what google wallet FOSS alternative do you know that works in Germany?

preview

I write to you from Germany, where I work. I use an android device.

The transportation authority I am in is called Mainzer Mobilität and because my employer only covers 50% of the transportation costs if I use the digital travel card and not the physical one, I’m basically forced to use google wallet, which I hate. This transportation authority doesn’t offer pkpass files I could use with FOSS Wallet or pdf cards with my full name and a small qr code I could download. It has to be google wallet or use a physical card (and pay double).

I used to take a screenshot of the qr code and download the receipt as a pdf each month. On the receipt everyone can see the relevant data, including my full name, address, expiry date of the travel document, type of travel card and what I paid, but 5 days ago a “Kontrolleur” (an employee who boards buses to identify passengers without valid travel documents) fined me for not showing him the google wallet app with my pass there.

Yo read that right, it MUST be google wallet, otherwise I’m not carrying a valid travel document. The qr code alone together with the receipt with all my data and my identity card are not enough.

Is there any FOSS wallet or application that would work in Germany like google wallet does?

I really hate being forced to use google crap like this, I really don’t want to trust them with my data but I need to save as much as I can.

Feel free to suggest other communities where I could ask this question.

How often do y'all use a VPN?

preview

Bit of an uphill fight with captchas everywhere. Do people here conduct all online activity over VPN whenever possible? Only for the sensitive stuff? Or perhaps the inverse because the bank already knows you? Maybe when travelling or getting around region blocking? Something else?

The one provided by my work aside, I realized that I don’t have any consistent rules around using VPN. Except sometimes, you know, when downloading ISO’s for my favorite distos.

Age verification mean end of anonymous account

preview

today I created a burner google account. these days google requires an Android phone in order to even create an account so I used an old phone to scan the QR code ( I am pretty sure this lets google grab all of the metadata of the mobile phone ). after about 1 hour creating the account. google’s automated system disabled the account however I appealed and got the account back. before someone asks I need google because of where I live.

this made me wonder what if google mandates age verification? if there were age verification google would immediately notice that I am creating another account ( burner account ) which it won’t like. burner account won’t be created in the first place!

we already have too much surveillance and this makes it worse. my mobile number is already tied to my read government identity. I DO NOT want my online account to be tied to my read identify too! it is sad, it really is

AI Didn't Steal the Mathematician's Work, Sam Altman Did

cepr.net
preview

cross-posted from: lemmy.dbzer0.com/post/75317530

Among the many recent controversies around AI, there is the claim that to solve a longstanding mathematical problem, OpenAI stole the work of the New York University mathematician Tristan Buckmaster and a colleague, Levent Alpöge, who also is a researcher for Anthropic. I have no ability to assess the validity of the claim, but as I understand it, the argument is that OpenAI had access to work done by Buckmaster and Alpöge. It then built on this work to quickly rush ahead and find a solution, which also had a $1 million prize attached to it.

Insofar as that accurately describes what OpenAI did, this seems like it would be equivalent to having a professor doing a seminar for colleagues and then having one of the attendees do a few additions and claim the work as their own. This would not be viewed as very collegial behavior in a normal academic department.

I’m not sure what claim a professor would have against a colleague under such circumstances. I suppose if their work was properly cited, there would not be a claim of plagiarism. (OpenAI’s work did not directly cite the work of Buckmaster and Alpöge, from my understanding.) I suppose there could be a basis for disputing rights to the million-dollar prize. But the problem seems much greater.

If AI can effectively steal the work of others, and claim it as its own, then it undermines the practice of openness in science that has allowed for enormous progress for centuries. This practice depended on norms, whereby scientists would properly credit the work of their peers.

In the seminar scenario I described, if one of the attendees listened to the presentation and realized the one or two additional steps needed to get over the goal line, they would be expected to raise the issue with the presenter. Assuming the additions were correct, the presenter would finish the paper, acknowledging the contribution or possibly adding the attendee as a co-author, if their contribution was sufficiently important.

