GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by admin :heart_cyber: (admin@kolektiva.social)

  1. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Thursday, 28-Dec-2023 16:00:34 JST admin :heart_cyber: admin :heart_cyber:
    • Framasoft

    🖤 Kolektiva Loves PeerTube 🖤

    PeerTube is one of Kolektiva's core services, running at kolektiva.media. It is a free and open source alternative to YouTube, developed by the non-profit organization @Framasoft During the end of the year, Framasoft is raising money to finance the future development of Peertube. You can check out the roadmap here: https://joinpeertube.org/news/peertube-future-2024.

    PeerTube allows Kolektiva to autonomously distribute video content with the kind of smooth and accessible interface that users expect. If you have some money left this year, you should consider making a donation to fund the future of this important platform: https://framasoft.org/en/#support. If you don't have money to give, we completely understand and we ask instead that you share this post and also visit Framasoft's website (https://framasoft.org/en/) to discover all their free services. We also encourage you to talk about them with your friends and comrades, so more people use these privacy-focused alternatives to the corporate services that only want to make money out of your data.

    - Kolektiva's tech collective

    In conversation Thursday, 28-Dec-2023 16:00:34 JST from kolektiva.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: framasoft.org
      Framasoft
      from Framasoft
      Framasoft is a not-for-profit popular educational organization, a group of friends convinced that an emancipatory digital world is possible, convinced that it will arise through actual actions on real world and online with and for you!

    2. https://kolektiva.social/system/media_attachments/files/111/653/506/998/330/082/original/1ac1a9f222dd957c.png

    3. Domain not in remote thumbnail source whitelist: framasoft.org
      Framasoft
      from Framasoft
      Framasoft is a not-for-profit popular educational organization, a group of friends convinced that an emancipatory digital world is possible, convinced that it will arise through actual actions on real world and online with and for you!
  2. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Saturday, 09-Sep-2023 04:53:43 JST admin :heart_cyber: admin :heart_cyber:

    We're happy to announce that the problems with our server have been resolved. Apologies to all those who have been experiencing latency and timeouts for the past day or so.

    A big thanks to our hard-working tech team, and a big thanks to everyone who reached out to offer support or advice. This issue has underscored our need to further strengthen our server and admin capacities... so if there are any anarchist sysadmins out there who would like to help out this project on a more sustained basis, please get in touch.

    In conversation Saturday, 09-Sep-2023 04:53:43 JST from kolektiva.social permalink
  3. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Monday, 03-Jul-2023 06:25:13 JST admin :heart_cyber: admin :heart_cyber:
    in reply to

    Some users have asked or pointed out, and yes it is the case that the database copy would also include cached copies of posts from users on other instances in the Fediverse, and this includes direct posts or "DMs" which were sent to or included a Kolektiva.social user.

    We welcome suggestions on how to most effectively notify (a lot) of Fediverse users in general of this, but we also ask for other instance admins to help by communicating this to their own users if it seems appropriate 🙏

    In conversation Monday, 03-Jul-2023 06:25:13 JST from kolektiva.social permalink
  4. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Monday, 03-Jul-2023 06:25:11 JST admin :heart_cyber: admin :heart_cyber:
    in reply to

    Two additional points:

    If you are a kolektiva.social user and have already enabled Two-factor Authentication on your account you should also reset that, just like your password. (Also consider that it's a good idea in general to set up Two-factor authentication, if you are able, to secure access to your account!)

    In conversation Monday, 03-Jul-2023 06:25:11 JST from kolektiva.social permalink
  5. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Sunday, 02-Jul-2023 02:12:35 JST admin :heart_cyber: admin :heart_cyber:
    in reply to

    Please see our previous post for full context 👆

    Why did we delay in notifying our users? After extensive internal discussions and advice from multiple movement lawyers, we made the difficult decision to delay informing our users, since an earlier public statement could have made the situation worse in a number of ways.

    To be clear, the physical Kolektiva servers were not targeted or affected by the FBI raid. Our actual, live servers are encrypted, in that the hard drives are encrypted at rest. We have no reason to believe that any Kolektiva.social data has been compromised, outside of the database back-up that was seized. Our admin's various electronic devices and other drives were encrypted, and we swiftly rotated all passwords and keys as appropriate for any potential breach like this. In other words, we have no reason to believe this is an evolving threat to our server integrity, or our users' data security.

