GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)

  1. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 02-May-2025 04:45:00 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    #Redis is #OpenSource again. Probably too late though. Everyone I know switched to Valkey.

    #FreeSoftware

    https://antirez.com/news/151

    In conversation about 17 days ago from fosstodon.org permalink
  2. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Wednesday, 09-Apr-2025 02:18:30 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    This is Internet Gold.

    > "... it is important to note that the compression algorithm used by lzip only discards the unimportant data. And if it was unimportant before, what makes it so important now? Huh? In fact, many users may find that compressing their entire file system and then restoring it will be a good way to learn what is truly important."

    https://web.archive.org/web/20010608045914/http://lzip.sourceforge.net/faq.html

    #compression #AprilFools #opensource #lzip

    In conversation about a month ago from fosstodon.org permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: web.archive.org
      Lzip lossy compression
      from The Lzip team
      Home page for the lzip project
  3. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Wednesday, 19-Mar-2025 06:37:02 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    #Ubuntu is moving away from GNU coreutils to Rust-based uutils coreutils with Ubuntu 25.10. There are two big differences with this move:

    1. uutils coreutils is MIT licensed, not GPL.
    2. Obviously, it's written in Rust, a memory-safe compiled language, unlike C.

    IMO, this is a good move.

    https://discourse.ubuntu.com/t/carefully-but-purposefully-oxidising-ubuntu/56995

    #gnu #rust #linux

    In conversation about 2 months ago from fosstodon.org permalink
  4. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Wednesday, 19-Mar-2025 06:37:01 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Chris Siebenmann

    @cks Agreed. I haven't looked over the source code, but 100% compatibility is an optimistic claim I think. GNU coreutils is 35 years old. That's a long time for one-off quirks to get implemented for all sorts of edge cases.

    In conversation about 2 months ago from fosstodon.org permalink
  5. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Tuesday, 25-Feb-2025 09:29:11 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    https://bugzilla.mozilla.org/show_bug.cgi?id=1950144

    In conversation about 3 months ago from fosstodon.org permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      1950144 - DigiCert: Threat of legal action to stifle Bugzilla discourse
      UNCONFIRMED (nobody) in CA Program - CA Certificate Root Program. Last updated 2025-02-24.
  6. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Sunday, 23-Feb-2025 05:08:40 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    The SystemV filesystem is getting removed from the #Linux kernel, as it had a bad bug proving no one was actually using it.

    https://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs.git/commit/?h=vfs-6.15.sysv&id=448fa70158f9b348e71869cfe4a31988e07b20b2

    In conversation about 3 months ago from fosstodon.org permalink
  7. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Thursday, 20-Feb-2025 06:48:18 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    • Evan Prodromou

    @evan Why wouldn't I chose the max option?

    In conversation about 3 months ago from fosstodon.org permalink
  8. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 03:57:35 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    • Ubuntu

    Developer applies at @ubuntu, goes through extensive hiring filters and many interviews, gets an offer in hand, accepts the offer, quits their job, only for Canonical to retract the offer.

    Don't work for Canonical.

    #Ubuntu #Linux

    https://www.reddit.com/r/linux/comments/1ij4itg/canonical_what_a_shame/

    In conversation about 3 months ago from fosstodon.org permalink
  9. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 03:35:30 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dalias @dimpase I agree. What I don't understand why you would choose to leak metadata unnecessarily when stronger alternatives exist.

    In conversation about 3 months ago from fosstodon.org permalink
  10. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 03:30:27 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dimpase @dalias I didn't call it grave.

    In conversation about 3 months ago from fosstodon.org permalink
  11. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 03:30:26 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dimpase @dalias It is horrible. No password manager should be doing this. But it's not leading to the compromise of each account ("grave"), just leaking what they are ("bad", "horrible", "not good").

    In conversation about 3 months ago from fosstodon.org permalink
  12. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:59:37 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dalias @dimpase The context is pass(1) however, not data in general. pass(1) reveals which accounts you're protecting, even if the password for each account is encrypted with your PGP keys.

    Syncing encrypted pass(1) files to 3rd party cloud providers is a security vulnerability that other password managers does not have.

    In conversation about 3 months ago from fosstodon.org permalink
  13. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:48:27 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dalias @dimpase I disagree. Provided your master password is sufficiently secure, you can sync a KeePass/KeePassXC database safely to 3rd party servers without risk of revealing any information as to the number of accounts they contain, or which accounts are stored.

    In conversation about 3 months ago from fosstodon.org permalink
  14. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:46:33 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker

    @dalias I was just curious. As a moderator of r/Passwords on Reddit, a user messaged me concerned about a certain post, which led to the discussion of biased and fair reporting of different password managers.

    I used subreddit subscriber counts as a poor metric for market share, and mentioned as much, which got me curious if actual research had been done in this area. I figured it would be via voluntary polling, which has its own problems.

    In conversation about 3 months ago from fosstodon.org permalink
  15. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:45:10 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Rich Felker
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dalias @dimpase The vulnerability exposing accounts to the filesystem is closed if the data is not synced across computers and cloud providers. But if the data is synced, such as checked into GitHub or copied to Dropbox, the vulnerability is exposed.

    In conversation about 3 months ago from fosstodon.org permalink
  16. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:40:07 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    Has there been any research on the market share of password managers? Both from the perspective of competition (Bitwarden vs 1Password), but also users versus non users.

    #passwords

    In conversation about 3 months ago from fosstodon.org permalink
  17. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 07-Feb-2025 01:40:04 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • Dima Pasechnik 🇺🇦 🇳🇱

    @dimpase I'm familiar with pass(1). It has a horrible vulnerability in that it leaks all accounts to the filesystem. No modern password manager today does this.

    LastPass got heavily criticized for not encrypting URLs in the DB, rightfully so, because it leaks which accounts a user has stored in the DB. They've since fixed it.

    Also, PGP can die in a fire. Heh.

    In conversation about 3 months ago from fosstodon.org permalink
  18. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Thursday, 30-Jan-2025 07:37:50 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:
    in reply to
    • BeAware

    @BeAware How so?

    In conversation about 4 months ago from fosstodon.org permalink
  19. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Thursday, 30-Jan-2025 07:36:03 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    This slipped past my radar: LetsEncrypt is ending support for TLS cert expiration notification emails.

    https://letsencrypt.org/2025/01/22/ending-expiration-emails/

    In conversation about 4 months ago from fosstodon.org permalink
  20. Embed this notice
    Aaron Toponce ⚛️:debian: (atoponce@fosstodon.org)'s status on Friday, 17-Jan-2025 21:39:13 JST Aaron Toponce ⚛️:debian: Aaron Toponce ⚛️:debian:

    Hard pass. I will not use #passkeys and will tell my friends and family to do the same.

    So long as attestation part of the WebAuthn spec, it allows companies to lock consumers into using specific passkey managers.

    It's exactly like streaming subscriptions. Attestation sets up the dystopia of a paid 1Password account for your email passkey, a paid LastPass account for your utility account passkey, a paid Bitwarden account for your health insurance, etc.

    #passwords

    https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better

    In conversation about 4 months ago from fosstodon.org permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      managers.it
      This domain may be for sale!

  • Before

User actions

    Aaron Toponce ⚛️:debian:

    Aaron Toponce ⚛️:debian:

    MSCSIA, cryptography, security, locksport, Linux, programming, mathematics, amateur radio, Buddhism, running, anime, and bibliophilia.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          8006
          Member since
          31 Aug 2022
          Notices
          90
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.