Bwahahaha, these security folks have a great sense of humor! :-D Got a phishing test e-mail disguised as an overdue anti-phishing training e-mail: 
We receive these test phishing e-mails every now and then at work. When you follow the links and log in at the fake login, you probably get assigned another (real) training.
When I got this e-mail, I immediately thought of such a test. Since I actually do have some stupid training deadlines coming up soon, I wasnât 100% sure, but still doubted that this was one of them. To make the timing even better, in the team meeting last week, our bosses reminded us to complete outstanding trainings before the deadlines. Ideally well in advance. Notifications about deadlines coming closer are sometimes not only sent to the individuals but also to the bosses and their bosses. And then things can get out of hands when somebody doesnât read the e-mails properly and mistakes them for deadline exceeded reports.
Anyway, the URL also looked kinda legit. It really doesnât help a single bit that domain names change all the fucking time. So, still with the test program in mind, I thought, I just give it a quick shot out of curiosity. Since I just had logged in before, the empty SSO username field was totally obvious then. Looking at the e-mail headers confirmed that this was indeed one of securityâs field checks. :-)
Are you aware of the Residential Proxy pest?
https://spur.us/blog/smart-tv-apps-residential-proxy-sdks
This explains the access patterns that I see in my logs.
Itâs funny, because I used to warn years ago that this might happen, and then I lost track of this topic. Now here we are and itâs a real issue. đ€Šââïž
twtd instnace or via Github/Gitea or any other publishing backend (doesn't amtter). Please read.
I will be monitoring the server logs for the next ~28 days, after that orphaned Namespaces will start to get cleaned up, especially ones that have never bothered to care about recovery.
15 years without reinstalling on this particular box.
$ head -n 1 /var/log/pacman.log
[2011-07-07 11:19] installed filesystem (2011.04-1)
Two more years and Iâll be celebrating the â20 years of Archâ anniversary.
@lyse@lyse.isobeef.org Found it and fixed it! đ The crawlerâs discovery spider was fetching every feed a second time, without any conditional headers (plus a couple of other politeness bugs: redirected feed URLs never stored their cache validators, and there was no floor between re-fetches). Now every feed is fetched at most once per crawl, always with If-Modified-Since / If-None-Match, and never more than once per 15m no matter what. Just deployed â please keep an eye on your access logs and let me know if you still see anything impolite from the crawler đ
@prologic@twtxt.net Thatâs cool to hear!
Looking at my access logs, something seems to be off, though:
2026-07-04T04:11:26+02:00 200
2026-07-04T05:16:09+02:00 304
2026-07-04T06:33:34+02:00 304
2026-07-04T06:37:46+02:00 304 # just four minutes since last crawl
2026-07-04T06:41:55+02:00 304 # another four minutes
2026-07-04T07:11:33+02:00 304
2026-07-04T07:11:40+02:00 200 # no conditional request just seven seconds later
2026-07-04T07:43:25+02:00 304
2026-07-04T07:43:33+02:00 200 # just eight seconds since last crawl
2026-07-04T09:18:06+02:00 304
2026-07-04T09:22:53+02:00 304 # just four minutes since last crawl
2026-07-04T09:27:03+02:00 304 # another four minutes
My mate and I hiked up the backyard mountain. We got 25°C and quite some wind, so it was actually not too terrible. The wind could have blown harder or the temps a little lower, but oh well.
I saw the squirrelâs bushy tail stick up on the forest floor in the sunlight and immediately thought of this cute little feller. Since it didnât move at all, even when we came closer, I got irritated and reconsidered that it might actually be some kind of dried up farn. But then we also were able to see its body. Unfortunately, the squirrel ran up the tree too quickly, so all the shots are kinda crap.
At one flower spot, there were sooo many butterflies, wasps, flies, bugs and other insects. The botanic was completely crowded.
The workers were transferring logs from one log truck to the other in a parking lot. Iâve never seen this happening before. When we passed the same place on the way home, they had moved logs into a sea container. That was surprising. This semi wasnât there on the way there. One log was probably too long and sticking out the container, so they probably had to wait for somebody to return with a chainsaw. Crazy that theyâre shipping logs from here probably overseas. Why else would they put them in a sea container?
