twtxt

Timeline for https://twtxt.net/user/thiegui/twtxt.txt

🔄 Refresh timeline

👨‍💻 Login

Following: 12

@mastodon.social https://mastodon.social/@NoSoloBot Remove

bender@twtxt.net https://twtxt.net/user/bender/twtxt.txt Remove

christian@feeds.twtxt.net https://feeds.twtxt.net/christian/twtxt.txt Remove

eapl.me@eapl.me https://eapl.me/twtxt.txt Remove

hundred-rabbits@feeds.twtxt.net https://feeds.twtxt.net/hundred-rabbits/twtxt.txt Remove

jcolag@john.colagioia.net https://john.colagioia.net/twtxt.txt Remove

movq@www.uninformativ.de https://www.uninformativ.de/twtxt.txt Remove

news@twtxt.net https://twtxt.net/user/news/twtxt.txt Remove

prologic@twtxt.net https://twtxt.net/user/prologic/twtxt.txt Remove

thiegui https://twtxt.net/user/thiegui/twtxt.txt Remove

tkanos@twtxt.net https://twtxt.net/user/tkanos/twtxt.txt Remove

xuu@txt.sour.is https://txt.sour.is/user/xuu/twtxt.txt Remove


prologic
Oh I forgot again 🤦‍♂️ Last Saturday of the month, so if anyone's up for a friendly catch up over video tomorrow? Same time, same place 👌
20 hours ago
💬 Reply


prologic
Reply to #kwepmhq
@bender Weird dunno what to say🤣
21 hours ago
💬 Reply


prologic
Reply to #kwepmhq
@bender Huh? 🤔
21 hours ago
💬 Reply


prologic
Reply to #2rxkcca
Also FWIW this is all my fault for writing shitty vulnerable code 🤣 So blame me! I'm sorry 🙏
1 day ago
💬 Reply


prologic
Reply to #2rxkcca
FWIW I'm still trying to find the the cause of the mult-GB avatars that both @stigatle and @abucci 's pods were both teying yo download. The flaw has since been fixed in the code but I'm still trying to investigate the source 🤞
1 day ago
💬 Reply


prologic
Reply to #2qczosq
@bender Hehe 🤣
1 day ago
💬 Reply


bender
Reply to #wbibk2q
@prologic somebody is playing with a new toy.
1 day ago
💬 Reply


bender
Reply to #juhuf5a
@prologic people went to sleep? I mean, at 03:00 I am on my second, or third sleep. 😜

Oh, AEST! No idea, but it might have been @xuu. LOL.
1 day ago
💬 Reply


prologic
Hmmm something happened last night at ~3am (AEST) that decrased traffic to my pod quite considerably... Hmmm? Anyone have any ideas? 💡
1 day ago
💬 Reply


bender
Reply to #74h6s4a
@xuu wow, such a remote place, eh? I imagine you living somewhere in the Himalayas, driving to town once every couple of months to resupply.

Don’t get me wrong, it is attractive, until my Internets are threaten. Then all bets are off. 😂
1 day ago
💬 Reply


bender
Reply to #c7kyxoa
@lyse lovely! I would have picked this one as a cover.

Bloody sunset
1 day ago
💬 Reply


jcolag
On my blog: Real Life in Star Trek, Hero Worship https://john.colagioia.net/blog/2024/07/25/hero-worship.html #scifi #startrek #closereading
1 day ago
💬 Reply


movq
Reply to #g6v4kxq
@lyse But stuff is still “mostly usable”, isn’t it? It’s not like it became impossible to write a letter because everything has gotten so slow.

That’s what I meant by “absolute” performance: A human being tolerates a system boot up time of 0.5-2 minutes, for example, so there’s an absolute/fixed duration that any task is allowed to take. Boot: 0.5-2 minutes. Opening Word: 1-10 seconds. Saving an image file: 1-10 seconds. Time until the next song starts to play when you click “next track”: 0-5 seconds. Stuff like that. As long as we don’t exceed those durations, people will be more or less happy.

Wasted potential? Ab-so-fucken-lutely.

