I Clicked a Random Button in Google SlidesāāāThen Google Paid Me $2,240
The strange trick that exposed a hidden security flaw (and how you can find bugs like this too).
[Continue reading on InfoSec Write-ups Ā»](https://in ⦠ā Read more
yarnd UI/UX experience (for those that use it) and as "client" features (not spec changes). The two ideas are quite simple:
Iād have to write i up in full, but essentially looks a bit like this (contribived examples follow)ā¦
irc.mills.io running behind Caddy Layer 4. However I don't terminate TLS at the edge in this case.
@prologic@twtxt.net OH SHIT using this for a protocol like gopher is smart! might have to try that for gemini so i donāt have to keep a port open for that
From $30 parmigianas to $15 pints, can Australia still afford the pub?
From our coffee addiction to a weekend pub tradition, some of the simple pleasures many Australians have taken for granted now feel like luxuries. But if patrons can no longer afford to visit the pubs and cafĆ©s we love, there may be something bigger at stake. ā Read more
@movq@www.uninformativ.de noted! i did try something like this but it wouldnāt connect on anything without the SSL stuff, which is normally handled by caddy for me but i canāt use certbot with caddy on so iām stuck there LOL
@kingdomcome@yarn.girlonthemoon.xyz itās slang that means to like focus and get shit done i guess. originates from AAVE
@prologic@twtxt.net Hmm, speaking of locally running āAIā stuff: Someone on Mastodon has this in their profile description:
My profile pic is AI modified to prevent deepfakes. I used local Stable Diffusion on my solar powered 7900XTX to average a few selfies.
That sounds like a fun thing to do. Do I have a chance of doing that on my old box from 2013 without a dedicated GPU? š
@kat@yarn.girlonthemoon.xyz At the core, you need an ngircd.conf like this:
[Global]
Name = your.irc.server.com
Password = yourfancypassword
Listen = 0.0.0.0
Ports = 6667
AdminInfo1 = Well, me.
AdminInfo2 = Over here!
AdminEMail = forget.it@example.invalid
[Options]
Ident = no
PAM = no
[SSL]
CertFile = /etc/ssl/acme/your.irc.server.com.fullchain.pem
KeyFile = /etc/ssl/acme/private/your.irc.server.com.key
DHFile = /etc/ngircd/dhparam.pem
Ports = 6669
Start it and then you can connect on port 6667. (The SSL cert/key must be managed by an external tool, probably something like certbot or acme-client.)
Iām assuming OpenBSD here. Havenāt tried it on Linux lately, let alone Docker. š
@prologic@twtxt.net Since you have to check and double check everything it spits out (without providing sources), I donāt find any of this helpful. Itās like someoneās in the room with you and that person is saying random stuff that might or might not be correct. At best, it might spark some new idea in your head and then you follow that idea the traditional way.
Information published on the internet (or anywhere, for that matter) was never guaranteed to be correct. But at least you had a āframe of referenceā: āAh, I read this information about Linux on a blog that usually posts about Windows, so this one single Linux post might not necessarily be correct.ā That is completely lost with LLMs. Itās literally all mushed together. š¤·
AI isnāt a shortcut for thinking. In her guide for skeptics, Hilary Gridley reframes AI as a collaboratorānot a replacement. Use it like spellcheck for your thoughts. Donāt fear itāiterate with it. Insight improves, speed follows. Full post: https://hils.substack.com/p/the-ai-skeptics-guide-to-ai-collaboration
Chaining Bugs Like a Hacker: IDOR to Account Takeover in 10 Minutes
šFree Article Linkā¦
[Continue reading on InfoSec Write-ups Ā»](https://infosecwriteups.com/chaining-bugs-like-a-hacker-idor-to-account-takeover-in-1 ⦠ā Read more
**Bypassing Like a Pro: How I Fooled the WAF and Made It Pay **
Hi there!
[Continue reading on InfoSec Write-ups Ā»](https://infosecwriteups.com/bypassing-like-a-pro-how-i-fooled-the-waf-and-made-it-pay-e433193e1d9d?source=rssā-7b722bf ⦠ā Read more
@prologic@twtxt.net Shit like what? References/threads? š
Just adopted this majestic floof. He looks like heās plotting something, but Iām too in love to care. ā Read more
Hmmm thereās a bug somewhere in the way Iām ingesting archived feeds š¤
sqlite> select * from twts where content like 'The web is such garbage these days%';
hash = 37sjhla
feed_url = https://twtxt.net/user/prologic/twtxt.txt/1
content = The web is such garbage these days š Or is it the garbage search engines? š¤
created = 2024-11-14T01:53:46Z
created_dt = 2024-11-14 01:53:46
subject = #37sjhla
mentions = []
tags = []
links = []
sqlite>
@movq@www.uninformativ.de Itās nice to see shit like this still works 𤣠Even years later š
I do want to improve the feeds.twtxt.net service one day (soonā¢) with features like this. But first Iāll have to prevent spammers from abusing it by introducing IndieAuth as an authentication layer.
