What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

When I first came to SF 13 years ago I asked for ‘cut chillies’ and ‘chilli sauce’ at a pho place and I didn’t understand when I was given jalapeños and sriracha. None of these met my definition for ‘even remotely spicy’.

13 years later, I’m still annoyed about it but no longer surprised.

(I was expecting sliced birds eye chillies..)

0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0

길어져서+불편한 화재(현 세태에 대한 입막음 관련N)

SNS는 취사선택이 가능한 공간입니다
뮤트랑 블락 기능이 존재한다는 것부터가 일단 그렇지요... 물론 그렇다고 해서 혐오 발언이나 사이버 불링 조장이 합당화되는 것은 아닙니다 당연하지만 단순히 이 발화가 '니가 걍 참아라'의 화두로 하는 말은 아닙니다

부당한 것을 말할 때 당연히 관련으로 네거티브한 이야기들이 많이 오르내릴 수밖에 없고 그것을 말하는 사람이든 듣는 사람이든 심력 소모가 클 수밖에 없겠지요 그게 마냥 기꺼운 사람은 없어요.. 좋은 거 즐거운 것만 보고 살고싶지 발언자들이 유난떨고 싶어서 그러는 거겠습니까?

제발 본인 감정 전시를 하기 전에 그게 불특정 다수를 향한 수동공격이 되지 않는지 생각을 좀 하십시오.. 자신의 불편함으로 타자를 통제하려고 하는 게 요새 저는 눈에 너무 잘 보입니다.. 의도하지 않더라도 그건 정말 발언자들을 역으로 지치고 고통스럽게 합니다.

SNS를 보기 괴롭다면 그만두십시오. 정신적 타격이 크다면 자신을 돌아보세요. 단순히 목소리를 내는 사람에게 '진정하라' '너무 과열됐다'는 둥 깎아내리는 것도 무례한 행위입니다. 그거야말로 플로우 조장이고 입을 막는 행위입니다.

적어도 어떤 부당함을 논할 때, 발언자들이 얼마나 큰 스트레스와 심력 소모를 감내하는지 본인의 개인적인 감정을 전시하기 전에 고려해주세요

0
0
0
0
0
0

I gave a talk at last month about the role of organising in Open Source. I have three obserpinions therefrom:

1. Going all-in on permissive licensing was a mistake that directly led to extractive behaviour
2. Copyleft not having a good answer to the actual concerns of people who chose permissive licensing was a mistake that directly led to people going all-in on permissive licensing
3. It's too late to care about licensing, so we need other forms of consequences/ways to encourage organising

0
0
0
0

yeah, one could say i'm a little alarmed that zionists are publicly talking about where to deport all the palestinians in gaza to, and are putting forth the island of socotra—an island of 60,000 people and its own history and language, but to these zionists is an island with "almost no inhabitants"—which is sickeningly alike the european plan in the 20th century to mass deport jewish folk to madagascar.

0
0
0
0
0
0
0

I continue to be incredibly frustrated with how difficult it is to fabricate a test virtual machine from an arbitrary configuration and have that test virtual machine actually match the real thing on basic details like the (virtualized) disk layout and filesystem mounts.

Maybe I'm doing something weird here, but basically all the tests I want to do before pulling the trigger on a real installation are invalidated by this semantic gap!

0
0

Fediverse Report – #111

A new security fund for the fediverse, and the Lemmy developers held an AMA.

The News

The Nivenly Foundation, the organisation that administers the Hachyderm.io instance, is opening a new security fund to sponsor contributors who disclose security vulnerabilities. All software has security vulnerabilities, and the fediverse is no exception. The recent Pixelfed vulnerability, which affected non-Pixelfed servers, is a clear example of how fediverse software can make software vulnerabilities more complex due to the interaction between different software platforms.

The Nivenly Fediverse Security Fund will sponsor $250 USD for vulnerabilities that are rated as high risk (7-9 CVSS score) and $500 USD for vulnerabilities with a critical score (9+ CVSS). The program will run until the end of September 2025. Nivenly members “hold a member vote to determine if we want to continue the program, and to establish a longer-term committee to steward and maintain the program.”

Last week, I wrote how Pixelfed’s vulnerability actually showed three different problems: The main problem is Pixelfed’s software vulnerability itself, but there were also two other problems: other software like Mastodon do not make it clear which risk comes with their private posts feature. And once a leak like this one happens, very few fediverse software admins communicated to their users that they might have been affected.

