GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Filippo Valsorda (filippo@abyssdomain.expert), page 2

  1. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Wednesday, 09-Jul-2025 12:54:00 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Chris Siebenmann
    • ✧✦Catherine✦✧
    • mei

    @cks @whitequark @mei I had in mind to reach out to you, so hi :)

    People are reading more into my off-hand pager comment than I intended. Google asks for two email addresses of “representatives” just so that there’s a fallback if eg there’s a vulnerability and the main person in on vacation. They don’t actually page anyone. It’s fine if the SRE work is done by a single person in the end.

    In conversation about 8 months ago from abyssdomain.expert permalink
  2. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Wednesday, 09-Jul-2025 03:59:43 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • ✧✦Catherine✦✧
    • mei

    @whitequark @mei I am listening! For example?

    In conversation about 8 months ago from abyssdomain.expert permalink
  3. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Wednesday, 09-Jul-2025 03:54:09 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • ✧✦Catherine✦✧
    • mei

    @whitequark @mei I am curious too! To be fair it's the least urgent pager ever. 22h of allowed downtime!

    If we get zero new logs, we'll finish the work on Verifiable Indexes (which replace the need to scrape the whole log, drastically reducing outbound) and try again next year.

    In conversation about 8 months ago from abyssdomain.expert permalink
  4. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 01-Jul-2025 01:55:14 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Glyph
    • ✧✦Catherine✦✧

    @glyph @whitequark oh 100%

    However, I'd be fine with a policy of "it's not the moderators' job to educate you, either take this spontaneously as a learning opportunity, or leave".

    In conversation about 8 months ago from abyssdomain.expert permalink
  5. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 01-Jul-2025 01:52:18 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Glyph
    • ✧✦Catherine✦✧

    @whitequark @glyph I don't know enough about the specifics of the Nix issue, but that sounds like a values mismatch with leadership, and I acknowledge that strict moderation enforces the leaders' values. If they are different from yours or mine, we won't be a good fit! There are settings where you can't just say "find better leaders and make another community" but there are settings in which you can! I wish we explored the latter more.

    In conversation about 8 months ago from abyssdomain.expert permalink
  6. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 01-Jul-2025 01:42:40 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Glyph
    • ✧✦Catherine✦✧

    @whitequark @glyph I see the risk in theory, but I can't remember from my experience a jerk in IETF-like spaces who was a legitimately upset stakeholder rather than a dude with opinions.

    FWIW I think gish gallops should also get moderated brutally. I am not asking for politeness, I am asking for subjective moderation action that matches what everyone is saying in the parallel emotional support group chats.

    In conversation about 8 months ago from abyssdomain.expert permalink
  7. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 01-Jul-2025 01:28:26 JST Filippo Valsorda Filippo Valsorda

    I wish we had spaces to collaborate on technical work where being a jerk was just not allowed. Like, actual proper fearless moderation.

    Your reply starts with "No." on its own line? Two weeks ban. Learn to behave.

    You go on a tear about another participant? One year ban. No warning.

    I'm a privileged white dude with 20k followers and even I hesitate to contribute to some spaces because of the mailing list hand-to-hand combat.

    Imagine how many contributions by talented folks we are wasting!

    In conversation about 8 months ago from abyssdomain.expert permalink
  8. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 24-Jun-2025 10:57:19 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • jcoglan

    @jcoglan gee, trying new ideas for open source maintenance sustainability, I should consider trying that

    In conversation about 8 months ago from abyssdomain.expert permalink
  9. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Sunday, 22-Jun-2025 13:54:36 JST Filippo Valsorda Filippo Valsorda

    Looks like the same poorly implemented Android CT library that broke a lot of apps a couple years ago... did it again 🤦♂️

    https://github.com/appmattus/certificatetransparency/issues/143#issuecomment-2993688741

    In conversation about 8 months ago from abyssdomain.expert permalink
  10. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Sunday, 22-Jun-2025 13:54:34 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Juli Jane

    @julijane it’s not so black and white. If you are an unpaid maintainer you have no obligation to put in extra work, for sure. But if you do take down the banking system of a country once (still not your fault!) and people tell you your library is broken… I think you start having a responsibility to either deprecate it, fix it, or at least warn users. We live in a society.

    In conversation about 8 months ago from abyssdomain.expert permalink
  11. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Thursday, 05-Jun-2025 22:28:21 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • Rich Felker

    @dalias Note that the "🤡🚗 browser" is the one that was already working on an actual definitive solution that would ship by default to all their users instead of the subgroup that installed the right extension.

    https://localmess.github.io/#disclosure

    And yes, uBO Lite (the MV3 ad-blocker I keep being told doesn't work but works) has the LAN intrusion list.

    I'm so tired of vibe-based criticisms that ignore factual reality.

    In conversation about 9 months ago from abyssdomain.expert permalink
  12. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Thursday, 05-Jun-2025 19:55:48 JST Filippo Valsorda Filippo Valsorda

    I usually get where big tech is coming from, but this is just malicious tracking. If you're an engineer and you're asked to implement something like this, it's time to whistleblow.

    I hope the IE DPA will look into it.

    Anyway, Local Network Access (https://github.com/explainers-by-googlers/local-network-access) can't come soon enough.

    https://localmess.github.io

    In conversation about 9 months ago from abyssdomain.expert permalink

    Attachments


    1. https://cdn.masto.host/abyssdomainexpert/media_attachments/files/114/629/981/491/852/409/original/bd64faca20eb3433.png
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - explainers-by-googlers/local-network-access: A proposal to restrict sites from accessing a users' local network without permission
      A proposal to restrict sites from accessing a users' local network without permission - explainers-by-googlers/local-network-access
  13. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 22-Apr-2025 21:03:50 JST Filippo Valsorda Filippo Valsorda

    I am writing an application that really cares about durability of created files (a Certificate Transparency log), and... oof.

