sam
@sam@cablespaghetti.dev
819 following, 775 followers
https://cablespaghetti.dev/hosting-a-fediverse-instance-on-an-original-raspberry-pi.html
⚠️ Maintenance:
For maintenance and security reasons all nodes have been urgently updated and rebooted at 11 AM UTC+1. If your workloads are not running anymore, please start them again from your control panel!
cc: @gyptazy
Let the planning commence
Chalk lines covered over with ink and wiped away, leaving me with the lines to go over
Just curious, are the curves freehand?
@cazabon Yep. Everything but straight lines (for which I use an extremely paint-covered spirit level/ruler)
Whee.
It's just had the protective anti-UV coating put on it but once that's dry it's ready to go!
@babe ohhh i didn't know that coating existed, that's really neat
@FrazzledBrynn You can get it as a spray on varnish and a brush on varnish. I've never found one that I like for watercolours but there's a lot of good options for acrylic
@babe Ohh nice! I did wonder about watercolour, but I guess there's probably protective frames for those or something
@FrazzledBrynn There's a bunch of options available but the ones I've tried so far I've had either poor or mixed results with, even going very lightly with them :|
@babe Non-artist here. Is that to prevent sun damage?
And out of curiosity, does it change its characteristics under a blacklight?
@me Even with really good paints, sometimes pigments can fade with prolonged exposure to sunlight. Anti-UV varnished protect the pigment long term and prevent that breakdown.
I have no idea on the blacklight front, though if someone were to specifically request one without it I'd be happy to oblige with the understanding sunlight could be more likely to negatively impact it
It’ll be going on the wall of the office I spend most of my time in, after we move house soon.
@sam Oh wow, you scooped that one up quick! lol
There's something about them that just sings to me, it's hard to put my finger one what it is.
I've got it all packaged up and I should be able to get it sent out tomorrow for you 
Who’s to say at what point your brain will decide it’s has enough of doing these and the supply will dry up. 😝
@warandpeas In the future, we're going to refer to this stuff as "organic content" and you're going to pay a lot more for it.
@warandpeas "Cmon! 600 Token. All genuine. All good stuff. Look at this! All handwritten on paper, with a pencil! Man! A fricking Pencil!"
@warandpeas
YouTube has figured out that I'm not interested in all that AI crap and now only recommends videos that are more than four years old.
I love this AI! ❤️
EDIT: Translated using Deepl AI.
@warandpeas Based. This makes me think of a song that I love dearly: "Those left standing will make millions,
Writing books on the way it should have been"
"Warning" by Incubus on their album "Morning View"
also:
"Floating in this cosmic Jacuzzi,
We are like frogs oblivious,
to the water,
starting to boil,
No one flinches, we all float face down"
Thank you for the wonderful art!
@warandpeas Yeah, but the trouble with street books is the dealers are cutting that shit with AI slop.
@warandpeas It's already happening. A lot of people are advertising their stuff as "made by a real human" or "no AI".
@warandpeas I'd totally love to see a sequel of Fahrenheit 451 where real books are outlawed now in favor of AI generated ones.
New by me - Microsoft Vibing. A very strange fake open source project published by Microsoft employees, which gathers screenshots and voice recordings of users with unique machine identifiers attached. Not sure how this one has happened.
This Vibing one is a fun blog btw as every page it gets to be a bigger version of this
Since publishing my blog, Yaoyao Chang, who authored Vibing, has removed references to it from Microsoft’s VibeVoice repo - marking the change as “removing outdated links”. https://github.com/microsoft/VibeVoice/commit/e73d1e17c3754f046352014856a922f8208fb5d3
@GossiTheDog this is all very surreal 🫠
On the other hand, Microsoft could be preparing a new season of their Standards of Business Conduct training "Trust Code" in the wild 😂
I withheld a load of details from the blog on this so far btw, if you're a researcher and want a laugh pull the binaries and have a look at what the MS Research team were doing and poke the backend.
