Your friendly neighborhood tech frog, here to explore society and complex systems together. My personal views are obscure and will probably be grating to most people, but we don't have to agree to be friends! Will often discuss things like distributed systems, programming, society, and computer security. Politics WILL come up sometimes. Video games are cool too :blobowo: I do serious research in between memes I swear, follow for fun computer adventures, and help build a better society together!!
Public Key
npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 Profile Code
nprofile1qqstaz0xjuk0lz0nca03xv8gp8a5jmkn5d6m0qjlzw82uzea6sd6g6gpz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0dspk6lge
Show more details
Published at
2026-07-14T13:16:49Z Event JSON
{
"id": "e18a95a4e2e8b07bffd7db66aa1a48bcd6582c78ff3cb77b25d7f959c0e79ab9" ,
"pubkey": "be89e6972cff89f3c75f1330e809fb496ed3a375b7825f138eae0b3dd41ba469" ,
"created_at": 1784035009 ,
"kind": 0 ,
"tags": [
[
"emoji",
"blobowo",
"https://social.glitched.systems/files/e8bb4696-d91c-4cf3-bf7f-49b37579c323.png"
],
[
"proxy",
"https://social.glitched.systems/users/9woullc2w5a60618",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://social.glitched.systems/users/9woullc2w5a60618",
"pink.momostr"
],
[
"-"
]
],
"content": "{\"name\":\"CyberFrog\",\"about\":\"Your friendly neighborhood tech frog, here to explore society and complex systems together. My personal views are obscure and will probably be grating to most people, but we don't have to agree to be friends!\\n\\nWill often discuss things like distributed systems, programming, society, and computer security. Politics WILL come up sometimes. Video games are cool too :blobowo:\\n\\nI do serious research in between memes I swear, follow for fun computer adventures, and help build a better society together!!\",\"website\":\"https://social.glitched.systems/@froge\",\"picture\":\"https://social.glitched.systems/files/16d914ee-2f7b-4d34-89c0-f195470b914e.gif\",\"banner\":\"https://social.glitched.systems/files/1901df0c-b047-42b4-aeab-8a8b6ac1308b.gif\",\"nip05\":\"[email protected] \"}" ,
"sig": "1938b92ba587aad0397a89f8507f28b2461856d90ecfed06b1c7ab85100fa5d1a48b3c621ec51a6ddb53824d87bc9ad78dafe0b2f89839726638de038c55e536"
}
Last Notes npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog every day I open the internet and spend 15-20 minutes cycling IP addresses in order to hit a winning combination that allows me to access all three (3) centralized services I regularly use to communicate with people, without one of them arbitrarily blocking me based on made up bullshit metrics npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog fedi there is so much full force sloperating happening in open source accounting software... no, NO look at me fedi, I know it's boring but you need to look at the accounting software, it's bad ok, it's really fucking bad out there, and I don't think your financial situation should depend on whatever logic an LLM spat into a bunch of accounting software without review beancount developer fantasizing about running "5-8 agents" on the beancount codebase and babysitting them instead of writing code https://groups.google.com/g/beancount/c/cz8Xwnb7BLE/m/LSA3rTfMAgAJ ledger accepting LLM code and talking about vibe coded ports to Rust (as an experiment, at least, but lol) https://github.com/ledger/ledger/discussions/2474 rustledger (seems almost entirely vibe coded) https://github.com/rustledger/rustledger paper by the american accounting association on "Applying Large Language Models in Accounting" https://publications.aaahq.org/jeta/article-abstract/21/2/133/12800/Applying-Large-Language-Models-in-Accounting-A npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog me watching two Rust libraries interact over the simulated C FFI calling convention because that's the only way they were exported even though they're both actually Rust code this is a real thing happening in several major production projects in several different ways and some people just aren't ready to accept that lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I think this is generally why the advice is that you shouldn't actually have auto-updates turned on, by default the auto-update systems only apply security patches even if you enable them usually too npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog fedi I've been programming for 15 hours straight, my code is linear but the output is nondeterministic, type abstraction has lost all meaning send help, for I have sinned, and this is my purgatory npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I'd like to see open street maps go back to contributor only updates, because I'm very certain it's going to suck way worse than incorporating the state maps, pretty sure they started doing that because it was *actually* much higher quality data tbh I do think they should offer a version that separately labels the state maps so you can choose to ignore them, but also, I'm very sure the state data will be if high enough quality that everyone will still prefer downloading it anyway tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog maps are constantly changing, even the government supplied state maps will have like 1,000+ changes a month, sometimes a street disappears and comes back, usually this is a better experience than an outdated maps with streets that don't even exist ghost streets exist in OSM too and it's way more annoying for me than just having updated maps tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog IACR out here taking shots at the non-js users https://iacr.org/tinfoil.html https://s3.eu-central-003.backblazeb2.com/glitched-social/social/3fe7a08a-4699-484a-a9aa-c08bef16934d.png npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this, 100% this, it's bullshit and shouldn't be tolerated for end users npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog imagine deploying this in a world where several alternatives do a better job for free lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog wow, what a piece of shit tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog > so if