    I fsync the file. I fsync the directory. Ok.

    But... how do I test it? Even targeting a specific filesystem, I have to make VMs and try to race killing them?

    In conversation about 10 months ago from abyssdomain.expert permalink
  14. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Saturday, 19-Apr-2025 19:36:22 JST Filippo Valsorda Filippo Valsorda

    Oof. Reportedly, if you got a certificate from SSL.com by putting “example[@]gmail.com” at _validation-contactemail.example.com, they would add gmail.com (!!!) to your verified domains.

    A good reminder to use the CAA record, and to sign up for CT monitoring (e.g. Cert Spotter).

    https://bugzilla.mozilla.org/show_bug.cgi?id=1961406

    In conversation about 10 months ago from abyssdomain.expert permalink

    Attachments


    1. No result found on File_thumbnail lookup.
      SSL Certificate & Digital Certificate Authority - SSL.com
      from Panos Pantousas
      SSL.com provides SSL/TLS & digital certificates to secure and encrypt data with our 4096-bit SSL/TLS Certificates, trusted by all popular browsers.

  15. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Monday, 14-Apr-2025 22:19:26 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • yossarian (1.3.6.1.4.1.55738)

    @yossarian something related that I'm getting convinced of is that in e.g. crypto/tls we should do profiles instead of config options.

    We take responsibility for the defaults, but then we say "if they don't fit, here are all the dials". Instead, we should have opinionated FIPS 140, compatibility, modern, etc. profiles, just like we have the default profile.

    In conversation about 11 months ago from abyssdomain.expert permalink
  16. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Friday, 21-Mar-2025 18:39:16 JST Filippo Valsorda Filippo Valsorda

    It’s disheartening to see AI reactionism lead my community to a 180° on copyright.

    Everyone is merrily attacking LibGen now. If it didn’t exist, big tech companies would still find training data, it just wouldn’t be accessible to regular people.

    In conversation about a year ago from abyssdomain.expert permalink
  17. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Friday, 21-Mar-2025 18:39:14 JST Filippo Valsorda Filippo Valsorda
    in reply to
    • ✧✦Catherine✦✧

    @whitequark to be fair the clever campaign that everyone seems to be falling for lets you search for your books in the dataset, but still disappointing from people that I would have never imagined calling for the shutdown of TPB or ZLib

    In conversation about a year ago from abyssdomain.expert permalink
  18. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Tuesday, 31-Dec-2024 23:45:34 JST Filippo Valsorda Filippo Valsorda

    Ever wanted to benchmark RSA key generation but found it too slow and variable, like benchmarking a lottery? No? Just me?

    Well, I nerd-sniped myself into producing average representative inputs that can be used to benchmark, profile, and compare RSA keygen.

    Happy New Year(?)!

    https://words.filippo.io/dispatches/rsa-keygen-bench/?source=Mastodon

    Reusable vectors and generator at https://c2sp.org/CCTV/keygen.

    In conversation about a year ago from abyssdomain.expert permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      CCTV/keygen at main · C2SP/CCTV
      Community Cryptography Test Vectors. Contribute to C2SP/CCTV development by creating an account on GitHub.
  19. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Saturday, 21-Dec-2024 00:09:18 JST Filippo Valsorda Filippo Valsorda

    age v1.2.1 fixes a security vulnerability in the CLI and in the plugin Go package.

    An attacker that controls a recipient, identity, or plugin name could cause age to execute arbitrary binaries. On Linux and macOS, the attacker needs some control over $TMPDIR.

    Advisory: https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c
    Release: https://github.com/FiloSottile/age/releases/tag/v1.2.1
    Also fixed in rage: https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w

    Thanks to ⬡-49016 for reporting this!

    In conversation about a year ago from abyssdomain.expert permalink

    Attachments


    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Malicious plugin names, recipients, or identities can cause arbitrary binary execution
      A plugin name containing a path separator may allow an attacker to execute an arbitrary binary. Such a plugin name can be provided to the age CLI through an attacker-controlled recipient or iden...
    2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      Release age v1.2.1: security fix · FiloSottile/age
      This release fixes a security vulnerability that could allow an attacker to execute an arbitrary binary under certain conditions. See GHSA-32gq-x56h-299c. Plugin names may now only contain alphanum...

  20. Embed this notice
    Filippo Valsorda (filippo@abyssdomain.expert)'s status on Wednesday, 11-Dec-2024 14:15:13 JST Filippo Valsorda Filippo Valsorda

    The Go team plans to issue a security fix for the golang.org/x/crypto/ssh package in the golang.org/x/crypto module on Wednesday, December 11th.

    https://groups.google.com/g/golang-announce/c/ZA1tNV10Mcs

    In conversation about a year ago from abyssdomain.expert permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      The Go Programming Language
    2. No result found on File_thumbnail lookup.
      The Go Programming Language
  • After
  • Before

User actions

    Filippo Valsorda

    Filippo Valsorda

    @FiloSottile elsewhere / Cryptogopher / Go crypto maintainer / Professional Open Source maintainer / RC F'13, F2'17
https://mkcert.dev / https://age-encryption.org / https://filippo.io/newsletter🕳️ “Gaze not into the abyss, lest you become recognized as an abyss domain expert, and they expect you keep gazing into the damn thing.” —@nickm

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          60766
          Member since
          8 Dec 2022
          Notices
          73
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.