After our first break, a blackbird was really posing for us with his worm in the dark shade.
Today was my first time I ever saw a hummingbird hawk-moth (TaubenschwÀnzchen) for real. My mate photographed them many, many times before, but I never came across one myself. So, that was really special.
The forest service installed an outdoor table with two benches next to the timber lion, that was cool to see. We sat down for a few minutes and enjoyed both the view into the Fils valley and ant on the tabletop, but the sun was beating down too heavily on us, so we had to move on.
All in all, it was a very nice few hours long hike. Enjoy! https://lyse.isobeef.org/waldspaziergang-2026-07-03/
@bender@twtxt.net Doing tail -f access.log looks like a Matrix screensaver at the moment. Whoooooosh âŠ
On the subject of debugging these so-called AI(s) / Black Boxes⊠the model is a black box sure, but thatâs not really the problem. Everything around it â the inputs, the outputs, the decisions it makes â all of that can and should be fully logged, traced and replayed. The âprogramâ isnât the model, itâs the full context you feed it. Thatâs what you debug. Itâs not so different from any other system really; if youâre running something in production with no logs, no structured outputs and no tests, youâd have the same problem. The model doesnât change that discipline, it just makes it more important.
Welcome @tftp@tilde.town, I just found you in my access log. :-)
So, itâs plenty good enough for them.
Yeah, but on the other hand, you canât even log in normally to a Matrix/Element account. I mean using username + password. Itâs not expected that you ever log out or lose your browser session. If you do, you must use a one-time backup code (that you must create and save beforehand) to log in again.
To be fair, I canât say that I fully understand what Matrix is doing in the first place. The text that I quoted reads like they have your keys. But they also claim that they only store this stuff encryped: https://element.io/en/help#encryption5 So ⊠encrypted with what? Only option here is my password, isnât it? (But if my password was good enough to reclaim an account ⊠why do all the other stuff âŠ)
Matrix takes end-to-end encryption seriously. When I ran a Matrix server for the family, the family members would regularly lose their keys, because they didnât pay attention to something. Thatâs on purpose! Or rather, that was on purpose. Maybe itâs different these days?
No clue.
Improvised log export from Claude Code on the web â https://dbohdan.com/claude-code-web-export
Just missed the 15th anniversary of the Linux installation on my laptop:
$ head -n 1 /var/log/pacman.log
[2011-04-27 11:38] installed filesystem (2011.04-1)
what is the user-agent name of the crawler that pulls the tweets here on twtxt.net? i am seeing getwtxt-ng/dev and twtstrm/0.4.0 in the logs
@itsericwoordward@itsericwoodward.com i am so glad that so many of us is realizing that internet is enshittified, i feel the same, i wrote about this on my website, kinda reflects what Neil wrote there, take a look https://klaxzy.net/var/log/202512-internet-hit.html
@d6b80: Use gopher over the portal gopher.floodgap.com/gopher/gwlite . You always present the same ip to the internet. But of course you are logged. You can do so by any old browser and mobile, that id capable for http.
