Skip to main content



Meta AI soll ab Mitte Dezember Chats auswerten


Ab dem 16.12. fängt der Konzern an, die #Meta AI mithören zu lassen, um auf Basis der Daten Werbung, Feeds und Reels gezielter auszuliefern.

Ab dem 07. Oktober bekommen die ersten Nutzer von #Facebook, #Instagram und #WhatsApp in ihrer App eine Mitteilung über die neue Nutzung der #MetaAI angezeigt. Die neue Funktion soll Mitte Dezember diesen Jahres zunächst im Ausland aktiviert werden. Die Länder innerhalb der #EU kommen erst später dazu. Grund dafür ist der strengere #Datenschutz innerhalb der Europäischen Union. Bisher ist nicht bekannt, ab wann die #Kommunikation mit dem #KI-Bot auch in Deutschland konsequent ausgewertet werden soll.

tarnkappe.info/artikel/kuenstl…



Exhibit N in why I will never ever go on a cruise. (Lots of other reasons too, including TOO MANY PEOPLE and the gross environmental footprint, but being trapped on a boat with noro is nightmare fodder).
RE: bsky.app/profile/did:plc:f5j66…


Oil and Gas Trade Group Blasts Reform’s Anti-Renewables Agenda

desmog.com/2025/09/30/oil-and-…



Earlier today I got an email from that wonderful delivery company Evri, saying they would be delivering a parcel between 8 and 9pm tonight. Now the parcel isn't due until next week, so that was a surprise, especially considering we have a weather warning.
Now its a minute past 9pm, so I can be outraged that Evri have not shown up? I mean, its not as it 97mph gusts have happened near here and trees are probably down in a lot of places. Piss poor service, 0 out of 5 stars.

( I am not mad in the least, its bloody awful weather and I would rather the driver was safe at home - it would be nice if they would update the tracking though)




I don't say I have ZFS issues at work, just that I would be very happy if @mwl reachs 30k
io.mwl.io/@mwl/115310417937554…


Four days left on the "Networking for System Administrators" #kickstarter! Back this campaign, get at LEAST three #sysadmin books.

Actually reading it will help you achieve peace with your network team.

mwl.io/ks


reshared this



Alright as soon as I get Situated on this train I'm gonna start asking a whole buncha questions about CSRF
in reply to mcc

OK so

I got a web app

I want the endpoints at /actions , and only those endpoints, to reject/not-receive requests that are not same-origin. Other endpoints (regular html pages; oauth callback) SHOULD be possible to link/redirect to.

I'm reading: developer.mozilla.org/en-US/do…

The 2 ways I can imagine doing this are:
- Check for Origin: header and reject request if wrong (will privacy plugins sometimes suppress this?)
- Send `Access-Control-Allow-Origin: https://me`, also use Post to force preflight

in reply to mcc

Can I rely on the first one. Do I need to do both. How important is the second if I do the first
in reply to mcc

not sure about privacy protections, but at the very least browsers aren't going to let anybody forge Origin:.

I'd definitely do both, as belt & suspenders against potential XSS/CSRF vulnerabilities in other parts of your site.

in reply to mcc

cors header is the usual option, but of course non-browsers aren't likely to respect it. The origin checking is a bit more robust against non-browsers - unlikely to cause issues for browsers, I've never countered issues with it. Of course non browser's can still fake their origin header.
in reply to Robin Neal

@SudoCat as long as browsers are universal about it. i'm only concerned about malicious redirects on real browsers because only the real browsers will have good cookies.
in reply to mcc

Personally, I would have anything that qualifies as an "action" to not be a GET request to begin with but I'm not sure that solves your problem.

(But CORS/CSRF is super complicated and personally i would never want to handle it manually)

in reply to mcc

I don't think that POST guarantees preflight by itself; you have to use a non-safelisted header or something? god the specs on this are obnoxious. But if you have a custom X- header that you check for, that should force the browser to always do it. (Alternately, you can just do regular CSRF prevention.)
in reply to Glyph

@glyph If you can do a cross-site POST request with a <form> that you programmatically .submit(), then you can do the same request with XHR without a preflight. The annoying spec rules basically try to formalize that idea.
in reply to mcc

the pattern I've seen to protect against CSRF is some extra token that needs to be present in order to accept the request. cheatsheetseries.owasp.org/che… explains it (and also has some other options).


Literary Fiction Novels That Blend Beauty and Emotion

Literary Fiction Novels That Blend Beauty and Emotion Perfectly balancing gorgeous writing with emotional resonance, these books remind us why literary fiction is so powerful. These upcoming literary fiction books are already generating buzz among critics and readers. Water Memory (The…
newinbooks.com/literary-fictio…

#BookstoReadifYouLike #eBook #LiteraryFiction



When you are a swift developer, every day your server is celebrating Christmas!
mastodon.social/@swiftlang/115…


Swift isn't just for client apps: when @elytra moved from Node to Swift for their server code, they benefited from better performance and a unified codebase. More here: elytra.app/blog/2025/10/01/swi…


À l'issue d'une série de mesures exhaustive, je suis en mesure de l'affirmer : il existe exactement deux longueurs de jarretière optique, la trop courte et la trop longue.


Landwirte bleiben auf Kosten sitzen: Bundesregierung streicht Förderung, die bis 2030 vorgesehen war apollo-news.net/landwirte-blei… In der Landwirtschaft rumort es gewaltig. Einen „Schlag ins Gesicht der landwirtschaftlichen Betriebe“ nennt es die Arbeitsgemeinschaft Bäuerliche Landwirtschaft, der ...
The post Landwirte bleiben auf Kosten sitzen: Bundesregierung streicht Förderung, die bis 2030


Boobs, Lewd

Sensitive content

in reply to Emily Tempest

re: Boobs, Lewd

Sensitive content



Where's the best place to get 2-5 genuine HD63C09EP 40 pin DIP 3Mhz versions ? I've looked at eBay but they are all in China and I really want genuine chips not rebadged 2Mhz versions or worse totally fake.

#RetroComputing

in reply to Justine Smithies

My go-to here in Canada is Digikey, but when I search HD63C09EP on your side of the pond it really is slim choice. There's donberg.co.uk/descript/h/hd_63… with which I personally have no experience - at least it has a physical address to scowl towards if they are trouble to deal with.


Hegseth announces U.S. blew up 4th boat near Venezuela
https://www.pbs.org/newshour/world/hegseth-announces-u-s-blew-up-4th-boat-near-venezuela?utm_source=flipboard&utm_medium=activitypub

Posted into Headlines @headlines-PBSNewsHour




Labour’s policies risk creating a society where everyone must prove who they are simply to go about their daily lives.

Is this really the future we want?

🔎 edinburghnews.scotsman.com/top…



Lift The Ban

realmedia.press/lift-the-ban/