Home | Notifications | New Note | Local | Federated | Search | Logout

Federated Timeline


:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:46:43) メイトで手が滑ったやつ
缶バッジはヤチヨ以外売るかは迷い中 ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-1537cb10-296c-4380-ae20-5d0d3a453d51

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:42:58) あの感じだともうオンライン全振りかね

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:42:23) そういや立飛の更地WEGOは黒鬼のアクスタだけ残ってた

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:41:20) タブ開いてそのままだったや

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:35:58) 中央線が止まってラベル缶で爆死した原因(諸説あり) ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-c60d95dd-c264-421c-ac92-e95d318da6e3

Reply to @hos1miya@misskey.0sakana.xyz :hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:31:32) キーホルダーと並べてみた ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-e976bb71-8a7d-46f4-b61e-72a397ddddeb

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:28:09) 手のひらサイズ

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz boosted: @ko8r_@takusuki.com (2026-07-18 20:19:20) ---Attachments--- image: https://083.takusuki.com/house/shell02/258bac4d-d1b8-4321-b792-d8ebb8150938.jpg

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:25:27) お迎えしました。 ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-48ff6bca-9a15-4b08-9d74-28225883d5b8

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:23:09) ​:static_polarbear_inverted:​ ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-d77d9b28-e363-4932-8f35-8dbe8ce192f2

fedicat@fedicat@pc.cafe boosted: @cwebber@social.coop (2026-07-22 21:45:10) Vibecoding gets banned on Codeberg! https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434

Reply to @hos1miya@misskey.0sakana.xyz :hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:20:06) しっかり書かれとるわ ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-9e24d161-a58f-4dd9-9ee0-8f9e76ad20e8

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:19:07) 4DX版も無事確保
あと例のも ---Attachments--- image: https://misskey.0sakana.xyz/files/webpublic-30698a2a-68bb-492e-9f0c-9d4a4fb1aa24

fedicat@fedicat@pc.cafe boosted: @silverpill@mitra.social (2026-07-22 21:21:08) Codeberg is banning "cryptocurrency projects":

https://codeberg.org/Codeberg/org/pulls/1254#issuecomment-19820413

I don't know if Mitra qualifies as such, but I guess it is time to move to a self-hosted forge.

dave@dthompson@toot.cat boosted: @cwebber@social.coop (2026-07-22 21:39:20) Most security vulnerabilities have pretty common shapes. But we also have solutions to them:

- Ambient authority! Mitigation: capability security
- Confused deputies! Mitigation: capability security
- Memory exploits: Mitigation: use memory safe languages (Rust and etc if you gotta go low level, though languages with a GC or etc are actually even *safer* because they don't have "unsafe" blocks of code) or use CHERI
- Injection attacks: Use structured representations. Quasiquote or combinator templating is much safer than string templating, for example. Why are we speaking to our databases in sentences? Send them the AST of the query!
- Bad crypto usage: Use standardized cryptography patterns

There are a few others, but even if you just focus on the above, we can simply *eliminate* huge swaths of security issues.

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:11:33) 逆にAPにデフォで付けなかったのか…って感じもある 掲示板とかには普通にあったので

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz boosted: @ozoramore@social.t2arc.net (2026-02-02 16:29:30) CW付きのポストができない実装もある…というか :mitra: もできないので CWはマナーですよ :npp_zoom: とか言われると困るかも

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:08:28) Mitraだと普通に全部見えてるはず

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz boosted: @int@misskey.intinfinity.com (2026-07-22 22:04:33) Misskeyで「内容を隠す」機能、ActivityPubでどのように扱われてるか、他の種類のインスタンスでどう見えてるのか気になる

いんと∞@int@misskey.intinfinity.com (2026-07-22 22:04:33) Misskeyで「内容を隠す」機能、ActivityPubでどのように扱われてるか、他の種類のインスタンスでどう見えてるのか気になる

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 22:00:23) 松屋のせいで機嫌悪い

:hosimiya_mion::star_stroke:@hos1miya@misskey.0sakana.xyz (2026-07-22 21:58:37) ​:matsuya:​入ったら自動ドア壊れてんのか全然閉まってくれないしお冷は全然冷えてないしで最悪だった

