Komunitas
feddit.org
E: apparently it needs to be said that I am not suggesting you switch to Linux on your phone today; just that development needs to accelerate. Please don’t be one of the 34 people that replied to tell me Linux is not ready. Android has always been a fairly open platform, especially if you were deliberate about getting it that way, but we’ve seen in recent months an extremely rapid devolution of the Android ecosystem: The closing of development of an increasing number of components in AOSP. Samsung, Xiaomi and OnePlus have removed the option of bootloader unlocking on all of their devices. I suspect Google is not far behind. Google implementing Play Integrity API and encouraging developers to implement it, which prevents apps from the Google Play Store from being downloaded without a system-wide OS-level account login. Notably the EU’s own identity verification wallet requires this, in stark contrast to their own laws and policies, despite the protest of hundreds on Github. And finally, the mandatory implementation of developer verification across Android systems. Yes, if you’re running a 3rd-party OS like GOS you won’t be directly affected by this, but it will impact 99.9% of devices, and I foresee many open source developers just opting out of developing apps for Android entirely as a result. We’ve already seen SyncThing simply discontinue development for this reason, citing issues with Google Play Store. They’ve also repeatedly denied updates for NextCloud with no explanation, only restoring it after mass outcry. And we’ve already seen Google targeting any software intended to circumvent ads, labeling them in the system as “dangerous” and “untrusted”. This will most certainly carry into their new “verification” system. Google once competed with Apple for customers. But in a world where Google walks away from the biggest antitrust trial since 1998 with yet another slap on the wrist, competition is dead, and Google is taking notes from Apple about what they can legally get away with. Android as we know it is dead. And/or will be dead very soon. We need an open replacement. E2: thank you to everyone stopping by from Hacker News, Reddit, etc. to check out the threadiverse. I hope you’ll stick around for a while. Check out https://phtn.app/ and the Voyager and Blorp apps for a nicer UI. Fuck Spez!
Komunitas
lemmy.world
I heard about it, downloaded it, tried it. Then i googled for other coupons and found a better one. Deleted Honey right away for being shit. Im surprised so many people would just trust the app immediately and not try to see if there were better coupons.
Komunitas
feddit.de
It just… lacks features? I couldn’t use ZFS or Btrfs, FDE requires third-party software (veracrypt) and lots of other things that I see as standard system utilities (think ssh, git etc.) are not available on a fresh install. And then you’re supposed to download and install .exe files from the internet? Since microsoft controls what goes in the windows store, that could provide the same experience as your distro’s repositories. But again, most things you want aren’t there, and you can’t even trust the things that are there. For some reason, a billion dollar company cannot curate a software repository of the same quality as the ones maintained by unpaid volunteers in the Linux world. So yeah, I think it’s just not there yet. Maybe in a few years windows will be a viable alternative for desktop systems.
Komunitas
lemmy.world
Hi all! I’ve posted a couple times in the past about Pinepods. The ultimate self-hosted podcast server that syncs times between devices, archives, plays, and manages your podcasts. I’ve just finished up the very first builds of the official Pinepods mobile apps for both Android and iOS and they are now in testing phases for both the Google Play Store and the App Store respectively. However, I’m at a small stop gap, and I need help from the selfhosted community. I need some people willing to sign up for the testing program and download the app in order to get them posted officially to the store fronts. You don’t even really have to use it (though I would really appreciate it if you gave it a try as Pinepods has really made strides in becoming the best it can be as one of the most feature rich Podcast platforms around) I just need people to join the programs and install the apps in order to get on the app stores. Oh and yes, before you ask, Android Auto and CarPlay support are coming in the next update. Not here yet, but very soon. I’ve done quite a bit of work to make sign ups for the beta program as easy as possible, you can simply do it here. Simply choose your platform of choice and you’ll get an email with a link. And as an aside, Pinepods 0.8.0 is days away from fully releasing and has had it’s api FULLY rebuilt in rust. The entire app is now 100% rust and is blazingly fast because of it. If you do want to test out Pinepods, I would highly recommend pulling down the :nightly docker tag rather than latest for the time being. It’s really close to bug free at this point. I could say more about Pinepods itself but I’ll let the site speak for itself, it got an overhaul in preparation for 0.8.0 and can really sell it. I’ve even just rolled out an official TUI based client called Firewood. I’m really trying to make the best self-hosted Podcast platform that does it all. GitHub: https://github.com/madeofpendletonwool/Pinepods Official site: https://pinepods.online/ And the beta testing link once more: https://www.pinepods.online/internal-testing Feel free to reach out via Github Issues, the feedback page on the site, or messages if you run into any problems!
Komunitas
geddit.social
How do you know if a closed source application is stealing your data? With open source, you can learn to read it, or talk to a community of people who know how to read it. If even just 1 in 500 people who downloads the software looks at the source, there are external eyes on it. Whereas with closed source, no one but the creator is looking. Biggest thing is to still only install software you trust.
Komunitas
sopuli.xyz
Discoverability is one issue and trust for longevity is another. No bigger distribution is going to rely their official download links on an individual home lab which can disappear overnight. Also I guess there’s also guestion if images are provided as is without adding/removing your own ‘extensions’, but that’s what cheksums are for. And this is obviously on a general level, I’m not trying to suggest that xana is not trustworthy :) But torrent seeding is a helpful thing for community, and easy/safe to set up.
Komunitas
local106.com
IMHO it’s cyclical. Computers started out client server because of limited computing capacity Then everybody got a PC and for a while, physical media were faster than downloads Then we got oodles of bandwidth, so servers seemed practical again Now servers are taking advantage of the trust we’ve placed in them Next, we’ll all enjoy a brief P2P revolution. Hooray! After that, homomorphic encryption will make servers seem appealing again Even farther into the future, the attacks against that encryption will no longer be tolerable It will be decades more before humanity accepts the teachings of Richard Stallman.
Komunitas
beehaw.org
I’m not going to weigh in on the specifics of Flatpak vs AppImage, because I don’t know enough about the particulars. However, I think the “user choice” argument is often deployed in situations where it probably shouldn’t be. For instance, in this case, it’s not the user’s choice at all, but a developer’s choice, as a normal user would not be packaging their own software. They would be merely downloading one of a number of options of precompiled packages. And this is the thrust of the argument. If we take the GitHub rant at face value, some developers seem to be distributing software using AppImage, to the exclusion of other options. And then listing ways in which this is problematic. I, for one, would be rather annoyed if my only option were either AppImage or Flatpak, as I typically prefer use software packaged for my package manager. That is user choice, give me the option to package it myself; hopefully it’s already been done for me. There are some good things to be said about trust and verification, and I’m generally receptive to those arguments way more than “user choice.”
Komunitas
lemmy.dbzer0.com
I recently downloaded this file from Audioz (I didn’t run the exe, just extracted the rar.) Check out the comments, many people have run it through sandbox environments like any.run or hybrid analysis and gotten iffy results: https://www.virustotal.com/gui/file/d1fdb98c8cd8be48bed316bc6740c09922b24fe54134a21f9c6935798800e0ce/community It looks like there are quite a few analysis services besides virustotal that are marking the file as malicious. https://hybrid-analysis.com/sample/d1fdb98c8cd8be48bed316bc6740c09922b24fe54134a21f9c6935798800e0ce https://bazaar.abuse.ch/sample/d1fdb98c8cd8be48bed316bc6740c09922b24fe54134a21f9c6935798800e0ce This is a popular upload on Audioz and is also listed directly on Team VR’s website, so what gives? I thought Team VR was considered safe. Maybe someone experienced needs to look at their stuff a little more closely?
