asklemmy

This magazine is from a federated server and may be incomplete. Browse more on the original instance.

SpaceNoodle, in Short(er) people of Lemmy--what are some lifehacks you figured out that've helped you out?

For a 2m giant, this is a fascinating glimpse into y’all’s little world.

We both share the pain or poorly hung mirrors.

Crackhappy,
@Crackhappy@lemmy.world avatar

Agreed. And urinals where the top is lower than the hanging song.

FarceMultiplier,
@FarceMultiplier@lemmy.ca avatar

The urinals at my work are terrible, even though I’m 5’10". One is so low that it’s like pissing in a bucket. The other is so high it’s like pissing straight ahead.

SpaceNoodle,

I never heard that euphemism before.

gravitas_deficiency,

“s” and “d” are right next to each other on the keyboard

qevlarr, (edited ) in What companies have made your blacklist?
@qevlarr@lemmy.world avatar

Blizzard

Back when they implemented Real ID and forced people to provide real namr and identification for playing the games they paid for, these motherfuckers locked me out of my account for account sharing because someone logged in from another country. That was me, logging in for my lunch break at work, about 1 hour away from home. They demanded I not only gave them my real name, but even send a copy of my passport to them by email. Obviously I refused. I had the original box and the game code, but they didn’t care. There were no other fraud indicators. Just me logging in from work and using a pseudonym. I never got any of my games back. Fuck them

quams69, (edited ) in Be honest: if you had the power to stop time, your morals would go out the window.

If I had the power to stop time I’d stop it, travel all around the world putting live grenades in the pockets of every type of evil greedy cunt I could find, then start it again and wait for the fireworks to ensue. Every time someone starts making psychopath money again? Suddenly a grenade appears in their pocket. Funding wars, poison and incarceration? Every person with a finger in haliburton or monsanto, turned into red mist at a board meeting. Shareholders, exploding in hot tubs, saudi princes splattered in their shitty lambos. Every jordan belfort wannabe fuckstick exquisitely morphed into charcuterie.

Grenade morality.

hswolf,
@hswolf@lemmy.world avatar

that would be extremely time consuming, imagine traveling around the world with every major transport frozen

and imagine the time It would take to actually find everyone who needs a pocket granade

A_Random_Idiot,

I think one of the necessary secondary support powers would be for time to flow normally for anything you touch.

Otherwise air would be frozen and you’d suffocate.

the_stat_man,

Also if air were frozen, it wouldn’t flow to move out of your way so you’d be locked in place.

pomodoro_longbreak,
@pomodoro_longbreak@sh.itjust.works avatar

I feel like after a while, and maybe with a few notes left behind, it would begin to have a chilling effect.

Tangent5280,

Would it really be time consuming? Depends on the ruleset of thw world I suppose. Do you age in this time frozen state?

PsychedSy,

I think you’d have to.

Tangent5280,

I think it can’t work without the “things Im touching are exempt” rule.

Cosmicomical,

If you can breathe and are not locked into your own clothes, you can surely use motor vehicles as well

Rooskie91,

How can you consume time if it is stopped?

PsychedSy,

Time is change. If you’re not aging then you’re not moving. Imagine destroying the universe by just stopping it.

bingbong,

Grenade morality.

Big grenade diplomacy

whats_all_this_then,

I’d vote for ya

archonet,

you paint a vivid mental image

I like that

Smoogs, (edited )

You’d need both the ability to stop time, create a time pocket for yourself and the ability to fly on your own

balderdash9,

The “Death Note” style of super powers lol

KISSmyOS, in Which things have you avoided or embraced on the name alone?

I actively avoid Fedora Linux.
I feel like that’s the worst name of any brand ever.

impiri,

tips distro m’linux

0000000nowhere,

m’Distro

soysauce,

Ah, another Hannah Montana Linux user, I presume.

Feathercrown, (edited )

Are you scared of technology?

Yes --> Abacus

No --> Hannah Montana Linux

indepndnt,

Same, I just can’t get over that name. I’m not sure if that’s because of or in spite of the fact that I had a fedora phase when I was younger…

m4xie,

It was originally developed in 2003, just as the hat started to come back. The neck beard meme seems to have come about later in the 2000’s (knowyourmeme.com/memes/fedora-shaming).

bjoern_tantau, in Dear Lemmings, what is your personal approach to human diet?
@bjoern_tantau@swg-empire.de avatar

My approach to human diet is to only eat organic free range humans. They might be more expensive to aquire but I’ve never tasted any better.

JoMiran,
@JoMiran@lemmy.ml avatar

What?!? Where can you still source organic and free-range?

intensely_human,

Unfortunately these days only in Bhutan

RGB3x3,

I hear the New Zealanders have a sweet and salty taste to them on account of their grass-fed diet. But I’ve never been able to afford the Kiwi-grown.

ptz, in why do & ampersands never display properly in titles?
@ptz@dubvee.org avatar

The API sanitizes them, so they’re stored encoded (&) in the database.

Some frontends correct for this when posts are rendered, some don’t. Voyager and Tesseract, at least, seem to correct them. Not sure about others.

lettruthout,

Does not work on MacOS Firefox.

Cosmicomical,

That's the problem, then. You shouldn't store entities in the db, the table is likely already utf8, which supports all characters

Max_P,
@Max_P@lemmy.max-p.me avatar

I think 0.19 is reverting that behaviour, because it was indeed a certified bad idea.

I think the idea was to attempt to bulletproof potentially crappy clients especially after the XSS incident, but the problem is it’s simply not even always rendered in a web context which makes the processing kind of a pain.

Wouldn’t surprise me if it becomes double and triple encoded too at times because of the federation. Do you encode again or trust that the remote sent you urlencoded data already?

Best format is the original format and transform as late as possible, ideally in clients where there’s awareness of what characters are special. It is in web, not so much in an Android or terminal app.

I don’t think the Lemmy devs are particularly experienced web developers in general. There’s been a fair amount of dubious API design decisions like passing auth as a GET parameter… Thankfully they also fixed that one in 0.19.

Cosmicomical,

Sorry for the late reply, it's been a week... but yeah passing creds in the Get is very bad for multiple reasons. For instance if you pass the creds on a page that contains ads or trackers, they are probably going to store the url AND your credentials and propagate them to a million systems of third parties. That's. Not. Good.

Alexstarfire,

What exactly makes storing it encoded a bad idea? A waste of space perhaps.

Max_P,
@Max_P@lemmy.max-p.me avatar

Because then you need to take care everywhere to decode it as needed and also make sure you never double-encode it.

For example, do other servers receive it pre-encoded? What if the remote instance doesn’t do that, how do you ensure what other instances send you is already encoded correctly? Do you just encode whatever you receive, at risk of double encoding it? And generally, what about use cases where you don’t need it, like mobile apps?

Data should be transformed where it needs it, otherwise you always add risks of messing it up, which is exactly what we’re seeing. That encoding is reversible, but then it’s hard to know how many times it may have been encoded. For example, if I type & which is already an entity, do you detect that and decode it even though I never intended to because I’m posting an HTML snippet?

Right now it’s so broken that if you edit a post, you get an editor… with escaped HTML entities. What happens if you save your post after that? It’s double encoded! Now everyone and every app has to make sure to decode HTML entities and it leads to more bugs.

There is exactly one place where it needs to encode, and that’s in web clients, more precisely, when it’s being displayed as HTML. That’s where it should be encoded. Mobile apps don’t care they don’t even render HTML to begin with. Bots and most things using the API don’t care. They shouldn’t have to care because it may be rendered as HTML somewhere. It just creates more bugs and more work for pretty much everyone involved. It sucks.

Now we have an even worse problem is that we don’t know what post is encoded which way, so once 0.19 rolls out and there’s version mismatches it’s going to be a shitshow and may very well lead to another XSS incident.

Alexstarfire,

That’s a problem of not conforming to any standard. Not with it being a bad idea in general, like say storing passwords in plaintext is.

Max_P,
@Max_P@lemmy.max-p.me avatar

It still leads to unsolvable problems like, what is expected when two instances federate content with eachother? What if you use a web app to use a third party instance and it spits out unsanitized data?

If you assume it’s part of the API contract, then an evil instance can send you unescaped content and you got an exploit. If you escape it you’ll double escape it from well behaved instances. This applies to apps too: now if Voyager for example starts expecting pre-sanitized data from the API, and it makes an API call to an evil instance that doesn’t? Bam, you’ve got yourself potential XSS. There’s nothing they can do to prevent it. Either it’s inherently unsafe, or safe but will double-escape.

You end up making more vulnerabilities through edge cases than you solve by doing that. Now all an attacker needs to do is find a way to trick you into thinking they have sanitized data when it’s not.

The only safe transport for user data is raw. You can never assume any user/remote input is pre-sanitized. Apps, even web ones, shouldn’t assume the data is sanitized, they should sanitize it themselves because only then you can guarantee that it will come out correctly, and safely.

This would only work if you own both the server and the UI that serves it. It immediately falls apart when you don’t control the entire pipeline from submission to display, and on the fediverse with third party clients and apps and instances, you inherently can’t trust anything.

Cosmicomical,

Sorry for the late reply, but the point is that there is no trivial way to detect whether and how many times something has been encoded. You may end up with multiple levels of encoding in multiple systems and everything becomes untractable. Morever, as i said this doesn't have to be a problem, as you can just decode everything as much as you can BEFORE you put it in the db, as the db can handle all of that by itself. Just let it do its job. Paradoxically, if you use only channels that support utf8 and don't apply any transformation, your data is already perfect as it is. Then it is the job of the client to do what it needs to be able to render properly, but for instance a non-html client shouldn't need to use html libraries to be able to strip html stuff from the text before it can be displayed.

hamid,

You don’t have to wonder about what the Lemmy devs do and don’t know. They aren’t cloistered or unreachable, you can just join matrix room and talk to them nearly at any time.

The main thing halting progress on the code is time and money. The devs are under strain from the amount of fixes and issues from the sudden burst in lemmy users so they are in an operational mode that isn’t ideal. For my part I’m one of the monthly contributors to the project; Lemmy is community developed software, not corporate.

Cosmicomical,

To be honest it's already incredible that the platform works at all and has all these features. Great job, really! I'm not being sarcastic, it needs improvement but it's a great achievement.

bernieecclestoned,

Thanks

Cocodapuf,

Works fine in connect

sanguinepar,
@sanguinepar@lemmy.world avatar

Working fine on Sync.

pewgar_seemsimandroid,

imma quicky test on thunder

edit: displays &

Illecors, in Tech workers - what did your IT Security team do that made your life hell and had no practical benefit?

Hasn’t made life hell, but the general dumb following of compliance has left me baffled:

  • users must not be able to have a crontab. Crontab for users disabled.
  • compliance says nothing about systemd timers, so these work just fine 🤦

I’ve raised it with security and they just shrugged it off. Wankers.

mesamunefire,

Thats really funny. Made my day thanks.

Are they super old school and not know about systemd? Or are they doing something out of compliance that they may hate too? I have so many questions.

Illecors,

I actually think they’re new school enough where Linux to them means a lot less than it does to us. And so they don’t feel at home on a Linux machine and, unfortunately, don’t care to learn.

I could totally be wrong, though. Maybe I’m the moron.

mesamunefire,

I dont think your the moron. Thats super strange. I can only think it might be some sort of standard that they had to comply with…or whatever.

PP_BOY_, in What are some problems that countries outside the U.S. are dealing with?
@PP_BOY_@lemmy.world avatar

The US, for one

krondo,

Came here to post this :)

stmcld,

Lol same, but i see a few people beat us to it.

leraje, in If Trump wins the election
@leraje@lemmy.blahaj.zone avatar

It’s an isolationist policy. The US military doesn’t have military bases/presences across Europe (and elsewhere) out of the goodness of its heart or to protect Europe. They also do it because their military realises that its much, much better to have bases somewhere where they can strike an international enemy quickly from. It’s a militarily mutually beneficial arrangement.

So, the US would lose that early strike capability. They’d also lose all the intelligence benefits having people on the ground brings with it. Also, should it happen and Europe was successfully invaded, US businesses would either temporarily or permanently lose access to one of their biggest trade export blocs and a large amount of access to imports too.

NeoNachtwaechter,

It’s an isolationist policy.

That is a trend that is happening anyway, and it has started even years before trumpeltier’s election (he has pushed it much further, though).

odium, in What can the US do to help Mexico finally stop the cartels?
HurlingDurling,
@HurlingDurling@lemmy.world avatar

Honestly, we shouldn’t consume drugs at all, but to each their one I always say.

However, I completely agree that the ATF should change their policy and prohibit ALL gun sales without a US identification and simple background check at least.

tatterdemalion, (edited ) in What's some amazing technology they have in Japan that's very normal to them but would blow our minds here in the US and western world?
@tatterdemalion@programming.dev avatar

Automated underground bike storage

www.youtube.com/watch?v=pcZSU40RBrg

derpgon,

We got a few of bike towers on the ground in Czechia. Very neat.

billwashere,

Why does this remind me of Death Stranding?

Bluebanrigh,

It’d be cool if they had those here but I swear we have enough idiots that would try to get in for shits and giggles and maim themselves

SkaveRat,

Make it self cleaning. Problem will solve itself after a while

qyron,

You could put giant billboards warning for the risk and it would still become a recurring event. Even if it said “warning: this is capable of grinding a human being to pulp”.

Bluebanrigh,

Meanwhile, I can’t retrieve my bike because someone’s mangled arm is jamming the main lift.

darkmatterstyx,

New viral challenge…

qyron,

Now you got me seriously depressed.

Malfeasant,

“Not only will this kill you, but it will hurt like hell the whole time you’re dieing”

qyron,

Where is that sentence from?

Why can’t we have basic, objective, uncomplicated worded warnings like that? Maybe the stupid ratio would drop.

Malfeasant,

I’ve heard of it posted on high voltage electrical panels, but never seen it myself (I’m not an electrician). I don’t know if I got the wording exactly right, but it sounds good.

AscendantSquid,

I’d imagine it’s got weight and pressure sensors, so I don’t think a person would get very far. I can definitely see the mechanism getting jammed by garbage or some shit, especially if someone’s trying to jam it.

Bluebanrigh,

Maybe, hopefully? I’d imagine whatever idiotproofing they do won’t be sufficient for the wild.

Potatos_are_not_friends,

We can’t have a lot of things because that 1% is fucking morons.

Everything from clean public bathrooms to high end vending machines.

Azal,

US here… it has less to do with the 1% being fucking morons and more to do with the only infrastructure we actually pay any attention to is cars. Sure we’re having a bit of a bicycle revolution but at least in my area the bikes aren’t being used for transport but for fun, but then that’s with a metro that’s sprawling with a city that’s only 100 sq miles smaller than NYC, with 8,000,000 less people in it. Add that the auto companies were allowed to buy out things like the streetcar that was local and able to tear up the tracks to get rid of competition, it really isn’t a shocker.

But we’re now stuck in a cyclical spiral, of no investment for things like this are happening because it’s not seen as profitable enough. Which means a constant problem of using something like a bike for commuting is “But then I have nowhere I can put my bike where it won’t get fucked with.” so people don’t commute with it, which leads to no investment to the infrastructure.

Dunno how to fix it. It just sucks.

sfgifz,

Don’t forget privacy in toilet stalls - I’ve seen the huge gaps in doors in the US.

intensely_human,

That’s the premise behind /r/ArchitectureForAdults: architecture that’s dangerous for morons, but safe for everyone else

JadenSmith, in Can't we just start calling it "Formerly Twitter" instead?

I still call it Twitter.

Thorny_Insight,

And Meta will always be Facebook

Chakravanti, (edited )

I always call it FaceBook Inc. It’s absurd that that shit has always gone right past everyones observation. Prolly still clicking because upon seeing it you’re ass will do the denial your damn self instead of reading it upside down: zero responsibility for maintenance of spying products handle when a corporation is doing the gig and not the gorramn government.

derpgon,

But Facebook hasn’t renamed. It’s still Facebook, but under company called Meta.

Chakravanti, (edited )

Call it whatever you like under whatever, IDC. It’s the FBI.

General_Shenanigans,

I never liked Twitter that much to begin with, but it’s definitely not the same thing as it used to be. I’m fine with calling it X instead of Twitter because of that. X is a stupid name for a stupid social media platform. It’s fitting. It’s definitely not Twitter anymore, which ever way you want to look at it.

gregorum, in What's your favorite piece of bullshit advice?

“Walk it off”

— coach

No, my torn ligaments need to rest and heal, asshole, not to endure further trauma. Get me some ice!

son_named_bort,

Take a salt tablet.

cheese_greater,

Puttin’ it on ice, bitches

flicker, in How do I get my sense of taste back after covid?

The following comment is NSFW and n=1 and also I wouldn’t post it if I wasn’t anonymous so here goes. Don’t keep reading if you’re easily grossed out. Content warning; urine.

Knowing that I had lost my sense of taste from covid, I reviewed the things I could do that not having a sense of taste might benefit from, and I asked my boyfriend (who I’m aware has a mild watersports fetish) if he’d like to take advantage of my lack of sense of taste…

And he did.

And later that night, shortly after our experiment, my sense of taste came back! I don’t know if it’s a revolutionary treatment for Covid, but if you’re desperate…

flicker, (edited )

Oh eff me, the first comment after moving from kbin is about getting pee in my mouth.

Deceptichum,
@Deceptichum@kbin.social avatar

You only changed your seat, you’re still on the same bus.

toiletobserver,

We need a larger sample size to be statistically significant. Please report back after 29 more attempts.

flicker, (edited )

I don’t want to get covid 29 more times so I need some people to volunteer as tribute.

Know anybody who can help, ToiletObserver?

Buffalox,

I don’t think it can work that fast, but there is connection between zink and sense of taste, and sperm has high level of zink.

Traegert,

She was not referring to sperm my dude.

flicker,

Indeed I was not.

Critical_Insight, in What's a useful mental model you've put into practice

I’ll let you, OP borrow my brain anyday if you’d like to experience what it’s like to live always expecting things to go wrong.

highenergyphysics,

TIL neurotypicals literally just go about their day and work life just assuming everything will go right

afraid_of_zombies,

That is not what I have observed. I do kinda wonder sometimes however

Me: right so we said we would be there by 630. If we leave within the next five minutes we should be there at 6:25

Wife: it’s fine

Me: just you know we could leave now and no one has to have any anxiety about being late.

Wife: they aren’t going to care

Me: true they won’t really care that much but we did say 6:30. Wouldn’t it be nice to not be worried? Like what if we make a wrong turn and have to double back? We would still be on time if we left now.

rikudou,
@rikudou@lemmings.world avatar

Yeah, it’s so alien to me. I’m envious, though, must feel nice.

EdanGrey,

We really don’t

eatthecake,

TIL neurodivergents think neurotypicals are neuroperfect. You’re an idiot.

cheese_greater, (edited )

I’m nothing if not non-neurotypical neurodivergent haha.

dingus,

Right??? Like wtf I thought everyone just thought about how everything could go wrong all the time. You mean people do things and expect to succeed instead of expect to fail??? This is legitimately wild to me.

KpntAutismus, (edited )

i don’t expect things anymore, it goes how it goes. if it doesn’t go how it’s supposed to go, i’ll see if i can fix it.

Critical_Insight,

I wish I could do that. Currently I’m trying to start a bussines, but my mind just keeps coming up with the most unlikely terrible scenarios that might happen and convincing me to never try anything new so that I can’t fuck it up.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • asklemmy@lemmy.world
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 10489856 bytes) in /var/www/kbin/kbin/vendor/symfony/http-kernel/Profiler/FileProfilerStorage.php on line 171

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 2097152 bytes) in /var/www/kbin/kbin/vendor/symfony/error-handler/Resources/views/logs.html.php on line 28