What do the Gopher Troopers think of the following? The Gopher protocol is a nearly-forgotten network protocol from the early 1990s, designed to serve and navigate text-based menus and documents over the Internet. While itÂs far less common than HTTP/HTTPS today, there are still some security risks associated with Gopher and Gopher space. LetÂs break them down carefully: 1. Lack of Encryption Problem: Gopher was designed long before widespread use of SSL/TLS. All dataÂincluding credentials, file transfers, and menu selectionsÂis transmitted in plaintext. Impact: Anyone intercepting traffic (e.g., via a network sniffer, public Wi-Fi, or a compromised router) can read sensitive information, including usernames and passwords. 2. No Authentication or Access Control Problem: Gopher servers rarely implement robust authentication; access control is usually limited or non-existent. Impact: Unauthorized users might browse sensitive directories or download private files, particularly if servers are misconfigured. 3. Server Software Vulnerabilities Problem: Modern OSes can still run legacy Gopher servers, but the software is often unmaintained. Impact: Old software may contain buffer overflows, directory traversal bugs, or command injection vulnerabilities that attackers could exploit. 4. Malicious Gopher Links Problem: Gopher menus can contain links that point to scripts or other servers, similar to hyperlinks in HTTP. A client following a malicious link could inadvertently: Download malware Access sensitive internal network resources (server-side request forgery) Impact: Could serve as a vector for attacks if a user opens content from untrusted sources. 5. Legacy Protocol Weaknesses Problem: Gopher lacks modern web security mechanisms like: Content security policies Same-origin policies Cross-site request forgery protection Impact: If Gopher is bridged to other services (like modern browsers via gateways), old vulnerabilities may be exposed. 6. Information Leakage Problem: Gopher servers often provide directory listings without restriction. Impact: Sensitive files, backup directories, and internal documents may be exposed unintentionally. 7. Bridging Risks Problem: Some modern browsers access Gopher via gateways (HTTP-to-Gopher proxies). These bridges may: Expose sensitive internal resources to the gateway Introduce logging or tracking that wouldnÂt exist on pure Gopher Impact: Attacks could occur indirectly through insecure intermediaries. Key Takeaways Gopher is inherently insecure due to its design in a pre-HTTPS era. Main threats: eavesdropping, unauthorized access, malware delivery, and exploitation of unpatched server software. Safe practice: Use Gopher only in isolated, trusted environments, or through secure HTTP(S) gateways with proper sanitization.
I dread the day that someone accuses an entry on my Gemini log or a cover letter to an employer of being created by AI. Itâs just the way I write, I promise!
Number 03, the warmest log in the land! :-) Number 04, was that in the middle of nowhere? Iâd find the garden decoration interesting if so. Love the succulent like looking plants on 06 (my wife loves them too)!
About those 13ÂșC⊠oh my, how we wishâŠ. we currently have 28ÂșC, cloudy.
@rdlmda@rdlmda.me writing it by hand is good, but without checking your server logs to see if someone is following your feed, and interacting with them, you are simply tossing bottles into the sea. That, of course, isnât a bad thing per se, if it is the intent. :-)
@kiwu@twtxt.net I am trying to read our Information Security Office âmindâ to grasp what they want. So far they seem to want to get logs from our BIG-IP F5 load balancers into Azure Sentinel, but the Telemetry Streaming plugin normally used for it is on maintenance mode, with deprecations happening on the F5 and Microsoft side soonish. So, yeah⊠âfunâ. Oh, and they want it on production by tomorrow. LOLz!
Here am I looking at the different tcell.Key constants and typing different key combinations in the terminal to see the generated tcell.EventKeys in the debug log. Until I pressed Ctrl+Alt+Backspace⊠:-D Yep, suddenly there went my XâŠ
So far, it appears as if I can have either only Ctrl or Alt as modifiers. But not in combination. And Shift is just never ever set at all. Interesting.
phlog is a ph thats like a log
Iâm seeing crashes in the 3D subsystem. (Gallium? Glamor? Whatever other Mesa thing they have? No idea.) In the logs I find this:
malloc(): unaligned tcache chunk detected
And thatâs why I still care about Rust and want to learn more about it, even though itâs giving me so much headache and Iâve given up so many times. Because Rust currently seems to be the only popular systems programming language that tries to eliminate these error classes.
And of course âthe Rust experimentâ in the Linux kernel has recently been concluded as âsuccessfulâ, so that alone is reason enough for me:
yarn stop logging me out challenge (impossible)
@lyse@lyse.isobeef.org My theory is that these people simply donât do âcode archeologyâ. When something breaks, they donât reach for git log. They simply donât experience the pain that comes with bad commits / commit messages.
Or is that different in your company? đ
@prologic@twtxt.net Hmm. đ€ Well, I donât run that server myself, so I canât peek into the logs to see whatâs going wrong ⊠đ„Ž
@prologic@twtxt.net Iâll create one manually and send you the creds so you can change them as soon as you log in (my instance isnât set up to send emails). Not sure how you could get access to logs, not even my admin account has that on the admin panel. I just snoop trough the /var/log/* when needed.
@aelaraji@aelaraji.com Ahh that would be awesome!!! Iâd also somehow need read access to logs so i can figure shit out on my own đ§
@lyse@lyse.isobeef.org I personally use twtAgent over here on Thunix (Also managed by deepend I believe) and then from time to time run wk -F ' ' '/\.txt/ {print $NF" "$(NF-1)}' $HOME/public_html/twtAgent.log | sed -e 's/\((\|)\|+\|;\|@\)//g' | sed '/^$/d'| sort -u to check for whoâs pulling this feed (Too lazy to alias it :â] ) .
Leaving this here just in case it might help a fellow Townie, Cheers!
Iâve once again brought up a Gitea instance on my server space, but there are two highlights here:
- No self-registration (accounts are tied to the e-mail server, which is in turn tied to the system accounts)
- Going beyond the landing page requires to be logged in, no excuses. (It also could scare the AI crawlers to oblivion, avoiding Anubis at that)
Thatâs it.
Fark me đ€Šââïž I woke up quite late today (after a long night helping/assisting with a Mainframe migration last night fork work) to abusive traffic and my alerts going off. The impact? My pod (twtxt.net) was being hammered by something at a request rate of 30 req/s (there are global rate limits in place, but stillâŠ). The culprit? Turned out to be a particular IP 43.134.51.191 and after looking into who own s that IP I discovered it was yet-another-bad-customer-or-whatever from Tencent, so that entire network (ASN) is now blocked from my Edge:
+# Who: Tentcent
+# Why: Bad Bots
+132203
Total damage?
$ caddy-log-formatter twtxt.net.log | cut -f 1 -d ' ' | sort | uniq -c | sort -r -n -k 1 | head -n 5
61371 43.134.51.191
402 159.196.9.199
121 45.77.238.240
8 106.200.1.116
6 104.250.53.138
61k reqs over an hour or so (before I noticed), bunch of CPU time burned, and useless waste of my fucking time.
@bender@twtxt.net Thanks. That pulley is just to hang back up the telephone wire (on the ground in 16) for that farm and restaurant in 04 once they finish logging. Hahahahahaaahaaaa, I didnât see the nails on top of the pole. :-D
Yup, these ice crystals are just lovely. :-)
@bender@twtxt.net Hmm, didnât find anything. But you mean a giant bucketload of access_log /home/$USER/logs/access.log if=⊠where the condition matches the requested path for said user? Yeah, that gets annoying very quickly. :-D
@lyse@lyse.isobeef.org nginx allows logging per user, via using defined variables on configuration. Not sure, though, if a Tilde would be willing to go to those âextremesâ.
@bender@twtxt.net Sounds about right.
I had a brainfart yesterday, though. For whatever reason I thought of subdomains, which are modeled with server entries in nginx. So, each could define its own access_log location. However, there are no subdomains in place! Searching around, I didnât find any solution to give each user their own access log file.
One way would be a cronjob, aeh, systemd timer as I learned the other day, that greps the main access log and writes all user access log files with only the relevant stuff.
access.log files. Hence theyâll never see followers, unless we notify them out of band. đ«€
@movq@www.uninformativ.de Actually, @threatcat@tilde.club popped up in my own access log first. Thatâs how I discovered the feed. :-) So I figured that this feed author actually sees my reply. The hope is that with the next mention of my feed in threatcatâs feed, the other tilde users, who are following threatcat, are then also informed of my existence. :-)
I donât know how tilde.club is set up. But it should be relatively easy to give all users access to their nginx access logs. Not sure if somebody already requested that or not. But Iâd encourage tilde users to ask for that. Maybe also just for twtxt.txt and/or in a custom, reduced log format.
