Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Sebastian Cohnen

@tisba@ruby.social
mastodon 4.7.3
  • Open on ruby.social

Developer 🤓 – Consultant 👔 – Load Tester 🚀

Mostly en, unless only de makes sense in the context.

#nobots

163 Followers
608 Following
50 Posts
Joined September 24, 2018
Github:
https://github.com/tisba
Codeberg:
https://codeberg.org/tisba
Location:
Cologne, Germany
lang:
en,de
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago
I learned the other day, that I must assume MUCH less I know about the implications the "AI” bubble has when talking to others. A good friend of mine, well educated, PhD in Psychology, is o/c aware of psychological issues caused by "AI”. She was completely unaware of the absolute reckless and exploitative behavior of the industry. I only noticed, b/c she was complaining about how expensive new notebooks are and was VERY surprised why this is the case. For her “AI” was just a “free service”.
251
18
161
2
Open post
Sebastian Cohnen @tisba@ruby.social
· 2mo ago
Naming heat haves after petrol companies is an excellent idea! https://mastodon.social/@dmian/116930053970724530
mastodon.social

Dmian 🇪🇺: "The “Saudi Aramco” #heatwave is starting in Spain…" - Mastodon

8
0
5
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago

Haven't seen a big splash in the (IT) news yet, but apparently there is a 16 year old vulnerability in KVM which can be used to escape a guest and even take over the host (CVE-2026-53359): https://github.com/V4bel/Januscape. If /dev/kvm is available (world-writable on the host), it can also be used as a LPE to root.

This is kind of bad. REALLY bad.

GitHub

GitHub - V4bel/Januscape

Contribute to V4bel/Januscape development by creating an account on GitHub.

4
0
1
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago
Replying to
@isotopp@infosec.exchange Hatte Max Schrems schon immer so eine Sharpie Unterschrift? Ich musste jedenfalls gut lachen, als ich das in dem noyb Schreiben gesehen habe! https://ruby.social/@tisba/116838245851456014
ruby.social

Sebastian Cohnen: "The Sharpie-style signature of Max Schrems signat…" - Ruby.social

4
1
1
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago
Replying to
@cwebber@social.coop with all the recent kernel LPEs, containers won’t help much. So maybe… run everything in microVMs now? 🫣
3
7
1
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago

Copy Fail (https://copy.fail/, CVE-2026-31431) is a good reminder why I don’t want to run CI jobs only in containers.

It would be great to get some momentum to https://code.forgejo.org/forgejo/forgejo-actions-feature-requests/issues/4 (microVMs for forgejo actions). At least on bare metal (or nested VMs with nested KVM) this would make things a lot safer. It would also simplify the usage of containers/docker in CI jobs without compromising security, which is kind of a pain with Codeberg Action currently.

#security

Copy Fail — 732 Bytes to Root
Xint

Copy Fail — 732 Bytes to Root

CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.

5
0
5
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@abies77 @moira @sebsauvage looks like they already reverted the change, at least in part: https://github.com/microsoft/vscode/pull/313931/changes tldr: When you set “chat.disableAIFeatures: true” it will be disabled too.
github.com
3
0
1
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

People on the internet trying to look smart by saying "not vibe coding" is like "not using a calculator”. Quite an evolution to the "like not using compilers” I have to listen to in person.

2
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago

Aside from the abysimal uptime Github currently presents, they -also- had one of the worst security incidents you can think of: An RCE via a simple “git push” with total loss of tenant isolation (via https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854).

If GitHub weren't such a central piece of infrastructure, the current situation would be disastrous for their business.

I am afraid this is just the beginning. #github #security

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
wiz.io

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog

A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.

3
4
5
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@diazona@techhub.social for a library, this kind of makes sense. But for an application that you develop this feels off. In Ruby, for example, most applications use Bundler, which allows to specify dependencies and it creates a lockfile. The lockfile is obeyed automatically, so CI, all developers or on deployment, you are guaranteed to get the exact same and expected versions. Ruby gems (Ruby libraries) don't have lockfiles, but rely on version constraints.
1
1
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

In a #Rust application, why would I specify a dependency version in Cargo.toml, if I don’t care about a specific version? Like using “*" by default.

Cargo.lock would contain a concrete version, so stuff doesn't break randomly, everybody gets the exact same version. If there is an incompatible change, you can add constraints, like limiting it to version “2” for example.

ruby.social

Ruby.social

1
5
1
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@FND@hachyderm.io Why using such a youngling like Python when LISP is really all you will ever need? It’s actually pretty impressive how much stuff was already around in 1970!
1
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@FND@hachyderm.io I’m sorry to inform you that JSON and Github was also conceived quite a bit after 1970 😂
1
3
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

Nice "hack" to get all your gists from Github, including private ones by @FND@hachyderm.io: https://prepitaph.org/snippets/gist-exfil/

prepitaph.org

Exfiltrating GitHub Gists | prepitaph

Everyone’s leaving the dilapidated slop factory. My own efforts were stumped by GitHub’s account-data export being incomplete: Gists were missing. Recovering them was a matter of assembling a couple of throwaway scripts.

