"I don't want you to be hopeful.
I want you to panic.
I want you to feel the fear I feel every day.
And then I want you to act." — #GretaThunberg
(b) as a reach goal, it would be great if it had a signature for this really strange shared thing called gmp-clearkey which comes in the form of a shared library libclearkey.so, which does have a file adjacent to it named libclearkey.so.sig, but which is definitely not a PGP signature.
i don't know if it's even anything meaningful at all--it seems not just plausible but indeed almost likely that after spending over a decade claiming they couldn't possibly use the zip file format for the single specific use case it was designed for (https://firefox-source-docs.mozilla.org/update-infrastructure/index.html#watershed-updates), that mozilla/google is demonstrating why they needed to NIH their system of referential integrity, because it was not designed to solve the problem of making mozilla firefox more secure, trusthworthy, and safe--but indeed the opposite
so it is with absolutely no pleasure (but no sense of confusion or outrage either) that i announce to you this particular bullshit https://ftp.mozilla.org/pub/firefox/nightly/2026/07/2026-07-01-09-27-14-mozilla-central/KEY
This file contains the public PGP key that is used to sign builds and
artifacts of Mozilla projects (such as Firefox and Thunderbird).Please realize that this file itself or the public key servers may be
compromised. You are encouraged to validate the authenticity of these
keys in an out-of-band manner.
which continues as:
gpg --show-keys < KEY
pub rsa4096 2015-07-17 [SC]
14F26682D0916CDD81E37B6D61B7B526D98F0353
uid Mozilla Software Releases <release@mozilla.com>
sub rsa4096 2021-05-17 [S] [expired: 2023-05-17]
sub rsa4096 2015-07-17 [S] [expired: 2017-07-16]
sub rsa4096 2017-06-22 [S] [expired: 2019-06-22]
sub rsa4096 2019-05-30 [S] [expired: 2021-05-29]
sub rsa4096 2023-05-05 [S] [expires: 2025-05-04]
sub rsa4096 2025-03-13 [S] [expires: 2027-03-13]
-----BEGIN PGP PUBLIC KEY BLOCK-----
Saw this photo on LinkedIn.
It's quite a clever idea! Rather than having to press potentially dirty buttons in a toilet to record your feedback, you can use a gesture instead. Nifty!
Except… Here's how they describe it on their website.
> No specialist hardware. No complex setup. Just plug in a camera-enabled device and you're live.
Oh. Good. A 24/7 video stream live from the loos. What could possibly go wrong with that?
my solution to the button would be to push it with a paper towel between the button and my finger. Because some people will push it before washing their hands (some people don't wash their hands at all).
I am not scanning some QR-code because that takes too much time and I want to be out of there as fast as I can thankyouverymuch.
Soviet soldiers, 1970s.
@jeffcutsinger @tantramar @Ashedryden
How about "257 Innocence Project victories to date"? Could you belive that?
I need more LLMisms to use in actual focused idea-dense writing.
* em dashes
* three of things
* it's not X, it's Y
what others?
these are normal basic rhetoric tricks that the chatbot has overlearnt and applies to zero-content writing. but i feel like being annoying.
@davidgerard the LLMs have a special trick. Watch their unique tendency of qualifying mundane or trivial things. Their genius way saves so much clarity, only their writing can achieve the vacous hyperbole that is their birthright.
FEP-d1cb: Same-origin actor re-identification
I ran into this while working on the ActivityPub plugin for WordPress, and I could not find a FEP that covers it.
Our actor ids used to be built from the permalink, so https://example.com/@handle. The id contains the handle, which means changing the handle changes the id. We are moving to an id that does not contain the handle. The origin stays the same, the WebFinger address stays the same, only the id changes.
FEP-7628 gives me the right signal for this, the Move activity. But the receiving behaviour it describes does not fit. It says a follower should Undo the follow of the old actor and Follow the new one. In my case both ids are the same actor, on the same origin, with the same inbox and the same followers collection. Unfollowing and following again is noise at best, and for an actor that approves followers manually the new follow arrives as a request, so people can quietly lose their followers.
The other migration FEPs do not cover it either, as far as I can see:
- FEP-e965 describes the actor object after a migration between personas.
- FEP-1580 does allow the target instance to be the same as the source, but only for migrating objects after an actor move, and it requires FEP-8b32 proofs. Here the origin never changes, so the authority over both ids never changes, and there is nothing to prove.
- FEP-a427 is a domain move, and its mapping rules (replace the origin, replace a path prefix) cannot express a change from /@handle to ?author=5.
So I would like to write a small FEP that relies on FEP-7628 and describes only this one case. Roughly:
- the old id has to stay dereferenceable and carries movedTo
- the new actor lists the old id in alsoKnownAs, so the Move can be verified
- WebFinger for the unchanged address returns the new id
- a receiver updates the id it has stored and keeps the follow, instead of undoing and following again
- no object integrity proof is needed, because the origin did not change
What I am not sure about is whether this should be its own FEP or a section in FEP-e965. There are a few migration FEPs already and I do not want to add one just to add one. But the receiver behaviour here contradicts FEP-7628 rather than clarifying it, and that felt wrong to put inside somebody else's document. Happy to be told otherwise.
It also does not solve the object side. Object ids change on the same origin too, for example when the permalink structure changes, and I have no answer for that yet.
The odious surveillance company Flock has been teaching police how to spy on Americans who are exercising their First Amendment rights. https://www.404media.co/r/beaca1b1?m=ea6b4c29-f97b-4025-aaeb-1d01a70b3b30
Since .org domains now apparently exist at the discretion of MAGA wastrels, just bought tbray.ca. Would rather not migrate the blog, but…
@timbray I went with a .ca for the first time earlier this year, when I registered a domain for the first time in decades. I also got the .org, but did note that was controlled by the U.S. (which I'm trying to avoid these days).
#Via Katie Phang
@katiephang
1:25 PM · Sep 4, 2026
"The fact that the website for the upcoming RNC convention in Dallas redirects to the Trump DOJ's Epstein Files website is...AMAZING."
Wiz Khalifa Just Became Running’s Most Unexpected New Inspiration and His Progress Is Hard to Ignore
https://www.mensjournal.com/fitness/wiz-khalifa-just-became-runnings-most-unexpected-new-inspiration-and-his-progress-is-hard-to-ignore?utm_source=flipboard&utm_medium=activitypub
Posted into The Latest From Men's Journal @the-latest-from-men-s-journal-mensjournal
Silly question: does @EuroBSDCon accept donations to help support recording and/or streaming the event for those who can't attend? 🤔
linuxrocks.online attracting the best minds of our time (?)
If the word does fit it remembers the potential breakpoint for the next iteration. If none do it hyphenates the word as just described. If the current word doesn't it accepts the remembered breakpoint. If it reached the end of string it ensures the last line is incorporated into the results.
After the (nested) loop it truncates the final line if appropriate.
There's methods to measure the font. And a method to iterate over the known hardware buttons & render rectangles & text for them.
3/?
There's a method (used during sizing text) to retrieve the width of a glyph within an "external font".
There's method to precache certain glyphs from an external font.
To measure Thai text it asks the Thai shaper to "shape" a list of "clusters" before summing up the advance-X for all the glyphs within. To draw Thai text it retrieves those clusters & a start-Y deferring each cluster to another method, which iterates over the glyphs.
4/5?
@urig @Edent @FediThing just put a button at foot height. I kick or knee the current ones anyway
@aturff @urig @FediThing
You do realise this isn't for flushing, right?
we need to start a new movement called good software. software that is good, and does good, for the public good.
the freedom part is the wrong focus. it's a misaligned value judgement. you can write free software that bombs children. you can have a free software project maintained by a fascist or a rapist. software that bombs children, by the very definition, can never be good. projects where fascists and rapists are allowed into positions of power are, by the very definition, not good.
RE: https://hachyderm.io/@thomasfuchs/117203696286976367
See how easy this is
@thomasfuchs no but you don’t get it it’s so hard to have to actively not send millions of dollars to a facist
#Fedilab lets you read timelines in reverse order (most recent messages at the bottom). I know "reverse" is not the right word, and some of you called it "natural" or "normal" order.
This feature, and especially its support across Fedilab with all its specificities, was really a lot of work, mostly in fixes. But I think we now have something stable. Thanks for your patience.