But that relies on norms. If the owner of the AI doesn’t share those norms and can freely scrape scientific work wherever it finds it, and then take credit for the product, it will threaten the longstanding practice of openness in science. With the risk of having years of work stolen without getting any credit, researchers will likely keep their work closely held until they have a finished paper.1 They would only share it with a small group of trusted colleagues. Posting a working paper, or having an open seminar, would put control over their work at risk.

However, it is important to recognize the villain in this story. It is Sam Altman and his company, not the AI. Altman and the company are the ones responsible for what their AI does. If it did something they disapprove of, it is their responsibility to correct it. However adept AI may become, it is not the active player; it is the individual or company that set it in motion.

This issue applies more generally. There has been a social media mini firestorm over Texas Attorney General and Republican Senate candidate Ken Paxton using AI to have his opponent, James Talarico, making a series of outlandish statements that he never said. Much of the outrage seems to be over Paxton using AI, rather than the fact that he is lying about what Talarico said.

The issue here is that Paxton is defaming Talarico; the AI is secondary. The AI presumably makes the defamation more effective, but if Paxton were an exceptionally gifted mimic, he could likely also trick some people into believing that he was speaking in Talarico’s voice when making outlandish assertions. If that were the case, it would be every bit as bad as using AI to accomplish the job.

There were also the claims that the girls’ school in Iran, which was destroyed by the US military on the first day of the war, killing 120 children, was selected as a target by AI. That may be the case, but the important point was that the military did not have a system in place to properly review targets. It doesn’t matter whether or not an AI system identified the target. The problem was that there was no system that ensured the places designated were proper military targets.

It is important to keep our eyes on the ball. The bad actors are those who do bad things with AI, not the AI. This is like the husband who gets drunk and beats his wife and then says the whiskey did it. No one should ever accept that story. In the same vein, if a theft of mathematical work did occur, it was Sam Altman who did it and it was Ken Paxton who libeled his political opponent. The AI is beside the point.

FX Fighter Kurumi-chan Drops Main Trailer, Begins on October 1 advance screening event for Episode 1 has been confirmed for 9/27 (Sun)!

YouTube TVアニメ「FX戦士くるみちゃん」メインPV【2026年10月1日放送開始!】FX Fighter Kurumi-chan MaineTrailer
preview

📈Advance Screening Event📈

TV Anime “#FX Warrior Kurumi-chan” The advance screening event for Episode 1 has been confirmed for 9/27 (Sun)!

💵Cast: #Suzuki Aina #Seto Asami #Ito Ayasa

💴Date: September 27 (Sun)

💶Advance Lottery Sales Now Open w.pia.jp/t/fxkurumi/

Lottery applications accepted until 9/17 (Thu) 23:59

Source: x.com/i/status/2094380427947741438

My low quality unqualified review of the Mobapad M12 S Joycon replacements

preview

After a long research journey I ended up with the Mobapad M12 S. A bit surprised how few mainstream media sites gave any coverage to Joycon replacements. But the small YouTuber community was a buzz with how great these were. So I took the plunge and spent my own money.

Spoiler alert: they’re not.

I’ve had the controllers for over a month now and the experience has never gotten better than awkward. And I really wish I could get my money back.

Let’s start with the build quality. On first glance it seems pretty sturdy. Initially the controllers even remove the screen flex that the official Joycon exhibit. However within days of heavy gaming I noticed issues. The Joycon stared to flex on the switch (magnets weakened I guess ?), scratches and smudges all over the joy con handles from basic use. Worse yet the (overly clicky) buttons started to get stuck and not register presses. Leading to some issues in games.

It’s been pretty well stated on the M12s that vibration motor isn’t as good as HD rumble. What most people neglected to mention is the games still treat the normal motors as HD motors. Meaning you get long drawn out and loud vibrations that sound and feel awful. Some games are worse than others but they are all terrible.