Komunitas
ibbit.at
Something which may well unite Hackaday readers is the experience of being “The computer person” among your family or friends. You’ll know how it goes, when you go home for Christmas, stay with the in-laws, or go to see some friend from way back, you end up fixing their printer connection or something. You know that they would bridle somewhat if you asked them to do whatever it is they do for a living as a free service for you, but hey, that’s the penalty for working in technology. Bad Laws Just Make People Avoid Them There’s a new one that’s happened to me and no doubt other technically-minded Brits over the last few weeks: I’m being asked to recommend, and sometimes install, a VPN service. The British government recently introduced the Online Safety Act, which is imposing ID-backed age verification for British internet users when they access a large range of popular websites. The intent is to regulate access to pornography, but the net has been spread so wide that many essential or confidential services are being caught up in it. To be a British Internet user is to have your government peering over your shoulder, and while nobody’s on the side of online abusers, understandably a lot of my compatriots want no part of it. We’re in the odd position of having 4Chan and the right-wing Reform Party alongside Wikipedia among those at the front line on the matter. What a time to be alive. VPN applications have shot to the top of all British app download charts, prompting the government to flirt with deny the idea of banning them, but as you might imagine therein lies a problem. Aside from the prospect of dodgy VPN apps to trap the unwary, the average Joe has no idea how to choose from the plethora of offerings. A YouTuber being paid to shill “that” VPN service is as close of they’ve ever come to a VPN, so they are simply unequipped to make a sound judgement when it comes to trusting a service with their web traffic. They have no hope of rolling their own VPN; setting up WireGuard and still further having a friend elsewhere in the world prepared to act as their endpoint are impractical. It therefore lies upon us, their tech-savvy friends, to lead them through this maze. Which brings me to the point of this piece; are we even up to the job ourselves? I’ve been telling my friends to use ProtonVPN because their past behaviour means I trust Proton more than I do some of the other well-known players, but is my semi-informed opinion on the nose here? Even I need help! Today Brits, Tomorrow The Rest Of You At the moment it’s Brits who are scrambling for VPNs, but it seems very likely that with the EU yet again flirting with their ChatControl snooping law, and an American government whose actions are at best unpredictable, soon enough many of the rest of you will too. The question is then: where do we send the non-technical people, and how good are the offerings? A side-by-side review of VPNs has been done to death by many other sites, so there’s little point in repeating. Instead let’s talk to some experts. You lot, or at least those among the Hackaday readership who know their stuff when it comes to VPNs. What do you recommend for your friends and family? Header image: Nenad Stojkovic, CC BY 2.0. From Blog – Hackaday via this RSS feed
Komunitas
hexbear.net
cross-posted from: https://ibbit.at/post/42569 At this summer’s HOPE conference, Joshua Aaron spoke about ICEBlock, his iPhone app that allows users to anonymously report ICE sightings within a 5 mile radius, and to get notifications when others report ICE sightings near them. You can see the full talk, and the lively/infuriating Q&A, here, starting at 6:12:10. Thanks to repression from the highest levels of the Trump administration, his app has gone viral and garnered over a million downloads from the App Store. Karoline Leavitt called it “an incitement of further violence against our ICE officers.” Tom Homan said, “DOJ needs to look at this and see if they’re crossing that line.” Kristi Noem called the app “obstruction of justice.” Pam Bondi announced “we are looking at it, we are looking at him, and he better watch out, because that’s not a protected speech.” (Notifying people about ICE sightings is protected speech, no matter what the fascist Attorney General says.) Joshua and his family have been receiving threats. But unfortunately, despite the app’s goal of protecting people from ICE, its viral success, and the state repression against it, ICEBlock has serious issues: Most importantly, it wasn’t developed with input from people who actually defend immigrants from deportation. As a result, it doesn’t provide people with what they need to stay safe. Because ICE sightings in the app aren’t verified in any way, it’s likely that most reports in the app aren’t actually ICE, even if they’re posted by people who mean well – as I describe below, the vast majority of ICE reports are false positives. And judging by the App Store reviews, it’s clear that not everyone means well. One review says: “This is a great app for safety information. Unfortunately MAGA is now posting false information on there and making racist comments in the comment section.” Joshua makes strong claims about the security and privacy of his app without backing any of them up with technical details. Many of his claims are false. He also chose to target only iOS, and not Android, because of a misunderstanding about how Android push notifications work. And even worse, during the Q&A, he made it clear that he didn’t understand terms like “warrant canary,” “reverse engineering,” or “security through obscurity,” which doesn’t inspire confidence. Privacy promises without the evidence When I first heard about ICEBlock, I liked the idea, but I – and others in various group chats I’m part of – were skeptical. Joshua promises that ICE reports are “completely anonymous,” that the app doesn’t store any personal data, and that it’s “impossible to trace reports back to individual users.” These are bold claims that he hasn’t backed up with evidence. Unlike reputable privacy tools, ICEBlock isn’t open source (in the talk, he explicitly rejected the idea of open sourcing it or allowing the security community to help him improve it), and Joshua hasn’t published a threat model or technical documentation explaining how his app keeps these promises. My friend Cooper Quintin, a security researcher at EFF, was also skeptical of ICEBlock, and so he reverse engineered it, and spoke to 404 Media about his findings. He largely confirmed Joshua’s claims: The TL;DR is that I didn’t find anything suspicious, the app doesn’t talk to any third parties, and it doesn’t send your location to the developer. Neither your phone ID or iCloud account are associated with the requests the app sends to the apple cloud servers to run. (2/11) — Exploit Code Not People (@cooperq.com) 2025-07-15T18:52:15.697Z This is great, and it’s the reason that (despite his hostility towards transparency) I really do think that Joshua means well. Even if we can trust that Joshua isn’t collecting data himself, it’s difficult to discern what Apple would be able to hand over if it got subpoenaed for data related to his app. The website simply says it’s “completely anonymous,” without any caveats. But ignoring the lack of transparency, there’s an even larger problem. ICEBlock spreads unverified information, making it useless for defending immigrants Local immigrant defense groups around the country have been defending people from deportation for the last decade or more. In a training with NorCal Resist, I learned that when people post (and repost) unverified reports of ICE sightings on social media, it does more harm than good. Millions of people are living in a state of fear. From my experience working with NorCal Resist, most ICE sightings that people hear about aren’t real, even when the person reporting it believes that they are. It’s common for someone to see a bunch of dudes in uniforms, or sketchy looking vans, and assume it’s ICE, when it’s actually something else. If I had to guess, I’d say about 98% of reports are false positives. False reports encourage panic, which doesn’t help anyone. Meanwhile, what people actually need are legal observers – people to document the behavior of federal agents, and provide this evidence to their lawyers. They also need help with connecting families of kidnapped people with information and lawyers, and they need communities coming out to defend their neighbors. When I asked Joshua about this during the Q&A of his talk, he didn’t answer the question. Here’s my question and his non-answers: 0:00/4:46 1× Joshua’s non-answer to my question about false positives and user research Specifically, I asked: With my local group, they put a whole lot of energy into verifying every single report before spreading information about it. My question is, how do you know that ICEBlock isn’t just full of false positives? And have you done any user research, or worked with local immigration groups to figure out how reliable this is, how much it’s actually helping people versus causing panic? In an attempt to answer the question about user research, Joshua said, “No, we do not do any user data or metrics.” He misunderstood the question, apparently thinking that I meant collecting data from users rather than talking to humans who know more than he does and incorporating their feedback into the design of the app. He then explained what ICEBlock does to prevent malicious people from making false reports — including falsely claiming that it’s “not possible” to make tons of simultaneous fake reports (more on this below). ICEBlock doesn’t verify anything, and instead only spreads unverified rumors. To be fair, verification is a very hard problem. In my local group, we have announcement-only Signal groups full of volunteers who physically verify every single ICE sighting that’s reported to our rapid response hotline. The vast majority of reports are false positives. There might be several reports a day, but actual ICE or CBP activity is much more rare. I’ve personally gone to check out maybe 10 to 15 different ICE sightings, only one of which turned out to be actual immigration enforcement (though by the time I got to the location, ICE had already left the area). None of these false reports were malicious: they were simply scared people who saw a bunch of vehicles and people in uniforms and reported an ICE sighting, when it was actually something else. Another person in the audience asked a similar question: I’m wondering, I think someone asked earlier, if in the design of ICEBlock, or even now, are you currently working with immigrant communities to figure out what resources they need? 0:00/3:18 1× Another question about if Joshua has engaged with community groups His answer was that ICEBlock has been translated into many different languages. And that the community organizers he’s spoken with told him that ICEBlock doesn’t meet their needs. So, he decided to not worry about their feedback and do his own thing