Guy
mastodon 4.7.2Geek, computer scientist, engineer, cryptography enthusiast, freediver (scuba sometimes, too), baseball nut, father, husband, odd ball, book reader, traveller, scout leader/kaiārahi, fermenter, free/open source/FLOSS geared, (self-) sovereignty promoting, anti Big Tech (TM), ...
Aotearoa/New Zealand 🇳🇿 with German 🇩🇪🇪🇺 origin.
RE: @heiseonlineenglish@social.heise.de
Good Switzerland is doing something against US Big Tech dominance and the CLOUD act risk. In this case to protect health data.
Aotearoa, please do so as well!
More reasons to ditch US Big Tech:
This is highly worrying from a cyber point of view: President Trump's Cyber Strategy for America
> This is highly worrying from a cyber point of view: President Trump's Cyber Strategy for America
https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf
>
> This document reframes cyberspace as a US-dominated military domain. It calls for offensive operations as a standard policy instrument. It boasts openly about destroying foreign critical infrastructure. Not only that, it also pledges to impose American “norms” on the global internet.
>
> It calls for deregulation at the very moment when any serious security expert agrees that regulation is essential for setting a baseline security bar.
>
> “Adversary” is not defined in this pamphlet, and any foreign organization may now fall easily inside the definition at any time. (akin to disabling all Microsoft infrastructures for the International Criminal Court, ICC, in 2025, or declaring Anthropic to be a “supply chain risk”).
>
> If the U.S. treats foreign technology as an adversarial risk, how can any government or organization trust U.S. technology any longer?
>
> This is the foundational strategic question now: how long are we willing to build our IT infrastructures on systems that another power, governed by executive orders, has declared to be part of their military arsenal?
#murica #trump #BigTech #sovereignty #cybersecurity #CloudExit
@foone If you're in the EU, or particularly a German speaking country, you could order your own 'Lichtbildausweis' for EUR 15 (with self-chosen information to be put onto it).
https://shop.digitalcourage.de/themen/ak-vorrat/lichtbildausweis-mit-selbst-waehlbaren-daten.html
Credits to @digitalcourage for providing the service!
Having said that: This service should not be needed!
Saying LLMs are good and have a useful side doesn't make them more ethical.
It's like saying Hitler had his positive sides for building the autobahns.
I'll be running a #freediving induction course (pool, not depth) in May in #Auckland. Dates are 4, 11 and 18 of May on Monday nights at Tepid Baths. Costs are $150 and that gives you a 3 months club membership (Auckland Freediving Club), including the induction course (3 weeks) with any subsequent training session at any of the Auckland training locations.
The induction includes some theory, freediving safety as well as static breath hold (just holding for a (longer) while) and dynamics (swimming (longer) distances under water). Usually after the Monday night training, we're hitting the pub for a bit of a social gathering (optional).
https://aucklandfreediving.co.nz/events/club-intro-membership-may-2026-tepid-baths/
Let me know if you're interested. There are currently 2 spots still available. As there was no induction in April, 8 are already taken up. So, don't delay ... ;-)
Also, feel free to share with others (if there's interest)
RE: @heiseonlineenglish@social.heise.de
Other countries (like ours) should do that too: Tax Big Tech!
Interesting to see all kinds of FUD on open source/copyleft licences emerging in (commercial/corporate) organisations over and over again.
I'm always feeling like that guy who spots someone on the Internet 'being wrong' when that happens. Just can't help myself.
Hmm, just ran a 'Spy Night' with the #scouts last night. It was a bit of a mixed bag. I'd put hours into preparing it, but it mostly fell apart when I tried to print out my work sheets last nights, and my home laser printer gave up. So I was 20 mins late, and I couldn't run through the plan with the other leaders to get the right knowledge for supporting the patrols on the different stations :-(
Running through it, I know now what needs to be changed to make it better, where I wasn't aware without a good 'dry run' that some things were a bit too complex.
Content wise, this was covered:
* Message transmission and encoding:
- Tap code
- Morse code
* symmetric ciphers:
- Pig Pen (Masonic) cipher
- Caesar cipher
- Rail Fence cipher
- Vignere cipher (didn't get to it, needs to be cut)
* steganography:
- Invisible ink (lemon juice)
- First letters of words in a paragraph
- A cut out mask over a (book) page
Had to re-install my Doom #Emacs setup. Unfortunately updating my `emacs-plus` install via Homebrew on the work Mac had resulted in a misbehaving editor :-(
But it was easy enough to re-build and secure the config items across, as it all follows the UNIX paradigm of configs being in files (as opposed to binary registries).
Biggest irk I'm having with the 'flavours' of Emacs these days is that they seem to have the feeling that the defaults should be on vim ('evil') style key bindings modes. Whyyyy?!?!?!?!?
Making a season's (likely) last feijoa and apple crumble. Making feijoa fizz has worked a treat so far. Trying a feijoa and apple fizz now from both peels.
RE: @glynmoody@mastodon.social
Better have multiple archiver bots hit my server than a swarm of AI harvester bots.
One delivers value and is ethical, the latter isn't.
Edge is the only Chromium‑based browser I’ve tested that behaves this way. By contrast, Chrome uses a design that makes it far harder for attackers to extract saved passwords by simply reading process memory. It decrypts credentials only when needed, instead of keeping all passwords in memory at all times. App‑Bound Encryption (ABE) adds another layer by binding decryption to an authenticated Chrome process, preventing other processes from reusing Chrome’s encryption keys. Because of these controls, plaintext passwords appear only briefly during autofill or when the user views them, making broad memory scraping far less effective.
The risk of keeping the passwords in cleartext in memory becomes evident in shared environments. If an attacker gains administrative access on a terminal server, they can access the memory of all logged‑on user processes. In the video the attacker has compromised a user account with administrative rights and is able to view stored credentials for two other logged on (or even disconnected) users with Edge running.
I reported this to Microsoft, and the official response was that the behavior is "by design". They have been informed that I would be sharing this as a responsible disclosure so users and organizations can make informed decisions about how they manage credentials.
(from the pen-tester/finder of this issue)
RE: @heiseonlineenglish@social.heise.de
How dense is that? Poor connectivity, increase in night sky light pollution, more space junk, increase in Kessler Syndrome, problem with energy supply, problems with cooling (radiation only, no efficient convective cooling) green house gas producing aluminium ablation in the upper atmosphere due to burning up satellites and launch vehicle parts. There's likely more.
To me, this is purely a land grab, but defies any common sense.
I love baseball movies. On the weekend, I've watched one I didn't know, yet: Eephus.
What a weird movie!!!
I'd say it scores 100% on atmosphere/mood as well as character variety in the actors. But it would likely score more like 0-10% on plot or 'suspense curve'.
I've really liked it in a way, but would not recommend it. Unless you like quirky character studies like those of the French director/actor Jacques Tati. And you *must* love baseball with all its quirks and idiosyncrasies, especially recreational baseball ('beer ball').
And, I've learnt about a new/different pitch, the 'eephus': https://en.wikipedia.org/wiki/Eephus_pitch
Embedding a Mastodon feed into a #Wordpress web site:
Web search resulted in many options, but I don't know which would be a most suitable for my needs.
I would like to integrate a block/widget into a Wordpress site that can pick up a particular Mastodon account feed of posts to embed in the web site. What would be a suitable approach for this?
I believe there was quite some discussion around Mastodon/Wordpress integration last year or so, but I've only now have had a use case for trying to put this into use.
Any tips/hints?