Damus
Chao-c' profile picture
Chao-c'
@Chao-c'

Nedokončil studia na vysoké škole života. Mužský rod, tykej mi. ADHD. ⁂ 🇺🇳 🇪🇺 🇨🇿 🇺🇦 🇬🇱

Moderator of f.cz. We recycle waste heat of our datacenter. If you read this on bsky I can't interact back unless you follow @ap.brid.gy

SpráFce obsahu instance f.cz. Odpadní teplo datacentra ISP SPOJE.NET, kde tohle běží, se využívá. Solární cyklista, cestovatel. Linuxák, ex-programátor (Arachne), ex-muzikant. Fanoušek kosmického výzkumu, vědy a techniky. Zakládající člen Pirátů. 🐧 🚀 🐘 🚲

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Chao-c' profile picture
We just received about 60 (?) fake account registrations - this time not even trying to pretend any identities, just kind of DDoS.

What it interesting, that this time, they did not use known #TOR exit nodes and the IPs are not known by existing blacklists. Instead, the attack seemed to came from pool of IP addresses owned by Japanese companies and from Japanese mailservers...

We need to figure identity of operators of this botnet. Let's setup some place to share the IP addresses used by botnet. If we want to keep #Fediverse and #Mastodon registration open, we must federate our blocklists too...

CC @nprofile1q...
Chao-c' profile picture
After cca 3 years of struggling with botnet, registering fake accounts on our instance, I finally started to play with some internet security basics.

The first free blocklist I stumbled upon was https://github.com/stamparm/ipsum - because web sites with fancy graphics seem to offer just few free queries and then ask for money (the security game is about money, just like advertising and spam... maybe even more so). The blocklist seems to be mostly list of tor exit nodes and known hacked routers.

Surprisingly, almost all IP addresses where the fake accounts came from were on this list. And in few cases, when won't, the subnet pattern was obvious and my malicious IP was the one the few, which were missing from mapped subnet. So automatic conversion of the ipsum.txt file to list of obvious malicious subnets may be nice challenge for former programmer, like me...

There is API for maintaining Mastodon instance IP block list, but it is just like with closing the registrations (registration approval won't stop bots from attempting). There would be still some chance, that some IPs on the list are by mistake. So I am mostly using the list to verify manual blocking, for now.

Basically, any security based on centrally maintained block lists is doomed by default. It would be nice, if Mastodon (or other future, better Fediverse software) can federate IP blocklist of instances which trust each other, so we can crowdsource the hard work.

#mastodon #ipblock #blocklist #ipsum #tor
Chao-c' profile picture
Stává se zřejmé, že poprvé v historii Vltavské kaskády se do udržování dostatečného průtoku ve Vltavě zapojí druhá největší nádrž - Slapy. Nastane to už ve chvíli, kdy hladina Orlíku klesne na 334,6 m.n.m. V úterý večer už k tomu chyběl necelý půlmetr. Pokles o tuto míru lze očekávat v horizontu zhruba tří dnů, tedy nejspíš někdy v pátek. Vypouštění Orlické přehrady bude dle vodohospodářského řádu zastaveno, pod tuto kótu by hladina klesnout neměla. Od té chvíle začne vypouštění Slapské přehrady, která převezme břímě doplňování průtoku ve Vltavě. To se dosud nikdy nestalo.

https://www.meteocentrum.cz/zpravy/26090101-na-orliku-padl-v-utery-vecer-novodoby-rekord-historicky-okamzik-prijde-uz-za-par-dnu

#czech #climate #orlik #slapy #vltava
Chao-c' profile picture
Dear botnet operators... never mind if Russian operators, operators hired by Russia or operators hired or owned by whatever damned psyops or spam operation it might be:

You should better consider our #fcz instance to be honeypot: big honeypot with rather well backed up database content.

Also, you should better consider Fediverse to be the largest doxing platform for doxing annoying botnet operators EVER.

We shall find you in your mother's basements, we shall find you in your troll farm offices, we shall find your seasteading Starlink connected retreats. We shall find you on the sea bottom, we shall find you on other planets, we shall find you on the far side of the Moon. You will never hide from us.

And also... we will never close our registrations either.
Chao-c' profile picture


Kauza Autistici / Inventati a zabavení jejich .org domény mi přijde v zajímavém kontrastu např. s kauzou proruských webů v ČR, u kterých bylo pozastavení (nikoliv zabavení) fungování domén či umisťování stránek na blacklisty poskytovatelů Internetu po roce 2022 organizací CZ-NIC zpětně shledáno nezákonné.
Chao-c' profile picture
As an ex-programmer (but not really active in any major open source project) I think I can have some opinion on the recent developments in the field of free and open source software.

Of course, I don't want to be dependent on AI generated code.

But keeping running the forks of apps from pre-AI era cannot keep us online forever. However, the problem is much deeper.

As someone, who started coding many years ago, when 8bits and later MS-DOS based PCs were relatively simple and straightforward, I could not ignore, how the entry barrier for participating in software development was increasing year after year.

Just any task, starting from simple initialization of graphics mode, was becoming more and more complicated every year. Simple programming tools were replaced by complex libraries. Simple APIs by complex APIs, which kept being obsoleted every few years.

Being free and open source was definitely an advantage and lot of the open data formats and free tools survived.

But Github is anyway already owned by Microsoft, which can change any rules deliberately anytime. It is clear, that massive global "free as in beer" service is exact opposite of "free as in speech software", but nobody seemed to notice, because it was so comfortable solution.. not having to self-host any more.

The AI is final and unpleasant stage od development, which started much earlier: despite all efforts, we failed to provide simple solutions and tools, accessible to general public and controlled by something like academia and not by corporations.

Very few coding-capable users of free software, including me, ever joined maintaeance of some open source tool. The reasons were complex and hard to explain. Linux had steep learning curve and some 25 years ago, just getting the damned stack running and networked was often complicated enough to discourage trying more.

Compared to what we did on earlier platforms, doing anything but basic scripting was hard.
Chao-c' profile picture
2026 trend: unboosting AI slop, when someone warns you. Somehow, it is not the same, as when we all knew, that we are boosting photoshopped memes...