What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

AAAARGH! I'm not at all surprised, but NIST's excellent whitepaper on Inclusive Language (NIST.IR.8366) has been withdrawn:

nvlpubs.nist.gov/nistpubs/ir/2

This was an excellent resource that I reference all the time. I feared it would go away so I made a snapshot a few weeks back that I uploaded here: nygren.org/archived/NIST.IR.83

0
0
0

โ€œOn Monday, Donald Trumpโ€™s Department of Justice made two arguments in two different courts that, taken together, amount to a legal claim of near-dictatorial power by Trump.โ€

That is, a claim of unreviewable, unstoppable, limitless power by Trump.

Will people finally stop saying the US is โ€œheaded towardsโ€ a Constitutional crisis and finally understand that it already happened. The coup is already in place. The question is whether Americans can overthrow it.

slate.com/news-and-politics/20

0
0
0
0
0

3/26-29ใฎ่ƒฝ็™ป่ขซ็ฝๅœฐ่กŒใใฏ้ †่ชฟใงใ™ใ€‚
่จˆ6ไบบใงๆฑบ่กŒใ—ใพใ™ใ€‚

็พๅœจ้ƒฝๅ†…ใงๅพ…ใกๅˆใ‚ใ›ไธญโ€ฆใ€‚
้–ข่ถŠ้“ใ€ไธŠไฟก่ถŠ้“็ตŒ็”ฑใ€ๅฐๆ‰ใ‚คใƒณใ‚ฟใƒผใƒใ‚งใƒณใ‚ธใพใง้ซ˜้€Ÿ้“่ทฏใฎ็„กๅ„ŸๅŒ–ๆŽช็ฝฎใ‚’ๅˆฉ็”จใ—ใพใ™ใ€‚

็„กๅ„ŸๅŒ–ๆŽช็ฝฎใฏไปŠใฎใจใ“ใ‚2025ๅนด6ๆœˆๆœซใพใงๆœ‰ๅŠนใงใ™ใ€‚ใ“ใฎใ‚ตใ‚คใƒˆใ‹ใ‚‰้€š่กŒ่จผๆ˜Žๆ›ธใ‚’็™บ่กŒใงใใพใ™๏ผ
exvolunteer.jp/VoUsr010/linkDi

0
0
0
0

ํ˜„์žฌ์ƒํ™ฉ 1. ๊ฒฌ์ธ์ฐจ ์•ž ์ •ํ˜œ๊ฒฝ ์˜์›, ์—ฌ์„ฑ๋†๋ฏผ ๋“ฑ ๋‚จ์„ฑ๊ฒฝ์ฐฐ๋“ค์ด ์‚ฌ์ง€ ๋“ค์–ด ๋Œ์–ด๋ƒ„ 2. ๊ฒฝ๋น„๊ณผ์žฅ ํ•ฉ๋ฒ•์ ์ง‘ํšŒ์žฅ์—์„œ ์ง์ ‘ ์ง€์‹œํ•˜๋ฉฐ ๋Œ์–ด๋‚ด๋ผ ์ง€์‹œ 3. ๊ฒฝ๋น„๊ณผ์žฅ ์Šค์Šค๋กœ ๋„˜์–ด์ ธ๋†“๊ณ  ํญํ–‰ํ˜„ํ–‰๋ฒ”์ด๋ผ๋ฉฐ ์ •์šฉ์ค€ ์ƒํ™ฉ์‹ค์žฅ ๋ถˆ๋ฒ• ์—ฐํ–‰ ์‹œ๋ฏผ์—ฌ๋Ÿฌ๋ถ„ ๊ด‘ํ™”๋ฌธ์œผ๋กœ ๋ชจ์—ฌ์ฃผ์„ธ์š”! [๋น„์ƒํ–‰๋™ ์‹ฌ๊ทœํ˜‘ ์‚ฌ๋ฌด๊ตญ์žฅ ํŽ˜๋ถ]