is it like⦠ethical to offer access to certain self hosted services as patreon exclusives. like i wanna offer the IRC client/bouncer i hosted which seems ok i think because iāve seen pico.sh offer their instances of that as paid services. but the other ones i have in mind are alt web frontends for stuff like imgur and pinterest. and i just feel weird about it for some reason. idk iām trying to think of ways to support my server stuff but every time i come up with something it feels weird
Seem like itās a server-client thingy? š¤ I much prefer tools in this case and defer the responsibility of storage to something else. I really like restic for that reason and the fact that itās pretty rock solid. I have zero complaints š
@kat@yarn.girlonthemoon.xyz ngircd is nice: https://ngircd.barton.de/ You can absolutely host this on your server for you and your friends (Iāve been doing that for a very long time). Actually peering with something like libera is hard, though, because they have strict requirements and a lot of traffic. Then again, thereās no real benefit in peering, actually. IRC is pretty ādecentralizedā anyway and people are usually used to connecting to several networks, so joining another one isnāt a big deal, imho. š
@kat@yarn.girlonthemoon.xyz is there anything i can even run or is this like email where you should just use libera and shut up
That was a wild ride:
https://www.youtube.com/watch?v=QSMDb1CWD6Y
Notice how old all these people sound. They started playing this game like 10, 15, 20 years ago, most of them left, but some are still there. I love that level of commitment. š
Also interesting from a technical point of view. Creating that virtual world and keeping it running consistently for so long ⦠š¤Æ
@kat@yarn.girlonthemoon.xyz Sounds like a lot of fun ! š GOOD LUCK!
LXQt 2.2.0 released
LXQt, the Qt-based alternative to KDE as Xfce is the GTK-based alternative to GNOME, has released version 2.2.0. LXQt is in the middle of its transition to Wayland, and as such, this release brings a number of fixes and improvements for Wayland, like improved multi-display support and updated compatibility with Wayland compositors. Beyond all the Wayland work, LXQt Power Management now supports power profiles, text rendering in QTerminal and QTermWidget has been improved, the file manager PC ⦠ā Read more
@movq@www.uninformativ.de From what I can tell, they use strict semantic versioning and backwards compatibility. There are two versions of the storage, v1 and v2, but it doesnāt look like v2 is enabled yet.
@prologic@twtxt.net @bmallred@staystrong.run So is restic considered stable by now? āStableā as in āstable data formatā, like a future version will still be able to retrieve my current backups. I mean, itās at version ā0.18ā, but they donāt specify which versioning scheme they use.
Got him from the shelter, look how cozy he is like he belonged here ā Read more
CAN MY FEDI INSTANCE STOP CRASHING
(it is running gotosocial which is like one of the lightest fedi servers out there. the machine it runs on is as old as a high schooler. guess the root problem)
Radxa Dual 2.5G Router HAT Expands Networking and Storage for Raspberry Pi 5 and ROCK SBCs
The Radxa Dual 2.5G Router HAT adds high-speed networking and NVMe storage expansion to single-board computers like the Raspberry Pi 5 and Radxa ROCK series, using a single PCIe connection in a compact form factor. The HAT uses the ASM2806 PCIe Gen3 switch chip to convert a single PCIe lane into multiple downstream lanes. This [ā¦] ā Read more
I think videos like this will be common in the futureš ā Read more
10 Mind-Blowing Revelations About Our Solar System
Considering the universe is almost 100 billion light-years acrossādue to inflation (not monetary) and whatnotāitās amazing that some of the coolest discoveries and revelations are in our solar system. Thatās like crossing the world (many, many, many times) and then finding treasure in your own backyard. Maybe the proximity is part of the appeal because [ā¦]
The post [10 Mind-Blowing Revelations About Our Solar System](https://listv ⦠ā Read more
@kat@yarn.girlonthemoon.xyz Itās more like a cache, it stores things like ātimestamp of the most recent twt weāve seen per feedā or ālast modification dateā (to be used with HTTPās if-modified-since header). You can nuke these files at any time, it might just result in more traffic (e.g., always getting a full response instead of just āHTTP 304 nope, didnāt changeā).
@quark@ferengi.one Yes, I often write a couple of twts, donāt publish them, then sometimes notice a mistake and want to edit it. Youāre right, as soon as stuff is published, threads are going to break/fork by edits.
@movq@www.uninformativ.de HELP THIS IS GENUINELY SO SWEET THANK YOU ;_; omg i felt so nervous posting this because i was like what if i get something wrong but then i did it anyway and i felt so free⦠like woah i did all of this
@kat@yarn.girlonthemoon.xyz As someone who has a say in hiring decisions (every now and then ā Iām not an executive nor an HR person š): This is gold. Writeups like these tell me/us so much about job applicants. Itās much more valuable than āa CV without gapsā or āknow your algorithmsā or whatever. Instead, it shows how you work and that you understand what youāre doing, and thatās the most important part. š„
@bender@twtxt.net NOOOO i self host an XMPP server and also revolt but as much as i love XMPP (gajim client reminds me of using skype as a kid highkey) i donāt use it much and revolt is a bitch to maintain. like i broke revolt file uploads and it stayed that way for months until literally last week lmao. i never bothered with matrix tbh maybe i shouldāve but it seems not worth it
SqliteCache backend I'm working on here, what are your thoughts regarding mgirations from old MemoryCache (which is now gone in the codebase in this branch). Do you care to migrate at all, or just let the pod re-fetch all feeds? š¤
@prologic@twtxt.net hm would there be any loss with the re-fetch option? i wouldnāt mind either but iād like to hold onto what i got if possible! but if it IS possible but also really annoying to do iāll just do the re-fetch of feeds because iām lazy af LMAO
Using AI in education is like using a forklift in the gym. The weights do not actually need to be moved from place to place. That is not the work. The work is what happens within you.
@xuu@txt.sour.is like, badly broken. I mean, the guy doesnāt even use twtxt (it is more like an RSS feed for him). So, yeah, even if it was the correct mention it would never reach the intended ears. š
ļø Mr. Robot CTF Walkthrough | TryHackMe
āA beginner-friendly guide to hacking like Elliot Aldersonā
** In reply to: Common Cyborg | Jillian Weise | Granta **
In reply to: Common Cyborg | Jillian Weise | Granta
They like us best with bionic arms and legs. They like us deaf with hearing aids, though they prefer cochlear implants. It would be an affront to ask the hearing to learn sign language. Instead they wish for us to lose our language, abandon our culture and consider ourselves cured. They like exoskeletons, which none of us use. They would never consider cyborg those of us with pace ⦠ā Read more
@hacker-news@feeds.twtxt.net I like this š
I do think integrating things like Salty.im might actually be a good idea. I can also see a future where we integrate other things like todo.txt and calendar.txt. Iād even love to see decentralised forms of āplain textā voting too.
@andros@twtxt.andros.dev I donāt see any āfightingā here. This is just good experimentation. Unfortunately there hasnāt really been enough time or effort by other āclient authorsā yet, me especially as Iāve been super busy with yaā know my āday jobā that pays the bills and refactoring yarnd to use a new and shiny and much better SqliteCache 𤣠ā I certainly donāt think your efforts are wasted at all. I would however like @doesnm.p.psf.lt@doesnm.p.psf.lt encourage you to look at the work weāve done as a community (which was also driven out of the Yarn.social / Twtxt community years back).
ā”ļøOops, They Logged It! Turning LFI into Remote Shell Like a Pro āļø
Free Linkš
[Continue reading on InfoSec Write-ups Ā»](https://infosecwriteups.com/%EF%B8%8Foops-they-logged-it-turning-l ⦠ā Read more
Gmail Showing 1 Unread Message? Hereās How to Find It
If youāre the type of person who likes to maintain Inbox Zero, or who recently went and tidied up their Gmail inbox to get every email marked as read, you may come across a frustrating situation where Gmail shows 1 unread message, and you simply canāt locate that unread email message in Gmail. If you ⦠Read More ā Read more
Happy 1st Twtxt~iversary to me ⦠I guess. It feels like it was 5 years since my first twt š
Do you like Betty? ā Read more
Beta 2 of iOS 18.5, MacOS Sequoia 15.5, iPadOS 18.5 Released for Testers
New betas are available as iOS 18.5 beta 2, MacOS Sequoia 15.5 beta 2, and iPadOS 18.5 beta 2, for users who are participating in the beta testing programs for Apple system software. No notable new features or major changes are expected in these beta versions, at least thus far, suggesting theyāre likely focused on ⦠[Read More](https://osxdaily.com/2025/04/14/beta-2-of-ios-18-5-macos-sequoi ⦠ā Read more
The subjective charms of Objective-C
To argue that Objective-C resembles a metaphysically divine language, or even a good language, is like saying Shakespeare is best appreciated in pig latin. Objective-C is, at best, polarizing. Ridiculed for its unrelenting verbosity and peculiar square brackets, it is used only for building Mac and iPhone apps and would have faded into obscurity in the early 1990s had it not been for an unlikely quirk of history. Nevertheless, in my time working as a softwar ⦠ā Read more
I personally really like the news minimalist (fuck it mentions are kind of broken atm here in the UI :/) feed myself, really good quality, very high signal š