GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:35:51 JST Hélène Hélène
    should implement support for accepting activities with LD signatures but I just hate the design too much
    if that can even be called a design, it's just terrible
    In conversation Wednesday, 14-Sep-2022 18:35:51 JST from p.helene.moe permalink
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:37:59 JST Hélène Hélène
      in reply to
      if you decide to implement signatures by putting the signature inside the structure of what is signed I will become the American Psycho
      In conversation Wednesday, 14-Sep-2022 18:37:59 JST permalink
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:40:10 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene bitcoin
      In conversation Wednesday, 14-Sep-2022 18:40:10 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:41:09 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko but they sign other signatures so that's different
      In conversation Wednesday, 14-Sep-2022 18:41:09 JST permalink
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:44:10 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko oh so like mitra.social
      In conversation Wednesday, 14-Sep-2022 18:44:10 JST permalink
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:44:11 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene ok but
      what if
      like
      just hear me out here
      what if
      we took pleroma right
      and then like
      right we got pleroma
      and then like we could like idk
      you know what i'm saying
      put it on the ethereum?
      so like
      pleroma on the blockchain
      you know what i'm saying
      In conversation Wednesday, 14-Sep-2022 18:44:11 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:44:26 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko https://docs.joinmastodon.org/spec/security/ seriously look at this i'm so upset
      In conversation Wednesday, 14-Sep-2022 18:44:26 JST permalink

      Attachments


    • Embed this notice
      inference (inference@plr.inferencium.net)'s status on Wednesday, 14-Sep-2022 18:44:35 JST inference inference
      in reply to
      @helene What? Signing inside of what needs to be signed? How would that even work?
      In conversation Wednesday, 14-Sep-2022 18:44:35 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:44:37 JST Hélène Hélène
      in reply to
      • inference
      @inference poorly
      In conversation Wednesday, 14-Sep-2022 18:44:37 JST permalink
    • Embed this notice
      johann150@genau.qwertqwefsday.eu's status on Wednesday, 14-Sep-2022 18:45:38 JST Johann150 Johann150
      in reply to

      @helene@p.helene.moe mastodon instance self destructs and turns helene into the american psycho

      https://docs.joinmastodon.org/spec/security/#ld

      In conversation Wednesday, 14-Sep-2022 18:45:38 JST permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Security
        Public key cryptography and supported signature schemes over HTTP and JSON-LD.
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:45:58 JST Hélène Hélène
      in reply to
      • Johann150
      @Johann150 that is precisely why i am upset
      and as far as i know matrix does this too
      In conversation Wednesday, 14-Sep-2022 18:45:58 JST permalink
    • Embed this notice
      inference (inference@plr.inferencium.net)'s status on Wednesday, 14-Sep-2022 18:46:01 JST inference inference
      in reply to
      @helene Let's write the address of where the letter should be send to *inside* of the envelope...

      Same concept.
      In conversation Wednesday, 14-Sep-2022 18:46:01 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:48:15 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko the true paidspeechextremist.com (i have no idea)
      In conversation Wednesday, 14-Sep-2022 18:48:15 JST permalink
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:48:16 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene looks interesting but does it cost a dollar to write a post
      In conversation Wednesday, 14-Sep-2022 18:48:16 JST permalink
      Hélène likes this.
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:50:31 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene wait do i understand correctly that the signature fields get added inside of the content after the signature is made and to test the signature you have to remove thoso fields before?
      In conversation Wednesday, 14-Sep-2022 18:50:31 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:50:32 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko yes.
      In conversation Wednesday, 14-Sep-2022 18:50:32 JST permalink
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:51:38 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene what the fuck, could've just made a breaking API change
      In conversation Wednesday, 14-Sep-2022 18:51:38 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:52:22 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko it's because they want activities to be relayed without needing to contact the original instance if you support the feature and because they didn't want to break federation
      still a terrible idea
      In conversation Wednesday, 14-Sep-2022 18:52:22 JST permalink
    • Embed this notice
      Ukko (fake) (ukko@p.enes.lv)'s status on Wednesday, 14-Sep-2022 18:55:35 JST Ukko (fake) Ukko (fake)
      in reply to
      @helene yea but they could have the signed data be encapsulated not mixed with the signature. make sure to design it so that older versions drop&ignore it and have some grace period where mastodon would still send unsigned or http-signed messages

