Skip to content

BSD Cafe Lounge

54 Topics 151 Posts

Grab a drink, take a seat.
Off-topic chat, introductions, and anything that doesn't fit elsewhere.

This category can be followed from the open social web via the handle bsdcafelounge@billboard.bsd.cafe

Subcategories


  • Let's introduce ourselves!

    8 13
    8 Topics
    13 Posts
    UsulU
    @stefano Thank you.
  • BSD Cafe Billboard and more in the Awesome BSD collection

    Pinned
    4
    8 Votes
    4 Posts
    322 Views
    stefanoS
    @grahamperrin@mastodon.bsd.cafe "this is fine!"
  • Welcome to the Lounge

    Pinned
    9
    12 Votes
    9 Posts
    2k Views
    UnusNemoU
    <<< Grabs a triple espresso and sits down and waits smiles, this should get interesting.
  • littleFedi

    activitypub littlefedi mastodon fediverse
    1
    8 Votes
    1 Posts
    106 Views
    grahamperrinG
    https://littlefedi.org/ a small ActivityPub server written in Go. It ships as a single static executable with a server-rendered web interface, a Mastodon-compatible client API, a durable federation queue, moderation tools, and optional PostgreSQL and S3 support. No runtime to install, no services to wire together. Via https://littleone.littlefedi.social/@stefano/08d20839-b21b-47bc-a1b6-800d1137f36e | https://mastodon.bsd.cafe/@stefano@littleone.littlefedi.social/117076101948770274 @stefano@littleone.littlefedi.social
  • Stéphane HUC :: Echoes Weekly IT

    25
    0 Votes
    25 Posts
    534 Views
    grahamperrinG
    @CiotBSD said: ⇒ When online commenters ‘detect’ my art as AI Reactions in Hacker News and the Fediverse: https://news.ycombinator.com/item?id=49188916 https://framapiaf.org/@davidrevoy/117043735577793210 @davidrevoy@framapiaf.org The reply from @uriel@bbs.keinpfusch.net made me giggle
  • [Hardware Open Source]

    hardware
    5
    1 Votes
    5 Posts
    133 Views
    CiotBSDC
    26/08/02 ⇒ reFrame — the ePaper camera reFrame is an experimental camera with a color ePaper display. Designed to capture and display one photo at a time, making every frame deliberate and memorable. https://reframe.camera/
  • 0 Votes
    1 Posts
    302 Views
    grahamperrinG
    A follow-up to https://mastodon.bsd.cafe/@82mhz/117002938483503805 @82mhz The linked article (June 2026) began: The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). .. – 18–23 minutes, according to Firefox Reader. I used AI to get a concise timeline. The text below is taken from Claude's response. … The general practice: 2015 The root of it all is Hola VPN / Luminati (Bright Data's predecessor). In May 2015, it was discovered that Hola — a free "VPN" — was quietly turning users' devices into paid exit nodes sold through a sibling brand, Luminati, at up to $20/GB. The discovery came after 8chan's admin, Frederick Brennan, traced a wave of DDoS/spam attacks against his site back to Hola users being abused as a botnet, and outlets like The Register, Fortune/Motherboard, and TechRadar covered it within days. Hola's Luminati brand was described as "the world's largest VPN network," routing HTTP, HTTPS, or TLS requests through millions of idling end-user devices. Luminati (founded 2014) was Hola's mechanism for selling access to its userbase as exit nodes, charging $20 per gigabyte for bandwidth from its free VPN users, and it later rebranded as Bright Data. So the general "your free app is secretly selling your connection as a proxy" pattern is a 2015 story, not a 2026 one. The smart-TV-specific angle: February 2026 The TV angle specifically is much newer, and predates the IncludeSecurity teardown by about three and a half months. Independent tech journalist Janko Roettgers broke it in his Lowpass newsletter (syndicated by The Verge) in late February 2026: with Bright's SDK, a viewer's smart TV becomes part of a massive global proxy network that crawls and scrapes the web, alongside apps on desktop PCs and mobile devices, with the company claiming roughly 150 million such residential proxies worldwide, gathering data later resold to train AI models. Multiple later write-ups explicitly credit this as the origin point: "Lowpass, syndicated by The Verge, first surfaced the smart-TV angle in February, and this is the technical teardown." The AI-scraping tie-in and platform response: 2025–early 2026 Around the same period, the broader AI-scraping-via-residential-proxy story was already building: Krebs reported in October 2025 on botnets like Aisuru fueling large-scale AI data harvesting, and Google dismantled the criminal IPIDEA proxy network in January 2026. By April 2026, FlatpanelsHD was reporting that Amazon, Google and Roku had restricted Bright Data and similar residential proxy networks from their app SDKs (Fire TV, Google TV, Roku OS), while Bright Data continued listing LG's webOS and Samsung's Tizen as partners, with over 200 apps on webOS alone. Your June 2026 post: the deep technical teardown The IncludeSecurity/Buchodi post you linked was the first to actually reverse-engineer the SDK rather than just report on the business model — documenting the peer channel's weak authentication and the iOS VPN bypass — which is why it got picked up so widely (Hacker News, Krebs, CyberSecurityNews, etc.) even though the underlying phenomenon was already known. Aftermath A follow-up Spur.us platform scan in June 2026 quantified the scale: Bright Data, Bright Data Ltd, and Bright SDK accounted for 367 proxy-flagged apps in their dataset, with residential proxy SDKs found in nearly half of scanned LG webOS apps and over a quarter of Samsung Tizen apps. And just last week, Krebs on Security reported LG moving to ban these SDKs from its smart TV apps entirely. So the short answer: the general practice (apps quietly monetizing users' devices as residential proxy exit nodes) was first exposed in 2015 with Hola/Luminati; the smart-TV-specific version of that story broke in February 2026 via Lowpass/The Verge; and your June 2026 link is the deep technical forensic follow-up, not the original discovery.
  • High-Quality Chaos | daniel.haxx.se

    cve security curl libcurl slop
    1
    1
    0 Votes
    1 Posts
    52 Views
    grahamperrinG
    https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/ via https://mastodon.social/@bagder/116448188069484288 (2026-04-22) – not recent, but it's news to me. From today's post about last month's Ottawa FreeBSD Developer Summit: Michael Winser – Alpha Omega – The Changing Landscape of Open Source Software Security AI has entered the chat A frame from Winser's presentation: [image: 1785197784883-9a762f41-ee1e-471a-9e56-b4100b9d01a5-image.jpeg] Daniel Stenberg on AI in security ― sentiment over time From Stenberg's blog post: … Everything is AI now Almost every security report now uses AI to various degrees. You can tell by the way they are worded, how the report is phrased and also by the fact that they now easily get very detailed duplicates in ways that can’t be done had they been written by humans. The difference now compared to before however, is that they are mostly very high quality. The reporters rarely mention exactly which AI tool or model they used (and really, we don’t care), but the evidence is strong that they used such help. We are not unique I did a quick unscientific poll on Mastodon to see if other Open Source projects see the same trends and man, do they! Friends from the following projects confirmed that they too see this trend. … Additional tag: AI ― #ai is currently not possible in (NodeBB) BSD Cafe Billboard.
  • bzfs-1.23.0 is out : r/zfs

    zfs openzfs freebsd bzfs
    1
    5 Votes
    1 Posts
    123 Views
    grahamperrinG
    https://www.reddit.com/r/zfs/comments/1uo72bi/bzfs1230_is_out/ … bzfs is a CLI for reliable ZFS snapshot replication using zfs send/receive and SSH. It is meant for the boring-but-important corner of infrastructure where "probably replicated" is not the vibe. The main bit in this release: bzfs can now drive recursive resumable ZFS stream packages …
  • This topic is deleted!

    1
    1 Votes
    1 Posts
    10 Views
  • 0 Votes
    3 Posts
    73 Views
    grahamperrinG
    Thanks, I deleted my duplicate!
  • Only IT Meme (image, photos, …)

    22
    3
    1 Votes
    22 Posts
    786 Views
    grahamperrinG
    [image: 1782175305024-76e6fcd1-27f9-4871-b6a4-9e6afb51c7e0-image.jpeg] https://anonsys.net/display/bf69967c-166a-39c2-0b07-20f210082765#gallery-209712756 @scriptkiddie@anonsys.net
  • OpenZFS is amazing

    openzfs zfs kubuntu linux
    4
    0 Votes
    4 Posts
    183 Views
    grahamperrinG
    hardware corruption?! Sometimes, errors occur when the USB connection is physically disturbed. Other times, there's no obvious explanation. I might be hands-off, with my cat nowhere near, at the time.
  • Code formatting representation in Mastodon

    nodebb mastodon code formatting
    3
    2
    1 Votes
    3 Posts
    156 Views
    grahamperrinG
    Sorry, I omitted a link to the affected post. It's now linked from above. Note the lines in the original. The representation in Mastodon is wrapped, no line endings.
  • 1 Votes
    1 Posts
    94 Views
    grahamperrinG
    https://thesiliconreview.com/2026/06/cybersecurity-incident-oracle-peoplesoft-shinyhunters-breach It's a sensationalist article, which is not a bad thing in this case. Less sensationally, but critical (9.8/10): Vulnerability in the PeopleSoft Enterprise PeopleTools... · CVE-2026-35273 · GitHub Advisory Database For the other three vulnerabilities, all moderate, that are mentioned in the article: Vulnerability in the PeopleSoft Enterprise PeopleTools... · CVE-2026-21934 · GitHub Advisory Database Vulnerability in the PeopleSoft Enterprise HCM Shared... · CVE-2026-22019 · GitHub Advisory Database Vulnerability in the PeopleSoft Enterprise FIN... · CVE-2026-34299 · GitHub Advisory Database This week's breach is all over the news, I first found it at https://mastodon.opencloud.lu/@BrideOfLinux/116737809000928257 from @BrideOfLinux@mastodon.opencloud.lu Before Oracle responded: Is this true? I have not seen a report yet who is affected. : r/oracle
  • To anyone promoting generative "AI" in any space...

    5
    1 Votes
    5 Posts
    274 Views
    etrigan63E
    @grahamperrin That was poorly written. Better said that a whole lot of money is being dumped into marketing these product before they are fully baked.
  • OpenSats

    bitcoin foss charity education research
    2
    0 Votes
    2 Posts
    145 Views
    grahamperrinG
    For the record: I don't use Bitcoin, or anything like it. I learnt of the organisation through Git commit log messages for an open source project – OpenSats Initiative is a sponsor.
  • 1 Votes
    1 Posts
    124 Views
    grahamperrinG
    https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA). PDF, 44 pages. Context Open source organisations weigh in on age attestation Availability Noted in Reddit: … easily found with Google – without completing Black Duck's form, which requires a business email address: https://www.google.com/search?q="2026+Open+Source+Security+and+Risk+Analysis+Report"+PDF&udm=14 …
  • 0 Votes
    1 Posts
    215 Views
    grahamperrinG
    https://lists.nongnu.org/archive/html/qemu-devel/2026-05/msg07614.html Until now QEMU's code provenance policy declined any contribution believed to include or derive from AI-generated content. A blanket ban was easy to maintain while LLM output was rarely usable on its own, but as the tools improved an absolute prohibition has become harder to justify. … Via QEMU Shifting On AI Policy To Allow Some AI/LLM-Generated Contributions - Phoronix comments discussion in r/linux – the first comment was popular but confused, I responded mentioned in Policy for AI/LLM contributions (#697) · Issue · alpine/council boosted in BSD Cafe Mastodon. The email was copied to Warner Losh (FreeBSD), Alistair Francis (WD), Alex Bennée and Peter Maydell (Linaro), and three people at Red Hat.
  • 0 Votes
    1 Posts
    70 Views
    grahamperrinG
    https://www.amnesty.org/en/documents/pol40/0996/2026/en/ This briefing examines how standalone generative AI systems, based on unlawful web scraping, are in conflict with international human rights law (IHRL) and standards through their design, development and deployment. While these technologies promise sophisticated automation and efficiency, they rely on data collection and model training practices that abuse privacy rights, enable discrimination, and threaten freedom of expression and thought. Amnesty International finds that standalone generative AI systems, based on unlawful web scraping, depend on mass invasions of privacy by design, and are fundamentally incompatible with IHRL. As such, Amnesty International is calling for a prohibition of such systems. PDF, 44 pages.
  • 0 Votes
    1 Posts
    98 Views
    grahamperrinG
    https://engineering.oregonstate.edu/all-stories/future-software-when-ai-writes-code-what-do-humans-do Below the four key takeaways, which I'll not quote here: At Oregon State University’s AI Week in mid-April, a panel of academic and industry experts, … confronted a question increasingly central to computing, education, and industry: If artificial intelligence writes most of the code, what role remains for human software engineers? The conversation blended historical reflection, a realistic outlook on the trajectory of technology, and a candid discussion about jobs, changes to university curricula, and public anxiety surrounding AI’s rapid advance. … Additional tag: #AI (can not be entered in NodeBB).