you're poor? Get fucked. That's basically it. this describes almost all technology I see in the modern world with some built in "market" or "profit incentive", you cannot implement these things without massively tipping your user base towards rich people with disposable income, especially during the early growth phase this is not technology for the people, this is not technology for the benefit of society, this is technology that works for the rich npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog :) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the policy for development at linux is to fix anything that you break when making changes... unless what you break is out of tree... so having this out of tree just imposes a lot of annoying problems on distribution and packaging systems, and having bcachefs be removed from the kernel over what is effectively a minor argument about patch timings is just bad and stupid tbh linux desperately needs a serious replacement or competitor to btrfs, and having it in-tree helps support migration over to it as a reliable default for linux users at some point in the future, which I think would be a good thing generally npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yeah, I guess it also depends on what you care about and consider "significant" protesting can change funding or fix some types of social issues, but very rarely will it change systemic problems caused by broken power structures tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I fear that even this is becoming impossible lately, which honestly is a truly despicable feat not even in ethereal form on a data network can our people move and exist freely... it's quite sad, and genuinely difficult to get to this point in society npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I feel this way most days tbh today I walked past several cars which I know for a fact recorded footage from 5 different angles of my body and face, and uploaded it to some private company to analyze and identify me, which will later be sold to some government department one day for barely justified reasons that was between walking through a local mall with no less than 15 different CCTV cameras and spending my last few dollars at a store that tracks my purchases through systems owned by a single global corporation, to maximize their income against my interests sometimes I just want to live in a society where I can walk down the street without being automatically profiled and squeezed for money, or have a genuine conversation with a friend that isn't recorded and ruthlessly analyzed to benefit somebody who doesn't even know me sometimes I just want to go into the woods and live in a cabin where the world will finally, at last, just leave me the fuck alone and let me live my life with like minded people tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog legal peaceful protest does little to a state or system of management imposing laws against their people which are immoral and unjust tbh nothing significant in life has ever been achieved through entirely peaceful means, it just... isn't something that works long term... because sometimes you have to actually anger the people in power for things to improve, and doing that necessarily involves more than passive peaceful resistance to inhuman and terrible conditions npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yes, so much this... I understand requiring MFA for certain special actions even after being logged into an existing session, but if your system has to ask *multiple times in a row* you're doing something very wrong (especially if these interactions are routine) annoying users this way only frustrates them into being insecure in new and increasingly fucked up ways tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yeah I have to fight my inner computer user when people do this too because... god wtf literally why the fuck would you do that it's so awful omg but then I calm down and just hope society doesn't collapse from everyone doing this repeatedly, and sometimes it's ok lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this reminds me of the time I saw a head teacher at a trade school open an MS excel document and, I swear to god, based on muscle memory checked the warning box and clicked "run embedded scripts" faster than I could finish reading the popup I'm extremely certain that when they get hacked due to this the person responsible will say "it just opened and ran without any warnings, I had no idea!" npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog damn, perhaps possible, but maybe not fun lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog but how much is it in drumsticks only? 🤔 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog well yes, but that is like... every security exploit ever, the issue is that reverse proxy and HTTP server implementations are buggy and non-conformant, which results in genuinely serious security issues sending extremely broken and malformed content to reveal a bug is standard, and if the implementation fails in ways that expose users to attacks, that is perfectly valid and important to disclose and fix the same thing is true of inputting malformed content into a binary and having a memory corruption exploit happen, just because you're not following spec doesn't mean the code should break npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog to be fair the portswigger researchers are well known for pulling off complex attacks (this is related to HTTP server desync attacks) also I'm 99% sure they're negotiating patches for the impacted software before this talk, it's not like them to just full disclosure bugs like this... but yeah the flashy websites are still annoying lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this, it's not even a competition, graphene wins in basically any metric you could imagine almost without effort, just because the practices of /e/OS are laughable npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog > Meanwhile, many companies investing heavily in AI are not finding any clear return on investment, the Autonomy Institute claims. Of those 500 firms, 57 (11 percent) have explicitly cautioned that they may never recoup their spending on AI, or actually realize the expected benefits. lol, lmao even #note1clp…exx3 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this website recently took down their server, about 10 minutes ago, and the DNS record has been removed from their domain seems they noticed and quickly burned the entire project, but I can confirm they cloned about 3.9k accounts at the time of checking (about 10 minutes ago) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog just found out the largest domain+email provider in Australia (ventraIP) is storing their customer IMAP passwords in plaintext.... what even the fuck? apparently iiNet is also doing this for their ISP customers... is this shit just normal? am I going insane? this is MILLIONS of people using services where their email password can be viewed by literally anyone at the company with access to the support systems, in plaintext format... wtf npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog "just work bone crushing manual labor until we find a way to replace that too" yeah thanks bro lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog surely they just jammed a single sentence into AI to generate this report.... I wish bug bounty didn't encourage people with the lowest possible skill level to spam 10,000 issues until one of them happens to stick for money *sigh* genuine question, would you say you get mostly useful reports on the curl bug bounty program, or are majority just noise that gets closed with no impact? a quick look at the "hacktivity" page shows a depressing stream of nonsense at first glance npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I remember reading about this story when it first broke, a huge part of the issue is that the UK legal regime maintained until very recently that "computer systems could not make mistakes" as a matter of legitimate legal authority it was absolutely insane and every time someone claimed the computer system was wrong the court automatically sided with the computer system against the employee truly they've never looked at software in the real world before, and it literally killed people as a result npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog hey, just a heads up, your new bot filtering software is breaking firefox with noscript enabled for some reason this seems to be because of the 301 redirects which attempt to set a `deflect_session` cookie, which firefox + noscript strips on page reload as far as I can tell, causing an infinite reload loop I fixed it by pre-allowing your website in noscript before the page even loads, but I'm guessing this is new because it hasn't really happened to me before on your site npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I swear to fucking god if another government website blocks access to their services based on shotty geolocation detection of an IP address assignment I'm going to lose it say it with me now: IP ADDRESSES ARE NOT TIED TO PHYSICAL LOCATIONS this shit is a *CRIME* and I am fucking sick of legitimate citizens being blocked from their OWN GOVERNMENT SERVICES because the absolute dickheads running these systems decided to block random IP assignments based on nothing except 3rd party geolocation databases, instead of funding actual security controls for their garbage systems fuck you, I'm 🤏 this fucking close to taking entire departments to court over this. npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I'm gonna be real with y'all I am extremely alarmed by the fact that politically sensitive services such as palestinian news organization Quds News Network just loads a shitload of google javascript into the browser on their page, including requests to accounts.google.com, meaning most likely everyone who visits them gets identified via their google account automatically if logged in this is like, extremely bad.... if you ever build websites for organizations like this, never ever do that, ever. https://s3.eu-central-003.backblazeb2.com/glitched-social/social/fd4669ff-eff7-4e26-896f-8c9b51ca363e.png npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog ready to be shared with law enforcement? I have awful news for you, Ring regularly signs deals to automatically share this crap with cops already, they've been doing that for years, thousands of police stations have unlimited warrantless access to ring video footage because Bezos thought it was cool already https://www.eff.org/deeplinks/2019/08/five-concerns-about-amazon-rings-deals-police npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog funny you should mention that, a few years ago I experimented with smuggling malware inside of the DICOM format, it bypassed every available anti-virus online when I stashed a KNOWN bad sample of ransomware inside the document as a binary polygot npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I don't really consider hospitals to ever be correctly air-gapped because in reality there are like 6,000 endpoints literally a single hop away from the "air gapped" devices with full internet access, and hacking the firmware of something like an insulin or drug pump is laughably easy because they simply ignored computer security for 30 years, you can still buffer overflow to RCE on those things without any issues @npub1fdr…lvhs wrote about this in 2014/15 and from the new research I've seen very little has improved since then https://boingboing.net/2014/04/27/hacking-the-hospital-medical.html npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog once saw a dentist chair running outdated windows 7 (yes, after EOL) with an anti-virus security alert popup which was ignored, and a horribly outdated Java version installed that was begging for updates this person was doing minor surgery with that machine daily, I had no choice but to let them use a probably malware'd device on my face, or leave and pray the next guy isn't as stupid nothing about this is fun npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I actively refuse to look at the security of the healthcare systems which keep me