IndieWeb post types
This content type is full of IndieWeb post types, which are all content types which allow me to take greater ownership of my own data. These are likely unrelated to my blog posts. You can find a better breakdown by actual post kind below:
Post details
This week did not show us weakness in Log4J, Java, or open source. It showed us their relevance and resilience. My🤘🏻to the folks keeping us safe with timely workarounds, fixes, and communications. This was a masterclass in global incident response.Andrew Lee Rubinger (@ALRubinger)Sun, 12 Dec 2021 07:01 GMT
Post details
from @BlackHatEvents USA 2016: A Journey From #JNDI/LDAP Manipulation to Remote Code Execution Dream Land by @pwntester and @olekmirosh blackhat.com/docs/us-16/mat… now the exploit vector presented in 2016 is the #log4jRCE. attached slide #11 from the presentation below. :)an0n (@an0n_r0)Sat, 11 Dec 2021 12:23 GMT
Post details
since everyone is talking about log4j/supply chains an experiment years ago i calculated 1-bit offset utf8 strings of the top few hundred npm packages and registered packages under them they received thousands of hits per week from machines trying to download and execute themsuzuha (@dystopiabreaker)Sat, 11 Dec 2021 08:06 GMT
Between and I took 5587 steps.
Post details
developer pro tip: the best way to prevent log4j from executing shell commands or querying LDAP is to not allow any user input of any kind
laserllama (@laserllama)Sun, 12 Dec 2021 03:32 GMT
Post details
RT @reathchris as a user i want you to leave me aloneA Christmas Carol 🎄 (@CarolSaysThings)Fri, 10 Dec 2021 07:49 GMT
Post details
RT @Ryan_Ken_Acts I perpetually feel like I’m 2 to 3 good back cracks from knowing true peaceA Christmas Carol 🎄 (@CarolSaysThings)Fri, 10 Dec 2021 07:38 GMT
Post details
Gotta love Hermes: “We left the parcel on your porch” In the picture: not my gd porch 😒A Christmas Carol 🎄 (@CarolSaysThings)Fri, 10 Dec 2021 17:40 GMT
Post details
RT @UrbanNathaliaA Christmas Carol 🎄 (@CarolSaysThings)Thu, 09 Dec 2021 22:38 GMT
Post details
we’re calling this thing the Yule Log4j, right? cuz in the dark of winter we’ve gathered together to watch it burn?gemily son of glóin (@themortalemily)Sat, 11 Dec 2021 18:23 GMT
Post details
Running Tycho?
Post details
The Discuss (@TheDiscussPod)Sat, 11 Dec 2021 21:24 GMT
James S.A. Corey (@JamesSACorey)Sat, 11 Dec 2021 22:41 GMT
Post details
Maintainable open source is not an easily solved problem. And yet most of our tech stacks would shut down if open source code was all of a sudden unavailable.Laurie (@laurieontech)Sat, 11 Dec 2021 22:44 GMT
Post details
As someone who does this quite often, they are not ignoring you. They are overwhelmed. They are forgetful. They are trying to figure out what it means to care for themselves and actually do it. They do not hate you. They, in fact, probably miss you.
Amy Gaeta (@GaetaAmy)Wed, 08 Dec 2021 03:37 GMT
OK, so the point of the tweet wasn't anything related to where you were quoting (the ongoing log4j issue) and just a chance to complain about Okta?
Post details
there is a cat!!! at this party!!! twitter.com/himaisie/statu…Post details
party outfit
maisie 🔔 🏳️⚧️ (@hiMaisie)Sat, 11 Dec 2021 12:56 GMT
maisie 🔔 🏳️⚧️ (@hiMaisie)Sat, 11 Dec 2021 21:57 GMT
Why the hate for Okta using a very well deployed and useful logging library?
Post details
The Apache Log4j project is maintained by three people who are volunteering their spare time. Please don't be a jerk to them because multi-billion dollar companies are using their tool without even bothering to throw $1,000 their way.
Post details
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. twitter.com/shipilev/statu…Volkan Yazıcı (@yazicivo)Fri, 10 Dec 2021 16:55 GMT
Catalin Cimpanu (@campuscodi)Sat, 11 Dec 2021 17:41 GMT
Post details
It took me about 5 minutes to start locally running an open source Ruby project despite the fact that I never touched Ruby on Rails in the past & project itself didn’t have related docs. Now that’s what I call strong external community resources that are easy to find 👏Cake is Kate. Always has been 💫 (@kefimochi)Sat, 11 Dec 2021 23:27 GMT
Post details
This is a “vaccination” for the log4j vulnerability Given a vulnerable piece of software, it exploits the log4j vulnerability, just to install a new piece of code that prevents exploiting it in the future Ethical? github.com/Cybereason/Log…Daniel Feldman (@d_feldman)Sat, 11 Dec 2021 16:21 GMT
Post details
It's incredibly annoying to see a snickering gallery of technologists laughing at the log4j vulnerability because it's Java. It's sophomoric and they should grow up and get over themselves.
John Graham-Cumming (@jgrahamc)Sat, 11 Dec 2021 17:46 GMT
Post details
The market rate of a developer who can maintain a large open source project is at least $300k/yr. (Conservatively, check levels.fyi.) The most I've seen someone rack up on GitHub Sponsors and Patreon is like $1,000/month. You see the problem?Filippo ${jndi:ldap://filippo.io/x} Valsorda (@FiloSottile)Fri, 10 Dec 2021 22:58 GMT
Post details
This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. "I work on Log4j in my spare time" "always dreamed of working on open source full time" "3 sponsors are funding @rgoers's work: Michael, Glenn, Matt" People, what are we doing.Filippo ${jndi:ldap://filippo.io/x} Valsorda (@FiloSottile)Fri, 10 Dec 2021 22:58 GMT
Post details
orgs: hire an oss strategy person to do this for your entire product portfolio. add in “what does the project need” to the “how is this being funded?” question eng: do this for your tech stackPost details
fun exercise for folks with production code in github: go to the Insights tab in your repo and navigate to the Dependencies page. pick a package that looks interesting and find out how it's funded.shelby spees (@shelbyspees)Sat, 11 Dec 2021 16:34 GMT
p🍐ris (@ParisInBmore)Sat, 11 Dec 2021 16:38 GMT
Post details
fun exercise for folks with production code in github: go to the Insights tab in your repo and navigate to the Dependencies page. pick a package that looks interesting and find out how it's funded.shelby spees (@shelbyspees)Sat, 11 Dec 2021 16:34 GMT
Post details
This may seem like overkill, but it's really an investment in your company's stability. #OpenSource may reduce many costs of development, but it's not entirely free. Don't find out that the library that's integral to your infrastructure is un(der)-funded when it's too late.Post details
orgs: hire an oss strategy person to do this for your entire product portfolio. add in “what does the project need” to the “how is this being funded?” question eng: do this for your tech stacktwitter.com/shelbyspees/st…p🍐ris (@ParisInBmore)Sat, 11 Dec 2021 16:38 GMT
julia ferraioli (@juliaferraioli)Sat, 11 Dec 2021 17:53 GMT
Post details
WholesomeMemes (@WholesomeMeme)Sat, 11 Dec 2021 12:59 GMT
Post details
Googling to learn more about the #Log4J vuln and google helpfully let me know that log(4) J is 0.602059991 joulesEdwin (@ed___wins)Fri, 10 Dec 2021 23:17 GMT
Post details
the dirty secret is that sound works just fine on linux. it's a just a lie told by the linux-using devs to get out of conference zooms with windows-using management.
Grant Horwood ↙↙↙ (@gbhorwood)Fri, 10 Dec 2021 19:16 GMT
Post details
No one is paying the log4j2 maintainers!? There is a whole page on the responsibilities of a @TheASF "Project Management Committee"... AND NO ONE IS PAYING THEM? apache.org/dev/pmc.html Open Source needs to grow the hell up. Yesterday.Post details
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. twitter.com/shipilev/statu…Volkan Yazıcı (@yazicivo)Fri, 10 Dec 2021 16:55 GMT
Filippo ${jndi:ldap://filippo.io/x} Valsorda (@FiloSottile)Fri, 10 Dec 2021 22:58 GMT
Post details
I wouldn’t be surprised if there are some male teachers who keep a list of female students’ 18th birthdays 🥴🤢
GDP Misleads (@GDP_Misleads)Fri, 10 Dec 2021 17:01 GMT
Post details
Sending hugs to Log4J people. This must be an extraordinarily shitty Friday for them.
Post details
If you're running a server with #Log4J, please add the following JVM argument to your command line immediately to protect against a 0-day exploit. -Dlog4j2.formatMsgNoLookups=true lnkd.in/gHmEFJ9w #Java #Security #InfosecBruno Borges (@brunoborges)Fri, 10 Dec 2021 06:07 GMT
Aleksey Shipilëv (@shipilev)Fri, 10 Dec 2021 15:26 GMT
Post details
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns.
Post details
Sending hugs to Log4J people. This must be an extraordinarily shitty Friday for them. twitter.com/brunoborges/st…Aleksey Shipilëv (@shipilev)Fri, 10 Dec 2021 15:26 GMT
Volkan Yazıcı (@yazicivo)Fri, 10 Dec 2021 16:55 GMT
Post details
Tony Hawk is proof that no one would think Clark Kent is Superman
Post details
At coffee shop this morning: Girl behind counter: (not joking) “has anyone told you that you look like Tony Hawk?” Me: yes, so much that I sometimes write about it. Her: haha, here’s your coffee Other girl by exit: (leans toward me as I walk out): “you really do look like him”Tony Hawk (@tonyhawk)Fri, 10 Dec 2021 16:17 GMT
andrew 🏳️🌈 (@McFreakinAndrew)Fri, 10 Dec 2021 16:59 GMT
Post details
At coffee shop this morning: Girl behind counter: (not joking) “has anyone told you that you look like Tony Hawk?” Me: yes, so much that I sometimes write about it. Her: haha, here’s your coffee Other girl by exit: (leans toward me as I walk out): “you really do look like him”Tony Hawk (@tonyhawk)Fri, 10 Dec 2021 16:17 GMT
Worse is that the replacement should still be working 🙃
Post details
Love that the Levi’s shop app used \n\r instead of \r\n
Ryan Pepper (@drpeps92)Sat, 11 Dec 2021 09:59 GMT
If any of y'all are using #Localstack with Java Lambda projects, I'd recommend updating to v0.13.1 as it includes stay open mode for docker-reuse so you won't be hitting cold starts on each invocation 🙌
Between and I took 4211 steps.
Post details
someone once broke up with me because they “had a big crush on this random person at a party” and it made them realize they weren’t that attracted to me. I moved on and got married and years later found out that I married THE RANDOM PERSON AT THE PARTY!!!!! Lol suck it
ely kreimendahl (@ElyKreimendahl)Thu, 09 Dec 2021 23:38 GMT
Post details
tell your girl you love her or Pete Davidson will
the King of Salad Island (@torchadub)Thu, 09 Dec 2021 20:29 GMT
Post details
He's making a list, And checking it twice, You're gonna find number 8 Very hard to believe. Santa Clause is working for Buzzfeed.Olaf Falafel (@OFalafel)Fri, 10 Dec 2021 13:32 GMT
Post details
This log4j exploit = remote code execution in basically everything Arbitrary code execution in iCloud, Twitter, Steam, CloudFlare, Amazon, Tesla, Baidu, Tencent This may well be devastating 0day RCE exploit that has ever been dropped in all of history. github.com/YfryTchsGD/Log…Mustafa Al-Bassam (@musalbas)Fri, 10 Dec 2021 13:28 GMT