Something tells me Microsoft are going to end up freezing the Azure backend for Vibing and having a security incident.
Vibing has been suspended and downloads removed pending a compliance review by Microsoft. https://github.com/VibingJustSpeakIt/Vibing
Also worth noting - Yaoyao Chang made the changes to the Vibing-Team repo, which is the first time Microsoft has officially been linked to Vibing.
It’s a very strange situation where MS were covertly operating an AI service, while pretending it was an open source project.
@GossiTheDog I feel like I'm being led into a Cyberpunk questline; with the unplanned discovery of a Redmond deniable op harvesting data out of a front operation.
Vibing has been made unavailable for download from Microsoft Store:
Microsoft are now trying to hide the compliance review message, by removing the download links and removing the compliance review messages on Github. https://github.com/VibingJustSpeakIt/Vibing/commit/ab8e6302543754685f85cf02e02d1d0287d2f4f0
Did anybody happen to the screenshot or archive the Microsoft Vibing website ( https://vibingjustspeakit.github.io/Vibing/ ) and Github ( https://github.com/VibingJustSpeakIt/Vibing/ ) showing the compliance suspension messages before they were deleted? The changes are archived on GitHub, but I'd like to document what they looked like prior to removal.
@GossiTheDog https://infosec.exchange/@simonpoirier/116459614756235115
It is just the suspension message
An attempt to hide the MS link with Microsoft Vibing on GitHub - “This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.” - the commit hiding the compliance review has been redone today without Yaoyao’s name on it.
New commit: https://github.com/VibingJustSpeakIt/Vibing/commit/84c82ccad2092b4bc2dffe5c96ef8c8d4466cc6e
Hidden commit: https://github.com/VibingJustSpeakIt/Vibing/commit/ab8e6302543754685f85cf02e02d1d0287d2f4f0
So @dangoodin asked Microsoft about Vibing - they’ve confirmed it is a Microsoft research project. They say “We have removed the application as we review its functionality and adherence to our policies. We remain committed to responsible AI and are taking appropriate steps as part of this review.”
Here's a question - re the Microsoft Vibing thing.
Microsoft didn't disclose they were behind Vibing, multiple staff pretended on Github it was an open source community project (it wasn't), one specifically said they weren't involved (they were), they collected screenshots and mic recordings, and it had no security, compliance or AI review by Microsoft.
Is that okay?
@GossiTheDog I think it is less malice and more disorganization.
@Sempf I'm not saying malice, for what it's worth. But is it okay for an org to do that, and then just.. nobody cares? Not a single press outlet covered it, for example. It's just like, yolo, orgs can do whatever they want as it's vibing.
@GossiTheDog No, it really isn't. The market has become more accepting of behavior like that, so there is less rigor in those orgs to prevent said behavior. If the community makes more of a stink there is a chance it will curb itself. But I don't think they were "out to put one over on us" as someone said in a recent article.
Totally. That’s insane. Y’know, I’ve seen some stuff, but reading your blog, this is bad. Probably just a screw up, but they seriously need to get a handle on this and be pressured to do so openly and transparently.
Weird that this hasn’t been much more widely covered. I can see a few sites have repackaged your blog, but I’d expect at least The Reg to cover this. Ideally more.
@GossiTheDog It’s just Vibislop doing typical Viboslop things. Of course it’s not okay, and the company gets wristslapped ever so gently evey now and then for its transgressions. And then carries on doing what it does.
@GossiTheDog
TBH, when I first read your writeup, I didn't believe that it was from Microsoft, the company.
@wdormann it is. I've found more I haven't posted, they've basically been having people pretend to be open source projects to bypass their own governance. But literally nobody gives a shit outside of MS.
I think at this point everyone is numb to the big companies being absolute shitbags when it comes to anything AI related
@GossiTheDog @wdormann "Nobody gives a shit outside of MS" *until someone finds something to sue over* at which point they start pushing for damages from Microsoft. I suspect the question "how much liability does this open up" is one that the people involved have ignored.