@lyse@lyse.isobeef.org Thereâs a couple of new users on https://tilde.club, but since this is a shared host, I doubt that they have access to their access.log files. Hence theyâll never see followers, unless we notify them out of band. đ«€
Thanks @prologic, thats what I get for not checking enough, my yarn service had deactivated for some reason. Restarted and all good. Maybe my VPS ran out of memory or something, I should probably look deeper into the logs
@prologic@twtxt.net Yeah. The actual services donât run on AWS, apparently, but often itâs just the login service?! The whole Atlassian suite was âdownâ today because you couldnât log in. But if you already were logged in, it wasnât much a problem.
I disabled the compression of logs on my edge, which Iâm hoping will fix the âinstabilityâ I see every now and again where my edge network just âfalls off the face of the earthâ. Some folks donât really appreciate / understand this, but Disk I/O can kill your application(s) no matter what. I/O Wait is a real thing.
@zvava@twtxt.net yarnd fetches the feeds roughly every ten minutes:
grep twtxt.net www/logs/twtxt.log | cut -d ' ' -f1 | tail -n 20
2025-10-04T07:00:45+02:00
2025-10-04T07:10:26+02:00
2025-10-04T07:22:43+02:00
2025-10-04T07:30:45+02:00
2025-10-04T07:40:48+02:00
2025-10-04T07:52:59+02:00
2025-10-04T08:00:07+02:00
2025-10-04T08:13:33+02:00
2025-10-04T08:23:13+02:00
2025-10-04T08:31:22+02:00
2025-10-04T08:41:29+02:00
2025-10-04T08:53:25+02:00
2025-10-04T09:03:31+02:00
2025-10-04T09:11:42+02:00
2025-10-04T09:23:11+02:00
2025-10-04T09:29:49+02:00
2025-10-04T09:36:17+02:00
2025-10-04T09:46:33+02:00
2025-10-04T09:58:40+02:00
2025-10-04T10:06:54+02:00
I suspect that the timing was just right. Or wrong, depending on how youâre looking at it. ;-)
url metadata field unequivocally treated as the canon feed url when calculating hashes, or are they ignored if they're not at least proper urls? do you just tolerate it if they're impersonating someone else's feed, or pointing to something that isn't even a feed at all?
@zvava@twtxt.net My clients trusts the first url field it finds. If there is none, it uses the URL that Iâm using for fetching the feed.
No validation, no logging.
In practice, Iâve not seen issues with people messing with this field. (What I do see, of course, is broken threads when people do legitimate edits that change the hash.)
I donât see a way how anyone can impersonate anybody else this way. đ€ Sure, you could use my URL in your url field, but then what? You will still show up as zvava in my client or, if you also change your nick field, as movq (zvava).
is the first url metadata field unequivocally treated as the canon feed url when calculating hashes, or are they ignored if theyâre not at least proper urls? do you just tolerate it if theyâre impersonating someone elseâs feed, or pointing to something that isnât even a feed at all?
and if the first url metadata field changes, should it be logged with a time so we can still calculate hashes for old posts? or should it never be updated? (in the case of a pod, where the end user has no choice in how such events are treated) or do we redirect all the old hashes to the new ones (probably this, since it would be helpful for edits too)
Phlog is a blog for gopher. Web Log - Blog, Gopher log - Phlog.
Next level poop: Canât log in to reddit anymore with adblock enabled. It says invalid usename or password.
<details> tag in HTML; it lets you write a sentence or so that someone can then click to expand to see the actual post. it's called a CW because most people use it to warn for potentially triggering/harmful subjects, but you can really use it for anything, like spoilers in a TV show or even for joke punchlines
@kat@yarn.girlonthemoon.xyz Ta. The only good use for <details> is to collapse long logs in bug analysis reports. Other than that, I find it rather annoying to expand sections manually.
As for spoilers, personally, I donât care at all. Not the slightest bit. If there is something that I donât wanna read, I just stop reading. ÂŻ_(ă)_/ÂŻ
But Iâve got the feeling that Iâve got an unpopular opinion on that matter. ;-)
@lyse@lyse.isobeef.org hihi ^^ i did that at first, but i personally i donât like it when websites donât let me change my password when i am already authenticated â fwiw you can view and log out other sessions, if that diminishes this attack vector at all