jens, to random
@jens@social.finkhaeuser.de avatar

Every argument I have seen so far for not immediately defederating from boils down to one of two points.

  1. The security of is rubbish; blocking won't help.

To which my response is: Yes, mate, I'm sure you're also handing out copies of your house key because crowbars exist.

  1. The users of don't deserve to be blocked out.

That's something I agree with, actually. But they're not my responsibility. The accounts on my instance are. Which makes this something...

baalzephon, to random
@baalzephon@mstdn.social avatar

So there's this fediverse/ app called aka. https://github.com/misskey-dev/misskey

It's similar to mastodon, and federates with most ActivityPub instances, except that it's:

a) Centralized (misskey.io is the only instance)
b) Mostly popular in Japan

So if anyone is wondering where the Japanese trends are coming from, they're from there :blobfoxcomfysmirk:

baalzephon,
@baalzephon@mstdn.social avatar

@HarkMahlberg Interesting, thanks. Most people I see are using misskey.io, but that's probably just because it's the largest one.

HarkMahlberg,
@HarkMahlberg@kbin.social avatar

By far lol. But since they closed Registrations, the next biggest is misskey.dev I believe.

thenexusofprivacy, to random
@thenexusofprivacy@infosec.exchange avatar

Threat modeling Meta, the fediverse, and privacy

https://privacy.thenexus.today/fediverse-threat-modeling-privacy-and-meta/

There's very little privacy on the fediverse today. Mastodon and other fediverse software wasn't designed and implemented with privacy in mind. Even the underlying protocol that powers the fediverse has major limitations. But it doesn't have to be that way!

Meta's new product means that it's critical for the fediverse to start focusing more on privacy. Of course, 's a threat in many other ways as well; that said, the privacy aspects are important too.

For one thing, if Meta does indeed follow through on its plans to work with instance admins and others "partners" who to monetize their users (and their data), people in the region of the fediverse that's not Meta-friendly will need stronger privacy protections to protect their data. And Meta's far from the only threat to privacy out there; changes that reduce the amount of data Meta can gather without consent will also help with other bad actors.

More positively, there's also a huge opportunity here. Privacy's even worse on Facebook and Instagram than it is in the fediverse. So If the fediverse can provide a more private alternative, that will be hugely appealing to a lot of people.

Any way you look at it, now's a good time for the fediverse to take privacy more seriously.

The bulk of the article focuses on threat modeling, a useful technique for identifying opportunities for improvement. It's a long article, though, so if you don't want to wallow in the details, feel free to skip ahead to the section at the end on the path forward and the specific recommendations.

And if you're already bought in to the idea that the
should focus more on privacy, and just want to know how you can help make it happen, it also suggests specific actions you can take -- and there's a section with some thoughts for

Here's the table of contents:

  • There's very little privacy on the fediverse today. But it doesn't have to be that way!
  • Today's fediverse is prototyping at scale
  • Threat modeling 101
  • They can't scrape it if they can't fetch it
  • Different kinds of mitigations
  • Attack surface reduction and privacy by default
  • Scraping's far from the only attack to consider
  • Win/win "monetization" partnerships, threat or menace?
  • A quick note to instance admins
  • Charting a path forward
  • Recommendations

This is still a draft, so as always feedback is welcome. And thanks to everybody for the feedback on previous drafts!

https://privacy.thenexus.today/fediverse-threat-modeling-privacy-and-meta/

TNLNYC, to random
@TNLNYC@mastodon.social avatar

Reading the tea-leaves, here's where we are in terms of US Fediverse migrations:

Chapter 1 (of X)
Chapter 3 (of X)
(Facebook and Instagram): Avoided due to launch of
Not started yet
Not started yet
Not started yet
Unlikely
Unlikely
: Avoided due to integration with

TNLNYC,
@TNLNYC@mastodon.social avatar

@sabret00the Yup. is not enough for video distribution. PeerTube is interesting indeed but the storage/bandwidth issue represents a challenge in terms of business model. You need to have a HUGE infrastructure to deal with volumes of video distribution. And that's costly. Not sure it's a business model that can work only through donation/subscription.