Ergonomics which is suppose to be a key selling point for devices like this are also not great. The placement of the buttons like screenshot, home and even their custom macro buttons are all to close together. It’s far too easy to accidentally hit the wrong button. The custom buttons in the back of the controller are placed right where your grip and I accidentally click them all the time. The buttons issue led to a scenario where I somehow set a macro to screenshot and enabled turbo. Which lead to my memory card filling up with screenshots taken every second. Spent an hour deleting photos.

The joystick, standard buttons and shoulder buttons for me are still awkwardly placed. I still feel fatigue and cramping with any long play sessions. Especially if I’m playing lying in bed. No matter what I tired I still felt like I wasn’t able to hold the controller comfortably and play. Especially in games like Metroid prime and StarFox.

Even the joysticks supposedly “TMR” also have issues with travel and centering. Not to mention the Mobapad sticks travel pale in comparison to the pro controller sticks which aren’t TMR. Meaning in games which require more precise stick control have issues. You will still hit walls avoiding things in StarFox you will still hit walls you shouldn’t in MarioKart.

The M12S can be found on sale for 80 bucks much of the time. But MSRPs for as much as the switch 2 Joycon do. And considering what you are getting I think it’s far too expensive for something that feels this cheap.

Reading that the Nyxi controllers have durability issues and Crked just a grip that uses Bluetooth. I feel confident saying at this point there is no true pro Joycon controller that’s worth purchasing yet in 2026.

Also do not listen to the small switch controller YouTube community. Save your money for now and do lots of research!

OS Tier List

operating system tier list in dark-mode theme (full description is in main post)
preview

So I saw political compass memes a while ago and started making one, but then I started taking it too seriously and eventually turned it into a tier list. Idk if it makes sense to share it here, but idk where else to share such a thing. I also made a browser tier list, but idk where to share that either.

This whole thing is a png export of a pure svg image. For some of the logos, I had to make them either from scratch or by using gimp and inkscape to convert a png into an svg (imperfect but good enough).

Hopefully this is all formatted properly.

OS Tier List

S-Tier (reasonably secure operating system):

  • Qubes OS

Advanced (complicated setup and configuration):

  • Gentoo Linux
  • Guix System
  • Slackware Linux
  • Linux From Scratch (LFS)
  • Mobile NixOS
  • NixOS
  • Whonix
  • Predator-OS
  • Linux Kodachi
  • Gentoo FreeBSD

Enhanced (optimized security and minimalism):

  • Alpine Linux
  • Hyperbola GNU/Linux-libre
  • Chimera Linux
  • EasyOS
  • postmarketOS
  • Tails
  • Kicksecure
  • NetHydra
  • ParrotOS
  • OpenBSD
  • GrapheneOS
  • Secureblue

Minimal (maximally mini resource use):

  • Tiny Core Linux
  • LibreCMC
  • Void Linux
  • Puppy Linux
  • AsteroidOS
  • Slitaz
  • 4MLinux
  • OpenWrt
  • DragonFly BSD
  • FreeBSD
  • NetBSD

Indie & BSD (independent distros and BSD systems):

  • PCLinuxOS
  • Dynebolic
  • KaOS
  • Mageia
  • LuneOS
  • Solus
  • AerynOS
  • GNOME OS
  • KDE Linux
  • GhostBSD

Arch (reasonably fresh and arch-based):

  • SystemRescue
  • Parabola GNU/Linux-libre
  • pearOS
  • EndeavourOS
  • Nemo Mobile
  • Arch Linux Arm
  • BlackArch Linux
  • Archhurd
  • Archcraft
  • Nyarch
  • Ageless Arch
  • Arch Linux
  • CachyOS
  • Garuda Linux

Debian (reasonably stable and debian-based):

  • Flora Linux-libre
  • Genuen
  • Devuan GNU+Linux
  • Loc-OS
  • antiX
  • MX Linux
  • Maemo Leste
  • Mobian
  • Emmabuntüs
  • Linux Mint Debian Edition (LMDE)
  • Ageless Linux
  • Debian
  • KNOPPIX
  • PikaOS Linux
  • RetroPie
  • LibreElec
  • Vanilla OS

Corpo-ish (corporation-created and/or dependent):

  • Replicant
  • Uruk GNU/Linux-libre
  • Trisquel GNU/Linux
  • AnduinOS
  • Linux Lite
  • UBports
  • Xubuntu
  • Lubuntu
  • Kubuntu
  • Linux Mint
  • KDE neon
  • Fedora
  • Asahi Linux
  • Bazzite
  • Nobara Linux
  • Rocky Linux
  • AlmaLinux
  • openSUSE

Corporate (corporation-owned and/or controlled):

  • /e/OS
  • Sailfish OS
  • PureOS
  • Manjaro Linux
  • Raspberry Pi OS
  • OSMC
  • Kali Linux
  • Zorin OS
  • Tuxedo OS
  • Pop!_OS
  • elementary OS
  • Ubuntu
  • Proxmox
  • SteamOS
  • CentOS Stream
  • Red Hat Enterprise Linux (RHEL)
  • CloudLinux OS
  • SUSE Linux Enterprise
  • Unraid

Dubious (questionable and/or suspicious):

  • Waydroid
  • Artix Linux
  • Omarchy
  • OpenMandriva

Borderline (possibly dangerous and best to avoid):

  • LineageOS

MALWARE (actively dangerous and harmful to use):

  • android
  • chromeOS
  • Apple Operating Systems (macOS, iOS, etc.)
  • Windows
  • Red Star OS

An app that detects nearby Meta smart glasses over Bluetooth

TNW | Apps A Polish developer built an app that detects nearby Meta smart glasses over Bluetooth
preview

A 30-year-old Polish software developer has built an iPhone app that detects Meta smart glasses in the vicinity and estimates how far away they are by reading the Bluetooth signals the glasses broadcast. It has around 5,000 users a month after launch.

[AIP] Versentry - notify-only Docker image update monitor with central regex rules and built-in proxy

GitHub GitHub - BlackRaincoat/versentry: Notify-only Docker image update monitor.
preview

I built Versentry to scratch my own itch: I run Docker across several self-hosted boxes and wanted to know when images have updates - without anything auto-pulling or restarting my containers behind my back.

Before that, I used WUD, but at the time Versentry was created, it didn’t have a proxy for Telegram notifications, which was the impetus. As a result, I ended up with a micro‑service that fully meets my needs.

What it does: reads running containers from the local Docker socket, compares their tags and digests against OCI registries, and sends a notification when something’s newer. It never pulls images or touches containers. That’s the whole point - notify-only by design.

A few things that set it apart:

  • Central tag-filter rules in config (regex by image repo), so you’re not forced to label every container. Per-container versentry.include labels also work if you prefer them.
  • Built-in proxy (SOCKS5/HTTP) for notifier delivery and registry traffic - handy behind network restrictions.
  • Any OCI registry - Docker Hub, GHCR, Quay, GitLab out of the box; private/self-hosted via type: oci.
  • Notifiers: stdout, Telegram, Discord, Gotify, ntfy, and a generic webhook.
  • Readable notifications out of the box - sensible default messages, no template-wrangling required; Go text/template overrides are there if you want to customize.
  • semver/numeric detection (cross-major updates get flagged) plus digest comparison for floating tags like latest.
  • Tiny ~5 MB scratch-based image, MIT licensed.

It’s probably not for you if you need: a web UI (try WUD), automatic pull-and-restart (that’s Watchtower’s job), non-Docker providers like Kubernetes/Podman (Diun covers more), or Slack/email as first-class notifiers.

It’s a young project - fewer battle-tested deployments than the established tools - so I’d genuinely welcome feedback from anyone who runs it.

GitHub: github.com/BlackRaincoat/versentry

AI Disclosure:

  • Design - Pair
  • Implementation - Generated
  • Testing - Assisted
  • Documentation - Generated
  • Review - Assisted
  • Deployment - Generated

Note: The idea, the architecture decisions, and all real-world testing were mine - I ran it across multiple live servers and that’s what caught the actual bugs. The AI wrote the implementation, the test code, docs, and CI config from my prompts. I reviewed behavior on real deployments rather than reading every line, so code-level review leaned on the AI.

Needed to replace an older server while on a budget. Went for a rackmount chassis with "normal" ATX hardware inside

www.inter-tech.de
preview

I was considering something new from supermicro, but I decided to go consumer grade for a change, as I mainly just need single threaded performance from this one.

My only requirement was rack mount, so I went for a Ryzen 5 build inside a rack mount chassis from Inter-Tech. My first build combining these two worlds.

I’m gonna miss IPMI, though.

Anthropic Is Building a Predictive Surveillance System to Monitor Activists - The American Prospect

The American Prospect Anthropic Is Building a Predictive Surveillance System to Monitor Activists - The American Prospect
preview

cross-posted from: hexbear.net/post/9504907

In a wide-ranging conversation about threat monitoring and analysis, the interview also touches on monitoring activists. “Last year we had an executive travel into a major city when we received some intelligence through Samdesk about a planned protest,” Ellison said. The originally scheduled protest was moved up due to permitting issues. “Samdesk gave us about 60 minutes of advanced notice that the protest organizers had moved the timeline,” Ellison explained. “That extra hour was critical. Without it our executives would have departed their meetings, they would have ran right into the heart of the disruption.”

📌 Pinterest used ~500 Million ROWS of user pins to train it's AI!

Screenshot of the "Generative AI and model transparency" section on this page: https://help.pinterest.com/en/article/ai-at-pinterest Some sentences are underlined in red. Pinterest Canvas Version 6 (“Pinterest Canvas”) is a multimodal foundation model that powers Pinterest experiences by enabling the enhancement of images. Pinterest Canvas has been trained on approximately 500,000,000 rows of publicly available Pins, Pin descriptions, and Pin metadata that Pinterest users have saved or uploaded to Pinterest, to which the users have granted Pinterest a license, as well as the continuous use of synthetic data. Training data rows may include one or more images together with text instructions and a target image. The data in the datasets were collected by Pinterest as early as 2009 and were first used in the development of Pinterest Canvas in or around January 2023. The data collection is ongoing. The data in the datasets may include limited personal information, and material that may be protected by copyright, trademark, and/or patent. The datasets do not include aggregate user information. The datasets were cleansed, processed, and modified for quality purposes and to meet our trust, safety, and other internal standards.
preview

cross-posted from: lemmy.world/post/51671840

📌 Pinterest used ~500 Million ROWS¹ of user pins² to train it’s AI!

Data from 2009-Now, however the Social Media corp claims “users have granted Pinterest a license”.

What license? Pretty sure AI training fine print wasn’t a thing in 2009!

It even includes “limited personal information”.

Grounds for a lawsuit? 🤓

¹ Never heard of this unit ever before, but even if we assume 1 ROW = 4-6 Pins that is 2-3 BILLION user Pins!

² Post would sound way worse wouldn’t it?

🔗 Source: help.pinterest.com/en/article/ai-at-pinterest

Meta Ran Hundreds of Paid Ads with Child Sexual Abuse Imagery

TTP - Meta Ran Hundreds of Paid Ads with Child Sexual Abuse Imagery
preview

cross-posted from: https://piefed.world/c/tech/p/1390196/meta-ran-hundreds-of-paid-ads-with-child-sexual-abuse-imagery

  • Meta has run more than 300 paid ads containing child sexual abuse material (CSAM) this year, a TTP investigation found.

  • Most of the ads showed a photo of a child, which is digitally altered with AI to make it appear the child is performing a sex act.

  • TTP identified multiple photos of real children, including a member of a European royal family, that were used in the ads.
  • Several of the CSAM ads were placed by Meta’s own advertising partners in China, including a Chinese state-controlled company.
  • The vast majority of the ads pointed to AI apps from China. Many of these apps were capable of “nudifying” people.