What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0
0
0
0
0
0
0
0
0
0

Signal is open source, so our code is regularly scrutinized in addition to regular formal audits. We also constantly monitor security@signal.org for any new reports, and we act on them with quickness while also working to protect the people who rely on us from outside threats like phishing with warnings and safeguards.

This is why Signal remains the gold standard for private, secure communications. 5/

0
0
0

pixelfed instance admins: Please update pixelfed to v0.12.5 asap. The version contains fixes for serious security vulnerabilities that I reported.
I will disclose further details about the vulnerabilities in about 24 hours.
:boost_requested:

Pixelfed before v0.12.5 has a vulnerability where it could leak your private posts, regardless of whether you are a Pixelfed user or not.
Admins should update ASAP.

When following someone from a different server on the Fediverse, the remote server decides whether you are allowed to do that. This enables features like locked accounts. Due to an implementation mistake, Pixelfed ignores this and allows anyone to follow even private accounts on other servers. If a legitimate user from a Pixelfed instance follows you on your locked account, anyone on that Pixelfed instance can read your private posts.

I wrote a blog post about how I found the vulnerability, how disclosure coordination went and general ramblings about Fediverse safety:
fokus.cool/2025/03/25/pixelfed

0
0
0

Right now there are a lot of new eyes on Signal, and not all of them are familiar with secure messaging and its nuances. Which means there’s misinfo flying around that might drive people away from Signal and private communications. 1/

0
0
0
0
0

@: 동지들 경찰 지금 2~3출 ->횡단보도까지 다 진 폈고 얼굴 확인, 기수들 현장 채증 후 즉시체포 중입니다 간청합니다 도움이 필요합니다 지금 즉시 경복궁역 3번 출구로 모여주십시요 현장 분위기가 예사롭지 않습니다 사람이 쓰러져도 신고를 안 해주고 모든 시민의 출입을 막으며 동지들을 에워싼 후 불법체포를 자행합니다 현재 현장에 여경(현재는 채증만 하는 중) 존재하며 경복궁역 일대를 모두 통제 중입니다 동지들 사이 퍼지고 있는 경복궁역 진입 가능 사잇길도 경찰이 돌아다닙니다 부디 몸 조심하세요 특히 기수분들이 가장 위험합니다

황 on X: "특히 기수분들!!!!!! 기수분들이 가...

0
0

When Signal was designed, our threat model was protecting the communications of civil society, journalists, just regular citizens ...

The threat model of military operations & sharing your hate of Europeans was not what Signal was designed for. Ephemeral messages and cryptographic deniability are not fit for communications that require accountability.
But I appreciate their effort to make government more efficient by adding journalists to the chat instead of requiring to go through FOIA.

0
0
0

Oh, great. had a broken implementation of "follower-only" posts, _and_ fucked up the disclosure / bugfix release process.

fokus.cool/2025/03/25/pixelfed

Summary of the bug: If you have a protected account (on Pixelfed, Mastodon, GTS, whatever) and a Pixelfed user followed you and got approved by you, _all_ users on that instance were now able to see your followers-only posts, not just the one you approved.

This also highlights an ActivityPub issue: If you approve someone's follow request, you're technically not granting that _user_ access, you giving their _instance_ access to your protected posts. And it's then up to that instance to behave in the correct way and only show your protected posts to those users you have actually accepted.

Sure, from a technical standpoint this might be obvious, but it can still be somewhat counterintuitive.

0
0
0
0

Really want a foursquare like thing for the fediverse. Could be a client app that just grabs GPS data and adds it to the post body if nothing else but that probably wouldn't go any where cause it's only fun when there is a certain mass of people also using the same tool

0
0
0
0

ATTENTION!!! IMPORTANT POLL!!!!
Question:
Do you recognize fedi-friends by their name first then picture, or picture first?

Please BOOST for added fun!
:Skeletor: :mastodon: :plushtodon:

0
0
0

To be clear, Trump does not have the authority to do this. The constitution explicitly states that "The Times, Places and Manner of holding Elections for Senators and Representatives, shall be prescribed in each State by the Legislature thereof; but the Congress may at any time by Law make or alter such Regulations, except as to the Places of chusing Senators"

That is, federal elections are governed by the states and by congress, not the president.

apnews.com/article/voting-elec

0
0
0

Kann die #EU oder wenigstens #Deutschland bitte jetzt einspringen? Wenn der #OTF (Open Technology Fund) in Schwierigkeiten ist, wird das für viele Menschen weltweit zum Problem.

#Tor ist essenziell für digitale #Freiheit – für #Journalistinnen, Aktivistinnen, Bewegungen für #Demokratie, z. B. gerade wieder in der #Türkei.
#Signal wurde (mit)gefördert.
#LetsEncrypt ist aus dem sicheren #Internet nicht mehr wegzudenken.
#FDroid, #VPN-Dienste und viele weitere freie Tools hängen da mit dran.

Stellt euch vor, all das wird wegen ein paar lumpiger Dollar kaputtgespart – aus ideologischer Laune heraus.

Wir sollten jetzt handeln:
• Diese Projekte fördern.
#OTF retten.
• Und fordern, dass zentrale Dienste, Entwicklung und Infrastruktur verstärkt in die #EU verlagert werden – so wie sie bisher oft in den #USA konzentriert waren.

Zeigen wir ihnen, wie sich #Trump gerade selbst rücklings ins Knie schießt.

https://www.heise.de/news/Nach-Trump-Dekret-Kampf-um-US-Foerdermittel-fuer-Tor-F-Droid-und-Let-s-Encrypt-10328226.html
0
0
0
0
0
0

Oh, great. had a broken implementation of "follower-only" posts, _and_ fucked up the disclosure / bugfix release process.

fokus.cool/2025/03/25/pixelfed

Summary of the bug: If you have a protected account (on Pixelfed, Mastodon, GTS, whatever) and a Pixelfed user followed you and got approved by you, _all_ users on that instance were now able to see your followers-only posts, not just the one you approved.

0
0

TIL that the "My" in MySQL is not the English word my but the Swedish name My, for the daughter of co-founder Michael Widenius. ♡

The name My was introduced by Tove Jansson for the character Little My, who is named after the Greek letter mu.

So you could pronounce My as [ˈmyː] or as [maɪ].

Never mind how to pronounce SQL.

MySQL documentation defines the official as “My Ess Que Ell” but the devs in Swedish say "mü-ess-ku-ell".

Sources in reply.

0
0
0
0

Hello! Thought I should introduce myself (and a thanks to the Mods and Administrator for accepting me).

I'm not new to the Fediverse. Came here first from Twitter after the M*sk buyout, didn't keep up - work was too much. Fast forward with the current upheaval, I'm back w/ job loss and now self-employed, trying to keep a roof over my head and myself and my cat fed. I do vuln research and RE.

Cyberpunk - its world, its lore is an escape, so I'm really glad to have found this instance. Other ttrpgs I've played: V:tM (V20, 3rd Ed.)

My laptop full of stickers from various places, collected over time.My home office desk with two monitors, speakers, mouse, keyboard, phone, dirty mug from hot cocoa, some notebooks, pens, mechanical pencils, handful of usb drives and multiple cell phones for my work.
0
0

2. The US has been designated “Do Not Travel” for foreign citizens—a designation I do not make lightly. But recent developments, including Rubio’s visa directive targeting transgender applicants and the detention of lawful visa holders and resident immigrants, demand such a warning. Full map here:

0

選挙期間の短期にボランティアとしてガーッと動くのは難しいので、選挙前のポスティングをコツコツやって選挙ボランティアの前払いをしているつもり(前払い?)

ohtsubaki.jp
大椿ゆうこの全国配れるビラみたいなんやってる共産社民の人(あるいはそれに近いポリシーの人)いたらいつでも教えてください。
大椿ゆうこのこのどこでいつやってもいいボランティア募集は私にはちょうどよくて助かるのだけど、大椿ゆうこがずっと全国どこでも配れるビラ出してくれる保障もないしねえ。

0
0
0

미 콜롬비아대 재학하며 팔레스타인 평화시위 참여한 것을 빌미로 공포정권에 의해 본보기로 체포 및 추방당할뻔한 정윤서씨에 대해, 연방법원이 집행정지 명령을 내림. 비슷한 상황에 처한 모두에게 같은 조치가 내려지는 당연한 수순이 이어지길.

RE: https://bsky.app/profile/did:plc:eclio37ymobqex2ncko63h4r/post/3lla57u2ivs2x

0
0
0

i wrote about what the fediverse can learn from bsky's proposal for User Intents. Fediverse is a network of many independent communities, each with their own values and culture, and it should use that to its advantage. fediversereport.com/fediverse-re...

RE: https://bsky.app/profile/did:plc:7g5cwudxc4ybqwvarredxzwi/post/3ll7viwnetn72

0

New: Fediverse Report 109

This week, an essay about 's proposal for setting user preferences on their accounts. This allows people to indicate how they want their data to be handled off-protocol. I wrote about how the can improve on this, using its strengths of many different communities, each with its own culture and values.

Also:
- Next week is the digital conference @fediforum
- A research dataset to compare Threads and Mastodon users

Read at: fediversereport.com/fediverse-

0
0

[비상행동 공지] 경복궁역에서 자하문로를 따라 청운동주민센터 방향으로 가고 있습니다. 시민들은 계속 저항하고 있고 경찰들은 계속해서 폭력적으로 대응하고 있습니다!! 어서 모여주시기 바랍니다!!

0