GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Wolf480pl (wolf480pl@mstdn.io), page 7

  1. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Tuesday, 29-Apr-2025 03:46:11 JST Wolf480pl Wolf480pl
    • Quad

    @kura @quad
    > PewDiePie is a normie

    *was

    look at the glint in his eyes when he's talking about freedom

    when he's taking about having the power to fix things

    either he's a very good actor, or he's one of us :D

    In conversation about 2 months ago from mstdn.io permalink
  2. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Monday, 28-Apr-2025 23:42:08 JST Wolf480pl Wolf480pl
    • Quad

    @quad @kura
    How to learn 2 linux:
    1. Windows fucked up the registry, can't boot
    2. Your dad can't fix it until next week
    3. You're bored and all you have is Knoppix live CD

    In conversation about 2 months ago from mstdn.io permalink
  3. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Monday, 28-Apr-2025 04:13:12 JST Wolf480pl Wolf480pl
    in reply to
    • cjd

    @cjd hmm idk, without being a mechanic I wouldn't dare to remove the engine head from the block.

    And my uncle who's a mechanic has pulled many engines out of the engine bay to disassemble them into pieces... though I guess most of them were inline-4 2.0 or smaller

    In conversation about 2 months ago from mstdn.io permalink
  4. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Monday, 28-Apr-2025 04:13:10 JST Wolf480pl Wolf480pl
    in reply to
    • cjd

    @cjd and then there are mechanics who can't get manuals and have to make up for it by being smart...

    In conversation about 2 months ago from mstdn.io permalink
  5. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Monday, 28-Apr-2025 04:13:07 JST Wolf480pl Wolf480pl
    in reply to
    • cjd

    @cjd does the electronics impact things that much tho?

    AFAIK the main thing it changes is you hook up an an OBD tool to read the error code before you start replacing parts, and then once you're done replacing a part you clear the error and see if it pops up again.

    In conversation about 2 months ago from mstdn.io permalink
  6. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Wednesday, 23-Apr-2025 17:03:38 JST Wolf480pl Wolf480pl
    in reply to
    • Ayo

    @ayo btw what do you call it in Dutch?

    In conversation about 2 months ago from mstdn.io permalink
  7. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Wednesday, 23-Apr-2025 17:03:35 JST Wolf480pl Wolf480pl
    in reply to
    • Ayo

    @ayo in Polish it's "wolne oprogramowanie", where "wolne" can mean both "free as in freedom" and "slow", which is quite funny :D

    In conversation about 2 months ago from mstdn.io permalink
  8. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Wednesday, 23-Apr-2025 16:05:37 JST Wolf480pl Wolf480pl
    in reply to
    • Ignas Kiela
    • Alexander Monakov
    • Martin Uecker

    @ignaloidas @amonakov @uecker
    > node
    > long-term maintenance

    Cotation needed

    In conversation about 2 months ago from mstdn.io permalink
  9. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Wednesday, 23-Apr-2025 12:39:01 JST Wolf480pl Wolf480pl
    in reply to
    • Ignas Kiela
    • Alexander Monakov
    • Martin Uecker

    @uecker @ignaloidas @amonakov
    trick question:

    how much time does each of you (Martin in C, Ignas in Python) spend checking whether the library authors promise backwards compatibility, security updates, and whether they're likely to still be around 3 years from now?

    In conversation about 2 months ago from mstdn.io permalink
  10. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Tuesday, 22-Apr-2025 15:59:57 JST Wolf480pl Wolf480pl
    in reply to
    • Ignas Kiela
    • Alexander Monakov

    @ignaloidas @amonakov
    NSS
    GnuTSL
    OpenSSL
    LibreSSL
    BoringSSL
    WolfSSL
    mbedTLS
    AWS-LC

    did I miss any?

    In conversation about 3 months ago from mstdn.io permalink
  11. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Tuesday, 22-Apr-2025 14:42:36 JST Wolf480pl Wolf480pl
    in reply to
    • Alexander Monakov

    @amonakov what about things that cannot be implemented in a portable way (like stdio, file io, sockets, etc) ?