Ragnell,
@Ragnell@kbin.social avatar

@TNLNYC We might be at a tumblr one soon. They want to "update the core experience" to make things "easier for new users" and are talking algorithm rather than linking posts or rolling out the ActivityPub integration they've been silent on.

eray, to random
@eray@ieji.de avatar

Head of Insta about and .

bacon, to random
@bacon@cheeseburger.social avatar

Someone should start like a service or non profit or organization or you know whatever you want to call it to help public services, non profits, and emergency services start up there own instances on the fediverse to help solve the communication issue they were left with when Twitter went to shit.

Maybe an organization with chapters in different regions/states that helps set up a server or multiple servers that are dedicated to that areas emergency services and things.

Get them either set up self hosting if they have the ability or get them connected and setup with a hosting provider.

They would be verified by domain name, in person in the community, and this new organization.

This would help solve future issues from big social media breaking their communication and would get more people onto the fediverse.

ablackcatstail, to random
@ablackcatstail@goblackcat.net avatar

I guess I have a warning for would-be social media influencers checking out the . The warning is that while the fediverse may appear to be similar to , the similarities remain superficial. If you've come here in the hopes of some algorithm to assist, you will be sorely disappointed. Furthermore, most participants in the realm have chosen to be here precisely because they found attempts to be influenced or manipulated tiresome and annoying.

Social media influencers will probably find more traction at Bluesky. The fediverse world is independent-minded and less likely to be swayed by an individual opinion, even regardless of celebrity status. We are more apt to question the influencer's point of view than to take it in faith.

In short, the fediverse isn't a popularity contest. It's merely a platform for exchanging ideas and learning from other people.

dahukanna, to random
@dahukanna@mastodon.social avatar

Head twist: How do server implementations like Mastodon not understand that account transfer means the whole digital content related to an account, not just selected pieces.

Analogy: This is operating like old school bank accounts where followers are direct debits and who you follow are standing orders. Your content (transactions) don’t move to your new bank but you have statements (export of data).

It’s digital and data plus 2023. We can do so much better. Wander pondering.

laurenshof,

@dahukanna 100% agreed. Someone build an content import tool on top of Mastodon (in very early testing). But thats definitely not an excuse for it to be natively included like other servers do

https://mastodoncontentmover.github.io/

jdp23,
@jdp23@calckey.social avatar

@dahukanna 💯. The explanation though is pretty straightforward: Eugen, who makes the decisions about what funcationliaty to prioritize in mainline Mastodon, also is CEO of the non-profit that runs mastodon.social. From that perspective, not having a migration tool helps keep people there and ensure that remains the largest instance. So even though it's something people have clamored for since forever ... somehow it never really gets prioritized in mainline Mastodon. It's better than it was but still not what it should be. Meanwhile Calckey has implemented post importing, and @tokyo_0's made good project on post important with -- so it's not like it defies the laws of physics for Mastodon to get a lot better.

Interestingly last week's reporting on Meta's Project 92 says it'll the ability to import posts from Mastodon. Who knows whether it actually well but they clearly know it's a valuable feature.

@laurenshof

0x1C3B00DA, to fediverse
@0x1C3B00DA@kbin.social avatar

Can any #fediverse / #ActivityPub devs take a look at a proposal I submitted to #kbin and #lemmy?

Since the lemmy issue is getting overrun with people talking about other proposals, I'm thinking about submitting this as a #FEP. Is that still a useful process? I don't know how many projects look to FEPs for implementation guidance.

ernest,
@ernest@kbin.social avatar

@0x1C3B00DA Added to bookmarks, I will come back to it after the migration, thanks.

EnglishMobster,
@EnglishMobster@kbin.social avatar

@0x1C3B00DA My issue with this proposal as a moderator is how conflicting moderation styles will work. Moderators would either have to do double the work (if everything is sent over) or they may lose out on posts that would be fine in one community but not another (if each community moderates separately).

The only way to fix it would be to "unfollow" the communities and that in turn can cause users to get upset. I think a multireddit approach is probably better TBH.

profoundlynerdy, to random
@profoundlynerdy@bitbang.social avatar

We really should consider services that are not based but still a federated to be part of the and promote them accordingly. Self-hosting is a plus.

Email other than or , such as or self-host.

is also federated and has been since 1979! There are free providers: https://www.big-8.org/wiki/News_service_providers. If one excludes binaries groups, it's possible to peer with other providers via . Posts and groups are linkable in HTML.

