@yawnbox@disobey.net cover

i'm passionate about ethics and the internet. autistic and queer. dissident and activist. dutch immigrant, human rights defender @emeraldonion, attack surface reduction engineer and data protection law student. photojournalist, electric sailor, he/they 🏳️‍🌈

join @emeraldonion's Amsterdam-hosted ActivityPub relay! https://relay.disobey.net :fediverse:

organizing @MinistryOfChaos :chaosknoten_white:

This profile is from a federated server and may be incomplete. View on remote instance

@yawnbox@disobey.net avatar yawnbox , to random

if you have ever been curious about running a web application firewall (WAF) in front of Mastodon or other fediverse instance, i've published a repo containing the policy we're now using, which is also configured to maintain strong privacy protections. i've recently turned on prevent mode, blocking critical events

https://code.disobey.net/dd/ap-waf

there's a lot of skip exceptions needed in order to not block required ActivityPub transactions. even things like changing a password in Mastodon is seen as a critical (false) positive

given the number of skip exclusions, there's a lot of attack surface that admins won't be able to action on since so much of ActivityPub looks malicious, and a targeted attack could easily take advantage of these necessary skip policies

i'm curious if any ActivityPub devs have ever run a WAF in front of their instance, and curious if any improvements can be made to the spec to reduce transactions that look like malicious behavior

i have to trust that for the ActivityPub exclusions, Mastodon properly sanitizes inputs and so the overall risk is still low

either way, this is a big win for overall risk reduction for anyone serious about protecting their community

@yawnbox@disobey.net avatar yawnbox , to random

delivery!!

ALT
@yawnbox@disobey.net avatar yawnbox , to random

i had a really nice time at - everyone was super friendly; i think more time was spent relaxing than actual events going on, which is the opposite of things like chaos events, where there's always 10 things going on at once xD

@Mer__edith@mastodon.world avatar Mer__edith , to random

📣THREAD: It’s surprising to me that so many people were surprised to learn that Signal runs partly on AWS (something we can do because we use encryption to make sure no one but you–not AWS, not Signal, not anyone–can access your comms).

It’s also concerning. 1/

yawnbox ,
@yawnbox@disobey.net avatar

@Mer__edith

The tor network has had 100% uptime. 100%

yawnbox ,
@yawnbox@disobey.net avatar

@Mer__edith

With respect Meredith, i’m talking about decentralized protocols and their capability to not depend so heavily on the service providers you’re arguing for. Tor Project has shown how possible it is (i used to work there, and it’s spelled Tor not TOR).

I listened to Moxie’s aversions to decentralization for years. That’s what I keep seeing now, with posts like these. I also understand the value of huge cloud providers, I’ve worked for many companies who use them, and have worked for them, and I understand why you depend on them and how important that is to a high quality service. Thank you for all that you all do.

But what conversations does Signal Foundation actually have on the topics of resiliency through decentralization? How much money could you save by allowing the community to take on aspects of the network? How much resiliency and trust could be gained, without losing performance?

@Mer__edith@mastodon.world avatar Mer__edith , to random

PSA: we're aware that Signal is down for some people. This appears to be related to a major AWS outage. Stand by.

yawnbox ,
@yawnbox@disobey.net avatar

@fedithom

Open Whisper Systems has a long history of being anti-decentralization

@Mer__edith

@yawnbox@disobey.net avatar yawnbox , to random

a update (shared on the ISOC "Global Encryption Coalition" mailing list):

"The good news is that the blocking minority held. Members states raised concerns about privacy and cybersecurity as reasons for their opposition. Even countries that are officially in support of the proposal asked questions along these lines for the first time – showing that they are facing increased pressure back home.

The bad news is that is moving forward even though they did not receive full support. They are keeping their plan to take this proposal to the Justice and Home Affairs Council meeting on October 14th.

After discussing with partners, we understand this as a strategy from Denmark. They are not making progress at the working level (the meeting today) and therefore will try directly at the political level (justice and home affairs). During these coming four weeks they will try to convince some of the blocking member states to reconsider their position.

What this means for us is that we need to keep up the pressure. We should be thanking the blocking countries for their position and encouraging the undecided or supportive countries to reconsider. We should keep up pressure in the media at the same time."

@yawnbox@disobey.net avatar yawnbox , to random

we ( @emeraldonion ) need 60 new tor exit relay :tor: names. please give us names

(must be alphanumeric, =<16 chars, no spaces)

:boosts_ok_gay:

@aral@mastodon.ar.al avatar aral , (edited ) to random

According to capitalists:

✅ Working for a company like Google or Microsoft that is complicit in genocide.

❌ Displaying images of the genocide.

Maybe if the consequences of your work are considered “Not Safe For Work”, you shouldn’t be doing that work in the first place.*

But, no, it’s just much easier to look away, isn’t it? After all, you’re just following orders, right?

  • Update: because I just know that someone will pipe in maliciously with “oh, so you mean sex workers shouldn’t be doing that work?”, I just want to preemptively say “fuck off, you pernickety prat, you know exactly what I’m talking about and it isn’t that.”

https://freefree.ps/@faab64/114903988836528662

yawnbox ,
@yawnbox@disobey.net avatar

@aral @faab64

i think about this a lot and also refuse to CW posts about genocide in Palestine, i don't know what to CW with since "pspol" doesn't exist according to the important white countries

@yawnbox@disobey.net avatar yawnbox , to random

holy shit

"The Business Court in Brussels, Belgium, has issued an unprecedentedly broad site-blocking order that aims to restrict access to shadow libraries including Anna's Archive, Libgen, OceanofPDF, Z-Library, and the Internet Archive's Open Library. In addition to ISP blocks, the order also directs search engines, DNS resolvers, advertisers, domain name services, CDNs and hosting companies to take action. "

https://torrentfreak.com/belgium-bans-internet-archives-open-library-in-sweeping-site-blocking-order/

@gerrymcgovern@mastodon.green avatar gerrymcgovern , (edited ) to random

I came across information that the original quote in Futurism which said 99% electricity use was incorrect.
https://futurism.com/google-ceo-congress-electricity-ai-superintelligence

The transcript says “3% to 9%”.
https://www.techpolicy.press/transcript-us-lawmakers-probe-ais-role-in-energy-and-climate/

The larger point remains, though. AI and data center energy and water use is surging, and we are only at the beginning of this whole thing. For years, data centers energy use stayed below 1% and we were told not to worry. In countries like Ireland, data center energy use is now already over 20%

yawnbox ,
@yawnbox@disobey.net avatar

@gerrymcgovern

i listened to Schmidt's opening statement, and it's not clear to me what he said at the 29:20 timestamp (https://www.youtube.com/live/HXoXMETZUiE?feature=shared&t=1759). he could have said "3% to 9%" or he could have said "3% to 99%" -- and the latter doesn't really make sense contextually

his written testimony doesn't include these figures https://d1dth6e84htgma.cloudfront.net/04_09_25_FC_Testimony_Schmidt_99aeab0962.pdf

yawnbox ,
@yawnbox@disobey.net avatar

@gerrymcgovern i completely agree with you, i am just trying to understand the stated facts. I'm concerned about misinformation in that news article.

@Gargron@mastodon.social avatar Gargron , to random

Anyone else's YouTube home page suddenly full of giant thumbnails and channels you've never heard of before? It suddenly became almost completely unusable.

yawnbox ,
@yawnbox@disobey.net avatar

@Gargron

i vote for enabling Mastodon admins to enable a feature whereby the Mastodon instance uses yt-dlp to automatically download a Youtube link shared my an instance's user, so fedi users can watch a video without dealing with Youtube abuse

@malwaretech@infosec.exchange avatar malwaretech , to random

[Thread, post or comment was deleted by the author]

  • Loading...
  • yawnbox ,
    @yawnbox@disobey.net avatar

    @malwaretech

    i am surprised that infosec leaders are still going to hold conferences in Las Vegas

    @yawnbox@disobey.net avatar yawnbox , to random

    " Hi all,

    As you might have just seen on the livestream or witnessed in person, I disrupted the speech of Microsoft AI CEO Mustafa Suleyman during the highly-anticipated 50th anniversary celebration. Here’s why.

    My name is Ibtihal, and for the past 3.5 years, I’ve been a software engineer on Microsoft’s AI Platform org. I spoke up today because after learning that my org was powering the genocide of my people in Palestine, I saw no other moral choice. This is especially true when I’ve witnessed how Microsoft has tried to quell and suppress any dissent from my coworkers who tried to raise this issue. For the past year and a half, our Arab, Palestinian, and Muslim community at Microsoft has been silenced, intimidated, harassed, and doxxed, with impunity from Microsoft. Attempts at speaking up at best fell on deaf ears, and at worst, led to the firing of two employees for simply holding a vigil. There was simply no other way to make our voices heard.

    We are witnessing a genocide

    For the past 1.5 years, I’ve witnessed the ongoing genocide of the Palestinian people by Israel. I’ve seen unspeakable suffering amidst Israel’s mass human rights violations - indiscriminate carpet bombings, the targeting of hospitals and schools, and the continuation of an apartheid state - all of which have been condemned globally by the UN, ICC, and ICJ, and numerous human rights organizations. The images of innocent children covered in ash and blood, the wails of mourning parents, and the destruction of entire families and communities have forever fractured me.

    At the time of writing, Israel has resumed its full-scale genocide in Gaza, which has so far killed by some estimates over 300,000 Gazans in the past 1.5 year alone. Just days ago, it was revealed that Israel killed fifteen paramedics and rescue workers in Gaza, executing them “one by one,” before burying them in the sand -- yet another horrific war crime. All the while, our “responsible” AI work powers this surveillance and murder. The United Nations and the International Court of Justice have concluded that this is a genocide, with the International Criminal Court issuing arrest warrants for Israeli leaders."

    🧵 1/3

    Source: https://www.theverge.com/news/643670/microsoft-employee-protest-50th-annivesary-ai

    yawnbox OP ,
    @yawnbox@disobey.net avatar

    " We are Complicit

    When I moved to AI Platform, I was excited to contribute to cutting-edge AI technology and its applications for the good of humanity: accessibility products, translation services, and tools to “empower every human and organization to achieve more.” I was not informed that Microsoft would sell my work to the Israeli military and government, with the purpose of spying on and murdering journalists, doctors, aid workers, and entire civilian families. If I knew my work on transcription scenarios would help spy on and transcribe phone calls to better target Palestinians (source), I would not have joined this organization and contributed to genocide. I did not sign up to write code that violates human rights.

    According to AP news, there is “a $133 million contract between Microsoft and Israel’s Ministry of Defense.”

    “The Israeli military’s usage of Microsoft and OpenAI artificial intelligence spiked last March to nearly 200 times higher than before the week leading up to the Oct. 7 attack. The amount of data it stored on Microsoft servers doubled between that time and July 2024 to more than 13.6 petabytes.”

    “The Israeli military uses Microsoft Azure to compile information gathered through mass surveillance, which it transcribes and translates, including phone calls, texts and audio messages, according to an Israeli intelligence officer who works with the systems. That data can then be cross-checked with Israel’s in-house targeting systems.”

    Microsoft AI also powers the most “sensitive and highly classified projects” for the Israeli military, including its “target bank” and the Palestinian population registry. Microsoft cloud and AI enabled the Israeli military to be more lethal and destructive in Gaza than they otherwise could.

    Microsoft has also been providing software, cloud services, and consulting services to the Israeli military and government, totaling millions in profit. War Criminal Benjamin Netanyahu has explicitly mentioned his strong ties to Microsoft. A list of these contracts with the Israeli military and government can be found here: An Introduction to Microsoft’s Complicity in Apartheid and Genocide

    In fact, Microsoft is so deeply connected to the Israeli military that it was just yesterday designated one of the priority boycott targets of the BDS (Boycott, Divest, Sanctions) campaign.

    Regardless of your political stances, is this the legacy we want to leave behind? Is working on deadly AI weapons something you can tell your children about? Do we want to be on the wrong side of history?

    Even though your work could be unrelated to the cloud that the military uses, your work benefits the company and allows it to take on the contract. Regardless of your team, you serve a company that is arming the Israeli occupation. It is undeniable that part of your compensation, no matter how small, is being paid by genocide.

    Whether you work on AI or not, you will be complicit if you do nothing. It is now OUR job to take a vocal stand against Microsoft AI’s involvement in crimes against humanity.

    This is why I decided to speak up today, and why I signed this important petition to demand Microsoft cut ties with genocide. And I urge you all to do the same."

    🧵 2/3

    Source: https://www.theverge.com/news/643670/microsoft-employee-protest-50th-annivesary-ai

    yawnbox OP ,
    @yawnbox@disobey.net avatar

    " Call to Action

    Silence is complicity. But action always has a reaction, no matter how big or small. As workers for this company, we must make our voices heard, and demand that Microsoft does the right thing: stop selling technology to the Israeli military.

    If you are also concerned about this news, and you also want your work to be used ethically, I urge you to take action:

    Sign the No Azure for Apartheid petition: We will not write code that kills. And join the campaign to add your voice to the growing number of concerned Microsoft employees.

    Join me in showing our discontent in this thread. If you also feel tricked into deploying weapons which target children and civilians, urge leadership (CC’ed) to drop these contracts.

    Don’t stop speaking up. Urge SLT to drop these contracts at every opportunity.

    Start conversations with your co-workers about the points above - so many employees may not know!

    Microsoft’s human rights statement prohibits retaliation against anyone who raises a human rights-related concern: Human rights statement | Microsoft CSR

    Our company has precedents in supporting human rights, including divestment from apartheid South Africa and dropping contracts with AnyVision (Israeli facial recognition startup), after Microsoft employee and community protests. My hope is that our collective voices will motivate our AI leaders to do the same, and correct Microsoft’s actions regarding these human rights violations, to avoid a stained legacy. Microsoft Cloud and AI should stop being the bombs and bullets of the 21st century.

    Sincerely,

    A concerned Microsoft employee"

    🧵 3/3

    Source: https://www.theverge.com/news/643670/microsoft-employee-protest-50th-annivesary-ai

    @9to5linux@floss.social avatar 9to5linux , to random

    XZ Utils 5.8 Introduces Performance Improvements in the LZMA/LZMA2 Decoder and Many Other Goodies https://9to5linux.com/xz-utils-5-8-introduces-performance-improvements-in-the-lzma-lzma2-decoder

    ALT
    yawnbox ,
    @yawnbox@disobey.net avatar

    @9to5linux

    but is the auditing better haha

    @w7voa@journa.host avatar w7voa , to random

    “I don't think there's any plans to invade Canada,” US National Security Adviser Mike Waltz says on NBC’s MTP. https://www.nbcnews.com/meet-the-press/video/nsa-waltz-says-gutting-usaid-absolutely-not-handing-power-to-china-and-russia-full-interview-231499845771

    yawnbox ,
    @yawnbox@disobey.net avatar

    @w7voa it's his job to know and he doesn't even know

    @molly0xfff@hachyderm.io avatar molly0xfff , to random

    https://slate.com/technology/2025/02/wikipedia-project-2025-heritage-foundation-doxing-editors-antisemitism.html

    ALT
    yawnbox ,
    @yawnbox@disobey.net avatar

    @molly0xfff

    I used to live in a witness protection program and that wasn't good enough of a reason for the privileged asshole Wikimedia admins to allow me to edit wikipedia behind tor (only signed in with my since-2006 account)

    jokes on them, sadly

    @EUCommission@ec.social-network.europa.eu avatar EUCommission , to random

    🎗 Did you know that 40% of cancer cases in the EU are preventable?

    This , we reaffirm our commitment to combatting this disease.

    With the EU Cancer Plan, we're targeting every stage:

    🛡️ Prevention of vaccine-preventable cancers & fostering a smoke-free environment
    🩺 Early detection through the new EU-supported cancer screening scheme
    🏥 Diagnosis and treatment
    🌿 Quality of life of cancer patients and survivors

    Cancer affects us all. We’re determined to tackle it together.

    video/mp4

    yawnbox ,
    @yawnbox@disobey.net avatar

    @EUCommission

    red meat, processed meat, and alcohol are some other Group 1 "Known Carcinogens"

    @arstechnica@mastodon.social avatar arstechnica , to random

    Silk Road founder Ross Ulbricht pardoned by Trump 10 years into life sentence
    Trump confirmed the pardon was partly to “honor” Libertarian movement.
    https://arstechnica.com/tech-policy/2025/01/silk-road-founder-ross-ulbricht-pardoned-by-trump-10-years-into-life-sentence/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

    yawnbox ,
    @yawnbox@disobey.net avatar

    @arstechnica

    did trump get a big donation from ross or from his supporters?

    and, so, are pardons for sale?

    @Wendy@chaosfem.tw avatar Wendy , to random

    If you don't have Signal installed on your phone, please fix that.

    You may not need the security for yourself, but someone you talk to will.

    Everyone needs to have it. ⚧️

    https://signal.org/

    yawnbox ,
    @yawnbox@disobey.net avatar

    @nemeciii @Wendy @matrix

    sorry, apps aren't e2ee unless the e2ee is on-by-default

    matrix is not e2ee

    yawnbox ,
    @yawnbox@disobey.net avatar

    @matrix @nemeciii @Wendy

    thanks - I'll delete my comment

    @kevinrothrock@infosec.exchange avatar kevinrothrock , to random

    👀

    video/mp4

    yawnbox ,
    @yawnbox@disobey.net avatar

    @kevinrothrock

    1. is this real
    2. what the fuck
    @9to5linux@floss.social avatar 9to5linux , to random

    24.04 LTS Is Now Available on the HiFive Premier P550 RISC-V Development Board https://9to5linux.com/ubuntu-24-04-lts-now-works-on-the-hifive-premier-p550-risc-v-development-board

    ALT
    yawnbox ,
    @yawnbox@disobey.net avatar

    @9to5linux

    so exciting! ^_^

    @nixCraft@mastodon.social avatar nixCraft , to random

    what is the dark web. wrong answers only

    yawnbox ,
    @yawnbox@disobey.net avatar
    @yawnbox@disobey.net avatar yawnbox , to random

    Have you ever thought about the privacy and security implications of Starlink satellites and cell phones? You're in luck, I've written a new blog post:

    "Threat modeling Starlink satellite cellular risks"

    https://yawnbox.is/blog/threat-modeling-starlink-satellite-cellular-risks/

    @gulovsen@mastodon.social avatar gulovsen , to random

    Does anyone have any recommendations for coffee that tastes like Starbucks but doesn't have the anti-labor baggage that goes along with it?

    I tried Death Wish and its not bad. I might stick with that if there are no better alternatives.

    And if you've got opinions about whether you think Starbucks tastes good feel free to post those elsewhere because that's not what I'm asking for and I don't care. :blobcatcoffee:

    yawnbox ,
    @yawnbox@disobey.net avatar

    @gulovsen cc @coffeegeek "recommendations for coffee that tastes like Starbucks but doesn't have the anti-labor baggage that goes along with it?"

    @Gargron@mastodon.social avatar Gargron , to random

    I'd love to hear something that you like about 4.3. It's been a long time in the works and I think our whole team could use some dopamine 🙂

    yawnbox ,
    @yawnbox@disobey.net avatar

    @Gargron

    1. the somewhat simplified backend changes for increasing max post character count and max profile bio character count are both great

    2. better illuminated alt text reminder on images is great

    3. the backend security enhancements are awesome

    4. the move away from ImageMagick is awesome

    curious about the future of Redis

    curios why i can't get nautical.social on your joinmastodon/servers page

    cheers

    @pixelfed@mastodon.social avatar pixelfed , to random

    We're working on some exciting new photography updates:

    • Bigger Resolution (4K -> 8K)
    • Resumable uploads (via webUI)
    • Native AVIF, HEIC, WEBP support
    • HDR support
    • Preserve ICC profiles + EXIF
    • New Compose UI
    • Improved Location tagging
    • New AI labelling + Anti-AI features

    And much more!

    We're eager to ship this massive update and gather feedback on how we can make our platform even better for novice to pro photographers!

    Spread the word ✨

    yawnbox ,
    @yawnbox@disobey.net avatar

    @pixelfed is C2PA validation possible?

    @dansup@mastodon.social avatar dansup , to random

    Let’s remember it’s not BlueSky vs the Fediverse

    Its walled gardens against freedom

    The web withers in monopoly’s shade

    Together we soar on the winds of freedom

    yawnbox ,
    @yawnbox@disobey.net avatar

    @dansup

    personal opinion as a matodon admin, i hope that bsky and activitypub will be able to interop at a protocol level someday soon

    @arstechnica@mastodon.social avatar arstechnica , to random

    Here’s how Michelin plans to make its tires more renewable

    The tire company wants a completely sustainable tire by 2050.

    https://arstechnica.com/cars/2024/07/heres-how-michelin-plans-to-make-its-tires-more-renewable/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

    yawnbox ,
    @yawnbox@disobey.net avatar
    @yawnbox@disobey.net avatar yawnbox , to random

    IT helpdesk (Lapsus$): ring ring

    Employee: hello?

    IT: Hello! This is Roger from IT. We've identified a problem with your Okta access and we need to replace your company Yubikey. We've already mailed you a replacement, return your old Yubikey in the box that will have a return shipping label. Please write down your company email and Yubikey PIN on a sticky note and include it in the box so we can fully remove the old Yubikey from Okta. The delivery is scheduled for today so your work wont be impacted come Monday.

    employee: ok!

    yes, a is possible

    @yawnbox@disobey.net avatar yawnbox , to random

    i think @9to5linux needs more followers

    @yawnbox@disobey.net avatar yawnbox , to random

    government backdoors in cryptography be like

    ALT