(Maybe I’m repeating myself. I’m tired. Sorry. 😅)
1 day ago
💬 Reply


movq
Reply to #c7kyxoa
@lyse Uhh, nice. Haven’t seen a sunset like that in a while, I think. 🤔
1 day ago
💬 Reply


xuu
Reply to #74h6s4a
@bender haha funny! though i just realized my ISP is the only one with fiber pulled to the property so i would have to get a phone line from them some how. The other ISP in the area is basically a mobile hotspot.
1 day ago
💬 Reply


bender
Reply to #2rxkcca
Xuu has shutdown his pod now, probably to avoid losing connectivity.
1 day ago
💬 Reply


bender
Reply to #74h6s4a
@xuu need a modem? I got a couple of 33.6K, and one 28.8K. :-P
1 day ago
💬 Reply


xuu
Reply to #2rxkcca
> We received the abuse report below regarding network abuse from the IP address indicated.
> On researching I see that HTTPS (tcp 443) traffic is continuing and originating from you NAT IP address 100.64.x.x
> This was further found to be originating from your firewall/router at 192.168.x.x (MAC D8:58:D7:x:x:x).
> This abuse is continuing and constitues a violation of [ISP] Acceptable Use Policy and Terms of Service.
> Please take action to identify the source of the abuse and prevent it from continuing.
> Failure to stop the abuse may result in suspension or cancellation of service.
>
> Thank you,
1 day ago
💬 Reply


xuu
Reply to #2rxkcca
he emailed my ISP about causing logging abuse. This is the only real ISP in my area, its gonna basically send me back to dialup.
1 day ago
💬 Reply


xuu
Reply to #2rxkcca
Hey so.. i just got an email from my ISP saying they will terminate my service. Did i break something @abucci ?
1 day ago
💬 Reply


prologic
Reply to #rdeh4dq
@abucci No worries! All in the name of better reliability and security 😅
1 day ago
💬 Reply


prologic
Reply to #4ljpfuq
@stigatle Thanks! Sooo cold 🥶
1 day ago
💬 Reply


prologic
Reply to #2rxkcca
@stigatle no problems 👌 one problem solved at least 🤣
1 day ago
💬 Reply


prologic
Anyway, I'm gonna have to go to bed... We'll continue this on the weekend. Still trying to hunt down some kind of suspected mult-GB avatar using @stigatle 's pod's cache:

```
$ (echo "URL Bytes"; sort -n -k 2 -r < avatars.txt | head) | column -t
URL Bytes
https://birkbak.neocities.org/avatar.jpg 667640
https://darch.neocities.org/avatar.png 652960
http://darch.dk/avatar.png 603210
https://social.naln1.ca/media/0c4f65a4be32ff3caf54efb60166a8c965cc6ac7c30a0efd1e51c307b087f47b.png 327947
...
```

But so far nothing much... Still running the search...
1 day ago
💬 Reply


prologic
Reply to #2rxkcca
Out of interest, are you able to block whole ASN(s)? I blocked the entirely of teh AWS and Facebook ASN(s) recently.
1 day ago
💬 Reply


prologic
Reply to #2rxkcca
@abucci Oh 🤣 Well my IP is a known subnet and static, so if you need to know what it is, Email me 😅
1 day ago
💬 Reply


prologic
Reply to #2rxkcca
@abucci Seems to be okay now hmmm
1 day ago
💬 Reply


prologic
Reply to #qv5sgja
@abucci Hmm I can see your twts on my pod now 🤔
1 day ago
💬 Reply


prologic
@abucci / @abucci Any interesting errors pop up in the server logs since the the flaw got fixed (_unbounded `receieveFile()`_)? 🤔
1 day ago
💬 Reply


prologic
Hmmm 🧐

```
for url in $(jq -r '.Twters[].avatar' cache.json | sed '/^$/d' | grep -v -E '(twtxt.net|anthony.buc.ci|yarn.stigatle.no|yarn.mills.io)' | sort -u); do echo "$url $(curl -I -s -o /dev/null -w '%header{content-length}' "$url")"; done
...
```