Wander, to random
@Wander@packmates.org avatar

Hey ,

I have an idea for an implementation that I believe can give users much more control over their content and also more privacy.

Do you know anyone who has enough experience with AP to discuss and review whether it's viable or not? I'm pretty excited about it actually.

Thank you <3 :vlpn_happy_heart:

Ada,
@Ada@kbin.social avatar

@Wander You might be interested in this https://blahaj.zone/notes/9ev0kge0aj

festal, to random
@festal@tldr.nettime.org avatar

I still haven't made up my mind about blocking Meta's , codenamed or , supposedly supporting , should it actually launch. As far as I can see, it's basically "keeping the evil surveillance corp. out" vs "avoiding nerdy self-marginalization".

Both are fair points. I guess, it depends. But on what? For me, the key point is if Threads (or whatever its name) supports easy migration (as Mastodon does). If that's the case, I would prefer not to block it, as it could be an offramp from the walled garden. If this feature is omitted, then I would be much more open to blocking.

But in the end, this should not be a decision by the admins, but a collective one by the users of the instance.

Stardust,

@festal
The issue is more complex than just 'surveillance' (which they don't need to join the fediverse to do). The fear is that they'll do basically what google and big providers did to email, which is now much more impractical to self host, by swamping out with sheer volume everyone else and being the big voice that ends up dictating the evolution of the fediverse to its own detriment, opportunistically grabbing more users and then cutting off support for little servers. There's a rumor circulating that they want to PAY big servers to federate with them, and demand that content meet their guidelines, which could obviously fuck over people as it would create a vicious cycle of dependency as big servers would become incentivized to do whatever they want in order to keep the cash flow going - you could no longer trust them, and I guarantee you big social companies will be tempted to start using advertisement bots and artificial upvotes on influencers and toxic controversy to increase clicks and engagement.
I dunno about you, but I don't want ads or upvote-bots in my fediverse or big servers becoming beholden to a for-profit corporation for money. We've seen where that story goes - worse and worse.
If they actually do pay big servers, I am all in favor of defederating immediately as that is a huge red flag to me. But so far it is just a rumor. If they behave well (which would mean not tolerating Neo-Nazis, which, y'know, twitter does) I could be okay with them getting a probationary entry.

steve, to random
@steve@social.technoetic.com avatar

Does anybody really implement pure #ActivityPub (and ActivityStreams 2)? Looking at the actor (and/or attributedTo) fields, for example. There can be multiple of each. The JSON representing them could have a string/URI, a mapping, a Link, or a list of a combination of those types. Assuming a server handles all those variations (I doubt any server does), how does it interpret it in a context where a specific inbox/outbox POST is authenticated using HTTP signatures (single actor)?

dansup, to random
@dansup@mastodon.social avatar

Really excited for the developer tools I’ve been working on lately, there are a few different tools that will aid in debugging and development of your AP projects!

Eventually I’d like to build a test suite using a corpus of community contributed projects to test compatibility with various projects

It will be open source, and you’ll be able to download single file scripts that you can run locally to test without requiring a prod/tls stack

Look forward to shipping this 😎

dansup,
@dansup@mastodon.social avatar

I know there is a need for this, and a group that is trying to organize something like this.

Nothing against them, but I think I can built a foundation for this myself without bureaucracy or countless meetings, and then hand it off to them or a trusted fediverse entity.

I’m all for collaboration, but sometimes it’s better to go alone and then release an MVP instead of trying to organize a project with many devs who can’t decide on what lang or code style to use.

preslavrachev, to random
@preslavrachev@mastodon.social avatar

“Fediverse can only win by keeping its ground, by speaking about freedom, morals, ethics, values. By starting open, non-commercial and non-spied discussions. By acknowledging that the goal is not to win. Not to embrace. The goal is to stay a tool. A tool dedicated to offer a place of freedom for connected human beings. Something that no commercial entity will ever offer.”

https://ploum.net/2023-06-23-how-to-kill-decentralised-networks.html #fediverse #mastodon #Meta #facebook #activitypub

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Testmaggi
  • KbinCafe
  • Ask_kbincafe
  • TheResearchGuardian
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines