[–] 5 points 4 days ago (1 child)

The article doesn't mention it, but it entails a geo-block, not a worldwide block. Github will probably honor the ineffective geo-block.

Because of the Streisand Effect, though, the Indian government made the "problem" far worse for themselves. These mesh networks will grow much faster now, worldwide. They will have even less control over people's communications.

  • source
  • [–] 2 points 4 days ago (2 children)

    This might have something to do with lemmy.kde.social no longer existing. It gives a 502, Bad Gateway error. This server hasn't had communication with it in over 2 months and has finally flagged it as "gone forever."

    It's possible that under this circumstance, PieFed, rather than providing an error when you try to post to an unreachable community, just posts to a different community.

    I added a couple of devs.

    @rimu@piefed.social @wjs018@piefed.social

  • source
  • [–] 2 points 1 week ago

    YouTube requires a valid Referer header to allow embedded playback, and if Nginx is stripping it out, like mine did, the videos throw an error and refuse to play.

    I fixed this by updating the referrer-Policy header. I updated the server {} block with this:

    add_header Referrer-Policy "strict-origin-when-cross-origin" always;
    
  • source
  • parent
  • context
  • [–] -1 points 2 weeks ago* (21 children)

    I've always believed, until this week, that if I posted something and it got upvotes, it was because people liked that I posted it. I've learned this week that because of some, it's become a much less meaningful indicator. It's been co-opted for unrelated purposes. I no longer trust it has any meaning. This is a letdown. Let's add it then to the list of meaningless metrics like lines of code, story points, and StatCounter statistics.

    If it remains an admin choice, I will keep it enabled for the two reasons that the behavior makes vote counts meaningless, which is unfair to the community, and that these empty votes add a ton of unnecessary traffic for every instance. I wonder what percentage of my server is used just to process meaningless votes. Each vote sends me a request to update the database. Each meaningless vote here requires me to send out a ton of requests to other servers. Why should I pay for this? Why should users see lower performance because of this behavior?

    Please leave the setting, Rimu.

    And I completely like the proposal.

  • source
  • [–] 1 point 3 weeks ago

    In the past 24 hours, only 13 requests got rate-limited by the firewall. No rate limits in the last 24 hours from the server itself. The 13 was part of a burst of requests coming from lemmy.world. But just 13 the whole day. Unsure where else the 429 error could have come from. Seems unlikely it was from feddit.online.

  • source
  • parent
  • context
  • [–] 1 point 3 weeks ago (1 child)

    Do you do a lot of voting? Version 7 puts a limit on how much voting can be done in a day. I don't know the limit or the details. If your quota bar is solid red, it's the reason. Let me know.

    image

  • source
  • [–] 35 points 3 weeks ago (1 child)

    There are two answers to this depending on what the reason is for asking.

    If you are asking because you are concerned about scrapers reading your posts and violating your privacy and your rights, then understand that even if an instance is 100% effective at blocking them, the post is sent all over the place in clear text anyway. It doesn't matter for them which of the federated servers your post is read from. They will read your post many times over. For this case, then, there is little incentive for a server owner to block bots if it's just to protect your posts from ingestion.

    If you are asking because you are concerned about scrapers sucking the life out of a server because there are multiple different AI companies trying to read every single post in the database multiple times over for training, which ends up causing gateway timeout errors and poor performance, then admins, for this reason, should take action.

    On my PieFed server, feddit.online, as of yesterday, the firewall discarded 99K requests it deemed were for AI scraping while processing the remaining 300K requests. Those 99K requests would have been expensive requests, not just upvotes and such, but requests asking for huge amounts of text, and so the impact on the server and infrastructure would have been much more than a 25% tax on the system.

    And if the bots realize your server is not well protected, it gets worse. 3 months ago I peaked at 1.2 million requests in one day, of which over 700K were AI bots. Now it's down to consistently under 100K from bots because many of them have given up, I like to believe.

  • source
  •  

    Received this email about Udemy having been hacked. Doesn't seem like Udemy feels any urgency in informing anyone.

