Hailey
woof! I am a computer tinkerer, polyglot hacker, music enjoyer, and bike rider. Also a huge nerd. Trans and queer 🏳️⚧️ 🏳️🌈 pfp by https://bsky.app/profile/jankapnoc.bsky.social
watching the whole industry jonestown itself is the craziest thing I have ever seen in my career
every time I read someone talking about their "AI adoption journey" I mentally gsub Claude with methamphetamine and the whole text still makes sense
How funny is it that the guy who wrote a book about the god delusion now has chatbot delusion
The latest (yes another) Linux kernel LPE also relies on an exotic socket type, AF_NETLINK. If you lock down allowed socket types to just internet+unix, you are safe.
Unfortunately even rootless podman relies on AF_NETLINK sockets via pasta (user mode networking), so it's trickier if you're using containers. Good time to reconsider if you really need all the extra complexity containers bring.
hello I am back I broke my instance's federation in a way where I could post stuff out but not receive anything back! I only clocked it when I was like hmm it seems quiet around here
It's small fry in the grand scheme of complaints about GitHub but I really dislike how the compare view has been pushed aside in favour of the new pull request view (which is the compare view with ?expand=true). It's very telling of where the focus has shifted and is yet another nudge in the wrong direction
bringing this toot back to say that if you have `RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6` in your systemd service (as distros have already been rolling out in services they ship), you're safe from someone chaining an RCE in one of your network services through to today's kernel LPE vuln
so like what's the story with the copyfail patch on debian? My trixie machine is still vulnerable and there are no updates available