A security fund contributes to combating software vulnerabilities, but it can also help with communication to the rest of the fediverse once a vulnerability is found. It incentives that standard industry practices regarding software vulnerability get followed, and make communication clearer to a wider audience. For example, if Pixelfed’s recent vulnerability had gotten a CVSS classification, it might have been easier to make the severity of the vulnerability explicit to other fediverse software admins. In turn, this might have made it more likely that server admins would communicate the situation with their users.

In last week’s email essay I also wrote about how the fediverse is missing governance infrastructure that connects the various independent nodes and communities. One way to view the fediverse is as a response to centralised Big Tech platforms. These platforms have centralised governance, and are under the control of few people. The fediverse’s response to this is to build a social network that consists of tens of thousands of independent communities, all with their own governance structure. The fediverse has been successful in decentralising the single entity that oversees a social network into many pieces that all oversee a small portion of the network. But it has struggled to build a governance structure that ties all these individual pieces together again.

The Nivenly Fediverse Security Fund is a good example of this problem: software security impacts all the thousands of independent fediverse communities, but there is no overarching structure to collaborate and improve the security. It took one server taking the initiative into their own hands and provide a service for the entire network, at their own cost. Ideally, communities would collaborate on such a security fund instead. Nivenly’s announcement does leave space for such a future direction of the fund, saying that they are open to “establish a longer-term committee to steward and maintain the program”.

Note: if you sign up for my email newsletter, you get a weekly essay about the open social web that I do not publish anywhere else. You can sign up right here:

<form action="https://fediversereport.com/wp-admin/admin-ajax.php?action=tnp&na=s" method="post" style="text-align: center"><input type="hidden" name="nr" value="minimal"><input type="hidden" name="nlang" value=""><input class="tnp-email" type="email" required name="ne" value="" placeholder="Email"><input class="tnp-submit" type="submit" value="Yep, I want to receive the newsletters" style=""></form>

The Lemmy developers, Dessalines and nutomic, held an Ask Me Anything recently, and here are some of the answers that stood out to me:

  • Lemmy is working towards their 1.0 release. This is currently expected to be in the fall, although nutomic also says that “these things always take longer than expected”. He also expects some instances like lemmy.ml already to upgrade some months before.
  • One of the main features for Lemmy 1.0 is private communities, where only approved accounts can browse and posts to the community. This type of closed group functionality is in high demand, and both Mastodon and Pixelfed have tried to implement it. Mastodon got a grant for it, but the proof-of-concept code has been sitting there since 2022. Pixelfed has announced and teased a group feature multiple times over the year and showed screenshots of it, but it also is not publicly available yet.
  • Lemmy posts are interoperable with Mastodon, but the interoperability is not great: a Lemmy post appears on Mastodon as the title plus the URL. There has been many conversations about how Mastodon handles content from other platforms, with no changes so far. In this AMA, nutomic is explicit in saying that it is up to Mastodon to change this. While Mastodon seems open to the idea, and has been in conversations with developers from platforms like Ghost and NodeBB on how to show their content better on Mastodon, there has been little indication that Mastodon is taking steps towards making Lemmy content also better visible on Mastodon.
  • On the subject of how Lemmy can grow, Dessalines describes it as an organic progress, saying: “niche communities on reddit will keep getting fed up with the changes, and migrate to lemmy.” Nutomic describes a similar dynamic for fedi and Bluesky more broadly, saying that he expects that over the long term the fediverse might grow in a similar manner: “when the Bluesky admins make decisions that the community doesnt like, and then there may be another migration wave to the Fediverse”. Both replies indicate Lemmy’s vision of how the project can grow in the long run: stay consistently working on your product, and because platforms like Lemmy are not beholden to investors, they can have a longer lifespan, and outlive platforms who are beholden to shareholder expectations.
  • Grouping of communities (similar to PieFed’s topics or Reddit’s multireddits) “will be implemented soon“.

Ahoy! is a one-day conference for the European Social Web, and will be held on April 24th 2025 in Hamburg, Germany. The conference is mainly focused on Bluesky and the AT Protocol, and has some super fascinating speakers of people who are in the forefront of building new communities on the open social web. If you’re around I can definitely recommend it. I’ll be doing some interviews with people there, so if you are considering joining, let me know and we can say hi!

