[-] ChairmanMeow@programming.dev 8 points 5 months ago

Erm, did you read them? The policies aren't complex at all, just submit the issue (and proposed fix if there is one) through a secure channel, that they're happy to help set up. If you want to disclose the vulnerability, just wait until the embargo passes so there's time to fix and have users update. There's not really anything else you need to do here. This is pretty standard stuff that this person just seemed too lazy to participate in.

Of the three fixes submitted, only a single one was closed since it didn't seem very major and would be a breaking change (which shouldn't be made without prior discussion). The other two are still open, and a maintainer is helping to add tests for the fixes (since the author didn't add them). The only comment that was somewhat negative was that security fixes should preferably follow the established guidelines. That's all.

[-] ChairmanMeow@programming.dev 8 points 7 months ago

That's definitely not what he did though. He did research on the internet, going through various websites and articles listing options, and asked ChatGPT. That's imo more than what the average user does (or is even willing to do).

He then picked the distro that he saw was being recommended most to him. He installed it with default options, which ended up being Cosmic. Which is improving fast these days, but it's still a bit unstable. But the install process won't tell you that.

Pretending that these users are "bad users" or that highlighting these issues that regular users run into is disingenuous or somehow irresponsible is just unfairly dismissing a valid perspective.

The whole "Linux just works"-shtick just isn't always true. And the sooner the community learns to accept that and works to help these users with their issues, rather than stomping their foot angrily whenever someone shows up highlighting problems. I'm pretty experienced myself with a job in software development, but even I needed to reinstall Bazzite 2 times when installing it for my sister because I somehow messed up something when mounting the hard drives, getting Bazzite stuck in an unrecoverable bootloop (none of the recovery options suggested online worked either). I hate Windows as much as the next guy, but I've never been able to manage that on a Windows install (once running Bazzite ran fine btw, just the setup was frustrating).

[-] ChairmanMeow@programming.dev 8 points 7 months ago

I'm not sure if I consider "Afghanistan during the Taliban guerilla war" a good example of ideal anarchist living. Nor what came after that for that matter.

[-] ChairmanMeow@programming.dev 8 points 7 months ago

I've had McDonald's in Italy and it's the same cardboard taste there as it is elsewhere in Europe imo.

[-] ChairmanMeow@programming.dev 8 points 1 year ago

One of the NPP maintainers responded with:

Notepad++ & its plugins are installed in "Program Files" directory by default, which means hackers would need admin privileges to replace any plugin. If a hacker gains such privileges, they could also replace all the DLLs in the system32 folder. By the same logic, once Notepad++ is compromised in this way, any applications or executable binary (*.exe & *.dll) on the system could potentially be replaced. Or am I missing somethings?

Which I suppose is true. You could argue it is a way to persist malicious code once you do have access, but it seems unlikely and not that useful. Low severity if anything.

You'd need to have some general attack script that can adjust (or create proxies for) dlls maliciously on the fly, without prior knowledge of which dlls are encountered. Only in that case could the exe maybe detect malicious changes to the dll and stop execution. But a targeted attack using a compromised NPP distribution wouldn't be covered with such a check.

[-] ChairmanMeow@programming.dev 8 points 1 year ago

But then Hamas got into power with a plurality of the vote and have been constantly attacking Israel ever since.

Hamas has always been extreme in rhetoric, but the violence afaik began when Israel, the US and the PA attempted to coup them out of power.

There have been a few times in this war there has been ceasefires with hostages exchanged for prisoners. Hamas eventually stops releasing hostages and the conflict resumes.

So far every ceasefire was broken by Israel, because they were unwilling to enter the next phase of negotiations which was a precondition to the release of more hostages.

It doesn't seem like Hamas wants sovereignty, they could have had that if they wanted it.

Like how Israel respects the sovereignty of the PA in the West Bank? Yeah right.

[-] ChairmanMeow@programming.dev 8 points 1 year ago

Iran doesn't even have nukes yet.

[-] ChairmanMeow@programming.dev 8 points 1 year ago

Well that's A) not a basic human right (though I generally agree with it) but mostly B) a drivers license is not available to everyone. There are plenty of crimes that can see you get your license revoked entirely, potentially permanently.

If you've exhibited clear mental volatility, a tendency for mass violence or straight-up potential for terrorist activities, why should society trust you with a car? Perhaps experts should first determine the risk of you driving before allowing you to obtain a license.

Being allowed to drive is a privilege, not a right. It's fine to extend that privilege to those who are deemed fit to have it, so then it should also be fine to deny it to those who are deemed a danger.

[-] ChairmanMeow@programming.dev 8 points 2 years ago

The amount of fluoride in water is significantly below the safe limits. To get fluoride poisoning like the article describes you'd have to drink so much water that you'll die of drinking too much water first.

An accident can happen with everything. It's very, very rare in most developed countries for something to go wrong with the water fluoridisation.

[-] ChairmanMeow@programming.dev 8 points 2 years ago

If I understand correctly they already can. It's not user-facing, but votes are federated if I understand correctly.

[-] ChairmanMeow@programming.dev 8 points 2 years ago

You're mixing the definitions of sideloading media and sideloading apps. Sideloading media follows your definition, e.g. transfer via another local device. Sideloading apps refers to the installing of apps outside of the (pre-)installed app store, e.g. by installing an APK directly.

view more: ‹ prev next ›

ChairmanMeow

0 post score
0 comment score
joined 3 years ago