@rysiek@mstdn.social
@rysiek@mstdn.social avatar

rysiek

@rysiek@mstdn.social

Hacker, activist, free-softie ◈ techie luddite ◈ formerly information security and infrastructure at https://isnic.is/ and https://occrp.org/ ◈ my opinions are my own etc.

(he/him)

profile image: drawing of a head and shoulders of a cat-person, in a space suit.

banner image: long-exposure photo of a large tent, brightly illuminated from inside, looking as if it is made of lava

#foss #libre #privacy #infosec #fedi22

(public toots CC By-SA 4.0 if applicable)

🇪🇺 🇵🇱 · 🇧🇦 🇮🇸 · 🇺🇦

This profile is from a federated server and may be incomplete. Browse more on the original instance.

rysiek, to Bulgaria
@rysiek@mstdn.social avatar

More than twelve years ago I was invited by @LaQuadrature to come to the Europarlament to help stop ACTA:
https://rys.io/en/65.html

This was the first time I got a chance to directly talk to MEPs to try change their minds on an issue I cared deeply about. It was not the last.

I've done a lot of activism, on both EU and national level. My experience with the European Parliament remains the best.

It really matters who we send there. And we do have a say on that.

Go vote. 🇪🇺

rysiek, to CrystalsHashtags
@rysiek@mstdn.social avatar

While is doing an absolute stupid with their new licensing terms, and (now Canva-owned) slashes prices by half in a "flash sale", I am once again asking people to consider supporting tools instead.

Yes, they are far from perfect.

But with a small fraction of what these closed source vendors are raking in, these tools could be made immeasurably better.

And they won't end up bought up and enshittified, as experience with past attempts at doing that to FLOSS tools shows.

rysiek,
@rysiek@mstdn.social avatar

@baldur I did not say "please use FLOSS tools", I merely said "consider supporting them". :blobcat:

rysiek, to random
@rysiek@mstdn.social avatar

Phone not reconnecting to the Bluetooth speaker in the other room randomly every 45min challenge.

Difficulty: impossible.

:nkoFacepalm2:

rysiek, to random
@rysiek@mstdn.social avatar

tired: the illuminati
wired: the illuminaughty

rysiek, (edited ) to infosec
@rysiek@mstdn.social avatar

Lukewarm take:

When I see general* "security advice" that mentions "do not use public WiFi" or "use a VPN", I am immediately suspicious about all other advice offered.

Yes, a decade ago that was a consideration, because most sites were not using HTTPS. Credentials were flying cleartext on the wire.

Today, almost all sites use HTTPS. Doesn't mean the risk is zero, but it's way lower.

*) "general" meaning "without a very specific threat model in mind", meant for general public, etc.

rysiek,
@rysiek@mstdn.social avatar

Actually, downgraded that take to "lukewarm", it should really not be controversial at all these days. It's been a hot minute since LetsEncrypt changed the HTTPS landscape!

What is beyond me is that such "security advice" still gets pushed. :blobcat0_0:

rysiek,
@rysiek@mstdn.social avatar

@steve yup!

rysiek, (edited )
@rysiek@mstdn.social avatar

Also, shout-out to @letsencrypt for dramatically changing the security landscape of the Web for the better over the years.

Rarely is there an example of a project so effective and so directly improving everyone's lives, while at the same time keeping the original engineering mindset and just Doing Stuff Right™ humbly in the background.

Next November it will have been exactly a decade since LE started. We all owe them a huge 10th birthday party.

rysiek,
@rysiek@mstdn.social avatar

@nblr truth!

@letsencrypt

rysiek, (edited ) to random
@rysiek@mstdn.social avatar

Looks like the Boeing Starliner Spacecraft mission is a resounding success – no doors were reported to have fallen off!

:blobcatcoffee:

#Starliner #Boeing

rysiek, to firefox
@rysiek@mstdn.social avatar

I just spent two hours trying to get #Firefox to use #KDE Dolphin as the default file manager.

I went on a journey from .desktop files and mimeinfo.cache, through DBus, to .service files.

I shook with anger when everything seemed configured correctly, but Firefox would just not launch a file manager at all. Click that "show in folder" button and nothing happens.

I have now found the problem.
The problem was: systemd. :angery:

Why. Is. Systemd. Involved. In. Launching. A file manager. 👀

jalcine, to random
@jalcine@todon.eu avatar

Just saw a video of high school kids doing lines in the bathroom.

Why are y'all recording this?!

rysiek,
@rysiek@mstdn.social avatar

@be @jalcine a friend of mine believes that this will lead to all sorts of "unnecessarily shameful" things becoming normalized, thus leading to a less prude, bigoted, hypocritical society.

The friend of mine is wrong.

rodhilton, to random
@rodhilton@mastodon.social avatar

ChatGPT is down, wonder how many "now with AI!" integrations just got broken. Logitech was stuffing OpenAI stuff into its mouse drivers last time I looked so I imagine the blast radius here might be substantial.

rysiek,
@rysiek@mstdn.social avatar

@rodhilton and nothing of value was lost

amberage, to random
@amberage@eldritch.cafe avatar

One other Mastodon feature I would like:

Display any notes I might have taken about a user under their follow request in the notifications tab, and let me add new notes.

That would make it much more easy to deal with larger amounts of follow requests right as they come in, see if they follow requested before, and let me write notes for later (i.e. what context they f-req'd in) so I don't lose track of my follow requests.

rysiek,
@rysiek@mstdn.social avatar

@amberage I would love it if the notes could optionally be made available like this anywhere a username is displayed.

