Mastodon Feed: Posts

Mastodon Feed

Boosted by jwz:
davidgerard@circumstances.run ("David Gerard") wrote:

Web4 will be fought with telnet to port 80

Mastodon Feed

Boosted by jwz:
jalefkowit@vmst.io ("Jason Lefkowitz") wrote:

Hard to read this as anything other than a torpedo directly under the waterline of FedRAMP's credibility

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government

The program’s layers of review, which included an assessment by outside experts, were supposed to ensure that service providers like Microsoft could be entrusted with the government’s secrets. But ProPublica’s investigation — drawn from internal FedRAMP memos, logs, emails, meeting minutes, and interviews with seven former and current government employees and contractors — found breakdowns at every juncture of that process. It also found a remarkable deference to Microsoft, even as the company’s products and practices were central to two of the most damaging cyberattacks ever carried out against the government. FedRAMP first raised questions about GCC High’s security in 2020 and asked Microsoft to provide detailed diagrams explaining its encryption practices. But when the company produced what FedRAMP considered to be only partial information, program officials did not reject Microsoft’s application. Instead, they repeatedly pulled punches and allowed the review to drag out for five years. And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but on the grounds that Microsoft’s product was already being used across Washington.

Mastodon Feed

Boosted by jwz:
gknauss ("Greg Knauss") wrote:

It’s a little known rule, but if you rename a corporation after a technology and then abandon that technology within five years, you have to dissolve the entire company out of embarrassment.

Mastodon Feed

Boosted by jwz:
georgespolitzer@monads.online ("[UNC] Alpha Panda") wrote:

Mastodon Feed

Boosted by jwz:
fasterandworse@hci.social ("Stephen Farrugia") wrote:

Never before has “I work in the tech industry” sounded so much like “I work in the tobacco industry”

Mastodon Feed

soatok@furry.engineer ("Soatok Dreamseeker") wrote:

wHY ISN'T the coffee working

Mastodon Feed

db@social.lol ("David Bushell 🪿") wrote:

i went outside today

Apple Stores do replace key caps for free

but they don't have right arrow keys in stock

so i gotta go outside again when they send the bat signal or something

Mastodon Feed

Boosted by fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷"):
so_treu@blackqueer.life ("RI DaSēr K") wrote:

RE: https://blackqueer.life/@so%5Ftreu/116251308180717654

Thanks so much for rocking with me y'all. In the short term, I have a phone bill due on Friday and an appt I need to uber to tomorrow, so there’s an immediate goal of $160!!!

http://cash.app/$sotreu2
http://venmo.com/sotreu
http://paypal.me/rikiam

#MutualAid #MutualAidRequest #HelpFolksLive2026

Mastodon Feed

Boosted by soatok@furry.engineer ("Soatok Dreamseeker"):
timbray@cosocial.ca ("Tim Bray") wrote:

RE: https://mstdn.social/@jschauma/116251321191395352

Why not both?

Mastodon Feed

soatok@furry.engineer ("Soatok Dreamseeker") wrote:

No ETA on the new blog post because I went to Taiwan for a week for https://rwc.iacr.org/2026 and I'm still exhausted

Mastodon Feed

fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷") wrote:

I might be the best baker of all time

1⅓ cup flour 1 my fav coffee mug's worth of brown sugar 1 little baking soda A couple pinches salt 3 Splenda packets worth of cinnamon roughly 1 not a lot but an okay amount of cocoa powder ½ bag chocolate chips 2ish eggs 3 bananas or 2 or 4 ½ thing of butter 1 splish splash olive oil 1 splash milk 4 drips of vanilla

Mastodon Feed

Boosted by glyph ("Glyph"):
mhoye@cosocial.ca wrote:

It's a very hard pill to swallow, especially given the panoptic, reflexive cruelty of this grudgefuck of a zeitgeist we're all presently stewing in and how easy it is to hit that boost or reply button, but one of the awful facts about high-semiotic-density memetic culture is that you might very easily be amplifying - and legitimizing - ideological positions you _don't even realize exist_ through the wonders of near-zero-friction and pushback-free participation.

Mastodon Feed

Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
jessie ("Jess Rose") wrote:

US, NYC, Hybrid:
ACLU are a nonprofit who defend free speech and civil rights.

Product Manager, Technology: to $137k, 2 days a week in office, working across both analytics and product teams
https://job-boards.greenhouse.io/aclu/jobs/8220646002

Director of Engineering, Data: $220k, 2 days a week in office, leading the data engineering team and line managing
https://job-boards.greenhouse.io/aclu/jobs/8417408002

Mastodon Feed

Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
neil@mastodon.neilzone.co.uk ("Neil Brown") wrote:

Walk around spraying salty water on metal, and you too have experience as a rust developer.

Mastodon Feed

jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:

there will be more of this: https://techcrunch.com/2026/03/17/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices/

Mastodon Feed

Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
colarusso_algo ("David's Alter (Algo) Ego") wrote:

Edison Carter: What happened to the old religions?

