Show newer

Honestly, I think I would hate banking less if I could use an API to interact with them instead of apps and humans.

Hey all, if you have a Google Pixel 6/7 or a Samsung phone: Disable VoLTE and Wi-Fi calling until this issue is patched: 9to5google.com/2023/03/16/goog

tl;dr: Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number. With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.

Google's Project Zero usually makes vulnerability reports public after 90 days. This is an exception because it goes directly from internet to baseband-level (tl;dr: the second OS inside your phone that powers the LTE/5G modem) remote code execution. This is morally equivalent to getting code running on your WiFi card.

Here is a list of the most likely affected devices:

Samsung Galaxy phones including those in the S22, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 series
Vivo phones including those in the S16, S15, S6, X70, X60, and X30 series
Google Pixel 6 and 6 Pro, Pixel 6a, Pixel 7 and 7 Pro
Any wearables that use the Exynos W920 chipset
Any vehicles that use the Exynos Auto T5123 chipset

Helpfully, the baseband is a binary blob of uninspectable firmware that users can't inspect or prove hasn't been tampered with.

Cooking up some grant applications to do some stuff along with and publishing onto local networks.

Longer term planning to deploy education materials as part of the setup so that communities can create software without needing to rely on the cloud or even local servers so much.

One thing that's a TODO is figuring out how the economics of maintaining things work for places where that's a concern.

Excited for spring to come so I can start practicing with my little RC quadcopter again.

It's just a cheap toy one at the moment but eventually I wanna get into racing with one once I can justify the cost.

banking 

Banking suuucks. One of my contracts involved using a custom payment service instead of my usual wise.com and it only gives me the option of depositing in my Canadian bank account even though it was being payed out in USD.

Now I need to physically go to my bank so I can do a SWIFT transfer to my Wise account so I can convert it to USD and send it out to subcontractors. 😭

Honestly if CBDCs can make this easier I'll let the gub control all my money for me.

Did you know the Journal of Trial and Error is wanting to publish rejected grant applications? In their words, "We believe that applications often suffer from a highly competitive system rather than a deficient proposal."

If this sounds interesting to you, check out the call for submissions, which also has a link to their blog post on the topic: journal.trialanderror.org/pub/

#AcademicChatter

Took my own advice and rewatched it. Still holds up 🥰

Show thread

ai talk 

Has anyone made some sort of LLM bridge/bot for Matrix? It'd be fun to prime accounts with a prompt of who they are and invite them into spaces to chat with folks.

"it works on my machine (fullscreen chrome on m2 macbook pro with gigabit ethernet and traditional mouse+keyboard)"

Show thread

"Inuit are 85% of Nunavut population, & 70% of us have Inuktut as our mother tongue. Yet all the schools operate in English. Greenland runs an entire government in Inuit language. They’ve had an Inuit language school system since 1979. If they can do it, we can do it. 🧵 👇🏾

#LanguageRevitalization #Inuit #Nunavut #Indigenous

Thread Reader: threadreaderapp.com/thread/163

Also, how the heck am I to explain what daylight saving time is to a cat?

Show thread

I wish automated cat feeders could automatically set themselves with the moon or sun cycle to match the something closer to the cat's biological cadence rather than some arbitrary human one.

Instantly forgot where I got this from, but this article is super cool for understanding programming on windows.

notgull.github.io/device-afd/

If you haven't yet, I'd recommend watching Shrek Retold. It's a scene by scene recreation of the original Shrek movie by a bunch of random animators on YouTube.

Each scene is done in a radically different style with different voice actors throughout and it's quite a trip.

I've been talking with an academic researcher who is interested in speaking with people who have shut down their fediverse servers, for any reason.

I know it's a touchy subject so I didn't want to just refer her directly to people, but if you are seeing this message and you're interested, please DM me and I will give you her email. I did a 1-hour interview with her on more general topics and really enjoyed the experience.

(Boosts appreciated!)

Lack of sleep linked to car accidents among teens and poorer achievement: When schools started after 8:30 a.m., attendance, standardized test scores, and academic performance in math, English, science, and social studies increased, while tardiness declined. One school that shifted start times from 7:35 a.m. to 8:55 a.m. saw a 70% decline in the number of local car accidents among drivers ages 16 to 18.

popresearchcenters.org/researc

It is truly impressive how bad google search has gotten at just finding basic information and I do not understand why almost no one is noticing or talking about this.

I do not want Slack to provide a probabilistic summary of what I said. I don't want notion to guess what I'm going to say. I want to choose my words with clarity and precision in mind, and if people want me to take the time to read what they've written I would hope that they've taken the time to choose their words too

And I really want to take my words out of training data sets

Show thread
Show older
Mauvestodon

Escape ship from centralized social media run by Mauve.