Tootfinder

Opt-in global Mastodon full text search. Join the index!

@kubikpixel@chaos.social
2026-02-18 18:15:03

Carelessness versus craftsmanship in cryptography
Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. […] The aes-js/pyaes maintainer, on the other hand, has taken a more… cavalier approach.
🔓

@migueldeicaza@mastodon.social
2026-02-18 21:26:00

This was glorious, and it is now implemented in SwiftTerm by default.
While it is true that certain users in a dorm at Darmouth or MIT might carry with them the script to tune their color palette, I believe that users in the wild deserve to keep their retinas.
gist.github.com/jake-ste…

@matthiasott@mastodon.social
2026-04-18 10:39:52

“Brevity was always a discipline. Now it’s a statement. When everything around you is excessive by default, choosing fewer words takes courage. It says: I thought about this. I edited. I respected your time more than I needed to show my work.”
Wise words from @… 💙

@hanno@mastodon.social
2026-02-18 06:26:20

If you manage your code on Github, you might expect that you get an email notification if someone opens an issue for your code. But it appears that's no longer true for new repos.
The "Watch" settings are now, by default, "Participating and Mentions". That means unless someone tags your Github username in the issue report, you won't know about it. Yeah, even if it's your own repo in your own namespace. No, I don't know what they were thinking at Githu…

@oligneisti@social.linux.pizza
2026-04-18 12:06:45

Last year my friend died. It was a rather public affair since he was much loved by people in the media and arts. Still, six months later people on Facebook sent him birthday wishes oblivious to the fact that he had died.
Last month another friend of mine died. It has been a much more private affair. His birthday is coming up later this month and I am dreading seeing people using Facebook's default emojis to wish him well.
If you are so out of touch with someone that they migh…

@publicvoit@graz.social
2026-04-15 13:42:58

#WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer #Fraud
cybersecuritynews.com…

@fanf@mendeddrum.org
2026-02-14 21:42:02

from my link log —
Same-site cookies by default.
textslashplain.com/2019/09/30/
saved 2019-10-02

@metacurity@infosec.exchange
2026-02-09 16:22:42

As a "safety measure," Discord will require a face scan or ID starting next month.
discord.com/press-releases/dis

@adulau@infosec.exchange
2026-04-11 19:39:11

Excited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.
F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.
A great step forward for the MISP community and for teams tracking financial fraud.
🔗

xcited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.

F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.

A great step forward for the MISP community and for teams tracking financial fraud.
xcited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.

F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.

A great step forward for the MISP community and for teams tracking financial fraud.
@cellfourteen@social.petertoushkov.eu
2026-03-16 10:40:06

That ominous "if" at the end tells me only that even the Linux community doesn't know why these files were taken down. I could make a breakthrough in my YouTube puddle if I spin up some clickbait video right now 😀

New Proton-CachyOS version for testing https://nightly.link/CachyOS/proton-cachyos/actions/runs/23121894868

https://nightly.link/CachyOS/proton-cachyos/actions/runs/23121894868/proton-cachyos-10.0-20260312-base-175-g8be3eec4-x86_64.tar.xz.zip

   
Updated to the most recent Proton Experimental release 10.0-20260312.
Enabled wine-nvml by default for Nvidia GPUs at the request of its developer in order to get wider testing for it. It can still be disabled with PROTON_NVIDIA_NVML=0 if needed.
nts…
@johnm@social.tchncs.de
2026-02-10 08:00:40

#Discord Launches Teen-by-Default Settings Globally
discord.com/press-releases/dis

@publicvoit@graz.social
2026-04-13 06:08:30

#WhatsApp’s ‘End-to-End #Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov
c…

@Techmeme@techhub.social
2026-02-09 14:11:51

Discord plans to roll out age verification globally starting in March to access some content; all accounts will have a "teen-appropriate experience by default" (Stevie Bonifield/The Verge)
theverge.com/tech/875309/disco