Considering boosting this toot right here? Oh there's a note about the person, that might be relevant!

Got a weird reply? Oh there's a note, might explain things!

rysiek,
@rysiek@mstdn.social avatar

@amberage :100a:

> We keep talking about AI assistants that could enrich our digital experience and provide comfort and semi-automate menial tasks, but we can't even get something like that right.

Truth!

rysiek,
@rysiek@mstdn.social avatar

@amberage

tired: digital assistants
wired: UI/UX that doesn't suck

hannah, to random
@hannah@social.alt-text.org avatar

Hi folks,

My surgery last Wednesday went as well as it could, and so far its impact on my language abilities has been minimal, much better than expected. While I am still very much in recovery, they've invited me to work with Scribely to move the Alt-Text.org project forward and I can't wait.

Hannah 💜

P.S. Surgical pictures below

rysiek,
@rysiek@mstdn.social avatar

@hannah so very happy to hear that. :blahaj_heart:

kuba, to devops
@kuba@toot.kuba-orlik.name avatar

A question: is there a way to set up a "rolling cache" with nginx?

I want it to handle each request like so:

  1. Immediately respond with the cached version
  2. Start rebuilding the cache for that request in the background, so the next request for this URI gets a newer cached version

Cc @rysiek

rysiek,
@rysiek@mstdn.social avatar

@robryk @kuba
yup, that's what my Fasada nginx config does:
https://0xacab.org/rysiek/fasada/-/blob/master/services/etc/nginx/sites/example.com.conf?ref_type=heads#L38

This has been battle-tested in production as well. I should really write it up. 😉

mkljczk, to random
@mkljczk@fediverse.pl avatar

Minister @mcgramat tłumaczył względami bezpieczeństwa wycofanie się z publikacji w całości kodu źródłowego front-endu mObywatela, ale nie widzi zagrożeń dla bezpieczeństwa w głosowaniu przez internet (może przez aplikację, której publikacja frontu byłaby zagrożeniem?🧐)

W ocenie Michała Gramatyki największym problemem w przypadku głosowania online nie jest jednak bezpieczeństwo, lecz właśnie tajność i konieczność zmiany konstytucji. Bezpieczeństwem bym się nie przejmował, bo jeśli możemy teraz bezpiecznie korzystać z systemów bankowych, a to dotyczy naszych pieniędzy, to myślę, że spokojnie też zaakceptujemy głosowanie przez internet” – uważa wiceminister cyfryzacji.

za cyberdefence24 https://cyberdefence24.pl/polityka-i-prawo/wybory-przez-internet-a-bezpieczenstwo-gramatyka-sa-wieksze-problemy

rysiek, (edited )
@rysiek@mstdn.social avatar

@timorl ok, no to siup.

Załóżmy, że mamy taki magiczny system, w którym głosujesz, a Twój głos jest oddany w sposób kryptograficznie tajny, a Ty dzięki zero-knowledge proofs i innej kryptografii możesz faktycznie sprawdzić, czy został policzony poprawnie.

O tym, że możesz to sprawdzić, wie jednak też Twój przemocowy partner, który ma swoje zdanie na temat tego, jak powinieneś był zagłosować w wyborach.

Więc przy kolacji w domu prosi Cię, żebyś pokazał, jak zagłosowałeś.

@mcgramat @mkljczk

rysiek, (edited )
@rysiek@mstdn.social avatar

@timorl albo inna sytuacja. Dalej zakładamy ten sam magiczny system pozwalający osobom głosującym sprawdzić, jak glosowały.

Burmistrz małego miasteczka też wie, że mogą. Więc oferuje 1000zł za oddanie głosu na niego, pod warunkiem, że osoby głosujące potem pokażą mu, jak zagłosowały.

@mcgramat @mkljczk

rysiek,
@rysiek@mstdn.social avatar

@timorl kryptografia dochodzi tylko do urządzenia. Potem zaczyna się skomplikowany, i często brzydki, świat fizyczny, w którym można ludzi skrzywdzić, i można ich przekupić.

Głosowanie tajne – również po fakcie zagłosowania – oznacza, że nieco zbyt ambitny burmistrz albo przemocowy partner nie ma jak sprawdzić, czy przekupstwo lub groźby faktycznie zadziałały na daną, konkretną osobę.

Więc opcja przekupstwa lub wymuszenia głosu staje się znacznie mniej efektywna.

@mcgramat @mkljczk

hazelweakly, to random
@hazelweakly@hachyderm.io avatar

Y'know how there's a pattern of behavior where someone says something is bad about the tech industry or community or OSS software or something, and then every single nerd within a 50 square mile radius says WELL ACKTUALLY??

I just realized that if, like, even 10% of them just... Sat down and spent some energy fixing the problem instead of insulting someone for experiencing it, we would've solved all those issues by now

rysiek,
@rysiek@mstdn.social avatar

@hazelweakly thank you.

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.

From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."

Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.

video/mp4

rysiek,
@rysiek@mstdn.social avatar

@GossiTheDog so… would that be considered a recall of Recall?

:blobcatpeek:

Edent, to random
@Edent@mastodon.social avatar

Woo! Just put down a deposit on a @frameworkcomputer

Looking forward to running @pop_os_official on it and, hopefully, building some expansion cards 🙂

rysiek,
@rysiek@mstdn.social avatar

@Edent ooooh

this is relevant to my interests. really interested in how well the hardware works for you!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines