2026-08-12 22:35:52
Twitch says it intends to use videos streamed on its platform to help train Amazon's generative AI models and tells creators how to opt out (Amanda Silberling/TechCrunch)
https://techcrunch.com/2026/08/12/amazon-will-train-o…
Twitch says it intends to use videos streamed on its platform to help train Amazon's generative AI models and tells creators how to opt out (Amanda Silberling/TechCrunch)
https://techcrunch.com/2026/08/12/amazon-will-train-o…
@… @… a slightly different issue there! We already handle `Date` instances for the special `date` property (whether yaml parses them by default or not is the js-yaml change) and String (previous luxon, now this new package)
(Most …
Twitch says it intends to use videos streamed on its platform to help train Amazon's generative AI models and tells creators how to opt out (Amanda Silberling/TechCrunch)
https://techcrunch.com/2026/08/12/amazon-will-train-o…
from my link log —
Same-site cookies by default.
https://textslashplain.com/2019/09/30/same-site-cookies-by-default/
saved 2019-10-02
Summary of the measures relating to EVs in the EU's Electrification Action Plan (and related initiatives), alongside the general adjustments to network tariffs, connection conditions and taxation
https://energy.ec.europa.eu/publications/co…
➡️ Wisconsin Department of Transportation - Southeast Region - Highway Projects and Studies
#bookmarks
Shopware 6 Hidden Gems #2: Bulk imports done right — taming the indexers
Every Shopware developer has been here: you push 50,000 products through the Sync API and the import crawls. The writes themselves are fast. What kills you is everything that happens after each write — inheritance updates, cheapest price calculation, search keyword generation, category denormalization. Shopware calls all of this "indexing", and by default it runs synchronously, per request,…
Dislike.
“Media Library infinite scrolling is now enabled by default, with a per-user opt-out”
https://make.wordpress.org/core/2026/07/23/media-library-infinite-scrolling-is-now-enabled-by-default-with-a-per-…
The UK government proposes a default overnight social media curfew for 16- and 17-year-olds and disabling features like auto-play and infinite scroll by default (Muvija M/Reuters)
https://www.reuters.com/technology/uk-plans-default…
TL;DR: Node’s standalone binaries have been broken on major Linux distributions since version 25. Stay on 24 if you need them functional by default.
If you’re installing Node.js via a standalone binary package, think twice before upgrading to Node 26.
On many Linux distributions these binaries will fail unless you separately install libatomic.so.1.
Can anyone guess what my fix was for ”Why is Mattermost always down in the early morning hours!?” 😅
Hint: Maybe #borgBackup should by default ignore the very repo it is backup-ing into...
Hang on. Firefox now includes a VPN by default?
Will Zen follow suit, I wander?
PSA: if you have a self-hosted ghost blog, check the CVEs from time to time—specifically there was an issue where they didn't sanitize user input and enabled SQL injection which lead to people adding injected code in site header/footers.
If you don't use header/footer injection in posts, here's a quick SQL script to clean your db:
UPDATE posts SET codeinjection_head='', codeinjection_foot='';
Side note: I don't get why this is even a feature that's on by default (and can't be turned off).
🇯🇵 #Japan is mad because the default free world maps on the #EqualEarth website depict the Kuril Islands under Russian control.
Internal OpenAI docs detail contractors evaluating anonymized prompts and chats to improve the models; model training is turned on by default for consumer plans (Joseph Cox/404 Media)
https://www.404media.co/inside-project-lily-the-humans-reading-your-chatg…
Yes, of course that includes Bernie.
I am a feminist.
Not a gender egalitarian, a feminist. @… https://
🚀 #JavaScript discovery extracts endpoints, URLs and emails and builds target-specific wordlists; captured #WebSocket connections can be inspected and frames injected
📊 Findings attach to the exchange that proves them; projects export sanitized by default, with
I decided to try out Ecosia for search today, having been a long-time DuckDuckGo user.
Some observations:
1. For some bizarre reason there's no way to access your user profile on the main page, only on search results. No, not even if you create an account and login.
2. So once I'd found that... the searches are backed by Google and/or Bing. Thus I selected Bing to match my DDG experience.
3. They default to some form of AI enhancement, but at least you can t…
#Java 27 features: Compact Object Headers by default, JFR redaction & post-quantum TLS!
https://aboullaite.me/java-27-features/
"If you’re someone who somehow lost their inner voice along the way (maybe without even realizing it) give yourself a shot. Don’t play anything in the background, don’t turn on your favorite show. Just sit in silence for a moment and see what happens. You might actually like it."
I agree. I do this by default. I am more likely to let myself think than fill my attention with some noise.
I do also rest my mind with mindless but enjoyable streaming... at times.
DuckDuckGo updates its browser for iOS, Windows, and macOS to block video ads by default, particularly those on YouTube, based on uBlockOrigin's filter lists (Anna Washenko/Engadget)
https://www.engadget.com/2209932/duckduckgo-browser-can-n…
via @… :
Meta views its users as something akin to vassals.
https://daringfireball.net/linked/2026/07/09/meta-instagram-ai-default…
Based on the linked research by Charlie Marsh, here's setup-cached-uv 2.6.0 that doesn't run `uv cache prune --ci` by default anymore: https://github.com/hynek/setup-cached-uv/releases/tag/v2.6.0
@… @… relying on user education is unlikely to work. Ordinary non-technical users deserve secure communications by default.
That's why for all Meta's faults, WhatsApp is such a major win for user privacy, in that th…
DuckDuckGo updates its browser for iOS, Windows, and macOS to block video ads by default, particularly those on YouTube, based on uBlockOrigin's filter lists (Anna Washenko/Engadget)
https://www.engadget.com/2209932/duckduckgo-browser-can-n…
Ah, finally, what we’ve been asking for for years: a browser setting (ideally, mandated by law to be on by default – that’s how it should be implemented to have the most effect) that sends a proper “do not track” signal that’s not a request but a legal obligation.
If this passes, and in the form described above, I do hope it also gets enforced (unlike, say, the half-arsed enforcement of GDPR). @…
""Starting with Red Hat Enterprise Linux (#RHEL) 10.2, #Firefox and #Thunderbird are delivered as Flatpaks by default. If you install RHEL with a graphical desktop, your browser and email client will now come from the
- Formal code of doctrine and discipline
This is just "what your objectives are." It can be as simple as ULC's "Do That Which is Right" or it can be much more complicated. You would figure that out with your group.
Personally, I would choose something like, "make life as easy as possible for caretakers." I've talked about this in the past. If you focus on care taking then you are feminist by default, you help everyone *at least once*, almost everyone twice, and most people 3 or 4 times:
- Children with supported caretakers do better
- Elderly people with supported caretakers will have a better quality of life
- Parents always need help and will do better when they have it, and the more kids the more support they need
But hey, I'm not here to tell you what to do. You can figure your own things out. (Technically, that last sentence could also be a legitimate formal code or doctrine, so we can move on.)
I don't think I actually *use* these key bindings, myself, but this kind of user-empowered thinking is a good illustration of why I've settled on Vivaldi as my daily driver browser.
It's the *least unlike* a User Agent, as we've come to expect, IMO. https://social.vivaldi.net/@jon/116818
Replaced article(s) found for cs.HC. https://arxiv.org/list/cs.HC/new
[1/2]:
- Music Interpretation and Emotion Perception: A Computational and Neurophysiological Investigation
Lyberatos, Kantarelis, Zioga, Anagnostopoulou, Stamou, Georgaki
https://arxiv.org/abs/2506.01982 https://mastoxiv.page/@arXiv_csHC_bot/114623887921808883
- Selective Prediction Reduces the Negative Effects of Automation Bias Overall but Increases False ...
Jabbour, Fouhey, Banovic, Shepard, Kazerooni, Sjoding, Wiens
https://arxiv.org/abs/2508.07617 https://mastoxiv.page/@arXiv_csHC_bot/115015501954907821
- Sighted by Default: Addressing Implicit Vision Assumptions in Real-Time VLM Assistance for BLV Users
Yi Zhao, Siqi Wang, Qiqun Geng, Erxin Yu, Jing Li
https://arxiv.org/abs/2511.00945 https://mastoxiv.page/@arXiv_csHC_bot/115490927925171769
- UXCascade: Scalable Usability Testing with Simulated User Agents
Steffen Holter, Eunyee Koh, Mustafa Doga Dogan, Gromit Yeuk-Yin Chan
https://arxiv.org/abs/2601.15777 https://mastoxiv.page/@arXiv_csHC_bot/115943802965989174
- Does Explanation Correctness Matter? Linking Computational XAI Evaluation to Human Understanding
Gregor Baer, Chao Zhang, Isel Grau, Pieter Van Gorp
https://arxiv.org/abs/2603.25251 https://mastoxiv.page/@arXiv_csHC_bot/116300187728326082
- Beyond Screenshots: Evaluating VLMs' Understanding of UI Animations
Chen Liang, Xirui Jiang, Naihao Deng, Eytan Adar, Anhong Guo
https://arxiv.org/abs/2604.26148 https://mastoxiv.page/@arXiv_csHC_bot/116492495199874264
- Quieting the Cobwebs: Browser Interaction for Visual Floaters
Kenneth Ge, Jinglin Li, Shikhar Ahuja
https://arxiv.org/abs/2605.12739 https://mastoxiv.page/@arXiv_csHC_bot/116571803728109358
- Patients With Personality: Realistic Patient Simulation through Controlled Diversity and Selectiv...
Moritz Schlager, et al.
https://arxiv.org/abs/2606.17441 https://mastoxiv.page/@arXiv_csHC_bot/116764285920198987
- TailVis: Expressive Chart Refinement Preserving Data-Binding Integrity
Yumin Song, Seokhyeon Park, Soohyun Lee, Aeri Cho, Hyeon Jeon, John Joon Young Chung, Jinwook Seo
https://arxiv.org/abs/2607.25386 https://mastoxiv.page/@arXiv_csHC_bot/117002258150815192
- How Usable Are Geospatial Foundation Models? A Systematic Evaluation of 89 Models
Robin Young, Artyom Gabtraupov, Kenzy Soror, Srinivasan Keshav
https://arxiv.org/abs/2608.03804 https://mastoxiv.page/@arXiv_csHC_bot/117041905504697955
toXiv_bot_toot
My wife complained her iPhone 17 display was "turning pink". Fishing through settings menus revealed Accessibility > Display > Color Filters set to pink. I turned it off, phone normal.
But the phone kept turning pink. Online searches revealed the default "Accessibility action" for hitting the side button 3x was to turn *on* the color filter (easy to do by accident just handling the phone).
Who at Apple thought this was a useful default??
#iphone17
That feeling when your renderer can handle a component that outputs HTML inside link text in Markdown that’s embedded in HTML.
(Yes, I’m bragging.)
#Kitten #SmallWeb #SmallTech
PEP 832 – Virtual environment discovery
#python
A product on Amazon was $25 cheaper than the same product at the manufacturer site. But between a coupon code and lack of sales tax, I paid ~$4 less through manufacturer site.
It may get fulfilled by Amazon anyway, but I continue to refuse to treat Amazon as default (when no local retailer has it).
Hierarchical neural integration of musical structure during expert performance https://www.biorxiv.org/content/10.64898/2026.07.20.738980v1 "Responses in the motor network, default mode network, and hippocampus were strongly impacted by scrambling, indicating that they…
🌐 Clients connecting by IP send no SNI, so Caddy needs a fallback identity: set CADDY_GLOBAL_OPTIONS: "default_sni https://example.com"
⚠️ Enabling a profile pins issuance to Let's Encrypt only (the ZeroSSL fallback is dropped) and renews roughly every 2 days, so the container needs reliable egress to …
Why should people in the UK suffer from heat in their own home? Because a piece of paper says so. Let's change it.
https://petition.parliament.uk/petitions/770729
Spec Sheets Are Not Kernels: An ISA- and Source-Level Audit of INT8 Availability on NVIDIA Blackwell Ultra
Teng-Ruei Chen
https://arxiv.org/abs/2608.11693 https://arxiv.org/pdf/2608.11693 https://arxiv.org/html/2608.11693
arXiv:2608.11693v1 Announce Type: new
Abstract: NVIDIA's published specifications give the Blackwell Ultra GPU (B300) a dense-compute ratio of roughly 30:1 between FP8 and INT8 tensor-core throughput; its predecessors, H200 and B200, both provide 1:1. We audit what this deprioritization means in practice by tracing INT8 W8A8 support through four layers of the stack: the published specifications, the PTX ISA, NVIDIA's CUTLASS kernel library, and the two major open-source LLM serving engines (vLLM and SGLang). We find a consistent, layered withdrawal: (i) the PTX ISA never exposes the fifth-generation tensor-core integer path (tcgen05.mma with .kind::i8) on sm_103a, even though the same PTX revision extends the FP4 kinds to that target, leaving legacy warp-level IMMA as the only architecturally legal integer tensor-core path on B300; (ii) CUTLASS's kernel generator explicitly skips INT8 UMMA generation for any build targeting 103a, while generating FP8 unconditionally; (iii) vLLM ships no INT8 GEMM for Blackwell and fails with a hard runtime error at the first forward pass, after the model has loaded; and (iv) SGLang's ahead-of-time INT8 GEMM stops at Sm90, while its FP8 tuning configurations already cover B200. We document an escape hatch (rerouting vLLM's INT8 path to a JIT-compiled Triton backend via an environment variable), a false-negative trap in the obvious profiler methodology for detecting "native INT8" on sm_103, and the practical failure semantics that make naive testing expensive. Together, these findings show that a quantization format's availability is a property of the whole stack rather than of the model or the spec sheet. Four distinct layers, three of them NVIDIA's own, withdrew INT8 support in mutually consistent ways, and a format that is nominally present on the datasheet is, by default, undeployable on this hardware.
toXiv_bot_toot
Classical Acceptance Is Not Hybrid Authentication: Measuring X.509 Verifier Semantics in Post-Quantum Migration
Taesung Kim, Boheung Chung, Keonwoo Kim, Yousung Kang
https://arxiv.org/abs/2607.20800 https://arxiv.org/pdf/2607.20800 https://arxiv.org/html/2607.20800
arXiv:2607.20800v1 Announce Type: new
Abstract: A relying party validating a hybrid X.509 certificate --- carrying both a classical and a post-quantum credential --- must distinguish whether its accepting judgment rests on the post-quantum evidence or only on the classical path. To preserve compatibility, the separable designs place that evidence where classical path validation may ignore it. A verifier can then validate the classical path and accept while the post-quantum evidence never bears on the decision --- a valid classical result silently promoted to a hybrid conclusion it did not establish. We measure this across eight path-validation stacks (seven independent codebases), in nine validation modes, over six certificate schemes. Under a hybrid-required policy, nearly every stack parsing a separable hybrid certificate accepts on the classical path without making the post-quantum evidence outcome-bearing; one enforcing mode instead fractures interoperability over a signature-input encoding not yet interoperably profiled; and stacks that verify post-quantum signatures still do not enforce the binding by default: the gap is structural, not explained by missing primitive capability alone. Under lifecycle desynchronization the downgrade is realized: when a bound post-quantum credential is revoked while the classical certificate stays valid, the default path still accepts, because the bound credential lies outside the decision's scope. Binding success is not authentication success. We contribute a specification-derived verifier model and an executable, policy-parametric reference contract --- what a verifier must recognize, verify, make outcome-bearing, and check before reporting a validation as hybrid --- with a diagnosis of why standards do not require it.
toXiv_bot_toot
TIL #Debian does not, by default, auto-manage journalctl logging and /var/cache/apt/archive, and purging flatpak leaves /var/lib/flatpak with GBs of god knows what (cruft from deleted apps?)
Claimed back 7 GB of disk correcting those!
Good lord, you are not going to believe the massive amount of cybersecurity news you might have missed since just Friday, so check out today's Metacurity for the top developments, including
--DPRK's Kimsuky built an in-house AI toolkit to power cyberattacks,
--Chinese components in UK military drones secretly transmitted data,
--California city declares emergency after cyberattack disrupts 911 services,
--Turkey's new cyber law sparks fears of sweeping digital censorship,
--OpenAI's Hugging Face hack reveals deeper AI safety failures,
--Anthropic makes Claude Code's autonomous mode the default,
--AI agent hacks gym booking system without being told to,
--Military supplier discloses phishing breach exposing sensitive defense data,
--Iranian water hacks revive push for EPA cyber authority,
--Levi Strauss says social engineering attack breached company systems,
--Australian court users' data posted on dark web,
--Framework customer data stolen in upstream Metabase breach,
--Major law firms paid $28m in Luna Moth ransomware attacks,
--Former SK Hynix employee jailed for leaking chip secrets to China,
--S. Korean opposition apologizes for breach affecting 17,000 members,
--S. Korean teams dominate DEF CON hacking finals,
--Breach at S. Korea's 3Pro TV exposes 460,000 customer records,
--Serbian entrepreneur arrested over alleged hacking of Croatian government systems,
--One-third of UK manufacturers hit by cyberattacks,
--Poland details second Russian cyberattack on power grid,
--Researchers' email honeypot captures hundreds of thousands of misdirected messages,
--Ransomware gangs increasingly target midlevel managers,
--Oklahoma Manufacturing Alliance hit by Booba ransomware attack,
--Thai agencies consider MFA after widespread government data leaks,
--Vintage computer collectors preserve the machines that built the digital age,
--Meta smart glasses face growing privacy backlash,
--Amazon backs massive gas-powered plant for Texas AI data center,
--OpenAI touts AI productivity while employees work 90-hour weeks
https://www.metacurity.com/dprks-kimsuky-built-an-in-house-ai-toolkit-to-power-cyberattacks/
🔒 Local & private by default — no cloud service, no model API calls, no API keys, and it never writes into your source repos. Includes local docs, man-page generation & signed self-upgrades
https://github.com/ctxrs/ctx
Filing: GoDaddy challenges a New Delhi court ruling requiring domain sellers to stop offering privacy by default, saying it could expose website owners globally (Reuters)
https://www.reuters.com/world/worlds-biggest-domain-…
Our 1563 partners have illegitimate interest and would like to process your data. Allow?
I've finally bisected my TV problem and indeed, #amdgpu starting to output RGB by default was the cause. Also found out that I can force YUV444 via debugfs, so with some hacking, I can actually use the latest #Linux kernel.
https://gitlab.freedesktop.org/drm/amd/-/work_items/5760
State AGs' trial: Adam Mosseri denies Instagram stalled by not making its "Take a Break" teen safety feature the default until nearly three years after launch (Reuters)
https://www.reuters.com/business/instagram-head-adam-mosseri-test…
🔗 Document links make view('orders.index') and route('https://orders.show') clickable, and the same index backs go-to definition, which is enabled by default.
🔧 composer global require laravel/lsp
Requires PHP 8.2 , ships prebuilt binaries for macOS, Linux (arm64/x64) and Windows x64.
An ex-Meta staffer testified that less than 1% of teens used Instagram's opt-in "Take a Break" tool when it launched; the feature is now on by default for teens (Madlin Mekelburg/Bloomberg)
https://www.bloomberg.com/news/articles/20
📊 Request logging lets you inspect authenticated traffic to monitor and diagnose agent behavior
⚙️ Single #Go binary acting as server and CLI: API on port 14321, proxy on 14322, #SQLite by default, #PostgreSQL
🎯 Built-in A/B testing with variant breakdowns, plus event- and funnel-based notifications
🌍 Cookieless tracking by default and #GDPR compliance, with SDKs for web, iOS (#Swift), Android (#Kotlin), #ReactNative and server-side tracking
In the meantime, #GitPython, the package that used to be dead (because the author is busily working on their next great thing) is now slopping out 4 "security" releases a week, as their #slop machine is busily fixing unintended variable expansion in every single URL they call. Unfortunately, they probably don't have enough tokens to fix them all at once, so instead all downstreams have to deal with the churn of endless security releases. Or the brain to figure out that maybe they could just disable variable expansion by default and solve them all at once.
It's truly a great time to be a #Python packager.
#NoAI #NoLLM
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.
One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.
This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
The CIRCL vulnerability-lookup instance is running the pre-release of 6.0 -
#cve #gcve #opensource #vulnerabilitylookup #opendata #vulnerabilitymanagement #cyberecurity #ssvc
@…
@…
Just finished "Rialto" by Kate Milford. A wonderful book with a *lot* of things to like but also a few I wish had been done differently.
Starting with the good stuff, an #OwnVoices portrayal of anxiety depression is always welcome, *especially* one that portrays positive coping strategies, including active therapy, and complex but ultimately supportive family dynamics. Dad & daughter each reminding each other to use calming strategies at different points in the book was lovely, and getting to see the complexities of the trying to be a supportive sibling was great! Larger than that aspect, portraying a YA adventure in which the parents are actively involved but don't spoil things is so great and must have been difficult to pull off. Most YA stuff quickly ushers the parents out of the picture, and this fails to provide any kind of positive or negative role model for parent/child interaction. This book had ample examples of the former, *and* let the kids have plenty of agency too. Excellent stuff that I absolutely want to see more of.
So what didn't I like?
First, as an anarchist, I always hate to see unapologetically positive (and thus drastically unrealistic) portrayals of the police. Without getting into spoilers, even the stuff about the Piepowder court bothered me. It's presented here as a cutesy alternate court tradition, but I can't help but speculate that these courts were likely not always fair in practice, and the whole "single person makes immediate judgments model" from this book is terrible in general. I just don't like positive portrayals of terrible systems that happen to be good because the people involved are good people, since they reinforce harmful positive mental models of "justice" that don't apply to the real world. This element wasn't enough to totally spoil the book for me (the plot could have mostly functioned without it) but it's a downside to me.
Second, the book is set in rural Missouri, and has plenty of Black characters. Yay for representation? Certainly better than the cast being all-white given the setting. But the book doesn't have any Black *culture* that I picked up on, and it chooses to try to completely sidestep the relevant history. Maybe I'm just not attuned to elements that were there; if anyone who read this did see them feel free to point them out. The history definitely isn't there though... for example, was the park segregated, or not? During the time it was active one imagines most parks would have been, and that if it hadn't been that would have been a very important difference, which would even have been relevant to the plot and themes of the book as written.
Now perhaps this critique is unfair because Black children and young adults *should* get to see themselves portrayed in cozy fantasies without things always having to be about racism... In a choice between erasing Black characters and erasing racism (and especially racist histories) maybe there's no right answer here and this is fine, actually. My instinct tells me that there are ways to do better, though, and that presenting a history with all the racism carefully elided isn't the greatest compromise to make here.
A while ago I read "Under the Heron's Light" by Randi Pink. It also has mythical animal guides, a Southern setting, helpful family members, a multi-generational mystery to solve, and a (slightly older) teen protagonist who is up to the task. In contrast, it is all about racist history, and takes us through multiple extremely harrowing scenes from the past.
In any case, this discomfort also wasn't a deal-breaker for me, in part because, as I said, I think it's probably good for Black children to see uncomplicatedly positive representations of people like them alongside the plenty of stuff out there that does get deep into the racism and history. I also don't have the best perspective to judge this stuff, although that doesn't mean I should default to "it's probably fine" (I'd be happy to hear from anyone who feels they have a better perspective on this, about this book or the trend in general...).
Overall, I enjoyed Rialto quite a lot. I don't think it quite makes it into my top tier of recommendations for my kids, but I think it does make the list somewhere.
#AmReading #ReadingNow #Bookstodon