GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Lorenzo Ancora :verified: (lorenzoancora@ieji.de)

  1. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Saturday, 09-May-2026 21:33:08 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • SuperDicq

    @SuperDicq not on all Linux distributions: on Fedora and rolling release distributions updating will install a new kernel with a patched module which isn't vulnerable; on Debian and Debian-based distributions the update process can be much slower/difficult.
    Additionally, your company/school/institution might also have policies with require the usage of older kernels to ensure retrocompatibility, which can delay the update process.
    The instructions will secure your PC, regardless of distro.😉

    In conversation about 4 months ago from ieji.de permalink
  2. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Saturday, 09-May-2026 09:30:32 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Steve's Place

    @steter not necessarily, it depends on your system configuration and on the policies of your sysadmin. If unsure, follow the above instructions.

    In conversation about 4 months ago from ieji.de permalink
  3. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Saturday, 09-May-2026 08:25:57 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:

    The Copy Fail vulnerability recently discovered in Linux allows for unauthorized admin access on your computer.
    Debian/Ubuntu users can fix with a single root shell command:

    `# echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf; rmmod algif_aead || true`

    ...and then reboot!

    Fedora user?
    Even simpler: run `sudo dnf upgrade --refresh`, reboot, you're safe now!👍😉

    #opensource #foss #linux #security #copyfail #exploit #hacking #debian #ubuntu #fedora #sysadmin

    In conversation about 4 months ago from ieji.de permalink
  4. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Friday, 13-Feb-2026 22:36:52 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:

    Notepad++'s update servers have been compromised by Chinese hackers and all users had been exposed to malware. The developer estimated the overall compromise period spanned from June through December 2, 2025.
    Users should update to version 8.9.1 (or superior) immediately.

    Source: https://notepad-plus-plus.org/news/hijacked-incident-info-update/

    #security #vulnerability #windows #text #editor #notepad #foss #freesoftware #software

    In conversation about 7 months ago from ieji.de permalink

    Attachments


    1. https://ftp.ieji.de/media_attachments/files/116/001/864/232/839/104/original/460c3e5b436ab9f5.png
    2. No result found on File_thumbnail lookup.
      Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
  5. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Thursday, 18-Dec-2025 02:09:21 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo no Alex, don't start victim blaming, it isn't worth it.😅

    I don't really get upset about the mafia thing. I won't call you "racist". Nobody will raise the arm during your speech and call you racist. I never used this word in my life, because it sounds heavy and permanent.

    As the entire world knows, we've created mafia and most of us (me included) don't get angry when others call us mafiosi. Mafia was born from desperation and is extremely common. Here we observe it every other day.
    If I were a mafioso for real, discussion wouldn't be an option. But I'm friendly, even if I have to be bitter. Just remember to not use that word lightly if possible. It still hurts a bit.🙂

    I thought an FSF board member would've been able to solve such a simple issue in days, if not minutes.
    The reason why I'm upset with you is that nobody got in touch with me in 3 months, so I had the impression that you didn't pass anything to anyone. Or that you've been ignored like a person without weight.

    In conversation about 9 months ago from ieji.de permalink

    Attachments


  6. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 17-Dec-2025 02:17:57 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo and I hear "he's Italian so he's also a mafioso for sure" pitch. Don't worry, we are accustomed to that. 🤣

    I'm not asking for an economic compensation. I want the Board to suspend the abuser for a fair amount of time and revert the misconfigurations he introduced. Nothing more.

    See I'm doing everything possible to cultivate a friendly environment for everybody. Alex, don't you think my requests are most rightful? 🙂

    In conversation about 9 months ago from ieji.de permalink
  7. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Tuesday, 16-Dec-2025 04:13:11 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo sure you don't want to assist me before that? Xmas is near.🙂

    In conversation about 9 months ago from ieji.de permalink
  8. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Tuesday, 16-Dec-2025 04:13:09 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo note, only if you really care. I'm just trying really hard to avoid the DIY, which would harm some FSF projects. I also pictured volunteers raising the issue during speeches and events.😅

    See that "pushing you around" is the last of my intentions, I'm friendly.

    If you want to assist me, please get in touch via same old encrypted email this week. Don't forget man.👋

    In conversation about 9 months ago from gnusocial.jp permalink
  9. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Monday, 15-Dec-2025 06:19:42 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo did you have a good holiday trip?🙂

    In conversation about 9 months ago from ieji.de permalink
  10. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Sunday, 14-Dec-2025 22:45:10 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo you forgot again and 3 months w/o progress are enough. 😐

    Bilateral losses seem now acceptable outcomes. I'll restore fairness personally during Xmas.

    In conversation about 9 months ago from ieji.de permalink
  11. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Saturday, 06-Dec-2025 12:12:39 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:

    Ireland started a Pause Before You Post Awareness Campaign: sharing photos and videos of children online can lead to unintended oversharing of personal data, which, in the wrong hands, can have serious consequences. Wise initiative!