@primonatura@mstdn.social
2026-03-27 20:00:55

"‘Greener By Default’ Hospitals Reduced Food Emissions By 22% With Plant-Based Meals"
#Food #Hospitals #Emissions

@AimeeMaroux@mastodon.social
2026-02-13 12:38:00
Content warning:

I quite like @… so far but one thing I found very annoying is that all AI features are turned on by default and I have to manually turn them all off. I understand that some people think a faulty summary is the shit but there are enough people who fucking hate it so having a way to turn

@floheinstein@chaos.social
2026-04-13 06:15:28

I should do some work with Authentik, but I keep getting sidetracked to find out where the default background for the SSO page is coming from
github.com/goauthentik/authent

Picture of the Icelandic Ringroad, taken from the center line, going straight to the center of the picture axisymmetrically. Partially covered by snow, same for the dried grass on both sides. Mountainrange from the right to the center, snow covered mountain on the left. Low standing sun outside the picture on the left
@axbom@axbom.me
2026-02-06 13:24:39

My message to Gaggle Mail:

I just want to let you know that I decided not to continue evaluating your service after I noticed that you have a setting to use ChatGPT from OpenAI turned on by default.

Among many other things, OpenAI is Trump's biggest donor and used by ICE.

It is one of the most morally corrupt companies in operation today and it was hugely disappointing to me to see a company that embraced the classic listserv platform (yay!) also integrating the w…

@jeang3nie@social.linux.pizza
2026-04-10 15:17:39

#Sunstone browser now has a searchable history. The period to display can be set to the last hour, day, week, a custom timeframe or 'all'. There is also an option to group the results by host. By default, 50 results are displayed per page.
This is a WIP and subject to change. This biggest miss so far is a link in the page to navigate beyond the first page of results, although y…

A screenshot of Sunstone browser with a tab displaying a history search
@fanf@mendeddrum.org
2026-04-05 20:42:02

from my link log —
Reducing Raspberry Pi 5's power consumption by 140x.
jeffgeerling.com/blog/2023/red
saved 2023-11-07

@almad@fosstodon.org
2026-04-07 23:05:24

The reason why I preferred OSS deps over reimplementation is that by default, author of a nontrivial library spent more time with a problem than me, and hence I trust their judgment more.
This is another default that LLM breaks…

@janneke@todon.nl
2026-02-02 07:01:36

Great talk by @… of #GNU #Hurd fame, in a packed room, selling the the Hurd really well (in my not entirely unbiased opinion, of course) and starting with
It'…

A slide on OS support (cont'd)

* Translator records in /dev and /servers
* Used to be a Hurd-specific ext2 extensions
* Now using xattrs by default
* Can now cross-install completely from Linux

* FS JBD2 journaling support (Milos Nikic)
* In progress

* Console xkb keyboard layout (Etienne Brateau)
A slide on Current state
* Rather stable
* Have not reinstalled boxes for a decade
  * Debian buildds keep building packages
* ~75% of Debian archive builds out of tree
* XFCE, gnome, KDE, ...
* Support merged upstream
* gcc, glibc, llvm, rust, ...
* Debian distribution
* Guix/Hurd released!
Slide on Dissemination

* News coverage
* Quarter of the Hurd (QotH) (Joshua Branson) 
* Guix/hurd (Manolis Ragkousis, Janneke Nieuwenhuizen, Yelninei) 
  * https://guix.gnu.org/blog/2024/hurd-on-thinkpad/
* Alpine (Sergey Bugaev) | z | |
 Slide: So, what do we have?