The Links

That’s all for this week, thanks for reading! You can subscribe to my newsletter to get all my weekly updates via email, which gets you some interesting extra analysis as a bonus, that is not posted here on the website. You can subscribe below:

<form action="https://fediversereport.com/wp-admin/admin-ajax.php?action=tnp&na=s" method="post" style="text-align: center"><input type="hidden" name="nr" value="minimal"><input type="hidden" name="nlang" value=""><input class="tnp-email" type="email" required name="ne" value="" placeholder="Email"><input class="tnp-submit" type="submit" value="Yep, I want to receive the newsletters" style=""></form>

fediversereport.com/fediverse-

Detail of building in Amsterdam-North
0
0
0

Fediverse Report #111

This week's news:
- A new security fund for the fediverse, by Hachyderm.io's parent organisation @nivenlyThe Nivenly Foundation
- The Lemmy developers held an AMA, in which they talked about the upcoming 1.0 release of Lemmy and more.

fediversereport.com/fediverse-

0
0
0
0
0
0

Fediverse Report – #111

A new security fund for the fediverse, and the Lemmy developers held an AMA.

The News

The Nivenly Foundation, the organisation that administers the Hachyderm.io instance, is opening a new security fund to sponsor contributors who disclose security vulnerabilities. All software has security vulnerabilities, and the fediverse is no exception. The recent Pixelfed vulnerability, which affected non-Pixelfed servers, is a clear example of how fediverse software can make software vulnerabilities more complex due to the interaction between different software platforms.

The Nivenly Fediverse Security Fund will sponsor $250 USD for vulnerabilities that are rated as high risk (7-9 CVSS score) and $500 USD for vulnerabilities with a critical score (9+ CVSS). The program will run until the end of September 2025. Nivenly members “hold a member vote to determine if we want to continue the program, and to establish a longer-term committee to steward and maintain the program.”

Last week, I wrote how Pixelfed’s vulnerability actually showed three different problems: The main problem is Pixelfed’s software vulnerability itself, but there were also two other problems: other software like Mastodon do not make it clear which risk comes with their private posts feature. And once a leak like this one happens, very few fediverse software admins communicated to their users that they might have been affected.

A security fund contributes to combating software vulnerabilities, but it can also help with communication to the rest of the fediverse once a vulnerability is found. It incentives that standard industry practices regarding software vulnerability get followed, and make communication clearer to a wider audience. For example, if Pixelfed’s recent vulnerability had gotten a CVSS classification, it might have been easier to make the severity of the vulnerability explicit to other fediverse software admins. In turn, this might have made it more likely that server admins would communicate the situation with their users.

In last week’s email essay I also wrote about how the fediverse is missing governance infrastructure that connects the various independent nodes and communities. One way to view the fediverse is as a response to centralised Big Tech platforms. These platforms have centralised governance, and are under the control of few people. The fediverse’s response to this is to build a social network that consists of tens of thousands of independent communities, all with their own governance structure. The fediverse has been successful in decentralising the single entity that oversees a social network into many pieces that all oversee a small portion of the network. But it has struggled to build a governance structure that ties all these individual pieces together again.

The Nivenly Fediverse Security Fund is a good example of this problem: software security impacts all the thousands of independent fediverse communities, but there is no overarching structure to collaborate and improve the security. It took one server taking the initiative into their own hands and provide a service for the entire network, at their own cost. Ideally, communities would collaborate on such a security fund instead. Nivenly’s announcement does leave space for such a future direction of the fund, saying that they are open to “establish a longer-term committee to steward and maintain the program”.

Note: if you sign up for my email newsletter, you get a weekly essay about the open social web that I do not publish anywhere else. You can sign up right here:

<form action="https://fediversereport.com/wp-admin/admin-ajax.php?action=tnp&na=s" method="post" style="text-align: center"><input type="hidden" name="nr" value="minimal"><input type="hidden" name="nlang" value=""><input class="tnp-email" type="email" required name="ne" value="" placeholder="Email"><input class="tnp-submit" type="submit" value="Yep, I want to receive the newsletters" style=""></form>

The Lemmy developers, Dessalines and nutomic, held an Ask Me Anything recently, and here are some of the answers that stood out to me:

