@hirihit640@sh.itjust.works
member since 28 Oct 2024 18:28
comments
- on The Nightmare of Migrating from Lightroom CC to Immich [Adobe doesn't make it easy] in c/selfhosted@lemmy.world · 2d ago
-
on The Nightmare of Migrating from Lightroom CC to Immich [Adobe doesn't make it easy] in c/selfhosted@lemmy.world · 2d ago
Mind sharing which local AI you used, the harness, etc?
-
on Had to do a clean install... in c/linuxmemes@lemmy.world · 17 Sep 2026
disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition
-
on World-first biological data center packs 16 mn living human neurons in c/technology@lemmy.world · 13 Sep 2026
hooks it up to speakers
“ahhhAAAaahAhhh”
scientists: “hmm something must be bugged, let me fiddle with it some more”
-
on Age verification mean end of anonymous account in c/privacy@lemmy.world · 11 Sep 2026
Ok so you clearly didn’t read the article because it calls out EUDI explicitly:
By the end of 2026, the 27 states within the European Union are expected to have infrastructure in place to do age verification within a “mini-wallet” app that will live inside the EUDI (European Digital Identity) Wallet. This is being met with plenty of warranted criticism from digital rights experts. The “mini-wallet” version is already being rolled out, with promises that the ZKPs are in working order. But recent insights show that the ZKP features aren’t yet turned on except for the closed demo/prototype build (not the version of the app people are using “out of the box”), which the vast majority of everyday users can’t access.
Worse still, a security researcher found they could bypass the app’s system using a quickly built Chrome extension that tricked the app into repeatedly accepting the same “over-18” token. It did so without ever asking for fresh verification.
Over 400 security researchers signed an open letter stating that age assurance checkpoints, even if implemented with privacy in mind, would cause more harm than good. A primary focus of their concern, which we share, is the fact that a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.
Once the “mini-wallet” version of this is fully integrated into the EUDI Wallet, it will replicate these same failures, perhaps more, but at a much larger scale. At that point, the failures will involve many more pieces of sensitive information that the EUDI Wallet contains: passports, driver’s licenses, travel information, financial information, to name a few.
-
on Get stremio to play videos again on Linux Mint 22.3 in c/selfhosted@lemmy.world · 11 Sep 2026
For those that like the cli, you can use
flatpak remote-info --log flathub com.stremio.Stremioto scroll through the list of past versions, and look for the “Commit” id of the version you want, then do:flatpak update --commit=<commit id> com.stremio.StremioThen use
flatpak maskto prevent further updates. -
on Age verification mean end of anonymous account in c/privacy@lemmy.world · 11 Sep 2026
Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets
The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user’s access to a service, essentially removing that person’s access to the internet entirely.
a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.
Personally I’m optimistic that tech like this can be used in positive ways, but imo they should be developed transparently (open source) and decentralized.
-
on GrapheneOS defends use of AI for coding in c/technology@lemmy.world · 11 Sep 2026
Reading the comments, wow AI is polarizing. Neither side will budge.
I guess only time will tell, to see if all the AI code will actually come crashing down.
-
on GrapheneOS defends use of AI for coding in c/technology@lemmy.world · 11 Sep 2026
Not the person you are replying to, but if there is no copyright there is no IP “theft”.
-
on GrapheneOS defends use of AI for coding in c/technology@lemmy.world · 11 Sep 2026
modern AI can be used to generate formal lean proofs:
-
on OpenAI steals Human Mathematicians work to solve a Millenium Problem in c/privacy@lemmy.ml · 11 Sep 2026
I’m aware that the data is used to train models. Most people know this, it’s stated clearly. That’s not the story here. The story is IP theft, not privacy.
-
on ‘The People Building AI Earnestly Believe That It Could Kill Us All’: Anthropic Researcher Quits Dramatically in c/technology@lemmy.world · 10 Sep 2026
Everybody is in competition with each other. We can only stop if we can convince everybody else to stop too. If these truly are weapons of mass destruction, no country wants to be the only one without it.
-
on OpenAI steals Human Mathematicians work to solve a Millenium Problem in c/privacy@lemmy.ml · 10 Sep 2026
surveilling users? chats are fed into the training data, I believe this is stated pretty clearly on every chat, something like "your chats are used to improve the model’
-
on OpenAI steals Human Mathematicians work to solve a Millenium Problem in c/privacy@lemmy.ml · 10 Sep 2026
This is interesting news but why is it in the privacy comm?