* x86_64 SMP
* SATA/USB disk/cd, all in userland
* netwokr driver & TCP/IP all in userland
* kernel only manages tasks, memory, IPC
* go, rust, ocaml, ghc, some java...
* Debian (~75% packages)
* Guix
* som Arch, some Alpine
* An the usual Hurd stuff: user-controlled translators, fine grain access control, sub-hurds.
@aral@mastodon.ar.al
2026-03-02 19:03:15

🥳 New Kitten release
Several but fixes, thanks to wunter8 (codeberg.org/wunter8):
• Default socket doesn't work when testing with a local mobile device (

@michabbb@social.vivaldi.net
2026-03-01 06:40:25

🖥️ Less relevant for server environments using SSH keys – primarily affects desktop users
heise.de/en/news/sudo-rs-shows

@Techmeme@techhub.social
2026-03-10 10:05:51

A look at the top 100 GenAI consumer apps: ChatGPT leads but the race for the "default AI" is on, global usage is splintering by product, and AI agents arrive (Olivia Moore/Andreessen Horowitz)
a16z.com/100-gen-ai-apps-6/

@rasterweb@mastodon.social
2026-02-24 11:40:21

This might be a useful Obsidian tip. I tried Obsidian (again!) last year but I just couldn’t walk away from Bear because it’s so good. (Bear is macOS only but they did add web access last year.)
“I discovered Obsidian's core plugin "File recovery". Enabled by default, it saves the state of your files every five minutes and keeps that history for a whole week!”

@theodric@social.linux.pizza
2026-03-05 21:36:41

Just in case anyone was hoping GrapheneOS would support face unlock, even as an option disabled by default, even for the Google Pixel devices with busted-by-design fingerprint sensors: lol keep fuckin' dreaming, noob. Much like Linux in 2026, GrapheneOS isn't about choice. It's about you quietly falling in line and adjusting your expectations, you ungrateful fuckhead leach deserving of mockery and derision and the questioning of your virility and political alignment.

@piger@mastodon.social
2026-02-11 13:00:42

still not sold on having to rely on new protocols (gemini) or very old protocols (gopher) instead of making a wiser use of the ones used at large (http). When the solution is to add more software I’m skeptical by default

@Sustainable2050@mastodon.energy
2026-03-02 21:03:43

Disappointing growth in EU biomethane production, growing by 'only' 12% from 'gas year' (Oct-Sep) 2023/24 to 2024/2025.
5 years to go to the REpowerEU target of 350 TWh; that would now require a 52% compound annual growth rate.
Tall order, but today's news shows how important it is to accelerate!

Screenshot of table on page 6 of https://www.entsog.eu/sites/default/files/2026-02/ENTSOG%20Report%20on%20Annual%20Renewable%20Gas%20Injections%20into%20Gas%20Networks%202026.pdf
@fell@ma.fellr.net
2026-02-06 11:39:24

I have set up my Thunderbird to use plain text and "interleaved, quote under" style, which is also the recommendation of the Linux Kernel mailing list. By default, it doesn't quote at all. I'm sick of throwing huge chunks of HTML back and forth where any long conversation grows into a formatting mess.
#Email

@samvarma@fosstodon.org
2026-02-09 00:22:43

Apple is losing the normals. At a superb owl gathering and everyone (all generations) is complaining about #iOS updates changing everything, and a specific example is enabling crossfade in Music by default.
Decision has been made not to update grandma's iPad going forward because that would render it effectively useless from her point of view. Have heard same complaint from my mother: &quot…

@grahamperrin@bsd.cafe
2026-03-07 03:15:28

@… not rw by default in single user mode.
I usually:
mount -uw /
(I can't remember where I learnt that variant. Lost in the mists of time.)
@…

@thomasfuchs@hachyderm.io
2026-01-30 13:57:35

To be entirely fair, macOS and Windows are going down such clownchute that it is possible that they just won't work for people at all anymore, so it could be that Linux gets popular by default.

@jtk@infosec.exchange
2026-03-05 15:10:36

Zenlayer (#AS4229 and others):
"[...] new pricing policy for public IPv4 addresses will take effect on March 31, 2026, reflecting rising IPv4 costs [...]"
"All compute products will no longer include complimentary public IPv4 addresses by default."
"Customers are strongly encouraged to accelerate IPv6 adoption to support a sustainable long-term network architecture."

