@icing@chaos.social
@icing@chaos.social avatar

icing

@icing@chaos.social

Apache httpd and curl project member, HTTP/2, HTTP/3, Lets Encrypt implementations. Likes to code.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

icing, to random
@icing@chaos.social avatar

Filled out a US online tax form, entering mandatory fields, and the full address did not make it into the generated pdf.

2024, your software breaks on seeing an „ü“, catching the error and continuing merrily. Probably a memory safe python.

Since the faulty pdf was filed by the site to the US gov, I will now live in fear of Black Helicopters.💁🏻‍♂️

icing, to random
@icing@chaos.social avatar

Cloudflare just released Pingora, a rust framework for HTTP proxying they use themselves: https://github.com/cloudflare/pingora

icing, to random
@icing@chaos.social avatar

According to the US government, the world would be a better place if everything were written in:

„Rust, Go, C#, Java, Swift, Python, and JavaScript„

In the curl project, we should use all of them. Combine their strengths. Like in Damascus Steel.

icing, to random
@icing@chaos.social avatar

The CVE thing gets sillier every month.

On one hand you have the laziness of Mitre and friends to add any silly CVE claim, unless someone like @bagder pushes back using days of his precious time

Otoh, there are these „super CVEs“ which apply to several projects and people demand coordinated rollouts on specific dates to limit exposure. But most projects don‘t work that way.

And I‘m not sure why unpaid people are putting in extra effort to protect business interests, myself included.

icing, to random
@icing@chaos.social avatar

Javascript sizes for landing pages;

Slack: 55 MB
Jira: 50 MB
Discord: 21 MB
Gmail: 20 MB
Youtube: 12 MB

Pornhub: 1.4 MB
People prefer fast sex, it seems.

(via @simon)
https://tonsky.me/blog/js-bloat/

icing, to random
@icing@chaos.social avatar

Poeple yelling at curl to stop having the gazillion year old http: default when you use urls without a scheme.

Look, pack your luggage and get ready to fly to all the datacenters that will break when we ship that.

No, you will not get paid for this. Some body armour might also be a good idea.😎

isotopp, to random German
@isotopp@chaos.social avatar

https://botsin.space/

Hier sieht man den ganzen Unsinn einer Fahrradmitnahme im Zug einmal kondensiert.

Dies ist schon für platzsparende Version, aber die dafür ist sie nicht AAA.

Man stelle sich das nun in voll vor, werfe noch ein paar Leute mit Gepäck und schweren E-Bikes ins Rennen, und jetzt wollen eine Hand voll von denen gleichzeitig aussteigen und Gepäck aufladen.

So etwas kann es geben, aber nicht als Regelfall in skalierbar und im Nahverkehr, womöglich zur Spitzenzeit.

icing,
@icing@chaos.social avatar

@unixtippse @isotopp Seid ihr alle hier so groß? Da fühlt man sich mit 187cm klein…

Ich sollte mir ein anderes Social Network suchen. Nichts gegen Riesen, aber den Sonnenaufgang immer erst eine halbe Stunde nach den Kollegen zu sehen, ist auch nicht schön. 💁🏻‍♂️

icing, to random
@icing@chaos.social avatar

30000 people is the official count.

The fascist AfD party has 2% of the votes in this city, the lowest in all of Germany. Yet, they do a yearly meeting in our historic city hall.

In previous years, there had been protests mostly from the left with up to 5000 people last year. This time, everyone was there. The city needed to be closed off for safety reasons.

https://www1.wdr.de/nachrichten/westfalen-lippe/demo-afd-muenster-104.html

icing, to random
@icing@chaos.social avatar

On Antifa demo with my daughter, lots of people of all ages there.

icing, to random
@icing@chaos.social avatar

Kazuho Oku and Lucas Pardue published a proposal to do HTTP/3 and QUIC over TCP+TLS. Very interesting.

https://datatracker.ietf.org/doc/html/draft-kazuho-quic-quic-on-streams
https://datatracker.ietf.org/doc/html/draft-kazuho-httpbis-http3-on-streams

icing, to random
@icing@chaos.social avatar

I write test cases because testing is mind-numbing and boring and I prefer handing that over to comrade computer.

But, hey, if you‘d rather do this youself, as I can see in repositories, who am I to deny your fun?💁🏻‍♂️

kubikpixel, to Engineering
@kubikpixel@chaos.social avatar

✨ I'm a 1x engineer ✨ (I post it again)
https://1x.engineer

icing,
@icing@chaos.social avatar

@kubikpixel @isotopp Sadly, they also do not write test cases. 💁🏻‍♂️

icing, to random
@icing@chaos.social avatar

Hmm, @bagder is on vacation, time for some curl changes, I guess!

