Mr_Figtree avatar

Mr_Figtree

@Mr_Figtree@kbin.social

Security advisory for Cargo (CVE-2023-38497) | Rust Blog (blog.rust-lang.org)

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

How to make Firefox trust a self-signed certificate? (fedia.io)

I'm a web developer working on an app running in Docker on my MacBook. Chrome, Edge and Safari trust the self-signed certificate that has been imported into the Mac's root certificate store and have no security issues, but when I try and access the web app, I'm hit with "Warning: Potential Security Risk Ahead" and the error code...

/kbin logotype
Mr_Figtree,
Mr_Figtree avatar

Does the certificate have a basic constraints extension with CA:TRUE set? Firefox doesn't allow that for certificates used as ‘end entity’ certificates. You'll want to re-generate the certificate without the extension.

Mr_Figtree,
Mr_Figtree avatar

The complete changelog:

Improved migration experience for users switching to the ESR release. (bug 1845338)

July 2023 Leadership Council Update | Inside Rust Blog (blog.rust-lang.org)

Hello again from the Rust Leadership Council. In our first blog post, we laid out several immediate goals for the council and promised to report back on their progress. It has been about a month since our first update so we wanted to share how it's going and what we're working on now.

Mr_Figtree,
Mr_Figtree avatar

Someone I know recently switched from automatic bathroom lights to manual ones. Remembering to turn them on isn't an issue, but months later everyone still forgets to turn them off.

Mr_Figtree,
Mr_Figtree avatar

so I can totally ditch chromium/electron

GNOME Web isn't Chromium-based and does support PWAs, so it might work for your usecase.

Mr_Figtree,
Mr_Figtree avatar

And .box has been registered as a generic TLD now, so you could run into external .box domains.

Mr_Figtree,
Mr_Figtree avatar

They're not going to have open signups. It's government agencies only. Not that there's technically anything stopping Germans from joining the PR departments of our government agencies…

Mr_Figtree,
Mr_Figtree avatar

So what you're saying is that Twitter successfully kept out a bad actor.

It's a shame that most of the users they have left are also in that category, but hey, they seem to be working on it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • tsrsr
  • DreamBathrooms
  • everett
  • magazineikmin
  • osvaldo12
  • Youngstown
  • InstantRegret
  • slotface
  • ngwrru68w68
  • rosin
  • hgfsjryuu7
  • kavyap
  • PowerRangers
  • normalnudes
  • thenastyranch
  • Durango
  • cisconetworking
  • ethstaker
  • tacticalgear
  • mdbf
  • khanakhh
  • vwfavf
  • cubers
  • modclub
  • GTA5RPClips
  • tester
  • anitta
  • All magazines