@jackie@social.linux.pizza
2026-02-02 21:57:19

Instead of an "AI kill switch" like they promised, #Mozilla will provide "AI controls" buried deep in settings a #Firefox update which isn't out yet, until then the AI features which are already released and on by default can only be disabled by digging through about:co…

@unixviking@social.linux.pizza
2026-04-04 12:10:01

Easter test weekend, initial findings. 😎
:fedora: On Fedora 44 Beta GNOME Edition, the file manager crashes every time I try to access my NAS. There are also frequent freezes with apps that weren’t included by default and were installed later.
:ubuntu: Ubuntu 26.04 LTS also comes with GNOME 50, and unlike Fedora, it already includes kernel 7.0, which is great—especially for the latest hardware. This beta also seems to run more smoothly and stably than Fedora’s beta.
Howev…

@tiotasram@kolektiva.social
2026-04-07 11:23:25

In the interests of starting a more productive dialogue than yesterday's main character was interested in, let's make a #brainstorm thread about design changes to ActivityPub and/or client UI that could actually help address drive-by (often racist) harassment on the fediverse.
Feel free to discuss pros/cons but don't feel an idea needs to be perfect to suggest it. Also since this is a brainstorm don't worry about complexity/implementation cost. If you have a great-but-hard-to-implement idea someone else may think of a way to simplify it.
Note that the underlying problem *is* a social one, do there won't be a technological fix! But tech changes can make social remedies easier/harder.
I've got some to start:
1. Have a "protected mode" that users can voluntarily turn on. Some servers might turn it on by default. In protected mode, users whose accounts are less than D days old and/or who have fewer than F followers can't reply to or DM you. F and D could have different values for same-sever vs. different-server accounts, and could be customized by each user. Obviously a dedicated harasser can get around this, but it ups the activation energy for block evasion and pile-ons a bit. Would be interesting to review moderation records to estimate how helpful this might or might not be. Could also have a setting to require "follows-from-my-server" although that might be too limiting on private servers. Restriction would be turned off for people you mention within that thread and could be set to unlimit anyone you've ever mentioned. Would this lock new users out of engagement entirely? If everyone had it on via a default, you'd have you post your own stuff until someone followed you (assuming F=1). One could add "R non-moderated replies" and/or "F favorites" options to soften things; those experiencing more harassment could set higher limits. When muting/blocking/reporting someone who replied to your post, protected mode could be suggested with settings that would have filtered the post you're reporting.
2. Enable some form of public moderation info to be displayed when both moderator and local server opt-in. Obviously each server would be able to ignore federated public tags. I'm imagining "banned from X server for R reason (optional link to evidence)" appearing on someone's profile & an icon on their PFP in each post viewed by someone on server Y *if* the mods of server X decide it's appropriate *and* server Y opts in to displaying such tags from server X specifically. Alliances of servers with similar moderation preferences could then have moderation action on one server result in clear warning propagation to others without the other mods needing to decide whether to also take action immediately. In some cases different moderation preferences would mean you wouldn't take action yourself but would keep the notice up for your users to consider. Obviously the "Scarlet Letter" vibe ain't great, but in some cases it's deserved, and when there's disagreement between servers about that, mods on server Y could either disable a specific tag or disable federation of mod tags from that server in general. Even better shared moderation tools are of course possible.
3. Different people/groups have different norms around boosting. Currently we only have a locked/public binary. Without any big protocol changes, adding a "prefers boosts/doesn't" setting which would warn in the UI before a viewer chooses to boost if the preference is "doesn't" could help. This could be set per-post, but could also have defaults and could have different values for same-server or not, or for particular servers. For example, I could say "default to prefer boosts from users on my server but not from users on other servers" or "default to prefer boosting on all servers except mastodon.social." Last option might be harder to implement I guess.
#ActivityPub #Meta #Harassment

@chrysn@chaos.social
2026-03-25 12:54:13

Funny how people, in light of the LiteLLM compromise, jump to the conclusion that the solution is to make your supply chain even more intransparent by vendoring in dependencies through an LLM's processing, rather than just using pinned and vetted dependencies by default over tools' defaults "yolo there has been an update and it claims to be semver compatible" attitude.

