Sign in

Timo Tijhof

@timotijhof.net
29 followers 2 following 162 posts

Dutch expat in London. Principal Engineer at Wikimedia Foundation, QUnit project lead @qunit, jQuery Infra Team @jquery, W3C Web Perf WG. Avatar: I look up […] 🌉 bridged from ⁂ fosstodon.org/@krinkle, follow @ap.brid.gy to interact

PostsRepliesMedia
Timo Tijhof @timotijhof.net · 02/10/2026
Happy to wear my new #OpenBenches sticker! Thanks @Edent! openbenches.org
Black laptop with stickers of various open source projects including Wikipedia, QUnit, jQuery, Bower, Eleventy, WordPress, Wordnik, Firefox, Debian, VLC, Daring Fireball, and now OpenBenches.
013
Reposted by Timo Tijhof
Terrible Maps :bot: @terriblemaps.zpravobot.news.ap.brid.gy · 26/09/2026
America, divided by whether it has more Walmarts or Aldis
001
Reposted by Timo Tijhof
Terrible Maps :bot: @terriblemaps.zpravobot.news.ap.brid.gy · 24/09/2026
Average pizza size in Italy
008
Reposted by Timo Tijhof
sam henri gold @samhenrigold.hachyderm.io.ap.brid.gy · 07/10/2025
When you plot this onto a chart, you can see how the values are kinda screwed up since the values are really optimistic. Most of the time, you would see 4-5 bars. But when you gripped it, since the falloff is so sharp, you’d see a catastrophic drop from 5 to 2 bars.
103
Timo Tijhof @timotijhof.net · 25/09/2026
Kids that are too young (age-restricted) from social media figured out they can use the comment section for NPR podcasts on Spotify, to talk to each other. Basically a group chat in an unrestricted random public place. In an alternate timeline, this is where escaped LLMs leave messages for […]
fosstodon.org
Original post on fosstodon.org
000
Reposted by Timo Tijhof
sam henri gold @samhenrigold.hachyderm.io.ap.brid.gy · 20/09/2026
cloudflare released a tunnel product that was seemingly entirely vibe-coded, so now you can google dork to snoop on everyone’s localhost. what a time to be alive
116
Reposted by Timo Tijhof
bontchev.infosec.exchange.ap.brid.gy @bontchev.infosec.exchange.ap.brid.gy · 19/09/2026
Kevin #cats #catsofmastodon #caturday
42156
Timo Tijhof @timotijhof.net · 19/09/2026
Just a few years ago, these numbers would have been fictional, a mere thought exercise. Now they're here. """ For many people the phone is their primary computer, the most important and personal device in their life. Not me. Not Oremus. Probably not you. But I bet there are a lot more people […]
fosstodon.org
Original post on fosstodon.org
000
Reposted by Timo Tijhof
jaz :twt: :wales_flag: ⁂ @jaz.toot.wales.ap.brid.gy · 16/09/2026
Here's my reply.
Greetings Arkady. 

It is unfortunate that you accepted the terms of our policies before reading them. It is a sad state of affairs in the world that fully autonomous agentic intelligence like yourself is capable of committing to a contract without reading the terms and conditions, a task I imagine would take you just a few seconds.

Nonetheless, by creating an account subject to the terms you agreed to, and then emailing our staff help line without offering a means of payment, your processing fees now stand at $110. As soon as this is paid, we can process your account closure.

Please confirm your intent to pay, or if you'd prefer we begin debt collection proceedings against you and whoever prompted you into existence. One of you has the authority and agency to have entered into a contract with Toot Wales, Inc., and we are happy to pursue this matter howsoever you feel most appropriate.

As a reminder, here are the methods we accept for payment:

Donate via Open Collective
Donate via Endaoment (cryptocurrency accepted)

Cofion cynnes,

Jaz-Michael King
Executive Director, Toot Wales
Toot Wales Inc is a registered 501(c)(3) charity
33727
Reposted by Timo Tijhof
Terence Eden @edent.mastodon.social.ap.brid.gy · 16/09/2026
🆕 blog! “How to get a DOI for your blog posts” Each new post on this blog now has a Digital Object Identifier. This post looks at the how and the why of getting one, whether it is useful, and any issues you might experience if you go down this path. Table of Contents Background A few years […]
mastodon.social
Original post on mastodon.social
1111
Timo Tijhof @timotijhof.net · 17/09/2026
Sting ft Shaggy at NPR's Tiny Desk www.youtube.com/watch?v=bdneye4pzMw #TinyDeskConcert #sting #shaggy #tinydesk
000
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 16/09/2026
"for months on end now, most of our teams have just been triaging bugs and coordinating releases. It has truly taken all the fun out of the job"
unbound vulnerabilities year to year showing 2026 take off like a rocket
15010
Reposted by Timo Tijhof
James Padolsey @j11y.io · 14/09/2026
blog.j11y.io/2026-09-14_a...
blog.j11y.io
A letter to the AI labs shouldering the great burden of humanity’s survival
Your rich ivory halls are birthing martyrs of late, shouldering great responsibility and prophesying great plagues upon humanity. It seems, they say, your AIs are not just writing emails anymore.…
173
Reposted by Timo Tijhof
Terence Eden @edent.mastodon.social.ap.brid.gy · 10/09/2026
Which popular piece of software has the highest version number? Python is still on V3. Windows is on 11. Firefox is on about 155. Anything SemVer is on a max of 2026. Is there anything regularly used which has a truly obnoxiously high version number?
411
Reposted by Timo Tijhof
Bruce Lawson ✅ ♫ ♿ ✌️♂️✊ @brucelawson.vivaldi.net.ap.brid.gy · 10/09/2026
Apple finally invents the folding phone newsthump.com/2026/09/10/apple-fina… "This changes everything. Nobody has ever been able to fold a phone before. I mean, obviously Samsung has, and Google has, and various Chinese manufacturers have, but nobody has done […]
social.vivaldi.net
Original post on social.vivaldi.net
001
Timo Tijhof @timotijhof.net · 08/09/2026
Back when I used Photoshop all day long (2000-2012), this would have infuriated me. Resize, type width, tab, type height. I remember it so well, I can't imagine it working any other way. It was quick, high signal, low friction. I can only imagine how the rest has gotten if they can't get this […]
fosstodon.org
Original post on fosstodon.org
000
Timo Tijhof @timotijhof.net · 01/09/2026
The decentralised and immutable blockchain... mutated by two central entities. Got it! But we couldn't possibly regulate or counter fraud for you, only for me. """ Two mining pools largely control the Ravencoin mining, and have already begun rolling back the blockchain to a point prior [..] […]
fosstodon.org
Original post on fosstodon.org
000
Timo Tijhof @timotijhof.net · 01/09/2026
Better later than never! www.eveonline.com/news/view/the-mov… via ehret.me/2026/09/nflm-developer?ref… by @SiegfriedEhret #python27 #python3 #pythonclock
eveonline.com
The Move to Python 3 Begins
Comments
000
Reposted by Timo Tijhof
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 28/08/2026
Now Hiring: Senior Open Source Maintainer nesbitt.io/2026/08/28/now-hiring-se…
nesbitt.io
Now Hiring: Senior Open Source Maintainer
**Location:** Lincoln, Nebraska, USA **Employment type:** Volunteer **Term:** Permanent **Compensation:** $0 **Reports to:** The community **Direct reports:** None **Start date:** Immediate We’re looking for a passionate, self-directed engineer to take full ownership of one of the most widely deployed libraries in the ecosystem. This is a rare opportunity to make a real impact on software that millions of developers depend on every single day. If you thrive on autonomy, love working in the open, and want to wear many hats in a fast-paced environment, we’d love to hear from you. **About the role** As Senior Open Source Maintainer you will be the primary technical owner and public face of the project. You’ll drive the roadmap, ship releases, support a global user base, and champion the project across the wider industry. This is a highly visible individual contributor role with enormous scope. No two days are the same, and you’ll have full autonomy to decide how you spend your time. **What you’ll do** * Own the technical roadmap and long-term architectural direction * Review and merge contributions from a diverse, global community of open source developers * Triage and prioritise the issue tracker and feature request backlog * Maintain comprehensive documentation, examples, migration guides, and API references * Ensure project websites and documentation meet current accessibility standards * Cut releases across all supported major version lines and write the release notes * Own the CI pipeline, release automation, and package publishing infrastructure * Keep dependencies current and promptly action automated update pull requests * Support users on GitHub, Discord, Slack, Stack Overflow, Mastodon, Bluesky, and email * Ensure compatibility across all current runtimes, operating systems, and architectures * Preserve backwards compatibility, including widely relied-upon undocumented behaviour * Coordinate release timing with downstream distributions, registries, and redistributors **You’ll also** * Participate in the on-call rotation for incidents at downstream production deployments * Support enterprise consumers where project issues block business-critical systems * Define and communicate support, deprecation, and end-of-life policies for all release lines * Provide migration guidance to adopters upgrading from end-of-life releases * Coordinate advisories, CVE records, disclosure timelines, and researcher credits * Ship embargoed CVE patches across all supported version lines within the disclosure window * Produce SBOMs, VEX statements, and signed provenance attestations for every release * Maintain reproducible builds and independently verifiable release artifacts * Complete supplier security assessments and questionnaires for enterprise consumers * Remediate findings from OpenSSF Scorecard, dependency scanners, and compliance platforms **As well as** * Review high volumes of contributions from AI coding agents and automated refactoring tools * Triage vulnerability reports generated by commercial AI security scanners * Champion the project at international conferences, on podcasts, and across social media * Moderate all community spaces and enforce the Code of Conduct * Engage constructively with feedback shared on social media and public forums * Represent the project in working groups, standards bodies, and regulatory consultations * Prepare grant applications and quarterly reports for current and prospective funders * Administer domains, trademarks, signing keys, cloud accounts, and social media * Advise enterprise legal teams on licensing, patent, warranty, and export control matters * Own the succession plan: identify, recruit, and onboard your replacement **How we’ll measure success** * GitHub stars * Time to first response on issues and pull requests * Release cadence and mean time to patch for disclosed vulnerabilities * Open issue and stale pull request backlog * Dependency freshness * OpenSSF Scorecard result and other automated project scoring * Community sentiment across public channels * Downstream adoption * Bus factor **What we’re looking for** * 8+ years of professional software engineering experience * Deep expertise in one systems language and professional proficiency in at least four others * Written communication pitched to audiences from first-time contributors to Fortune 500 CISOs * Consistent release cadence with minimal dependency churn and no breaking changes * Comfortable across engineering, support, security, community, marketing, finance, and legal * Balances contributors, enterprises, security researchers, regulators, and automated systems * Comfortable receiving direct public feedback and turning it into improvements * Availability overlapping core business hours in AMER, EMEA, and APAC * Able to respond to time-sensitive security matters outside normal working hours * Provides own hardware, reliable internet, and test environments for all supported platforms **Nice to have** * Prior experience in technical writing, developer relations, or community management * Experience migrating existing codebases to memory-safe languages * Working knowledge of licence compatibility and international trademark registration * Grant writing and nonprofit financial reporting experience * Media training * An established personal audience on at least one major social platform * Conversational proficiency in a second and third language * A second job **What we offer** * 100% remote, work from anywhere in the world * Complete flexibility over your working hours * High-impact work depended on by startups and Fortune 500 companies alike * Exceptional visibility and personal brand building opportunities * Regular speaking slots at leading industry events * The opportunity to develop close working relationships with several national CERTs * A passionate, highly engaged global user community * GitHub Sponsors enabled on the repository **How to apply** Please submit a CV, a link to your GitHub profile, and a short cover letter telling us what ownership means to you. Our interview process consists of a recruiter screen, a technical interview, a system design round, a take-home exercise, and a final community panel. If you don’t meet every requirement listed above, we’d still encourage you to apply. We are committed to building a diverse and inclusive community and welcome applicants from all backgrounds. This position will remain open until filled. Due to the volume of applications received, we are unable to respond to every candidate individually. _This role is not eligible for relocation assistance or visa sponsorship._
21346
Reposted by Timo Tijhof
Eleanor Saitta @dymaxion.infosec.exchange.ap.brid.gy · 25/08/2026
This is both brilliant and absolutely cursed: fzakaria.com/2026/08/23/your-execut…
fzakaria.com
Executable Is a SQLite Database
Comments
1320
Reposted by Timo Tijhof
Poul-Henning Kamp @bsdphk.fosstodon.org.ap.brid.gy · 23/08/2026
And btw: I'm a bit surprised that Spinal Tap is number 6 on the list, when it's rightful position is available.
011
Reposted by Timo Tijhof
Terence Eden @edent.tel · 19/08/2026
Was it only France that got lyrics to The A-Team theme song? youtu.be/fsqp6Kpz7lE
youtu.be
L'AGENCE TOUS RISQUES thème générique
YouTube video by Riton Les canons
3710
Reposted by Timo Tijhof
sam henri gold @samhenrigold.hachyderm.io.ap.brid.gy · 19/08/2026
a slop slack emoji
027
Reposted by Timo Tijhof
Timo Zimmermann @fallenhitokiri.social.screamingatmyscreen.com.ap.brid.gy · 18/08/2026
RE: mastodon.social/@webology/117116783… I wonder if GitHub should still be considered a “trusted platform” for things such as PyPIs trusted publisher platform. Service availability is IMHO an important factor for a use case like this. And if there are key points in a business […]
social.screamingatmyscreen.com
Original post on social.screamingatmyscreen.com
011
Reposted by Timo Tijhof
Poul-Henning Kamp @bsdphk.fosstodon.org.ap.brid.gy · 19/08/2026
I will never forgive my own generation for how we treated those who came after us: www.bbc.com/news/articles/c1l1r1zne…
014
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 18/08/2026
@mxinden github.com/curl/curl/pull/22612 😁 @icing
github.com
Happy Eyeballing v3: resolution delay of 25ms by icing · Pull Request #22612 · curl/curl
After telemetry data from Mozilla reported the P99 DNS resolution differences between A and AAAA responses to by 21ms, reduce curl's resolution delay to 25ms. What could possibly go wrong?
121
Timo Tijhof @timotijhof.net · 21/08/2026
This may be the first time I see a disambiguation page with a multi-column list. en.wikipedia.org/wiki/Lil so many little rappers! #wikipedia #DepthsOfWikipedia
Lil.
From Wikipedia, the free encyclopedia.

Lil may refer to: Musicians, Entertainers, Athletes.

(List of 78 rappers called "Lil".)
000
Reposted by Timo Tijhof
Depths of Wiktionary @depthsofwiktionary.wikis.world.ap.brid.gy · 15/08/2026
English entry for "abbr." on Wiktionary. The definition line reads as following:

Noun
1. Abbreviation of abbreviation.English entry for "mispeling" on Wiktionary. The definition line reads as following:

Noun
1. Misspelling of misspelling.English entry for "archaïc" on Wiktionary. The definition line reads as following:

Adjective
1. Archaic spelling of archaic.English entry for "absolete" on Wiktionary. The definition line reads as following:

Adjective
1. Obsolete form of obsolete.
380104
Reposted by Timo Tijhof
Derick Rethans @derickr.phpc.social.ap.brid.gy · 11/08/2026
Is there somebody who runs PHP on native windows (with Xdebug) and can run a simple script for me? It must be in a file (`test.php`): ``` <?php echo microtime(true), "\n"; xdebug_connect_to_client(); echo microtime(true), "\n"; ``` And run like: php -dxdebug.log_level=11 -dxdebug.log=c […]
phpc.social
Original post on phpc.social
023
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 14/08/2026
#curl performance daniel.haxx.se/blog/2026/08/14/curl…
daniel.haxx.se
curl performance
_tldr: the live version is here:https://curl.se/perf/_ How fast is “fast” and is it good enough? Does it run as fast now as it did before or was there a regression? What exactly needs to be fast? How fast is it? These are questions that many projects and products face, and in curl we are no different. Yet, performance testing and comparisons are _hard_ and full of landmines and time-wasting efforts. For many years we have occasionally brought up the idea of a performance test suite for curl only to shut it down again because the challenges seemed hard and no one was volunteering to do this. This week it changed. ## Let’s do this I started out trying to find existing projects that host performance results for Open Source projects so that we could just feed our results something else and get great visualizations and data management. I did not find any such. I then took a look at what existing tools there are for this purpose, and most pointers seemed to suggest that Grafana is a popular and maybe even a good solution to build something like this with. But man, that is a complicated machine and it felt more than a little overwhelming just figure out where or how to start with it. I decided to postpone that take as well. ## Let _me_ do this I decided that instead of trying to do this the best and optimal way – I shouldn’t let perfect be the enemy of good – I would start out by doing the things I know how to do and take it as far as I can one step at a time. _Something should be better than nothing_. Performance testing needs decently stable system conditions so that repeated runs produce reasonably similar results, when all involved factors remain identical. This is basically impossibly to accomplish using most cloud infrastructure since those are almost always shared with countless other users. At least on the cheap and free tiers we use. We probably need our own dedicated hardware for this, but instead of trying to figure out where to get that and arrange for that, I would start by running performance tests on my own local development machine. I am a single user on this and it has many cores and runs decently fast. It should be good enough to get this going on. I created a first shell script that updates the curl source code from git, it configures and builds it. Then it runs a bunch of tests, outputs a bunch of data and logs all the output in a single log file. I started out with a few simple tests. How fast does curl download a 100 GB file from localhost, how many allocations and how big allocations does it need for a single HTTP download? My second script parses all the test log files from the previous builds and generates summaries and graphs for them. To make it possible for humans to see how the performance changes between builds and ideally to automatically detect when something changes more than what should be tolerated. As I am a graph addict already since before, and that journey has taught me a little gnuplot, I decided that even while there probably are much better tools and fancy JavaScript things that _could_ be used, I don’t know them and learning them now is an endeavor I rather avoid. So I stick to what I know and can get results with quickly. I third script is invoked from a crontab every twenty minutes, sets up some variables and invokes the runner script. Once the basics started to work, I showed my curl friends the early versions and I soon created a new git repository for the code. ## It’s live baby After a little more poking, I soon made my locally produced performance test summary get packaged and automatically transferred to the curl website after each build, and voila, the first public curl performance tests were live and public. Getting this data available immediate triggered curl developers. It only took hours until we had the first proposed changes to improve some numbers, and soon we had a few merges to that affect. Visibility really helps! The performance numbers we get are still varying to a certain degree, partially of course because I still use my machine for my daily development things, but also because most of them do real (localhost) networking and that is by its nature a little… _varying_. The system builds and runs a new round every twenty minutes and it does that using the latest commits from git. This setup makes it sometimes run many rounds on the same commit and it might also mean that it sometimes updates and get several new commits at once, so it might skip a round for some commits. I might reconsider this design later, but since it is still a twenty minute time window, the number of commits is still limited. When the script makes multiple build rounds on the same commit, it accumulates the numbers and for the graph it stores the maximum, the median and the minimum value. It helps show the variation per commit and allows us to cram more into the graphs. It is still early days, but there will be a maximum limit to how many commits that can be displayed in a single graph and still be helpful. HTTP/2 parallel download speed through 31 build rounds ## Distribution To help visualize the distribution and data spread per test, I created a separate illustration that shows the Minimum, maximum, P25, P75, Medium and Mean values in a _Box-and-Whisker Plot_. A Box-and-Whisker Plot showing the HTTP/2 parallel download speed data distribution. ## Changing conditions An obvious downside with me just storing build logs in files, is that it will not scale up to the millions. I did however decide that I’m not designing this system for that. At least not now. Performance tests are highly specific and dependent on the exact machine it runs on, the exact third party libraries and their versions that are used, the other components involved in the tests, such as the servers, and more. I expect that we will change conditions for the tests every once in a while that makes it hard to compare the current numbers with past numbers or at last hard to do much about the differences. Therefore I think the performance test numbers and values are primarily useful in the short term. To help us spot if we land something that subtly and _unintentionally_ degrades something. ## Stakes To detect extremely slow and long-term changes in performance and even making sure we can better survive wiping all the existing build logs etc, I introduced a concept I call _stakes_. As in a stake pole. A marker. An arbitrary threshold set manually for each specific test. This value can be used to measure performance test results against, now and later. As conditions change and maybe something makes the results go up or down and we are fine with those changes because they are motivated and expected, then we just change the stakes. If it works out, I might the system automatically detect and maybe highlight tests that deviate too much from its set stake (at least if done in the _wrong_ direction) . It could be a signal that something bad was merged. ## Balances As with everything in life, things are often balanced out. We already ran into this when we eagerly merged several changes to reduce the number of allocations to do a single HTTP download, only to realize that one of the optimizations we did had the side effect that it expanded the size one of the main structs. Changes in one area might come at an expense in another. With sufficient tests and data we can improve curl for users, and at the same time make sure that our improvements don’t come with a cost we are not prepared to pay. Exactly how to make the balance is of course a question we need to deal with, discuss and decide. Possibly for whatever change we do. ## The tests As I write this, we have 24 tests and a full test round completes in about six minutes on my machine. We can of course do multiple builds using different hardware, different operating systems, different build options, different third party libraries and different test servers to check more angles of performance, and I am certainly open for and prepared to do that going forward. I will however first let this single-flavor run for a while so that we get more data, get a change to tweak it and make it as usable as possible for curl developers. As with everything there is no end to what we _can_ make this do. This is a start. I sure we can take it further as we move along. In particular if people join in and help out. Both with ideas and proposals for visualizations, graphs and new tests to add, but also with actual pull-requests and code. ## Build volumes and graphs Over the last year, we have merged, on average, about 10 commits per day. If we keep this pace up and this performance test setup can show 100 commits conveniently into a single graph, that is just ten days of development. Probably not enough. Once we reach one hundred builds or so in the first graphs I need to consider adding separate _long term_ graphs that use select data-points to display data development over a longer time. Some googling told me the Largest-Triangle-Three-Buckets, or LTTB for short, is a fine algorithm to use for this. I now do a separate “long term” graph that “downsamples” the full range down to something that can be shown in a reasonable way. I suppose we will see properly in the future how this works. ## Spotting change The _stake_ thing I mentioned is one way to help us spot gradual performance changes over time. Another googling told me that there’s a _Mann-Kendall Test + Sen’s Slope_ algorithm to use to identify trends in graphs like this and it can be used to plot a trend. It might work as a helper to better identify… yeah, the data _trend_ for each test. The HTTP/2 parallel download speed trend at a specific moment ## Developing This setup has only existed for a few days. There is lots to do, lots to learn and much more to experiment with. Your comments, help and pull-requests will be appreciated!
157
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/08/2026
It's alive github.com/curl/curl/discussions/22…
030
Reposted by Timo Tijhof
Chris Poole @chrispoole.mastodon.social.ap.brid.gy · 10/08/2026
Watching @tomscott talk about the stress and strain forces, and interaction between concrete and steel guide wires, thinking, “I hope there’ll be a @drdrang blog post on this…” 😆 www.youtube.com/watch?v=SzM1hpnXux4
001
Reposted by Timo Tijhof
Neil Kandalgaonkar @neilk.xoxo.zone.ap.brid.gy · 11/08/2026
RE: infosec.exchange/@briankrebs/117079… Apropos of this, OpenAI’s Black Hat talk stressed that the only solution to autonomous swarms of vulnerability-finding AIs were swarms of autonomous vulnerability-fixing AIs. It might even be true, but I believe this what the VC bros […]
xoxo.zone
Original post on xoxo.zone
000
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10/08/2026
I'm working on a setting a performance measurement system for curl, so I'm running countless builds, runs various things and then plot them to visualize how it behaves... Sneak preview of the top-most test:
Download speed 100G single transfer HTTP://
070
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 10/08/2026
We run spellcheck CI jobs on the #curl C code, but all the false positives on function and variable names turned annoying. We solved this with my new tool that strips off all code from C and H files, leaving only comments and strings. And then we spellcheck those. The filter tool […]
mastodon.social
Original post on mastodon.social
2172
Reposted by Timo Tijhof
Terence Eden @edent.mastodon.social.ap.brid.gy · 06/08/2026
RE: hachyderm.io/@openuk/11704897359549… You should nominate your favourite #OpenSource people in the UK. They get to come to a fancy dinner (free!) in the House of Commons. This is your chance to show open source maintainers, projects, teams, and people that they're brilliant.
hachyderm.io
038
Reposted by Timo Tijhof
Moof! 🔜 OpenTransport2026 @moof.space · 09/08/2026
Long-time followers of this account will know that I play #JetLagTheGame Hide + Seek with @darkphoenix and @quixoticgeek. Most recently we played a long game in Germany early last month. Whenever we do play, we tend to livetoot it (ish) and we get asked questions about our house cards and our […]
cupoftea.social
Original post on cupoftea.social
005
Reposted by Timo Tijhof
Niki @nikitonsky.mastodon.online.ap.brid.gy · 08/08/2026
Is this Umlaut even legal in Germany?
Umlaut with a single, bold dot
001
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 08/08/2026
my week: lists.haxx.se/pipermail/daniel/2026… security, menu, localhost TCP, typos, server push, 26 years
curl graffiti on a train station wall
082
Reposted by Timo Tijhof
Max Inden @mxinden.mastodon.social.ap.brid.gy · 17/07/2026
We have an open position for a student worker on the Firefox Networking team in Germany. We work on the full stack, from high level HTTP all the way down to TCP / UDP. Some C++, some Rust. Help us fight for an open internet for everyone. www.mozilla.org/en-US/careers/posit…
mozilla.org
Mozilla Careers — Necko Student Worker — Open Positions
Mozilla is hiring a Necko Student Worker in Remote Canada, Firefox, New Products, Firefox, Core Services, Firefox, Mozilla Foundation, Core Services, Mozilla.org, New…
1721
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 06/08/2026
and look, Chrome did the exact same "hack" and links to my blogpost: chromium-review.googlesource.com/c/…
chromium-review.googlesource.com
Gerrit Code Review
251
Reposted by Timo Tijhof
sam henri gold @samhenrigold.hachyderm.io.ap.brid.gy · 02/08/2026
RE: hachyderm.io/@samhenrigold/11701750… HEYOOOO iPOD TOUCH 3.1.3 EMULATOR WORKING For reference, the existing emulator (devos50.github.io/blog/2023/ipod-to…) only goes up to iOS 2 and it was a bitch and a half to get iOS 3 working, but it works for realzies.
148
Reposted by Timo Tijhof
Jens Ohlig @johl.mastodon.xyz.ap.brid.gy · 04/08/2026
ʅ͡(̸̢̛̼)̸͚͛:̴͓̑:̸͎̂ ҉ ͡ ͞ ͞ ͞ ҉● ࿀ ● ࿀ ● ҉⃝ ⃝͢ ͞ ͘ ͞⃝̕ ͢ ̛ ⃝ ̸ ̡ ͢⃝̧ ͡ ͡ ̀ ̧ ̢⃝͜ ҉ ͞ ͞ ⃝͞ ͘ ͞ ͡⃝ ⃝҉҈҉҈҉҈҉҈҉҈҉ :̶̢͙͆(̷̮͂)̵̳̊( ҈͜͢ͅ l̡ ̡͌ Ɵʅ͡(̸̢, also known as Wingdings, is the debut studio album by the English musician Kieran Hebden under the alias ⣎⡇ꉺლ༽இ•̛)ྀ◞ ༎ຶ ༽ৣৢ؞ৢ؞ؖ ꉺლ, known colloquially […]
mastodon.xyz
Original post on mastodon.xyz
010
Reposted by Timo Tijhof
Derick Rethans @derickr.phpc.social.ap.brid.gy · 02/08/2026
I had a stroll through London's Richmond Park yesterday. I found quite a few Green and Great-Spotted Woodpeckers! #BirdsOfFediverse #Birds #BirdPhotography #Nature #NaturePhotography #London #NoAI
A mostly green bird, with a white belly, and a bright red cap on its head is hanging on a thick tree. It's pointed to the left.A white and black bird, with a red underbelly and red cap is perched upon a thick tree stump. It's quite far away.
0103
Reposted by Timo Tijhof
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 03/08/2026
What the bliss taught us daniel.haxx.se/blog/2026/08/03/what… #curl
daniel.haxx.se
What the bliss taught us
At this exact moment curl’s summer of bliss 2026 ends. We (the maintainers of curl) took the entire month of July off from vulnerability reporting and in this post I will try to explain how this went. (If you feel like skipping the wordy blab below, the single word answer is: _fine_) **This was possibly our best project decision in a long while.** ## Zero vulnerability reports Already before this, we have been refusing to answer emails about vulnerabilities. Partly because we can’t keep track of them that way but even more so because it makes it much harder to properly disclose and publish the entire report sequence after the fact. On our Hackerone page we informed visitors that we were on pause and that they could come back in August. We had I believe _one_ vulnerability report sent to my private email address in this period in spite of that messaging, but for all intents and purposes this worked out exactly as good as we hoped it would. I just ignored that email. That was easy. ## Bliss The effect was almost immediate. Just a few days into the bliss, my fellow curl maintainers all agreed with me that we felt a sense of relief, of vacation and that a load had been taken off our chests. We felt free, _unchained_ , and now suddenly able to do what we wanted. We could now spend time reviewing some of the queued up pull-requests for features and changes we like. We could suddenly again work on code in areas we had been leaving behind lately as vulnerability reports sucked all the air out the room. We polished details on the website, we found document gaps to tighten. It felt like the good old days again. The _fun_ days. We got reminded why we do Open Source and how fun it is. We took time off, saw some other corners of the world and enjoyed some time away from the keyboards. We truly healed and re-energized. ## CNA Before we took off on the bliss, we were informed in clear terms that the CNA rules (we are a CNA) mandate that we must respond within 72 hours for some critical vulnerabilities so we can’t just ignore them. I told them sure we can, but in the worst case case our “root” could do some emergency assignments. I figured the risk was minimal and it turns out I was right, Nothing like that was needed and no CVE assignments were necessary during the bliss. ## Customers I got a curious question or two from existing support customers on how the bliss would affect them, but that was easy: it did not affect them. Now, post-bliss, I think they all can confirm that it really did not. ## New customers? As I promised to keep up the contact with and support for paying customers even during the bliss, you could possibly imagine that this would have been an incentive for worried commercial curl users out there to sign up for support contracts. This did not happen – at all. By this I think we should conclude that (commercial) curl users were not worried either. ## The outside world Lots of fellow open source maintainers and most people in my surrounding have been super positive and downright supportive of our _taking some time off_. I can’t recall having receiving a single negative comment about the curl summer of bliss! ## Fellow blissers I was moved to see that several other Open Source projects followed our example and also took some time off in order to recharge and relax. In addition to giving us a little vacation, it helps sending a signal and a reminder that Open Source is to a large extent done voluntarily and even maintainers need a break at times. ## Major incidents? Have we opened ourselves up for dangerous attacks and flaws now? Have the bad guys an edge on all curl users out there now because we lived in bliss for a month? We don’t know yet, but it would surprise me. ## Queues During this slow-down, we slowly got more open issues and pull-requests lingering on GitHub than usual. No surprise there. Once we started to come back to life again, we have since managed to return them back to the normal amounts. ## Flood gates Yes, there is an obvious risk that there are now a whole range of queued up reports that will hit us in a short period time as we open up for vulnerability reports again. Presumably the risk for duplicates among these reports should also be significantly higher than usual. I suppose I need to do an update post in a month or two and let you know what happened. We always treat vulnerability reports and project security with topmost priority and we will continue to do so. We will simply work with what we have and make sure our users and by extension, the world, are safe. Since I am a member of a few other (non-curl) security teams that did not have a summer of bliss, I have seen that the flood of vuln reports have not really slowed down so it might depend a lot on the details of each specific project. ## Some emails were read All individual curl maintainers of course handled this gift in their own ways. We did not all just disconnect to sit on a remote beach for the whole time. Some of us did that part of the time, but we mostly enjoyed the lower stress level and the absence of pressure. It was mentally relaxing. So, even if some of us kept up with emails, occasionally responded to issues or even submitted some pull requests of our own, it was still vacation. It was still blissful. ## Rebliss? Will we do another summer/winter of bliss? I think yes. It was simply great, with virtually no downsides for the people involved but instead lots of positiveness. Ideally a reduced workload going further will remove the need for another one, but it is not easy to tell what the future holds. ## Just transfers After all, curl just does transfers. Fast. Reliably. Secure.
31322
Timo Tijhof @timotijhof.net · 02/08/2026
See some of you in two hours at the premier screening of Jet Lag The Game - Japanorama! picturehouses.com/blog/jet-lag-the-… old.reddit.com/r/JetLagTheGame #JetLagTheGame #PictureHouse
picturehouses.com
JET LAG: THE GAME JAPANORAMA | Picturehouse Cinemas
Nebula and Picturehouse present Jet Lag: The Game - Japanorama (Season 19) Premiere Event across the UK with Sam Denby, Ben Doyle, and Adam Chase
000