instead. If you want to support people who are actually protecting immigrants from deportation, please donate to NorCal Resist or your local community rapid response networks. What’s GPS spoofing? When Joshua explained the safeguards against abuse in the app, he claimed that it’s “not possible” to make 100 fake reports in a single morning, in part because you can only make reports within a 5 mile radius of your location. But apparently, Joshua has never heard of GPS spoofing. Even though I’m sitting at my house in California right now, here’s a screenshot I just took of the ICEBlock app from the Eiffel Tower in Paris. While I won’t go into details of the masterful hacking skills that this took, I’ll give you a hint: it’s the same technique kids use to cheat at Pokemon Go. Screenshot of ICEBlock app, with GPS location spoofed to make it think I’m in Paris Make ICEBlock open source? “Absolutely not.” Someone asked whether Joshua would be interested in collaborating with the hacker community on ICEBlock, so they could provide him with advice and help him with feature development. Joshua rejected the idea, saying that he believes that he’d need to completely trust anyone he collaborated with. “Believe me when I say I would love help. I’m supporting over a million users myself. There’s not some giant company behind this,” he said. “But it’s really really hard for me to put my trust in somebody, and share the source code, and share the access to this.” 0:00/1:49 1× Joshua explaining that he’s building ICEBlock all on his own because he can’t trust outside contributors This is, of course, not how secure software development works. The most widely trusted security and privacy tools that exist, like Signal and Tor, are open source, and they accept peer review and code contributions from the public. The thing that makes this perfectly reasonable and safe is code review. If Joshua published the ICEBlock source code, experts in the hacker community could add features or fix bugs for him, and make pull requests with their changes. He could then carefully review the changes before merging them into his codebase. He could reject whatever changes he wants. You don’t actually need to trust – or even know the identity of – hackers who help you develop software. This is a solved a problem, and Joshua seems utterly unaware of it. My friend Jen Helsby, the CTO of Freedom of the Press Foundation and a SecureDrop developer, explicitly asked if he would be open to making ICEBlock open source. Here’s the clip: 0:00/1:40 1× Joshua will not release ICEBlock as open source because he doesn’t believe in reverse engineering and thinks keeping the implementation details of his app obscure makes it more secure Jen asked: There’s a lot of secure software, that probably people in this room work on, that is developed in the open, and that is used primarily by at-risk users, including things like Tor, Signal, SecureDrop. That’s great, because it makes it easy for folks to contribute. Maybe you don’t want that, I understand that can be hard. But it also makes it easier for people to audit and gain assurance that the app is doing what you claim without having to have, you know, EFF reverse engineer it. Would you be open to making the app open source? His answer: “Absolutely not.” Why? “I don’t want anybody from the government to have their hooks in how I’m doing what I’m doing. Once you go open source, everybody has access to it. So I’m just going to keep the codebase private at this time.” He also claimed that the government can’t learn everything about how an app works by reverse engineering it, which isn’t true. I agree with Jen. His answers are very concerning. What’s security through obscurity? Another person asked specifically how concealing the details of how the app works from the government is distinguishable from security through obscurity, Joshua agreed that security through obscurity is terrible… and denied that he’s doing it? 0:00/0:37 1× Joshua falsely claiming he doesn’t do security through obscurity In case you’re not aware of this term, the first sentence of the Wikipedia article on security through obscurity has a concise definition: In security engineering, security through obscurity is the practice of concealing the details or mechanisms of a system to enhance its security. NIST’s General Guide to Server Security lists “Open Design” as a core security principle, saying that, “System security should not depend on the secrecy of the implementation or its components.” Minutes before this, Joshua had just finishing explaining that he definitely won’t open source his app because, “I don’t want anybody from the government to have their hooks in how I’m doing what I’m doing.” He’s implying that his code includes some “secret sauce” that, if it were made public, would make the app less secure, so he can’t risk letting anyone discover how it works. This is the definition of security through obscurity. My server is “HIGHLY secure,” he says to a room full of hackers Throughout the Q&A, Joshua kept referencing the security of his server. At one point, he even said that he built it himself and it’s “HIGHLY secure.” He also assured the audience, “Trust me when I tell you, I think about EVERYTHING to the Nth degree.” It took about 20 minutes of digging around to discover that the server that hosts the iceblock.app website is running on Linode and also hosts the websites of several of Joshua’s other projects, going back decades. This includes a website for his IT consulting business, his band, etc. If any one of those old websites gets hacked, it’s possible that the hacker could more easily access ICEBlock data that’s stored on the same server. Without providing more details, I also discovered that his server is running outdated software with known vulnerabilities. What’s a warrant canary? At one point, a lawyer asked some excellent legal questions: I’m curious if ICEBlock either currently or has intentions to implement something like a warrant canary or other method. And more generally, whether you have received anything like search warrants, or All Writs Act requests, or anything else. Things like more intrusive means of obtaining information from ICEBlock. Things like requests for live interception, which would be authorized under a search warrant. And if you have a response plan in place already for those. 0:00/3:56 1× A lawyer asking Joshua about warrant canaries and data requests If you’re not familiar with warrant canaries, these are basically public notices that say, “I’ve never been forced to give up user data.” If the notice ever gets taken down, the public can infer that the service was in fact forced to hand over user data. Joshua said, “No on the warrant canary, because it would probably require some sort of user data to do that.” He seemed to think that a warrant canary would be a new feature in the app (that’s uh, not what a warrant canary is), and he completely ignored the legal questions, instead opting to talk about why it’s important to keep the app design simple. When the lawyer asked again what he would do if the government tried to compel him to spy on his users, Joshua simply said, “I’d just tell them to go fuck themselves.” It’s a good answer, but it’s also naive. Government requests can include gag orders, preventing him from telling anyone that he has received them, and punishment for disobeying them can include threats of jail time. It’s good to plan ahead. Luckily, he has EFF and ACLU offering him legal support, in case he ever actually has to face something like this. It’s not too late Despite everything, I do think that Joshua’s heart is in the right place and that he genuinely wants to help people. He’s sticking his neck out to fight fascism, and the far right is harassing him and his family for it. This is why I, and several other hackers who attended his HOPE talk, spent so much time and energy (both during his talk and in the days after it) trying to encourage him to open things up so that ICEBlock, and its million-strong userbase, might yet become a helpful tool in defending immigrants against Trump’s fascist plans. He has rejected our offers. It’s possible for him to turn things around, but sadly, I’m not holding my breath. From micahflee via this RSS feed
Komunitas
ibbit.at
At this summer’s HOPE conference, Joshua Aaron spoke about ICEBlock, his iPhone app that allows users to anonymously report ICE sightings within a 5 mile radius, and to get notifications when others report ICE sightings near them. You can see the full talk, and the lively/infuriating Q&A, here, starting at 6:12:10. Thanks to repression from the highest levels of the Trump administration, his app has gone viral and garnered over a million downloads from the App Store. Karoline Leavitt called it “an incitement of further violence against our ICE officers.” Tom Homan said, “DOJ needs to look at this and see if they’re crossing that line.” Kristi Noem called the app “obstruction of justice.” Pam Bondi announced “we are looking at it, we are looking at him, and he better watch out, because that’s not a protected speech.” (Notifying people about ICE sightings is protected speech, no matter what the fascist Attorney General says.) Joshua and his family have been receiving threats. But unfortunately, despite the app’s goal of protecting people from ICE, its viral success, and the state repression against it, ICEBlock has serious issues: Most importantly, it wasn’t developed with input from people who actually defend immigrants from deportation. As a result, it doesn’t provide people with what they need to stay safe. Because ICE sightings in the app aren’t verified in any way, it’s likely that most reports in the app aren’t actually ICE, even if they’re posted by people who mean well – as I describe below, the vast majority of ICE reports are false positives. And judging by the App Store reviews, it’s clear that not everyone means well. One review says: “This is a great app for safety information. Unfortunately MAGA is now posting false information on there and making racist comments in the comment section.” Joshua makes strong claims about the security and privacy of his app without backing any of them up with technical details. Many of his claims are false. He also chose to target only iOS, and not Android, because of a misunderstanding about how Android push notifications work. And even worse, during the Q&A, he made it clear that he didn’t understand terms like “warrant canary,” “reverse engineering,” or “security through obscurity,” which doesn’t inspire confidence. Privacy promises without the evidence When I first heard about ICEBlock, I liked the idea, but I – and others in various group chats I’m part of – were skeptical. Joshua promises that ICE reports are “completely anonymous,” that the app doesn’t store any personal data, and that it’s “impossible to trace reports back to individual users.” These are bold claims that he hasn’t backed up with evidence. Unlike reputable privacy tools, ICEBlock isn’t open source (in the talk, he explicitly rejected the idea of open sourcing it or allowing the security community to help him improve it), and Joshua hasn’t published a threat model or technical documentation explaining how his app keeps these promises. My friend Cooper Quintin, a security researcher at EFF, was also skeptical of ICEBlock, and so he reverse engineered it, and spoke to 404 Media about his findings. He largely confirmed Joshua’s claims: The TL;DR is that I didn’t find anything suspicious, the app doesn’t talk to any third parties, and it doesn’t send your location to the developer. Neither your phone ID or iCloud account are associated with the requests the app sends to the apple cloud servers to run. (2/11) — Exploit Code Not People (@cooperq.com) 2025-07-15T18:52:15.697Z This is great, and it’s the reason that (despite his hostility towards transparency) I really do think that Joshua means well. Even if we can trust that Joshua isn’t collecting data himself, it’s difficult to discern what Apple would be able to hand over if it got subpoenaed for data related to his app. The website simply says it’s “completely anonymous,” without any caveats. But ignoring the lack of transparency, there’s an even larger problem. ICEBlock spreads unverified information, making it useless for defending immigrants Local immigrant defense groups around the country have been defending people from deportation for the last decade or more. In a training with NorCal Resist, I learned that when people post (and repost) unverified reports of ICE sightings on social media, it does more harm than good. Millions of people are living in a state of fear. From my experience working with NorCal Resist, most ICE sightings that people hear about aren’t real, even when the person reporting it believes that they are. It’s common for someone to see a bunch of dudes in uniforms, or sketchy looking vans, and assume it’s ICE, when it’s actually something else. If I had to guess, I’d say about 98% of reports are false positives. False reports encourage panic, which doesn’t help anyone. Meanwhile, what people actually need are legal observers – people to document the behavior of federal agents, and provide this evidence to their lawyers. They also need help with connecting families of kidnapped people with information and lawyers, and they need communities coming out to defend their neighbors. When I asked Joshua about this during the Q&A of his talk, he didn’t answer the question. Here’s my question and his non-answers: 0:00/4:46 1× Joshua’s non-answer to my question about false positives and user research Specifically, I asked: With my local group, they put a whole lot of energy into verifying every single report before spreading information about it. My question is, how do you know that ICEBlock isn’t just full of false positives? And have you done any user research, or worked with local immigration groups to figure out how reliable this is, how much it’s actually helping people versus causing panic? In an attempt to answer the question about user research, Joshua said, “No, we do not do any user data or metrics.” He misunderstood the question, apparently thinking that I meant collecting data from users rather than talking to humans who know more than he does and incorporating their feedback into the design of the app. He then explained what ICEBlock does to prevent malicious people from making false reports — including falsely claiming that it’s “not possible” to make tons of simultaneous fake reports (more on this below). ICEBlock doesn’t verify anything, and instead only spreads unverified rumors. To be fair, verification is a very hard problem. In my local group, we have announcement-only Signal groups full of volunteers who physically verify every single ICE sighting that’s reported to our rapid response hotline. The vast majority of reports are false positives. There might be several reports a day, but actual ICE or CBP activity is much more rare. I’ve personally gone to check out maybe 10 to 15 different ICE sightings, only one of which turned out to be actual immigration enforcement (though by the time I got to the location, ICE had already left the area). None of these false reports were malicious: they were simply scared people who saw a bunch of vehicles and people in uniforms and reported an ICE sighting, when it was actually something else. Another person in the audience asked a similar question: I’m wondering, I think someone asked earlier, if in the design of ICEBlock, or even now, are you currently working with immigrant communities to figure out what resources they need? 0:00/3:18 1× Another question about if Joshua has engaged with community groups His answer was that ICEBlock has been translated into many different languages. And that the community organizers he’s spoken with told him that ICEBlock doesn’t meet their needs. So, he decided to not worry about their feedback and do his own thing instead. If you want to support people who are actually protecting immigrants from deportation, please donate to NorCal Resist or your local community rapid response networks. What’s GPS spoofing? When Joshua explained the safeguards against abuse in the app, he claimed that it’s “not possible” to make 100 fake reports in a single morning, in part because you can only make reports within a 5 mile radius of your location. But apparently, Joshua has never heard of GPS spoofing. Even though I’m sitting at my house in California right now, here’s a screenshot I just took of the ICEBlock app from the Eiffel Tower in Paris. While I won’t go into details of the masterful hacking skills that this took, I’ll give you a hint: it’s the same technique kids use to cheat at Pokemon Go. Screenshot of ICEBlock app, with GPS location spoofed to make it think I’m in Paris Make ICEBlock open source? “Absolutely not.” Someone asked whether Joshua would be interested in collaborating with the hacker community on ICEBlock, so they could provide him with advice and help him with feature development. Joshua rejected the idea, saying that he believes that he’d need to completely trust anyone he collaborated with. “Believe me when I say I would love help. I’m supporting over a million users myself. There’s not some giant company behind this,” he said. “But it’s really really hard for me to put my trust in somebody, and share the source code, and share the access to this.” 0:00/1:49 1× Joshua explaining that he’s building ICEBlock all on his own because he can’t trust outside contributors This is, of course, not how secure software development works. The most widely trusted security and privacy tools that exist, like Signal and Tor, are open source, and they accept peer review and code contributions from the public. The thing that makes this perfectly reasonable and safe is code review. If Joshua published the ICEBlock source code, experts in the hacker community could add features or fix bugs for him, and make pull requests with their changes. He could then carefully review the changes before merging them into his codebase. He could reject whatever changes he wants. You don’t actually need to trust – or even know the identity of – hackers who help you develop software. This is a solved a problem, and Joshua seems utterly unaware of it. My friend Jen Helsby, the CTO of Freedom of the Press Foundation and a SecureDrop developer, explicitly asked if he would be open to making ICEBlock open source. Here’s the clip: 0:00/1:40 1× Joshua will not release ICEBlock as open source because he doesn’t believe in reverse engineering and thinks keeping the implementation details of his app obscure makes it more secure Jen asked: There’s a lot of secure software, that probably people in this room work on, that is developed in the open, and that is used primarily by at-risk users, including things like Tor, Signal, SecureDrop. That’s great, because it makes it easy for folks to contribute. Maybe you don’t want that, I understand that can be hard. But it also makes it easier for people to audit and gain assurance that the app is doing what you claim without having to have, you know, EFF reverse engineer it. Would you be open to making the app open source? His answer: “Absolutely not.” Why? “I don’t want anybody from the government to have their hooks in how I’m doing what I’m doing. Once you go open source, everybody has access to it. So I’m just going to keep the codebase private at this time.” He also claimed that the government can’t learn everything about how an app works by reverse engineering it, which isn’t true. I agree with Jen. His answers are very concerning. What’s security through obscurity? Another person asked specifically how concealing the details of how the app works from the government is distinguishable from security through obscurity, Joshua agreed that security through obscurity is terrible… and denied that he’s doing it? 0:00/0:37 1× Joshua falsely claiming he doesn’t do security through obscurity In case you’re not aware of this term, the first sentence of the Wikipedia article on security through obscurity has a concise definition: In security engineering, security through obscurity is the practice of concealing the details or mechanisms of a system to enhance its security. NIST’s General Guide to Server Security lists “Open Design” as a core security principle, saying that, “System security should not depend on the secrecy of the implementation or its components.” Minutes before this, Joshua had just finishing explaining that he definitely won’t open source his app because, “I don’t want anybody from the government to have their hooks in how I’m doing what I’m doing.” He’s implying that his code includes some “secret sauce” that, if it were made public, would make the app less secure, so he can’t risk letting anyone discover how it works. This is the definition of security through obscurity. My server is “HIGHLY secure,” he says to a room full of hackers Throughout the Q&A, Joshua kept referencing the security of his server. At one point, he even said that he built it himself and it’s “HIGHLY secure.” He also assured the audience, “Trust me when I tell you, I think about EVERYTHING to the Nth degree.” It took about 20 minutes of digging around to discover that the server that hosts the iceblock.app website is running on Linode and also hosts the websites of several of Joshua’s other projects, going back decades. This includes a website for his IT consulting business, his band, etc. If any one of those old websites gets hacked, it’s possible that the hacker could more easily access ICEBlock data that’s stored on the same server. Without providing more details, I also discovered that his server is running outdated software with known vulnerabilities. What’s a warrant canary? At one point, a lawyer asked some excellent legal questions: I’m curious if ICEBlock either currently or has intentions to implement something like a warrant canary or other method. And more generally, whether you have received anything like search warrants, or All Writs Act requests, or anything else. Things like more intrusive means of obtaining information from ICEBlock. Things like requests for live interception, which would be authorized under a search warrant. And if you have a response plan in place already for those. 