Sign in

Michael Hanke

@mih.mas.to.ap.brid.gy
2 followers 0 following 75 posts

NeuroDebian/PyMVPA/studyforrest/DataLad (chronologically). Always free and open. I have opinions, they are mine, and can be changed. 🇪🇺 🌉 bridged from ⁂ mas.to/@mih, follow @ap.brid.gy to interact

PostsRepliesMedia
Reposted by Michael Hanke
tante @tante.tldr.nettime.org.ap.brid.gy · 22/09/2026
Also als die Leute anfingen, die Faschisten der AfD zu wählen, wurden die bürgerlichen Medien nicht müde, jedem Neurechten ein Mikro ins Gesicht zu halten, damit man seine "Sorgen und Nöte" verstehen kann. Das passiert jetzt doch sicher auch mit den Wähler*innen linker Parteien, oder? Oder ging […]
tldr.nettime.org
Original post on tldr.nettime.org
0322
Reposted by Michael Hanke
jonny (nonvenomous) @jonny.neuromatch.social.ap.brid.gy · 08/09/2026
> The route to the Clay problem through a smooth force, options c and d in Fefferman’s statement of the problem, is the route Luis and Diego opened and the one Levent and I had quietly chosen to attack. Almost nobody else I know of was working on it. It is not the direction one arrives at in a […]
neuromatch.social
Original post on neuromatch.social
2029
Reposted by Michael Hanke
Yann Büchau :nixos: @nobodyinperson.fosstodon.org.ap.brid.gy · 08/09/2026
For several days now my DSL Internet at home is broken (because I moved the cabinet?), so my #homelab and its web infrastructure is unavailable - even locally because of CSRF and https annoyances. 🙄 Single point of failure, huh... At least anything :gitannex: #gitAnnex is reliable as ever - […]
fosstodon.org
Original post on fosstodon.org
001
Reposted by Michael Hanke
Roasting House Coffee @roastinghouse.mastodonapp.uk.ap.brid.gy · 09/08/2026
If you're a small business introducing a #ChatBot. Don't. We stand out because our service is better, we use higher quality materials, we care about every part of the product down to the glue on the envelopes (real thing, we did this). Introducing #chatbots indicates your customer's needs can […]
mastodonapp.uk
Original post on mastodonapp.uk
2512
Reposted by Michael Hanke
Annika Joeres @annikajoeres.bsky.social · 08/08/2026
Wir sollten unseren Artikel über KT Guttenberg sofort löschen, schrieb uns sein Anwalt Christian Schertz. Es folgten zahlreiche juristische Schritte gegen CORRECTIV - wir haben nun Details im Artikel präzisiert Gelöscht haben wir die Recherche natürlich nicht. Ihr könnt sie hier sehr gerne lesen: ⬇️
correctiv.org
Guttenberg: Der Mann aller Märkte
Unsere Recherche zeigt eine lange Liste an Firmen, in denen Guttenberg investiert ist – und Verbindungen zu MAGA-Unterstützer Peter Thiel.
40986473
Michael Hanke @mih.mas.to.ap.brid.gy · 19/06/2026
We presented our work with @matrss at @fzj on self-hostable (meta)data infrastructure at OHBM 2026 in Bordeaux. The poster by @adswa won the people's choice award!