    Hi Jerry, an announcement has been made from Alexander, instructor of Elementor Mastery - Build Amazing Websites With Elementor, The Ultimate WordPress Boot Camp Course - Build 10 Websites and 1 more course.

    Hi everyone,

    I wanted to reach out directly about a security incident that affects this platform and may affect you.

    On April 24, the threat group known as ShinyHunters added Udemy to their data leak site and issued a three-day deadline. The deadline passed on April 27, and the data has now been published. Have I Been Pwned has confirmed the leak contains approximately 1.4 million unique email addresses, along with names, physical addresses, phone numbers, employer information, and for instructors, payout method details (PayPal, cheque, bank transfer information).

    As of this announcement, Udemy has not issued a public statement, has not responded to media inquiries, and has not directly notified affected users. I want to be transparent with you that this is the case, because you may not learn about it from Udemy itself.

    What you should do right now:

    1. Check your email address at haveibeenpwned.com to confirm whether your account is in the leaked dataset.

    2. Change your Udemy password immediately, and change it anywhere else you may have reused that password.

    3. Enable multi-factor authentication on your Udemy account if you have not already.

    4. Be alert for targeted phishing emails over the coming weeks. Attackers will likely send messages referencing your course history, instructor name, or payout details to appear legitimate. Treat any unexpected email about your account, refunds, or payments with extra scrutiny.

    5. If you are an instructor, monitor your linked payout accounts (PayPal, bank) closely for unusual activity.

    I have published a video on my YouTube channel that walks through the breach in detail, explains how this attack pattern works, and covers each of these protective steps in depth. If you find this kind of breakdown useful, the link is below.

    https://www.youtube.com/watch?v=Ycbeoibawp8

    I will continue to update you here if Udemy issues a statement or if new information emerges. In the meantime, take the steps above and stay vigilant.

    Stay safe,

    Alex

    submitted 5 months ago* (last edited 5 months ago) by to c/boston@lemmy.world
     

    On this day 250 years ago, the British were succumbing to George Washington's army and would soon flee Boston. Special thanks to Henry Knox, a bookseller, who traveled hundreds of miles to Fort Ticonderoga to fetch dozens of cannons for Washington's troops in the middle of winter that were instrumental in pushing out the British.

    Happy Birthday, George Washington!

    The article is about George Washington.

    https://apnews.com/article/george-washington-siege-of-boston-250th-anniversary-5fcf9c85e1887af7aab9398a5e0d08d4

     

    I played around with Zorin, the Linux distribution supposedly made as a Windows alternative. My experience did not match all the reviews about it nor the claims they make in their marketing.

    I found this great review about Zorin if you have an interest in knowing more about it and what the experience may be like for a Windows user. It's an honest review.
    https://novafuture.org/open-source/no-nonsense-full-review-of-zorin-os-the-linux-distribution-targeting-beginners/

     

    Early New Yorkers tossed garbage into the street or into one of the rivers. The city stunk. In the absence of organized waste disposal, pigs played an important role in reducing (and reusing and recycling) trash in the city.

    Brought to America by European colonists, pigs were commonplace and an important source of food. Without room to house them, hogs were largely left to roam the city foraging for food scraps, which not only kept them alive but also removed waste from the streets. By some estimates, upwards of 20,000 pigs free-ranged on the streets of Manhattan in the early 1820s.

     

    TIL the guillotine was named after a man who neither invented it nor believed in the death penalty.

    The guillotine was named after Joseph-Ignace Guillotin, a surgeon who didn’t believe in public executions and was appalled that while nobility was given merciful deaths, the masses went through extreme suffering during their executions. He spoke out about this, advocating that all killings should be painless and the same regardless of class if the death penalty continued.

    It ended up being named after him as more of a joke because of something he allegedly said about the device being as quick as a twinkling of an eye. The new name stuck. The original name, named after the true inventor, Antione Louis (the louisette), ceased, and the official name assigned by the government was guillotine.

    The family was so embarrassed by the association that they legally changed their last names.

     

    TIL the guillotine was named after a man who neither invented it nor believed in the death penalty.

    The guillotine was named after Joseph-Ignace Guillotin, a surgeon who didn't believe in public executions and was appalled that while nobility was given merciful deaths, the masses went through extreme suffering during their executions. He spoke out about this, advocating that all killings should be painless and the same regardless of class if the death penalty continued.

    It ended up being named after him as more of a joke because of something he allegedly said about the device being as quick as a twinkling of an eye. The new name stuck. The original name, named after the true inventor, Antoine Louis (the louisette), ceased, and the official name assigned by the government was guillotine.

    The family was so embarrassed by the association that they legally changed their last names.

     

    Rule 1: Don't ever use an agentic browser (one that an AI can control).
    Rule 2: But, if you do use an agentic browser, only run it inside a virtual machine.

    AI hacking. Downloading images can allow your computer to become hijacked. Here's how.

    https://www.scientificamerican.com/article/hacking-ai-agents-how-malicious-images-and-pixel-manipulation-threaten/

     

    I have a #Pixel 10 Pro XL phone, which may be the first phone to give warnings when the phone connects to a rogue cellphone tower or IMSI catcher. The OS cannot block it; it can only tell you that someone read information, and it presents an alert. It says,

    "Your data may be at risk. Device ID accessed. At 6:57 PM a nearby network recorded your device's unique ID (IMSI or IMEI) while using your T-Mobile SIM. This means that your location, activity, or identity has been logged."

    I didn't ever get an alert before walking through the building, but this time, during a 30-minute walk through the building, I got about 8 alerts, ranging between 1 and 3 minutes apart.

    Using this information from repeated connections, someone can follow my movements and location; they can identify it's me because the IMSI number is unique to my phone, so it can be an indication that someone was collecting all the cellphone information in the area, most likely law enforcement.

    It can also mean that I was connecting to a rogue cell phone tower, not just an IMSI catcher, and it was an attempted Stingray attack, likely also law enforcement. If successful, they can try to see and hear what I'm doing on my phone, as my phone won't know that it's a fake cellphone tower.

    Be aware that a rogue tower will try to negotiate your phone's connection down to a 2G connection, which is unencrypted, providing them with access to everything that you are doing and saying. Please go into your phone's settings and disable 2G!!

    It's been believed for some time that this technology has been used by law enforcement secretly and consistently. This is creepy and unnerving.

    Turning off the phone, by the way, doesn't stop an IMSI catcher. Your phone still responds. You need to keep the phone in a Faraday bag if you're really concerned.

    It's a good thing that phones are now starting to inform people that they are being watched and that people will begin to see how much of an issue this is. You can assume that your local law enforcement knows where you are all the time.

     

    Two weekends ago I upgraded my Ubuntu desktop from 22.04 to 24.04.3 and was left with an unusable system because I opted to keep my existing copy of the gdm-smartcard-pkcs11-exclusive configuration file because I don't use a smartcard.

    But it's a new configuration file and is REQUIRED. By saying I didn't want it updated, the update program didn't create the new one. And since there wasn't an old one, the upgrade failed with "error: alternative path /etc/pam.d/gdm-smartcard-pkcs11-exclusive doesn’t exist" and "The upgrade has aborted. Your system could be in an unusable state." Oh, it certainly was.

    It might as well have said, "Enter N if you want your system to become unusable."

    The upgrade program should never have asked. If the file is required and it isn't there, it should have just created it. I think it's a bug in the update program.

    gdm3, ubuntu-desktop, and ubuntu-desktop-minimal weren't installed. PAM was not set up. No way to log in.

    I wrote a blog post about how I recovered from this in case anyone else is bitten by this same issue: https://jerry.hear-me.blog/ubuntu-22-04-to-24-04-upgrade-failure-missing-file/

     

    “Cognizant was not duped by any elaborate ploy or sophisticated hacking techniques,” according to a copy of the lawsuit reviewed by Reuters. “The cybercriminal just called the Cognizant Service Desk, asked for credentials to access Clorox’s network, and Cognizant handed the credentials right over.”

    https://www.nbcnews.com/business/business-news/lawsuit-says-clorox-hackers-got-passwords-simply-asking-rcna220313

    view more: next ›