

I still don’t know what Tesseract is and now I guess I don’t need to care.
I try to respond to every genuine engagement. I block trolls, contrarians, and provocateurs because life is too short.


I still don’t know what Tesseract is and now I guess I don’t need to care.


Google has simply officially said they won’t block ADB sideloading as part of the change, so it’s the same old ADB install method for unsigned APKs that devs use.
Shizuku uses ADB commands to install apps so it’s much of a muchness there - same thing. Though I speculate Google will start to block Shizuku installs (of the main Shizuku app) from the Gplay store in soonI’m sure due to ‘breech of T&Cs’ of some kind, but really to add more side-loading hurdles.


You can definitely remove the APK, but it’ll just reinstall itself next time Play Store services do their thing. In addition, Google Play won’t allow installation of new apps without approval from the service, so removing it will block install via official GPlay.
The main ways to avoid it to my knowledge are to either go through the official ADB method (if you have official Google Play) or use a de-Googled phone and install via alternative stores eg Aurora / F-Droid.
I like your fancy words, rock person.
Cool work. Would stare at in trinket store for extended time. Possibly even buy (I’m irresponsible).


I did read the text. I suggest you read the article. Microsoft lied and literally called it “expected behaviour”, then silently patched it. Why would they patch expected behaviour?
The exploit discovered and lodged by O’Leary was confirmed independently to exist and function by CERT/CC and they gave it an interim CVE entry. The only reason it was not finalized and publicized is that Microsoft has the right to overrule CVEs as part of the CNA hierarchy rules.
As the researcher said, it’s a privelige escalation bug. So yes, an attacker would need some privilege… But this is still a major vulnerability.
The vulnerability allowed a user with only Backup Contributor (an Azure RBAC role with zero Kubernetes permissions) to trigger this access grant [for the entire Kubernetes cluster].
Azure’s Backup Contributor is a role widely assigned in organizations to their mid and even low-level IT staff. At a Fortune 500 company there may be hundreds of people around the world with that permission to manage their own site’s or office’s backups.
Azure’s Kubernetes Cluster Admin is a much more powerful role. It allows unrestricted access to the entire Kubernetes cluster - including retrieving admin credentials for the cluster via powershell, and accessing or modifying any data on the cluster. How much that could impact a particular environment depends on what services they have containerized into their Kubernetes cluster, but it could be almost anything… web frontend for user logins, a payroll system interface also with logins, etc - attacker would be able to access all that information with some skill. They could also simply install a pod that acts as a backdoor into the whole environemnt and take their time looking through all data to extract what further access they need or want.
That’s why this was assessed by CERT to a CVE rating of 9.9 - critical vulnerability that poses a severe risk.
The bigger issue as I said is not the bug, its Microsoft’s response. Lie, use their power to quash the report, silently patch it, alert nobody. There may be impacted businesses/orgs out there that have been breeched through this vulnerability, and now they will not even know to check their logs, rotate Kubernetes cluster admin password or audit & validate their Kubernetes pods.


Feels like a really, really dumb decision. Has Microsoft forgotten the reason CVEs and bug bounties exist is to bring them to the light of day and prevent them being packaged and sold on the darkweb for abuse?
Or maybe AI tools are just helping researchers identify such a wealth of MS bugs that Microsoft is overwhelmed with notifications and pushing back by aggressively closing them?
Either way - this is a bad choice and will come back to bite them.


Its not as egregious as you think. ‘Everyone’ group means every Synology user account - not that everyone on the network that can talk to the NAS, they’d still need both a Synology account and Shared folder permissions. Any Synology user trying to access those files would still have to have read and write access to the Share to actually access it (eg via file explorer SMB/CIFs or app-level access to Synology File Manager, or they would need to be granted SSH access to get in via terminal, etc) in order to R/w/m the files.
I know it’s a bit confusing, but it’s correct. Docker often causes confusion with file permissions. There are file-level permissions (this article) and there are share-level permissions. You need both to access folders and files via mapped drives / SMB, this setting is just to ensure that Docker containers which can be running as a variety of user names (depending on how you config docker and the container) don’t experience issues accessing files you’re expecting them to be able to access, as Synology says, the default Docker folder permission is for the ‘everyone’ group to have Read-only access. This should allow most Docker containers configs to at least run and then if you run into issues writing/modifying files… That’s a clue you have missed some file permission configuration settings that need to be done, and the only reason it’s running at all is because that default ‘everyone’ permission is saving your butt.


Yep. It’s happening. Ignore the naysayers.
The market share data showing increase is still early to make sweeping predictions on, but that’s not important because the processes driving the uptake are measurable and show consistent trends.
Windows won’t get better. Apple won’t get cheaper. Steam will continue supporting investment in Linux. Linux will continue to get more developers and community support and keep improving from its already very respectable usability.
I use very popular router by Gl.Inet called Flint 2 (GL-MT6000). Goes on special for about $125 USD. Great specs, solid device.
Fully supported by OpenWRT, and I recommend flashing to that so that you have completely FOSS software with no possibly hijinks from the manufacturer’s OEM OS.
You’ll need to read some guides or watch some vids to get you set up on OpenWRT, bit of a learning curve, but it has everything you could possibly need. Check it out.


https://lemmy.world/post/45703415
See this for more evidence.


“Privatize the profits, socialise the costs” may as well be Amazon’s corporate motto by this point.
I feel for sellers who are faced with a slowly shortening list of alternatives to sell their products via to get as wide a customer base as possible, and feel pushed onto Amazon by its ubiquity. It’s a shit service for sellers.


Sir, this is a Lemmy.ml thread.
Reasonable, considered responses are not welcome here.


Don’t be logical. You’re supposed to cry fascist and hurl slippery-slope fallacies like this is the Reichstag Fire.


100% agree.
P. S. Keep the downvotes coming. You only prove the point of the post with your toxicity.


No, entirely incorrect. “bad thing can happen, so it will happen” is essentially a mangling of Murphy’s Law.
In a slippery slope argument, a course of action is rejected [eg: this minor law] because the slippery slope advocate believes it will lead to a chain reaction resulting in an undesirable end or ends [eg: loose claims of a pot getting hotter implying further details will be demanded next].


Yep. Its honestly mild as hell.
Essentially legislation that says:
Its just a standardized system that should have been done ages ago, but was not a priority for standards orgs, so none stepped up - so legislation appeared.
I strongly argue that it should only apply to commercial OSes and app stores though - as they’re the ones that primarily cause issues these laws intent to address.
Linux and FOSS have been caught in the crossfire in a privacy and personal data battle they were not involved in.
Even Windows 7 actually didn’t care if you had no key.
You could leave it unactivated forever and the worst thing that would happen is it would have a “Activate windows” watermark message bottom right over the desktop, and it wouldn’t let you change the personalization settings eg theming (oh no).
Just search. It’s easy. There’s heaps of data on LTT being shit, but particularly in Linus being a greedy, grubby little man.
https://en.wikipedia.org/wiki/Linus_Media_Group
Scroll down to ‘controversy’ and see if that’s someone you want to support.