0

ํŠธ๋ž™ํ„ฐ์— ๋ง‰ํžŒ ๋‚จํƒœ๋ น ๊ณ ๊ฐœโ€ฆํ‡ด๊ทผ๊ธธ ์‹œ๋ฏผ๋“ค "์ •์น˜ ์‹ธ์›€ ๋„ ๋„˜์—ˆ๋‹ค"

n.news.naver.com/article/025/0

์ƒ์กด์„ ์œ„ํ•ด ํˆฌ์Ÿ๊ณผ ์‹œ์œ„๋ฅผ ํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์„ ์ถœํ‡ด๊ทผ ํ•˜๋Š” ์‚ฌ๋žŒ๋“ค์ด ๋ถˆํŽธํ•˜๋‹ค๋Š” ํ•‘๊ณ„๋Œ€๋ฉฐ ์•ž์„œ์„œ ๋น„๋‚œํ•˜๋Š” ์–ธ๋ก  ๋ฌธํ™”๊ฐ€ ์ข€ ๋ฐ”๋€Œ์–ด์•ผ.

0
0
0
0

Wow, this Pixelfed bug is *nasty*. Allowed users to access private posts of remote users they're not following so long as another user on the same Pixelfed server legitimately followed that account.

If you're running a Pixelfed server, definitely upgrade immediately now that the vulnerability is publicly known.

fokus.cool/2025/03/25/pixelfed

0

Really enjoying Ghostโ€™s new ActivityPub feature by @index@activitypub.ghost.orgBuilding ActivityPub.

Itโ€™s been a while since something genuinely felt like the future of the web, and this really does. As more features come online, I might even make that my primary social web account.

Think about that. My blog could be the medium through which I interact with the rest of the web!

If you want to get a head start, you can already follow my blog @index@thoughtcicles.xyzThoughtcicles. Iโ€™ll post more about this, soon.

0
0

Uh, is it normal for an automated scanner to be unaware of patched packages?

Like how OpenSSH 9.2p1 is vulnerable to CVE-2023-38408 but the Debian version 1:9.2p1-2+deb12u5 is patched. But the security scanner sees the "9.2p1" string and sounds the alarm.

security-tracker.debian.org/tr

Is this a common problem for people running Debian servers?

@teleclimberOlivier Forget Yes. Most security scanners (Pentesters) are that stupid.

I speak from experience, trying to tell customers that just because it said the server they installed have a vulnerable version of something or other installed, that's not actually the case.

The ones that *actually* try to break stuff (like using known issues, fuzzing input and such) are great, though. Use those.

0
0
0
0

์ง„๋ณด๋‹น ๊น€์žฌ์—ฐ: ํŠธ๋ž™ํ„ฐ ์•ž์„ ์ง€ํ‚ค๋˜ ์ •ํ˜œ๊ฒฝ ์˜์›๊ณผ ์—ฌ์„ฑ ๋†๋ฏผ๋“ค์€ ์‚ฌ์ง€๊ฐ€ ๋“ค๋ ค ๋Œ๋ ค๋‚˜์˜ค๊ณ , ํŠธ๋ž™ํ„ฐ๋Š” ๊ฒฌ์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋„๋Œ€์ฒด ์ด ๋‚˜๋ผ ๊ณต๊ถŒ๋ ฅ์€ ๋ˆ„๊ตฌ๋ฅผ ์ง€ํ‚ค๋Š” ๊ฒ๋‹ˆ๊นŒ!!! x.com/jaeyeon80/st...

x.com/jaeyeon80/stat...

0
0
0
0
0
0

ํ˜„์žฌ์ƒํ™ฉ 1. ๊ฒฌ์ธ์ฐจ ์•ž ์ •ํ˜œ๊ฒฝ ์˜์›, ์—ฌ์„ฑ๋†๋ฏผ ๋“ฑ ๋‚จ์„ฑ๊ฒฝ์ฐฐ๋“ค์ด ์‚ฌ์ง€ ๋“ค์–ด ๋Œ์–ด๋ƒ„ 2. ๊ฒฝ๋น„๊ณผ์žฅ ํ•ฉ๋ฒ•์ ์ง‘ํšŒ์žฅ์—์„œ ์ง์ ‘ ์ง€์‹œํ•˜๋ฉฐ ๋Œ์–ด๋‚ด๋ผ ์ง€์‹œ 3. ๊ฒฝ๋น„๊ณผ์žฅ ์Šค์Šค๋กœ ๋„˜์–ด์ ธ๋†“๊ณ  ํญํ–‰ํ˜„ํ–‰๋ฒ”์ด๋ผ๋ฉฐ ์ •์šฉ์ค€ ์ƒํ™ฉ์‹ค์žฅ ๋ถˆ๋ฒ• ์—ฐํ–‰ ์‹œ๋ฏผ์—ฌ๋Ÿฌ๋ถ„ ๊ด‘ํ™”๋ฌธ์œผ๋กœ ๋ชจ์—ฌ์ฃผ์„ธ์š”! [๋น„์ƒํ–‰๋™ ์‹ฌ๊ทœํ˜‘ ์‚ฌ๋ฌด๊ตญ์žฅ ํŽ˜๋ถ]

0
0
0

๐Ÿ‡ต๐Ÿ‡ธ Liste BDS mise ร  jour !

Pour รชtre efficace, le boycott doit รชtre ciblรฉ et stratรฉgique. Cโ€™est la diffรฉrence entre une dรฉmarche purement individuelle et la campagne BDS qui se veut un outil collectif de lutte contre lโ€™occupant israรฉlien et ses crimes.
Partagez au maximum ! ๐Ÿ“ฃ

Affiche de la campagne BDS (Boycott, Dรฉsinvestissement, Sanctions)  par le comitรฉ BDS Saint Etienne appelant au boycott de certaines entreprises en raison de leur implication dans le soutien ร  Israรซl.

L'affiche est divisรฉe en trois sections :

1 - Boycott des marques israรฉliennes : Logos de marques telles que SodaStream, Teva, Ahava, Moroccanoil, Mehadin, Hadiklaim, Jordan River, Stanley, Keter, Curver et Allibert.

2 - Boycott d'entreprises complices des crimes israรฉliens : Logos de grandes entreprises internationales, dont Carrefour, McDonald's, Coca-Cola, Reebok, HP et Siemens.

3 - Dรฉsinvestissement d'entreprises impliquรฉes : Logos de BNP Paribas, AXA, Intel, CAF et Elbit Systems, cette derniรจre รฉtant une entreprise d'armement.

L'affiche porte le slogan "Ne finanรงons pas le gรฉnocide" accompagnรฉ d'un drapeau palestinien.
0
0
0

Wow, this Pixelfed bug is *nasty*. Allowed users to access private posts of remote users they're not following so long as another user on the same Pixelfed server legitimately followed that account.

If you're running a Pixelfed server, definitely upgrade immediately now that the vulnerability is publicly known.

fokus.cool/2025/03/25/pixelfed

0
0
0

Really enjoying Ghostโ€™s new ActivityPub feature by @index@activitypub.ghost.orgBuilding ActivityPub.

Itโ€™s been a while since something genuinely felt like the future of the web, and this really does. As more features come online, I might even make that my primary social web account.

Think about that. My blog could be the medium through which I interact with the rest of the web!

If you want to get a head start, you can already follow my blog @index@thoughtcicles.xyzThoughtcicles. Iโ€™ll post more about this, soon.

0

ํŠธ๋Ÿผํ”„ ํ–‰์ •๋ถ€๊ฐ€ ์ „๋ฐฉ์œ„์ ์œผ๋กœ ์™ธ๊ตญ์ธ๋“ค์„ ์ฒดํฌยท๊ตฌ๊ธˆํ•˜๋ฉด์„œ ์œ ์—”๋ณธ๋ถ€ ์ง์›๋“ค๊นŒ์ง€ ์œ„ํ˜‘๊ฐ์„ ๋А๋ผ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์œ ์—”์€ ๋‰ด์š• ๋ณธ๋ถ€์— ๊ทผ๋ฌดํ•˜๋Š” ๋ชจ๋“  ์ง์›๊ณผ ๊ทธ ๊ฐ€์กฑ๋“ค์—๊ฒŒ ์œ ์—” ์‹ ๋ถ„์ฆ๊ณผ ๋น„์ž๊ฐ€ ํฌํ•จ๋œ ์—ฌ๊ถŒ ํŽ˜์ด์ง€ ์‚ฌ๋ณธ์„ ํ•ญ์ƒ ์†Œ์ง€ํ•˜๋ผ๊ณ  ๊ถŒ๊ณ ํ–ˆ์Šต๋‹ˆ๋‹ค.

