2026-07-29 13:03:57
Dislike.
“Media Library infinite scrolling is now enabled by default, with a per-user opt-out”
https://make.wordpress.org/core/2026/07/23/media-library-infinite-scrolling-is-now-enabled-by-default-with-a-per-…
Dislike.
“Media Library infinite scrolling is now enabled by default, with a per-user opt-out”
https://make.wordpress.org/core/2026/07/23/media-library-infinite-scrolling-is-now-enabled-by-default-with-a-per-…
That feeling when your renderer can handle a component that outputs HTML inside link text in Markdown that’s embedded in HTML.
(Yes, I’m bragging.)
#Kitten #SmallWeb #SmallTech
""Starting with Red Hat Enterprise Linux (#RHEL) 10.2, #Firefox and #Thunderbird are delivered as Flatpaks by default. If you install RHEL with a graphical desktop, your browser and email client will now come from the
A product on Amazon was $25 cheaper than the same product at the manufacturer site. But between a coupon code and lack of sales tax, I paid ~$4 less through manufacturer site.
It may get fulfilled by Amazon anyway, but I continue to refuse to treat Amazon as default (when no local retailer has it).
Requiring DNSSEC adoption to signal that an http connection is supported, feels absurd? Like, it's not the sort of suggestion that someone with real world network experience would think was plausible.
https://blog.apnic.net/2026/07/27/secu
PEP 832 – Virtual environment discovery
#python
Ah, finally, what we’ve been asking for for years: a browser setting (ideally, mandated by law to be on by default – that’s how it should be implemented to have the most effect) that sends a proper “do not track” signal that’s not a request but a legal obligation.
If this passes, and in the form described above, I do hope it also gets enforced (unlike, say, the half-arsed enforcement of GDPR). @…
Based on the linked research by Charlie Marsh, here's setup-cached-uv 2.6.0 that doesn't run `uv cache prune --ci` by default anymore: https://github.com/hynek/setup-cached-uv/releases/tag/v2.6.0
@… @… If it actually worked, how stupid would the engineers building LLMs have to be, not to just put that in the context by default.
- Formal code of doctrine and discipline
This is just "what your objectives are." It can be as simple as ULC's "Do That Which is Right" or it can be much more complicated. You would figure that out with your group.
Personally, I would choose something like, "make life as easy as possible for caretakers." I've talked about this in the past. If you focus on care taking then you are feminist by default, you help everyone *at least once*, almost everyone twice, and most people 3 or 4 times:
- Children with supported caretakers do better
- Elderly people with supported caretakers will have a better quality of life
- Parents always need help and will do better when they have it, and the more kids the more support they need
But hey, I'm not here to tell you what to do. You can figure your own things out. (Technically, that last sentence could also be a legitimate formal code or doctrine, so we can move on.)
🔗 Document links make view('orders.index') and route('https://orders.show') clickable, and the same index backs go-to definition, which is enabled by default.
🔧 composer global require laravel/lsp
Requires PHP 8.2 , ships prebuilt binaries for macOS, Linux (arm64/x64) and Windows x64.
I don't think I actually *use* these key bindings, myself, but this kind of user-empowered thinking is a good illustration of why I've settled on Vivaldi as my daily driver browser.
It's the *least unlike* a User Agent, as we've come to expect, IMO. https://social.vivaldi.net/@jon/116818
The UK government proposes a default overnight social media curfew for 16- and 17-year-olds and disabling features like auto-play and infinite scroll by default (Muvija M/Reuters)
https://www.reuters.com/technology/uk-plans-default…
Lately I've been thinking about how #Gentoo is perceived by people. So often they're stuck in the "ricer" mindset: Gentoo is being built from source, so it must be ZOMG fast. And if it isn't, then what's the point?
If I were to make four points for Gentoo (to stop myself from making more), they would be:
1. Gentoo is independent.
There is no company behind Gentoo. There is no business plan. It's made and maintained by volunteers. Driven by passion and not profit incentive. And we want to keep it that way.
2. Gentoo aims to be secure.
We are maintaining our own infrastructure to reduce the risk of being hijacked. We're securing our distribution channels and mirrors using OpenPGP. We're only using Codeberg (which we really appreciate) and GitHub as mirrors (with OpenPGP commit signatures) and contribution channels. We have a dedicated security team, who works with the developers to keep packages free of vulnerabilities and our users informed.
3. Gentoo is made by humans.
We banned LLM contributions two years ago, and never regretted it. We didn't "wait and see", we took decisive action, and if we got left behind, it's only for the better. Unfortunately, in today's LLM-ridden world we can't stop slop software from being packaged in Gentoo without sacrificing our commitment to keep packages up to date, but we try to keep the worst offenders (like copywashed chardet) at bay.
4. Gentoo supports sustainability.
This may sound ironic when so many of us build everything from source, but we're actually trying to make computing sustainable. Gentoo's source-first nature makes it inherently flexible. We try our best to support a plethora of older and less common hardware. We go against the flow and still try to provide a workable system on hardware that is not supported by Rust or V8. And on top of that, we do our best to provide binary packages for a variety of configurations.
Of course, that's not all. I want Gentoo to be reliable and stable, to be oriented towards privacy by default, to be welcome and respectful.
And all these things ultimately depend on people working on Gentoo, and contributing to Gentoo. We always need more people that share these principles and want to help us achieve them.
What do you appreciate in Gentoo?
Huh. Microsoft has a feature called Controlled Folder Access that protects files from ransomware but it is off by default.
https://www.tweaktown.com/guides/11496/this-windows-security-feature-protect…
Why should people in the UK suffer from heat in their own home? Because a piece of paper says so. Let's change it.
https://petition.parliament.uk/petitions/770729
FTLOG...People... The #AI stuff in #WordPress is not installed by default...
It can only be activated by installing the 'AI' plugin and then a connector plugin for a platform (OpenAI, Gemini) to talk to it.
If you don't install the 'AI' plugin, nothing changes.
"B-b…
DuckDuckGo updates its browser for iOS, Windows, and macOS to block video ads by default, particularly those on YouTube, based on uBlockOrigin's filter lists (Anna Washenko/Engadget)
https://www.engadget.com/2209932/duckduckgo-browser-can-n…
Hierarchical neural integration of musical structure during expert performance https://www.biorxiv.org/content/10.64898/2026.07.20.738980v1 "Responses in the motor network, default mode network, and hippocampus were strongly impacted by scrambling, indicating that they…
This is a bigger deal than people may think. I've often wondered how much my life (as a fluent tri lingual) has been impoverished by all my tech interactions being in English by default. Especially search!
For example, I want a search engine that seeks across languages and finds me the top results in any language that I have told it I can speak.
Just encountered on mobile Firefox (both Apple and Android). New in version 151.
Seems Firefox has added a new AI kack option, turned on by default, of course:
AI summaries of web pages.
Go to your Settings>Page summaries and turn it off.
There's now also an AI controls submenu where you can limit other AI features.
Classical Acceptance Is Not Hybrid Authentication: Measuring X.509 Verifier Semantics in Post-Quantum Migration
Taesung Kim, Boheung Chung, Keonwoo Kim, Yousung Kang
https://arxiv.org/abs/2607.20800 https://arxiv.org/pdf/2607.20800 https://arxiv.org/html/2607.20800
arXiv:2607.20800v1 Announce Type: new
Abstract: A relying party validating a hybrid X.509 certificate --- carrying both a classical and a post-quantum credential --- must distinguish whether its accepting judgment rests on the post-quantum evidence or only on the classical path. To preserve compatibility, the separable designs place that evidence where classical path validation may ignore it. A verifier can then validate the classical path and accept while the post-quantum evidence never bears on the decision --- a valid classical result silently promoted to a hybrid conclusion it did not establish. We measure this across eight path-validation stacks (seven independent codebases), in nine validation modes, over six certificate schemes. Under a hybrid-required policy, nearly every stack parsing a separable hybrid certificate accepts on the classical path without making the post-quantum evidence outcome-bearing; one enforcing mode instead fractures interoperability over a signature-input encoding not yet interoperably profiled; and stacks that verify post-quantum signatures still do not enforce the binding by default: the gap is structural, not explained by missing primitive capability alone. Under lifecycle desynchronization the downgrade is realized: when a bound post-quantum credential is revoked while the classical certificate stays valid, the default path still accepts, because the bound credential lies outside the decision's scope. Binding success is not authentication success. We contribute a specification-derived verifier model and an executable, policy-parametric reference contract --- what a verifier must recognize, verify, make outcome-bearing, and check before reporting a validation as hybrid --- with a diagnosis of why standards do not require it.
toXiv_bot_toot
Summary of the measures relating to EVs in the EU's Electrification Action Plan (and related initiatives), alongside the general adjustments to network tariffs, connection conditions and taxation
https://energy.ec.europa.eu/publications/co…
Venmo is implementing a major privacy update to set new users' posts to "friends only" by default during onboarding; in 2021, a reporter found Joe Biden's Venmo (Jay Peters/The Verge)
https://www.theverge.com/tech/927503/venmo-app-redesign-privacy-post…
Hang on. Firefox now includes a VPN by default?
Will Zen follow suit, I wander?
1. modern "traditional" desktop environments waste WAY too much screen space by default
2. tiling desktops are absolutely fucking bizarre and I don't like how much control I'm expected to hand over to the system
3. fish is weird
Shopware 6 Hidden Gems #2: Bulk imports done right — taming the indexers
Every Shopware developer has been here: you push 50,000 products through the Sync API and the import crawls. The writes themselves are fast. What kills you is everything that happens after each write — inheritance updates, cheapest price calculation, search keyword generation, category denormalization. Shopware calls all of this "indexing", and by default it runs synchronously, per request,…
Can anyone guess what my fix was for ”Why is Mattermost always down in the early morning hours!?” 😅
Hint: Maybe #borgBackup should by default ignore the very repo it is backup-ing into...
99% of people probably don't use ipsec (and probably shouldn't use it), why do we have ipsec kernel modules installed by default on every linux distro? #dirtyfrag
Yes, of course that includes Bernie.
I am a feminist.
Not a gender egalitarian, a feminist. @… https://
Geen whatsapp of Signal meer nodig?
https://blog.google/products-and-platforms/platforms/android/android-ios-end-to-end-encrypted-rcs-messaging/
OpenAI says GPT-5.5 Instant produces 52.5% fewer hallucinated claims "on high-stakes prompts covering areas like medicine, law, and finance" (Megan Morrone/Axios)
https://www.axios.com/2026/05/05/openai-chatgpt-update-default-model
@… There are mitigations. For systems where algif_aead is a loadable module like Ubuntu (by default). Something like this prevents the vulnerable algif_aead module from loading:
$ sudo sh -c 'echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf'
Then unload the module if it is currently loaded, like so:
$ sud…
via @… :
Meta views its users as something akin to vassals.
https://daringfireball.net/linked/2026/07/09/meta-instagram-ai-default…
Normally I have to script in Windows, so I have a folder `C:\users\me\Dropbox\skripts` that contains it all. This folder is historical and has perl and shell scripts from my UNIX sysadmin days.
Had to do some stuff in WSL and I just discovered that your WSL shell - by default - inherits your Windows `%PATH%` (and handles the mapping into the WSL file system like `C:\` --> `/mnt/c/` etc.)... as I typed a command name in my `skripts` folder and it worked.
So..
Reuters and Time started blocking all AI bots by default and created whitelists of approved bots, following the default disallow strategy of People and others (Sara Guaglione/Digiday)
https://digiday.com/media/reuters-and-time-adopt-bot-blocki…
Looks like this got rolled back, but… if you use VSCode for source control… Microsoft has a new chore for you. (check your commits, I guess? this is bonkers.)
https://github.com/microsoft/vscode/pull/310226
I decided to try out Ecosia for search today, having been a long-time DuckDuckGo user.
Some observations:
1. For some bizarre reason there's no way to access your user profile on the main page, only on search results. No, not even if you create an account and login.
2. So once I'd found that... the searches are backed by Google and/or Bing. Thus I selected Bing to match my DDG experience.
3. They default to some form of AI enhancement, but at least you can t…
🔍 Tracing — per-request & per-job waterfalls of every query, cache op & HTTP call, off by default & persisted only when slow, errored or sampled to stay cheap at scale
🐞 Unified error tracking — web, queue, command & browser exceptions fingerprinted into a grouped inbox with stacktraces, sparklines & assign/ack/mute/resolve
Get a load of the high-risk apps that the DHS OIG discovered on the smartphones of DHS employees, including apps from companies the US gov't has banned and apps from US foreign adversaries.
https://www.oig.dhs.gov/sites/default/files/assets/2026-05/OIG-26-06…
DuckDuckGo updates its browser for iOS, Windows, and macOS to block video ads by default, particularly those on YouTube, based on uBlockOrigin's filter lists (Anna Washenko/Engadget)
https://www.engadget.com/2209932/duckduckgo-browser-can-n…
Timeō Microsoftōs et dōna ferentēs
Aenid, Publius Vergilius Maro, 19 BC colorised
via @…
https://floss.social/@hywan/116509265759021346
@… I mean... they made a staggeringly bad call on EternalBlue, which led to WannaCry, so the third option seems plausible. However, I think reviewing code and missing a bug in an obscure feature and missing that it's enabled by default is also not implausible.