1
7
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@halfbyte@ruby.social @bitboxer@mastodon.social @janl@narrativ.es @rmehner@chaos.social I'd actually like mailing list or forum (or similar), if it is about discussing (a document). Works great to have a slowed down (?, “entschleunigt”) conversation IMO.
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@halfbyte@ruby.social if this wasn’t clear already: I’m in!
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@halfbyte@ruby.social @_davd@mastodon.social I agree. Commercial hosting is quite a different beast, even for SMBs. Doesn't mean that they are in direct opposition to one another, but commercial hosting is a business, IMO.
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@halfbyte@ruby.social @_davd@mastodon.social https://codeberg.org/Codeberg/org/src/branch/main/TermsOfUse.md is pretty clear about it, only Free and Libre Open Source Software (§ 1), private repos included (§ 2, Sec 2).
Codeberg.org

org/TermsOfUse.md at main

org - Official Codeberg Documents and their unofficial translations.

1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@moonglum@yakshed.social oh, got confused by your double negative 😅 depending on specific needs I’d say options for self-hosting everything but CI are pretty good these days.
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@mntmn super fascinating to follow! Is there or will there be an option for a mobile LTE/5G modem for the MNT Reform Next? Sorry in case it's already answered and I missed it somehow 🫣
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@hukl@chaos.social to be fair, comparing lossless PNG with (in your example) lossy AVIF is of course resulting in good savings 😀 Out of curiosity, what kind of images have you converted? E.g. In the past I used to stick to PNG (with pngquant) for screenshots, because I've bitten too often with weird color issues.
1
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@janl Ich habe seit quasi immer ein Technoline BC 700. Das kannte ich schon aus den 90igern von Zuhause und war damit immer gut zufrieden. Ich glaube Technoline vertreibt die Dinger lediglich, aber die waren vor 1-2 Jahren echt super und haben mir gegen Portokosten ein neues Netzteil geschickt.
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@janl Wäre total super, wenn sich Akkus mit einer Seriennummer (oder so) dem Ladegerät zu erkennen geben könnten, so dass das Ladegerät ab und an mal die Kapazität ermitteln kann und das dann maschinenlesbar macht. #wishfulthinking Ich mache das gerade manuell ab und an um alte eneloops aussortieren zu können. Aber das ist alles andere als ein gelöstes Problem - für mich zumindest.
1
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@halfbyte @marijn It’s a little outside my area of expertise, but I'd like to see some kind of microVM-based setup, so that you can do basically what you want in your CI job, with much better levels of isolation.
1
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 1mo ago
Observation: If you are learning a new language (for me #Rust atm), you don't quite know yet what existing go-to libraries are and you start searching around. Maybe that has always been the case in some form, but the amount of vibe-coded, only 1-2 releases in total, still with clear bugs and issues and then abandoned is just CRAZY. Sure, I'm still learning and certainly not quick understanding why something doesn't work, but I've literally wasted many hours already b/c of slop-crates 🤬
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@hukl@chaos.social Ich denke man kann die beiden Beine kaum so massiv bauen, damit es nicht wackelt. Oder anders: Mit 4 "normalen" Beinen wird es vermutlich immer besser sein, wegen #Physik und so 😅 Aber will dir deinen neuen gar nicht madig machen! Weniger wackeln = mehr gut :)
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@_davd@mastodon.social @halfbyte@ruby.social codeberg only allows FOSS. Not everything is open source ;)
0
3
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@ehashman@cloudisland.nz funny that IPv6 is only mentioned in two places, each with exactly the same two sentences!
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

What is this? Some kind of spammy cold calling/outreach? I most certainly did not trigger this. The email looks very legit (as in comes from Anthropic). It's sent to an old email I basically don't use anymore.

0
3
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@marijn The best part of GH Actions is (or nowadays used to be) that it basically just worked and is basically free. But you could do almost anything with it, including running/building docker images etc. That’s something I miss at Codeberg and where I haven't found a good replacement so far.
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@bitboxer@mastodon.social @halfbyte@ruby.social A coop offering commercial services needs some infrastructure, employees/contractors anyway, so the issued capital requirement of 30k is probably not the biggest problem. That said, I have no idea what this all entails additionally and if this is even a good idea. My thought was just that such an effort might be worth thinking on an European level.
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 2mo ago
Replying to
@koehntopp@infosec.exchange Problem als “gelöst" im Thread markiert. Falls der FinTS Zugang durch zu viele Versuche gesperrt wurde, muss man sich selber drum kümmern. Ach und wenn es gut läuft 🤞 geht's vielleicht am Donnerstag auch wieder - natürlich nur sofern der Zugang nicht durch den Fehler der Bank gesperrt wurde… 🙄 (Ich bin allerdings froh, dass es wenigstens noch ein paar Banken gibt, die überhaupt FinTS anbieten.)
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago
Replying to
@jaseg@chaos.social @cwebber@social.coop Didn't know about QubesOS. Quite interesting, thanks! Memory safe languages are also a viable option for avoiding this kind of issues (if I understood the bug correctly). In the end it boils down to what always has been a good idea: defense in depth.
0
3
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 2mo ago
Replying to
@koehntopp@infosec.exchange diese Support-Simulation, die die comdirect (und andere) da mit ihren Foren fahren, ist wirklich furchtbar und eigentlich eine Frechheit.
0
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3mo ago
Replying to
@jaseg@chaos.social That's a little outside of my expertise, but my understanding is that a memory safe language could have helped in this particular case. But I don’t want to argue with you - there is certainly no general applicable and simple solution.
0
1
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@hukl@chaos.social @sesamzoo@mastodon.social super! Vielleicht hatte ich auch einfach nur Pech ;) Aber ich fand das immer so nervig, wenn man ganz ausgefahren war, sich dann mal kurz mit den Ellenbogen abgestützt hat und alles am weckeln ist.
0
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@godfat@mastodon.social yeah, probably. It's just creepy AF coming from an “AI" company. But since the address is pretty old, it's probably in a bunch of “lists" somewhere. Although I have no idea, what someone could possibly get out of this move… 🤷‍♂️
0
1
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

Any #ruby #minitest users in my timeline? Today I tried to understand how to use MiniTest::Mock to expect a method call with some positional arguments, but arbitrary (none or any) keyword arguments.

I think you can’t. It's just not a thing. The only way to do this, is to use the block form with MiniTest::Mock#expect and to all argument matching yourself.

What am I missing here?

Disclaimer: I’m deep in the RSpec camp when it comes to Ruby test frameworks 🫣

ruby.social

Ruby.social

0
4
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@rmehner@chaos.social excellent, thank you! I only have mental bandwidth for a small incremental improvement, and this looks like a step in the right direction.
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@zenspider@ruby.social hey 👋🏻 thanks for confirmation! it's not a very active project, so I probably won't switch the mocking lib. For now I'm using the ENV["MT_KWARGS_HAC\K"] workaround and pass “Hash” as the kwargs.
0
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@luisfcorreia@mastodon.social @halfbyte@ruby.social only open source on Codeberg. https://ruby.social/@tisba/116505529481052434
ruby.social

Sebastian Cohnen: "@halfbyte @_davd@mastodon.social https://codeberg…" - Ruby.social

0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@moonglum@yakshed.social You went with a self-hosted solution for your work project? Interesting. I'm more and more convinced that I don't want to run any kind of self-hosted CI without immutable, throwaway VMs (or MicroVMs). Haven't found a good solution to do this yet :-/
0
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@hukl@chaos.social 💯
0
0
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago

Which one of the #redis drop-in replacements is still active and maintained these days?

It’s for the Celery worker of paperless and I'm not exactly sure what is needed feature wise. I was just wondering what you would replace "docker.io/library/redis:8" with in a docker-compose file 😀

ruby.social

Ruby.social

0
2
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 5mo ago
Replying to
@hukl@chaos.social I’m curious how sturdy the desk is fully elevated. I got so annoyed by various two-legged desks, that I bought one of the very few four-legged ones I could find deliverable in Germany in 2021 (nowadays they are easier to find). No more wobble, even when fully elevated, with monitor arm and camera on top.
0
7
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 4mo ago
Replying to
@FND@hachyderm.io I would have used jq to get the repo URLs, but vim also works, I guess 😅
0
5
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 3w ago
Replying to
@FRYTG@beoriginal.social in case you didn't know: If your mac is reachable over the network and by "unlock" you mean the initial FileVault unlock, you can do this via SSH (at least since macOS 26): https://support.apple.com/en-euro/guide/security/sec8447f5049/web I'm also looking for a reason to get one of those 😅 They are really neat and do support Tailscale/Headscale out of the box. Direct support for WireGuard is also discussed https://github.com/jetkvm/kvm/issues/66 🤞
Apple Support

Managing FileVault in macOS

On devices with macOS, organizations can manage FileVault using SecureToken or Bootstrap Token.

0
1
0
0
Open post
Sebastian Cohnen @tisba@ruby.social
· 2mo ago
Replying to
@alexia@shrimp.starlightnet.work it would be crazy to make this a paid-only feature… Trading payment info for phone numbers is not good for many cases where privacy is a concern. „It’s unclear whether this means that registration without a phone number will become a paid feature.“
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:48:41 UTC