@vorlon@mastodon.social avatar

vorlon

@vorlon@mastodon.social

Portland, OR. 1312. Exiled from Twitter before it was cool. I was there at the dawning of the Third Age of Free Software.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

mjg59, to random
@mjg59@nondeterministic.computer avatar

This corresponds to my experiences with Eben: https://fsfe.org/news/2023/news-20231011-01.html

vorlon,
@vorlon@mastodon.social avatar

@mjg59 I hear the "Fuck Eben Moglen" mark is currently available

enobacon, to oregon
@enobacon@urbanists.social avatar

"The Oregon (OMV) registration law took effect on January 1, 2016, making the first state in the nation to implement automatic [for drivers]" and then they mail you a ballot, but how do we get non-drivers to vote?

vorlon,
@vorlon@mastodon.social avatar

@enobacon are you aware of the efforts to automatically register everyone on the Oregon Health Plan? There's a strong correlation between non drivers and Medicaid recipients!

vorlon,
@vorlon@mastodon.social avatar
ct_bergstrom, to random
@ct_bergstrom@fediscience.org avatar

I wanted to consolidate a few thoughts on google, misinformation, large language models, enshittification, and the fate of the web as we know it.

It started when Carl Zimmer shared this remarkable example of Google being fooled by machine-generated bullshit online.

vorlon,
@vorlon@mastodon.social avatar

@ct_bergstrom yes. Stop trying to use a search engine as an answer engine.

BlackAzizAnansi, to random
@BlackAzizAnansi@mas.to avatar

Gaza is one of the most densely populated places on earth and the people who live there are walked in how to are they supposed to "get out?!?"

vorlon,
@vorlon@mastodon.social avatar

@BlackAzizAnansi

"stop resisting".

"Leave the area to your west."

There is no difference.

There is a reason American cities send their police forces to Israel for training.

timonsku, to China
@timonsku@mastodon.social avatar
vorlon,
@vorlon@mastodon.social avatar

@timonsku "I fear that our export-control laws are not equipped to deal with the challenge of open-source software" lol

mcc, to random
@mcc@mastodon.social avatar

It finally happened. A robot asked me if I have stairs in my house

vorlon,
@vorlon@mastodon.social avatar

@mcc hahahaha I'm so old

vorlon, to random
@vorlon@mastodon.social avatar

Many people who could not implement encryption, or even explain it, nevertheless have absorbed the message that they should use it, because it keeps their information secret from prying eyes.

This is good.

But encryption is not a panacea, not even "end-to-end" encryption. The problem arises when people believe "it's encrypted, therefore it's safe".

Because encryption relies on you having a secret that no one else has, that you use to do math, to reveal the plain text.

1/6

vorlon,
@vorlon@mastodon.social avatar

But that secret doesn't just live in your head; you share it with software to do the decryption.

When the software you're sharing it with is running in a web browser, that software is directly controlled by the web server that serves the page. There is NOTHING that stops the software running in your browser from sharing that secret back to the web server.

2/6

vorlon,
@vorlon@mastodon.social avatar

Web browser security considers it critically important to not share with a server information that was given to it by ANOTHER website, but web apps just plain wouldn't work if they couldn't consistently pass information back and forth between the frontend and the backend.

So when someone promises you end-to-end encryption to imply that you don't have to trust the server in the middle, it's important to ask: who controls the software that has access to my key?

3/6

vorlon,
@vorlon@mastodon.social avatar

If the answer is that it's the same party that controls the server that the end-to-end encryption is supposed to protect against, are my messages really secure?

Maybe you trust the server today. But will you trust it tomorrow? If the server is compromised, will you have any way of finding this out before you visit the compromised site and your web browser joyfully hands over the keys to the castle?

4/6

vorlon,
@vorlon@mastodon.social avatar

In-browser "end-to-end" encryption is better than no encryption, and it does protect against offline attacks of the server data. But you shouldn't be lulled into a false sense of security.

So when you use Protonmail's webmail to decrypt emails, or you let keybase "escrow" your PGP keys so you don't lose them, be mindful of what you are or aren't protected against.

5/6

juliank, to random
@juliank@mastodon.social avatar

US has like 10mg slow-release melatonin and here we have 1.8mg, 1mg instant release and 0.8mg slow release.

US has what, 240mg pseudoephedrin, here we have 30mg.

US is the 10x drug amount country?

vorlon,
@vorlon@mastodon.social avatar

@juliank ok but it's impossible to find Alka Seltzer without aspirin in it unless you special order it because Bayer

Not sure where that pseudoephedrine number comes from though, the tabs in our medicine cabinet are 30mg

vorlon,
@vorlon@mastodon.social avatar

@juliank in Oregon it's worse, they require a prescription for pseudoephedrine, basically making cold relief inaccessible to anyone for whom that's a burden.

I've never gone to the doctor to get a script for it. That's dumb. I travel enough that I've just bought all of mine out of state and brought it home.

And the 30mg tabs in the cupboard? It's a 96-count box

vorlon, to random
@vorlon@mastodon.social avatar

Can you explain this gap in your CVE

Andres4NY, to random
@Andres4NY@social.ridetrans.it avatar

So how do we think Officer Adams will sabotage NYC's congestion pricing? Make your predictions.

vorlon,
@vorlon@mastodon.social avatar

@Andres4NY the income from the congestion pricing will be earmarked exclusively for funding NYPD enforcement of MTA fares

foo, to random
@foo@fosstodon.org avatar

Del Taco has replaced drive through order taking with a chatbot. I hate this timeline.

vorlon,
@vorlon@mastodon.social avatar

@foo Checkers also

juliank, to random
@juliank@mastodon.social avatar

I don't think I can find good kimchi. Outside of tiny canned one from Korea, the options are all just very strongly ginger forward and that doesn't seem right.

vorlon,
@vorlon@mastodon.social avatar

@juliank we have a lot of options for kimchi here. I don't know if Koreans would consider it good, but I've found one I really like!

I'd offer to bring you some except i don't like their vegan version and can't endorse it 👋

b9AcE, to random
@b9AcE@todon.eu avatar

A bit late, but anyway because it's both funny and important,
from Devuan, the Linux distro you should probably be using (Debian but reverting the systemd-disaster), over at the ex-birdsite, on September 5:
─────
Once again we are not affected by this bug involving systemd! 🥋 https://pulsesecurity.co.nz/advisories/tpm-luks-bypass it allows anyone to bypass the password of an encrypted systemd/Linux installation... just mashing enter 😂

p.s. the exploit POC can be implemented using Devuan! https://github.com/dyne/devuan-pi-gadgeteer
[attached picture]
─────

vorlon,
@vorlon@mastodon.social avatar

@b9AcE please point users to the documentation of the Devuan implementation of TPM-backed full-disk encryption that was unaffected by this bug

vorlon,
@vorlon@mastodon.social avatar

@b9AcE I already know the answer. Just confirming for the public that you don't.

vorlon,
@vorlon@mastodon.social avatar

@b9AcE lol go ahead and block me, hater.

I don't agree with the Clevis implementation, but I have respect for anyone trying to tackle the hard problems of improving Linux desktop security.

Devuan is a joke.

ned, to feminism
@ned@mstdn.ca avatar

Sad, but...

"Heard of a cool tech-bro-weeding interview technique the other day. A male and female engineer conduct the interview session together. If, when the female engineer asks the candidate a question, he directs his answer to the male engineer, then he's out. They said it happens a lot"

vorlon,
@vorlon@mastodon.social avatar

@ned have not had capacity to push for this at work but I believe first-round interviews of all candidates should be conducted by Black women, who are compensated appropriately for the job duty, and if they say the candidate is out, the candidate is out, no exceptions.

Not a tech interview. Interviewer need not have a technical background (and this should apply for all roles, tech and not tech). Job qualification for the interviewer role is to be a Black woman who a racist can't hide from.

juliank, to random
@juliank@mastodon.social avatar

The truth is out there

Not inside yourself.

Outside.

OUTSIDE

Don't trust yourself.

vorlon,
@vorlon@mastodon.social avatar

@juliank I have difficulty imagining what an X-Files reboot would look like. There's a lot of it that just feels inherently pre-9/11 to me.

vorlon,
@vorlon@mastodon.social avatar

@juliank ok I guess what I'm saying is I'm not sure how anyone would do a reboot that's worth watching 😁

juliank, to random
@juliank@mastodon.social avatar

Oh god, public financial authorities are getting back to me about an issue I raised months ago and forgot about, lol.

vorlon,
@vorlon@mastodon.social avatar

@juliank thanks for the reminder that I need to get around to figuring out a class action suit against Orrick, Herrington & Sutcliffe, LLP for 1) having my PII, and 2) losing my PII in a data breach.

Who is Orrick, Herrington, & Sutcliffe?

Why, they're the law firm retained by the company managing our employer-provided vision benefits plan in the US TO REPRESENT THEM AFTER THEY LOST OUR PII IN A DATA BREACH

And WHY did this company give our PII to their LAWYERS?

GOOD FUCKING QUESTION

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ethstaker
  • thenastyranch
  • ngwrru68w68
  • magazineikmin
  • khanakhh
  • rosin
  • mdbf
  • Youngstown
  • slotface
  • everett
  • cubers
  • kavyap
  • DreamBathrooms
  • provamag3
  • InstantRegret
  • Durango
  • normalnudes
  • osvaldo12
  • tacticalgear
  • cisconetworking
  • Leos
  • GTA5RPClips
  • modclub
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines