baalzephon, to random
@baalzephon@mstdn.social avatar

So there's this fediverse/ app called aka. https://github.com/misskey-dev/misskey

It's similar to mastodon, and federates with most ActivityPub instances, except that it's:

a) Centralized (misskey.io is the only instance)
b) Mostly popular in Japan

So if anyone is wondering where the Japanese trends are coming from, they're from there :blobfoxcomfysmirk:

thenexusofprivacy, to random
@thenexusofprivacy@infosec.exchange avatar

Threat modeling Meta, the fediverse, and privacy

https://privacy.thenexus.today/fediverse-threat-modeling-privacy-and-meta/

There's very little privacy on the fediverse today. Mastodon and other fediverse software wasn't designed and implemented with privacy in mind. Even the underlying protocol that powers the fediverse has major limitations. But it doesn't have to be that way!

Meta's new product means that it's critical for the fediverse to start focusing more on privacy. Of course, 's a threat in many other ways as well; that said, the privacy aspects are important too.

For one thing, if Meta does indeed follow through on its plans to work with instance admins and others "partners" who to monetize their users (and their data), people in the region of the fediverse that's not Meta-friendly will need stronger privacy protections to protect their data. And Meta's far from the only threat to privacy out there; changes that reduce the amount of data Meta can gather without consent will also help with other bad actors.

More positively, there's also a huge opportunity here. Privacy's even worse on Facebook and Instagram than it is in the fediverse. So If the fediverse can provide a more private alternative, that will be hugely appealing to a lot of people.

Any way you look at it, now's a good time for the fediverse to take privacy more seriously.

The bulk of the article focuses on threat modeling, a useful technique for identifying opportunities for improvement. It's a long article, though, so if you don't want to wallow in the details, feel free to skip ahead to the section at the end on the path forward and the specific recommendations.

And if you're already bought in to the idea that the
should focus more on privacy, and just want to know how you can help make it happen, it also suggests specific actions you can take -- and there's a section with some thoughts for

Here's the table of contents:

  • There's very little privacy on the fediverse today. But it doesn't have to be that way!
  • Today's fediverse is prototyping at scale
  • Threat modeling 101
  • They can't scrape it if they can't fetch it
  • Different kinds of mitigations
  • Attack surface reduction and privacy by default
  • Scraping's far from the only attack to consider
  • Win/win "monetization" partnerships, threat or menace?
  • A quick note to instance admins
  • Charting a path forward
  • Recommendations

This is still a draft, so as always feedback is welcome. And thanks to everybody for the feedback on previous drafts!

https://privacy.thenexus.today/fediverse-threat-modeling-privacy-and-meta/

eray, to random
@eray@ieji.de avatar

Head of Insta about and .

TNLNYC, to random
@TNLNYC@mastodon.social avatar

Reading the tea-leaves, here's where we are in terms of US Fediverse migrations:

Chapter 1 (of X)
Chapter 3 (of X)
(Facebook and Instagram): Avoided due to launch of
Not started yet
Not started yet
Not started yet
Unlikely
Unlikely
: Avoided due to integration with

TNLNYC,
@TNLNYC@mastodon.social avatar

@sabret00the Yup. is not enough for video distribution. PeerTube is interesting indeed but the storage/bandwidth issue represents a challenge in terms of business model. You need to have a HUGE infrastructure to deal with volumes of video distribution. And that's costly. Not sure it's a business model that can work only through donation/subscription.

bacon, to random
@bacon@cheeseburger.social avatar

Someone should start like a service or non profit or organization or you know whatever you want to call it to help public services, non profits, and emergency services start up there own instances on the fediverse to help solve the communication issue they were left with when Twitter went to shit.

Maybe an organization with chapters in different regions/states that helps set up a server or multiple servers that are dedicated to that areas emergency services and things.

Get them either set up self hosting if they have the ability or get them connected and setup with a hosting provider.

They would be verified by domain name, in person in the community, and this new organization.