alive because literally EVERY time I have checked it scares me deeply npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog can confirm LoRa radios and meshtastic is very cool, definitely your thing if you haven't looked at it before I once saw those devices transmit data at passable speeds from over 150km away on a free-to-use radio band, very nice stuff npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the most hilarious part is that I think we already have this, it's called pending payments on the card, I think online purchases can even request that payment type and it works and everything, they're just not used very often for whatever reason (probably that it takes 3-8 days for a payment on the business side because real banking is slow as fuck) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog huh, just heard a bank advertising rotating CVC codes for online purchases with their card, and this combined with the cards that technically offer 2 valid CVC codes has me wandering about the rate limiting and other security controls on card verification systems 🤔 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog me spamming the reply button with "yes Derek, I discussed it, we need to do <x> I think actually" like it's an NPC dialogue and I'm waiting for the story to start (it will still take 5 more emails) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the USA likely won't do anything except kill the person responsible, either through the death sentence or otherwise however this comes only a day after IDF soldiers shot at a delegation of 25 diplomats in the occupied West Bank, this shooting in the USA is likely to be a retaliatory action taken by an independent citizen as a result of world governments not representing the values of their people in regards to Israeli actions, including in the USA The news hasn't reported a motive yet, it's either American turbo racism (which is entirely possible), or what I think is more likely is that it's probably a reaction to the recent aggression on display by the IDF toward world leaders, and the current lack of any real reaction from many governments in response npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog uhoh.... this can't end well #note1wvp…qwj4 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I have enough self awareness to know I shouldn't be fucking with things like that at least lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yooo federated forgejo is becoming real, this is great news #note1hct…nkun npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the reports from industry leaders have LONG echo'd that cybersecurity is not an "entry level" field and there will never actually be "entry level" jobs in that market, because the skills required are not taught by businesses and employees won't be useful without years of experience anyway I heard almost 5 years ago that entry level jobs don't exist in the cybersecurity market and literally nothing has changed since then, and this is probably a good thing npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog Undocumented backdoor commands were found in the popular Espressif ESP32 microcontroller bluetooth stack > In total, they found 29 undocumented commands, collectively characterized as a "backdoor," that could be used for memory manipulation (read/write RAM and Flash), MAC address spoofing (device impersonation), and LMP/LLCP packet injection. https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog it's mostly a side effect of UNIX treating everything as files, in linux a "file descriptor" is opened for tons of shit that really has nothing to do with the filesystem, for example a network socket or UNIX socket consumes a file descriptor as defined by ulimits, and yeah so does an mmap'd file It's less about not sanitizing things in linux, and more like by limiting the number of open files you prevent weird race condition/threading attacks like this https://binarygecko.com/race-conditions-in-linux-kernel-perf-events/ this attack needs to open thousands of new FDs (which in this case are actually just a reference to a struct, not a real file) in order to trigger a race condition around an actually mmap'd file, so if your hard limits were quite low there is a better chance this fails to execute > The struct perf_event is returned to the user mode process as a file descriptor. this second link also explains a simple kernel module race condition, where the example code requires multiple threads to loop opening files until a bug is triggered that duplicates one of the FDs, so again limiting the open files can sometimes help stop this, since these type of exploits are common in real world attacks https://santaclz.github.io/2024/01/29/Linux-Kernel-Exploitation-exploiting-race-condition-and-UAF.html#race-to-get-double-file-descriptor npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog it's mostly about exploit mitigation, a huge amount of race conditions and threading exploits rely on opening millions of files and hoping that probability lets them trigger a bug eventually (cache related exploits also do this) so basically by limiting the number of concurrent open files you slow down those attacks so much that they stop working usually, which is why most distros have a pretty small soft limit, and a larger but not actually unlimited hard limit besides that it also sometimes stops buggy code from crashing everything lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yeah, the weird thing is that my distro hasn't changed and the soft/hard limits are still set to very low defaults for security reasons, because the only time I go over the limit is large compiles but actually I can't find the documentation note about increasing the file limits anymore, so maybe they fixed this in the build process for me instead of requiring a file limit increase from users tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I've been using this OS professionally for over a decade and to be real I have no idea why this happened, my best guess is that the system was under less load and the compiler managed to get enough open files to complete without