100
Reposted by Michael Hanke
Sven-Erik Volberg @volberg.bsky.social · 12/06/2026
For #SpaceX Day, the Brits have a very fitting message to Elon
9708293
Reposted by Michael Hanke
Konrad Hinsen @khinsen.scholar.social.ap.brid.gy · 07/04/2026
@brembs AI slop and even paper mills are too recent to have a major visible impact so far. But yes, they are also a welcome scapegoat for distraction. The overarching question is quality control in research. 1950s style peer review is no longer adequate. Two to three individuals can not […]
scholar.social
Original post on scholar.social
101
Michael Hanke @mih.mas.to.ap.brid.gy · 06/04/2026
When you are working in the field of research data management, and get an email with... "We had the pleasure to read your recent work and were truly impressed by the depth of your research. If you are currently working on a related study, we would be glad to review it for possible inclusion in […]
mas.to
Original post on mas.to
000
Reposted by Michael Hanke
jonny (nonvenomous) @jonny.neuromatch.social.ap.brid.gy · 31/03/2026
* Claude code source "leaks" in a mapfile * people immediately use the code laundering machines to code launder the code laundering frontend * now open source knockoff in python and rust What's anthropic going to do, sue them? Insist in court that LLM recreating copyrighted code is a […]
neuromatch.social
Original post on neuromatch.social
11912
Reposted by Michael Hanke
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 13/02/2026
Treating Maintainer attention as a finite resource: nesbitt.io/2026/02/13/respectful-op…
nesbitt.io
Respectful Open Source
I found and fixed a bug in a popular open source project last week. Went to look at the repository and saw a maintainer drowning in issues and pull requests, clearly underwater, and I didn’t submit the fix. I’ve been on both sides of this for a long time. I ran 24 Pull Requests for years, a project that actively encouraged people to send PRs to open source maintainers every December. The incoming was so overwhelming that I ended up building Octobox just to help maintainers manage the flood of GitHub notifications. I’ve spent a decade building tools to help maintainers cope with inbound, and I still couldn’t bring myself to add to someone else’s pile. When I mentioned this on Mastodon, most people got it immediately. A couple said send it anyway, which I think misses something about what it’s like to be on the receiving end. A fix from a stranger still carries cognitive load beyond just merging: triage, review, checking for regressions, responding, managing expectations when you can’t get to it quickly. And once you merge someone’s code, you’re maintaining it. They move on, but you’re the one who gets the bug report a year later when something breaks in a way the original patch didn’t anticipate. Even a perfect PR with a note saying “no rush” creates a low-grade obligation the moment it appears. The maintainer now knows it exists, unanswered. Someone in the thread suggested framing it as a gift with no expectations, and another person put it well: it doesn’t matter how carefully you word it, it still lands as a thing that needs a decision. The fix exists on my fork. If discovery were good, anyone hitting the same bug could find it there, but nobody will because fork discovery is effectively broken. ### Git was pull-based The open source contribution model is almost entirely push-based. You do the work, then you push it at a maintainer and wait. Issues, PRs, @mentions, automated updates, audit findings, all of it puts something in front of a person who didn’t ask for it. `git request-pull` generates a summary of changes in your repo and asks someone to pull from it, a genuine peer-to-peer request where the maintainer decides if and when to look. The contributor publishes their work and the maintainer pulls at their own pace, which is about as respectful of someone’s attention as a collaboration model gets. GitHub took that name and bolted it onto what is functionally a push-based review queue. GitLab is at least honest about it by calling them merge requests. Nobody can really use the `git request-pull` workflow anymore because it depends on the other person being able to find and browse your repo, which is a discovery problem that doesn’t have good answers right now. If the default were flipped so that fixes exist publicly without requiring maintainer attention, the contributor’s job would be done when the fix is public rather than when it’s merged, and other users could find and benefit from fixes independently of upstream. ### Fork discovery is broken The best tools for fork discovery are a handful of browser extensions that filter GitHub’s fork list to show forks with commits ahead of upstream, and the most ambitious one I found clones all forks into a single repo and lets you grep across them locally. GitHub made forking easy and fork discovery nearly impossible. The old fork graph rarely works for popular repos because so many people use the fork button as a bookmark, and Dependabot, CI bots, and AI agents all generate forks that are nothing but noise. Someone in the thread mentioned installing a browser plugin just to look at forks. GitHub have said they’ll let maintainers turn off PRs on their repos, which makes sense as a pressure valve, but turning off PRs without an alternative channel doesn’t make fixes discoverable elsewhere. It might be more interesting to pair that switch with better discovery. Imagine a maintainer triaging issue #347 and being able to see “three forks have patches touching this code” without anyone having submitted anything, because the signal is already there in git, just not surfaced anywhere. ### Everything is push PRs are just the most visible channel. Bug reports, feature requests, support questions, and bot-generated updates all land in the same inbox with the same zero friction and the same assumption that someone on the other end has time to look at them. Compliance and audit requests add another layer, where someone runs a scanner, finds something, and opens an issue that reads like a demand. “Your project has a licensing problem.” “This code has a known vulnerability.” The maintainer didn’t ask for the audit, didn’t agree to the compliance framework, and is now expected to respond on someone else’s timeline. With the EU CRA pushing more software supply chain accountability, there’s a growing class of inbound that amounts to “prove to me that your free software meets my requirements,” which is a lot to push at a volunteer. Private vulnerability disclosure is different because it needs a direct channel by nature, and that channel has its own AI spam crisis as anyone following curl’s experience with HackerOne can attest. But for everything else, the problem isn’t bad faith on anyone’s part, it’s that every one of these interactions assumes the maintainer has capacity to receive, and there’s no mechanism for them to control that. Open source sustainability conversations tend to focus on money, and maintainers absolutely need more of it, but maintainer attention and mental health are at least as scarce a resource, and nobody’s trying to conserve them. Miranda Heath’s report on burnout in open source names six causes, and workload is only one of them: toxic community behaviour, hyper-responsibility, and the pressure to keep proving yourself all compound the problem. The communities around projects aren’t fungible either, built on years of shared context and ambient trust that can’t be rebuilt once the people holding them together burn out. Unsolicited PRs, drive-by issues, and automated audits are all withdrawals from a finite account. A pull model, where people log problems and publish fixes somewhere discoverable and the maintainer engages on their own schedule, would at least stop treating that account as bottomless. ### AI slop accelerates the problem All of this was already a problem before AI coding agents, but the past six months have made it noticeably worse. The volume of low-quality inbound to popular projects has exploded. Daniel Stenberg watched AI-generated reports grow to 20% of curl’s bug bounty submissions through 2025, added a checkbox requiring AI disclosure, then finally killed the bounty program entirely in January 2026 after receiving seven submissions in sixteen hours. Ghostty implemented a policy where submitting bad AI-generated code gets you permanently banned. tldraw stopped accepting external PRs altogether. These are experienced maintainers who tried graduated responses and ended up at the nuclear option because nothing else worked. The pattern is the same every time: add disclosure requirements, then add friction, then restrict access, then close the door, with each step costing maintainer energy on policy rather than code. That might work for individual projects, but it’s hard to see it scaling when the number of potential contributors becomes effectively infinite and the tooling to generate plausible-looking code keeps getting better. And if GitHub’s answer is letting maintainers turn off PRs entirely, AI pressure is going to force that switch on more and more repos, which only widens the discovery gap. GitHub made forking a one-click operation a decade ago without ever investing in making the resulting graph navigable, and now that turning off PRs is becoming a reasonable response to the AI firehose, all those would-be contributions just pile up as diverging forks that nobody can find. A pull-based model would sidestep most of this, because agents can fork and generate garbage all day without anything landing in anyone’s inbox. The maintainer never has to evaluate it, write a policy about it, or spend emotional energy closing it with a polite note. Generated code that happens to be good sits in a fork where someone might eventually find it useful, and the rest is invisible. The empathy of not adding to the pile, the choice to fix something and walk away, is invisible in open source sustainability discussions, and I suspect the contributions people deliberately don’t make out of respect for maintainer capacity might matter just as much as the ones they do. The fix is on my fork, and for now that’s where it stays.
106
Michael Hanke @mih.mas.to.ap.brid.gy · 01/02/2026
I am looking to migrate a bunch of domains. I am searching for a registrar with good reputation and ethics. Ideally one that is unlikely to be blackmailed by foreign governments to punish individuals with a if-you-want-to-continue-business-in-our-market... threat. I am EU/Germany based. I […]
mas.to
Original post on mas.to
000
Michael Hanke @mih.mas.to.ap.brid.gy · 07/01/2026
Having to watch what is happening across numerous #forgejo sites is not so simple. Tried #gitnex, but it wasn't smooth enough. Email notifications don't work for me (psychological; too much noise on the channel). Recently, I found #ntfy to be a wonderfull, self-hostable tool that can easily […]
mas.to
Original post on mas.to
100
Michael Hanke @mih.mas.to.ap.brid.gy · 06/01/2026
Very happy to finally have a digital photo frame to resurface pictures I took once, but haven't seen in ages. There was nothing to buy that wasn't severely enshittified, so I had to build one. I think it came out really nice -- hardware and software. blog.datalad.org/posts/photoframe […]
mas.to
Original post on mas.to
000
Reposted by Michael Hanke
Annika Joeres @annikajoeres.bsky.social · 01/08/2025
Wahnsinnsgrafik, Wahnsinnszahl, kaum besprochen:
Bundesumweltministerium: Großer Teil des BUdgets geht für Atommüll drauf
7625111304
Reposted by Michael Hanke
Robin Berjon @robin.berjon.com · 16/12/2025
In the context of AI, this creates a double incentive: 1. If all the other CEOs praise AI, you have to do the same, and roll it out. 2. The CEO is the position that is the easiest for an LLM — that drive to the most average conformity — to emulate. You could automate most big American CEOs away.
1165
Reposted by Michael Hanke
Dan Gillmor @dangillmor.mastodon.social.ap.brid.gy · 08/12/2025
In a preview of his next book, Cory Doctorow explains of where the "AI" business is taking us -- nowhere good -- and how we can fight its most malevolent impacts: pluralistic.net/2025/12/05/pop-that… The section on copyright is, for artists, particularly important.
