Sekitar 20 hasil (2.47 detik)
Komunitas pawb.social

Is anyone using Debian Sid for gaming?

I’ll do you one better: I’m using Debian Stable for gaming and there’s nothing bad to report. Based on my experience I’d recommend that you use Stable first, unless you feel you really need Sid. I previously ran Arch Linux, but after switching to Stable and manually sourcing a few critical cutting-edge applications through e.g. Flatpak, it feels the exact same. I don’t feel like running the entire system as bleeding edge is a good idea when you can just run a couple dozen things as cutting-edge instead. If you plan on using Sid instead of Stable, most of the following will not apply: Lutris has its own Deb repo if you need the latest updates, or it’s available as a Flatpak. If you use Flatpak Lutris and want to use MangoHud, you’ll need to install the Flatpak version with flatpak install flathub org.freedesktop.Platform.VulkanLayer.MangoHud (I don’t think it shows up in the normal store) The one gotcha I’ve found regarding Debian Stable and gaming is that Mesa will fall out of date as the release cycle goes on and probably won’t be backported. The solution is that running games via Flatpak (Lutris, Steam, etc.) uses Flatpak’s Mesa instead, which is cutting-edge. You can also try to compile a local Mesa version with this script, and you can manually trigger games to use this version instead of the system version. It does work, but it’s more complicated and a little bit more messy. I use the Xanmod “Main” kernel for a more recent kernel that isn’t too bleeding-edge - it stays on the previous Linux kernel version until a few point releases have come out. CoreCtrl is available as a bookworm-backport. I manually backported it myself but it looks like it’s official now. I’m running Wayland and KDE, with no issues to report (even with gaming) I’ve manually compiled Libstrangle for FPS limiting, but I’ve found that I can use MangoHud to transparently limit FPS as well, by using the following environment variable: MANGOHUD_CONFIG=fps_limit=YOURFPSHERE,fps=0,frame_timing=0,cpu_stats=0,gpu_stats=0,background_alpha=0. When I want MangoHud to act as normal, I switch it to MANGOHUD_CONFIG=readcfg which uses my normal config instead. Notably, Libstrangle cannot be used with Flatpak Lutris, so FPS limiting will need to be done with MangoHud if you want to limit Linux games. DXVK games can be limited with DXVK_FRAME_RATE as well, if that’s all you need. I make heavy use of Flatpaks for any user applications that I need to keep more modern If it’s not available as a Flatpak, I tend to use Homebrew to keep any other critical applications up-to-date (usually some CLI tools) I use cargo through rustup to keep some rust programs updated I use deb-get with a couple programs that aren’t on any real repos in order to get updates I’ve compiled a couple backports by following this guide in a stock Debian Stable VM, then copying the .deb files back out to my main system. So far this has been super easy, but I don’t want to do this unless I have to. If a program needs to be manually compiled, I try to install it using checkinstall. checkinstall basically fake-runs an installation and notes where everything goes, then stuffs it all into a .deb for you for a proper installation that can be uninstalled later. It’s a little buggy and doesn’t always work, but if it does it’s preferable. I rarely am forced to compile something that actually needs to be installed to system, but I’ve used it a few times with good success. (Do not make a FrankenDebian) I can’t think of anything else regarding Debian Stable that I’ve done at the moment. Anything else has just worked as I’m used to on a bleeding-edge distro like Arch Linux. Debian’s large package base has really helped me with obscure programs that I used to need to compile manually with Arch Linux.

Komunitas lemmy.world

[Discussion] Flatpaks, ram/disk usage and compression

This is why I’ve never liked the idea of flatpak, it really seems like the Windows way of doing things. It honestly still kind of surprises me that Linux people really wanted to download random binaries from non-trusted distributors that contain a copy of every library that software needs to run. wedontdothathere.jpg

Komunitas feddit.nl

one last banger stolen from rednote

I’m so tempted to try it out, but I just really don’t like downloading a “random” APK without at least knowing if there’s a way to verify there’s nothing malicious in the app. Chinese or otherwise, it’s all the same. Took me forever to trust the newpipe download… I’m just too cautious I guess.

Komunitas lemmy.sdf.org

CAPTCHAs are 'a tracking cookie farm for profit that made us spend 819 billion hours clicking to generate nearly $1 trillion for Google

What will be effective depends on the nature of the site and that of the bots causing trouble. For example, a forum can limit posting privileges until an account builds a reputation, a paid goods/services site can restrict access until a purchase is made, a web service can use revocable credentials, and a data download site can use rate limits. (That last one is actually useful in a variety of situations, and can be done at the network level instead of or in addition to the application level.) There is no silver bullet, but there are lots of small measures that can be very effective when applied thoughtfully, without turning a site into a frustrating-to-use surveillance tool for Google at the expense of the humans who want to or have to use it. Even a small, locally hosted, activate-only-once, simple image or text-based CAPTCHA would be preferable to the ones operated by third parties.

Komunitas feddit.de

Why do you still hate Windows?

It just… lacks features? I couldn’t use ZFS or Btrfs, FDE requires third-party software (veracrypt) and lots of other things that I see as standard system utilities (think ssh, git etc.) are not available on a fresh install. And then you’re supposed to download and install .exe files from the internet? Since microsoft controls what goes in the windows store, that could provide the same experience as your distro’s repositories. But again, most things you want aren’t there, and you can’t even trust the things that are there. For some reason, a billion dollar company cannot curate a software repository of the same quality as the ones maintained by unpaid volunteers in the Linux world. So yeah, I think it’s just not there yet. Maybe in a few years windows will be a viable alternative for desktop systems.

Komunitas europe.pub

The Free JavaScript campaign

When looking to ensure that our computers are running free software, we usually turn our attention to the operating system and programs we install. Increasingly, we also need to look at the Web sites we visit. Simply visiting many sites loads software onto your computer, primarily JavaScript, that carry proprietary licenses. If we want to be able to browse the Web without running nonfree software, we need to work together to call for change. The Free JavaScript campaign persuades companies, governments, and NGOs to make their Web sites work without requiring that users run any proprietary software. We pick one site at a time and focus energy on it, working as a team to send many polite but firm messages to the site maintainers. The JavaScript programs in question create menus, buttons, text editors, music players, and many other features of Web sites, so browsers generally come configured to download and run them without ever making users aware of it. Contrary to popular perception, almost no JavaScript runs “on the Web site” – even though these JavaScript programs are hidden from view, they are still nonfree code being executed on your computer, and they can abuse your trust. Join us in calling for a Web that respects our freedom by being compatible with free software. Use the action box on the right to contact the organization we’re currently focusing on and ask them to make their site work without nonfree JavaScript. https://ghostarchive.org/search?term=https%3A%2F%2Fwww.fsf.org%2Fcampaigns%2Ffreejs I guess the lemmy javascript my instance runs ins open source software, right?

Komunitas lemmy.ml

RARBG clone launches: NQ-RARBG

One thing I REALLY hope doesn’t make it into the clone… Rarbg made a point of claiming every single entry was seeded, despite the fact that pretty much anything more than a few months old was in fact not seeded and could only be obtained if another user came back. If you wanted to grab a TV show that had ended a couple years ago, you could bet that many episodes had a number of peers listed who were hoping it would be seeded again, but they never were. I guess I should clear out that stuff from my client now, but I actually have entries that have been waiting for up to two years because I couldn’t find them anywhere else. So if any of the devs are reading this thread, please don’t insult your users in this way. Rarbg eventually became my last resort for finding downloads since I knew I couldn’t trust if anything was seeded, despite the high quality of the files that were represented when you could get them.

