Rokosun reshared this.

“The researchers suspect that Glassworm—the name they assigned to the attack group—is using LLMs to generate these convincingly legitimate-appearing packages. “At the scale we’re now seeing, manual crafting of 151+ bespoke code changes across different codebases simply isn’t feasible,” they explained. Fellow security firm Koi, which has also been tracking the same group, said it, too, suspects the group is using AI.”

reshared this

in reply to Aral Balkan

What I don’t get is how this snippet passed code review regardless.

I mean, it’s clearly dodgy and the last line basically meaningless without the code being evaluated.

The real story here isn’t the invisible Unicode characters, it’s the lack of proper code review on code submissions.

This entry was edited (Sunday, March 15, 2026, 11:22 AM)
in reply to Aral Balkan

I agree, I had the same thought, first of all an eval function is super suspicious; "eval is evil", on the other hand what the earth is the const s doing there. And in the name of love what is the reviewer thinking about when someone does a PR with this kind of "functionality". I will check but I think that a simple SAST is going to complain about this PR.
On a second thought maybe the snippet provided by the security researchers is just a non realistic example to illustrate the concept.
Rokosun reshared this.

I set up a liberapay account. If you appreciate my work on #SailfishOS ports for @volla or @pine64 devices, or like my applications then feel free to use it. :) liberapay.com/adampigg

reshared this

Rokosun reshared this.

theguardian.com/global-develop…

*Two women arrested in Uganda for allegedly kissing in public could face life sentence.* That is one item in a long catalog of unjustified cruel bigotry that is fueled by various religions.

reshared this

Rokosun reshared this.

We have to increase a bit the fundraiser due to some "sales taxes"... gofundme.com/f/yearly-fundrais…

Apparently we had to pay that too...

Thank you so much everyone! We are 83% there!

#fediverse #fedi #donation #volunteer #tromsite #trom

reshared this

Rokosun reshared this.

Reminder: The romancelandia.club mastodon instance will only exist for ONE MORE MONTH.

If you haven't moved to another instance by that time, all of your follows and followers will be lost.

reshared this

in reply to romancelandia admin

If anyone needs help moving their account, there's a step-by-step non-technical guide at fedi.tips/transferring-your-ma…

Also feel free to ask if you need help with any specific part of moving your account.

If you need help finding a reliable server to move to, have a look at fedi.garden

Rokosun reshared this.

We are half way through with our fundraiser for our backups gofundme.com/f/yearly-fundrais… !

Many many thanks people! Almost there!

#campaign #foss #fedi #fediverse #opensource #trom #tromsite

reshared this

Rokosun reshared this.

The wait is (almost) over! Ghost in the Machine is coming to audiences on March 27th! Screenings and rentals are available via Kinema, and the film will stream free on PBS and YouTube this fall. Details at: notaidoc.com
This entry was edited (Saturday, March 14, 2026, 2:23 PM)
Rokosun reshared this.

Yearly Fundraiser for our Backups - gofund.me/d96c58985

Hello friends,

We need to pay for our backups every year. We backup with borgbase.com all of our websites. Two servers, a total of around 3TB of data.

We backup:

- tromsite.com
- videoneat.com
- tromjaro.com
- trade-free.org
- directory.trade-free.org
- trom.tf - all of our services: Friendica, Peertube, Nextcloud, etc.

See all of our projects here tromsite.com/

Many thanks!


#campaign #foss #fediverse #fedi #tromsite

Rokosun reshared this.

Every developer or dev team can relate -

#dev #development #Tech #techdev

This entry was edited (Monday, January 5, 2026, 6:25 PM)
Rokosun reshared this.

This week in #FDroid (TWIF) is live after 2 weeks:

* everyone has a voice to #keepandroidopen install F-Droid everywhere, make it unavoidable
* Basic 2.0-alpha4 animates things
* #NewPipe reminds you of September
* more downloads stats
* more #FLOSS devs using #AI
+ 38 new apps
& 347 updates
- three archived
~ one downgraded

Elephants in rooms, f-droid.org/2026/03/13/twif.ht…

reshared this

Rokosun reshared this.

Have you been browsing with Chrome lately? Holy shit! It’s like driving an ambulance through the brightest city in the world after eating hallucinogenic mushrooms.

Does Google really think it can convince its users that it removed uBlock for their own good? As far as I’m concerned, Evil Corp can go eat its own shit.

#privacy

reshared this

Rokosun reshared this.

Two weeks in, our Open Letter to Google to Keep Android Open has gotten over 50 signatures from 20 countries. Our latest endorsement: Forbrukerrådet, the creators of the viral hit video: "A Day in the Life of an Ensh*ttificator". youtu.be/T4Upf_B9RLQ?si=FlZ4Cs… keepandroidopen.org/open-lette…

reshared this

Rokosun reshared this.

"We see a future where intelligence is a utility, like electricity or water, and people buy it from us on a meter..." -- Sam Altman

x.com/TheChiefNerd/status/2032…

There you go, there it is. Yup.

in reply to Christine Lemmer-Webber

i&i say: metaphysical- historical- & materially speaking, Altman just pronounced his own death sentence & OpenAI's & the whole TESCREAL TechBroism's death sentence.
they & this must die, the sooner the better, & will eventually.

this is the clearest Writing On The Wall one can get at this stage.

#AI #AIism #TESCREAL #TechBroism #DeathSentence
#WritingOnTheWall
(i&i humbly speak so as a poet & a conscious being)

e.g. Karp's last one is a mere confirmation:
pouet.chapril.org/@DeliaChrist…

Rokosun reshared this.

Thank you @fastmail for supporting Keep Android Open at keepandroidopen.org/open-lette… @keepandroidopen #KeepAndroidOpen

reshared this

Rokosun reshared this.

📱 We're happy to announce that the #PeerTube app is now available on #AltStore PAL!

AltStore is an alternative store for #iOS and we've collaborated with them to make our app available on it.

It's great to see alternative stores existing on platforms such as iOS!

🌐 altstore.io/

Rokosun reshared this.

Whenever you hear "ban for kids" on the internet, read in reality "ID collection by a sketchy third-party company that will definitely use it or leak it or both for every adult."

Because that's what this truly means.
Also, it doesn't even help the kids.

#AgeVerification #Privacy #MassSurveillance #Authoritarianism