GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Mario Zechner (badlogic@mastodon.gamedev.place)'s status on Tuesday, 17-Oct-2023 11:52:50 JST Mario Zechner Mario Zechner

    The past two nights I wrote a "thread reader app" for BlueSky.

    https://skyview.social

    Oh boy. The protocol is absolutely insane. RPC galore, responses are only partially typed. The docs are pretty much useless.

    But the "funniest" part is this: there's no privacy. And I don't mean missing DMs.

    All your posts are available through API endpoints. Without any authentication. By design.

    The "invite-only" thing may have you think otherwise.

    Here are my last 100 posts.

    https://bsky.social/xrpc/com.atproto.repo.listRecords?repo=badlogic.bsky.social&collection=app.bsky.feed.post

    In conversation Tuesday, 17-Oct-2023 11:52:50 JST from mastodon.gamedev.place permalink

    Attachments


    1. https://cdn.masto.host/mastodongamedevplace/media_attachments/files/111/246/791/778/477/909/original/9070f60b3991b347.png
    • Pleroma-tan likes this.
    • HistoPol (#HP) 🏴 🇺🇸 🏴 repeated this.
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Tuesday, 17-Oct-2023 18:54:39 JST Sexy Moon Sexy Moon
      in reply to
      @badlogic your posts are marked as public on bluesky, they said there are only public posts on bluesky right now. the limitations are only because it's still in active development not intrinsic, if there was more then one server then obviously your posts would be readable by everyone without an app since it would be decentralized. mastodon has an unauthenticated feed for all public user posts as well. none of this is better or worse.
      In conversation Tuesday, 17-Oct-2023 18:54:39 JST permalink
      eris likes this.
    • Embed this notice
      Mario Zechner (badlogic@mastodon.gamedev.place)'s status on Tuesday, 17-Oct-2023 18:54:41 JST Mario Zechner Mario Zechner
      in reply to

      For all its faults, Mastodon is the better platform for people who care about having control over their data. It's definitely not perfect in that regard either, but at least it tries.

      Also, it has GIFs and videos and polls. Based on BlueSky's dev velocity, they'll have that sometime 2032.

      In conversation Tuesday, 17-Oct-2023 18:54:41 JST permalink
    • Embed this notice
      Mario Zechner (badlogic@mastodon.gamedev.place)'s status on Tuesday, 17-Oct-2023 18:54:42 JST Mario Zechner Mario Zechner
      in reply to

      Quite a few people sure were surprised to learn that all their posts can be read without a BlueSky account. Especially those who fled Xitter to be a bit more sheltered from harassers and nazis.

      Welp.

      In conversation Tuesday, 17-Oct-2023 18:54:42 JST permalink
      HistoPol (#HP) 🏴 🇺🇸 🏴 repeated this.
    • Embed this notice
      Herbi :coffefied: (herbi@mstdn.social)'s status on Tuesday, 17-Oct-2023 18:55:39 JST Herbi :coffefied: Herbi :coffefied:
      in reply to

      @badlogic When I sent my first post I received a warning similar to “Your posts are public” the faq also confirmed this.

      “Bluesky is a public social network. Think of your posts as blog posts – anyone on the web can see them, even those without an invite code. An invite code simply grants access to the service we’re running that lets you publish a post yourself. (Developers familiar with the API can view all posts regardless of whether they have an account themselves.)”

      https://web.archive.org/web20230523205354/https://blueskyweb.xyz/blog/5-19-2023-user-faq

      In conversation Tuesday, 17-Oct-2023 18:55:39 JST permalink
      Sexy Moon likes this.
    • Embed this notice
      Inventor (inventor@linuxrocks.online)'s status on Tuesday, 17-Oct-2023 18:56:39 JST Inventor Inventor
      in reply to
      • Erik Moeller

      @eloquence

      Hello?
      https://social.coop/@eloquence.rss

      In conversation Tuesday, 17-Oct-2023 18:56:39 JST permalink

      Attachments


      Sexy Moon likes this.
    • Embed this notice
      Erik Moeller (eloquence@social.coop)'s status on Tuesday, 17-Oct-2023 18:56:40 JST Erik Moeller Erik Moeller
      in reply to
      • Inventor

      @inventor

      How exactly does it fence them off though if all those posts can be freely mirrored and crawled anyway?