Komunitas ibbit.at

This Week in Security: The Shai-Hulud Worm, ShadowLeak, and Inside the Great Firewall

Hardly a week goes by that there isn’t a story to cover about malware getting published to a repository. Last week it was millions of downloads on NPM, but this week it’s something much more concerning. Malware published on NPM is now looking for NPM tokens, and propagating to other NPM packages when found. Yes, it’s a worm, jumping from one NPM package to another, via installs on developer machines. It does other things too, like grabbing all the secrets it can find when installed on a machine. If the compromised machine has access to a Github account, a new repo is created named Shai-Hulud, borrowed from the name of the sandworms from Dune. The collected secrets and machine info gets uploaded here, and a workflow also uploads any available GitHub secrets to the webhook.site domain. How many packages are we talking about? At least 187, with some reports of over 500 packages compromised. The immediate attack has been contained, as NPM has worked to remove the compromised packages, and apparently has added filtering code that blocks the upload of compromised packages. So far there hasn’t been an official statement on the worm from NPM or its parent companies, GitHub or Microsoft. Malicious packages uploaded to NPM is definitely nothing new. But this is the first time we’ve seen a worm that specializes in NPM packages. It’s not a good step for the trustworthiness of NPM or the direct package distribution model. Token Impersonation in Azure There’s an interesting write-up from [Dirk-jan Mollema] detailing his findings regarding Azure impersonation tokens and how to abuse them. This is about the Entra ID service, the identity and access management component of the Azure cloud. Azure has a function that allows a service like Exchange to generate an actor token, allowing the service to interact with the rest of Azure on behalf of a user. These tokens are just signed JSON Web Tokens (JWTs). For a service to actually use one of these tokens, it’s embedded inside yet another, unsigned JWT. This outer token container has multiple fields indicating the the tenant that signed the inner token and the tenant the request is intended for. You may already wonder, what happens if we could get our hands on one of these double-wrapped tokens, and manipulate the target tenant field? If an attacker can discover the tenant ID and a valid netId for a user in the victim tenant, one of these impersonation tokens could be generated from the attacker-owned tenant, and then manipulated to point to the victim tenant. From there, the attacker could perform any action as that user. It was an extremely significant flaw, and Microsoft pushed an immediate patch within days. The CVE scores a perfect 10 base score in the CVSS 3.1 scale. ShadowLeak and Prompt Injection, the Attack That Won’t Go Away There’s yet another example of weaponizing prompt injections against LLMs, in the form of ShadowLeak. And again, it’s the case where agentic AI can fall to social engineering. The setup is that the AI is handling incoming emails, and the prompt is hidden inside an incoming email, perhaps as white text on a white background. The real challenge here isn’t sneaking the prompt in, but how to exfiltrate data afterwards. OpenAI’s Deep Research agent includes browser.open, to allow the AI to interact with the Internet. And of course, this gives the agent the ability to send data to a remote endpoint. Firewall Warnings SonicWall has announced that their MySonicWall systems were breached, and customers have been warned that their firewall configuration backups may have been compromised. These backups appear to include passwords. Watchguard Firebox firewalls have an out-of-bounds write that can allow Remote Code Execution (RCE) on firewalls running VPNs with IKEv2. A fix is available for the units that are still actively supported, and it’s possible to mitigate against the flaw. Inside The Great Wall There was a huge, 600 GB leak last week, of source code and information about the Great Firewall of China. If you click through, the 600 GB leak is available to download, but it’s not something to download and interact with lightly. Put simply, it’s a lot of data produced by level state-sponsored actors, dealing with rather sensitive capabilities. Among the non-source files, there are some interesting details, such as how the Chinese firewall has been exported to multiple other countries. The source code itself is still being analyzed, and so far it’s an interesting look into the cat and mouse game that has been long played between the Chinese government and VPN technologies. This leak will likely take quite some time to fully analyze, but promises to provide a significant look into the internals of the Great Firewall. Bits and Bytes LG TVs running WebOS had a fun issue, where plugging in a USB drive exposed the files on a web endpoint. The filename to download is specified via a parameter to that url, and that parameter doesn’t do path traversal filtering. This gives arbitrary read access to the whole device filesystem. Google has uncovered and then squashed the SlopAds advertising fraud campaign. This campaign was a collection of apps that presented themselves as hastily made, “AI slop” apps. But when installed, these apps clicked as fast as they could on ads that paid out for the attackers. This represents 224 malicious applications removed, and was resulting in 2.3 billion ad hits per day. From Blog – Hackaday via this RSS feed

Komunitas ibbit.at

The Subnautica 2 lawsuit is getting even messier, with Krafton doing a massive U-turn, confusing both the ousted founders' lawyer and the judge: 'This is a little bit bewildering'

It wasn’t all that long ago that we were anticipating the imminent arrival of Subnautica 2. The sequel to the superb underwater survival game has yet to appear, though, and the founders of Unknown Worlds have been ousted by owner Krafton, leading to a messy legal dispute between the two parties. One of the reasons given for the termination was the state of the game. The founders believed that it was ready for an early access launch and planned to go through with it; Krafton, meanwhile, believed it wasn’t ready for its debut and that the founders had been shirking their duties. But there’s been a surprising U-turn, with Krafton significantly changing its argument. The lawsuit is now in the discovery phase, so Fortis Advisors, which represents the ousted founders, sought discovery to see if Krafton held evidence to back up its claims. “But despite its obvious relevance, Krafton feigned astonishment during the parties’ meet and confers at how it could possibly be part of Phase I,” Fortis said. Essentially, Krafton said that documents relating to the readiness of the game were irrelevant to the termination—which is what this phase of discovery is focused on—despite this being the reason cited in the termination notices, which was also repeated publicly and in court. “The termination notices of the founders gave one reason for their termination,” said Fortis, “and that was the supposed lack of readiness of Subanutica 2 for release. Krafton reiterated that basis for its actions repeatedly.” Fortis called it a “seismic shift in the case” and “a little bit bewildering”. This was also echoed by the judge, Lori W. Will, when the parties met for a ruling on the filed motions, saying: “Well, that’s something that we definitely need to get to the bottom of today, because that is precisely what was cited as the reason in the answer.” Krafton’s representatives were not clear about why this argument has been taken off the table, only that it has been, and that it’s no longer why they are saying the founders were terminated. Instead, Krafton is focusing on the argument that the founders “abandoned their posts” and “deceived” their employer. Causing more confusion is the accusation that the founders downloaded files and kept devices with confidential information on them. This only came to light after the termination, so its relevance has been questioned. Krafton’s position is that this justified their termination after the fact, and it filed a motion to forensically inspect the founders’ devices. The founders, meanwhile, contend that they had a right to those documents and devices, and that the motion is too invasive—and to the latter point, the judge agreed. Fortis also alleged that Krafton hasn’t been playing ball, pushing back against some of its requests for discovery and refusing to confer. It claimed it needs emails and documents that relate to the earnout (the founders have accused Krafton of intentionally delaying the game so it wouldn’t have to pay a $250 million earnout) but Krafton is only willing to provide data from two people high up in the company, rather than employees who were “on the ground”. Another point of contention is what documents Krafton is willing to provide: specifically, only where the word “earnout” intersects with the word “termination”. “That’s very narrow,” the judge replied. “That sounds like a really terrible email for someone to write, and it’s hard for me to imagine that they’d be that blunt about it.” Krafton also argued that the plaintiff requested too many custodians—people who possess relevant data—and that it would take too long. The judge agreed the number was too high, but that the two parties would need to confer—something that Krafton had previously declined to do after it changed its argument. “That’s very frustrating,” the judge said. The discussion of the motions ended with both parties agreeing to confer, at least, and confirmation that game readiness was not the reason why the founders were terminated. Still, the whole thing remains rather messy, and it continues to be unclear why Krafton has made a U-turn when it was so adamant before that the state of Subnautica 2 was one of the reasons the founders were fired, which only happened after discovery was sought. What does seem clear, though, is that this likely won’t be resolved any time soon. 2025 games: This year’s upcoming releasesBest PC games: Our all-time favoritesFree PC games: Freebie festBest FPS games: Finest gunplayBest RPGs: Grand adventuresBest co-op games: Better together From PCGamer latest via this RSS feed

Komunitas ibbit.at

Chop Wood, Carry Water 9/15

From Into Action. Download here. Hi, all, and happy Monday. I hope you had a great weekend— it is, as always, a wild moment in the news and I trust you’re caring for yourself accordingly. This will be an eventful week in Congress, as some sort of spending bill must be passed by both chambers before September 30. The House will likely be voting on a Continuing Resolution today or tomorrow that goes for about 7 weeks, but it’s unclear—surprise surprise—whether Johnson has the votes to pass it. In the Senate there’s even less clarity. Remember, Schumer has some leverage in this fight, as Democrats have filibuster power in the Senate. One would like to think that Dems, as a result, had a unified and powerful ask in this moment, but I’m not convinced that they do. Schumer and Jeffries are making vague noises about healthcare, but mostly they’re just asking Republicans to come to the bargaining table—something the GOP has thus far been unwilling to do. As far as demanding anything beyond a permanent extension of the ACA premium tax credits and maybe a repeal of the cuts to Medicaid funding (which they’ll never get) Democratic leadership seems thus far uninterested in demanding real concessions. We’ve got to try to change that. I’ve provided call scripts below. It is imperative that we keep trying to push Democrats to ask for more than they currently are. Polling shows that Americans will support them in shutting down the government if Democrats demand, in return, a repeal of both Medicaid cuts and the billionaire tax cuts, too, and more checks on Trump’s power! But Schumer, as always, is approaching the fight armed with a metaphorical plastic fork. His jumble of tepid asks and unclear demands does not, in short, inspire confidence. It’s frustrating, to say the least. Folks, Democrats need new leadership. Desperately. I will continue to call for it every time I call my representatives, and I hope you will, too. In the meantime we must push the leaders we have as hard as we can. Will they listen? Hard to say. Schumer is well aware of how furious we were with him for his capitulation in March. He appears to be determined to do better. Perhaps if we push him he will. OK. This newsletter is already late so I’ll leave it there. I’m sending love and strength to every one of you. If I have to be in a seemingly endless slog to save our democracy there is no one I’d rather be in it with than you. Let’s get to work. Correction I inadvertently posted something false in yesterday’s “Extra Extra.” I wrote that the UN had moved its summit from NYC to Geneva in response to the Trump administration’s refusal to grant Palestinian leadership entry to the US. This was apparently misinformation. I’m terribly sorry about that! I’ve removed the item from the online version of the newsletter and will, again, endeavor to be more careful about what I post. Call Your Senators (find yours here) 📲 Hi, I’m a constituent calling from [zip]. My name is ______. First, please ask the Senator to oppose the nomination of Stephen Miran for the Federal Reserve Board. Allowing a White House advisor to serve on the board will disrupt its independence and put the stability of our already shaky economy at greater risk. [H/T] [If Democrat:] Also, I’m furious to hear that Senate Democrats are considering caving to Republicans on the government spending package. I’m hearing they are thinking of allowing Trump some rescissions and that they’re not demanding a reversal of tax cuts for the richest Americans—even though Americans support these asks. In short, they’re not using their leverage to fight for popular policies. I can’t begin to express my frustration with this. Democrats wonder why they’re not popular? THIS is why. They should be saying NO to any rescissions. They should demand a permanent extension of the ACA tax credits, a reversal of all Medicaid cuts, and a reversal of tax cuts for billionaires. Otherwise they should vote no. [If Republican] I understand that Republicans have made no move to negotiate with Democrats on the spending bill, even though we are two weeks away from a shutdown. I find this so disappointing. The Senator knows Trump’s rescissions are wrong and that we must permanently extend the ACA premium tax credits and reverse Trump’s Medicaid cuts. S/he knows that bipartisanship matters. Please ask him/her to uphold his/her values and work with Democrats to achieve these ends. Thanks. Call Your House Rep (find yours here) 📲 Hi, I’m a constituent calling from [zip]. My name is _______. [If Republican] I understand that Republicans have made no move to negotiate with Democrats on a spending bill, even though we are two weeks away from a shutdown. I find this so disappointing. The Congressmember knows that bipartisanship matters. Please ask him/her to uphold his/her values and work with Democrats to achieve a spending bill that represents all Americans. Thanks. [If Democrat:] Please ask the Congressmember to vote no on the upcoming Continuing Resolution unless it contains provisions preventing all future rescissions, codifying a permanent extension of the ACA tax credits, reversing all Medicaid cuts, and reversing Trump’ tax cuts for billionaires. Thanks. Extra Credit ✅ A great action from reader Katharine H. I’ve written a letter to SCOTUS [asking each member to uphold their oath to the Constitution] that your readers are welcome to use and edit as necessary. I’ve saved it in a Google Drive folder (“LETTERS FOR DEMOCRACY”) along with letters to the 15 cabinet secretaries, and a letter people can use if they have Republican members of congress. Here’s the link to the SCOTUS letters. Here’s the link to the folder with ALL the letters. I copied the text of the letter and pasted it onto my own Google doc, then edited as I wished. I will be mailing my letter to John Roberts today. You can write only him, or to all of the justices individually. There is a template for each one. Get Smart! 📚 Reminder, Activate America’s next Organizer 101 training is coming up on Tuesday, September 16 at 5 PM Pacific / 8 PM Eastern. They host these to give people the skills they need to start organizing for the critical upcoming election. They have trained nearly 500 organizers across the country since Spring, especially in the swing districts and states that will determine control of Congress. These skills will also be very useful for anyone organizing around California’s redistricting initiative, Prop 50, on the ballot this November. You can sign up HERE. Give 💰! See below regarding the Zoom fundraiser on Wednesday at which I’ll be speaking. It’s a great description of Swing Blue Alliance’s goals and the rationale behind all of their grassroots work. And I do hope some of you can come! The Grassroots ConnectorTurning Virginia’s Red Districts Blue in 2025 – The Path to Winning in 2026By Michelle Moore, Swing Blue Alliance-Virginia…Read more4 days ago · 21 likes · 5 comments · Robbin Warner Win Races! 🗳 Join Sister District on September 16 for Fight for our Future: Momentum Starts Now. Hear from a Sister District alum elected official preparing for 2026, a volunteer leader, and members of their team powering grassroots action every day. Learn why state legislatures are the key to lasting change, and how volunteering with Sister District can make the difference. Sign up below! https://sisterdistrict.com/event-details/eventid/828665/ Chop Wood, Save the Planet 🔥 There are just 10 days to go until Sun Day! Over 350 events are planned across 46 states, making it the biggest day of action for clean energy in decades. All we need is YOU. You can search their events page here to see what’s planned! Resistbot Letter (new to Resistbot? Go here! And then here.) 💻 [To: all 3 reps] [H/T ] [Text SIGN PWZIIK to 50409, or to @Resistbot on Apple Messages, Messenger, Instagram, or Telegram] (Note that for the most effective RESISTBOT it’s best to personalize this text. More about how to do this here. But if you’re short on time just send it as is using the above code.) Treasury Secretary Scott Bessent’s recent behavior — reportedly screaming threats of violence, including “I’m gonna punch you in your f***ing face,” at a journalist — is not only disgraceful but also disqualifying. A man entrusted with the nation’s economic stability must not behave like an unhinged playground bully. This is not a partisan issue; it is a matter of basic competence and dignity in office. Bessent’s tantrums and sleazy smears, documented by respected journalists including Paul Krugman, show a pattern of behavior that is both childish and dangerous. How can Congress expect the American people to trust an official who lashes out like an angry adolescent when asked hard questions? Congress must hold hearings to investigate Bessent’s conduct and fitness for office. The Treasury Secretary wields enormous influence over our economy, our markets, and our international credibility. If he cannot manage his temper, or if he cannot engage with criticism without resorting to threats, then he is not grown-up enough to handle this job. I urge you to take immediate action. The American people deserve leadership marked by integrity, not intimidation. OK, you did it again! You’re helping to save democracy! You’re amazing. Talk soon. Jess Chop Wood, Carry Water is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber. Share Leave a comment From Chop Wood, Carry Water via this RSS feed

Komunitas ibbit.at

Dragon is the Latest, and Final, Craft to Reboost ISS

The International Space Station has been in orbit around the Earth, at least in some form, since November of 1998 — but not without help. In the vacuum of space, an object in orbit can generally be counted on to remain zipping around more or less forever, but the Station is low enough to experience a bit of atmospheric drag. It isn’t much, but it saps enough velocity from the Station that without regular “reboosts” to speed it back up , the orbiting complex would eventually come crashing down. Naturally, the United States and Russia were aware of this when they set out to assemble the Station. That’s why early core modules such as Zarya and Zvezda came equipped with thrusters that could be used to not only rotate the complex about all axes, but accelerate it to counteract the impact of drag. Eventually the thrusters on Zarya were disabled, and its propellant tanks were plumbed into Zvezda’s fuel system to provide additional capacity. An early image of ISS, Zarya module in center and Zvezda at far right. Visiting spacecraft attached to the Russian side of the ISS can transfer propellant into these combined tanks, and they’ve been topped off regularly over the years. In fact, the NASA paper A Review of In-Space Propellant Transfer Capabilities and Challenges for Missions Involving Propellant Resupply, notes this as one of the most significant examples of practical propellant transfer between orbital vehicles, with more than 40,000 kgs of propellants pumped into the ISS as of 2019. But while the thrusters on Zvezda are still available for use, it turns out there’s an easier way to accelerate the Station; visiting spacecraft can literally push the orbital complex with their own maneuvering thrusters. Of course this is somewhat easier said than done, and not all vehicles have been able to accomplish the feat, but over the decades several craft have taken on the burden of lifting the ISS into a higher orbit. Earlier this month, a specially modified SpaceX Cargo Dragon became the newest addition to the list of spacecraft that can perform a reboost. The craft will boost the Station several times over the rest of the year, which will provide valuable data for when it comes time to reverse the process and de-orbit the ISS in the future. Reboosting the Russian Way By far the easiest way for a visiting spacecraft to reboost the ISS is to dock with the rear of the Zvezda module. This not only places the docked spacecraft at what would be considered the “rear” of the Station given its normal flight orientation, but puts the craft as close as possible to the Station’s own thrusters. This makes it relatively easy to compute the necessary parameters for the thruster burn. Progress 72 in 2019 Historically, reboosts from this position have been performed by the Russian Progress spacecraft. Introduced in 1978, Progress is essentially an uncrewed version of the Soyuz spacecraft, and like most of Russia’s space hardware, has received various upgrades and changes over the decades. Progress vehicles are designed specifically for serving long-duration space stations, and were used to bring food, water, propellants, and cargo to the Salyut and Mir stations long before the ISS was even on the drawing board. Reboosts could also be performed by the Automated Transfer Vehicle (ATV). Built by the European Space Agency (ESA), the ATV was essentially the European counterpart to Progress, and flew similar resupply missions. The ATV had considerably greater cargo capacity, with the ability to bring approximately 7,500 kg of materials to the ISS compared to 2,400 kg for Progress. Only five ATVs were flown, from 2008 to 2014. There were several proposals to build more ATVs, including modified versions that could potentially even carry crew. None of these versions ever materialized, although it should be noted that the design of the Orion spacecraft’s Service Module is based on the ATV. American Muscle Reboosting the ISS from the American side of the Station is possible, but involves a bit more work. For one thing, the entire Station needs to flip over, as the complex’s normal orientation would have the American docking ports facing fowards. Of course, there’s really no such thing as up or down in space, so this maneuver doesn’t impact the astronauts’ work. There are however various experiments and devices aboard the Station that are designed to point down towards Earth, so this reorientation can still be disruptive. Depending on the spacecraft, simply flipping the Station over might not be sufficient. In the case of the Space Shuttle, which of the American vehicles performed the most reboost maneuvers by far, the entire complex had to be rotated into just the right position so that the thrusters on the spaceplane would be properly aligned with the Stations’ center of mass. As described in the “AUTO REBOOST” section of the STS-129 Orbit Operations Checklist, the Shuttle’s computer would actually be given control of the maneuvering systems of the ISS so the entire linked structure can be rotated into the correct position. A diagram in the Checklist even shows the approximate angle the vehicle’s should be at for the Shuttle’s maneuvering thrusters to line up properly. With the retirement of the Space Shuttle in 2011, maintaining the Station’s orbit became the sole domain of the Russians until 2018, when the Cygnus became the first commercial spacecraft to perform a reboost. The cargo spacecraft had a swiveling engine which helped get the direction of thrust aligned, but the Station did still need to rotate to get into the proper position. After performing a second reboost in 2022, the Cygnus spacecraft was retired. It’s replacement, the upgraded Cygnus XL — is currently scheduled to launch its first mission to the ISS no earlier than September 14th. Preparing for the Final Push That brings us to the present day, and the Cargo Dragon. SpaceX had never designed the spacecraft to perform a reboost, and indeed, it would at first seem uniquely unsuited for the task as its “Draco” maneuvering thrusters are actually located on the front and sides of the capsule. When docked, the primary thrusters used for raising and lowering the Dragon’s own orbit are essentially pressed up against the structure of the ISS, and obviously can’t be activated. Crew Dragon approaching the ISS, note four Draco thrusters around docking port. To make reboosting with the Dragon possible, SpaceX added additional propellant tanks and a pair of rear-firing Draco thrusters within the spacecraft’s un-pressurized “trunk” module. This hollow structure is usually empty, but occasionally will hold large or bulky cargo that can’t fit inside the spacecraft itself. It’s also occasionally been used to deliver components destined to be mounted to the outside of the ISS, such as the for the outside of the ISS, such as the International Docking Adapter (IDA) and the roll-out solar panels. Additional propellant tanks mounted in the trunk of the Cargo Dragon. While the ability to have the Dragon raise the orbit of the International Space Station obviously has value to NASA, the implications of this experiment go a bit farther. SpaceX has already been awarded the contract to develop and operate the “Deorbit Vehicle” which will ultimately be used to slow down the ISS and put it on a targeted reentry trajectory sometime after 2030. Now that the company has demonstrated the ability to add additional thrusters and propellant to a standard Dragon spacecraft via a module installed in the trunk, it’s likely that the Deorbit Vehicle will take a similar form. So while the development of this new capability is exciting from an operational standpoint, especially given deteriorating relations with Russia, it’s also a reminder that the orbiting laboratory is entering its final days. From Blog – Hackaday via this RSS feed

Komunitas atomicpoet.org

Katanaut just dropped on Steam—and it’s a blood-soaked beast.

Katanaut just dropped on Steam—and it’s a blood-soaked beast. This is a Metroidvania-flavored roguelite where you descend through a space station ravaged by a grotesque infection. Once-human inhabitants are now nightmares. You carve them apart with a katana, unload what little ammo you’ve got, and push deeper with every death. Each run feeds into meta-progression—downloaded “memory fragments” unlock new skills, perks, and weapons. And at the end of each elevator descent, you carry those gains forward into the abyss. Boss fights? Enormous and nasty. Think Dead Cells in motion, Dead Space in mood. The visuals are rich pixel art built in Godot. Detailed sprites, hand-crafted rooms, and backgrounds that drip with atmosphere. For all the darkness, it’s vivid—blood reds, cold steel blues, cosmic purples. Accessibility is baked in too: adjustable text size, subtitle support, color alternatives, and save-anywhere. The combat feels incredibly tight. Keyboard and mouse were a breeze—I found myself slicing and shooting with the mouse buttons alone. It clicked instantly. The katana swings have real bite, and when you land a shot, the crisp sound effects make it satisfying every time. I tested it with gamepads too—Xbox and PlayStation both—and they worked flawlessly. And best of all, no timed input nonsense. Just raw reaction and skill. Audio slams just as hard. A pounding synthwave score fuels the pace. It’s become the default genre for action indies, and here it works—neon soundscapes with sharp, surgical effects. I loved how every katana strike felt amplified by the soundtrack. Custom volume controls let me balance music against effects, and surround support made headphones a joy. Specs are modest. Any halfway-decent CPU, 4GB of RAM, 1GB of space. Runs on Godot’s Vulkan renderer, but if your GPU isn’t up to snuff, there’s a compatibility mode too. Having played it myself, I can say this: Katanaut is tuned to perfection. I never hit that cheap frustration wall that so many roguelites throw up. Instead, it’s tough but fair. Voidmaw may be a first-time developer, but this feels like the work of a seasoned studio. It launched today with a 20% discount—C$18.71—and for the time I’ve already sunk in, that’s absurdly good value. This is no mere rogue-like. It’s a finely honed 2D side-scroller that absolutely nails the mix of speed, atmosphere, and challenge. https://store.steampowered.com/app/3032830/Katanaut/ @[email protected]

