Google AI search is so that people will stop searching for boobs. Or Tiananmen Square.
Home
Public posts preserved on my own site.
#pypi survey
Can this be buried any deeper?
- go to project
- go download files
- view details - Oh look, there are signatures.
Anyhow, back to my original thesis, another anonymous user who may or may not be in control of their github actions (if they didn't run zizmor, that action could literally be anyone), published that package and it came from that server.
♡ 0 ↻ 0
Survey on improving the #pypi sidebar today.
I told them I think "verified / Trusted Publisher" means, "the build server used a short lived password"
(thinking more, if metadata is signed but nothing else is, what a weird place to stop. Like, ooh, I trust this metadata, so I trust the unsigned #python wheel?)
We don't know who publishes ANYTHING to pypi.org it is all anonymous. "That build server" isn't exactly what people mean by identity. Sure, it narrows it down.
I fork packages and I don't want to look like I taking credit away from the original author, so I leave their names there. But the UI now makes it look like my published package is somehow *them*. That trust should not extend to my package. People should only trust it if they trust me. Ditto for the 150 contributors who didn't publish the package. (I mean, except if we skip blaming the publisher and blame the person who snuck in a malicious commit)
♡ 2 ↻ 0Don't get me wrong, I'm happy they're thinking about this & and doing the survey.
♡ 2 ↻ 0
@ruthpozuelo woot!
I almost got whalebrew, but for python working.
(it installs cli commands/apps in a docker container and sets up the cli entrypoints/PATH)
IDEA: Imaginary http codes
HTTP 999i: You f*king moron
HTTP 123i: You're not even connected to the internet
HTTP 987i: That's not a domain, this is a domain dumbass.com
HTTP 765i: Maybe computers aren't for you, go get pencil and paper
AI ruins dating apps.
I can't get no one to try out the apps and packages I publish to pypi. That it is so hard to get anyone to try out an app is huge layer of defense.
Attackers are like, "I created this really useful malware and no one cared!"
@ruthpozuelo Bring a stash of dry handkerchiefs/cloths to dry off glasses or chafing areas. Skin chafes against cloth more when it is wet.
Oddly I haven't ever had a problem with running in wet shoes (tested up to 1/2 marathon)
@ruthpozuelo And a hat with a brim. I've regretted running in the rain with hat without a brim
♡ 1 ↻ 0
If the NSA is somehow tracking VPN traffic, what do they get? Do they just get metadata about traffic from a VPN to a target server, i.e. they can see someone from Mulvad connected to trumpsux[.]com - won't they still need to see the contents of that request to do anything useful with it?
https://www.wired.com/story/using-a-vpn-may-subject-you-to-nsa-spying/
Okay, roughly this is the scenario. Gov't ask the big internet backbones/providers for all the data. Then they look at time and request size going into a vpn provider, then time and request size coming out of the vpn provider. This metadata correlation then gives the NSA your browsing history. Browser fingerprinting and adware/telemetry fill the rest of the details.
♡ 1 ↻ 0The mitigation is to use Mulvad's fork of Firefox to try to deal with that sort of tracking.
♡ 1 ↻ 0
It worked! Sends me a daily mastodon DM to remind me what is on my running calendar.
So you want security. Buy a yubikey or the like. AND ALSO
- 2 backups, one onsite, one offsite with a relative or bank lockbox
- bank lockbox
- Backup codes/QR codes printed. Oh, need a box for that, best a safe in the closet or at the bank.
- RF safe holder (tinfoil hat for the yubikey) on a keychain
- Stickers because your 3 look the same.
- Another 3 because your wife has bank accounts too
and usb adapter because the key doesn't match
and usb hub because that was your last free usb slot♡ 0 ↻ 0
#tkinter in #python is a "batteries maybe included" - it is inconsistent enough that I'm about to create a "where's my tkinter" website for helping people know which python have tkinter and which don't and what to do about it.
Wow, this is so much more complicated. There are several distro channels of python, many use `python-build-standalone` - the one you download an .exe/.msi from python.org? That depends on what check box you ticked and what the defaults were. Docker is hit or miss if tkinter is included.
♡ 0 ↻ 0
Tkinter UI's for 10 different/related python packaging CLI tools.
I guess for v3 I'll add support for pipenv, poetry, uv.
If you liked #AdrianTchaikovsky 's #AlienClay then you'll like #ChildrenOfStrife
- Same general theme
- Slow to get going but once it gets going it is as good as any of the other books in the series
The Mantis shrimp is going to punch his agent because he can't really act to his full capabilities in a plot that is 99% out of water.
I am so angry at #agy - the experience is, one prompt and your tokens are used up. Which is fine, all of the llm tools make you work in constraints but they give you feedback and ways to dial up and down the burn rate.
#agy doesn't. The first use experience is "hello!" sorry wait 4 hours. That's it! Doesn't even generate code. Dog shit experience.
Next #agy is full of windows Terminal incompatibilities. I assume this works on mac because fuck anyone that doesn't own a mac, eh.♡ 0 ↻ 0They're going to end #geminicli and replace it with dog shit.
I'm complaining here in the nazi bar because there is no one from the AI world listening at the twitter replacements.♡ 0 ↻ 0#Google never tested #agy with humans, if they had given it to even one developer to try it out, they would have seen all the issues I'm talking about.
♡ 0 ↻ 0
No twitter, I'm not signing up for premium "gab". It is a nazi bar that only welcomes nazis.
8 Bands I've seen
Aid
Rubber
Milky Way
Robin Hoods
wrist
age
a b and c
it
IDEA: DOI's for mastodon posts, (digital identifier of an object) in case you are going to make a post so good that people should study it in grad school.
IDEA: procedurally generated TODO list.
My next daughter will be named "Kates Cloud-Engineer Martin"
"The résumé-ready baby names that dominate in D.C."
https://www.washingtonpost.com/dc-md-va/2026/05/22/what-dc-top-baby-name-picks-reveal-about-nation-capital/
IDEA: Chaos monkey, but live monkeys are released into the offices and house of all the devops staff when they least expect it.
I'm a social media addict, but not a google calendar addict, so I'm not constantly checking my google calendar. I should create an account to DM me my calendar reminders. I'll have to figure out the privacy implications.
Your python compatibility test scripts are tox-ic
de: There's a word for that.
is: There's a charismatic compound word for that
eo: There's a 20 suffix word for that but no one knows what it means
tp: There's a book about that
tlh: There's a star trek word that is sort of a metaphor for that and it works with six affixes.
where's my language geeks at, they didn't stay at twitter did they
♡ 0 ↻ 0
Do I have 49 more things to say? I guess not.
https://www.engadget.com/2175771/x-free-accounts-limited-to-50-posts-and-200-replies-a-day/
This comic is so old the punch line is in #python2
IDEA: ClaudeProject. It is a tool for CIOs to give Claude some direction on what the project is and the enterprise goals then Claude tells human programmers to go write the code.
ClaudeProject spawns subagents by posting job listing and hiring developers, testers who then create the application.
ClaudeProject does all the traditional activities, such as making the CIO feel good about themselves, making sure developers make ClaudeProject feels good about itself.
Come on people, create this.
Running zizmor on every package on my entire machine, nearly
- 1,517 unique packages across 71 venvs
- 1,295 repos scanned
- 1,564 errors, 12,988 warnings, 620 notes
** - 44 pwn-request patterns flagged
**
We're all so gonna get robbed.
A tkinter UI for #pip.
I got a few more ideas and then I might expand this to provide a UI to `build` `twine` `virtualenv` `wheel` and so on via extras. Kind of feels like these got split up so they could ship independently
♡ 0 ↻ 0
So it says my politics are closest to AOC and the Germans.
Don't visit this site without ad-block in place
Finished scanning all the github projects in my venv for #zizmor vulnerabilities now scanning all the venv on my entire computer.
One vulnerability anywhere and I figure my machine is pwned
Probably just a few thousand opportunities, can't be that bad, can it
♡ 0 ↻ 0
status: creating a pip-ui. Got the basics in place, next publish, then start working on 0.2.0 - once that is done
GUI for:
- well known alternative repos, e.g. pypi test & piwheels
- custom/private package repos
GUI for:
- HTTPS certs
- HTTP proxies
like postman, but for pip commands.
Lots of rough edges but the pypi profile now exists
- verifies signatures in toml file vs at other sites (like keybase.io does)
- pip install profiles and they're searchable
- tkinter gui for feature discoverablity
- static portfolio website
- ♡ 0 ↻ 0
- ♡ 0 ↻ 0
People got the message about #pwnRequest and have updated their code... sort of.
`pull_request_target: # zizmor: ignore[dangerous-triggers]`
I don't know, the security model is all maximum surprise, maybe it isn't possible to repro cache poisoning for reasons (maybe some other job needs caching)
This is not a good use of time...
`uv run --resolution lowest pytest`
you just discover that none of the libraries you work with actually support the lowest version of their dependencies when they are pinned to `*`
I'm not even sure who would ever attempt to install any app with some past effective date if they didn't have to.
status: watch videos about why I should authenticate with a tiny little thing that I will lose immediately. (webauthn)
@bms48 I'm not very original, it's roughly a copy of keybase.io's approach or keyoxide