFrog

    Just here to vibe and share cool computer facts, your friendly neighborhood tech frog. Will often discuss things like distributed systems, programming, society, and computer security. Politics WILL come up sometimes. Video games are cool too :blobowo:Follow for more fun computer adventures!!

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          275421
          Member since
          9 Aug 2024
          Notices
          65
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.