@kurt@nelson.fun
2026-04-02 17:03:45

I'm waiting for a lawsuit against Waymo to pop-up about yesterday's April Fools easter egg. You should not make jokes about microphones when the T&Cs specifically say they are not on by default.

@lightweight@mastodon.nzoss.nz
2026-02-21 22:55:01

Amendment: this is dodgy. Consider this retracted.
Wow, if true this is big: Lenovo says they're losing money on every computer pre-installed with MS Windows 11 due to it comprehensively sucking. They are apparently moving to Ubuntu Linux installed by default. Windows will only be an extra-cost option... youtube.com/…

@axbom@axbom.me
2026-02-06 12:11:37

I almost signed up for Gaggle Mail even though it's US-based. I figured at least they seem to have good sense in seeing the value of email for discussion groups. And then while trialing I saw they have a function to summarise email discussions via ChatGPT that is *turned on by default*. I mean, wtaf.

So I'm deciding on self-hosting Mailman. It always seems to come back to self-hosting in the end, doesn't it... which is not nearly easy enough for most people to grapple with.

@aredridel@kolektiva.social
2026-03-26 14:03:02

RE: social.coop/@cwebber/116295745
100% this. But also sometimes it's okay. That's the weirdest part.
And we are not yet fully ready to make those decisions. It's gonna be messy as hell, and we need to choose better than a lot of us do by default.

@stsquad@mastodon.org.uk
2026-01-31 13:03:44

I thought I'd killed my trusty #turrisomnia but it turned out my tinkering had left it and the recovery partition in a very old broken state. Fortunately after failing with a cheapo usb key I did get a more recent factory image on it. I now realise quite how fast back the system was because everything is dark mode by default now with a nice onboarding process.

@frankel@mastodon.top
2026-03-26 09:06:56

Semantic Conventions for #GenAI agent and framework #spans
opentelemetry.io/docs/specs/se

@yaxu@post.lurk.org
2026-01-23 13:50:12

My top debian-derived linux tip is to uncomment the bash completion bits in /etc/bash.bashrc
It enables tab completion for a bunch of commandline stuff that saves loads of time
No idea why this isn't enabled by default. Setting up a new linux mint install for me these days is basically just doing that and mapping caps lock to ctrl.

@qbi@freie-re.de
2026-02-19 07:29:44

Reuse,
gut für die Fischerei
schlecht in der Kryptografie
blog.trailofbits.com/2026/02/1

Microsoft provided the FBI with the recovery keys to unlock encrypted data on the hard drives of three laptops as part of a federal investigation, Forbes reported on Friday.
Many modern Windows computers rely on full-disk encryption, called #BitLocker, which is enabled by default.
This type of technology should prevent anyone except the device owner from accessing the data if the computer is …

@vyskocilm@witter.cz
2026-03-30 15:43:56

TIL: Incremental selection is available by default in Nvim 0.12, see `:help v_in`.
#neovim

@fanf@mendeddrum.org
2026-03-08 21:42:02

from my link log —
Understanding systemd-resolved, split DNS, and VPN configuration.
blogs.gnome.org/mcatanzaro/202
saved 2020-1…

@scott@carfree.city
2026-03-19 05:51:29

So SF public school teachers had to go on strike and it was considered a historic win when their strike resulted in 5% raises, but SF cops just waltz in and get a 14% raise by default.
The cops are robbing our city blind. Stop voting for pro-cop "moderates" who enable this!