0213
Reposted by Michael Hanke
Dan Gillmor @dangillmor.mastodon.social.ap.brid.gy · 05/12/2025
I retired from teaching 18 months ago, in part because it was becoming clear to me that the "AI" industry was undermining education in profound ways. This essay makes a convincing case that LLMs are a plague on learning -- and, not incidentally, higher education […]
mastodon.social
Original post on mastodon.social
4156
Reposted by Michael Hanke
Bastian Greshake Tzovaras @gedankenstuecke.scholar.social.ap.brid.gy · 21/11/2025
Wohoo, what feels like ages ago, @dpk, @n0toose & I started a motion to clarify which licenses are compatible with #Codeberg's mission. And after our motion for that ToS update had passed at the annual assembly, it is now live! You can read about that – and many other cool news from @Codeberg – […]
scholar.social
Original post on scholar.social
014
Michael Hanke @mih.mas.to.ap.brid.gy · 13/11/2025
I really like collaborative document editing, was using Google docs for a long time. I struggled to find a self-hostable alternative. I really do not want to run a database server for the little load I'd produce. Turns out that #hedgedoc works just fine with sqlite, which makes it a breeze to […]
mas.to
Original post on mas.to
001
Michael Hanke @mih.mas.to.ap.brid.gy · 13/11/2025
I couldn't take it anymore. The level of abuse from AI scrapers is unbearable. I have now put git.gammaspectra.live/git/go-away in front of the most bombarded #forgejo site I look after. I like that it has all the JS tricks that are forced upon us these days, but also the simple rules […]
mas.to
Original post on mas.to
001
Michael Hanke @mih.mas.to.ap.brid.gy · 10/11/2025
Completed my first personal technology upgrade after this year's #distribits: new phone running #grapheneos Needing new hardware was annoying (it appears nothing in the past 5 years has made devices truly better). But the software makes up for it! Smooth installation, polished feel. For the […]
mas.to
Original post on mas.to
111
Michael Hanke @mih.mas.to.ap.brid.gy · 27/10/2025
And now Berlin for the #bigbrain training day, contributing a workshop on @datalad with @adswa
010
Michael Hanke @mih.mas.to.ap.brid.gy · 24/10/2025
Data modeling going on at #distribits2025 by @jsheunis #distribits
000
Michael Hanke @mih.mas.to.ap.brid.gy · 23/10/2025
New favorite slide #distribits2025
000
Michael Hanke @mih.mas.to.ap.brid.gy · 23/10/2025
#distribits2025 starting. #distribits
000
Michael Hanke @mih.mas.to.ap.brid.gy · 22/10/2025
On my way to #distribits2025. Looking forward to intense three days. It will be hard to meet the transformative power of the 2024 edition, but the program does look exciting. #distribits
000
Michael Hanke @mih.mas.to.ap.brid.gy · 28/09/2025
Gearing up for a @datalad workshop on Monday and Tuesday at @ufz Version control, provenance tracking, collaborative workflows, and metadata-driven #rdm Looking forward to meeting people outside the #neuroscience bubble!
012
Reposted by Michael Hanke
Robert W. Gehl @rwg.aoir.social.ap.brid.gy · 13/09/2025
In exchange for asking my students not to use #generativeAI, I've pledged to my that *I* won't use it. That means I will not use generated images for slides, for example, among other things (no generated summaries, no generated lectures, nothing). But the slop is so ubiquitous that even looking […]
aoir.social
Original post on aoir.social
000
Michael Hanke @mih.mas.to.ap.brid.gy · 12/09/2025
Next month #distribits 2025 will take place in Düsseldorf. For me, last year's meeting was absolutely transformative. I have substantially changed how I work, and also the tooling I use for that. It is amazing what can happen, when enthusiastic people get together. The 2025 talk abstracts are […]
mas.to
Original post on mas.to
111
Michael Hanke @mih.mas.to.ap.brid.gy · 08/08/2025
With @adswa we built a #gitAnnex special remote for internxt.com/drive They offer "lifetime" plans for >>TB-sized zero-knowledge-encrypted cloud storage. Should be good for private stuff. The special remote implementation is wrapped around the official CLI. It is not without issues […]
mas.to
Original post on mas.to
000
Reposted by Michael Hanke
tante @tante.tldr.nettime.org.ap.brid.gy · 30/06/2025
I think one main issue I have with the whole "EURO Stack" stuff is that it is not looking for an alternative. It's "we want what we got just with EU companies". But the fact that the Internet and its services have been turned into a mall is the big fucking problem. I don't want a "European […]