      well, what can i say, power of FOSS
      In conversation Wednesday, 14-Sep-2022 18:55:35 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 18:57:45 JST Hélène Hélène
      in reply to
      • Ukko (fake)
      @ukko there were ways around it really, but the idea of it isn't really great either honestly
      In conversation Wednesday, 14-Sep-2022 18:57:45 JST permalink
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 20:43:31 JST Hélène Hélène
      in reply to
      • patter
      • Ukko (fake)
      @patterfloof @ukko that's basically what they do though? just that it's awful because it requires modifying the payload and canonising JSON-LD
      In conversation Wednesday, 14-Sep-2022 20:43:31 JST permalink
    • Embed this notice
      patter (patterfloof@meow.social)'s status on Wednesday, 14-Sep-2022 20:43:32 JST patter patter
      in reply to
      • Ukko (fake)

      @helene @ukko why couldn't they borrow from signed email? where a pgp message signature is an attachment. you can read the message without parsing the signature, but the sig is proof that the message is unaltered & from whoever claimed to send it

      I guess it's like a lot of modern tech "we'll make it new & not look at what's already worked"

      In conversation Wednesday, 14-Sep-2022 20:43:32 JST permalink
    • Embed this notice
      infinite love ⴳ (trwnh@mastodon.social)'s status on Wednesday, 14-Sep-2022 22:48:19 JST infinite love ⴳ infinite love ⴳ
      in reply to

      @helene fwiw ld sigs are recommended against and were only implemented for relays, which people largely don't even use anyway

      if i were doing a greenfield project i simply would not bother, as i find relays conceptually flawed in their current form and also i think you can generally trust what was sent to you without having to verify it 100% -- like, have the relay do the verification before sending it out, then implicitly trust the relay

      In conversation Wednesday, 14-Sep-2022 22:48:19 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 22:48:55 JST Hélène Hélène
      in reply to
      • infinite love ⴳ
      @trwnh aren't they used to relay deletes/edits too as well as favs and a few others
      but yes they're terrible as-is
      In conversation Wednesday, 14-Sep-2022 22:48:55 JST permalink
    • Embed this notice
      infinite love ⴳ (trwnh@mastodon.social)'s status on Wednesday, 14-Sep-2022 22:54:45 JST infinite love ⴳ infinite love ⴳ
      in reply to

      @helene possibly idk, there are some limited cases where ld sigs are used/supported and there will probably never be more bc mastodev is against using them in general due to how terribad and complex they are

      i think favs are not relayed, they are sent directly to the author instead of your followers

      deletes are generally sent out via "best effort" paths which is roughly like sending it out to the whole known fedi

      In conversation Wednesday, 14-Sep-2022 22:54:45 JST permalink
      Hélène likes this.
    • Embed this notice
      patter (patterfloof@meow.social)'s status on Wednesday, 14-Sep-2022 23:49:28 JST patter patter
      in reply to
      • Ukko (fake)

      @helene @ukko if json was worthy of being canonised, it would have been created with original sin #justsayni

      In conversation Wednesday, 14-Sep-2022 23:49:28 JST permalink
      Hélène likes this.
    • Embed this notice
      Hélène (helene@p.helene.moe)'s status on Wednesday, 14-Sep-2022 23:49:45 JST Hélène Hélène
      in reply to
      • patter
      • Ukko (fake)
      @patterfloof @ukko few understand this
      In conversation Wednesday, 14-Sep-2022 23:49:45 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.