New post: Can we have a more “social” media?
https://profpatsch.de/essays/a-more-social-media
On advertising, the Fediverse, and what a more human social web could look like.
Special mentions: @smallcircles, @phnt, @happy-programming
New post: Can we have a more “social” media?
https://profpatsch.de/essays/a-more-social-media
On advertising, the Fediverse, and what a more human social web could look like.
Special mentions: @smallcircles, @phnt, @happy-programming
@evan xh, a rust rewrite of httpie, both are a nicer UX alternative to curl for http-only use-cases like querying REST APIs
Sorry, but requiring requests to public activitypub objects to be signed is completely whack, merveilles.town
@silverpill @Yonggan ah I skipped that one cause it lacked a motivation section
@silverpill So thinking about this, I think it has a fundamental flaw in the current setup:
Mastodon will never reply to the Announce object, it will always dereference to the original note and set that as inReplyTo.
So an ActivityPoll impl loses all interesting features, most notably replies/comments by default.
@silverpill The other issue is that remote instance actor statuses are *invisible to Mastodon until someone actively follows the actor*, so messages won’t ever propagate
@silverpill At least that’s what Sonnet gathered when I threw the codebase & FEP at it, and it matches my observations of Mastodon behaviour
This cafe has amazing ambience, but I can't share it because Mastodon does not accept .m4a
We need an audio sharing fedi plattform
@Yonggan no audio sharing not music, I feel like those have different UIs
@Yonggan but maybe not, thinking of how you can have a "post created on behalf of actor X" thing so you don't need a different account for each service cc @silverpill
@NeonPurpleStar bounce bounce bounce bounce
@silverpill I just had a thought: can we make Activitypub “degrade” to an RSS-like protocol to make implementations simpler, by making an instance able to say “we don’t implement server-to-server, but you can fall back to the outbox and poll instead, if you respect its caching headers”
@silverpill I mean ideally we already have a cache from the corresponding server key to its origin, so we don’t have to do a https resolution on every incoming message
Has anybody thought about modelling #activitypub with a tool like https://alloytools.org/book.html
to find potential exploits? Thinking about the spec it’s missing any algorithms for authorization, but I already found a couple of edge-cases that make a server DoSssable or give an attacker the ability to spoof messages …
@silverpill does the http signature not contain the domain of the requesting server and if yes, can't it be used to compare origins after the signature check?
@NeonPurpleStar Augsburg!
@NeonPurpleStar I don't think it's shifted, but it's been legalized to use the USD to gamble on these markets
@NeonPurpleStar does that mean it's starting to collapse?
~ Kissed by a rose on the grey ~Warrior / struggling / to remain / consequential (In my Raspberry Heaven〜)
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.