The SMC Blind Spot: A Failure Mode Analysis of State-of-the-Art Beat Tracking
Jaehoon Ahn, Tae Gum Hwang, Moon-Ryul Jung
https://arxiv.org/abs/2605.12287 https://arxiv.org/pdf/2605.12287 https://arxiv.org/html/2605.12287
arXiv:2605.12287v1 Announce Type: new
Abstract: Over the past two decades, the task of musical beat tracking has transitioned from heuristic onset detection algorithms to highly capable deep neural networks (DNN). Although DNN-based beat tracking models achieve near-perfect performance on mainstream, percussive datasets, the SMC dataset has stubbornly yielded low F-measure scores. By testing how well state-of-the-art models detect beats on individual tracks in the SMC dataset, we identify three distinct failure modes: octave errors, continuity errors, and complete tracking failure where all metrics fall below 0.3. We reveal that state-of-the-art models tend to generate "confident-but-wrong" activations. Furthermore, we show that the standard DBN's default minimum tempo of 55 BPM prevents it from inferring the correct tempo for 21\% of SMC tracks, forcing double-tempo predictions on slow music. By exposing such fundamental oversights, we provide concrete directions for improving beat and downbeat detection, specifically emphasizing training data diversification and multi-hypothesis tempo estimation.
toXiv_bot_toot
If Apple's Siri AI works as it was shown in the WWDC demos, Apple is set to take the lead in consumer AI, with iPhone becoming the first true AI device (M.G. Siegler/Spyglass)
https://spyglass.org/siri-ai/
In around two weeks I’m migrating from iOS to a postmarketOS phone. Please leave app suggestions, I’m definitely going to need them!Waydroid is… fine, but not preferred Please avoid android apps unless it’s something that is like confirmed to work well on waydroid, is proprietary or something so has no alternatives or something like that. I’m not launching waydroid to listen to music, to read my e-mails or to use xmpp.
Some examples of what I’m looking for, probably for Plasma Mobile:
And also just anything y’all find useful in your daily life with a postmarketOS daily driver, I’m sure I’m forgetting a lot of stuff here.
I know some of those exist for desktop Linux, but I’m obviously looking for stuff made with phones in mind (so like… apps made for gnome should be automatically fine maybe?)
(Also, has anyone managed to get nix’s system-manager to work on postmarketOS? There’s no way I’m configuring all of this by hand every time I need to flash it lmao)
#postmarketOS #LinuxMobile #Linux
Apple releases iOS 26.5, introducing end-to-end encryption for RCS messaging in beta with supported carriers; the setting is enabled by default (Chance Miller/9to5Mac)
https://9to5mac.com/2026/05/11/ios-26-5-adds-end-to-end-encryption-for…
🔒 Local & private by default — no cloud service, no model API calls, no API keys, and it never writes into your source repos. Includes local docs, man-page generation & signed self-upgrades
https://github.com/ctxrs/ctx
PSA: if you have a self-hosted ghost blog, check the CVEs from time to time—specifically there was an issue where they didn't sanitize user input and enabled SQL injection which lead to people adding injected code in site header/footers.
If you don't use header/footer injection in posts, here's a quick SQL script to clean your db:
UPDATE posts SET codeinjection_head='', codeinjection_foot='';
Side note: I don't get why this is even a feature that's on by default (and can't be turned off).
In the meantime, #GitPython, the package that used to be dead (because the author is busily working on their next great thing) is now slopping out 4 "security" releases a week, as their #slop machine is busily fixing unintended variable expansion in every single URL they call. Unfortunately, they probably don't have enough tokens to fix them all at once, so instead all downstreams have to deal with the churn of endless security releases. Or the brain to figure out that maybe they could just disable variable expansion by default and solve them all at once.
It's truly a great time to be a #Python packager.
#NoAI #NoLLM
Filing: GoDaddy challenges a New Delhi court ruling requiring domain sellers to stop offering privacy by default, saying it could expose website owners globally (Reuters)
https://www.reuters.com/world/worlds-biggest-domain-…
> Users of #GitHub's command-line interface (#CLI) who value #privacy, beware. The #Microsoft-owned code-hosting platform has quietly begun collecting pseudonymous client-side #telemetry from CLI users and enabled it by default.
Wed 22 Apr 2026, Brandon Vigliarolo, The Register: #Datenschutz #TeamDatenschutz #DataProtection #DiDay
🎯 Built-in A/B testing with variant breakdowns, plus event- and funnel-based notifications
🌍 Cookieless tracking by default and #GDPR compliance, with SDKs for web, iOS (#Swift), Android (#Kotlin), #ReactNative and server-side tracking