fiat_lux 🆕 🏠

Relocated from: @fiat_lux@lemmy.world ⛓️‍💥(04-2026)

  • 1 Post
  • 59 Comments
Joined 25 days ago
cake
Cake day: April 24th, 2026

help-circle



  • The raw changes are interesting but not particularly descriptive of the problem(s?) it intends to resolve, so I can’t gauge whether it achieves the goal from this. The description of the version bump as simply “security improvements” doesn’t help me determine if any of these changes add dedicated tests or anything else to prevent future occurrences (and I’m not traversing the repository on my phone). Additionally, the issue acknowledged via inline comment: “This will probably break PeerTube federation” is odd to omit from even the briefest changelog. In my opinion, this is not that reassuring an update.

    The LLM generated report of Lemmy’s vulnerability, which I note requires an entire DNS configuration to exploit, is a little ironic to point to as an authoritative source while characterizing the Piefed exploit discovery as “someone running an LLM and trying to discover vulnerabilities without double checking them”.

    But I don’t think it’s necessary or helpful to have a competitive security score-card situation between packages either - I would much prefer that each ActivityPub implementation is meaningfully improving their development lifecycle processes, especially around security risk mitigation, even if they don’t go quite as far as having a formal “security posture”.


  • Fair. In my case I wish someone had not overlooked the systemic inflammation (from a different condition that has been recently correlated with OA, somewhat unexpectedly) and the malmechanics I was experiencing, so that I might have avoided some of the further issues, but, so it goes.

    I manage to shift some of the chronic pain, but sadly society really likes to build worlds that have only one blessed way of doing certain things, which makes it impossible to shift more consistently. So I will have to mostly content myself with smugly sore.

    Given you appear to be a doctor though, I do have one favor to ask. If you ever get a flexible kid with crepitus come through your doors, maybe add a CRP test to their blood work, just on the off-chance and even if only for the chain of evidence.


  • A few months ago I mentioned in a thread about Piefed there were questionable system design choices that indicated that other parts of the system should be carefully examined for how they’re handling and sanitizing input. I’m assuming someone discovered one of the places that this was actively exploitable.

    From what I’ve seen of the code, although Python is not my specialty, it might be worth delaying reactivation until it can demonstrate that it is at least somewhat resistant to the OWASP Top 10, especially Injection.

    Irresponsible disclosure is annoying, but vastly better than discovery and exploitation by those who aren’t going to disclose at all.







  • Oh, that percentage is the year on year change, not a return on investment. So 2025 financial year they reported roughly -30 million cash from investments, this year is roughly -267 million, so they reported a loss of (267-30) / 30 = ~7.78 times as much money against the scope of the category “investments”.

    You’d expect to see the percentage go below zero when you buy more stocks / bonds or securities than you sell or which mature, or (I think) when you take money gained from an investment and then put it towards another investment or other cash category, so it’s not necessarily a really bad thing for a company to have a negative number there. It just means they’re either shuffling it internally or committed to spending it. The size and timing of the change is what is unusual.

    There are all sorts of rules and tricks in this shell game though, I couldn’t say with any certainty where that money went, or if it ever really existed at all. I just see a pattern of companies with big negative short term investment cash flows and layoffs that correlate maybe too well with the Bitcoin dump at the end of January.


  • I think the “original” money is still mostly from their 2021 IPO, so “leveraged” was the wrong word, my brain is a mess today.

    But, they certainly look like they either ate up to a quarter billion loss on crypto gambling, or shuffled the money from that column into a different part of the books to pay for AI, or spent that money on other new investments. I don’t think it could be entirely new investments because they’ve never even hit one billion in annual revenue, their net income has never been positive, and they’ve had no new acquisitions over the last couple of years. The new CFO in January move also points at a big financial fuckup being the reason.


  • No surprises here. Their cash flow suggests they were heavily leveraged on crypto (Edit: or other unusual spending, the crypto part is speculation, they officially claim to have no crypto), -776% y/y change for investments in 2026. Not as bad as their 2023 -1,023%, but their new CFO has an uphill battle ahead of her.

    I can see them being on the 2027 casualty list. They’ve been pushing AI hard internally the last year or so, which caused me some issues at my workplace after their misplaced confidence led them to call out my niche as an “opportunity” they had “mostly solved”. Spoilers: They hadn’t then, visibly still haven’t now, and will have less chance doing so by adding more AI because it is particularly terrible at this niche.


  • lemmy.zip was the nearest similar comm? This could have been put in an instance that is involved with the dispute, many of them have Fediverse communities.

    Putting aside the irony of cross-posting a thread about the potentially ideologically inspired muting of smaller instances by Piefed to draw attention to lemmy.ml’s potentially heavy-handed censorship and bias harming the growth of the Lemmy-verse - it looks less like “vitilizing” and more like fragmenting discussion.

    More ironic still is that if I see one of your posts now it means that I’ll probably go look at ml to see the actual discussion and hear more from the OP. Perhaps posting original content might go further to achieve your goals?




  • We had slightly different readings.

    As he was writing he became aware that he was being watched, and a figure slowly emerged to his left. It was indistinct and on the periphery of his vision but it moved as V.T. would expect a person to. The apparition was grey and made no sound… V.T. was unable to see any detail and finally built up the courage to turn and face the thing. As he turned the apparition faded and disappeared.

    He experienced a visual disturbance in his periphery manifesting as the false perception of a person. Even without it being interpreted as a person, that’s a textbook mild hallucination.

    Once V.T. knew this he calculated the frequency of the standing sound wave … 18.97Hz … plus or minus 10%

    Table IV on page 212 of this book shows frequencies causing disturbance to the eyes and vision to be within the band 12 to 27 Hz.

    Most interestingly, a NASA technical report mentions a resonant frequency for the eye as 18 Hz (NASA Technical Report 19770013810).

    He cited two sources inline with ranges narrower than 8-40Hz which indicate that vision can be affected at the same frequencies he measured in the lab. He even noted that everyone would have slightly different resonant frequencies.

    No, it’s not a full research paper, but it is the citation you requested.