This would help solve future issues from big social media breaking their communication and would get more people onto the fediverse.

ablackcatstail, to random
@ablackcatstail@goblackcat.net avatar

I guess I have a warning for would-be social media influencers checking out the . The warning is that while the fediverse may appear to be similar to , the similarities remain superficial. If you've come here in the hopes of some algorithm to assist, you will be sorely disappointed. Furthermore, most participants in the realm have chosen to be here precisely because they found attempts to be influenced or manipulated tiresome and annoying.

Social media influencers will probably find more traction at Bluesky. The fediverse world is independent-minded and less likely to be swayed by an individual opinion, even regardless of celebrity status. We are more apt to question the influencer's point of view than to take it in faith.

In short, the fediverse isn't a popularity contest. It's merely a platform for exchanging ideas and learning from other people.

dahukanna, to random
@dahukanna@mastodon.social avatar

Head twist: How do server implementations like Mastodon not understand that account transfer means the whole digital content related to an account, not just selected pieces.

Analogy: This is operating like old school bank accounts where followers are direct debits and who you follow are standing orders. Your content (transactions) don’t move to your new bank but you have statements (export of data).

It’s digital and data plus 2023. We can do so much better. Wander pondering.

0x1C3B00DA, to fediverse
@0x1C3B00DA@kbin.social avatar

Can any #fediverse / #ActivityPub devs take a look at a proposal I submitted to #kbin and #lemmy?

Since the lemmy issue is getting overrun with people talking about other proposals, I'm thinking about submitting this as a #FEP. Is that still a useful process? I don't know how many projects look to FEPs for implementation guidance.

profoundlynerdy, to random
@profoundlynerdy@bitbang.social avatar

We really should consider services that are not based but still a federated to be part of the and promote them accordingly. Self-hosting is a plus.

Email other than or , such as or self-host.

is also federated and has been since 1979! There are free providers: https://www.big-8.org/wiki/News_service_providers. If one excludes binaries groups, it's possible to peer with other providers via . Posts and groups are linkable in HTML.

Wander, to random
@Wander@packmates.org avatar

Hey ,

I have an idea for an implementation that I believe can give users much more control over their content and also more privacy.

Do you know anyone who has enough experience with AP to discuss and review whether it's viable or not? I'm pretty excited about it actually.

Thank you <3 :vlpn_happy_heart:

festal, to random
@festal@tldr.nettime.org avatar

I still haven't made up my mind about blocking Meta's , codenamed or , supposedly supporting , should it actually launch. As far as I can see, it's basically "keeping the evil surveillance corp. out" vs "avoiding nerdy self-marginalization".

Both are fair points. I guess, it depends. But on what? For me, the key point is if Threads (or whatever its name) supports easy migration (as Mastodon does). If that's the case, I would prefer not to block it, as it could be an offramp from the walled garden. If this feature is omitted, then I would be much more open to blocking.

But in the end, this should not be a decision by the admins, but a collective one by the users of the instance.

steve, to random
@steve@social.technoetic.com avatar

Does anybody really implement pure #ActivityPub (and ActivityStreams 2)? Looking at the actor (and/or attributedTo) fields, for example. There can be multiple of each. The JSON representing them could have a string/URI, a mapping, a Link, or a list of a combination of those types. Assuming a server handles all those variations (I doubt any server does), how does it interpret it in a context where a specific inbox/outbox POST is authenticated using HTTP signatures (single actor)?

static, to chat in non-stickied PSA: Beehaw has signed the Anti-Meta Fedi Pact
@static@kbin.social avatar

I'm not shure, there are a few good arguments against plain blocking of Meta.

This article is mostly against federating
https://privacy.thenexus.today/should-the-fediverse-welcome-surveillance-capitalism/

it does highlight contra's:

John Gruber describes the Anti-Meta Pact as "petty and deliberately insular" and suggests that the whole point of ActivityPub is to turn social networking into something more akin to email, which he describes as "truly open."1

Tristan Louis says "The anti-Meta #Fedipact can only achieve one thing: make sure that #ActivityPub loses to the Bluesky protocol."2

Dan Gillmor suggests that "preemptively blocking them -- and the people already using them -- from your instance guarantees less relevance for the fediverse."

dansup, to random
@dansup@mastodon.social avatar

Really excited for the developer tools I’ve been working on lately, there are a few different tools that will aid in debugging and development of your AP projects!