tldr.nettime.org
Original post on tldr.nettime.org
0026
Michael Hanke @mih.mas.to.ap.brid.gy · 30/06/2025
Getting ready for a 3-day DataLad workshop, organized by @dkz2r with @adswa @doktorpanik @jsheunis www.dkz2r.de/events/2025-06-30_data… Everything will be hot: all new materials, and the city of Aachen has prepared 30C+ and lots of sun! @abcdj reaching out beyond […]
mas.to
Original post on mas.to
110
Michael Hanke @mih.mas.to.ap.brid.gy · 31/05/2025
There is now a #gitAnnex package on #PyPi: pypi.org/project/git-annex This should make it simpler to deploy git-annex in Python virtual environments, also as versioned dependencies for software like #Datalad Packages are built for Linux, Windows, and Mac via GitHub actions […]
mas.to
Original post on mas.to
103
Reposted by Michael Hanke
Paco Hope @paco.infosec.exchange.ap.brid.gy · 15/05/2025
OMG. #Microsoft #Copilot bypasses #Sharepoint #security so you don’t have to! “CoPilot gets privileged access to SharePoint so it can index documents, but unlike the regular search feature, it doesn’t know about or respect any of the access controls you […] [Original post on infosec.exchange]
The “all the things” meme where a scribbled cartoon character has a fist raised and their mouth open like shouting. It says “Backdoor all the things!”
817178
Reposted by Michael Hanke
Bastian Greshake Tzovaras @gedankenstuecke.scholar.social.ap.brid.gy · 31/03/2025
We have decided to sunset openSNP at the end of April. While triggered by the sale of #23andme, @PhilippBayer @i_dabble & I had been thinking about this for a while. Ultimately, we think that it's the most responsible act of data stewardship given the state of the world. I've written a […]
scholar.social
Original post on scholar.social
4215
Michael Hanke @mih.mas.to.ap.brid.gy · 28/03/2025
If you are not on it already, it would be a good time to pull precious information from US sites and data portals. git init git annex init git annex addurl --file <goodname> <urltoresource> git commit -m "goodmessage" will preserve the content, checksum, time of download, downloader and origin […]
mas.to
Original post on mas.to
102
Reposted by Michael Hanke
Bodo Tasche @bitboxer.mastodon.social.ap.brid.gy · 18/02/2025
You know why we Germans are so pedantic about data protection? Someone around 90 years ago went through all records available, selected people with certain criteria, with the help of IBM, and then killed them all. We don't want to be on any list. And now the US Gov and Musk is trying to get […]
mastodon.social
Original post on mastodon.social
16932
Michael Hanke @mih.mas.to.ap.brid.gy · 14/03/2025
Soon the #alibabacloud will only be useful for running things that do not need to talk to the internet whatsoever. I feel sorry for the other folks in 47.0.0.0/8.
000
Reposted by Michael Hanke
Yann Büchau :nixos: @nobodyinperson.fosstodon.org.ap.brid.gy · 11/03/2025
I often annotate or arrange images in :inkscape: @inkscape and emojis are often a very nice addition to point to things or add emphasis. Here I made a useful emoji SVG picker with #bemoji, #twemoji and #homeManager that simplifies search and dragging into any […] [Original post on fosstodon.org]
011
Reposted by Michael Hanke
Lars Fosdal @larsfosdal.mastodon.social.ap.brid.gy · 05/03/2025
Follow the #instructions
There is a cardboard box with a half full wine glass standing on a IKEA-style drawing on the box - of a wine glass, followed by the steps 1 + 2 + 3 = a drawing of a bookshelf.
On top, there is a text saying "If I'm reading the instructions correctly, after 3 glasses of wine, the bookshelf assembles itself.
3959
Reposted by Michael Hanke
Nate Vack 🍴 @njvack.ruby.social.ap.brid.gy · 21/02/2025
Dear World, You can now see what happens when a group of people bent on empowering themselves at any cost get root access to government databases. It's happening in the USA. It's likely to get much worse. It can happen to your government, too. There are ways to design systems that don't have […]
ruby.social
Original post on ruby.social
001
Michael Hanke @mih.mas.to.ap.brid.gy · 04/03/2025
The events of the past weeks have again upped the urgency of moving away from the US tech cloud. After forever Google and 18 years GitHub this is hard for me. I am lucky that @distribits gave me the enthusiasm and the tools to make this happen for me and the #infrastructure of the #research […]
mas.to
Original post on mas.to
103