- 2 Posts
- 41 Comments
5ymm3trY@discuss.tchncs.deto
DACH - Deutschsprachige Community für Deutschland, Österreich, Schweiz@feddit.org•Was ist euer Projekt zum heutigen Digital Independence Day?
0·3 months agoFür die Datenübertragung von/zum Handy nutze ich mittlerweile auch gelegentlich KDE Connect, abgesehen davon bin ich absoluter Fan der manuellen Übertragung mit USB-Kabel. Es ist super einfach und funktioniert einfach immer, egal ob Fahrrad-Computer, eReader etc. Keine Cloud, kein Account, keine proprietären Programme und Apps der Hersteller, keine Probleme mit Bluetooth-Pairing usw.
Wenn du Interesse an Self-Hosting hast, ist evtl. auch Endurain als eine Strava Alternative interessant für dich.
5ymm3trY@discuss.tchncs.deto
DACH - Deutschsprachige Community für Deutschland, Österreich, Schweiz@feddit.org•Was ist euer Projekt zum heutigen Digital Independence Day?
0·3 months agoVielleicht meinst du Linkwarden. Das ist ein Bookmark-Manager bei dem der Websiteninhalt auch in diverses Formaten lokal gespeichert werden kann.
5ymm3trY@discuss.tchncs.deto
Ask Lemmy@lemmy.world•Which national flags would you change?
0·3 months agoIt is always a little strange for me to see the flag of Mozambique. I don’t really know anything about the country, but the flag with its AK47 in there has the vibe of a terrorist organization.
5ymm3trY@discuss.tchncs.deto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
0·4 months agoI appreciate your effort and really enjoy the discussion. Most of your suggestions are probably a good idea for the future, but they are not really a solution for a potentially infected system right now.
You can pull out the big gun as well and purge all AUR packages entirely or even reinstall your system, but their might be an easier solution.
What do you think this does, in bash:
:(){:&:;};:Without looking it up, I wouldn’t have had a clue. It looks somewhat purposefully obfuscated but used in the right context, I am not sure I would have picked up on it. Maybe you are right and I should reconsider my approach.
5ymm3trY@discuss.tchncs.deto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
0·4 months agoI have no idea about the stance of CachyOS on AUR packages.
I totally agree with you, establishing trust is not an easy problem. I don’t expect the average joe to understand shell scripts. I would put myself in that categorie as well. This one however was simple enough that it seemed okay to me. If I don’t understand what’s going on in a script I am really careful and try to avoid it, if possible. I still wouldn’t consider them universally bad. For some things it is even the recommended install option. I vaguely remember some things in the Raspberry Pi universe ( IIRC this was even the case for Docker in the past).
There are multiple factors which can lead to trust. Maybe you know the CachyOS forum and how well it is maintained. How old is the account etc… But as you said, there are always risks. The account could be compromized as well. But most of that isn’t specific to shell scripts or Linux in general. You shouldn’t install an application from some shady website in Windows either.
What is your recommended way to deal with the current situation?
5ymm3trY@discuss.tchncs.deto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
0·4 months agoI don’t use CachyOS nor do I know anything about their team and I haven’t used the script either. My point was just that I would trust OS maintainers more than some random guy on the internet.
I have checked again and it seems the script I was referring to was actually from a mod on their community forum. Not sure if this is a maintainer as well or not.
My point still stands, if you trust the source and checked the code that nothing shady is going on, it is perfectly fine to run a script. Even if it is just an additional check after you cleaned it manually. Maybe you have missed something.
5ymm3trY@discuss.tchncs.deto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
0·4 months agoI haven’t checked the scripts from OP, but i think there is a script that is provided by the CachyOS team that basically just contains a list of compromised packages and compares that to your pacman -Qm output. If it finds a match, it tells you that the compromized package X is on your system. That seems pretty reasonable.
I get your point and as always, you should check the source of the script as well as the code inside of it. Never installing anything outside of official OS repositories is probably not an option for most people. There are always pros and cons. Like in my example maybe some OS maintainers know more about the affected packages than I do with a quick search. On the other hand, the script might be outdated because the number of packages changed a lot over the last few days.
5ymm3trY@discuss.tchncs.deto
Technology@lemmy.world•AMD pulls a bait-and-switch on Linux users with Vivado licensing changesEnglish
0·4 months agoNice, seems like it was a good decisions. Do you miss anything from the Xilinx world?
5ymm3trY@discuss.tchncs.deto
ErgoMechKeyboards@lemmy.world•TAIKO 01 Keyboard - Launches Tuesday (June 2)
0·4 months agoNever thought I’d see a Kinesis Advantage labelled as a traditional keyboard ;)
Nevertheless, good luck with the campaign. It seems like a well thought of design. I haven’t used one of these split concave keyboards, but the angle of the thumb cluster looks way better on yours than on the Kinesis.
5ymm3trY@discuss.tchncs.deto
Technology@lemmy.world•AMD pulls a bait-and-switch on Linux users with Vivado licensing changesEnglish
0·4 months agoI am very much pro open-source, but these are highly specialized tools for a very niche market so it is atleast somewhat understandable. Unfortunately we are not blessed with open source toolchains like software developers even though there are some steps in that direction. Because it is such a niche market, it is like the software space from 20-30 years ago. Proprietary tools and compilers were pretty common back then and for some microcontroller architectures outside of ARM and RISCV they still are I think.
5ymm3trY@discuss.tchncs.deto
Technology@lemmy.world•AMD pulls a bait-and-switch on Linux users with Vivado licensing changesEnglish
0·4 months agoWhat do you mean by this kind of shit? I am in the FPGA space for quite some time now but I don’t think something like this happened before. When did you leave and what are you using now? I agree with you on the support. If there isn’t an (unpaid) member in the community forum or on some other platform you are pretty much fucked. I never used another vendor, so I can’t say if it is different there though.
5ymm3trY@discuss.tchncs.deto
Ask Lemmy@lemmy.world•On what specific episode does your favorite "I swear it eventually gets really good" television show actually start turning around?
0·4 months agoThe Walking Dead was also the first thing that came to my mind. I think I eventually stopped in season 7-8 or something and never went back.
Recently I was thinking about rewatching the first season. Have you watched it again?
5ymm3trY@discuss.tchncs.deto
DACH - Deutschsprachige Community für Deutschland, Österreich, Schweiz@feddit.org•30 Tagessätze verhängt: Merz als "Lackaffe" bezeichnet – Strafbefehl
0·4 months agoAnne Will hat kürzlich einen Podcast zum Thema Meinungsfreiheit mit Ronen Steinke gemacht in dem es unter anderem auch um den Punkt Beleidigung von Politikern ging. Ich finde die Analyse darin sehr treffend.
5ymm3trY@discuss.tchncs.deto
Technology@lemmy.world•DuckDuckGo installs are up 30% as users reject being ‘force-fed’ Google’s AI SearchEnglish
0·4 months agoYou can use https://noai.duckduckgo.com/ to avoid AI all together.
5ymm3trY@discuss.tchncs.deto
Ask Lemmy@lemmy.world•What are some solid European products of any sort?
0·5 months agoCool, I didn’t even know about that. That’s a great gift.
5ymm3trY@discuss.tchncs.deto
Ask Lemmy@lemmy.world•What are some solid European products of any sort?
0·5 months agoI like the tools from Wera and Knipex.
5ymm3trY@discuss.tchncs.deto
Programming@programming.dev•‘No Way To Prevent This,’ Says Only Package Manager Where This Regularly Happens
0·5 months agoThings like the AUR in Arch Linux are also susceptible to this. About a year ago there were malicious versions of popular browsers e.g. firefox-patch-bin or librewolf-fix-bin in the AUR. As others have said, NPM has a huge attack surface because it is practically used by everyone which is probably why it is targeted a lot more.
5ymm3trY@discuss.tchncs.deto
Neovim@programming.dev•My Neovim Config — Opinionated, Minimal, and Actually Usable
0·7 months agoLooks nice. One thing I noticed is lsp-zero. Starting from v0.11 you don’t need that anymore. VonHeikemen (the developer of lsp-zero) even says that on the Github page and has some links how to migrate to the native lsp commands of Neovim. Maybe an excuse for you to tweak your config ;)
5ymm3trY@discuss.tchncs.deto
Selfhosted@lemmy.world•What's your self-hosting success of the week?English
2·7 months agoPurely from reading about the different tools Restic is also my favourite at the moment. I mainly want to use it so my client devices can do backups on my NAS and maybe at some later stage backup my NAS to a NAS at a family members home just like you do.
The project was archived back in April. I assume there were multiple incidents along the way, but the final straw was the discussion in this thread:
https://github.com/nvim-treesitter/nvim-treesitter/discussions/8627#discussioncomment-16440673
Basically it is just people demanding things from open-source developers and behaving like shit while doing so. These guys don’t have any respect for the work other people do for free in their spare time.
I use a lot of open-source software, but I usually don’t interact with the developers. Whenever something like this happens I feel like we as a community should show our love and appreciation for these projects a lot more, so that devs don’t burnout due to this loud minority full of negativity and sometimes just plain harassment.