My list for next week:

  • rip out ftp:. a protocol who clearly overdid the ‚networking‘
  • ldap: lol, as if that ever was a scheme. gone.
  • cookies need to go! they are even worse for security than C
    (Ah, C! Remind me of rewriting everything in Rust once it supports dynamic linking of crates!)
  • add url completion on the command line. I always forget the query parameters for tracking…

Anything else?

isotopp, to random German
@isotopp@chaos.social avatar
icing,
@icing@chaos.social avatar

@isotopp PasOps, often better then DevOps. 😌

icing, to random
@icing@chaos.social avatar
icing, to random
@icing@chaos.social avatar

OpenSSL QUIC: "IMO the performance issues [in curl] are less of a concern than they are for server-side applications"

Well...I'll write that down here and we'll let our power users decide.💁🏻‍♂️

https://github.com/openssl/openssl/discussions/23339#discussioncomment-8397243

icing, to random
@icing@chaos.social avatar

How can you tell if an LLM was educated to deceive you? You can’t.

Just as with brains: slice them any way you want, you‘ll not find the place that will steal your money. Or stay loyal and truthful.

Just as with humans: you can check they are capable of being cashiers, but you still need safeguards against theft. Or one day, it will happen.

https://www.schneier.com/blog/archives/2024/02/teaching-llms-to-be-deceptive.html

bagder, (edited ) to random
@bagder@mastodon.social avatar

Thank you Bitwarden! @bitwarden

icing,
@icing@chaos.social avatar

@bagder they sent curl a nibble of appreciation and then some.

icing, to random
@icing@chaos.social avatar

Why will @bagder talk about other people possibly making curl at FOSDEM? Does he want to stop? Is he not happy with my work?

Anxiously awaiting the talk in 50 minutes. 😳

icing, to random
@icing@chaos.social avatar

The evolution of HTTP/2 performance in curl, where I make a confusing chart and many wrong analogies to, hopefully, your entertainment.😌

https://github.com/icing/blog/blob/main/curl-h2-perf-evolution.md

isotopp, to random German
@isotopp@chaos.social avatar

Pulse Secure isn't, and is to be turned off:

https://twitter.resolvt.net/@zaphodb/111857221592137558

"CISA is requiring all Federal
agencies to disconnect Ivanti products by Friday at midnight (Ivanti Connect Secure & Ivanti Policy Secure). This is roughly 48 hours notice, to not patch, but rip it out! Ivanti is an American company. This is unprecedented."

icing,
@icing@chaos.social avatar

@isotopp Wenn man - guckt in den Kalender - 2024 noch Probleme mit XML external entities hat, dann besteht das Ding wohl aus Leichenteilen und wird von Zombies gemanaged.

icing,
@icing@chaos.social avatar

@isotopp Ja, genau so hab ich das vermutet.

isotopp, to random German
@isotopp@chaos.social avatar

https://www.golem.de/news/bitkom-warnt-nur-wenige-nutzer-aendern-das-standardpasswort-ihres-wlans-2401-181734.html
"Außerdem ändern gerade einmal 3 Prozent ihr WLAN-Passwort regelmäßig."

Total unklar. Wo es doch automatisch auf allen verbundenen Geräten mit geändert wird, sodaß man damit kaum Arbeit hat.

icing,
@icing@chaos.social avatar

@isotopp
Ich habe auch keine Zugbrücke an meiner Haustür. Es ist alles ganz schlimm!

icing, to random
@icing@chaos.social avatar

„Do you want to use a computer where you easily can’t show anyone else what you’re looking at?“

You are alone in there. You can decorate your space with as many spatial windows you want, no one will ever see what you did. No one can share what they did with you.

If you remember Avengers augmented reality scenes, they were looking together at pieces, sharing, cooperating and coming to conclusions. This is not like that.

https://www.theverge.com/24054862/apple-vision-pro-review-vr-ar-headset-features-price

icing, to random
@icing@chaos.social avatar

Now I think I need wall-covering world maps in my office.

icing,
@icing@chaos.social avatar

@peturdainn @bagder obtained a cat last year. I believe we're set.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • osvaldo12
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • everett
  • Youngstown
  • ngwrru68w68
  • slotface
  • cubers
  • rosin
  • thenastyranch
  • kavyap
  • InstantRegret
  • provamag3
  • tacticalgear
  • Durango
  • cisconetworking
  • GTA5RPClips
  • modclub
  • normalnudes
  • mdbf
  • ethstaker
  • Leos
  • tester
  • megavids
  • anitta
  • lostlight
  • All magazines