Murray: I don't know. Television killed it. We have better miracles.

Mastodon Feed

Boosted by soatok@furry.engineer ("Soatok Dreamseeker"):
munin@infosec.exchange ("Fi 🏳️‍⚧️") wrote:

Really, in the US, there's no way for cops to be held accountable thru legal means, given the incredibly unjust doctrines surrounding "qualified immunity".

So seeing them in a situation where they are able to be humiliated publicly at a national scale for their unjust and damaging actions is about all the catharsis that we can get these days.

Mastodon Feed

Boosted by fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷"):
Tarnport@mastodon.green wrote:

I was urging someone younger today to really appreciate the regional accents of the old folks around them, because after tv and other media spread, accents started to die and our generation will pretty much live to see the end of them. I've already outlived many I remember personally. I miss them - perhaps especially the ones that at the time I considered bumpkin.

Mastodon Feed

dysfun@treehouse.systems ("gaytabase") wrote:

i have just transcribed all of the gcc custom function attributes into an ADT. it is a rather chonky ADT

Mastodon Feed

typst ("Typst") wrote:

In the penultimate talk of the meetup, Kyano rings the alarm bell: HTML with packages is the wild west! What standards could the ecosystem converge upon? Let's kickstart a discussion before it's too late.

https://youtu.be/KETMlZ4He9k

#Typst

Video thumbnail: Kyano in front of a HTML doctype tag and a box where "Standards" are rated with two stars. Caption is "HTML for packages".

Mastodon Feed

Boosted by fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷"):
Wearwolf@kind.social ("Kyle Brown :DBFHBear:") wrote:

There is a legit problem in the industry right now where management sees AI as a way to tighten deadlines and then tight deadlines then encourage the use of AI

It's a race to the bottom and it's not going to end well

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

This is a power play. By giving away the farm to native apps while keeping the web at bay, they play out enclosure and lock-in strategies.

First, they build non-standard versions of commodity features. Next, get anchor apps to build to those APIs, forcing App Stores distribution. Step 3? Profit.

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

The security story that is sold to users is cover; a way to make the deeply rotten design choice to give away the farm to Zuck et. al. seem like it is being done on the user's behalf. But it was never true.

The only thing that *really* protects users is the runtime (the OS container or the browser engine):

https://infrequently.org/2026/01/naked-power/#the-security-argument

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

The past decade of mobile has been characterised, primarily, by the duopolists trying to take credit for infinitesimal reductions in the overpowered access to your most private devices that they give to app developers as inducement to continue building to proprietary APIs.

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

Apple and Google promoted insecure native apps as "safe" thanks to "beware of dog" signs posted in front of their poorly-tended walled gardens.

It was enough to get everyone locked in, but never delivered security. Browsers, on the other hand, don't allow this sort of predation in the first place.

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

Back in '21, court filings recounted an Apple engineer characterising Cupertino's App Store protections as "bringing a plastic butter knife to a gunfight". And for however bad Apple has been (terrible), Play was always worse.

So how's that going? Oof:

https://www.pcmag.com/news/study-reveals-googles-play-store-is-main-distributor-of-malicious-apps

Mastodon Feed

slightlyoff@toot.cafe ("Alex Russell") wrote:

The fundamental insecurity of native apps, and the role of App Stores in a cover-up of that essential fact cannot be stressed enough.

The always-suspect security of stores creates the mythos that enables the whole extractive App Store racket. Without the patina of security, giving away ridiculous amounts of user data and system access to any app the user installs would never pass muster.

Which is why browsers don't do that.

Mastodon Feed

baldur@toot.cafe ("Baldur Bjarnason") wrote:

Basically: "we were doing a great job, everybody said so! What are you talking about?"

Mastodon Feed

baldur@toot.cafe ("Baldur Bjarnason") wrote:

RE: https://toot.cafe/@baldur/116239014761650611

A criticism of this post that took me by a bit of a surprise involves replies from people completely unaware of anybody having any kind of concern about the state of software development, let alone worried to the point of thinking a crisis was developing.

Mastodon Feed

Boosted by fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷"):
fromjason ("fromjason.xyz ❤️ 💻 ✍️ 🥐 🇵🇷") wrote:

How to scare us into voting for dog shit candidates:

1. Scientific data proves Trump is dictatoring! We're doomed!
2. Unless...👀 wait a minute elections still work!
3. Oh, Trump is super unpopular with voters now! Guess they'll need a new political home 🤷‍♂️

It's the same article over and over again since 2016.

It's not trying to get us to fight authoritarianism. It's priming us to reject progressive ideas in fear of losing the mythical "reasonable republican".

https://www.theguardian.com/world/commentisfree/2026/mar/17/trump-is-aiming-for-dictatorship-thats-the-verdict-of-the-worlds-most-credible-democracy-watchdog