      In conversation Tuesday, 17-Oct-2023 18:56:40 JST permalink
    • Embed this notice
      Inventor (inventor@linuxrocks.online)'s status on Tuesday, 17-Oct-2023 18:56:42 JST Inventor Inventor
      in reply to
      • Erik Moeller

      @eloquence @badlogic

      It's not cosmetic, it's a way of fencing off bad actors.

      In conversation Tuesday, 17-Oct-2023 18:56:42 JST permalink
    • Embed this notice
      Erik Moeller (eloquence@social.coop)'s status on Tuesday, 17-Oct-2023 18:56:43 JST Erik Moeller Erik Moeller
      in reply to

      @badlogic

      https://firesky.tv/ has been running a searchable live stream for a few months. It's bizarre to me that they're not making it clearer that the login wall is purely cosmetic.

      In conversation Tuesday, 17-Oct-2023 18:56:43 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: firesky.tv
        Firesky
        Watch every Bluesky post in real-time – filter the firehose
    • Embed this notice
      eris (eris@akko.disqordia.space)'s status on Tuesday, 17-Oct-2023 18:57:29 JST eris eris
      in reply to
      • Sexy Moon
      @Moon @badlogic the struggle with a lot of it though is it's gonna be impossible to retroactively apply sensible changes that should've been there in the first place. Like how blocking didn't remove a follower because there's no authenticated following. Dumb team sometimes
      In conversation Tuesday, 17-Oct-2023 18:57:29 JST permalink
      Sexy Moon likes this.
    • Embed this notice
      Sexy Moon (moon@shitposter.club)'s status on Tuesday, 17-Oct-2023 19:02:17 JST Sexy Moon Sexy Moon
      in reply to
      • eris
      @eris @badlogic I believe that was deliberate but at least yeah that is unintuitive and should be made clear. with regard to public posts being publicly available, should be obvious especially when the major selling point is (eventually) decentralized.
      In conversation Tuesday, 17-Oct-2023 19:02:17 JST permalink
      eris likes this.
    • Embed this notice
       (mint@ryona.agency)'s status on Tuesday, 17-Oct-2023 19:30:37 JST  
      in reply to
      • Pawlicker
      @badlogic cc @PurpCat
      In conversation Tuesday, 17-Oct-2023 19:30:37 JST permalink
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      Pleroma-tan (kirby@lab.nyanide.com)'s status on Wednesday, 18-Oct-2023 03:18:14 JST Pleroma-tan Pleroma-tan
      in reply to
      @badlogic Another amazing win for bluesky!!!!!!!!! The developers are so competent
      In conversation Wednesday, 18-Oct-2023 03:18:14 JST permalink
      ✙ dcc :pedomustdie: :phear_slackware: likes this.
    • Embed this notice
      Iska (iska@catposter.club)'s status on Wednesday, 18-Oct-2023 03:28:12 JST Iska Iska
      in reply to
      • Sexy Moon
      • eris

      @eris@akko.disqordia.space @Moon@shitposter.club @badlogic@mastodon.gamedev.place
      okay but
      bluesky alt frontend when

      In conversation Wednesday, 18-Oct-2023 03:28:12 JST permalink
      eris likes this.
    • Embed this notice
      HistoPol (#HP) 🏴 🇺🇸 🏴 (histopol@mastodon.social)'s status on Wednesday, 18-Oct-2023 08:43:46 JST HistoPol (#HP) 🏴 🇺🇸  🏴 HistoPol (#HP) 🏴 🇺🇸 🏴
      in reply to

      @badlogic

      #Bluesky =User is a publicly available product:

      "But the "funniest" part is this: there's no privacy. And I don't mean missing DMs.

