What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0
0
0
0
0
0
0
0
0

“frozen confection of attractive appearance, which can be conveniently consumed without contamination by contact with the hand and without the need for a plate, spoon, fork or other implement” 🍧 kqed.org/bayareabites/98186/ho

0
0

🍏튜링의 사과 2월 요금개편 안내 (2월 9일차주 적용)

안녕하세요 튜링의사과 입니다.
2026년 추가 공간 구성으로 2월을 맞이하여 요금 개편 통해 저렴하게 이용 하실 수 있도록 패키지를 구성하였습니다.

최저 900원 안되는 요금😮으로 이용을 하실 수 있게 마련을 해봤습니다.
많은 분들이 저렴하게 쓰시면 좋지만 좌석이 여유치 않아 튜링의 사과 컨셉 맞춰 (집중된 공간을 제공을 위해) 선착순으로 문의를 통해 패키지를 구매 하실 수 있습니다.🤩

패키지 요금은 금일 부터 선착순으로 문의를 받고 있으니 참고부탁드립니다.(디코⁠🎟∙티켓 문의)

평일 프리패스(월, 금)
30일 프리패스 (월 ~ 금+주말 포함)
직장인 패스 (월 ~ 금19시 ~ 23시)

추가안내
-몰입형 12시간권은 결제 시점부터 유효기간 3개월로 제한되며 3개월(90일) 이후 소멸됩니다.
-기존 12시간권 결제자 분들은 유효기간 없이 이용 가능합니다.
-자율형 좌석은 당일 강연이 있을 시 (몰입형 공간으로 안내)

0


일본 여행가서 캡슐 호텔(사진 처럼 자는 곳이 세로로 배치된 전통적인 캡슐 호텔 한정, 자는 곳이 가로로 배치된 캡슐 호텔이나 1층만 있는 캡슐 호텔은 해당 안됨)에서 자본 적이

0

“We are at a turning point in how we exist online,” says @jazjaz :twt: :wales_flag:, Director at Tŵt Cymru. “The legacy platforms are failing to provide safe, joyful spaces for community connection. By focusing on the “pethau bychain”, we are proving that digital sovereignty isn’t just about technology; it’s about hospitality, kindness, and taking control of our own digital heritage. This is our cyfraniad to Cymru – our contribution to the nation.”


newsfromwales.co.uk/gwnewch-y-

0
0
1
0
2
0
0
0
2
2
0
0
0
0
0

우리의 운명은 선택의 연속

1. 두려움보다 용기를 선택하라
2. 실패를 성장의 기회로 여기자
3. 작은 변화가 큰 변화를 만든다
4. 자신을 믿는 힘을 키워라
5. 현재에 최선을 다하면 미래가 열린다
6. 인생은 짧으니 후회 말고 도전하라
7. 긍정적인 마인드로 길을 열어가자

0

A big and warm thank you hug to all the friends I met and talked to in Brussels this time. Two packed days of events before including an awesome prize ceremony, then two intense days at ULB where I must have talked to more than a hundred persons. All the positivity, the appreciation, the smiles, the ideas, the energy.

I got to end-keynote the thing and then top it off with more drinks and countless friends - again.

I'm drained now, but in a good way. I'll be back next year.

0

다음 타자는 오라클입니다 ㅎㅎ 보면 AI 자체가 문제가 아님 무리하게 투자했다가 수습을 못하는 경우가 생기니까 문제인데 닷컴 버블때도 그랬던것 같음 기술 자체의 문제라기보단 다들 너무 희망회로를 많이 돌리고 무리하게 투자를 했던것 같고...

RE: https://bsky.app/profile/did:plc:43fdk46qa5gsokzygzildsaq/post/3mduigr6d2l2j

0
0

다음 타자는 오라클입니다 ㅎㅎ 보면 AI 자체가 문제가 아님 무리하게 투자했다가 수습을 못하는 경우가 생기니까 문제인데 닷컴 버블때도 그랬던것 같음 기술 자체의 문제라기보단 다들 너무 희망회로를 많이 돌리고 무리하게 투자를 했던것 같고...

RE: https://bsky.app/profile/did:plc:43fdk46qa5gsokzygzildsaq/post/3mduigr6d2l2j

0
0
0

"If it looks like fascism, sounds like fascism, acts like fascism, dresses like fascism, talks like fascism, kills like fascism, and lies like fascism - brothers and sisters, it's fucking fascism."

youtube.com/watch?v=LLMKAxFtjB8

Ladies and gentlemen, the citizens of Minneapolis filling in for Zack de la Rocha.

0
0
0
1
0
Notepad++ 更新機制遭具國家背景的攻擊者劫持 https://notepad-plus-plus.org/news/hijacked-incident-info-update/ 😱

Notepad++ 官方在延續 v8.8.9 的資安揭露後更新調查結果,指出這起「被疑似國家級駭客劫持」事件的攻擊點在共享主機商的基礎設施層,而非 Notepad++ 程式碼本身的弱點。攻擊者能在特定條件下攔截並重導原本要到 notepad-plus-plus.org 的更新請求,對被鎖定的使用者回傳惡意更新清單(update manifest),再把下載導向攻擊者控制的主機,藉此散布被動手腳的更新安裝檔。由於鎖定對象高度選擇性,研究人員研判幕後可能是中國國家級駭客團體,事件最早可追溯到 2025 年 6 月。

前主機商提供的紀錄顯示,承載更新端點的共享伺服器在 2025 年 9 月 2 日前可能遭入侵;該日進行包含 kernel 與 firmware 更新的維護後,疑似已中斷攻擊者對伺服器本體的存取。但主機商也承認,攻擊者仍可能保有伺服器上的內部服務憑證直到 2025 年 12 月 2 日,使其得以把部分更新流量重導到外部伺服器並回傳遭竄改的下載網址。主機商稱未見其他同機客戶遭鎖定,攻擊者是針對 Notepad++ 網域下手,並意圖利用舊版更新驗證控管不足;後續已修補可能被用來針對 Notepad++ 的弱點、輪替相關憑證並全面稽核其他主機。由於外部專家判定攻擊在 11 月 10 日已停止,但主機商推估仍可能影響到 12 月 2 日,作者綜合兩者把整體風險期間估為 2025 年 6 月至 12 月 2 日。

為善後與強化防護,Notepad++ 網站已移轉到新的主機商,宣稱具備更強的資安作法;軟體端則在 v8.8.9 強化 WinGup 更新器,新增對下載安裝檔進行憑證與數位簽章驗證,並將更新伺服器回傳的 XML 以 XMLDSig (XML Digital Signature,XML 數位簽章) 簽署,預計在約一個月後的 v8.9.2 起強制驗證。主機商也建議若先前尚未處理,應更換 SSH (Secure Shell,遠端登入協定)、FTP (File Transfer Protocol,檔案傳輸協定)/SFTP (SSH File Transfer Protocol,基於 SSH 的檔案傳輸) 與 MySQL (關聯式資料庫) 等憑證,並檢查 WordPress 管理者帳號、更新 WordPress 外掛與佈景主題及核心版本、視情況開啟自動更新。

Hacker News 討論串多數把這起事件視為典型「供應鏈攻擊」(透過更新機制把惡意內容送進終端環境),擔憂使用者在 Notepad++ 內開啟的機密是否可能被監看或外流,也質疑公告對「哪些人被鎖定、如何被鎖定」仍偏模糊,並呼籲公開主機商名稱以利風險辨識。也有人推測動機可能與 Notepad++ 過去在版本公告中高調談及台灣、烏克蘭、維吾爾等政治議題有關。技術面則出現對更新驗證的辯論:有人主張簽章驗證應與不同伺服器分離,但也有人反駁更關鍵的是把開發者公鑰內建在軟體內、私鑰以 HSM (Hardware Security Module,硬體安全模組) 保護並具備撤銷或告警機制,單純多一台伺服器提升有限;另有人建議改用套件管理工具可降低內建更新器遭劫持的風險(但安裝檔本身仍可能成為目標)。此外也有人追問既然更新端點是 HTTPS,為何仍能重導,凸顯即使有 TLS (Transport Layer Security,傳輸層安全) 加密,只要攻擊者控制了供應端的主機或回應內容,使用者端依然可能在「看似安全的連線」下被餵送惡意更新。

https://news.ycombinator.com/item?id=46851548
0
Notepad++ 更新機制遭具國家背景的攻擊者劫持 https://notepad-plus-plus.org/news/hijacked-incident-info-update/ 😱

Notepad++ 官方在延續 v8.8.9 的資安揭露後更新調查結果,指出這起「被疑似國家級駭客劫持」事件的攻擊點在共享主機商的基礎設施層,而非 Notepad++ 程式碼本身的弱點。攻擊者能在特定條件下攔截並重導原本要到 notepad-plus-plus.org 的更新請求,對被鎖定的使用者回傳惡意更新清單(update manifest),再把下載導向攻擊者控制的主機,藉此散布被動手腳的更新安裝檔。由於鎖定對象高度選擇性,研究人員研判幕後可能是中國國家級駭客團體,事件最早可追溯到 2025 年 6 月。

前主機商提供的紀錄顯示,承載更新端點的共享伺服器在 2025 年 9 月 2 日前可能遭入侵;該日進行包含 kernel 與 firmware 更新的維護後,疑似已中斷攻擊者對伺服器本體的存取。但主機商也承認,攻擊者仍可能保有伺服器上的內部服務憑證直到 2025 年 12 月 2 日,使其得以把部分更新流量重導到外部伺服器並回傳遭竄改的下載網址。主機商稱未見其他同機客戶遭鎖定,攻擊者是針對 Notepad++ 網域下手,並意圖利用舊版更新驗證控管不足;後續已修補可能被用來針對 Notepad++ 的弱點、輪替相關憑證並全面稽核其他主機。由於外部專家判定攻擊在 11 月 10 日已停止,但主機商推估仍可能影響到 12 月 2 日,作者綜合兩者把整體風險期間估為 2025 年 6 月至 12 月 2 日。

為善後與強化防護,Notepad++ 網站已移轉到新的主機商,宣稱具備更強的資安作法;軟體端則在 v8.8.9 強化 WinGup 更新器,新增對下載安裝檔進行憑證與數位簽章驗證,並將更新伺服器回傳的 XML 以 XMLDSig (XML Digital Signature,XML 數位簽章) 簽署,預計在約一個月後的 v8.9.2 起強制驗證。主機商也建議若先前尚未處理,應更換 SSH (Secure Shell,遠端登入協定)、FTP (File Transfer Protocol,檔案傳輸協定)/SFTP (SSH File Transfer Protocol,基於 SSH 的檔案傳輸) 與 MySQL (關聯式資料庫) 等憑證,並檢查 WordPress 管理者帳號、更新 WordPress 外掛與佈景主題及核心版本、視情況開啟自動更新。

Hacker News 討論串多數把這起事件視為典型「供應鏈攻擊」(透過更新機制把惡意內容送進終端環境),擔憂使用者在 Notepad++ 內開啟的機密是否可能被監看或外流,也質疑公告對「哪些人被鎖定、如何被鎖定」仍偏模糊,並呼籲公開主機商名稱以利風險辨識。也有人推測動機可能與 Notepad++ 過去在版本公告中高調談及台灣、烏克蘭、維吾爾等政治議題有關。技術面則出現對更新驗證的辯論:有人主張簽章驗證應與不同伺服器分離,但也有人反駁更關鍵的是把開發者公鑰內建在軟體內、私鑰以 HSM (Hardware Security Module,硬體安全模組) 保護並具備撤銷或告警機制,單純多一台伺服器提升有限;另有人建議改用套件管理工具可降低內建更新器遭劫持的風險(但安裝檔本身仍可能成為目標)。此外也有人追問既然更新端點是 HTTPS,為何仍能重導,凸顯即使有 TLS (Transport Layer Security,傳輸層安全) 加密,只要攻擊者控制了供應端的主機或回應內容,使用者端依然可能在「看似安全的連線」下被餵送惡意更新。

https://news.ycombinator.com/item?id=46851548
0
0

마이크로소프트 이놈들은 워드 엑셀 파워포인트 뷰어를 없애버렸으면서 워드 엑셀 파워포인트를 리드온리모드로 쓰려고하면 섭스크립션에 돈내라고 3번식 물어본다.

0
0
0
0

The so-called ‘peace plan’ for Gaza is instituting foreign control - as in Bosnia.

"Ordinary Bosnian citizens were excluded from the process".

It's the same logic re Gaza: "peace negotiated about a people, not with them."

"Bosnia became a semi-protectorate, a territory governed from the outside... & without democratic sovereignty in which those who hold decision-making power cannot be held accountable."

aljazeera.com/opinions/2026/2/

.

0
0
0
0
0
0

The UN agency for Palestinian refugees (UNRWA) has warned that the occupied West Bank is experiencing a “silent war” marked by unprecedented levels of Israeli military and settler violence since October 2023.

UNRWA Commissioner-General Philippe Lazzarini said tens of thousands of Palestinians remain displaced following Israel’s large-scale operation “Iron Wall,” the biggest displacement since 1967, with homes being demolished to prevent residents from returning.

Since October 2023, more than 1,000 Palestinians were killed in the West Bank, nearly a quarter of them children. Israeli settler attacks also continued unchecked, leading to intimidation, destruction of livelihoods, and widespread impunity.

0
0
0
0
1
0

“We are at a turning point in how we exist online,” says @jazjaz :twt: :wales_flag:, Director at Tŵt Cymru. “The legacy platforms are failing to provide safe, joyful spaces for community connection. By focusing on the “pethau bychain”, we are proving that digital sovereignty isn’t just about technology; it’s about hospitality, kindness, and taking control of our own digital heritage. This is our cyfraniad to Cymru – our contribution to the nation.”


newsfromwales.co.uk/gwnewch-y-

0
0
1
0