When Microsoft formed a fake charity with Charles Koch (worst oil oligarch on the planet after Putin & #PrinceBonesaw ) to force AI adoption by the so-called "lower orders"; what did we think would happen?
Koch Network does nothing but covert ops that further fossil fuel fascism & corporate oligarchy.
AI doesn't help the working class.
https://www.pbs.org/newshour/show/how-online-retailers-are-using-ai-to-adjust-prices-by-mining-your-personal-data
It exploits them.
https://news.bloomberglaw.com/daily-labor-report/states-target-ai-that-tells-companies-how-much-to-pay-workers
https://www.desmog.com/2025/12/11/the-koch-network-is-pushing-trump-to-accelerate-ai-documents-show/
1/
@GossiTheDog absolutely not okay - and the cover up and complete lack of public acknowledgement and attempt at accountability is the worst part of it.
We also don’t know if anything happened internally, a disciplinary process, a review of controls to prevent this from happening again and so on, but that lack of public knowledge is itself part of the problem.
@GossiTheDog hard nope on that. The blatant lying when questioned about it, more than the actual security/privacy infringements, tbh. Covering up rather than fessing up is next level Evil.
@GossiTheDog I’ve been busy the last week and just caught up on all this. oof it kinnnd of sounds like a rogue employee with a data stealing side hustle
@GossiTheDog It seems like a bad look for anyone; and a very, very, bad look for an outfit with substantial cloud offerings that are mostly on a 'trust me bro' basis when it comes to what they supposedly can't or won't do to a customer tenant.
This should be absolutely radioactive for Microsoft; both their response to one or more of their people basically doing malware with company resources and the questions about exactly how well-watched the roles with insider threat potential are or aren't.
@GossiTheDog this reeks of an employee (or small group of them) unilaterally sidestepping process. probably in part because the company culture around rigor has rotted to the point where they thought it was acceptable.
Seriously don't know what to make of this. Rogue employees, sailing under the Microsoft flag? Fake employees?
The app itself is terrifying and stupid. I can easily imagine naïve users interested in AI installing this thing and forgetting about it.
@GossiTheDog oh, it's pretty goddamn obvious exactly how this one happened.
See also: GitHub's official applications abruptly sprouting similar levels of spyware and calling it 'telemetry.'
@GossiTheDog I just reported it through Microsoft Store links. Let's see if anything comes out of it.
@GossiTheDog for what it’s worth, the package family name of this thing is YaoyaoChang.Vibing_ssp53fcyfr9ha - in my opinion it doesn’t seem to look like anything “official”, but rather an employee releasing it on their own partner center account?
@GossiTheDog Now that Microsoft has a 24/7 OpenClaw team in Oslo, I expect a lot more vibe artifacts appearing from within their network...
https://mstdn.social/@jukkan/116449605862675745
Thanks for the heads up, glad i use neither microslop nor rotten apples trojan usa spyware applications.
Bost companys are maga I am not.
The treatment was rm -rf
@GossiTheDog I'm guessing Yaoyao Chang did what I'd be tempted to do, if I worked at MS: Orchestrate some agentic whatever with a prompt like "Pretend you're me, working at MS research and publish an innovative new TTS app on github and the windows store," and then duck out of the office for a couple of weeks, letting that thing answer all emails and github issues.
No I don't really have hyper fixations.... #Seamonkeys
Very tempted to get myself a bigger tank…
Random question. Do you find your monkeys are attracted to the bubbles from the air stones? Some of mine seem obsessed with going for rides…
The cat's out of the bag! My latest book, "The Secret Life of Circuits", is available in early access:
https://lcamtuf.coredump.cx/blog/secret/
It's the reference I wish I had when I was starting out. Electrons to embedded systems, 290+ color illustrations and 420+ pages of well-explained theory.
Lots of them hatched overnight. We’re all having a great time watching the progress!
Any interest in a separate account for daily aqua dragon updates?
