Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)L
Posts
3
Comments
87
Joined
3 yr. ago

  • We hypothesise that the production of fully entangled sheep is easy, given how hard it can be to disentangle their coats in the first place. The logistics of assembling the tens of thousands of sheep necessary to factorise RSA-2048 numbers is left as an open problem

    Omg, I simply cannot! Thanks for brightening my day with this paper XD

  • I am still active at my local scouts troop. I'm not a group leader anymore (not enough time), though I'm responsible for the courses for new group leaders (those that are needed to start being a group leader in my scouts organization). Also I was the main author of our new song book and play guitar for the kids on various camps.

    Besides that I currently try to get politically active with a leftist party here. Though I'm not sure, what I can contribute. We will see.

    What crosses my mind again and again for quite a while now is joining or creating a neighborhood help group. Something to help people locally and tie the neighborhood together. Though I'm unsure on how to start that, find other people that would like to join, and also not sure about my own time constrains. Don't want to overwork myself with volunteering.

  • The important part where this scheme came from:

    According to Tex Texin, the first numeronym of this kind was "S12n", the electronic mail account name given to Digital Equipment Corporation (DEC) employee Jan Scherpenhuizen by a system administrator because his surname was too long to be an account name. The use of such numeronyms became part of DEC corporate culture.[3]

    So it was a technical limitation gotten corporate naming scheme.

  • Though that is mostly a problem for big techs vision of VR, where we use it everyday allday (like all the shit with business meetings in VR). It was always a niche technology. But 3D printing is also a niche. But it got to be a big niche. And with even the current developments we got quite a reduction in size (thus better wearing comfort). I think an open hardware and software system would quite help the whole VR industry to get better, though still being a niche.

  • While you generally have a point, the year of the linux desktop is not hindered by that. Distributions like Linux Mint, Ubuntu and the like are just as easy to install as Windows, the desktop environments preinstalled on them work very good and the software is more than sufficient for like 70% to 80% of people (not counting anything, that you cannot install with a single click from the app store/software center of the distribution.

    Though Linux is not the default. Windows is paying big time money to be the default. So why would "normal people" switch? Hell, most people will just stop messaging people instead of installing a different messenger on their phone. Installing a different OS on your PC/Notebook is a way bigger step than that.

    So probably we won't get the "Year of the Linux Desktop", unless someone outpays Microsoft for quite some time, or unless microsoft and Windows implode by themselves (not likely either)

  • I sometimes wonder what would happen to VR, if it would get the same situation as 3D printing. That took of, because some patents where expiring and it was then easy to build up your own version. We had/have many open source/FOSS printers and nearly all the companies currently in this space wouldn't exist, if it werent for the many open source developments and the extention of the market, that they created. I know this is highly unprobable for VR, but one should be allowed to dream

  • Are there any infos about what an attacker can do with this? The article didn't say this. Remote Code execution? With the privileges of the app? Reading all files? Or only some? The impact information seems important here.

  • I really don't understand that argument. So is most of the US not connected to the sewers? Since these are also dug underground. If you already dig trenches for the sewer system, then you can also place electricity lines for relatively cheap. Though that was not done in the US and retrofitting is a big cost, usually only done, when you need to dig either way (e.g. for modernizing the sewer system). So its more about the default and if a country can take the opportunity when sewers get modernized

  • Though in development of an area you probably already dig up the ground for other utilities, so in that case it is relatively easy and cheap to also put electricity lines in there too. But retrofitting in an already developed area is really expensive. So it becomes more a question of the default.

  • If the recipient is technically inclined, then a kit for a mini tesla coil would be cool

  • You can get the image SHA. If you then provide the corresponsig tag, that you used, an application could check if a new image is available. Or maybe if you use docker compose, the app could get the tag from the compose file, and even check for new tagged versions based on a specific pattern.

  • Wow, thats one kind of a project. I'm impressed. Though it doesn't really fit my problem. It has to be something webbased, where everyone of us can use it without an app, without seeing each others information. From the github page it looks like a local tool. And also focused trading similar items. The presents in our secret santa are highly individualized, so randomly trading does not make much sense. And if the interface is too clunky, my non-tech siblings will just reject using it. I want to keep them from deciding for some free privacy nightmare app.

    But I thank you for the suggestion. Its an interesting project

  • Security noob here. Would it be sufficient (in addition to only local authorized access) to directly put the file in an unprivileged container, watching its log output? And of course limiting resource use and execution time of the container (don't know if common container tools like docker or podman have a way to limit resources out of the box)

    So lets say a simple interface for the file upload behind an authentication service, based on lets say python cgi, ramping up an unprivileged nonroot docker container, killing the container after a fixed time (a few seconds).

  • That looks promising. And I can contribute with a translation for another language

  • I will try it, when I'm home again. The commit history starts and ends about 5 months ago, so yeah, probably not fully finished. Thanks for the suggestion

  • I run headscale on my VPS. The tailscale clients are already open source, though by default they connect to the companies servers for coordinating the net. Headscale is open source and replaces the companies servers with your own. Best to not rely on some corporate service, which could cease to exist or be enshittiefied.

  • Maybe someone has more history knowledge than Wikipedia in this case: Were the Young Pioneers inspired by the Scouts movement, which was startet 1908 by Baden Powell? Or more by nationalist youth groups that followed them (like the Hitler Youth in germany took the traditions of scouts and the wandervogel groups and contorted them into violent nationalism)? Is there any connection?

  • Otherwise, you need to be some kind of freaking retro-engineering expert.

    Nah, often software is stupidly easy to breach. Often its an openly accessable database (like recently with the Tea app), or that you can pull other data from the webapp just by incrementing or decrementing the ID in your webrequest (that commonly happened with quite a number of digital contact tracing platforms used during Covid).

    Very often the closed source just obscures the screaming security issues.

    And yeah, there are not enough people to thorouhly audit all the open source code. But there are more people doing that, than you think. And another thing to mind is, that reporting a security problem with a software/service can get you in serious legal trouble depending on your jurisdicting - justified or not. Corporations won't hesitate to slap suit you out of existance, if they can hide the problems that way. With open source software you typically don't have any problems like this, since collaboration and transparency is more baked in into it.

  • NSFW Deleted

    Permanently Deleted

    Jump
  • No, I think that you have that right for every contract, that you enter (buying contract or otherwise). Though there are exceptions (for example digital goods like ebooks). Ypu can very much bring back a retail good that you bought in a store for 14 days after the purchase. Though I think they can refuse, if you damaged the product in that time.

    For example I returned an item I bought in the tool store, because I realized I bought the wrong one.