    So then, why are we asking users to reset their passwords? The seized database did not contain user passwords, it contained hashed user passwords. To better understand why we recommend users change their password, here is a good explainer: https://www.troyhunt.com/we-didnt-encrypt-your-password-we-hashed-it-heres-what-that-means/

    Without offering any excuses, we also think it warrants mentioning that the seized data would be similar to data obtained in any raid or other unauthorized access of any typical Mastodon server. It is the same data any cooperating instance admin can hand over willingly when requested. Unfortunately, there are serious limits to what admins of Mastodon instances can do to protect the data of their users. Users should always take precautions to protect the privacy of information, especially any sensitive information, they share on the Fediverse or anywhere else on the Internet. We hope that if nothing else, this situation serves as a learning experience for our users, and others on the Fediverse. It certainly has for us. For an intro to operational security on Mastodon, we strongly recommend checking out this guide: https://distro.f-91w.club/masto-opsec/

    Going forward, we will continue to explore our legal options. Ideally, we would be presenting a comprehensive list of internal changes, policies and best practices that we plan to implement to avoid outcomes like this in the future. These are definitely conversations we have started having, and intend to continue, but we also want people to be aware that we're a small volunteer collective, and we are dramatically affected by these events. Things may be slow to develop. We also have to keep Kolektiva.social running and pick up the slack now that we are missing a crucial team member 💔 .

    Our admin's legal situation is shitty, but they currently have the support and legal representation they need. We will post any information or calls for support if that becomes appropriate or needed.

    As many understand, our political movements are currently facing high levels of state repression, which has resulted in an increase in digital and other forms of surveillance, raids and arrests, false and overblown criminal charges, increased use of pre-trial detention and lengthy prison sentences. At times like these, political movements are tested and solidarity and security culture become important touchstones for our work to make the world a better place for all.

    Thank you again for your understanding, solidarity, and time taken to read all this.

    In conversation Sunday, 02-Jul-2023 02:12:35 JST from kolektiva.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn-p.ways.to
      Best Ways
      Best Ways to do all sorts of things. The number one stop for best practises. See and learn from others. Share your own tricks.
    2. No result found on File_thumbnail lookup.
      http://security.So/


  6. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Saturday, 01-Jul-2023 21:50:39 JST admin :heart_cyber: admin :heart_cyber:
    • Håkan Geijer

    @hakan_geijer

    thank you! added this in a reply.

    In conversation Saturday, 01-Jul-2023 21:50:39 JST from kolektiva.social permalink
  7. Embed this notice
    admin :heart_cyber: (admin@kolektiva.social)'s status on Saturday, 01-Jul-2023 15:18:01 JST admin :heart_cyber: admin :heart_cyber:

    🚨 Kolektiva.social SECURITY ALERT 🚨

    This is an alert for Kolektiva.social users. Please read this post in its entirety!

    In mid-May 2023, the home of one of Kolektiva.social's admins was raided, and all their electronics were seized by the FBI. The raid was part of an investigation into a local protest. Kolektiva was neither a subject nor target of this investigation. Today, that admin was charged in relation to their alleged participation in this protest.

    Unfortunately, at the time of the raid, our admin was troubleshooting an issue and working with a backup copy of the Kolektiva.social database. This backup, dated from the first week of May 2023, was in an *unencrypted* state when the raid occurred and it was seized, along with everything else.

    The database is the heart of a Mastodon server. A database copy such as the one seized may include any of the following user data, in this case up to date as of early May 2023:

    - User account information like the e-mail address associated with your account, your followers and follows, etc.
    - All your posts: public, unlisted, followers-only, *and direct ("DMs")*.
    - Possibly IP addresses associated with your account - IP addresses on Kolektiva.social are logged for 3 days and then deleted, so IP addresses from any logins in the 3 days prior to the database backup date would be included.
    - A hashed ("encrypted") version of your password.

    🚨 👉 As a precaution we highly recommend that all users on Kolektiva.social *change their password immediately* to a new, unique, and strong password.

    We sincerely apologize to all our users and regret this breach. In hindsight, it was obviously a mistake to leave a copy of the database in an unencrypted state. Unfortunately, what would otherwise have been a small mistake happened to coincide with a raid, due to bad luck and spectacularly bad timing.

    We understand that our users and other people on the Fediverse will have a lot of questions. We will try to answer them as best we can, but please be patient and bear in mind that we may be overwhelmed with messages, and may be delayed in responding or unable to provide answers to certain questions for legal or technical reasons. As a security culture reminder, it can be extremely harmful to the individuals charged and to our community to openly speculate on the Internet about alleged criminal activity or about what law enforcement may be able to do with seized data. Our present awareness is that the seized Kolektiva data is unrelated to the federal investigation and prosecution and we are exploring legal avenues to have the seized data returned and copies destroyed.

    Thank you for your understanding and solidarity :black_sparkling_heart:

    👇 Please see our replies to this post for additional information (1/?) 👇

    In conversation Saturday, 01-Jul-2023 15:18:01 JST from kolektiva.social permalink

User actions

    admin :heart_cyber:

    admin :heart_cyber:

    lowly sysadmin ...loading the floppies ? to make this and ? kolektiva.media run on the information super highway :win3_terminal:personal account: @skreetsPlease use #kolektivamod for moderation requests.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          76929
          Member since
          19 Dec 2022
          Notices
          7
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.