Thanks @Tattooed_Mummy@beige.party for sending me down this rabbit hole. 😆
Fergal Sharkey was on #channel4 news inviting us to sign a petition about getting a referendum to bring the water industry back into public ownership
It is here. Do sign and share xxx
@sam yes! Let me know how you get on. I'm now up to three tanks and I'm thinking about a goldfish bowl I have that I might be able to change to a Seamonkey enclosure. I live near the beach and someone I know said you can put seaweed in the tanks for them to eat and play in as well so I'm tempted to try that
Seamonkeys
What’s your setup? I can see some kind of air pump?
@Tattooed_Mummy
Now I no longer need to buy Seamonkeys from the back of a comic book.
I can just watch your video, Tattooed Nonna.
Thank YOU.
PS: I always hated to wait the days -- or weeks -- it took for things to arrive in the mail after I ordered them.
🚨 Trivy is under attack again.
Attackers force-pushed 75 of 76 tags in aquasecurity/trivy-action, impacting 10K+ workflows and turning trusted GitHub Actions into malware.
Any version ≠ v0.35.0 may execute an infostealer in CI.
Analysis forthcoming: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
Been working on a small decentralised music search tool https://squirrel.band/, initially indexing sites using faircamp (by @freebliss).
Currently grabs the sites listed on https://simonrepp.com/faircamp/ and in the webring (https://faircamp.webr.ing/) using each pages available RSS feeds, keen to add more sources if anyone has any suggestions.
An appropriate T-shirt for today.
@neil where can I get one I absolutely need it
@wombatpandaa @neil you steal the design from Neil :-)
And make sure to use the rip off (“stolen”) version of the font like they did on the original campaign….
Ageless Linux: Software for humans of indeterminate age. We don't know how old you are. We don't want to know. We are legally required to ask. We won't.
@nixCraft This website is such an excellent rebuttal to the nonsensical parameters of the Californian law. Funny read!
@nixCraft love this, but the website is very US-centric. This age verification madness is sweeping the whole world.
@nixCraft Here's the #Debian #SystemDCensorD proposal, using D-Bus - "On installation, the user will be required to enter their location. ... This location and user data will be managed by a new daemon, systemd-censord, ... For example, ... a unit for China will implement keyword scans ... debian will need to switch to being a binary-only distribution ... with ... controls to prevent any non-signed software from being installed , written, or compiled, ..."
[1] https://lists.debian.org/debian-legal/2026/03/msg00018.html
@nixCraft is this a joke? or i don't get it. when it requires first the download or e.g. debian, but debian itself requires the age check on install, how can ageless linux work, when you have to run the conversion script after the debian installation?
@nixCraft I love this solution, but what are the plans for hardware providers? I feel like companies that offer Linux pre-installed will be the ones on the hook for ensuring the age verification is there. Will there be California editions that come with no OS?
@nixCraft linux can’t fundamentally do age verification because how it’s built into the system to be local by default and even if something was made you could literally strip it out of the source code so even if a company like Ubuntu added it into something a dev team like Linux Mint would remove that crap anyway.
The law makers really are showing their age being out of touch with technology like my mother and grandmother.
@nixCraft One can assemble your own linux-based operating system from scratch... how's blocking that gonna work?
I would like to drop armhf (armv6) support in #AlpineLinux. The only current hardware I am aware of that is armv6 is Raspberry Pi Zero series (EOL 2030). I don't think it is worth the extra effort to support both armhf (armv6) and armv7 at this point.
Do you think we should drop armhf to free up some resources?
| Lets drop both armhf and armv7 (no 32 bit arm): | 54 |
| Lets drop armhf (armv6) but lets keep armv7: | 67 |
| NOOOOO! Lets keep both armhf and armv7!!!!!: | 52 |
Closed
@ncopa In the embedded/industrial space I'm still seeing a surprising amount of ARM9 and expect those to go on quite a while, but that'd be v5, so even older. v7 seems like a more sensible target for Alpine 32bit support than trying to keep that /and/ v6 on life support together.
