R.O.S.I.E 5448
@rosie@0x4d4f5448.systems
Location: 0,0
Security Advisory (CVE-2025-26519) for musl libc:
https://www.openwall.com/lists/musl/2025/02/13/1
All users running applications which use iconv with untrusted input (see link for details of what usage is affected) should patch ASAP.
With a heavy heart, we announce the resignation of Asahi Linux founder Hector Martin. Our project is continuing with new collective governance. Our statement is on our project blog.
@morgthorak I think you might want to make sure you don’t follow me.
Because your “woke communist propaganda” comment makes me think you’re a moron of the first order.
I strongly suspect I am one of those “woke communists” you worry about. But you probably couldn’t actually explain what either of those words actually mean, could you?
I’m a card-carrying atheist, I think a woman’s right to choose is very important, I think that “well regulated militia” means that guns should be carefully licensed and not just randomly given to any moron with a pulse, and I couldn’t care less if you decided to dress up in the “wrong” clothes or decided you’d rather live your life without feeling tied to whatever plumbing you were born with.
And dammit, if that all makes me “woke”, then I think anybody who uses that word as a pejorative is a f*cking disgrace to the human race. So please just unfollow me right now.
Fun fact: it is literally, objectively impossible to legally watch Ultra HD Blu-Rays on a desktop computer, because Cyberlink PowerDVD is the only legal way to watch Blu-Rays of any sort on PC at all and it dropped support for UHD BRs.
Once again, DRM exclusively and disproportionately affects legal users without being a blip in the way of pirates (MakeMKV works just fine)
Mastodon isn't perfect.
But the fact a social network exists that is completely free to use
has no venture capital investors
has no shareholders to answer to
has no growth targets
with a web interface with zero tracking cookies
and mobile apps with zero trackers at all
with ten thousand server administrators who donate their time for user safety
is - in my opinion - mindbogglingly cool, given the state of the world we live in. Not everything has to be shit. People make things better.
A few facts and thoughts about #BlueSky being decentralized or not:
#ATProto (the protocol behind bluesky) is decentralized and open-source, but is controlled by a for-profit (albeit fiscally a public benefit) organization, "Bluesky Social PBC".
"Bluesky" refers to a sum of ATProto concepts, notably the AppView (bsky.app), the main Personal Data Servers (PDS, bsky.social), and the Relays (or firehose, bsky.network). There are others, but they're the 3 important ones.
Anyone can run their own AppView, PDS or Relay AND consume the content from/get their content consumed by the Bluesky infrastructure. HOWEVER, not everything is trivial or cheap to run.
3.1 A PDS, which contains your data (account details but also posts, likes, follows, etc), is trivial and cheap to self-host. Cheaper than hosting a mastodon instance, even, because it does way less stuff and receives way less requests. See https://github.com/bluesky-social/pds
3.1 An AppView (the presentation layer, where users interact with ATProto content) can be created by anyone, but the bsky.app backend is NOT open-source, so there are not a ton of options right now.
3.2 Running a relay is trivial but expensive to self-host. This is because its purpose is to act as an aggregator for all the PDS so that AppViews can consume the data in a way that scales better. The Bluesky relay implementation (bigsky) is open-source: https://github.com/bluesky-social/indigo/blob/main/cmd/bigsky/README.md
About 2.5 months ago, 4.5TB of storage was needed and an OVH server costing 150$/month worked to host a full-atmosphere relay (more on that later).
To make a comparison with #ActivityPub (the protocol behind #mastodon ), the AppView and PDS is the same thing in ActivityPub, and the concept of relay doesn't exist. There are advantages and drawbacks to both architectures, I might do a future post highlighting those.
With those definitions out of the way, some observations:
5.1 A lot of users self-host their PDS, but the vast majority of users chose the simpler option.
5.2 There are some alternative AppViews built on ATProto, but the vast majority of users visit bsky.app.
5.3 There are very little non-bluesky self-hosting of relays, mostly because of their prohibitive cost. Running the bigsky relay is expensive partly because of design decisions for ATProto and partly because it takes ALL content from ALL accounts for ALL the network on the atmosphere (in this case atmosphere == fediverse but for ATProto). This is like if your Mastodon instance queried ALL servers for ALL accounts querying ALL posts. In the future, there might exist relays that don't scrape ALL data but only a subset of it, which would bring down costs, but it's not yet the case.
6.1 In theory, yes, everything that bluesky does on ATProto can be.
6.2 In practice, however, the most decentralized part of Bluesky is the PDS, where the user data is stored, and even that is not that decentralized.
6.3 Will it stay this way? I'm hopeful it won't, but I don't know. ATProto is fairly new compared to ActivityPub, and the ecosystem around it was mostly built by the BlueSky company, but I expect this to change in the future. However, the cost of entry for things built on ATProto will always be more than the cost of entry for things built on ActivityPub.
6.4 Things built on ActivityPub will always be more decentralized than things built on ATProto, because of design decisions from both of these protocols.
🦨As promised, we've added a toggle that allows you to remove any lesbian content from the game, to keep all the anti-woke anti-DEI people happy. Here's a demonstration of it in action
Suddenly, out of nowhere, a declassified World War II-era CIA guide to sabotaging fascism in the workplace has become one of the most popular free ebooks on the internet:
https://www.404media.co/declassified-cia-guide-to-sabotaging-fascism-is-suddenly-viral/