Ganbold@ganbold@sns1.hydranlab.com (2026-07-22 21:56:09) its so easy to spot if its song from bocchi the rock or not. I wonder why

Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 21:45:10) Vibecoding gets banned on Codeberg! https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434

Phoronix@phoronix@masto.ai (2026-07-22 21:39:38) libx11-compat Is Working To Implement Xlib Atop SDL For Wayland, macOS, Android

For helping to keep X11 clients running in a modern Linux desktop world with Wayland or even for running on macOS or Android, there is now yet-another option being developed with libx11-compat. The libx11-compat project is working to re-implement the Xlib client library atop SDL2/SDL3 interfaces for allow broad underlying platform coverage...
https://www.phoronix.com/news/libx11-compat ---Attachments--- image: https://s3.masto.ai/media_attachments/files/116/963/668/480/642/363/original/9dadf14c61ba8210.webp

Reply to @cwebber@social.coop Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 21:39:20) Most security vulnerabilities have pretty common shapes. But we also have solutions to them:

- Ambient authority! Mitigation: capability security
- Confused deputies! Mitigation: capability security
- Memory exploits: Mitigation: use memory safe languages (Rust and etc if you gotta go low level, though languages with a GC or etc are actually even *safer* because they don't have "unsafe" blocks of code) or use CHERI
- Injection attacks: Use structured representations. Quasiquote or combinator templating is much safer than string templating, for example. Why are we speaking to our databases in sentences? Send them the AST of the query!
- Bad crypto usage: Use standardized cryptography patterns

There are a few others, but even if you just focus on the above, we can simply *eliminate* huge swaths of security issues.

OSNews@osnews@mstdn.social (2026-07-22 21:36:25) Building an AmigaOS Development Environment in 2026

If you want to develop an application for AmigaOS 3.x but don't want to deal with real hardware, virtualisation and emulation are your friends.

Apropos of nothing, I decided to set up an Amiga development environment. Since figuring things out wasn't straightforward, I wrote down instructions for Linux about how to compile the

https://www.osnews.com/story/145581/building-an-amigaos-development-environment-in-2026/

#AmigaAROS

Reply to @cwebber@social.coop Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 21:34:41) I really don't think that you can fight LLM agent exposed and exploited security issues with *more vibes*. You absolutely cannot. These machines are good at finding exploits, but they are also good at *inserting* them, accidentally all over the place, and also in terms of them being the perfect machines to insert subtle, hard-to-find intentional vulnerabilities.

In terms of using them as vulnerability scanners, I think they're important tools. In terms of code generation, there is simply no way to fight vibes with more vibes.

Instead, we need to get systemic about things.

So how do we fix security issues SYSTEMICALLY?

Reply to @cwebber@social.coop Christine Lemmer-Webber@cwebber@social.coop (2026-07-22 21:31:00) To those saying the OpenAI + Hugging Face thing is an ad, I think that's true, but I think it's not just an ad. They're taking the marketing opportunity for sure, and it's *awfully convenient* that it's two AI companies as part of the story, right?

But, despite being a big critic of this stuff, I do think that they are *very good at attacking systems*. The reason being that most attacks tend to have very similar patterns, and these models are great at blasting similar patterns over and over again, so they can ruthlessly find their way through exploits.

The bigger question to me is: which examples *aren't* there motivations for two companies to put out statements together? Where else has stuff like this happened?

And the more important one, the response I think they *want* people to hear is "our stuff is so scary and powerful, you have to use and trust even more of our vibetech".

But that's not MY takeaway...

Phoronix@phoronix@masto.ai (2026-07-22 21:24:05) Intel Directed Package-Level Thermal Interrupts Slated For Linux 7.3

Back in March Intel software engineers began sending out Linux patches for Directed Package-Level Thermal Interrupts as a new capability with recent Intel processors. This notable efficiency improvement is now queued for introduction in the Linux 7.3 cycle once its merge window opens in a month...
https://www.phoronix.com/news/Intel-Direct-Pkg-Therm-Linux-73 ---Attachments--- image: https://s3.masto.ai/media_attachments/files/116/963/609/475/228/006/original/e47044085231595f.webp
Older Notes