Eventually I’d like to build a test suite using a corpus of community contributed projects to test compatibility with various projects

It will be open source, and you’ll be able to download single file scripts that you can run locally to test without requiring a prod/tls stack

Look forward to shipping this 😎

preslavrachev, to random
@preslavrachev@mastodon.social avatar

“Fediverse can only win by keeping its ground, by speaking about freedom, morals, ethics, values. By starting open, non-commercial and non-spied discussions. By acknowledging that the goal is not to win. Not to embrace. The goal is to stay a tool. A tool dedicated to offer a place of freedom for connected human beings. Something that no commercial entity will ever offer.”

https://ploum.net/2023-06-23-how-to-kill-decentralised-networks.html #fediverse #mastodon #Meta #facebook #activitypub

tchambers, to activitypubblueskybridge
@tchambers@indieweb.social avatar

@activitypubblueskybridge - as we look to rebuild the old test suite, and the compatibility report, look at the old one cached here in the WaybackMachine: https://web.archive.org/web/20221031085815/https://test.activitypub.dev/

tchambers, to activitypubtestsuite
@tchambers@indieweb.social avatar

@activitypubtestsuite - question for the group: even if we were not to use it’s codebase, is there value in getting the old ActivityPub.rocks test suite live again? Just to see the old test in action?

tchambers,
@tchambers@indieweb.social avatar

@rmdes @activitypubtestsuite @cwebber I’ll ask some others who might be a person or two removed from those who might know.

steve,
@steve@social.technoetic.com avatar
mauve, to random
@mauve@mastodon.mauve.moe avatar

It'd be cool if had a way to log in with your accpunt on another AP server. Like, if I wanted to check out kbin it'd be nice if I could reuse my mastodon account.

wave_walnut, to fediverse
@wave_walnut@kbin.social avatar

actually has a lot of fake accounts for investment/romance scams.
Scammers take advantage of the propensity of people to blindly trust Facebook's capital power.
instances might keep distance from Facebook to avoid scamming incidents even if Facebook adopts .

loshmi, to random
@loshmi@social.coop avatar

All this conversation about #Meta on #Fedi feels like the worst parts of geek culture. So technical, without understanding context or what strikes can actually do. My thoughts:

Meta will make a great app for Fedi because it has more money to throw at the task. People will start using that because it's better. It will have QTs and an algorithm. People they want to follow will be there.

🧵1/6

loshmi,
@loshmi@social.coop avatar

A #strike / #FediPact doesn't let them do this. It prevents #Meta from entering the existing conversation with interesting content and dynamic developments. It makes it harder and more expensive for them to develop their own ActivityPub software, makes #EEE slightly more expensive.

Whoever thinks that we have somehow "won" by having them adopt #ActivityPub is deeply ignoring reality and history. We have opposing interests. They are capitalists, we are a commons. They want to eat us.

🧵 5/6

weekinfediverse, to random
@weekinfediverse@mitra.social avatar
osma, to random
@osma@mas.to avatar

A few days ago I suggested that once Meta's Threads launches, its focus probably will be in groups - either public or semi-private. The details of what that could mean are in this thread.
https://social.fishpool.org/@[email protected]/posts/193897234189601792/

Earlier, I asked why Strava hasn't integrated with .
https://mas.to/@osma/110371213306088525

Now, consider these two items in combination. A lot of athletes are sharing their training and competition diaries with fans in apps like Strava as well as Instagram. AP could link them together.

mariusor, to random
@mariusor@metalhead.club avatar

One of the small things I managed to do while sick this week was to add support for <link rel=alternate type="application/activity+json"> for all the pages where this makes sense.

So now the instance and the individual users are directly discoverable on Mastodon instances by entering the URL in the search box. (Accepting the follows is not functional at the moment... oops)

Ex instance: https://brutalinks.tech/

Ex user: https://brutalinks.tech/~marius

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines