[-] Deebster@infosec.pub 2 points 2 hours ago

The comment in question was clearly tongue in cheek, calm down.

[-] Deebster@infosec.pub 2 points 2 hours ago

I think they were adding the missing words from your title

[-] Deebster@infosec.pub 14 points 1 day ago

Some top tier charts in there

[-] Deebster@infosec.pub 23 points 1 day ago

It's great, but not very subtle

[-] Deebster@infosec.pub 2 points 2 days ago

It was from the same project that created Friendica, and they definitely did a lot of things first or early, although the W3C have got most people using ActivityPub now (just one of the protocols Hubzilla speaks). Probably the standout feature is account migration - there's work towards supporting this in ActivityPub, but it is a long way from being what Hubzilla allows.

[-] Deebster@infosec.pub 111 points 2 days ago

The one thing he didn’t plan for was that auto-uploading the files this way required a paid account.

“There was really only one reasonable solution: my hamster now has Strava Premium,” de Buck said.

Love the commitment to the bit. I was unsurprised to learn that the owner is a physicist and an injured runner meaning he has both the time and motivation to geek out on data and live vicariously.

20
submitted 3 days ago* (last edited 1 day ago) by Deebster@infosec.pub to c/cybersecurity@infosec.pub

I missed it last year, but not this time.

There's about 33 hours left of the sale at the time of this post.

Edit: it's finished now, but they have it every year in July/August. I watched their mastodon for the announcement.

[-] Deebster@infosec.pub 1 points 4 days ago

Here we were having a civil, good faith discussion, then you start flinging around downvotes to try to suppress any post you don't 100% approve of. That's not conducive to quality discourse, and you should stop it. You comments votes are downvotes 42% of the time.

Thanks for the link and I'll look into this, but I won't be talking with you any further.

[-] Deebster@infosec.pub 1 points 4 days ago

AISI is the AI Security Institute, so it's within their remit to discover what the AI companies' products can do - but then to not be monitoring them while they were running is where I call incompetence and negligence.

This is at least independent verification that these "breaches" aren't just AI bro marketing.

[-] Deebster@infosec.pub 2 points 4 days ago

AISI admitted it was not actively monitoring the agents’ behaviour during the evaluation and said it was putting tighter controls on internet access in tests as a result of the incident, introducing constant monitoring and reassessing its design of tests.

Sounds like the AISI are irresponsible and negligent - they took off the guardrails and gave it internet access, then didn't monitor it.

[-] Deebster@infosec.pub 7 points 6 days ago

He's been given an official birthday of 4 December 1832, so he's not quite there yet.

He predates Queen Victoria's coronation, the telegraph, Hans Christian Andersen's fairy tale collections, Charles Darwin's theory of natural selection, etc.

[-] Deebster@infosec.pub 3 points 6 days ago

Wow, this is comprehensive. What I've read so far is great. I love the coral reef metaphor/imagery.

7

cross-posted from: https://lemmy.world/post/50148512

Original post here [redlib link].

Written by deluan

The next release normalizes every ID in the database into a single format. It runs a one-time migration on first start. The PR with this change will be merged this weekend: https://github.com/navidrome/navidrome/pull/5824

If you run develop or auto-update, this lands soon (this weekend) and without warning. Make a backup of navidrome.db now. The migration is one-way, so rolling back (if needed) means restoring that backup.

The short version:

  • Takes ~30s to ~1m20s on my 96k-track library (QNAP Celeron). Scales with library size.
  • Everyone gets logged out once. Web UI and clients using the Navidrome API need to log in again. Subsonic clients authenticate per request, so they are unaffected.
  • Song IDs change, album and artist IDs do not. Clients that cache song IDs (offline downloads, cached playlists) may need a re-sync.
  • Cover art gets re-fetched, so the first browse after upgrading is slower.
  • Share links keep working.
  • Nothing is lost: favorites, ratings, play counts, bookmarks, play queues, scrobble history and Last.fm / ListenBrainz links all survive. No rescan needed.
  • One manual fix: .nsp smart playlists using inPlaylist or notInPlaylist keep the old playlist ID on disk and need updating by hand.

Full write-up: https://gist.github.com/deluan/917ebc243c8b486101de857ffae6739b

If you can, please test it with your favourite client once it is merged, and reply here (or on our Discord) if anything looks off.

EDIT: For app/client developers: I'll merge the topSongsByArtistId PR at the same time as this ID migration. This means that you'll be able to detect if a server is migrated by checking the getOpenSubsonicExtensions response and looking for the topSongsByArtistId extension.

57
submitted 3 weeks ago* (last edited 3 weeks ago) by Deebster@infosec.pub to c/canvas@toast.ooo
36
submitted 3 weeks ago* (last edited 3 weeks ago) by Deebster@infosec.pub to c/canvas@toast.ooo

This is good fun, as always, but I've gone afk and am not enjoying the mobile experience as much as desktop because I keep having to click through the welcome modal and/or deal with a screen covered in duplicate (and superseded) errors. Sometimes it's more errors than fit on the screen so I get it multiple times.

Please only one of each error.

42
submitted 3 weeks ago* (last edited 3 weeks ago) by Deebster@infosec.pub to c/canvas@toast.ooo
20

I'm a little late with this news, but it's a good write-up.

The unread file was src/_probe/never_read_canary.txt, planted with a unique marker. Cloning the captured bundle recovered it verbatim along with the repo's full commit history, and the same test replicated on a second, unrelated repo.

12
submitted 2 months ago by Deebster@infosec.pub to c/gentoo@reddthat.com

The Linux kernel has recently been facing a series of discovered privilege escalation vulnerabilities, starting with the Copy Fail vulnerability and followed by subsequent vulnerabilities in the same spirit (Dirty Frag, Fragnesia). This development is part of a general trend where vulnerabilities are being found - and disclosed - faster than before. We expect it to continue, at least for the short-term.

The Gentoo Linux Kernel and Distribution Kernel teams are doing their best to keep Gentoo kernels secure. This includes both packaging the latest upstream releases as soon as possible, and backporting additional vulnerability fixes or mitigations whenever they become available. As example, while upstream kernel releases are still vulnerable to Fragnesia, the respective Gentoo kernels feature fixes from day one. At the time of writing, all supported Gentoo kernels feature the latest Fragnesia v5 patch. Please expect more updates. We recommend exploring ways to automate upgrading your kernel.

Please note that only sys-kernel/gentoo-kernel, sys-kernel/gentoo-kernel-bin and sys-kernel/gentoo-sources packages are security-supported. The vanilla kernel packages are vulnerable at the moment. Other kernel packages may carry fixes, but they usually are slower to be updated. Additionally, we recommend running the latest kernel version (~arch or latest stable LTS), as upstream does not reliably backport security fixes to older versions.

[-] Deebster@infosec.pub 150 points 3 months ago* (last edited 3 months ago)

My first thought was that Benn Jordan did a great bit of video journalism on this, but it's already linked from the article, although without any other mention of it.

22

CPUID has since confirmed the breach, pinning it on a compromised backend component rather than tampering with its software builds.

"Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display malicious links (our signed original files were not compromised)," one of the site's owners said in a post on X. "The breach was found and has since been fixed."

36
submitted 4 months ago by Deebster@infosec.pub to c/amiga@sopuli.xyz

Original IFF Deluxe Paint images from back in the day, courtesy of the Amiga Graphics Archive.

This is the one that always makes me think of DPaint:

source

11
submitted 4 months ago* (last edited 4 months ago) by Deebster@infosec.pub to c/chrisspargo@feddit.uk

My favourite bit is this from the comments:

I wrote "please do not deliver this letter" on a correctly addressed and stamped letter once, it never arrived. A thrilling day indeed.

37
submitted 5 months ago* (last edited 5 months ago) by Deebster@infosec.pub to c/unitedkingdom@feddit.uk

I love Doom Bar and I'm not alone since it's among the bestselling cask ales in the UK, but it seems that the US owners are going for a quick payout by closing and asset stripping what's left.

I wonder how long until they start building houses or an industrial park on the old site?

6
submitted 6 months ago by Deebster@infosec.pub to c/chrisspargo@feddit.uk

This video covers Great Ormond Street Hospital, Quality Street and copyright special cases.

view more: next ›

Deebster

joined 2 years ago