    #socialmedia #video #photography #privacy #children #child #kids #safety #ireland

    In conversation about 9 months ago from ieji.de permalink

    Attachments


  12. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Friday, 19-Sep-2025 06:28:38 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo you're welcome. Don't worry, my name is hard to pronounce and remember for non-Italian speakers. 2018..2021+, you'll find everything you need on my website. (enable JS)

    I'll get in touch with you in the weekend.👋

    In conversation about a year ago from ieji.de permalink
  13. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Friday, 19-Sep-2025 06:28:37 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • Alexandre Oliva

    @lxo 2 emails in, 1 week has passed, still no answer.🪦📬

    In conversation about a year ago from ieji.de permalink
  14. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 19:16:12 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石

    @Suiseiseki no, server-side any language (PHP, Python, Perl, C, ...) can be used to process and answer AJAX (JavaScript background requests). There is little difference from standard web requests.

    If there is no documentation, it means the endpoint is just ad-hoc for internal use (Official website↔server or Official client↔server) and forbidden to 3rd party access. Abusing internal endpoints may violate the ToS or even be a felony, regardless of the goal and depending on the damage caused. 😅

    In conversation about a year ago from ieji.de permalink
  15. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 19:13:36 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石

    >>Browsing the web safely and correctly requires modern web browsers, like Mozilla Firefox, Chromium/Google Chrome or Microsoft Edge, updated to their latest stable version.
    >Those browsers contain malware
    > Firefox also contains malware

    @Suiseiseki all these browsers are widely used and perfectly safe.😅

    I've asked you 3 times to not spread misinformation here. I can't allow you to terrorize the FOSS volunteers and the readers this way.

    > Only cowards block.

    Don't mix cowardice with wisdom.

    In conversation about a year ago from ieji.de permalink
  16. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 18:28:42 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石

    @Suiseiseki text-only web browsers can have a smaller attack surface, but they are still susceptible to many XML-based and network-based attacks and are largely incompatible with any modern web application (like online banking, chats, games, ...) and with most websites which express through multimedia.

    Browsing the web safely and correctly requires modern web browsers, like Mozilla Firefox, Chromium/Google Chrome or Microsoft Edge, updated to their latest stable version.

    In conversation about a year ago from ieji.de permalink
  17. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 18:26:41 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石

    > Such sites do in fact still have an API - an undocumented JavaScript one
    > wipe the entire EU off the face of the planet

    @Suiseiseki if you keep talking about politics or intentionally sharing false information to scare the users I'll be forced to block you. This is the 3rd time I've asked you to stay on-topic. 😅

    In conversation about a year ago from ieji.de permalink
  18. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 18:22:49 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石
    • Ténno Seremél’
    • LisPi

    @lispi314 I don't want political discussions in my profile and I don't want to be involved in old ideologies. 😅

    Let's focus on tech. Thank you in advance.

    @Suiseiseki @tennoseremel

    In conversation about a year ago from ieji.de permalink
  19. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Wednesday, 10-Sep-2025 18:22:46 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • LisPi

    @lispi314 politics are divisive and are best fitted for dedicated channels, instead of intruding in technical discussions.

    FOSS is a social movement which thrives on unity, so I'm kindly inviting you one last time in considering party politics as off-topic when discussing with me. 😅

    In conversation about a year ago from ieji.de permalink
  20. Embed this notice
    Lorenzo Ancora :verified: (lorenzoancora@ieji.de)'s status on Tuesday, 09-Sep-2025 21:51:01 JST Lorenzo Ancora :verified: Lorenzo Ancora :verified:
    in reply to
    • 翠星石

    @Suiseiseki if you don't update your web browser, every attack is possible with and without JS.

    JS already requires permissions for critical operation.

    JS requests are subject to CORS and cannot be arbitrary.

    Web apps from YouTube to your bank need same-domain background requests to work, its normal.

    Unless both the DNS and the site is compromised and you are specifically targeted, JavaScript can't hack your LAN.

    JavaScript is executed in a sandbox and sometimes cached, never installed.

    In conversation about a year ago from ieji.de permalink
  • Before

User actions

    Lorenzo Ancora :verified:

    Lorenzo Ancora :verified:

    Open Source Advocate | Software Developer | Webmaster 🇪🇺🇮🇹Friendly and enterprising geek committed to promoting user freedom and computer literacy. As a lifelong scholar and social activist, I specialize in Free/Libre and Open Source software development. A rational free thinker, I believe in personal growth through the power of knowledge and community.Golden rule: respect → more respect.#italian #foss #floss #opensource #linux #developer #fedi22 #programming #webmaster #sysadmin

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          286580
          Member since
          10 Oct 2024
          Notices
          80
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.