Skip Navigation
Malicious VSCode extensions with millions of installs discovered
  • I believe they're referring to lower down in the article, where the researchers analyzed existing extensions on the marketplace:

    After the successful experiment, the researchers decided to dive into the threat landscape of the VSCode Marketplace, using a custom tool they developed named 'ExtensionTotal' to find high-risk extensions, unpack them, and scrutinize suspicious code snippets.

    Through this process, they have found the following:

    • 1,283 with known malicious code (229 million installs).
    • 8,161 communicating with hardcoded IP addresses.
    • 1,452 running unknown executables.
    • 2,304 that are using another publisher's Github repo, indicating they are a copycat.
  • This Week in Self-Hosted (24 May 2024)
    selfh.st This Week in Self-Hosted (24 May 2024)

    Self-hosted news, updates, launches, and a spotlight on Stirling PDF - a self-hosted PDF editing tool

    This Week in Self-Hosted (24 May 2024)

    It's been a little bit, but I'm back! As usual, not my blog, just a good community share. Authors are on Mastodon at @selfhst@fosstodon.org

    8
    Anon helps with his gf's vaping addiction
  • Yeah exactly, but to get to that point we needed to message it to consumers as such for ~20 years. Similarly, in OPs example, the 20mg feels similarly to a 40mg, but with half the nicotine - clearly the measurement on the box is being used as a proxy for "how does this feel" (no clue if that has a measurement/is measureable) but could definitely message it similarly

  • Anon helps with his gf's vaping addiction
  • That's when you take a page out of the book of lightbulb manufacturers. On the box, CFLs and LEDs don't show their actual wattage on the front, they write "100w equivalent" because that's how people are used to measuring luminosity.

  • Just getting into JS
  • I feel the same way. Designing good, opinionated APIs is HARD, but it also provides the best experience for both the author and the consumer.

    • Prettier is the undisputed king of JS formatters because it has no options by design. You set and forget.
    • One of the reasons iOS is so successful is because they lock down their APIs and put strict standards on apps, making it hard to write something that doesn't at least look good and slot into the OS well.

    Among other examples.

  • Ubisoft insists yet again that its uncanny AI-generated 'NEO-NPCs' will make games 'more alive and richer', whatever that means
  • I disagree that procedural generation makes games more boring and repetitive. I think it depends on the game and how the procedural generation is implemented. Look at Noita for example - uses lots of procedural generation, mixed with some handcrafted elements, and it's really fun! Terraria, another similar formula.

    Not my cup of tea, but a lot of people love No Man's Sky for that reason - it's fun to explore the crazy combinations.

    The original Elite was procedurally generated IIRC, and from what I understand it was super fun (before my time though).

  • anon is sus
  • That's what NEET technically means, but it's taken on a greater meaning (especially on 4chan) of "person who lives in their parents basement well past the age it's socially acceptable, has no social skills/is actively antisocial, has poor personal hygiene, and rarely (if ever) leaves the house".

  • got him
  • In a world where your IDE and maybe also compiler should warn you about using unicode literals in source code, that's not much of a concern.

    VSCode (and I'm sure other modern IDEs, but haven't tested) will call out if you're using a Unicode char that could be confused with a source code symbol (e.g. i and ℹ️, which renders in some fonts as a styled lowercase i without color). I'm sure it does the same on the long equals sign.

    Any compiler will complain (usually these days with a decent error message) if someone somehow accidentally inserts an invalid Unicode character instead of typing ==.

  • Who is Stephen in Howl's Moving Castle?
  • Yeah, also a bunch of other details, and the whole plot is way more focused on the war in the movie. In the book it's more of a backdrop. You should give it a read, it's worth it :) I also like her other books!

  • Who is Stephen in Howl's Moving Castle?
  • I don't know the answer, but happy to see someone talking about this book. I feel like so many people know the movie and have no clue that it's based on the book, nor how much they changed it. I personally love the book and am happy to see it.

  • This Week in Self-Hosted (3 May 2024)
    selfh.st This Week in Self-Hosted (3 May 2024)

    Self-hosted news, updates, launches, and a spotlight on Zoraxy - a reverse proxy and forwarding tool with a web interface

    This Week in Self-Hosted (3 May 2024)

    Not my newsletter, just a good community share. Authors are on Mastodon at @selfhst@fosstodon.org

    3
    Introducing selfh.st/companions, a Directory of Companion Apps for Self-Hosted Software
    selfh.st Introducing selfh.st/companions, a Directory of Companion Apps for Self-Hosted Software

    A directory of companion apps for self-hosted software curated for easy browsing and discovery

    Introducing selfh.st/companions, a Directory of Companion Apps for Self-Hosted Software

    Not my website. Interested to see how this will play out though!

    7
    Introducing selfh.st/apps, a Directory of Self-Hosted Software
    selfh.st Introducing selfh.st/apps, a Directory of Self-Hosted Software

    A directory of self-hosted software and applications for easy browsing

    Introducing selfh.st/apps, a Directory of Self-Hosted Software

    As a long time follower, this is pretty exciting! I've definitely been looking for something along these lines.

    0
    This Week in Self-Hosted (29 March 2024)
    selfh.st This Week in Self-Hosted (29 March 2024)

    Self-hosted news, software updates, launches, and a spotlight on Fitbit Health Dashboard - a script for fetching and visualizing Fitbit data

    This Week in Self-Hosted (29 March 2024)

    As usual, not my blog, just a good community share. Authors are on Mastodon at @selfhst@fosstodon.org

    4
    This Week in Self-Hosted (22 March 2024)
    selfh.st This Week in Self-Hosted (22 March 2024)

    Self-hosted news, software updates, launches, and a spotlight on EGG, a minimal self-hosted photo gallery

    This Week in Self-Hosted (22 March 2024)

    The weekly post. As usual, not my blog, just a good community share. Authors are on Mastodon at @selfhst@fosstodon.org.

    14
    [BUG] Comment number doesn't show on collapsed last comment

    Until I trigger the collapse mechanism, the last comment in a post doesn't have the number of subcomments when it hides subcomments by default. See the below pictures for an example with a specific post, but I've noticed this on every post I've seen recently.

    If I reload by pulling down, it again hides the comment number.

    Without the comment number after loading the post: !Without the comment number

    After tapping to collapse the comment, comment count shows: !After tapping

    0
    This Week in Self-Hosted (15 March 2024)
    selfh.st This Week in Self-Hosted (15 March 2024)

    Self-hosted news, software updates, launches, and a spotlight on DDNS Updater - a web application for updating DNS records across multiple providers

    This Week in Self-Hosted (15 March 2024)

    Weekly share. As usual, not my blog, just a good community share. Authors are on Mastodon at selfhst@fosstodon.org.

    12
    This Week in Self-Hosted (8 March 2024)
    selfh.st This Week in Self-Hosted (8 March 2024)

    Self-hosted news, software updates, launches, and a spotlight on HortusFox, a plant management and tracking application

    This Week in Self-Hosted (8 March 2024)

    Weekly posting! As usual, not my blog, just a good community share. Authors are on Mastodon at selfhst@fosstodon.org.

    9
    This Week in Self-Hosted (1 March 2024)

    My weekly post :) usual reminder: not my blog, just a good community share! Writers are on Mastodon at selfhst@fosstodon.org.

    1
    Instance upgrade (sh.itjust.works)

    My instance has just upgraded to Lemmy v0.19.3 yesterday, but I don't see any of the new features (scaled sort etc). I tried logging out and back in (had to anyway as the subscriptions weren't showing). Switching to a different instance on 0.19.3 shows the correct features, but when I switch back, nothing.

    4
    Does anyone know anything about Solid pods?

    I heard about this project years ago. Cool concept: standardized, interchangeable storage + identity that can be plugged into arbitrary apps. The idea is that your identity is tied to your data, and your data can be hosted anywhere so you can retain control over your data or use a simple provider. It was also created by Tim Berners-Lee, creator of the web.

    However, it doesn't seem to be gaining traction anywhere, even in the already-niche self-hosting community. From the GitHub (which was hard to find on the website!) I could see that it's being actively developed, including a new website redesign, but everything else seems stagnant. Their newsletter has no updates since 2021. There are only a small handful of apps listed on the site and most of them haven't been maintained since 2019 or earlier, and a lot are just things like "solid pod explorer" or "demo app".

    Anyone had any experience with it? Or know more about the situation? I would love to see this become more widely used.

    7
    This Week in Self-Hosted (9 February 2024)

    Not my newsletter, just a good community share. Writers are on Mastodon: selfhst@fosstodon.org

    3
    This Week in Self-Hosted (19 January 2024)

    Again, not my newsletter, just a good community share. Author is on mastadon: https://fosstodon.org/@shollyethan?ref=selfh.st

    3
    InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)SA
    Tekhne @sh.itjust.works
    Posts 30
    Comments 116