-
on LG TV shown scanning LAN for third-party phones and other devices in c/technology@lemmy.world · 9 Sep 2026
Fair enough. I also recommend Apple when Linux isn’t an option
-
on LG TV shown scanning LAN for third-party phones and other devices in c/technology@lemmy.world · 9 Sep 2026
it’s a trojan horse for Apple though right? Apple still collects tons of telemetry they’ve just never been caught selling it
-
on Your reminder to remove the microphone from your TV remote today in c/privacy@lemmy.ml · 9 Sep 2026
SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit
Seems to have some caveats but I’m not an expert.
Edit: fixed link
-
on Your reminder to remove the microphone from your TV remote today in c/privacy@lemmy.ml · 9 Sep 2026
I personally haven’t seen any proof that they are actively doing this, but I’ve seen enough about Amazon Sidewalk and from the Gamer’s Nexus video to be certain that they are capable of these methods, and if they aren’t doing it now they’ll probably do it soon.
In most cases by the time the evidence breaks, it’s years after the fact, and so better to be on the precautionary side.
-
on US police fear Meta smart glasses could be used to secretly record them in c/technology@lemmy.world · 8 Sep 2026
The joke is about tying the toast to the cat to make a flying machine. If the toast is on the cat it has already landed. If the toast falls off the cat then the cat can land on its feet and the toast can land butter side up, no paradox
-
on US police fear Meta smart glasses could be used to secretly record them in c/technology@lemmy.world · 8 Sep 2026
Even if the adages were correct, the toast would not prevent the cat from landing on its feet because the toast has already landed. It’s landed on the cat’s back.
-
on SHOULD you use vpn and tor? in c/privacy@lemmy.ml · 8 Sep 2026
Are you asking what cover traffic is? It’s just adding extra traffic to obfuscate the real traffic. There’s many ways to do this, you can look it up online
-
on LG smart TVs caught logging audio with screen off and snooping on local devices in c/technology@lemmy.world · 7 Sep 2026
how will you deal with Amazon Sidewalk?
-
on LG smart TVs caught logging audio with screen off and snooping on local devices in c/technology@lemmy.world · 7 Sep 2026
You’ll also have to make sure to properly destroy it afterwards. If you re-sell it, the next owner might connect it to the internet and all the stored data will get uploaded.
Also there’s tech like Amazon Sidewalk that allows devices to talk to other devices nearby in a mesh, bypassing your router entirely.
-
on SHOULD you use vpn and tor? in c/privacy@lemmy.ml · 7 Sep 2026
A VPN is basically just a replacement ISP. They see everything your ISP traditionally sees.
Many ISPs are already selling your traffic data. So if you trust that your VPN isn’t selling that data, then you’ll be more private using them. And if the VPN is in a different country, then your government is less likely to be able to force the VPN to give up data.
You can defend against timing attacks and other traffic correlation attacks too, using techniques like cover traffic.
-
on SHOULD you use vpn and tor? in c/privacy@lemmy.ml · 7 Sep 2026
What metadata are you talking about?
-
on GPT-6 Astra reaches and surpasses human-level performance on ARC-AGI-3 with a memory harness, but still at 1000x the cost - ARC Prize Foundation in c/technology@lemmy.world · 4 Sep 2026
Wow they benchmaxxed this pretty quickly. Wasn’t this benchmark released only a few months ago with like 0% success rate from all major AI models?
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
I just re-read their post and yes you’re right, in which case I disagree with them. “Perfect” is not achievable by any means. Maybe accurate enough to be mistaken as a twin for the real person, but not perfect
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
But there are examples of twins who grew up apart and still look almost identical
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
I don’t think root comment was saying the AI would generate perfectly accurate images. I think 90% accuracy is doable, just from DNA
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
But they could probably get 90% the way there with just DNA. I think that was the point.
-
on New compression technique in c/programmer_humor@programming.dev · 3 Sep 2026
Don’t know why you’re being downvoted, it’s a good point that shows that genetics is the main factor for your appearance
-
on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company in c/selfhosted@lemmy.world · 2 Sep 2026
A lot of times its tech opinion articles. Stuff like “why AI is bad”. And I read the arguments and judge them for myself.
-
on Linus Torvalds used AI to fix a Linux bug, and now LLM critics on Linux face an uncomfortable choice in c/technology@lemmy.world · 1 Sep 2026
I think of it like age verification. Slipperly slope to a proprietary kernel-level “security compliance module” on all devices, aka the end of general computation.
-
on I hate packaging my software for Linux (fresh) in c/technology@lemmy.world · 1 Sep 2026
How does it lead to dependency hell? I thought the point was that it didn’t share dependencies with the host, so different apps could have different versions of the same package and everything would still work.
-
on I hate packaging my software for Linux (fresh) in c/technology@lemmy.world · 1 Sep 2026
Well great news, the world has mostly settled on Flatpak now.
-
on reason enough to fail the interview in c/programmer_humor@programming.dev · 1 Sep 2026
You actually get them all the time, because the programmer is more deeply knowledgeable about the features they wrote and can identify gaps better.
Boss: “Can we move the widget to the left side of the page?”
Programmer: “Sure but that means when the sidebar opens it will obscure the widget, making it hard to see both at the same time. Do we want that?”
Boss: “Hmm I didn’t consider that. Let me ask the UX team what they think.”
-
on reason enough to fail the interview in c/programmer_humor@programming.dev · 1 Sep 2026
The point is that in a real software engineering process, specs and requirements are rarely defined precisely from the start, and the programmer should be able to identify the gaps and clarify them. A generic answer doesn’t help as much as a clarifying question.
A common but amateur mistake is to just make assumptions about how something should work and then forge ahead. As a programmer in a company, you are building things for somebody else (your boss, your client), so you need to ask them first.
-
on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company in c/selfhosted@lemmy.world · 31 Aug 2026
I already considered that, and for an untrusted website I already don’t trust the content or the scripts. So it doesn’t matter if it was modified or not, it’s still untrusted.
Facts can be verified with sources you do trust (which should be using HTTPS). Logic can be used to verify others.
-
on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company in c/selfhosted@lemmy.world · 31 Aug 2026
IMO when reading random articles on the internet you already have to worry about untrusted scripts. I just use NoScript, and if the website requires Javascript I move on
-
on Experimental Build Of Nvidia’s DLSS 5 AI Slop Filter Leaks And Turns Beloved Video Game Characters Into Uncanny Valley Weirdos in c/games@lemmy.world · 29 Aug 2026
I want to see it with Quake
-
on What's something people should buy today instead of tomorrow? in c/privacy@lemmy.ml · 28 Aug 2026
The government could force Huggingface to implement KYC. This would probably push people to start uploading torrents of models, but the problem is that there are dozens of quants for each model. Depending on what GPU you have, how much VRAM and RAM you have, the perfect quant for your machine might not be available on these third party download sites. So might as well grab them now while you can.
-
on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company in c/selfhosted@lemmy.world · 28 Aug 2026
If you’re just pushing for WebPKI without “thinking too hard” about perpretrating a security system with a large number of failure points, then you’re following that windows method.
SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web. So I don’t see the problem with this website doing their own thing to bring attention to the potential issues of the current system.
-
on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company in c/selfhosted@lemmy.world · 28 Aug 2026
It works fine, just ignore the warning and don’t enter any sensitive info
-
on Data centers’ ‘oh s--t’ moment in c/technology@lemmy.world · 27 Aug 2026
How do you donate heat? Ventilation pipes?
-
on Rule in c/linuxmemes@lemmy.world · 27 Aug 2026
It’s true, offline updates are more reliable. Less risk of running programs interfering with the update.
-
on Rule in c/linuxmemes@lemmy.world · 27 Aug 2026
First off, downvoted for thorn.
Making sweeping upgrades of multiple sources exacerbates supply chain attacks
What else are you supposed to do? Not upgrade? The user most likely installed those packages/flatpaks/distroboxes for a reason, why would they not upgrade them?
Sure, security can be improved. But no idea why
topgradedeserves any blame here. -
on Rule in c/linuxmemes@lemmy.world · 27 Aug 2026
Let’s look at the alternatives:
- System packages: not viable for the majority of packages because the distro devs don’t have time to manually package everything
- AppImage: even worse integration (like no desktop shortcuts on install). Developer has to guess what libraries need to be included and which ones are already installed by the user. No sandboxing. Probably worse SLSA scores.
- AUR: even worse security. No sandboxing. Packages are often compromised by hackers.
-
on Rule in c/linuxmemes@lemmy.world · 27 Aug 2026
Is it just a terminal app?
-
on Every time I use podman in c/linuxmemes@lemmy.world · 26 Aug 2026
That is cool. A creative use of their templates. Thanks for giving me some food for thought.
-
on UK/EU homelabbers: would you host a hardened Pi so I can watch baseball I already pay for? in c/selfhosted@lemmy.world · 26 Aug 2026
This is a cool idea, and I love the hacker energy behind it, but I agree with some of the other comments that the receiver would have to trust you quite a bit to allow hardware into their house. Even with the SSH view-only accounr, you could be putting the SSH server in a VM so that the client thinks they’re seeing the whole OS but they aren’t.
Alternative idea would be to provide an open source ansible script or docker compose file to spin up everything you need, and let them verify and deploy it themselves. Then they give you the wireguard configs to remote in.
If you wrote an article I’d read it! But this is a great starting point nonetheless, thanks