@Mediagazer@mstdn.social
2026-03-19 15:10:51

Adobe launches Firefly Custom Models in public beta, letting users train AI image generators on their own assets; the custom models are private by default (Jess Weatherbed/The Verge)
theverge.com/tech/897243/adobe

@jtk@infosec.exchange
2026-03-27 18:00:29

Ubuntu will be adopting ntpd-rs as the default time sync client/server if all goes according to plan for release 27.04 (~2027). For most this means replacing chrony.
discourse.ubuntu.com/t/ntpd-rs

@hacksilon@infosec.exchange
2026-01-22 21:14:57

Seems like this could be useful for some #Selfhosted / #HomeLab folks. m.vinduv.app/@VinDuv/115940541

@Demirramon@cyberfurz.social
2026-01-24 20:29:38

Are you kidding me. I couldn't make Decky Loader work no matter what and I just learned that Syncthing overrides the port it uses by default 💀

@samvarma@fosstodon.org
2026-02-03 23:27:39

So I am now at 10% battery, with the machine connected to the power adapter… I wonder what happens when it gets to 0, but is still connected. Losing a percentage point every few minutes at this stage.
Almost seems like it uses the battery by default, and the power going in only goes to charging the battery, not actually running the machine?
And what would happen if I set topaz to do upscaling overnight?

@tiotasram@kolektiva.social
2026-01-30 03:56:02

Just finished "If You'll Have Me" by Eunnie. A wonderful and very sweet sapphic romance graphic novel. I love the fact that it's set in a world where gay is the unremarkable default (there's a subtle token hetero couple that appear on a single page, IIRC).
#AmReading #ReadingNow

@michabbb@social.vivaldi.net
2026-04-02 08:28:09

🤖 AI-native #CMS: built-in #MCP server, CLI & Agent Skills — let agents handle migrations, schema changes and content updates programmatically.
🔑 Passkey auth by default — no passwords, no brute-force vectors. Role-based access for admins, editors,
authors & contributors.
📦 Im…

@stargazer@woof.tech
2026-04-01 15:07:16

#games #kek

A comment from Youtube by redblack9618, concerning the attached video with the new male player model for Satisfactory:

"Look, facts don't care about your feelings. Science tells us that 1: life begins at conception, 2: all fetuses begin female and differentiate later in development, and 3: you can't change your biological sex, and therefore the default is being a WOMAN. Get this woke "male model" nonsense out of my video games, I hate when you shove politics down out throats!"
@jeang3nie@social.linux.pizza
2026-03-26 03:49:36

#Sunstone browser now has a start page, with default search provided by DuckDuckGo. All of Sunstone's internal pages are going to be linked through the menu bar provided in the default page template. I am no web designer, but I've taken time to make the design responsive and hopefully nice and cleanly functional. Shrink the page down past a certain level and the sidebar becomes a top…

A browser window with vertical tabs displaying the browser's "start" page.
A browser window with vertical tabs displaying the browser's "start" page in a wider format, where the top menu is now a sidebar.
@frankel@mastodon.top
2026-01-20 09:12:37

I Love You, #Redis, But I’m Leaving You for #SolidQueue
simplethread.com/redis-solidqu

@stsquad@mastodon.org.uk
2026-03-25 14:53:45

I find it perplexing that after 5 and a bit years of Trump in the Whitehouse that the media don't treat anything he says as a lie by default until and unless they corroborate the details via other less tainted sources. His pronouncements seem less about manifesting the result he wants and more about manipulating the markets to grow his own wealth.

@Techmeme@techhub.social
2026-03-19 13:30:44

Adobe launches Firefly Custom Models in public beta, letting users train AI image generators on their own assets; the custom models are private by default (Jess Weatherbed/The Verge)
theverge.com/tech/897243/adobe

@michabbb@social.vivaldi.net
2026-03-01 06:40:23

#sudo-rs breaks with 46 years of #Unix tradition: The #Rust-based sudo replacement now shows password asterisks *** by default

@pre@boing.world
2026-02-02 22:48:39

The AI features are "Optional by default" which is a mad thing to say. What?
If you want to turn them off then just flip the "off" switch to the "on" position 😆
youtube.com/watch?v=iD4LspntEmI

@gyp_vokag@social.linux.pizza
2026-04-02 07:10:11

Defaults at AtSite will shape place. Scope the world to fit the moment. Rate-limit week by default.