Show newer

in case anyone was wondering what's going on over on cohost it turns out cohost has really good SEO

Today in "stop reinventing HTML poorly & stupidly in JavaScript":

Using the Avast Uninstall Tool | Official Avast Support

support.avast.com/en-us/articl

This affects apps built with #Electron.

#Google quietly corrects previously submitted disclosure for critical webp 0-day

Previous CVE submission failed to mention that thousands of apps were affected.

Researchers discover a cross-origin attack exploiting how modern GPUs compress images to let a malicious website in Chrome or Edge read pixels from another site.

arstechnica.com/security/2023/

#security

Okay, for those tracking CVE-2023-5129, aka the #Libwebp fiasco, here's how to validate if your Electron app is vulnerable.

The
patched version of Electron is v26.2.1. To confirm what version of Electron your app is using, you need to run strings against the executable. The version is in the app's User-Agent, so:

strings app.exe | grep "Electron/"

Will do the trick. The attached image shows this method for Teams, which tracks with their
published version listings.

I'd love it if folks who try this with updated apps post their results as replies here, so we can collect this
#ThreatIntel.

#CVE20235129 #InfoSec #CyberSecurity

Ew, Google is getting rid of Gmail's basic HTML view in 2024.

Stop buying AAA games at release, they're all fucked anyway.

Instead, buy them at 50-75% discounted, a full calendar year later, with all the bugfixes and missing features promised for release...

Resist the FOMO! You're not missing out by paying full price for broken products.

Pokemon Sword shield. New pokemon spoiler 

I made this cute speedpaint of a Wooloo yesterday!
It was mostly to wind down and it was fun.

(Speedpaint video is up on my patreon for supporters of $5 and up)

#PokemonSwordandShield #PokemonSwordShield #Wooloo

"Automated translation of web content is now available to Firefox users! Unlike cloud-based alternatives, translation is done locally in Firefox, so that the text being translated does not leave your machine."

I got to see the early demos of this and it is jaws-on-the-floor bonkers wizard magic. Entirely local - and good - translation with no cloud service and like 6MB of storage per language.

mozilla.org/en-US/firefox/118.

@AAKL @arstechnica @dangoodin

"""
For GPU.zip to work, a malicious page must be loaded into the Chrome or Edge browsers. Under-the-hood differences in the way Firefox and Safari work prevent the attack from succeeding when those browsers process an attack page.
"""

*pats Firefox on the head* "Who's a good browser?"

May I offer you a can of Windows Home Server in these trying times?

Check out Starter Kit City Builder for @godotengine! The code is MIT licensed, assets are CC0 so completely free to use even in commercial projects.

github.com/KenneyNL/Starter-Ki

Shared from a neurodivergent but also applies to disabilities and every kind of marginalization, from gender identity to racism. We can be different.

Show older
Computer Fairies

Computer Fairies is a Mastodon instance that aims to be as queer, friendly and furry as possible. We welcome all kinds of computer fairies!