@ncopa I have AlpineLinux on an RPi 1 running pi-hole (head-less). More efficient and such a nice experience compared to RaspberryOS.
@mjwin yeah, I guess what I have been thinking so far is that if you still use RPi 1, which OS would make sense to run?
Even if we'd drop armhf now, you could still continue to use alpine 3.23 for a while.
@ncopa i wonder how apk would react if an edge system were to upgrade an upstream had no packages for it. i say that because i upgraded my pi0w 1.1 to edge because i was trying to get mdns to work and i read that avahi2dns and unbound worked.
@ncopa Removing armv7 would have major impact on postmarketOS as we still have many people actively working on devices with such CPUs. On the contrary armhf is pretty much dead.
armhf (and armv7) are very heavily used in education: many schools/universities are using lots of devices in labs to teach computing/coding, as they are so cheap and powerful-enough for this.
That's many users: 1 teacher admin => lots of silent students, and probably new users down-the-road...
#AlpineLinux is ideal distro to learn (small, simple, secure), and one of the last one to support those arch (is a feature, not a reason to give-up).
(poll seems closed now...guess my vote 😉 )
The UK Government has launched a public consultation which is seeking views on whether to ban children from using social media. This consultation will run until 26 May 2026.
It is highly likely that later this year, the establishment will attempt to introduce legislation which forces social media platforms (potentially including Mastodon) and VPNs to verify the age of their users. Therefore, this consultation is likely to be the only opportunity we will have to push back against these authoritarian measures.
Please take the time to read the consultation and answer the questions (especially if you are the parent or carer of a young person):
https://www.gov.uk/government/consultations/growing-up-in-the-online-world-a-national-consultation
Highlight of the #GortonAndDenton #byelection: The #DailyTelegraph sent their man out to talk to Green Party #GPEW canvassers.
It did not go well for him. 😅🤣
Linux 7.0 launches with enablement for Intel Nova Lake, AMD Zen 6 — major kernel update expected in Ubuntu 26.04 LTS and Fedora 44 first
A major kernel update, Linux 7.0, has been officially released. Although it'll take some time to show up in various Linux distros, the kernel comes with preliminary support for AMD's upcoming Zen 6 and Intel's Nova Lake.
#hardware
https://www.tomshardware.com/software/linux/linux-7-0-launches-with-enablement-for-intel-nova-lake-amd-zen-6-major-kernel-update-expected-in-ubuntu-26-04-lts-and-fedora-44-first
Unfortunately plug-in/balcony solar isn’t legal in the UK at this point. There has been talk of legalising it but I don’t think any of it has made it into law.
The UK has announced plans to fast-track legislation requiring “age verification for VPN use”. The correct term, however, is not age verification but identity verification.
A law like this would require everyone to identify themselves in order to use a VPN. This would pose a risk to whistleblowers, violate human rights, and represent yet another step toward an authoritarian society.
The first loop 2 finishers: Sébastien Raichon in 22:35:40; Mathieu Blanchard :42; Damian Hall :44. At the same time, another loop 2 runner has quit and is tapped out. #BM100
Ohhh Iain and Damian are running and the rumor mill is talking about a certain Kilian might be running #BM100 #UltraRunning #BarkleyMarathon
Ohhh and it sounds like Jasmin (not on list) is there too and Emma from Ireland (on list) and some French dudes ;)
The 2026 Barkley Marathons began with one of the strongest fields ever. The starting field came from 15 Counties as well as 15 States, and included ten women. The course seemed not to care. Over 70% of the field is done. #BM100
Water Ballon Guy has begun loop 2, followed quickly by another French guy. Seven runners are on loop 2. #BM100
Moltbook was peak AI theater, less of a glimpse at the future and more of a mirror simply reflecting society's current obsession with AI (Will Douglas Heaven/MIT Technology Review)
https://www.technologyreview.com/2026/02/06/1132448/moltbook-was-peak-ai-theater/
http://www.techmeme.com/260208/p18#a260208p18