  • Lemmy is working towards their 1.0 release. This is currently expected to be in the fall, although nutomic also says that “these things always take longer than expected”. He also expects some instances like lemmy.ml already to upgrade some months before.
  • One of the main features for Lemmy 1.0 is private communities, where only approved accounts can browse and posts to the community. This type of closed group functionality is in high demand, and both Mastodon and Pixelfed have tried to implement it. Mastodon got a grant for it, but the proof-of-concept code has been sitting there since 2022. Pixelfed has announced and teased a group feature multiple times over the year and showed screenshots of it, but it also is not publicly available yet.
  • Lemmy posts are interoperable with Mastodon, but the interoperability is not great: a Lemmy post appears on Mastodon as the title plus the URL. There has been many conversations about how Mastodon handles content from other platforms, with no changes so far. In this AMA, nutomic is explicit in saying that it is up to Mastodon to change this. While Mastodon seems open to the idea, and has been in conversations with developers from platforms like Ghost and NodeBB on how to show their content better on Mastodon, there has been little indication that Mastodon is taking steps towards making Lemmy content also better visible on Mastodon.
  • On the subject of how Lemmy can grow, Dessalines describes it as an organic progress, saying: “niche communities on reddit will keep getting fed up with the changes, and migrate to lemmy.” Nutomic describes a similar dynamic for fedi and Bluesky more broadly, saying that he expects that over the long term the fediverse might grow in a similar manner: “when the Bluesky admins make decisions that the community doesnt like, and then there may be another migration wave to the Fediverse”. Both replies indicate Lemmy’s vision of how the project can grow in the long run: stay consistently working on your product, and because platforms like Lemmy are not beholden to investors, they can have a longer lifespan, and outlive platforms who are beholden to shareholder expectations.
  • Grouping of communities (similar to PieFed’s topics or Reddit’s multireddits) “will be implemented soon“.

Ahoy! is a one-day conference for the European Social Web, and will be held on April 24th 2025 in Hamburg, Germany. The conference is mainly focused on Bluesky and the AT Protocol, and has some super fascinating speakers of people who are in the forefront of building new communities on the open social web. If you’re around I can definitely recommend it. I’ll be doing some interviews with people there, so if you are considering joining, let me know and we can say hi!

The Links

That’s all for this week, thanks for reading! You can subscribe to my newsletter to get all my weekly updates via email, which gets you some interesting extra analysis as a bonus, that is not posted here on the website. You can subscribe below:

<form action="https://fediversereport.com/wp-admin/admin-ajax.php?action=tnp&na=s" method="post" style="text-align: center"><input type="hidden" name="nr" value="minimal"><input type="hidden" name="nlang" value=""><input class="tnp-email" type="email" required name="ne" value="" placeholder="Email"><input class="tnp-submit" type="submit" value="Yep, I want to receive the newsletters" style=""></form>

fediversereport.com/fediverse-

Detail of building in Amsterdam-North
0
0
0
0
0
0
0
0
0

Allergy test tomorrow, hot damn am I going to be happy to go back on the antihistamines immediately after.

I was starting to question whether they were doing anything, whether I needed them - yup!! Once they wore off, the increase in snots and sneezes and itchy eyes has been obvious. I'm more tired too, when that's all going on.

0

👋💻 Hey !
🆓✨ Libre React UI Alert!

FOSS-UI: A freedom-respecting UI library (Radix UI-based).

🔧 Features:
✅ Navbars/Sidebars
✅ Sign-Up Forms
✅ Copy-paste-ready
✅ 100% Libre

🌐 Demo/Docs (decentralized):
bafybeihpnjgdjrc7eujhsj4rvfypy

📂 Repo: codeberg.org/MukiOpenSource/FO

Join the libre movement! 🌍
Use, study, modify, share! - Becouse software should empower everyone!

0
0
0
0

i'm grumpy that all the modern open source collaborative markdown document editors (but probably also the closed source ones) don't actually let you see or edit the markdown source of the docs anymore (tried so far: docmost, appflowy, affine [well, that one's just totally over the top]). i want to replace my NIH solution, but howww

edit: should have written that i mean web-based

0

So this is weird I think. Gmail is sending me emails for someone else but their email is the same as mine except it has a period in it. Is this expected?

Like, should I recieve emails for my.same.email@gmail.com and that person just gave out the wrong email address? Or is this a Gmail bug?

0
0
0
1
0
0
0