Oof. Does this happen often?
Ulrich
- 5 Posts
- 830 Comments
The affected malicious packages are:
librewolf-fix-bin firefox-patch-bin zen-browser-patched-bin
So…did someone just like create a new package cloning these or did they somehow get into the “official” repository? Is there no attestation process?
Ulrich@feddit.orgto Technology@beehaw.org•Linux smashes through five per cent desktop share in the USEnglish9·2 days agoat least not very often
The people you’ve seen are likely enthusiasts. A small minority of the millions of users. The vast majority probably never leaves game mode.
Ulrich@feddit.orgto Technology@beehaw.org•Linux smashes through five per cent desktop share in the USEnglish6·2 days agodoes that mean we’ll need to start worrying about viruses on Linux now?
- Linux is still a very small marketshare on workstations.
- Pretty much every server runs Linux and is probably much more likely to be attacked than a workstation.
- Lots of very profitable companies that run these servers need high security, so they will invest as much as is strictly necessary.
- Everything is open source and auditable by anyone.
Ulrich@feddit.orgto Technology@beehaw.org•Linux smashes through five per cent desktop share in the USEnglish21·2 days agoThe stats come from webpages, something a Steam Deck is unlikely to ever see, or at least not very often, so I would say it has almost nothing to do with Steam Deck, other than maybe exposing more people to Linux.
Ulrich@feddit.orgto Linux@lemmy.ml•OS Backup - what should and what should not be backup'd?English1·2 days agoI usually just use SyncThing and sync the Home directory to another device.
Ulrich@feddit.orgto Technology@beehaw.org•3D Printing Patterns Might Make Ghost Guns More Traceable Than We Thought | 404 MediaEnglish7·3 days agoEach individual level of the print is called the print line
It’s called a layer.
“So on the firearm, I’m seeing from the trigger guard—maybe print line 200—and the top of the magazine well—print line 400—the marks are staying consistent,” Garrison said.
…I don’t even understand what that’s supposed to mean? “The marks are staying consistent”? What marks? Consistent with what?
Even if they were able to match a print to a nozzle (which they won’t be because it’s a wear item that’s constantly changing), nozzles are cheap and replaced often. You replace them in 2 minutes.
However, none of this will stop DAs from trying to use this shit as evidence, just like all the other junk science they pay people to lie about.
Ulrich@feddit.orgto Gaming@beehaw.org•Valve gets pressured by payment processors with a new rule for game devs and various adult games removedEnglish21·3 days agoGov can’t really do anything about it. Bitcoin was designed to be gov agnostic. They can tell you it’s illegal but there’s also really no way for them to know (if you’re not dumb).
Hell there are entire unregulated black markets on the dark web.
Also with the orangutan in chief being something of a crypto grifter himself, it’s not likely to be regulated at all.
Use Nextcloud and KDEConnect (or similar) and forget about iCloud.
Ulrich@feddit.orgto Technology@beehaw.org•Host Your Own Bluesky PDS: A Complete Azure-Powered GuideEnglish11·4 days agoThen you’re just going to be at the mercy of the people that do run these things
I wasn’t asking for a way around them, I’m asking why they exist and suggesting we collectively move on from them.
I realize maybe my response was taken as disagreement
I didn’t take it as a disgreement, I took it as a dismissal. Rather than discussing why it’s necessary or whether it should be removed, you suggest that I create my own alternative.
As a product owner I’d want a way to contact
You can. We’ve already been over this. Send them a message on the platform.
or validate a user
How is an email address validation? I can spin one up in 3 seconds.
Self service password reset
You’re just creating a security vulnerability.
I’m not trying to defend email, just curious what mechanism could take its place.
Again, I already explained this.
Some platforms only require a username and a passkey (not even a password). That is ideal, in my opinion.
Email is also used to track user activity across the web, and while you know whether or not you will be tracking, collecting, and selling my activity, I don’t. Removing email eliminates that concern.
Some sort of cryptographic signature might work
That’s called a Passkey.
though I would have to think carefully about no separate communication/ confirmation channel
Again I ask, why? What is this fixation on multiple communication methods? Maybe as the user I don’t want you to have other ways of contacting me?
If you really need it there are hundreds of alternatives.
Ulrich@feddit.orgto Technology@beehaw.org•Host Your Own Bluesky PDS: A Complete Azure-Powered GuideEnglish11·4 days agoIt’s all of the above at once. It’s hard to think of another identifier that hits them all.
I already gave you one. The username.
It’s not a communication method outside of the platform it’s on.
Why is that necessary?
It looks like your complaint is as a user, not the service owner?
My complaint, as someone who hosts a variety of services, is that setting up an email server is ridiculously complicated, costs money, and is completely unnecessary.
Recently Ghost updated their software to add 2FA for email. Not TOTP or Passkeys, or anything actually secure, those are still unavailable. After updating I was completely locked out of my own account because it was trying to verify my login using a system that doesn’t exist on my install. It was a super annoying and completely unnecessary problem I had to deal with.
I wouldn’t run a project like that, but feel free to start one up.
Great, I’ll just go ahead and fork every open source project in existence on my own to remove this feature using the software engineering degree and the time I don’t have.
Ulrich@feddit.orgto Technology@beehaw.org•Host Your Own Bluesky PDS: A Complete Azure-Powered GuideEnglish33·4 days agoIt’s a communication tool
So is BlueSky
It’s a unique identity
As is 4093rnbgv3q09vn032. Everyone already needs a unique identity. It’s called a username.
You can have more than one
More than one what? Email? How about zero?
It’s platform agnostic
There are a thousand platform-agnostic communication methods.
It’s anonymous
Email? LOL absolutely not.
It’s transferable
It’s only transferable if you use your own domain, which the vast majority are not doing.
What would you propose instead?
That depends on the purpose. You can receive messages and notifications right in the app, so for the purposes of communication I would propose absolutely nothing.
Ulrich@feddit.orgto Technology@beehaw.org•Host Your Own Bluesky PDS: A Complete Azure-Powered GuideEnglish4·4 days agoWhy the fuck are so many software projects dependent on email? Why do we need this!? It’s infuriating.
Because there is choice. There is very little choice on Windows or Mac, so there’s not really anything to argue about 😅 Champagne problems, if ya ask me.
Yes, you can download videos.
Ulrich@feddit.orgto Android@lemdro.id•Google confirms it's 'combining' Chrome OS and Android into a single platformEnglish3·5 days agoI think this is precisely why they added Linux support to Android.
Ulrich@feddit.orgto Android@lemdro.id•Google confirms it's 'combining' Chrome OS and Android into a single platformEnglish1·5 days agoAs far as I know, Chrome OS is proprietary
It’s only proprietary in much the same way as Android. That’s why there are forks like FydeOS.
They also started cramming videos in other languages with these absolutely trash quality dubs into my recommendations.
Not what I asked.