breaking, but that's just a wild guess, compiling firefox should have saturated the file limit still npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog chat somehow 1024 FDs actually allowed the project to compile correctly, despite this failing every single other time I tried, and the documentation explicitly warning you to increase this limit or the compile will fail and yet it worked... this is an even BIGGER linux moment than I thought, wow npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog Oh no, I compiled firefox with `mold` linker and forgot to increase my open file limit above 1024 FDs.... welp guess I gotta restart that now classic linux moment :^) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog did you see that github's copilot will refuse to autocomplete ANY code which has the word "gender" in it? also several other banned keywords lol supposedly there are over 1,000 words which it will detect and refuse to operate on... https://github.com/orgs/community/discussions/72603 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog catch me hacking this algorithm and releasing information to the public to trick the system into believing everyone is impoverished, algorithmically driving Microsoft's profits into the dirt, and allowing thousands to buy items at a relative discount. I promise me and those like me have infinitely more time and energy to fuck this up than the corporations have to fix it, I'll make it my lifelong side project to lose them vast amounts of money with the same technology they built to exploit people lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog damn that's kinda rough, the show is really old so I don't imagine many people seed it, but I'm like 99% sure it would be on usenet somewhere... issue with usenet is that you have to pay for it :/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog apparently there are a *lot* of versions of the series, but they all float around on nyaa somewhere npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog that show was fire, don't worry I gotchu fam https://nyaa.si/view/1923190 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog The loops.video instance has been submitted to #FediBlock with the reason being outlined below. I can't say I disagree, the terms of service presents a serious problem for user content rights, and this should be addressed before federation of loops. Otherwise for the safety of your users I would highly suggest that instance admins defederate loops immediately once it comes online (assuming the TOS is not changed first) https://bajsicki.com/blog/loops-video-terms/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I have said this for many months, but it is worth repeating: Based on a lot of current state of the art research, AI models could probably be 10x smaller and trained with 10x less data than they are today. I genuinely believe we have enough data to just never collect anything new, and train AI on that for the next decade easily. Also Deepseek in particular was trained on 100% "synthetic" datasets, which are increasingly becoming common (and are usually generated by other AI models). This means no human/user data was even put into the model for training, it was all generated by other systems and completely made up to fit some desired statistical patterns Before someone asks, no model collapse doesn't matter in the real world, for reasons seemingly nobody can understand (please send me research if you do) training models on other model output, with the correct statistical approach, doesn't cause any problems. Merging the resulting model with other models also doesn't cause any problems really. Your guess for why this works is as good as mine, currently I think the variations in model output and differences in training data (thus embeddings) are enough to prevent model collapse. I tried finding research papers about this, and didn't see much analysis on why it works, just that it does work in practice. I think the single most impressive thing about Deepseek, aside from being trained on synthetic datasets, is that it's actually produced by China which is currently under extremely strict US sanctions and has no access to top of the line computing hardware for training, unlike OpenAI and other US companies do. Even while literally being sanctioned they still produced a better model, and this isn't the first time it has happened either lol also here is some info about model collapse due to synthetic data not mattering in practice, for anyone who is interested: https://www.theregister.com/2024/05/09/ai_model_collapse/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I used to write a lot of C, I read K&R like 3 times, and used to regularly consult the man pages every time I did anything. I once had a 50 line piece of code doing a super basic XOR operation over some bytes, which was technically vulnerable to a memory corruption bug even though I had used best practices as much as possible. It took me and literally three other experienced C programmers, and a straight block of three hours of arguing over the definition of two words in a man page, before concluding that yes it was probably buggy. I just stopped writing C after this, I'm convinced shitty C is the only thing that exists. npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog wow, even I learned something new from this, namely that #Apple #AirDrop is using a completely broken and flawed security system which is essentially broadcasting your name, email address, and phone number to the world all the time 🤯 https://arstechnica.com/security/2024/01/hackers-can-id-unique-apple-airdrop-users-chinese-authorities-claim-to-do-just-that/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog very very true, I am not impressed by their response, but I understand why Graphene maintains an official community there regardless npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I've also spoken to several Graphene contributors about the Matrix rooms, previously more than one of them was bricked due to state resolution bugs that Matrix insists are/were fixed, it's not exactly ideal for a big support community lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog #shametesla did nothing wrong! npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog they regulate usage of the internet, they don't actually manage or run it right now (for the most part), I just don't think national governments that don't even manage or control the internet should be regulating how people use it most of the world doesn't have net neutrality, and the USA repealed it recently (again), so packet shaping and blocking/censorship happens constantly online according to whatever your government just doesn't like that day, in the USA internet providers will check for insecure connections and inject extra advertising into websites just to rake money out of you (and this is technically legal), in other places entire protocols like torrents are blocked The people responsible for running the internet should be working on regulating and managing more of it without intervention and demands from random governments, like US states that want to block porn, or Egyptian and Chinese governments trying to block news websites, letting some national government which only represents a fraction of the people online control how shared resources are used and accessed by everyone else is just shitty in general This isn't even such a new idea, the people who built these systems understood the issues it could create, that's actually why the governments don't manage who can buy and run a website online, that'd be terrible lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog no, I just care about improving the world and don't like the way governments manage the internet for their own interests smh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog internal politics and people management are almost as important as the technical skills in most, if not all roles tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I genuinely can't view this because reddit is a garbage platform not built for humans anymore, and they block my browser and network, and block people without an account in a lot of cases now, but I'm sure whatever this was it's damning lmao npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog Very VERY much agree with all of this, Gargron and his control over the mastodon server codebase itself creates these problems sometimes (as do the other popular implementations and their devs), rejecting social discovery because they personally don't like it is absolutely no way to run a community project used by millions of people Definitely think social discovery and search should just be implemented, ignore those people honestly, their concerns have been considered and discussed and I personally believe they are probably way overblown compared to the benefits of actually improving the software, network, and discoverability of the fediverse in general, especially for new users. This isn't to say that it's not important to consider the negative aspects of any change on the fediverse, it's absolutely critical to consider the impact of these things, but the reality is that we're just not implementing features because a small handful of people don't want them... not because it would be a huge issue for the fediverse itself tbh As you said, I absolutely agree that there are some fair points against implementing this, but we need to face reality here and realize that the harmful actors don't care and have discoverability anyway, and everyone else suffers shitty UX without it. npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog not entirely surprising, considering the fediverse is a public network, and most servers don't have a robots.txt or similar which prevents scraping tbh I mean if they're pulling data from reddit and every other popular website, better believe their scrapers found the fediverse too npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I feel like the internet should be an independent national organization, independently regulated with its own rule of law and governance systems, letting national governments which are tied to specific populations and land areas control such an important shared global resource is misguided and morally/ethically wrong tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the Irish DPC being basically useless on GDPR enforcement is a hot button issue in Europe right now, from what I understand the rest of the EU is essentially applying legal pressure and threatening penalties for non-enforcement so hopefully the Irish DPC gets much better in future npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog if I had to guess I'd assume it corresponds to defender team/department increases and funding increases I find the Mozilla data very interesting, it seems they're consistently ahead of attackers despite producing a browser, which is more-or-less hit with 0day exploits and many other unknown bugs regularly? I suppose it depends on the measurement methodology, since I guess if they patch those issues within mere hours of being told it counts as extremely good remediation? or maybe it's just a measurement of the "mozilla org" and their security rather than security of their products npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog is... is this real? I mean even just the branding here is awful from a PR perspective, wtf are they even doing... incredible npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog what company operators this scraper? where does the data go? how do you know it's actually related to AI and not some random bot? npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I think in pretty much every modern system UEFI is considered a security boundary, that's why vendors care about things like secure boot, particularly for virtual machine hosts or other high security applications the UEFI and boot chain security get really important super interesting exploit though, I'd definitely say it was either some UEFI bug or maybe a hypervisor bug that caused UEFI issues, especially because they mention bypassing the "secure kernel" which requires working UEFI security to establish at boot time npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog the way the old blocking `/dev/random` call worked, and the OLD linux kernel random number generator, yes it could go down LOL also at very early boot if you need CPRNG material you'd sometimes have to wait for entropy to increase first, especially on routers or servers with no external inputs, but the MODERN linux kernel has a better system which avoids this afaik npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog in short this is why an entropy graph is useless, thanks for coming to my TED talk :^) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog entropy doesn't "go bad", it will always reach a max buffer size after boot and initialization, and the entropy will probably stay full after that forever without being depleted even when doing crypto operations if it "goes down" it sort of also doesn't matter at all, you should definitely read the justification for Linux changing the `/dev/urandom` function to a varient of CPRNG with ChaCha20, Bernstein himself makes VERY good points about how entropy can't be deplete in practice when doing crypto anyway, along with an attack that occurs when constant re-seeding happens :) https://en.wikipedia.org/wiki/Dev/random#Critique_of_entropy_injection npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog me when I keep telling people all these alternative packaging methods are slower than the normal distro and full of outdated software society just ignoring me until it's a major problem again: 😃 npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yeah it's absolutely awful, there is literally no standard way to render this and nothing written down about what is supported or why, it's all just so gross and cursed... also everything has to be inline CSS it sucks so bad npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog email actually has NO standard for HTML, I had to do this professionally once, turns out that's just the set of tags people like gmail and yahoo maybe might support... and they're not even consistent between each other another fun fact: gmail supports a single type of flexbox element but nothing else npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog > In an order on Monday, US District Judge William Orrick denied key parts of motions to dismiss from Stability AI, Midjourney, Runway AI, and DeviantArt. The court will now allow artists to proceed with discovery on claims that AI image generators relying on Stable Diffusion violate both the Copyright Act and the Lanham Act, which protects artists from commercial misuse of their names and unique styles. https://arstechnica.com/tech-policy/2024/08/artists-claim-big-win-in-copyright-suit-fighting-ai-image-generators/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog ngl there are zombie bots with no C2 server still infecting XP systems online, I actually don't think windows 2000 would be ok lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this is why it rubs me the wrong way when people ignore my technical advice am I basically nobody? yes am I still offering sound and important advice that experts should listen to? also yes often when I'm ignored for long enough people begin realizing that despite my lack of status I know what the hell I'm saying still lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I feel that, my perspective here is weird, because I'm just personally capable of running something reliably for 10+ years if I want... I feel like normal people don't have that option lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this is true for all websites though, just depends on if you're using a fedi instance that intends to exist forever, or one made by a friend in their basement that will probably be gone in 6 months npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog oh yeah to be fair, modern complex JSON based apps probably suck at those speeds, a lot of my websites end up being static content with some images or maybe very basic dynamic data trying to do a modern "rich data" website with all the fancy animations and JS frameworks/APIs/etc would feel terrible I think lol npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog yeah, I feel that so much, modern websites are absolutely shit... for what it's worth I've been testing every website I build in mobile compatibility mode with a 2G internet speed since like 2016, I think it would genuinely make people much better programmers if they tried this every once in a while lol The pages I built were still snappy and loaded in 1-1.5s on 2G connections (mostly because it was just 90% HTML and CSS) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this is why I test all my programs and web pages on 2g/3g connection speeds before I release them... 2G internet fucking sucks but if some person in Africa (or Asia, or Australia lol) can't use the software I'm making then I probably built it wrong tbh npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog of course, I just genuinely appreciate the project, it's rare to find cool people who build cool tech that helps with world like this :blobowo: npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog this is VERY cool tech, shoutout to @npub1p09…m5vl for keeping the web (or should I say 'small web') alive with projects like Kitten, a simple and straightforward framework that gets out of your way and lets you build powerful impressive things for each other and the world https://kitten.small-web.org/ npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog At the risk of being dragged into a political argument for a passing comment, I do have to point out that perhaps the several other nations with the ability to use nukes, but the restraint to choose not to, are perhaps going to be fine... Besides I was mostly commenting on the idea that the USA alone ended up defeating nazi germany, historically that's not really the case, although they helped they weren't the cause of the loss (talk to your local history buff about why) npub1h6y7d9evl7yl836lzvcwsz0mf9hd8gm4k7p97yuw4c9nm4qm535snglzm0 CyberFrog I'm sure the rest of the entire planet and human race will figure it out, this reeks of US exceptionalism lol