0:00/3:56 1× A lawyer asking Joshua about warrant canaries and data requests If you’re not familiar with warrant canaries, these are basically public notices that say, “I’ve never been forced to give up user data.” If the notice ever gets taken down, the public can infer that the service was in fact forced to hand over user data. Joshua said, “No on the warrant canary, because it would probably require some sort of user data to do that.” He seemed to think that a warrant canary would be a new feature in the app (that’s uh, not what a warrant canary is), and he completely ignored the legal questions, instead opting to talk about why it’s important to keep the app design simple. When the lawyer asked again what he would do if the government tried to compel him to spy on his users, Joshua simply said, “I’d just tell them to go fuck themselves.” It’s a good answer, but it’s also naive. Government requests can include gag orders, preventing him from telling anyone that he has received them, and punishment for disobeying them can include threats of jail time. It’s good to plan ahead. Luckily, he has EFF and ACLU offering him legal support, in case he ever actually has to face something like this. It’s not too late Despite everything, I do think that Joshua’s heart is in the right place and that he genuinely wants to help people. He’s sticking his neck out to fight fascism, and the far right is harassing him and his family for it. This is why I, and several other hackers who attended his HOPE talk, spent so much time and energy (both during his talk and in the days after it) trying to encourage him to open things up so that ICEBlock, and its million-strong userbase, might yet become a helpful tool in defending immigrants against Trump’s fascist plans. He has rejected our offers. It’s possible for him to turn things around, but sadly, I’m not holding my breath. From micahflee via this RSS feed
Komunitas
ibbit.at
Photograph Source: CGP Grey – CC BY 2.0 In the United States, diquat is used everywhere—from the potato fields of the Pacific Northwest to the watersheds of New England and the weeds wilting along suburban sidewalks. Approved by the Environmental Protection Agency (EPA), this fast-acting herbicide remains a go-to chemical for farmers and home gardeners. A growing body of scientific research, however, has highlighted the harmful effects resulting from its widespread use. Studies have linked diquat to organ damage, reproductive harm, and ecological destruction—from fish and birds to the microbes that keep the soil alive. These concerning facts have led the European Union, the United Kingdom, and several other countries to ban the chemical outright. So why is it still being sprayed so freely in the U.S.? Diquat is widely used across the U.S. as a herbicide and desiccant, particularly for drying out crops like potatoes, soybeans, and cotton before harvest. It is also applied to manage invasive aquatic plants in lakes, rivers, ponds, and canals, as well as to control broadleaf weeds in orchards and vineyards, and for general weed control. Despite its known toxicity, diquat is used in lawn care products sold at major retail outlets across the U.S., putting potent toxins within easy reach of unsuspecting consumers. A Toxic Divide: Banned Abroad, Sold at Home The European Commission decided to ban diquat in 2019 after the European Food Safety Authority concluded that it posed high risks to bystanders, residents, and birds and did not meet the required safety criteria. Despite the serious concerns raised about the use of diquat by international reviews, including worker exposure levels exceeding acceptable levels even with protective gear, the EPA has not initiated any comparable reevaluation of diquat use in the United States since 2002. Diquat’s ubiquity in the U.S. (it was first approved by the EPA in 1986) reflects a complex web of regulatory gaps, industry influence, and uneven global standards. The herbicide continues to be marketed and exported by some of the very nations that now refuse to use it themselves. Moreover, its toxic legacy—ranging from sickened farmworkers in Latin America to the quiet unraveling of soil and aquatic ecosystems—exposes the “hypocrisy” of governments and large corporations who continue to support the trade and use of this deadly chemical in our food systems. It also shows how little most consumers know about the chemicals used not just on farms, but also in their backyards. “Other countries have banned diquat, but in the U.S., we’re still fighting the fights that Europe won 20 years ago,” Nathan Donley, environmental health science director for the Center for Biological Diversity, told the Guardian in 2025. “It hasn’t gotten to the radar of most groups, and that really says a lot about the sad and sorry state of pesticides in the U.S.” As regulatory gaps widen, diquat’s story highlights uncomfortable truths about accountability, transparency, and who ultimately bears the cost of chemical-intensive agriculture and lawn care. Amid growing concerns over its long-term impacts, diquat is an example of how chemical safety standards can diverge sharply across borders, often with little consumer awareness. The Dangerous Alternative to Glyphosate In the wake of growing controversy surrounding glyphosate—the active ingredient in Monsanto’s (now Bayer’s) Roundup—being a “public health hazard,” diquat has increasingly emerged as a substitute herbicide, both in agricultural settings and consumer lawn products. In response to multiple lawsuits and public concern over glyphosate’s alleged links to cancer, Bayer announced in 2023 that it would begin reformulating certain Roundup products for the U.S. market. In place of glyphosate, some new formulations now feature alternative active ingredients, including diquat dibromide. In 2024, the nonprofit Friends of the Earth (FOE) published the report “New Roundup, New Risks,” to evaluate the new formulations currently being sold in Lowe’s and Home Depot in the United States. The FOE analysis found diquat overall to be “200 times more chronically toxic” than glyphosate in terms of chronic exposure. FOE identified eight Roundup products in which Bayer has replaced glyphosate with combinations of four different chemicals, including diquat dibromide, fluazifop-P-butyl, triclopyr, and imazapic. “All four chemicals pose greater risk of long-term and/or reproductive health problems than glyphosate, based on the EPA’s evaluation of safety studies,” according to FOE’s analysis, which noted “the new Roundup formulations are 45 times more toxic to human health, on average, following chronic, long-term exposure.” “From a human health perspective, this stuff is quite a bit nastier than glyphosate, so we’re seeing a regrettable substitution, and the ineffective regulatory structure is allowing it,” said Donley. Diquat-based herbicides are sold under several well-known brand names in the U.S., including Reglone, Reward, and Tribune. Reglone, originally developed by Imperial Chemical Industries and now marketed by Syngenta, is primarily used as a crop desiccant. In aquatic and turf management, Reward and its generic counterpart Tribune (both containing diquat dibromide) are commonly used to control invasive pond and lake weeds. Health Risks of Exposure to Diquat Long-term or repeated low-level exposure to diquat has been linked to serious health issues, including organ damage. It is also thought to be a neurotoxin and carcinogen and has been linked to Parkinson’s disease. A May 2025 study published in Frontiers in Pharmacology found that diquat can damage the gut barrier, which plays a critical role in immune function and nutrient absorption. Animal studies have raised concerns about potential neurological impacts, with some evidence suggesting oxidative stress and damage to brain cells similar to that seen in paraquat herbicide exposure—although this area requires further study. Research also points to reproductive toxicity, including harm to sperm quality and fetal development in mice. As a bipyridyl compound, diquat shares structural and functional similarities with paraquat, a highly toxic chemical first produced for commercial purposes in 1961. Since Brazil banned paraquat in 2020, diquat use surged by 1,600 percent between 2019 and 2022 as a replacement, leading to increased exposure among agricultural workers. According to a 2024 article in Greenpeace-operated publication Unearthed, reports have surfaced of “acute pesticide poisoning,” including symptoms of blurry vision, numbing sensation, and temporary paralysis. While studying the effects of diquat on farmworkers, EU safety officials set up a “modeled scenario” using tractor-mounted equipment and found that “worker exposure would exceed the maximum acceptable level by more than 4,000 percent—even if the farmworker was wearing personal protective equipment (PPE),” the Unearthed article stated. Exposure to high doses of diquat can lead to a rapid onset of severe symptoms, according to scientific research. “While laboratory experimentation has suggested that diquat is not directly neurotoxic, there have been relatively consistent pathologic brain changes noted in reported fatal cases of diquat poisoning. These consist of brain stem infarction,” according to the EPA. The Long-Term Ecological Damage Diquat’s ecological footprint extends beyond its intended target, posing harms to soil health, aquatic ecosystems, and wildlife. The mobility and stability of the herbicide can vary significantly depending on the environmental context, with rapid removal seen in some settings and persistence under others. “In soil, diquat is easily adsorbed onto soil particles, resulting in low mobility and slow degradation, primarily relying on microbial and chemical processes for breakdown,” states the Frontiers in Pharmacology study. However, noting that while its “degradation rate is relatively fast, the degradation products may pose secondary toxicity to aquatic organisms, long-term threats to organisms and ecosystems in the environment.” Other research suggests that acute diquat exposure can result in toxicity, and its presence in waterbodies can lead to it being “accumulated in aquatic organisms,” becoming a high burden to them. “As an aquatic herbicide… diquat induced potential risks to non-target aquatic organisms are considerable,” stated a 2024 study in Scientific Reports, adding the need for stringent policymaking for the use of such chemicals. Another 2010 study published in the Philosophical Transactions of the Royal Society B studied the effect of diquat on freshwater snails. It concluded that even “low diquat concentrations… may induce significant adverse effects on hatching rate, embryonic stage duration, juvenile mortality rate and age at maturity in the freshwater snail L. stagnalis.” Exporting Risk: How Banned Chemicals Keep Circulating Diquat’s continued use is driven in part by powerful industry actors and uneven global regulations. Chemical manufacturers—most notably Syngenta, one of the world’s largest agrochemical firms—play a central role in the worldwide production, marketing, and continued use of diquat. While Syngenta ceased selling diquat in the European Union following the 2019 ban, the company continues to export the chemical to countries where regulations are less stringent, according to a 2018 article in Politico, which noted that investigations have revealed that Syngenta lobbied against tighter pesticide regulations in Europe before the ban. Moreover, while diquat is banned in Switzerland, Syngenta’s headquarters, this has not stopped the company from selling its product to other poor countries. “Although it was banned in the EU… diquat remains a top export. In 2023, Syngenta exported over 8,500 tons of banned pesticides from the UK, with diquat-based products making up the majority,” pointed out a May 2025 article by the Slow Food Foundation. This dual standard underscores a broader trend in the agrochemical industry, where companies shift toxic products away from high-regulation markets while maintaining global profit streams, raising ethical questions about environmental justice and chemical safety in lower-income countries. A 2020 investigation by Unearthed and Public Eye, a Swiss nonprofit, revealed the “abhorrent’ trade in pesticides” by Europe and the UK to poor countries, noting, “Loopholes in European law mean chemical companies like Bayer and Syngenta can continue making pesticides for export long after they have been banned from use in the EU to protect the environment or the health of its citizens.” Campaigners in the importing countries have highlighted this “double standard,” “which placed a lower value on lives and ecosystems in poorer countries,” according to the Unearthed investigation report. Meanwhile, a 2024 investigation by Unearthed and Public Eye revealed the continuation of these exports to poor countries. A Syngenta spokesperson justified the company’s actions by saying that agricultural needs differed around the world and the “use of agrochemical products is based on assessment by national governments of the risks and the benefits for use in their own country.” “In some instances, Syngenta’s UK manufacturing facilities provide products no longer available or needed in a UK domestic context but deemed required for agronomic and agricultural reasons by farmers and regulators in the importing country,” added the spokesperson. An article published by Pesticide Action Network Europe illustrates the irony: Food grown with EU-banned pesticides frequently finds its way back to European grocery stores. In 2022, 69 banned active substances were detected in food sold in the EU—especially in imported tea, coffee, and spices. In effect, Europeans are consuming pesticides that are banned from use on the farms of their home countries. Chemical Control: Profits, Policy, and the Public Good The regulation of herbicides like diquat varies widely across the globe, shaped not only by scientific evidence but also by political and economic forces. In regions such as the European Union and the United Kingdom, bans are often implemented when regulatory agencies determine that the health and environmental risks of a chemical outweigh its benefits—decisions typically informed by the precautionary principle. In contrast, countries like the United States allow continued use of these herbicides based on older risk assessments or differing thresholds for acceptable exposure, especially under pressure from agrochemical industry lobbyists. “As a general rule… it is express U.S. policy to reject the precautionary principle in favor of so-called ‘risk-based’ regulation,” wrote Sharon Anglin Treat in a 2020 article for the Institute for Agriculture and Trade Policy, adding, “U.S. trade officials and multinational chemical and agri-food corporations often employ the language of ‘science’ to create a false choice to deny the potential for harm caused by lax U.S. regulation in the absence of the precautionary approach.” In an article on their website, the Pesticide Action and Agroecology Network explains that corporations and trade associations frequently influence regulatory decisions by funding research, challenging proposed restrictions, and lobbying policymakers. A particularly troubling consequence of this uneven landscape is the practice of “double standards” in pesticide exports. Trade agreements and intellectual-property protections further complicate efforts to align global policy, often prioritizing commercial interests over public health. Ultimately, this regulatory patchwork underscores the tension between the drive for agricultural productivity and the need to protect human and ecosystem health. Toward a Safer Future: Rethinking Weed Control Growing recognition of the trade-offs inherent in current regulatory and agricultural systems is prompting a shift in how weed control is approached—one that prioritizes safety, sustainability, and long-term resilience over short-term chemical convenience. Farmers and advocates are increasingly looking to safer and more sustainable practices as alternatives to diquat. Integrated Pest Management (IPM) principles and Integrated Weed Management (IWM)—which combine cultural, mechanical, biological, and limited chemical tools—are gaining ground as effective strategies to reduce herbicide reliance while maintaining yields. Mechanical methods, such as manual weed removal, tillage, flailing, or even hybrid electrical sprayer systems, have shown promise, especially for pre-harvest crop desiccation. Regenerative and agroecological agriculture models—emphasizing organic matter recycling, cover crops, and microbial soil treatments—demonstrate that chemicals like diquat and paraquat can be phased out without resulting in yield penalties for some crops. However, significant barriers hinder broader adoption: Many farmers cite high costs, limited access to equipment, and a lack of training or institutional support. Still, some farmers remain optimistic about the shift. While they recognize the economic and agronomic challenges—such as temporary yield declines and higher input costs—they view the transition as a long-term investment in soil health, ecological resilience, and access to growing premium markets, rather than a step backward. Despite these obstacles, grassroots resistance is growing. NGOs and health advocates—including the Environmental Justice Foundation and the Pesticide Action Network—have highlighted the exploitative trade of banned chemicals and campaigned for local and national restrictions on diquat use. At the international level, scientists and health experts are calling for global phase‑outs and harmonized regulations. A proposal adopted at the 2023 International Conference on Chemicals Management (ICCM5) urged stakeholders to eliminate highly hazardous pesticides—including diquat—by 2030, and to prohibit or regulate exports of chemicals already banned nationally. Together, these actions reflect a growing movement toward reducing chemical dependence, empowering farming communities, and promoting safer and more resilient agricultural systems that will benefit the consumer. Ditching Diquat: Solutions for the Home and Garden For consumers concerned about diquat exposure, primarily through household herbicides and aquatic weedkillers, there are several safer alternatives and practical steps to reduce risk. A growing network of trusted resources offers practical, science-based, and health-conscious guidance, including Beyond Pesticides, which provides extensive tools for managing pests and weeds without synthetic chemicals and has a searchable database of safe alternatives and resources for creating pesticide-free lawns, gardens, and public spaces. Experts also recommend the homeowner-friendly primer on ecological, pesticide‑free landscaping published by the Northeast Organic Farming Association, which introduces the concept of organic land care—applying regenerative agricultural principles (biodiversity, soil health, water conservation, and low inputs) to everyday lawns and gardens. Many mainstream weed-control products sold for home use—such as Spectracide Weed and Grass Killer or Reward—may contain diquat or similar toxic ingredients. Instead, consumers can opt for low-toxicity or organic alternatives such as vinegar-based, acetic acid herbicides, which are effective for small-scale spot treatment of weeds; clove oil and citric acid-based sprays; corn gluten meal, a pre-emergent herbicide that inhibits weed seeds from forming roots after germination; or using boiling water or flame weeders, which can be effective for patios, driveways, or between garden rows. These alternatives are widely available at garden centers and online, often labeled “natural” or “pet-safe.” Look for OMRI-listed (Organic Materials Review Institute) products when in doubt. By switching to non-toxic methods and staying aware of chemical ingredients in common weedkillers, consumers can not only help protect their health but also the health of ecosystems and workers further up the supply chain. When it comes to food safety, choosing organic and regeneratively grown foods is one of the most effective ways to avoid crops treated with diquat and other synthetic herbicides, since USDA-certified organic standards prohibit their use. Supporting local farms that commit to chemical-free or low-input growing methods—particularly those using IWM or agroecology—also helps reduce herbicide dependence and build more resilient food systems, according to the USDA’s Conservation Practice Standards. It’s also wise to wash all fruits and vegetables thoroughly to help reduce trace chemical exposure. Another good resource is the EWG Shopper’s Guide to Pesticides in Produce, an annual consumer guide published by the Environmental Working Group (EWG) that ranks conventionally grown fruits and vegetables based on the amount of pesticide residues found on them, using data from the U.S. Department of Agriculture (USDA). Beyond personal choices, consumers can have a broader impact by advocating for local or state-level restrictions on the use of hazardous pesticides and urging elected officials to adopt the precautionary principle in public health policy. Finally, demanding action from the EPA to reassess outdated approvals can help close regulatory loopholes and protect both human and environmental health. The issues surrounding diquat emphasize the urgent need for a global consensus on pesticide safety—one that prioritizes public health, ecological integrity, and long-term food security over short-term yield gains. Achieving that will require more than just regulatory reform. Transparency from chemical manufacturers, bold action from policymakers, and a groundswell of consumer awareness are the need of the hour. The path forward lies in investing in sustainable farming, empowering farmers with safer tools, and holding industry and governments accountable for the chemicals that shape our landscapes—and our lives. This article was produced by Earth | Food \ Life, a project of the Independent Media Institute. The post America is Still Using Diquat, a Toxic Weedkiller Banned in Much of the World appeared first on CounterPunch.org. From CounterPunch.org via this RSS feed
Komunitas
lemmy.world
Managarr v0.6.0 has been released with some fun new features! Managarr is a terminal-based application for managing all your Servarr instances from one place. It provides a user-friendly interface to interact with your media libraries, making it easier to manage your downloads, monitor your series and movies, and perform various actions directly from the terminal. It sports two modes: a TUI mode (Text User Interface) and a CLI mode (Command Line Interface). TUI mode gives you an interactive User Interface right inside your terminal window, allowing you to navigate through your Sonarr and Radarr libraries, view details about your series and movies, and perform actions like adding or removing items, all through keyboard shortcuts. CLI mode lets you execute commands directly from the terminal to manage your Servarr instances without needing to open the TUI. This is great for quick tasks or for integrating with scripts and automation tools. The biggest change: Managarr now has themes! The UI has been completely overhauled to support themes! You can now customize the look and feel of Managarr to suit your preferences. Choose from a variety of themes to change the color scheme and overall aesthetic of the application. Here’s just a few examples: Default Dracula Watermelon Dark You can also customize the themes to your heart’s content! Check out the themes documentation for more details on how to create and apply your own themes. Features Added support for alternative Vim-like navigation keybindings (hjkl movements) Discussion #34 Added support for terminal-like backspace operations (Ctrl-h instead of Backspace) You can now specify the number of downloads to fetch from the CLI: managarr list downloads --count 1234 You can now toggle movie monitoring from the CLI without needing to use the edit subcommand: managarr radarr toggle-movie-monitoring --movie-id 1234 #43 You can also now toggle series monitoring from the CLI without needing to use the edit subcommand: managarr sonarr toggle-series-monitoring --series-id 1234 #43 You can now also toggle movie/series monitoring directly from the Library view for each Servarr with the m key. No need to open the Edit [Series/Movie] modal anymore to simply toggle monitoring for an item! #43 Users can now skip up/down tables 20 items at a time using Ctrl-d and Ctrl-u keys (mirroring the same functionality in the Helix editor). Alternatively, the standard PgUp and PgDown keys are supported for the same operation. This is particularly useful for large libraries with many items #45 The total disk usage for any given series is now displayed in the Series Library view to mirror Radarr functionality #44 All keybindings and help tips have been refactored into a unified, dynamic menu that displays the available keybindings for the current view. This is accessible by pressing ? in any view, and it will display the keybindings relevant to that view. #32 Users can now add any number of custom headers to each Servarr’s configuration, enabling support for OAuth and other custom authentication schemes for Servarr access #47 Fixes Fixed a bug that caused the Collection Details modal to vanish when attempting to add a new film to a collection Fixed a bug that caused the Radarr library to be rendered, then the Collections table to be rendered over it (merging the two), and then showing a popup which made for ugly and confusing UI Wrapped Season.statistics with Option to prevent a panic if the season doesn’t have any statistics (edge-case, only happens with outdated Sonarr data) #35 Corrected a bug that caused double key presses on Windows machines #40 (Thanks @cwesleys!) Defaulted to empty tags to improve fault tolerance within the Sonarr and Radarr UIs. This is in response to #42, #48. It seems like this may be a bug in Sonarr where a series can have an associated tag ID but that tag Id doesn’t exist in the list of tags, but I still can’t quite track it down. Fixed an issue that caused some panics to occur when video codecs are undefined in file metadata #38 More than 10 downloads will be listed in the Downloads tabs for both Radarr and Sonarr Fixed a bug where Sonarr would have empty values on season releases for seeders/leechers instead of ‘0’ Fixed a bug where some Radarr films don’t have studios associated with them, so the studio field is now nullable, preventing crashes when loading the Radarr library Security Fixes Upgraded to the most recent version of Tokio to mitigate CWE-664 Improper Control of a Resource Through its Lifetime Updated to the most recent patch of OpenSSL to mitigate CWE-416 Use-After-Free Minor Changes Due to the new support for Vim-like navigation keybindings, the system logs are now opened using L instead of l Refactored the network module to be more idiomatic Rust and to improve maintainability Documentation Update README.md to remove the cheeky Try Before You Buy heading since some users reported it as misleading; i.e. they thought it meant Managarr cost money. Managarr is and always will be, free As always, thank you to everyone who reported an issue or requested a feature! You all make it a LOT easier to keep up with breaking API and add new features. If you have any feedback or suggestions, please don’t hesitate to open an issue or discussion on the GitHub repository.
Komunitas
lemmy.world
Managarr v0.6.0 has been released with some fun new features! Managarr is a terminal-based application for managing all your Servarr instances from one place. It provides a user-friendly interface to interact with your media libraries, making it easier to manage your downloads, monitor your series and movies, and perform various actions directly from the terminal. It sports two modes: a TUI mode (Text User Interface) and a CLI mode (Command Line Interface). TUI mode gives you an interactive User Interface right inside your terminal window, allowing you to navigate through your Sonarr and Radarr libraries, view details about your series and movies, and perform actions like adding or removing items, all through keyboard shortcuts. CLI mode lets you execute commands directly from the terminal to manage your Servarr instances without needing to open the TUI. This is great for quick tasks or for integrating with scripts and automation tools. The biggest change: Managarr now has themes! The UI has been completely overhauled to support themes! You can now customize the look and feel of Managarr to suit your preferences. Choose from a variety of themes to change the color scheme and overall aesthetic of the application. Here’s just a few examples: Default Dracula Watermelon Dark You can also customize the themes to your heart’s content! Check out the themes documentation for more details on how to create and apply your own themes. Features Added support for alternative Vim-like navigation keybindings (hjkl movements) Discussion #34 Added support for terminal-like backspace operations (Ctrl-h instead of Backspace) You can now specify the number of downloads to fetch from the CLI: managarr list downloads --count 1234 You can now toggle movie monitoring from the CLI without needing to use the edit subcommand: managarr radarr toggle-movie-monitoring --movie-id 1234 #43 You can also now toggle series monitoring from the CLI without needing to use the edit subcommand: managarr sonarr toggle-series-monitoring --series-id 1234 #43 You can now also toggle movie/series monitoring directly from the Library view for each Servarr with the m key. No need to open the Edit [Series/Movie] modal anymore to simply toggle monitoring for an item! #43 Users can now skip up/down tables 20 items at a time using Ctrl-d and Ctrl-u keys (mirroring the same functionality in the Helix editor). Alternatively, the standard PgUp and PgDown keys are supported for the same operation. This is particularly useful for large libraries with many items #45 The total disk usage for any given series is now displayed in the Series Library view to mirror Radarr functionality #44 All keybindings and help tips have been refactored into a unified, dynamic menu that displays the available keybindings for the current view. This is accessible by pressing ? in any view, and it will display the keybindings relevant to that view. #32 Users can now add any number of custom headers to each Servarr’s configuration, enabling support for OAuth and other custom authentication schemes for Servarr access #47 Fixes Fixed a bug that caused the Collection Details modal to vanish when attempting to add a new film to a collection Fixed a bug that caused the Radarr library to be rendered, then the Collections table to be rendered over it (merging the two), and then showing a popup which made for ugly and confusing UI Wrapped Season.statistics with Option to prevent a panic if the season doesn’t have any statistics (edge-case, only happens with outdated Sonarr data) #35 Corrected a bug that caused double key presses on Windows machines #40 (Thanks @cwesleys!) Defaulted to empty tags to improve fault tolerance within the Sonarr and Radarr UIs. This is in response to #42, #48. It seems like this may be a bug in Sonarr where a series can have an associated tag ID but that tag Id doesn’t exist in the list of tags, but I still can’t quite track it down. Fixed an issue that caused some panics to occur when video codecs are undefined in file metadata #38 More than 10 downloads will be listed in the Downloads tabs for both Radarr and Sonarr Fixed a bug where Sonarr would have empty values on season releases for seeders/leechers instead of ‘0’ Fixed a bug where some Radarr films don’t have studios associated with them, so the studio field is now nullable, preventing crashes when loading the Radarr library Security Fixes Upgraded to the most recent version of Tokio to mitigate CWE-664 Improper Control of a Resource Through its Lifetime Updated to the most recent patch of OpenSSL to mitigate CWE-416 Use-After-Free Minor Changes Due to the new support for Vim-like navigation keybindings, the system logs are now opened using L instead of l Refactored the network module to be more idiomatic Rust and to improve maintainability Documentation Update README.md to remove the cheeky Try Before You Buy heading since some users reported it as misleading; i.e. they thought it meant Managarr cost money. Managarr is and always will be, free As always, thank you to everyone who reported an issue or requested a feature! You all make it a LOT easier to keep up with breaking API and add new features. If you have any feedback or suggestions, please don’t hesitate to open an issue or discussion on the GitHub repository.