Komunitas ibbit.at

Chop Wood, Carry Water 9/8

Download this meme from Into Action here. Hi, all, and happy Monday. Of course, it’s not super happy. We got a couple of terrible SCOTUS rulings this morning (here and here, if you haven’t yet seen them.) The immigration-related decision, announced with no explanation, is especially heinous, as it gives ICE free rein to continue its policy of rampant racial profiling. This is in clear violation of the 4th Amendment, which protects everyone in the U.S. from “unreasonable search and seizure.” It’s depressing stuff, and there’s no quick antidote to it. There is, however, a long term fix: term limits, court expansion, and ethics reform. Don’t let anyone tell you this is an insoluble problem—it’s not. It’s simply going to require a galvanized Democratic trifecta to get it done. I highly recommend checking out Demand Justice, the Brennan Center and/or the Alliance For Justice if you’d like to learn more about Supreme Court reform. There is hope! In the short term, however, this decision is disastrous. There’s no sugar coating it. So instead of digging into more news items I want to share, with permission, a note that subscriber Christopher T. Wood just sent me. I think it’ll inspire you and maybe lift you out of the doldrums a bit. He said: Disappointed with the election results in January, my wife formed a little group called the Tropical Meme Society (@tropical.meme.society). We met at our local coffee house, Café Tropical, in the Silverlake section of LA. A few folks gathered on a bi-weekly or monthly basis. We decided to do a few bridge drops (hang signs with pro-democracy messages) over the 101 Freeway. One of our group is French and went home this summer for vacation. She noticed that all or most of the news outlets in France seemed to be voicing the opinion that while the Trump Administration had fascist tendencies, all or most Americans appeared to be fine with it. Not agreeing with that assessment, she wrote in to her local paper in Bordeaux and told them about what our group and others had been doing in support of democracy, including the No Kings Day protests. She had pictures and video, so her local paper ran the story. [Here is the link.] Within a day or so, all or most of the major news outlets had picked up the story about “La Resistance” in the US. No longer were the major media outlets of France saying all Americans were fine with what Trump was doing. The entire narrative had changed. Why? Because a few people gathered in a small café in the Silverlake section of LA to talk about what they could do. My wife has shown us, never doubt what effect a few committed people can have. Beautiful, right? Never forget—your voice has power. Every one of us is simply called to do what we can in this moment. Sometimes it will feel like our impact is minimal. Other times we’ll stumble into something that will create large ripples. The truth is we just don’t know how our actions will affect those around us, or, for that matter, history itself. It doesn’t matter. We take them anyway. Ours is not to predict outcomes. Ours is simply to do the next right action, trusting that it will lead to some good. That’s what this group did, and look at the ripples their actions created! One last thing before I go: I want to apologize for unknowingly posting misinformation in yesterday’s good news list. Chicago officials did not, in fact, use salt trucks to block ICE this weekend. The story that they did do that was—and still is—everywhere, but I should have fact checked it more carefully. I’ll endeavor to avoid similar mistakes in the future. OK, folks. I’ll be doing my Substack Live at 4PM solo, so if you want to come for an update on all the day’s news and a pep talk, join me! Now let’s get to work. Call Your Senators (find yours here) 📲 Hi, I’m a constituent calling from [zip]. My name is ______. [If Democrat:] Democrats shouldn’t provide a single vote to keep funding Trump’s repressive agenda this September. No compromises, no folding, no caving by Chuck Schumer. There should be no yes vote unless the White House guarantees, among other things, that funds will be distributed as appropriated, that there will be a 60-vote requirement for any recission, and that they will institute a ban on masked ICE/DHS agents without court orders. Democrats have power here. If they want to win back the voters who have abandoned them they’d better use it. Thanks. [If GOP:] I’m disgusted by Trump’s threat to declare war on Chicago. And please don’t tell me he was quoted out of context. We all know he wasn’t. Declaring war on an American city is arguably treasonous and definitely grounds for impeachment. Trump is dangerous, he’s unfit, and he needs to be impeached and removed. I want to hear the Senator speak out clearly against this lawless attack on American cities. Thanks. Call Your House Rep (find yours here) 📲 Hi, I’m a constituent calling from [zip]. My name is _______. First, I want the House to fully fund NIOSH [pronounced nye-osh] in 2026, consistent with the recent bipartisan Senate appropriations bill. I also want Trump and Kennedy to fully reinstate all NIOSH researchers who are still not back to work. Second, I ONLY support a government spending bill that reverses Medicaid cuts and blocks tax breaks for the rich and big corporations. I oppose any package that doesn’t contain those two provisions. [Only if Democrat add:] Finally, I want to put in a word of support for Rep. Monica McIver. I’m glad to see that the motion to censure her was tabled, and I want to see House Democrats continue to stand with her every time she’s attacked. She deserves our unqualified support. Thanks. [Only if Republican add:] Finally, has the representative signed on to Rep. Massie’s discharge petition to release the full Epstein files yet? If not, I expect him/her to do so today. The House Oversight Committee is releasing redacted papers and things we’ve already seen. It’s gaslighting. We want to see the files. The victims deserve no less. Thanks. Extra Credit ✅ The FTC is trying to attack gender-affirming care under the guise of consumer protection and the Christopher Street Project is trying to get as many public comments as possible to oppose their action. In order to make the process safer, they published a comment portal that they will use to submit on your behalf: christopherstreetproject.org/FTC. Please help uplift the portal and this instagram post: christopherstreetprojectA post shared by @christopherstreetproject . We have until September 26th to make our voices heard! Get Smart! 📚 WHY FASCISTS FEAR TEACHERS W/ RANDI WEINGARTEN Tuesday, September 9, 7:30PM ET Fascists fear education! Defunding public education, banning books, and censoring history are all part of the extremist playbook. It’s no wonder that teachers who empower students to think critically and ask questions are under attack. Join Red, Wine and Blue to hear from Randi Weingarten, President of the American Federation of Teachers, as we talk about this coordinated assault on education and why concepts like curiosity and empathy outrage fascists. Learn what’s at stake, how these attacks hurt our kids and our country, and how we can fight back. SIGN UP NOW Messaging! Messaging! Messaging! 📣 Here are some key facts on Trump’s economic failures, courtesy of Defending American Democracy. Make sure to share widely! Trump’s tariffs will cost families an additional $2,400 this year. The U.S. added just 22,000 jobs in August, while June revisions revealed the economy actually lost jobs that month. U.S. factory orders fell 4.8% in June and construction spending collapsed. Trump says he will put a 100% tariff on semiconductors. Beef prices are hitting record highs, rising nearly 9% this year. Electricity prices rose 6.5% in the last year. Trump’s tariffs are expected to impact 75% of U.S. food imports. Vegetable prices increased by nearly 40% from June to July. Get excited about campaign finance reform! I just heard a presentation from someone at CAP Action about the Montana Plan, an initiative that can essentially overturn Citizens United without actually overturning it, one state at a time. It’s very exciting and it may start in Montana! Read all about it here. Attend a Town Hall—MICHIGAN! 🪧 The amazing folks are the Progressive Caucus Center are holding a Progress for the People Town Hall in Warren, MI, on Friday Sept 12 at 1pmET with Michigan Rep. Talib & Vermont’s Rep. Balint. If you live in the area please join them to learn what the Republican budget law means for you, hear from your neighbors, and ask your questions! RSVP here. Grab Your Wallet! 💳 Rolex sponsored Trump at the U.S. Open. It’s probably a moot point for most of us, but if you’re in the market for a luxury watch please choose a different brand! Win Races! 🗳 Markers For Democracy and a coalition of grassroots groups are launching a series of four National Virtual Postcard Parties for Virginia. Join them weekly, when Virginia candidates will tell you what they are seeing and hearing in their districts. Write for the candidates of your choice, celebrate VA Dems running 100 candidates in 100 districts, and enjoy being with grassroots activists from around the country. More details here. Each evening has its own Zoom registration link: Monday, Sept 8, 2025 7-9 pm ET - Zoom Registration Link Monday, Sept. 15, 2025 7-9 pm ET - Zoom Registration Link Sunday, Sept. 21, 2025 7-9 pm ET - Zoom Registration Link Tuesday, Sept. 30 - 7-9 pm ET - School Board Night - Zoom Registration Link Chop Wood, Save the Planet 🔥 From climate denial to pandemic disinformation, powerful forces are working overtime to undermine facts and delay vital action.On Friday, September 12 at 7 PM ET, join Climate Action Now for an Action Party about the powerful forces fueling today’s war on science—and what we can do to fight back. You’ll be joined by leading climate scientist Dr. Michael E. Mann, who will share powerful insights from his newest book in a conversation moderated by Climate Action Now President Tim Guinee.Together, let’s challenge disinformation, call for accountability, and stand up for science! REGISTER NOW Resistbot Letter (new to Resistbot? Go here! And then here.) 💻 [To: all 3 reps] [H/T ] [Text SIGN PMSILR to 50409, or to @Resistbot on Apple Messages, Messenger, Instagram, or Telegram] (Note that for the most effective RESISTBOT it’s best to personalize this text. More about how to do this here. But if you’re short on time just send it as is using the above code.) Donald Trump has crossed a constitutional red line. By threatening to unleash federal immigration raids, militarized crackdowns, and what he himself calls a “Department of WAR” against Chicago, he is not merely using inflammatory rhetoric—he is levying war against an American city. The Constitution defines this as an act of treason. Trump’s “Chipocalypse Now” post, accompanied by an image evoking Apocalypse Now, was not satire or bluster. It was a declaration of intent to use the power of the federal government against U.S. citizens and local governments who defy him. This is authoritarianism, plain and simple. The threat is also baseless. Crime in Chicago has been dropping sharply, with homicides down nearly 30% and shootings down over 40%. There is no emergency that could justify such an extraordinary federal assault. Local leaders have resisted: Governor J.B. Pritzker labeled Trump a “wannabe dictator,” and Mayor Brandon Johnson has barred city agencies from assisting with raids. Thousands of Chicagoans have protested in defiance, even as community events were canceled under pressure. Congress cannot treat this as political theater. The stakes are constitutional and historic. When a president declares war on his own people, silence is complicity. I urge you to: • Hold hearings immediately to expose Trump’s threats as unconstitutional and potentially treasonous. • Legislate strict limits on the use of federal forces and immigration agencies in domestic political disputes. • Protect sanctuary jurisdictions from federal overreach and retaliation. • Affirm the principle that no president can wield war powers against the states or their people. This is bigger than Chicago. If Trump succeeds here, every city, every state, and every community is at risk. Congress must act now to defend the Constitution, protect American democracy, and stop Trump from levying war against his own country. OK, you did it again! You’re helping to save democracy! You’re amazing. Talk soon. Jess Chop Wood, Carry Water is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber. Share Leave a comment From Chop Wood, Carry Water via this RSS feed

Komunitas ibbit.at

ICEBlock handled my vulnerability report in the worst possible way

Last week, I wrote about how Joshua Aaron’s ICEBlock app, which allows people to anonymously report ICE sightings within a 5-mile radius, is – unfortunately, and despite apparent good intentions – activism theater. This was based on Joshua’s talk at HOPE where he made it clear that he isn’t taking the advice of local community groups, that ICE sightings aren’t verified in any way, and that he doesn’t know what he’s doing when it comes to security and privacy. In that post, in the section about his “HIGHLY secure” server that he kept mentioning, I wrote: Without providing more details, I also discovered that his server is running outdated software with known vulnerabilities. I was intentionally vague because I knew that his server was vulnerable at the time of writing, and I didn’t want anyone to exploit one of these vulnerabilities before he had a chance to fix it. ICEBlock has been downloaded over one million times from the App Store. I don’t know whether Joshua’s server stores data related to these users or the reports they submit, but it might, and he certainly bragged about the security of it in his HOPE talk. I’m publishing this because it’s important for people who are trusting ICEBlock to know that the developer is careless about computer security, even when people specifically point out security issues and give him time to fix them. Hopefully his server doesn’t have any user data. Hopefully no one will hack his server despite the fact that he’s making it easy for them to. And hopefully this blog post will compel him to finally fix the issue. UPDATE: It worked! Hours after I published this, Joshua has updated Apache in his server, fixing the issue. Joshua runs two Bluesky accounts: @iceblock.app, the account of the ICEBlock app, and @joshua.stealingheather.com‬, Joshua’s personal account. His personal account had DMs closed, but the ICEBlock account had DMs open, so I sent him DMs there. On September 1, I wrote: Hey Joshua, I’m one of the people who saw your HOPE talk and asked some of the questions. I’m giving you a heads up that I’m preparing to publish a blog post about the app and your talk that isn’t very flattering. But also, I wanted to give you notice that you’re running a vulnerable version of Apache on your linode server. I’m not mentioning this specifically, but you should install updatesYou seem to be running Apache httpd 2.4.57. See https://httpd.apache.org/security/vulnerabilities_24.html for more details, but this version of Apache has multiple critical CVEs which could take over your server. Like for example, this one https://nvd.nist.gov/vuln/detail/CVE-2024-38476 Then, an hour and a half later, I published my blog and sent him my Bluesky post about it: I wrote about @iceblock.app, the developer’s infuriating HOPE talk, and how it’s unfortunately basically activism theater micahflee.com/unfortunatel… — Micah Lee (@micahflee.com) 2025-09-01T22:56:27.196Z He didn’t respond from the @iceblock.app account other than blocking me. (Which, honestly, isn’t very fair, since I’m not ICE.) Screenshot from Bluesky of @iceblock.app blocking me after my responsible disclosure He did, however, send me a DM from his @joshua.stealingheather.com account, saying: It would be so great if you could stop lying about me and ICEBlock. You are doing nothing to help. You don’t know me, my history, my knowledge, or anything more than hearing me at Hope.Don’t bother responding because this will be my last and only communication with you. Do better. To which I replied: If I got anything wrong in my blog post, please let me know and I’d be happy to post a correction Here’s a screenshot of the exchange. Screenshot from Bluesky DMs with @joshua.stealingheather.com telling me I’m lying about him and his app A few days later, on September 3, I decided to check again. His server was still running Apache 2.4.57, which has multiple vulnerabilities. He ignored my report and didn’t fix it. And just so you know, fixing this problem is extremely easy. He just needs to SSH in and run something like sudo apt update && sudo apt upgrade, wait for the Apache updated package to install, and his server would no longer be vulnerable. Seeing that he wasn’t taking this seriously, I decided to give him a deadline to patch his server before I publicly disclosed the vulnerability. I sent his @joshua.stealingheather.com account these messages: Hey Joshua, I noticed that you still haven’t updated Apache on your server. I disclosed that you’re running Apache 2.4.57, which has known critical vulnerabilities, on September 1. I don’t know what data (if any) related to [ICEBlock] and its users that you store on your server. But until you update Apache, it might be trivial for anyone to hack your server and steal all of it. So, please install updates.I’m giving you a week from when I first disclosed this before I write about it (so, September 8), which should give you more than enough time to update a package.Just so you’re aware, I determined the version of Apache using nmap’s version detection feature. You can run nmap -p443 -sV iceblock.app to test the version yourself, and it should show you this:PORT STATE SERVICE VERSION443/tcp open ssl/http Apache httpd 2.4.57 ((Unix) OpenSSL/3.0.9)As a reminder, you can find the known vulnerabilities for this version of Apache here: https://httpd.apache.org/security/vulnerabilities_24.htmlAnd, as I showed you before, just one of the vulns is CVE-2024-38476, which you can read about here: https://nvd.nist.gov/vuln/detail/CVE-2024-38476. This is a “critical” vulnerability that could potentially be used to execute scripts on your server. Please get back to me. He didn’t get back to me. And an hour and a half later, he blocked me from this account too. Screenshot from Bluesky DMs with @joshua.stealingheather.com, where I disclose his vulnerability again, and he blocks me It’s now been a week, and I checked again: Joshua’s “HIGHLY secure” server is still running a version of Apache with multiple known critical vulnerabilities. And even with plenty of time to fix the issue, he still hasn’t. I hope he isn’t storing any ICEBlock-related data on there. From micahflee via this RSS feed

Komunitas ibbit.at

RFK Jr Doesn’t Care About Long COVID

Photograph Source: Embajada de EEUU en Argentina – CC BY 2.0 During his confirmation hearings to serve as Secretary of Health and Human Services (HHS), Robert F. Kennedy Jr. emphatically pledged to prioritize tackling Long COVID, a debilitating chronic condition that develops after COVID-19 infections and leaves many patients with lasting symptoms, such as fatigue, brain fog, and respiratory problems. Sen. Todd Young (R-Indiana) asked Kennedy if he would commit to funding research into treatments and diagnostics for Long COVID. Kennedy’s response? “Absolutely, senator, with enthusiasm.” Fast forward to August 2025, and Kennedy has dismantled not only federal COVID prevention programs but also much of the research infrastructure devoted to understanding and treating Long COVID. He closed the Office of Long COVID Research and Practice, a central coordinating body established in 2023 to unify agency efforts on Long COVID, and failed to meaningfully replace it. His sweeping reorganization of HHS eliminated or consolidated key centers essential for disease surveillance and chronic illness response, including the National Center for Chronic Disease Prevention and Health Promotion. Reckless funding cuts have dealt a significant blow to ongoing research, derailing NIH-funded clinical trials on antivirals and immunotherapies for Long COVID, halting large-scale cohort studies that track patient outcomes, and stalling the development of new diagnostics to improve detection and classification. Long COVID is a chronic, multisystem condition that follows COVID‑19 infection. It can arise regardless of the severity of the initial illness and is characterized by symptoms that may persist or emerge weeks to months after the acute phase of infection. Researchers have drawn parallels between Long COVID’s impact and that of a stroke or Parkinson’s. Long COVID also shares similarities with other post-viral syndromes such as myalgic encephalomyelitis/chronic fatigue syndrome (ME/CFS), which similarly involve long-term fatigue and autonomic dysfunction. Studies have shown that both Long COVID and ME/CFS can lead to quality-of-life impairments that outstrip many advanced cancers. Additional research suggests that Long COVID may be just the tip of the iceberg. Studies of large patient cohorts have found that COVID infection significantly increases the risk of cardiovascular complications, including myocarditis, arrhythmias, heart failure, and blood clots, even in people without prior heart disease. Other studies have documented a higher incidence of metabolic conditions such as new-onset diabetes. There are also neurological sequelae; COVID infections can cause or accelerate cognitive decline and dementia. Evidence suggests that repeated infection may accelerate cancer risk, in part due to inflammation and immune dysregulation. Taken together, these findings suggest that the long-term burden of COVID may extend far beyond what is captured by “Long COVID” alone. Kennedy is not a solo actor in this. Closing the Long COVID office, for example, coincided with a Trump executive order to “reduce the federal bureaucracy.” The involvement of others does not absolve Kennedy — the head of HHS — of responsibility for what takes place in his agency on his watch. It does, however, suggest that this is not a one-man problem but something more systemic and entrenched. The issue is not limited to HHS; the Occupational Safety and Health Administration (OSHA), for example, is currently seeking to remove the few remaining emergency reporting requirements for hospitals. Creating Barriers to COVID Vaccines Of course, one of the best ways to avoid Long COVID is to avoid getting infected with COVID. Kennedy has spoken about wanting to address root causes, and the root cause of post-COVID complications is infection with COVID, making prevention efforts a key way to prevent new health problems. Unfortunately, Kennedy has approached COVID prevention the same way he has approached measles prevention. He has gone after COVID vaccines, both the currently available shots and promising research into improved versions. As a form of protection from Long COVID, the current vaccines appear to be useful, albeit insufficient on their own. Most studies indicate that vaccination reduces the risk of Long COVID, and several find additional benefits from boosters, although this varies by timing and variant. One meta-analysis found that COVID vaccination reduces the risk of developing Long COVID by around 30 percent, depending on variant and timing of vaccination. A more recent study suggested that vaccination had played a major role in observed declines in new cases of Long COVID during later infection waves. Primary series vaccinations appear to be the most effective in reducing the risk of developing Long COVID following infection. Subsequent variant-specific shots appear largely helpful as a means of preventing infection (as imperfectly measured by symptomatic disease), which in turn lowers the downstream risk of Long COVID. However, such protection is limited and short-lived. Vaccine effectiveness against symptomatic disease peaks at 50 to 70 percent within a few weeks of administration and declines substantially over the following months. It often approached negligible levels within six months, particularly in the face of immune-evasive variants like XBB and its descendants. Taken together, the evidence suggests that vaccines, although far from a silver bullet, are a useful tool for reducing Long COVID. Cutting off access to vaccines will almost certainly mean more Long COVID cases and more people with lasting complications. Unfortunately, Kennedy’s leadership thus far has culminated in new barriers to COVID vaccination that threaten to severely limit this year’s uptake (assuming new vaccines become available at all). The Food and Drug Administration (FDA) declined to approve COVID vaccines for those under age 65 without high-risk conditions, instead requiring randomized controlled trials in those groups before considering future approval. This includes both primary series vaccinations and additional variant-specific shots for those who have already received their primary series. The FDA also revoked the Emergency Use Authorization for Pfizer’s vaccinein children under the age of 5, leaving Moderna’s formulation as the only authorized option for high-risk children in this age group. For healthy children under 5, the only remaining path to vaccination is now through off-label use by a healthcare provider. The new framework imposes similar restrictions on adults: as of August 22, individuals under the age of 65 without high-risk conditions became ineligible to receive COVID vaccines through standard authorization channels. The effort was touted as a cautious, evidence-driven approach, but its effect is to delay and potentially deny broad access to vaccines that were previously available (if not always affordable) to a much wider population. Limited access for children younger than 5 years old could be especially devastating. This age group has experienced some of the highest COVID-19 hospitalization rates of any pediatric cohort. Emerging data suggests that Long COVID may have overtaken asthma as the most common chronic illness affecting US children, with nearly 5.8 million affected by post-COVID conditions. Kennedy has gone after public health officials who don’t share his approach to vaccination. Earlier this summer, Kennedy fired every member of the Centers for Disease Control and Prevention (CDC) Advisory Committee on Immunization Practices (ACIP), a critical advisory body, replacing many of them with known vaccine skeptics. The ACIP’s role is to make recommendations within the boundaries of FDA approval; its personnel shake-up suggests that even within the FDA’s more restrictive framework, the CDC’s recommendations will be guided by an anti-vaccine political agenda rather than science. While ACIP had not always taken Long COVID seriously before, it did greenlight broad COVID vaccine eligibility in 2024, even if said vaccines remained financially out of reach for far too many. Kennedy, CDC Firings, and Massive Research Cuts And this past week, President Trump (at Kennedy’s behest) fired Susan Monarez, the director of the Centers for Disease Control and Prevention (CDC). A wave of protest resignations followed across senior leadership, including Chief Medical Officer Dr. Debra Houry, Director of the National Center for Immunization and Respiratory Diseases Dr. Demetre Daskalakis, and Director of the National Center for Emerging and Zoonotic Infectious Diseases Dr. Daniel Jernigan. In his resignation letter, Daskalakis opined, “Having worked in local and national public health for years, I have never experienced such radical non-transparency, nor have I seen such unskilled manipulation of data to achieve a political end rather than the good of the American people.” The insufficient protection afforded by current vaccines makes ongoing research into the next generation of prophylactics that much more crucial. But this month, Kennedy unilaterally slashed $500 million from mRNA-related research, which encompassed, among other things, vaccines targeting COVID, H5N1 bird flu, and RSV. Kennedy justified the cuts in part by suggesting that mRNA technology is inherently unsafe, an assertion not supported by scientific evidence. Earlier this year, Kennedy’s HHS issued a stop-work order to CastleVax for its development of an intranasal COVID vaccine. Intranasal vaccines have shown promise in inducing the mucosal immunity necessary to better prevent transmission. The Trump government, however, has declared COVID “over” (despite evidence to the contrary), and thus all further research related to it is considered expendable. This month, Kennedy’s HHS also took aim at wastewater surveillance, a crucial tool for people trying to use real-world data to calibrate their preventive measures. Wastewater monitoring provides an early warning system for spikes in COVID and other infectious diseases, helping immunocompromised individuals — such as those recovering from cancer — decide when it may be safer to risk exposure from necessary activities like visiting the dentist. Kennedy’s HHS has doubled down on a favorite minimization tactic of the previous administration, and has changed the thresholds for transmission categories, such that virus levels that were previously categorized as “high” are now considered “very low.” More alarmingly, under Kennedy, the CDC has quietly stopped normalizing wastewater data (that is, adjusting for things like rainfall levels), a technical change that will significantly degrade its quality and comparability over time. Without normalization, raw viral counts are misleading, making it far harder for individuals, communities, and health systems to gauge real infection trends. This change threatens to undermine one of the most important and cost-effective surveillance tools still available. Kennedy is clearly not interested in keeping the promise he made to the American people to tackle Long COVID. His behavior does, however, track with the ableist healthism that Julie Doubleday lucidly identifies as the beating heart of Kennedy’s “Make America Healthy Again” (MAHA) movement. Ableist healthism is an ideology that equates being healthy with virtue and reframes public health as an individual lifestyle project rather than a collective obligation. It also conflates “natural” with “good,” which explains why MAHA advocates seem so unfazed by preventable deaths from ‘natural’ diseases like measles. Given MAHA’s complacency in the face of preventable death and disability from measles, it’s unsurprising that they would shun interventions like vaccines and other preventative medical interventions for COVID. To be sure, Kennedy has capitalized on the earned mistrust of his predecessors. That mistrust was fueled by a series of blunders, including but not limited to downplaying the threat of long-term COVID sequelae, failing to fully grapple with the reality of airborne transmission, and an unwillingness to meaningfully revisit the “vax and relax” strategy even as evidence increasingly failed to support that approach. Many but not all of these blunders appeared to originate from corporate pressure to return to a “normal” with a weaker social state and fewer protections for workers. However, rather than building back trust based on sound science, Kennedy has doubled down on misinformation. Rather than leveling with people about both the benefits and limitations of existing COVID vaccines, for example, he has cast ill-founded aspersions on their safety profile (and the safety profile of other preventative medicine). He has also actively made it more difficult for those who want to use vaccines to protect themselves to do so. Where the agency once sowed confusion through poor messaging, Kennedy has actively weaponized that communications weakness to recast scientific uncertainty as evidence of conspiracy, replacing cautious half-truths with clear falsehoods. It is abundantly evident that Kennedy does not intend to prioritize the well-being of Long COVID patients. Instead of using his immense power to expedite research to help current patients and prevent new cases, he has taken a hatchet to the limited systems of care that were already in place. But disabled lives are not expendable. Millions of people living with Long COVID and other post-viral and chronic conditions deserve dignity, care, and a government that values their survival and well-being. Investing in scientific research and robust public health infrastructure is not charity, but a commitment to a collective future that values and includes everyone in our community. The Trump government’s abandonment of Long COVID patients and disdain for prevention is not acceptable and should be recognized for what it is: a political choice to deepen suffering rather than relieve it. This first appeared on CEPR. The post RFK Jr Doesn’t Care About Long COVID appeared first on CounterPunch.org. From CounterPunch.org via this RSS feed

Komunitas lemmy.ml

Are there any examples of Linux (desktop) viruses that are actively or were recently in circulation?

TLDR: While Linux is less susceptible to malware in some ways, it mostly boils down to Linux having a more technically minded userbase whereas Windows is a “mainstream” operating system. Most Windows malware nowadays come from social engineering scams (complete this “captcha” by pressing Windows+R and pasting in this powershell script we conveniently put in your clipboard) or untrusted third party installers because Windows doesn’t natively have a package manager. Like others have said, the old school self-propagating worms and drive by downloads that activate just by clicking on a link aren’t really possible anymore (outside of state actors with unlimited budgets to buy zero days) unless your system or browser is horrifically outdated. In terms of social engineering, Linux is not necessarily better at preventing it than Windows. In fact, sudo in Linux will unquestioningly delete the kernel and system software or make unlimited changes to them. Windows, for better or for worse (tbh more worse than better), uses TrustedInstaller to limit access to system files. Windows 11 won’t easily let you delete or modify System32 for example, even if you’re an admin. So it’s in theory easier to do more damage to your system on Linux if you don’t know what you’re doing. But if someone is using Linux full time, they’re most likely technical enough to not be fooled into running random untrusted bash commands. The biggest thing is to be careful with those Linux terminal tutorial sites that have a “add to clipboard” button, they can put literally anything into your clipboard, including an enter key to run the script as soon as you put it in your terminal (though this may or may not be possible depending on your terminal app). Actually, they don’t even need you to use their copy button. They can just set an event listener for control-C anywhere on their site and automatically replace the clipboard content. Just double check everything you copy before running it, especially since there’s a lot of times where Linux users have to rely on obsecue tutorials hosted on untrusted websites. You also don’t really need to run untrusted installers on Linux because almost everything you need is in a properly moderated software repository, be it your native package manager, Flatpak, or Snap. Everything is signed by the authors and has a ton of eyes from the open source community on it. The only things to look out for is compiling something from GitHub, random AppImages, Elf binaries, scripts, and last but not least third party repositories that can be added as an installation source to your package manager/Flatpak/Snap. Basically, Linux gets most of its “doesn’t get malware” reputation from the same place Mac does: you rarely have to manually download and run an executable from a random website, which is the norm on Windows. Add to the fact that even when that’s needed, the Linux userbase is more technical and is more able to discern which sources are reputable and which are suspicious. Another major source of malware is pirated versions of Windows or untrusted “license activators” from the internet. This just isn’t a problem on Linux because there’s no license to activate and it’s free to begin with so there’s nothing to pirate. And again, if someone is running Linux, they’re probably technical enough to know not to run random pirated versions of paid software to begin with, helped by the fact that the vast majority of paid software is Windows only.

Komunitas lemmy.world

Zed on Linux is out!

Very first impressions since I literally just downloaded before writing this, and haven’t read the manual, I may change my mind with more experience. It’s incredibly snappy, to my eyes as fast as Helix. A lot of stuff that took me a while to figure out in VS Code was immediately obvious. How to toggle inlay hints for Rust? Parameter Icon > Inlay Hints (with the keyboard shortcut there for easy toggling). Interactive is generally intuitive because it seems pretty permissive. Tab vs Enter to autocomplete? Either! ctrl-shift-Z vs ctrl-Y to redo? Same thing! After being so used to Helix I often reach for keybinds that don’t exist. I might have to learn Vim keybinds because I’m definitely going to keep trying Zed. Not sure how I feel about what seems to be an inline discord-like chat/voice-call feature. Going to check out if there’s git integration, because I couldn’t easily find it.