@grishka@mastodon.social avatar

grishka

@grishka@mastodon.social

Software developer from Russia who's almost lost faith in the modern IT. Used to work at VKontakte, then Telegram. Currently building my own fediverse project to save our online social lives from greedy corporations. Follow the progress: #smithereen

Also working on the Mastodon Android app.

Русскоязычный аккаунт — @grishka

This profile is from a federated server and may be incomplete. Browse more on the original instance.

grishka, to random
@grishka@mastodon.social avatar

Apple is in its "fuck around" phase with the EU right now. Can't wait for the "find out". It's gonna be gorgeous.

grishka,
@grishka@mastodon.social avatar
grishka,
@grishka@mastodon.social avatar

But I also want to see the bullshit "core technology fee" challenged.

grishka, to random
@grishka@mastodon.social avatar

Facebook may be down, but is not 👀

jsrailton, (edited ) to infosec
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • grishka,
    @grishka@mastodon.social avatar

    @jsrailton just don't update the mobile app. You don't want it to be called "X" instead of "Twitter" anyway.

    GottaLaff, to random
    @GottaLaff@mastodon.social avatar

    Need some good news? Me too.

    “Opill, the first over-the-counter birth control pill that can be purchased without a prescription, will be available later this month online and in pharmacies for $19.99 a month, $49.99 for a three-month supply or $89.99 for a six-month supply”

    https://trib.al/YAXpbwX

    grishka,
    @grishka@mastodon.social avatar

    @GottaLaff as a non-American, I'm confused that a prescription could be required for this sort of thing to begin with

    grishka, to random
    @grishka@mastodon.social avatar

    Can anyone recommend a free, preferably open-source, stock-looking launcher for Android that has usable pages on both sides of the main page? Like it used to be before Google Now was introduced (which was wonderful until someone totally ruined it with news to get promoted).

    bagder, (edited ) to random
    @bagder@mastodon.social avatar

    DISPUTED, not REJECTED or maybe "we simply cannot get rid of rubbish CVEs because they say so" - an update from my last few days.

    https://daniel.haxx.se/blog/2024/02/21/disputed-not-rejected/

    grishka,
    @grishka@mastodon.social avatar

    @bagder oh wow so they ARE actually capable of doing that?

    JLuisNieves, to mastodon Spanish
    @JLuisNieves@mastodon.la avatar

    Hello, @grishka .
    Please, have you heard or do you know of anyone using the oficial app having troubles with receiving Android notifications from the app lately?
    I would gratefully appreciate your reply.
    Thanks.

    grishka,
    @grishka@mastodon.social avatar

    @JLuisNieves no, I don't know anything about this. Nothing has changed on the app side, however, there may be something on the relay (web push -> FCM) server, cc @renchap

    grishka, to random
    @grishka@mastodon.social avatar

    Before Taylor Swift, there was Taylor Objective-C

    grishka, to random
    @grishka@mastodon.social avatar

    It's been 0 days since I last got cloudflared

    grishka, to fediverse
    @grishka@mastodon.social avatar

    is about to become GDPR compliant 😅

    I like my approach with deactivation period better than what others do. For example, @pixelfed deletes accounts immediately and it turns out people change their minds on this stuff sometimes.

    image/png

    grishka,
    @grishka@mastodon.social avatar

    @aral @smallcircles @pixelfed there is an admin option to immediately delete a deactivated/suspended account

    grishka,
    @grishka@mastodon.social avatar

    @aral @smallcircles @pixelfed no, they'll have to ask the server staff

    bagder, to random
    @bagder@mastodon.social avatar

    Almost out of stickers now...

    grishka,
    @grishka@mastodon.social avatar

    @bagder oops, I didn't get any but I was at your talk

    macrumors, to random
    @macrumors@mastodon.social avatar
    grishka,
    @grishka@mastodon.social avatar

    @macrumors the year is 2024, and it is now forbidden to release software without some kind of AI integration

    sdw, to random
    @sdw@mastodon.social avatar

    Vision Pro comes with all the standard apps a user might expect like mail, messages, music, dinosaurs

    grishka,
    @grishka@mastodon.social avatar

    @sdw dinosaurs AND mindfulness. Open them side by side for a mindful dinosaur encounter.

    grishka, to fediverse
    @grishka@mastodon.social avatar

    A question for those who might want to run a server in the future — is support for S3-compatible object storage for storing media files a desirable feature? I'm refactoring media file storage anyway so could as well add an abstraction layer that would allow this sort of thing.

    grishka, to fediverse
    @grishka@mastodon.social avatar

    While I'm currently working on many (and I mean many) New And Improved™ moderation tools in , I also added a tiny user-facing thing because clicking CWs one by one was tedious to say the least.

    video/mp4

    grishka, to random
    @grishka@mastodon.social avatar

    Please, stop calling Twitter "X". There's no such thing as "X", it's still Twitter, has always been, will always be. You can't call things single-letter names even when their stupid CEO insists you do.

    grishka, to random
    @grishka@mastodon.social avatar
    grishka, to random
    @grishka@mastodon.social avatar

    Their webfinger endpoint (/.well-known/webfinger), which is essential for federating with Mastodon, is still not up tho 🤔

    thisismissem, to mastodon
    @thisismissem@hachyderm.io avatar

    Have just opened a pull request to enable OAuth 2.0 refresh tokens for Mastodon, which is a first step towards enabling expiration of access tokens, to increase security to best practices.

    https://github.com/mastodon/mastodon/pull/27948

    grishka,
    @grishka@mastodon.social avatar

    @thisismissem
    > to prevent hijacking them from browser history

    Something that has access to your browser history also likely has access to your cookies, meaning unlimited unrestricted access anyway.

    > or from having applications collect on your account that have permanent write access to your account

    This can be mostly mitigated with more granular permissions. Right now Mastodon has "write everything" and "read everything", basically.

    grishka,
    @grishka@mastodon.social avatar

    @thisismissem I do think that there should be "offline" scope though. This would make the token indefinite. By default it would be short-lived. IMO it's a good enough compromise for the two common use cases: one-off authentication and a client app.

    grishka,
    @grishka@mastodon.social avatar

    @thisismissem well this is something I'm firmly against. Offline means offline. There may be a checkbox to revoke access tokens when changing your password though.

    If a database of offline tokens leaks, they would still be valid because they're regularly refreshed. This whole refreshing procedure solves nothing despite being a "best practice". Some people think password composition rules are good because they are also a "best practice" written somewhere.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • rosin
  • thenastyranch
  • ethstaker
  • DreamBathrooms
  • osvaldo12
  • magazineikmin
  • tacticalgear
  • Youngstown
  • everett
  • mdbf
  • slotface
  • ngwrru68w68
  • kavyap
  • provamag3
  • Durango
  • InstantRegret
  • GTA5RPClips
  • tester
  • cubers
  • cisconetworking
  • normalnudes
  • khanakhh
  • modclub
  • anitta
  • Leos
  • megavids
  • lostlight
  • All magazines