      All your posts are available through API endpoints. Without any authentication. By design."

      https://mastodon.gamedev.place/@badlogic/111246798083590676

      In conversation Wednesday, 18-Oct-2023 08:43:46 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.masto.host
        Mario Zechner (@badlogic@mastodon.gamedev.place)
        from Mario Zechner
        Attached: 1 image The past two nights I wrote a "thread reader app" for BlueSky. https://skyview.social Oh boy. The protocol is absolutely insane. RPC galore, responses are only partially typed. The docs are pretty much useless. But the "funniest" part is this: there's no privacy. And I don't mean missing DMs. All your posts are available through API endpoints. Without any authentication. By design. The "invite-only" thing may have you think otherwise. Here are my last 100 posts. https://bsky.social/xrpc/com.atproto.repo.listRecords?repo=badlogic.bsky.social&collection=app.bsky.feed.post
    • Embed this notice
      HistoPol (#HP) 🏴 🇺🇸 🏴 (histopol@mastodon.social)'s status on Thursday, 19-Oct-2023 16:18:42 JST HistoPol (#HP) 🏴 🇺🇸  🏴 HistoPol (#HP) 🏴 🇺🇸 🏴
      in reply to

      Nicht nur massive #Sicherheitslücke bei #Bluesky (alias #Twitter20):

      ALLE Posts sind grundsätzlich ÖFFENTLICH, wenn man über die offizielle Schnittstelle darauf zugreift!

      Via @badlogic

      https://mastodon.gamedev.place/@badlogic/111246798083590676

      In conversation Thursday, 19-Oct-2023 16:18:42 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.masto.host
        Mario Zechner (@badlogic@mastodon.gamedev.place)
        from Mario Zechner
        Attached: 1 image The past two nights I wrote a "thread reader app" for BlueSky. https://skyview.social Oh boy. The protocol is absolutely insane. RPC galore, responses are only partially typed. The docs are pretty much useless. But the "funniest" part is this: there's no privacy. And I don't mean missing DMs. All your posts are available through API endpoints. Without any authentication. By design. The "invite-only" thing may have you think otherwise. Here are my last 100 posts. https://bsky.social/xrpc/com.atproto.repo.listRecords?repo=badlogic.bsky.social&collection=app.bsky.feed.post
    • Embed this notice
      HistoPol (#HP) 🏴 🇺🇸 🏴 (histopol@mastodon.social)'s status on Thursday, 19-Oct-2023 20:20:55 JST HistoPol (#HP) 🏴 🇺🇸  🏴 HistoPol (#HP) 🏴 🇺🇸 🏴
      in reply to
      • z428

      @z428

      Das meinte ich mit "*nicht nur* eine Sicherheitslücke"
      @badlogic

      In conversation Thursday, 19-Oct-2023 20:20:55 JST permalink
    • Embed this notice
      z428 (z428@loma.ml)'s status on Thursday, 19-Oct-2023 20:20:57 JST z428 z428
      in reply to
      • HistoPol (#HP) 🏴 🇺🇸 🏴
      @HistoPol Ist das wirklich eine "Sicherheitslücke" oder by-design? Soweit ich sehe, ist in Bluesky nirgendwo darauf hingewiesen, dass dort irgendetwas "privat" ist - die Posts haben keine Möglichkeit, Reichweiten oder Zugriffe einzugrenzen, und DM gibt es explizit noch nicht... 🙂
      @badlogic
      In conversation Thursday, 19-Oct-2023 20:20:57 JST permalink
      HistoPol (#HP) 🏴 🇺🇸 🏴 repeated this.
    • Embed this notice
      Mario Zechner (badlogic@mastodon.gamedev.place)'s status on Thursday, 19-Oct-2023 20:21:08 JST Mario Zechner Mario Zechner
      in reply to
      • z428
      • HistoPol (#HP) 🏴 🇺🇸 🏴

      @z428 @HistoPol by design

      In conversation Thursday, 19-Oct-2023 20:21:08 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.