    In conversation about 3 months ago from mstdn.io permalink
  12. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Sunday, 20-Apr-2025 23:01:04 JST Wolf480pl Wolf480pl
    in reply to
    • jonossaseuraava
    • rin

    @rin @jonossaseuraava are you sure this isn't upside-down arabic? :thinkeyes:

    In conversation about 3 months ago from mstdn.io permalink
  13. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 23:19:50 JST Wolf480pl Wolf480pl

    @algernon moral of the story: computers are fast, we're just using them wrong most of the time?

    In conversation about 3 months ago from mstdn.io permalink
  14. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 21:34:17 JST Wolf480pl Wolf480pl
    in reply to
    • Ayo

    @ayo so, I don't know how perl packaging works, but assuming it works like pip:

    typically language-level package managers don't have the ability to add a dependency on OS-level tzdata... so I don't see an advantage of getting the source from a language-specific package repository as opposed to straight from the maintainer's website / github / etc

    In conversation about 3 months ago from mstdn.io permalink
  15. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 21:25:12 JST Wolf480pl Wolf480pl
    in reply to
    • Ayo

    @ayo (if there was, it'd be packaged by your distro, not on CPAN)

    In conversation about 3 months ago from mstdn.io permalink
  16. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 19:13:04 JST Wolf480pl Wolf480pl
    in reply to
    • Haelwenn /элвэн/ :triskell:
    • Tulip ?️‍⚧️
    • Leszek

    @makdaam @domi @lanodan
    oh, and also about goals

    At my $dayjob, the reason I do anything about vulns at all is compliance with a standard.

    But I look at the standard, try to figure out why someone would put a particular requirement in the standard, and try to think of something that we could do that is actually useful, that could also be argued to check the box.

    I think this might be a rare attitude.

    In conversation about 3 months ago from gnusocial.jp permalink
  17. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 19:09:42 JST Wolf480pl Wolf480pl
    in reply to
    • Haelwenn /элвэн/ :triskell:
    • Tulip ?️‍⚧️
    • Leszek

    @makdaam @domi @lanodan
    Now, you could argue that if the checkbox didn't shield companies from liability, they would care more about security, because simply ignoring vulns would get them sued to oblivion.

    And maybe that is the case in some fields.

    But IME it's more about the choice between trying to meet an impossible standard, and not giving a fuck thus doing nothing.
    2/2

    In conversation about 3 months ago from mstdn.io permalink
  18. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 19:06:28 JST Wolf480pl Wolf480pl
    • Haelwenn /элвэн/ :triskell:
    • Tulip ?️‍⚧️

    @domi @lanodan
    IME the hardest part of the problem is that if a python library has 50 functions

    one of them is vulnerable

    and you use a different one

    with input that is not user-controlled

    it's still getting flagged, and there's no way to filter that out without someone who understands the code taking a look at it.

    In an ideal world, vulns would be expressed through a type system.
    1/

    In conversation about 3 months ago from mstdn.io permalink

    Attachments


  19. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 19:06:27 JST Wolf480pl Wolf480pl
    in reply to
    • Haelwenn /элвэн/ :triskell:
    • Tulip ?️‍⚧️

    @domi @lanodan
    but IRL, if I could just

    take all known exploits

    automatically run them against our public endpoints, to find all the things a script kiddie can easily find

    and patch only those things

    that'd probably prevent 80% of the likely attacks for 10% of the effort

    In conversation about 3 months ago from gnusocial.jp permalink
  20. Embed this notice
    Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 19-Apr-2025 19:06:22 JST Wolf480pl Wolf480pl
    in reply to
    • Haelwenn /элвэн/ :triskell:
    • Tulip ?️‍⚧️
    • Leszek

    @makdaam @domi @lanodan
    don't worry about thread necromancy, it hasn't even been a week yet

    So you're saying that the checkbox exists purely for performative/blameshifting purposes?

    I think even if that is true, the side effect of complying with the checkbox is doing some good things. In this case - how do you make the CVE scanner happy without patching at least some vulns?

    And if you patch some vulns, you're already doing better than those who don't give a fuck.

    1/

    In conversation about 3 months ago from gnusocial.jp permalink
  • After
  • Before

User actions

    Wolf480pl

    Wolf480pl

    Sysadmin stuck with k8s,Linux nerdLikes The Unix Way🇬🇧🇵🇱(🇯🇵 a bit)

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          6007
          Member since
          17 Aug 2022
          Notices
          1191
          Daily average
          1

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.