๋ฏธ, ์ •์œค์„œ์”จ ๊ฐ™์€ ์˜์ฃผ๊ถŒ์ž๋„ โ€˜์ถ”๋ฐฉ ๋Œ€์ƒโ€™โ€ฆ์œ ์—” ์ง์›...

0

GitHub Actions now supports free-threaded Python!

I wrote up how to add it your workflows so you can start testing free-threaded Python 3.13 and 3.14 with either actions/setup-python or actions/setup-uv.

hugovk.dev/blog/2025/free-thre

0
0
0
0

I've just moved what I think is a leopard slug from the top of one of our bins to the flower bed where I struggled so much with SO MANY slugs last year.

I gather leopard slugs are more likely to eat other snails and slugs and the rotting plant matter, rather than my living plants. Fingers crossed ๐Ÿ˜…

0
0
0

All sizes in inches, price ($US) doesn't include shipping:

Watercolor painting:
3x3 inch (no matting): $25
6x6 inch (no matting): $50
10x10 inch (no matting): $75
10x10 inch with matting: $100

Acrylic painting:
6x6 inch on canvas: $60
8x8 inch on canvas: $80 g
10x10 inch on canvas: $100
12x12 inch on canvas: $120

16x20 on wood: $500

Payment: 50% down at start
remaining 50% plus shipping when piece is finished and approved by you

Payments/orders handled here:
ko-fi.com/pussreboots4573

0
0

It's shamelessness, lack of decency, lack of self-awareness, a broken psyche desperately hungry for ego reinforcement, will to power ... those are advantages in our system, adaptive qualities. That's what distinguishes the people in that chat, the people running things. They don't need to be smart.

0

๐Ÿ“‘ New on my postroll:

Pixelfed leaks private posts from other Fediverse instances - fiona fokus

There are right ways for a developer to respond to a responsible vulnerability disclosure.

This is not one of those ways, and demonstrates (once again) that the developer behind one of the most popular ActivityPub implementations is maybe not a great steward of the thing(s) he creates.

https://fokus.cool/2025/03/25/pixelfed-vulnerability.html

0
0
0

hot take: dealing with vuln disclosures can be really scary and carry a lot of shame and/or embarrassment, but if you can't handle that or if you're so immature that you don't even mention the issue in your release notes, you probably shouldn't be leading the development of multiple federated social network platforms

0

Now available: ORCID's 2024 Annual Report!
Highlights include:
โœ… Helping address the research integrity crisis through new Record Summaries and Trust Markers;
โš™๏ธ Improving data quality through automation and smart recommendations;
๐ŸŒ Expanding global participation we welcomed new consortia in Lebanon and Nigeria in 2024!

Explore the full report to see what we've accomplished togetherโ€”and don't forget to register for our April 1 Community Town Hall to learn what's next: info.orcid.org/now-available-o

Graphic showing three highlights from ORCID's 2024 Annual Report
0

(X์œ„ํ„ฐ๋ฐœ ์†๋ณด) ํŠธ๋ž™ํ„ฐ ์ผ๋ถ€๊ฐ€ ๊ด‘ํ™”๋ฌธ์œผ๋กœ ๊ฐ”๋Š”๋ฐ ๊ฒฝ์ฐฐ์— ์˜ํ•ด ๊ธฐ์Šต ๊ฒฌ์ธ๋‹นํ•˜๊ณ  ์žˆ์–ด์„œ ๋‹ค๋“ค ๊ด‘ํ™”๋ฌธ์œผ๋กœ ๋ชจ์—ฌ์ฃผ์…”์•ผ x.com/yoonoutactio...

์œค์„์—ด์ฆ‰๊ฐํ‡ด์ง„ยท์‚ฌํšŒ๋Œ€๊ฐœํ˜ ๋น„์ƒํ–‰๋™ on X: "[๊ธด๊ธ‰ ...

0
0
0

One of our highlights of 2024 was our work with the GNOME Foundation to make GNOME OS a viable daily driver for QA.

The project included migrating GNOME OS to systemd's new update system โ€” sysupdate โ€” which offers improved benefits such as immutability, auto-updating, and modernised security properties.

You can read the first blog post covering the project here: codethink.co.uk/articles/2024/

0