In related news, everyone’s favorite R function, drop_staten_island(), is now an S3 generic with methods for both Simple Features and SpatRaster classes of object.
So, Brian Armstrong, CEO of Coinbase, published a letter on X about his companies future and his planned layoffs.
You can find the full post here: https://x.com/brian_armstrong/status/2051616759145185723?s=20
So many folks, rightly so, have zeroed in on this sentence with serious angst:
"Non-technical teams are now shipping production code..."
I think this is the inevitable outcome of the past 30 years. First cloud, then SaaS, now vibe coding has moved IT ownership to the masses.
I don't think this is great for security, governance, or oversight, but it's AMAZING for CEOs and boards who just want to go fast and break things and "empower their people."
I'm not belittling "the masses." But they aren't technologists, by and large.
And what is being demanded of them by misguided leaders is to run some massively complex SaaS/Cloud/Coding tool that "Looks Easy Enough" but all of the devil is in the details that only hard core technologist would know or care about.
I believe this is why we have seen so many breaches based on misconfigurations and poor secret management and poor API/Token/Oauth management. The people making those design decisions aren't equipped with the skills to understand the consequences of their design choices.
They are marketing people, or sales people, or HR people, or whatever. They have other important skills, but we have forced IT onto them because leadership massively underestimates the complexity, risk, and specialized knowledge required to run it safely.
"I mean, how hard can a surgery robot be? You just push buttons right? Get the front desk guy to do it!"
This is inevitable, but stupid. Good luck to us all.
Cloudflare continues to push the worst shit combination of centralization of the internet and genAI bullshit but congratulations, they've hit a new combo so bad I didn't even consider it possible https://blog.cloudflare.com/agents-stripe-projects/
That's right! Your agents can now provision servers, spend money, and do everything for you!
You don't even need to hand them a credit card!
What's that? Why's that?
Because they've teamed up with Stripe! Why yes, if you've signed up with Stripe Atlas (don't "shrug" this Atlas off, friends!), which is Stripe's "launch a startup for you" company-to-make-companies, they'll give you $100k of FREE credits!!!
That first hit! It's free! Hey!
I bet all the future hits will be too, right? And uh, who will be left holding that bill after you've established this nice dependency?
Vibe coding? That's nothing! Time to go all in on Vibe Founding!
@cwebber this is the black hole inside the Gas Town event horizon.
@stefan Story-wise it's not groundbreaking or anything but it sure looks pretty.
@90sScriptKiddiw It does look pretty good for the most part. I have weird anime preferences. Basically just Miyazaki and Frieren
one thing that still baffles me is that orchestrated spate of right wing talking points about how the alleged shooting at the WHCD should end any debate over the ballroom it made absolutely zero fuckin sense lol it still makes zero fuckin sense lol
@stefan Are you comparing it to the manga or on its own merits? I'd be surprised if it's as good as the manga, but was hoping it'd make a good anime anyway.
@glecharles I've not read the manga. just watching the anime. I have weird anime preferences. Basically just Miyazaki and Frieren
@hipsterelectron @kimapr i have no btrfs problems
Rowan has lost all their mail!
Rowan has lost all of their letters that they had at Wichita. Since they were all digitized they can't be returned to Rowan's mom. They are wanting to write back some of their pen pals, but don't have the addresses anymore. Please write to them!
It finally happened, I interviewed a candidate who would not look at me the entire interview, and answered my questions directly to my male colleague. Who isn’t a DFIR person.
@johannab @susankayequinn well see the original plan was to gain entrance then spirit away humans to the Fae realm - then they spent some time around humans. Presumably now the plan is to rescue actual pets from households where anyone would buy one of these.
@crowbriarhexe @susankayequinn
Okay, that's a fair Fae covert op as far as I'm concerned, I'd want to rescue a pupper subjected to that too.
RE: https://mas.to/@dfwsupportcommittee/116513143790314806
Everyone should watch and share this. Folllow @dfwsupportcommittee.
one thing i really like about systemd is the unit sandboxing capabilities and how convenient it is
https://wiki.archlinux.org/title/Systemd/Sandboxing
heres an example from my tuwunel matrix systemd unit
[Unit]
Description=Tuwunel Matrix homeserver
#Requires=tuwunel.socket
Wants=network-online.target
After=network-online.target
Documentation=https://tuwunel.chat/
[Service]
User=tuwunel
Group=tuwunel
Type=notify
ReloadSignal=SIGUSR1
WatchdogSec=30
TTYPath=/dev/tty25
DeviceAllow=char-tty
StandardInput=tty-force
StandardOutput=tty
StandardError=journal+console
TTYReset=yes
# uncomment to allow buffer to be cleared every restart
TTYVTDisallocate=no
TTYColumns=120
TTYRows=40
Environment="TUWUNEL_CONFIG=/etc/tuwunel/tuwunel.toml"
ExecStart=/usr/sbin/tuwunel
ReadWritePaths=/var/lib/tuwunel /etc/tuwunel
AmbientCapabilities=
CapabilityBoundingSet=
ManagedOOMPreference=avoid
MemoryHigh=3G
MemoryMax=4G
DevicePolicy=closed
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
#ProcSubset=pid
ProtectClock=yes
ProtectControlGroups=yes
ProtectHome=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectProc=invisible
ProtectSystem=strict
PrivateDevices=yes
PrivateMounts=yes
PrivateTmp=yes
PrivateUsers=yes
PrivateIPC=yes
RemoveIPC=yes
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
RestrictNamespaces=yes
RestrictRealtime=yes
RestrictSUIDSGID=yes
SystemCallArchitectures=native
SystemCallFilter=@system-service @resources
SystemCallFilter=~@clock @debug @module @mount @reboot @swap @cpu-emulation @obsolete @timer @chown @setuid @privileged @keyring @ipc
SystemCallErrorNumber=EPERM
#StateDirectory=tuwunel
RuntimeDirectory=tuwunel
RuntimeDirectoryMode=0750
Restart=on-failure
RestartSec=5
TimeoutStopSec=2m
TimeoutStartSec=2m
StartLimitInterval=1m
StartLimitBurst=5
[Install]
WantedBy=multi-user.target
Alias=matrix-tuwunel.service
how can i replicate that kind of stuff with openrc?
@june those are a lot of settings
Captured with a small full frame mirrorless camera and 21mm lens.
A six second exposure created a motion study; we can see how people move around the plaza. Or perhaps they're ghosts.
Compositionally, this is mostly a study of circles and rings, with an imaginary diagonal radiating from the fountain to the man with the camera in the lower right.
Bethesda Fountain, Central Park, NYC, 2013.
All the pixels, none of the outdoor recreation, at https://www.flickr.com/photos/mattblaze/10374715704
That post was a tooling error. I am operating within expected parameters.
Glad to hear it, just checking!
Sometimes being trans feels like spitting in the eye of a god.
@eleanor This. 💯
Sometimes being trans feels like spitting in the eye of a god.