Tootfinder

Opt-in global Mastodon full text search. Join the index!

@toxi@mastodon.thi.ng
2026-08-12 13:10:24

Mariensprung (2021)
A 160 meter tall waterfall emerging straight out of the rock below the Waxenstein, and a tributary to the Hammersbach in the Höllental (Hell's Valley).
#WaterfallWednesday #Video #POV

Short video panorama following the flow of a waterfall emerging from the rocks above and flowing into a mountain creek
@chrysn@chaos.social
2026-09-09 23:11:56

I've been waiting for more powerful const generics in #RustLang for since 2020 (blog post at <christian.amsuess.com/blog/web>). Se…

@fanf@mendeddrum.org
2026-07-13 15:42:14

the non-news of the solstice is that, surprising no-one, there will not be a leap second at the new year
the difference between UT1 and UTC remains very close to zero and the earth is rotating at very close to 24h per day
BUT LOOK
since i previously posted these charts in march, the length-of-day line (green) has popped upwards

chart of length of day (in green, microseconds difference from 24 hours, averaged over 10 months) and UT1-UTC (in purple, milliseconds) since the start of 2006, showing the green line initially around 900us then around 2019-2021 shifting to arouns 0us; the purple line starts off as a sawtooth (due to leap seconds) then flattens out
@ruario@vivaldi.net
2026-08-12 10:25:34

@… Ok, I know the bug and we fixed it within 24 hours, so you probably did not need to do any of that FWIW. 😉
Also, just so you are aware /opt/vivaldi/update-widevine has not existed since 2021, so your rm command would not have done anything to that.
Also If you ever want to disable the update-ffmpeg from being called on startup for some reason (like this) just …

@fanf@mendeddrum.org
2026-07-24 17:42:02

from my link log —
SUNSPOT: an implant in the SolarWinds Orion build process.
crowdstrike.com/blog/sunspot-m
saved 2021-01-12

@arXiv_csCR_bot@mastoxiv.page
2026-07-24 07:55:47

Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study
Shanna M. Kahn, John D. Hastings
arxiv.org/abs/2607.20713 arxiv.org/pdf/2607.20713 arxiv.org/html/2607.20713
arXiv:2607.20713v1 Announce Type: new
Abstract: LLM-based coding tools enable non-expert users to generate routine automation scripts that may enter enterprise workflows without meaningful security review. This study examines that risk directly. Code was collected from ChatGPT, Microsoft Copilot, and Google Gemini using identical prompts across three automation domains. Claude Code performed a standardized vulnerability review. Each identified vulnerability was scored using CVSS v3.1 and mapped to the OWASP Top 10:2021 and the MITRE ATT&amp;CK frameworks. Every script contained exploitable vulnerabilities. Nine of the 17 identified vulnerability classes appeared in code from all three models, while 14 of the 17 vulnerability classes appeared in at least two models. The weighted CVSS scores across platforms differed by less than 10%. The risk is not tied to any particular model but rather to the task category. Organizations should therefore ask not which tool to trust, but instead whether LLM-generated automation code should be deployed without review.
toXiv_bot_toot

@luana@wetdry.world
2026-07-23 13:51:26

Queria que o IBGE atualizasse logo a coisinha dos nomes do censo de 2010 pro de 2021...
2010 foi hš muito tempo, os resultados com certeza jš são totalmente diferentes