Komunitas
lemmy.world
Managarr v0.6.0 has been released with some fun new features! Managarr is a terminal-based application for managing all your Servarr instances from one place. It provides a user-friendly interface to interact with your media libraries, making it easier to manage your downloads, monitor your series and movies, and perform various actions directly from the terminal. It sports two modes: a TUI mode (Text User Interface) and a CLI mode (Command Line Interface). TUI mode gives you an interactive User Interface right inside your terminal window, allowing you to navigate through your Sonarr and Radarr libraries, view details about your series and movies, and perform actions like adding or removing items, all through keyboard shortcuts. CLI mode lets you execute commands directly from the terminal to manage your Servarr instances without needing to open the TUI. This is great for quick tasks or for integrating with scripts and automation tools. The biggest change: Managarr now has themes! The UI has been completely overhauled to support themes! You can now customize the look and feel of Managarr to suit your preferences. Choose from a variety of themes to change the color scheme and overall aesthetic of the application. Here’s just a few examples: Default Dracula Watermelon Dark You can also customize the themes to your heart’s content! Check out the themes documentation for more details on how to create and apply your own themes. Features Added support for alternative Vim-like navigation keybindings (hjkl movements) Discussion #34 Added support for terminal-like backspace operations (Ctrl-h instead of Backspace) You can now specify the number of downloads to fetch from the CLI: managarr list downloads --count 1234 You can now toggle movie monitoring from the CLI without needing to use the edit subcommand: managarr radarr toggle-movie-monitoring --movie-id 1234 #43 You can also now toggle series monitoring from the CLI without needing to use the edit subcommand: managarr sonarr toggle-series-monitoring --series-id 1234 #43 You can now also toggle movie/series monitoring directly from the Library view for each Servarr with the m key. No need to open the Edit [Series/Movie] modal anymore to simply toggle monitoring for an item! #43 Users can now skip up/down tables 20 items at a time using Ctrl-d and Ctrl-u keys (mirroring the same functionality in the Helix editor). Alternatively, the standard PgUp and PgDown keys are supported for the same operation. This is particularly useful for large libraries with many items #45 The total disk usage for any given series is now displayed in the Series Library view to mirror Radarr functionality #44 All keybindings and help tips have been refactored into a unified, dynamic menu that displays the available keybindings for the current view. This is accessible by pressing ? in any view, and it will display the keybindings relevant to that view. #32 Users can now add any number of custom headers to each Servarr’s configuration, enabling support for OAuth and other custom authentication schemes for Servarr access #47 Fixes Fixed a bug that caused the Collection Details modal to vanish when attempting to add a new film to a collection Fixed a bug that caused the Radarr library to be rendered, then the Collections table to be rendered over it (merging the two), and then showing a popup which made for ugly and confusing UI Wrapped Season.statistics with Option to prevent a panic if the season doesn’t have any statistics (edge-case, only happens with outdated Sonarr data) #35 Corrected a bug that caused double key presses on Windows machines #40 (Thanks @cwesleys!) Defaulted to empty tags to improve fault tolerance within the Sonarr and Radarr UIs. This is in response to #42, #48. It seems like this may be a bug in Sonarr where a series can have an associated tag ID but that tag Id doesn’t exist in the list of tags, but I still can’t quite track it down. Fixed an issue that caused some panics to occur when video codecs are undefined in file metadata #38 More than 10 downloads will be listed in the Downloads tabs for both Radarr and Sonarr Fixed a bug where Sonarr would have empty values on season releases for seeders/leechers instead of ‘0’ Fixed a bug where some Radarr films don’t have studios associated with them, so the studio field is now nullable, preventing crashes when loading the Radarr library Security Fixes Upgraded to the most recent version of Tokio to mitigate CWE-664 Improper Control of a Resource Through its Lifetime Updated to the most recent patch of OpenSSL to mitigate CWE-416 Use-After-Free Minor Changes Due to the new support for Vim-like navigation keybindings, the system logs are now opened using L instead of l Refactored the network module to be more idiomatic Rust and to improve maintainability Documentation Update README.md to remove the cheeky Try Before You Buy heading since some users reported it as misleading; i.e. they thought it meant Managarr cost money. Managarr is and always will be, free As always, thank you to everyone who reported an issue or requested a feature! You all make it a LOT easier to keep up with breaking API and add new features. If you have any feedback or suggestions, please don’t hesitate to open an issue or discussion on the GitHub repository.
Komunitas
beehaw.org
If they gave more time than just a few months, in example at least an entire year, then people could at least download those files before hand. Not sure how long this would take and how stressful this would be for their servers. Is anyone actually surprised by this? How can you think Twitch is a longterm archive? Its like having backups on Microsoft or Adobe servers. Do not trust them and always have a backup plan! Not even YouTube is, because they deleted old unused accounts and therefore the associated videos. Not sure how far this gone though. I wouldn’t be surprised if Amazon/Twitch announces some premium service where all files will stay active if you pay a monthly fee.
Komunitas
lemmy.dbzer0.com
Not recommending a VPN here. But there are many open-source anonymizing networks out there that need more attention. I know speed and avoiding blocks and captcha’s are important to you, so this answer is not geared toward your use case, but for those looking for a free alternatives to VPN’s and don’t care about the speed and want to help out the network, there are lokinet: (https://github.com/oxen-io/lokinet) (Based on the LLARP, low-latency anonymizing protocol, basically tor 2.0). (My personal favorite): i2p. A network within a network. Downsides are you can only download torrents within the network, but the upside is there is a solid community and there are more and more torrents that exist. Mental Outlaw has a great video about i2p There are some VPN’s you can trust, but in the end of the day, I trust encryption and the decentralized network better than any centralized corp.
Komunitas
hexbear.net
I have also uploaded the wrong thing on occasion, so it’s understandable to that extent, but I still want you to consider the Swiss cheese model here. This is after all the selfcrit community, and I think it should be guided by what’s known as “just culture”, i.e. asking “What went wrong?” instead of “Who caused the problem?” — like in aviation accident reports, you know. In the case of accidentally posting porn on a public forum, the Swiss cheese model might look like: Don’t save porn to your computer. This is pretty unenforceable, and it’s pretty pointless to judge people for downloading porn or to try to stop them from doing it; but still, consider what files you actually need to have on your computer. But if you determine that you need to have porn on your computer — even if it’s just for self-pleasure without sending unnecessary Internet packets, or driving traffic to surveillance-capitalist tube sites with their algorithms and all — then… Keep the porn on your computer segregated from other files. Perhaps on an external hard drive if you want to be extra safe that you won’t accidentally upload it, but a separate (hidden?) folder should normally do. Double check the name of the file before uploading. When I’ve uploaded the wrong thing on Hexbear, it’s always been because when I click on “upload image”, Firefox opens up a file explorer, and I start typing in the name of the picture I want, and if the file name contains a space, I’ll hit space… only to remember a second too late that hitting space selects the top file in the search results, rather than adding a space to the search query. Which I think is pretty bogus but what can ya do. Double check that you’ve uploaded the correct file before posting. This is what’s stopped me from ever accidentally posting something I didn’t mean to: just take ten seconds or so to look over the post title, the attached picture, the body, and the community, before hitting post. I think the most embarrassing thing I’ve ever accidentally uploaded to Hexbear was a screencap of the tags on some AO3 smut fanfiction, but as said, I didn’t post that picture, I just hit “delete” and found the file I meant to upload. Another thing to consider is how these lessons can be applied elsewhere. If you could accidentally post porn on a public forum, then what if you’re entrusted with even more sensitive files, like documents related to the inner workings of your organization? You can of course just avoid being assigned that sort of responsibility, yes, but it can’t hurt you to become capable of taking on that sort of responsibility, right? That’s what growth is about, right? In any case, I think it’s safe to say that everybody here forgives you, and doesn’t think it was a big deal, since no harm was done and most of us can relate to making that sort of mistake. «{Мы|(“We’re} {чуть-чуть|a-little-bit} {злые,|evil,} {тюрьма|prison} {для|for} {нас!»|us!”)}
Komunitas
lemmy.world
You can download Artix Linux 2026.04 right now Why would anybody? It’s actively advertising that it’s using a replacement for X11 created by a MAGA, anti-vaxx dipshit whose claim to ultra-niche fame was making a fucking mess of Xorg by recklessly churning out PRs, accordingly getting barred from contributing, and throwing a removed fit and spinning his removal into some incoherent Red Hat conspiracy theory. Here’s the raw level of competence you can expect when you trust XLibre’s developer to reimplement a decades-old mountain of low-level spaghetti. (For anybody who’s never written C/C++, this is something you would – generously – learn in the first half-hour of learning the language. Making a typo is semi-understandable. Being confused when confronted by it and having it directly explained to you is fucking insane given the nature of the project.)