😅 Let's see... 🤔
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@stigatle The one you sent is fine. I'm inspecting it now. I'm just saying, do yourself a favor and nuke your pod's garbage cache 🤣 It'll rebuild automatically in a much more prestine state.
1 day ago
💬 Reply


prologic
Reply to #ve43paq
That was also a source of abuse that also got plugged (_being able to fill up the cache with garbage data_)
1 day ago
💬 Reply


prologic
Reply to #ve43paq
Ooof

```
$ jq '.Feeds | keys[]' cache.json | wc -l
4402
```

If you both don't mind dropping your caches. I would recommend it. Settings -> Poderator Settings -> Refresh cache.
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@stigatle Thank you! 🙏
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@stigatle Ta. I hope my theory is right 😅
1 day ago
💬 Reply


prologic
Reply to #ve43paq
But just have a look at the `yarnd` server logs too. Any new interesting errors? 🤔 No more multi-GB tmp files? 🤔
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@stigatle You want to run `backup_db.sh` and `dump_cache.sh` They pipe JSON to stdout and prompt for your admin password. Example:

```
URL=<your_pod_url> ADMIN=<your_admin_user> ./tools/dump_cache.sh > cache.json
```
1 day ago
💬 Reply


prologic
Reply to #ve43paq
Just thinking out loud here... With that PR merged (_or if you built off that branch_), you _might_ hopefully see new errors popup and we might catch this problematic bad feed in the act? Hmmm 🧐
1 day ago
💬 Reply


prologic
Reply to #ybzi67q
@slashdot I _thought_ Sunday was the hottest day on Earth 🤦‍♂️ wtf is wrong with Slashdot these days?! 🤣
1 day ago
💬 Reply


prologic
Reply to #ve43paq
if we can figure out wtf is going on here and my theory is right, we can blacklist that feed, hell even add it to the codebase as an "asshole".
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@stigatle The problem is it'll only cause the attack to stop and error out. It won't stop your pod from trying to do this over and over again. That's why I need some help inspecting both your pods for "bad feeds".
1 day ago
💬 Reply


prologic
Reply to #ve43paq
@abucci / @stigatle Please `git pull`, rebuild and redeploy.

There is also a shell script in `./tools` called `dump_cache.sh`. Please run this, dump your cache and share it with me. 🙏
1 day ago
💬 Reply


prologic
Reply to #ve43paq
I'm going to merge this...
1 day ago
💬 Reply


prologic
Reply to #homd37a
@abucci Yeah I've had to block entire ASN(s) recently myself from bad actors, mostly bad AI bots actually from Facebook and Caude AI
1 day ago
💬 Reply


prologic
Reply to #ve43paq
Or if y'all trust my monkey-ass coding skillz I'll just merge and you can do a `git pull` and rebuild 😅
1 day ago
💬 Reply


prologic
@stigatle / @abucci My current working theory is that there is an asshole out there that has a feed that both your pods are fetching with a multi-GB avatar URL advertised in their feed's preamble (metadata). I'd love for you both to review this PR, and once merged, re-roll your pods and dump your respective caches and share with me using https://gist.mills.io/
1 day ago
💬 Reply


prologic
Reply to #ze3zlba
@stigatle I'm wondering whether you're having the same issue as @abucci still? mulit-GB `yarnd-avatar-*1` files piling up in `/tmp/`? 🤔
1 day ago
💬 Reply


prologic
Reply to #uqxxstq
@abucci So... The only way I see this happening at all is if your pod is fetching feeds which have multi-GB sized avatar(s) in their feed metadata. So the PR I linked earlier will plug that flaw. But now I want to confirm that theory. Can I get you to dump your cache to JSON for me and share it with me?
1 day ago
💬 Reply


prologic
Reply to #homd37a
@abucci Yeah that should be okay, you get so much crap on the web 🤦‍♂️
1 day ago
💬 Reply


prologic
Reply to #uqxxstq
@abucci `sift` is a tool I use for grep/find, etc.

> What would you like to know about the files?

Roughly what their contents are. I've been reviewing the code paths responsible and have found a flaw that needs to be fixed ASAP.

Here's the PR: https://git.mills.io/yarnsocial/yarn/pulls/1169
1 day ago
💬 Reply


⏭️ Next