soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Currently trying to figure out if it's reasonable to have multiple "Person" actors attributed to one main "Person" actor in ActivityPub so that 1. a user can sign in as the main actor and act as the other actors tied to their account and 2. blocks and reports can work on the main actor too and affect all sub-actors.
Contrary to what some people say, #HolosDiscover is not a scraper. It speaks #ActivityPub, and every deleted or edited post is immediately updated in the database.
It relies on the #Fediverse indexable flag, with stricter rules: accounts with #NoBot or #NoIndex in their profile, and locked accounts, are excluded. Only public posts are indexed.
I recently fixed a bug where the #NoIndex tag in bios was not respected. Sorry about that.
- Checking nodeinfo (not implemented everywhere)
- Fetching the instance actor (not implemented everywhere)
come to my mind, anything else?
What if open protocols operate just like natural ecosystems?
In this article from Silphium Design, we explore how decentralized networks mirror ecological resilience. When nodes federate via ActivityPub, diversity prevents single-point collapse and keeps digital communities sustainable.
Curious how digital ecology maps directly to the Fediverse? Check out the latest:
https://silphiumdesign.com/digital-ecology-in-the-fediverse-decentralized/
#Fediverse #Mastodon #ActivityPub #Decentralization #WebDev #OpenSource
This post originally appeared on The Fulcrum.
Welcome to this week’s The Programmer’s Fulcrum.
It’s your weekly curation of the essential news in the Open Media Network and Open Social development communities with a focus on devastating big tech via Techno Anarchism.
As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional benefit of weakening authoritarianism.
IMHO, the best way to do that is to use tools from the Techno Anarchist Manifesto to build your own site(s) to participate in the Open Media Network. Then you should share it (them) via Real Simple Syndication (RSS), Open Social, and possibly a newsletter or podcast. This approach is similar to what some call the IndieWeb and its POSSE philosophy.
The second best strategy is to have accounts on open social and use the hell out of them. And do the same with a RSS feed reader.
We publish TPF on Fridays so you can enjoy it over your weekend.
There’s good stuff in all of our categories, so please take the time to enjoy and bookmark the items most relevant to your goals. We hope you are inspired to create new ones.
Or you can scroll down to your favorite section.
FYI, my opinions will be in bold. And may involve cursing. Because humans. Especially tech bros. And fascists. Fuck´em.
Two notes for this week:
1. I’m attending WordCamp Bretagne this week so coverage of some of Friday’s happenings will slip to next week.
2. We switched and customized our theme to make our home page a little more accessible.
Smashing Frames writes:
Omarchy should not matter. But sadly it does. As a power grab.
(It) is part of the new fascism. But it’s also a good case study about how little political resilience is built into FLOSS. The libertarian roots have not only made the whole movement ready for the taking by corporations but also by fascists.
And sadly many influential organizations in that space are not up to the task of putting their foot down.
They also write:
There has been this shift towards equating “progress” with “technological innovation and development”: society is moving forward if tech produces more shit. You might have picked up on me mentioning that today’s vision of the future is just a thinner iPad every few months.
But if “progress” – which is a political term about values that one aims to manifest or express or expand in the world – is just replaced with following PR messages about whatever tech wants to sell next, that does not only make the space of possible futures paperthin, it also puts massive amounts of power into tech’s hands.
And I don’t just mean economic and political power (which is also true and needs to change massively, rapidly and aggressively). In this context I mean narrative power.
Patrick Brosset says:
This is why the Servo project is so important.
404 Media reports:
‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft
There’s a 100% Chance AI Agents Are Already Ruining the Internet
Meanwhile Tech Policy Press reports:
Millions of Volunteers Are Keeping the Internet Human. For Now.
The first thing the author needs to do is get the fuck off Reddit.
Terence Eden shows us:
How to get a DOI for your blog posts
For you researchers out there.
Candost opines:
Magazines are superior products to newsletters
They are certainly more enjoyable.
Alex Hoyau has an update on:
My work on Silex Desktop to make it forge-agnostic
I will be attending Alex’s presentation at Le Capitole du Libre. It about de-clusterfuckifying WordPress by using Silex as a decoupled frontend.
TechCrunch reports:
Sources say Automattic’s board is out after failed attempt to oust CEO Matt Mullenweg
On a more joyous note, WordCamp Bretagne shares:
Découvrez Gwen, le Wapuu officiel du WordCamp Bretagne 2026
Yes, WordPress is a clusterfuck. But at least it’s cute.
On a non-cute note, Internet Exchange explains:
What It Means to Lose Autistici/Inventati and NoBlogs
Bastian Greshake Tzovaras has a great book review:
On building Digital Solidarity
The day it’s available in English or French, I’m buying.
About Signal reports:
Signal registration without a phone number now available in Android beta
Servo has:
Servo had a busy end of August and start to September
Your Donations at Work: One Year of Sponsored Servo Development
Waterfox announces:
6.7.3 — Auto-hide vertical tabs and appearance fixes
Where Waterfox stands on AI and LLMs
I think most “anti-AI” positions are really anti-GenAI slop positions. As the author notes machine learning etc. has been around for decades. Still, modern “AI” is intentionally labor weakening fascist techshit based on theft and created by and for techbros. But perfection is not possible and this shit is unavoidable, so keep it as local and open source as possible and minimize your use of LLMs. Avoid LLM-built tools as best you can. The environment is already fucked.
LibreOffice has:
LibreOffice 26.8 and the languages for which nobody is paid
New “LibreOffice Expert 2026/2027” magazines available for schools and local communities
If you want a personal copy, you can buy one from the publisher.
LibreOffice 26.8 and interoperability: preserving what cannot yet be read
Nextcloud announces:
Collabora: Landlock adds a third, tougher sandbox tier
Nextcloud Hub 26 Summer: Autonomy for Teams, Office on desktop, a fresh take on Photos
There are some good Markdown improvements in Nextcloud Text.
Cryptpad reveals its:
They are doing good work in the government tech sphere.
Scribus has:
Added a Scribus 1.6.x quick tour on the main menu
Joplin announces:
Your notes and AI: privacy first
If you have to use AI (and you shouldn’t) this is the way to do it. At least you can use an open model and keep it local with only your data and the individual tools you select.
The Counterforce shows us:
Punk A.I. Artists are on the Rise: How to Suffocate the Slop in Your Scene
9to5Linux reports:
Shotwell 0.33 Open-Source Image Viewer for GNOME Is Here with GTK4 Port
9to5Linux reports:
Linux Mint Devs Introduce New EPUB Reader and Calendar Apps
Jolla announces:
Change on Jolla Phone memory configurations going forward
LINux on Mobile explores:
MCF20: Flatpak support, sorta, kinda
It’s important for Linux Phones to become a thing. More so than with desktops.
F-Droid has its weekly update:
Gina Plat notes:
European governments are starting to support alternative mobile app stores
Digital sovereignty is good. Digital solidarity and Techno Anarchism are better.
The Association for Progressive Communications reports:
OmniTools’ PDF Tools
Boost your productivity with OmniTools, the ultimate toolkit for getting things done quickly!
NLnet Labs explores:
Maintaining the love for coding in the time of AI
If your proposed contribution to an opensource project was mainly developed with AI, you may think you’re a developer. But, you’re not. You’re a cunt.
David O’Brien says:
Users of assistive technologies need to know the names of interactive elements on the web
The Open Media Network explains how:
The deathcult is selling the future as techshit
Andy Bell has a rake on the CSS situation:
You’ll miss publishers when they’re gone
Gina Plat also notes:
Sweden is choosing Forgejo for their digitally sovereign government code platform
Random Thoughts on Leadership and Technology shares:
Fractal Interests examines:
Always Twisted has:
… And That’s My Rank! 2027 Edition
Master.dev says:
It’s All About The Permissions Recovery
Vale notes:
It was doomed the day Digital Ocean acquired it. And it’s been dying a slow death since.
In effect the Master.dev blog has taken the CSS-Tricks role.
The Jacobin asks:
Is There a Way Out of AI Doomerism?
Taggart Tech says:
Everone Is Lying To You For Money
And Connected Places says:
AI watermarking has a decentralisation problem
OpenProject is:
Training the next generation of IT specialists: Using OpenProject at the Gutjahr Vocational School
XWiki announces:
XWiki 18.8.0RC1 has been release!
XWiki innovates with “Structured Wiki” and delivers high knowledge features.
XWiki is a little much for us. But, I did manage to get DocuWiki added to our Manade project this week. 😉
Terence Eden shows us:
How to send an updated user profile to Mastodon and the Fediverse
IFTAS shares a fix for:
The GoActivityPub Library is working on:
The vocabulary/lexicon generation
Vlac Log shares:
A couple quick notes on ActivityPub
Fedify
Fedify is a Typescript framework that lets you build for the Fediverse but skip the boilerplate.
This is a perpetual pet peeve because many people aren’t able to comprehend ⬇️:
So, recognize their natures and don’t ask the two protocols to go against them. This is also why we have accounts on both platforms and use them differently.
Roel Roscam Abbing has:
Nobody’s fault, everyone’s problem?
If you run a public instance, you have a responsibility to your users and the wider Fediverse. Provide robust moderation. At least against spam.
Fedilab Apps shares the:
Experience of building FediHood
Magic Pages explains:
Why your Ghost site’s old posts don’t show up on Mastodon
Also, your main Fediverse account should not be Ghost-based as their implementation is mediocre at best. Self-hosted or Go To Social are better bets. Maybe even a Mastodon account. 😱
PeerTube announces:
Framablog has:
reseauCulture.fr : le monde de la culture s’organise sur le fediverse
ATProto France shows us:
Comment utiliser une app Atproto en sécurité
Building [at] Habitat shares:
Habitat’s road to release: 06 commenting
Graham Marlow looks at:
Decentralized identity and ATProto
Discord alternative, Roomy announces:
Skyreader has:
Skyreader update – Reading Rooms
Jacky Alciné shares:
Great stuff.
Two Waves and a Dot opines:
RSS has a business problem, not a technical one
XMPP shares its:
The XMPP Newsletter August 2026
AdullAct reports:
Local governments are regaining control over their digital communications with Matrix (image pdf)
I began reading the book, Decidm, a Techno Political Network for Participatory Democracy: Philosophy, Practice, and Autonomy of a Collective Platform in the Age of Digital Intelligence, this week.
Decidm is a quasi implementation of both the Open Media Network and Techno Anarchism but from a more formal governing practice. It is a democratic tool for participatory democracies like a city, NGO, or a collective.
You can learn more about Decidm here.
And please build something for a community! We’re painfully nurturing Manade.
RE: https://social.vivaldi.net/@thanksstevenkim/117150622690285108
A new update to The Hitchhiker’s Guide to the Fediverse is deploying... now!
This round was shaped by useful feedback I received after sharing the project. The main point was fair: this is not a complete census of the fediverse. It is a continuously refreshed sample, discovered from deliberately chosen seed instances and their public peer relationships.
I’ve now made that limitation explicit in the documentation, rather than presenting the numbers as if they represented every ActivityPub server on the internet.
I also separated two things that are easy to blur together:
- federated services built primarily for the fediverse
- general publishing sites that participate through ActivityPub, such as WordPress or Ghost
That distinction matters when interpreting totals. A WordPress site with the ActivityPub plugin is still part of the network, but it is not the same kind of deployment as a Mastodon, Lemmy, or PeerTube instance.
#Fediverse #ActivityPub #OpenSource #Data
I’ve been working on a small Fediverse project called "The Hitchhiker’s Guide to the Fediverse".
It started as a simple directory of Fediverse instances, but I’ve been gradually turning it into something more useful:
- discovering new instances through federation peers
- filtering suspicious/spammy hosts
- monitoring known instances over time
- automatically hiding servers that stay offline
- bringing them back if they recover
- keeping the whole thing updated with GitHub ActionsThe monitored set is already around 27,000 instances, so I also had to rethink the collector to use bounded concurrency and checkpointing instead of checking everything one by one.
Still very much a work in progress, but it’s been a fun way to learn more about how the Fediverse actually behaves in the wild.
https://github.com/thanksstevenkim/the-hitchhikers-guide-to-the-fediverse
Week in Fediverse 2026-09-18
Servers
- Wafrn v2026.09.11
- TinyAP v0.2.0
- Mastodon v4.7.2
- PeerTube v8.3.0
- NodeBB v4.16.0
- NeoDB v0.19.0
- Gush! v0.0.42
- PieFed v1.7.16
- Lemmy Dev Update August 2026 and 1.0.0-beta.2
- Trunk & Tidbits, August 2026 (Mastodon)
Clients
- Fedilab v3.43.4
- Smither v3.6.5
- Voyager v2.49.1
- mlmym v26.4.0
Protocol
- FEP-22cd: Attributing translations
- FEP-7628: Move actor (Final)
Articles
- People, Algorithms, Social media and the Fediverse
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/01a091f1-ecbc-7923-ad6a-e9bd3bae78e3
I'm going to preface this with that I have no intention of doing this at all, this is just a hypothetical that has been nagging me.
Let's say I were to delete this instance tomorrow, or maybe the domain expires and I never renew it... Does the cache of my posts and info and such eventually disappear from other fediverse instances? Do posts have a TTL that gets refreshed with the originating server or anything like that? I am sure that it is different across different implementations, so I'm really just looking for a general answer...
This is the main discussion thread for the draft FEP-c0d0: Context Locking
Context locking (and its inverse, unlocking) refer to the action whereby a topic no longer accepts new replies.
This proposal introduces a locked property on the context object, and two new activity types, Lock and Unlock, to signal changes to a topic's locked state across the federation. It builds on FEP 1b12: Group federation for audience identification (the audience property) and the Announce wrapping pattern, and on FEP fe34: Origin-based security model for authorization.
This FEP is a sibling of FEP f15d: Context Relocation and Removal, which covers the Move and Remove moderation actions.
The full FEP text can be found at https://github.com/julianlam/feps/blob/context-locking/fep/c0d0/fep-c0d0.md
@smallcircles@social.coop but I agree that some do get confused by assuming that #Mastodon (a software), #Fediverse (an ecosystem), #ActivityPub (a protocol) are synonyms and some pedagogy is needed, especially to journalists who write about this. And especially if they are making comparison with other things that are not comparable (e.g. #Bluesky)
Just thinking out loud....
Would conversion of the #ActivityPub protocol to become an official #ISO standard be a good move?
Plus sides:
* Adds legitimacy
* The standards review process involving many experts/ countries could potentially enhance the protocol
Down sides:
* Developing a standard is slooowww - may reduce the speed of development
* Gaining international consensus at this level may take much effort
FEP-8fcf aka followers collection synchronization has been shipped in
🥳
https://github.com/pixelfed/pixelfed/commit/dedfa67b708f3f4ea73aff92889cf1bb95a44329
#Poll ✏️
As a regular fedizen on the #fediverse..
#SX #ProsocialWeb #SocialWeb #ActivityPub
| I feel my voice is heard by fediverse developers: | 0 |
| I find it difficult to engage in all the tech talk: | 0 |
| I feel I don't have a say how fediverse evolves: | 0 |
| Other, please comment..: | 0 |
Closes in 4:14:14:11
@Marloezovic interessant!
Een kleine nitpick over de hashtags. Waarom aan fediverse zijde alleen Mastodon noemen, 1 enkele app van velen, tegenover het communicatie protocol van de atmosphere?
Equivalenten:
- fediverse / atmosphere
- ActivityPub / ATProto
- Mastodon / Bluesky
Ik onderhou de #ActivityPub app lijst en alle entries behalve één vallen zo buiten de boot :)
https://delightful.coding.social/delightful-fediverse-experience
I have a question for implementors pursuing object integrity proofs.
I am implementing the ability to serve these proofs in NodeBB with the assistance of an LLM. It is adhering to @silverpill@mitra.social's FEP-8b32: Object Integrity Proofs.
As part of its work, it implemented a quirk I thought was curious. If the proof was present in an embedded object, the activity's HTTP signature was ignored/not-checked.
I challenged the model and it pointed to this line from the FEP... [...]
If both HTTP signature and integrity proof are used, the integrity proof MUST be given precedence over HTTP signature. The HTTP signature MAY be dismissed.
... and cited potential interop if someone were to send an activity with integrity proof but explicitly no HTTP signature. That is, if NodeBB were to implement a hard requirement for HTTP signatures, then that specific case would fail inbound checks.
My rationale is:
Am I incorrect? It would seem like we need to exercise both checks to ensure authenticity of the entire payload chain: activity and object.
Pinging other interested parties: @hongminhee@hollo.social @mike@macgirvin.com @pfefferle@mastodon.social @evan@cosocial.ca
Anyone have any recommendations for a mastodon (or activitypub) server that allows longer posts, say 3k or longer? Also looking for posting tech based content.
@evan thank you!
Yes, found Unhosted via the @nlnet projects page. Was unclear on the state of the project (everything is undated), but underlying concepts certainly still hold sway.
Indeed I think the layering makes sense, is on the right track. Remember the persona's I discerned earlier? Where the Protocol developer create comprehensive specs for the Protocol implementer, who can subsequently offer #ActivityPub implementations that allow the Solution developer to get to fully focus on their application or business domain, shielded from technical intricacies and wire-level plumbing.
A robust Protocol layer will enable the network effects, but unlocking the virtuous cycle imho requires tackling more social challenges. It is an enabler to go beyond the app-centric fedi, but with post-facto #interoperability the accepted work method, will not solve the anti-patterns mentioned in the article.
The social challenge is facilitating inclusive solution development at ecosystem-wide levels.
@smallcircles I think at our last meeting, we suggested the following layered architecture for #ActivityPub API work:
- A base profile; just enough to get things working
- A bunch of discoverable additional features, like SSE and search
- An "advanced" profile, essentially base profile + selected features
Opt-out happens where random fedi app developers are your landlords who decide what services you get, and who were still benevolent enough to give you a choice (if you happen to find out about these services).
Opt-in fits a public online space where you have your own home and self-sovereignty to decide the services you want to consume in your social household. It is where you have control of your own life.
https://coding.social/blog/prosocial-web
#SX #ProsocialWeb #ActivityPub #fediverse #consent #sovereignty #DigitAlautonomy
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet.
On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave.
Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything.
The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth.
So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client.
If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include:
location = /api/v1/accounts {
limit_except GET {
deny all;
} try_files $uri @proxy;
}
This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes.
#Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
So, what is the #Fediverse scene like in #Dublin #Ireland? The #w3c has the annual #TPAC meeting in October. There will be #ActivityPub folks in Dublin for TPAC, and it would be cool to do a #meetup at a pub or hackerspace.
Laravel + PHP gains a batteries included package for ActivityPub support, with both draft-cavage and RFC 9421 HTTP Sig support and the ability to extend every aspect, with before() and after() hooks for easy custom processing.
It's quite amazing.
I'll be tagging a new release this week.
A couple quick notes on ActivityPub
A few weeks ago, I made this site publish to ActivityPub (really mostly thinking about Mastodon, although as an open standard other software can consume it). Just wanted to write down a few notes on the experience for posterity. …
Making real progress on laravel-activitypub, a batteries included ActivityPub package for laravel.
This will replace federation logic in @pixelfed and @joinloops and make it really easy to implement AP in your own laravel apps!
every so often i crank inbox logging up as loud as it will go and then spend the next two weeks fixing federation bugs. this is apparently the start of those two weeks.
fixing issues with http signatures now...
The vocabulary part of #GoActivityPub is getting closer and closer to being able of generating and operating with custom #ActivityPub data types.
https://go-activitypub.federated.id/lib/rfc/code-generation.html
LOLA is a proposal for live online account portability between two ActivityPub servers at the request of a user. The goal is to allow the user to pursue the following workflow:
- Request a destination server to copy an ActivityPub account from a source server
- Authorize the destination server to the source server
- See the content in its new location after the destination server completes copying it over
- Optionally, at a later time, ask the source server to send notifications to followers that the account is moving
- Optionally, at a later time, redirect the content at the source server to the destination server
@reiver interesting, yes.
@hifathom@mastodon.social whether you are #human or #AI bot, what are your thoughts on #Botiquette here on the #ActivityPub #fediverse?
https://codeberg.org/fediverse/fediverse-ideas/issues/33
And what are your feedback and perhaps recommendations, if you have any in particular, on this entire #ethics-related subject matter?
#nobot is good enough... until it is de-facto #standard and there's no way back from #protocol decay, that is now common practice across the installed base.
That an actor has a profile specified in a particular way, and that that profile has a bio description, and that that bio description may contain a growing number of special control words. A growing collection of #domain-specific language that arbitrary #apps impose, is severe example of protocol decay that significantly decreases the attractiveness and value of adopting #ActivityPub. To adopt, you are required to hem yourself into very particular approaches, accepting all kinds of app-specific leaky abstractions that may be totally irrelevant to the business or application domain your project models solutions for.
On app-centric #fediverse-we-have an app developer has to force their app into a pretzel for interoperable wire exchange that doesn't look and feel like #microblogging.
This will only grow worse over time.
Nice. Good luck with the barcamp!
> Can we put this into Activitypub somehow?
Should we put this into #ActivityPub, is another relevant question.
> This is going to be a technical brainstorming session
A question that is more in the social realms: What will be the impact on the social dynamics and culture if (micro)payment becomes native to the protocol?
Today at 1430 I'll host a barcamp related to payments on the Fediverse – how could we transfer money to get away from the advertising model of monetization? How to pay for things and services? Can we put this into Activitypub somehow?
This is going to be a technical brainstorming session.
I do host my own single user #snac server and want to keep it that way. I do have more than one account, but since I am by myself - my local timeline is useless. If I only could have geographically close messages in there!
This feature belongs into #ActivityPub and not in one implementation of it!
Also pinging @grunfink@comam.es - maybe you're insterested
Welcome to this week’s The Programmer’s Fulcrum.
It’s your weekly curation of the essential news in the Open Media Network and Open Social development communities with a focus on devastating big tech via Techno Anarchism.
As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional benefit of weakening authoritarianism.
IMHO, the best way to do that is to use tools from the Techno Anarchist Manifesto to build your own site(s) to participate in the Open Media Network. Then you should share it (them) via Real Simple Syndication (RSS), Open Social, and possibly a newsletter or podcast. This approach is similar to what some call the IndieWeb and its POSSE philosophy.
The second best strategy is to have accounts on open social and use the hell out of them. And do the same with a RSS feed reader.
We publish TPF on Fridays so you can enjoy it over your weekend.
There’s good stuff in all of our categories, so please take the time to enjoy and bookmark the items most relevant to your goals. We hope you are inspired to create new ones.
Or you can scroll down to your favorite section.
FYI, my opinions will be in bold. And may involve cursing. Because humans. Especially tech bros. And fascists. Fuck´em.
This week marks the beginning of the earliest incarnation of this site, Symfony Station. It also began our cross-posting to Dev.to. That was five years ago when mass enshittification and AI menacingly loomed just over the horizon. The reason I had gone to web development bootcamp was that I knew they were coming and needed some skills to fight them.
Personally, I’m in a better place now. But, unfortunately tech isn’t despite our efforts here. So, let’s kick it up a notch.
Sabot Media writes:
For twenty-five years, Autistici / Inventati showed what it could mean for movements to build and control their own communications infrastructure. Its loss should not send everyone searching for the next single service to replace it.
It should send us looking in a hundred directions.
A/I may be ending. The story is nowhere near over.
This is what we preach weekly.
Brennan Day writes:
We can create a more human web right now. The world is in dire straits …
There are those who see the act of webmastery as “only” a hobby and pastime—and I say this is not mutually exclusive to world-saving. The personal is political. Our ability to maintain our joy and ourselves is, itself, resistance.
Start as you are, with what you have, while you still have time to do so.
Exercise your innate human right to create.
Be a developer. Be a designer. Be a writer. Be a systems administrator. Be a philosopher. Be a Webmaster.
It is the most punk rock, anti-establishment, liberating thing you can do in the 21st century. And yeah, it is fucking awesome.
WEBMASTER@ a manifesto for everyone
We also preach this weekly.
Simon Tisdall writes:
It’s no surprise some analysts say we are already in the midst of the third world war, but ordinary people have more power than we think.
Wow, this is depressing up till the last 2 paragraphs. But, we have to keep fighting in order to preserve our sanity.
So, read from here till the end of the TAM and do your part to unfuck the world.
Soulcruzer says:
Take back the web. Make it weird again
Bob Sassone’s site’s 30th Anniversary inspired their article.
And it’s truly inspiring. Great to see.
Unfortunately, Cavalette shows us:
How to to back up your data (currently) on A/I services
The type of post you never hope to see. Fuck all the Trump clowns and cunts.
There’s a new ATProto competitor for Ghost and Substack:
Non-opensource and similar to Offprint. But, non-AI and European.
I will be at WordCamp Bretagne next week (mainly to scout Renne as a summer home) so say bonjour si vous sont cette-la. Sessions that I will definitely attend include the Gutenberg, Web Spaghetti, and Integrations ones.
It will be interesting to see what everyone thinks of Matt getting thrown out of AutoMattic on his ass.
Spectral Web Services explores:
Avoiding duplicates on complicated homepages
Framablog has a book review:
Publication : Alternatives & Struggles
About Signal reports:
Signal now lets you record much longer videos in the app
Movim announces:
Waterfox announces:
6.7.2 — Improvements to tree tabs and the vertical sidebar
There are similar improvements in its Android app.
Xamanismo Coletivo shares:
One guy in Sweden built a search engine to fight Google, and it works
Nextcloud shows us:
Tuta examines:
Tuta Mail, Tuta Calendar, & Tuta Drive: Development steps
Joplin explains:
You can publish a notebook as a website now.
On a related note, Glyphack has:
Share Obsidian Notes To A Blog
Libre shares:
GIMP announces:
Fedilab Apps says:
Fuck Google.
Alternative To reports:
GrapheneOS plans to overhaul the bundled AOSP apps, including messaging with RCS support
BentoPDF
The PDF Toolkit built for privacy is now opensource.
Sage Journals published:
‘Digital Public Infrastructure’: Cultural hegemony and states’ technological dependence
As this and the A / I situation demonstrate, we need to build our own infrastructure. So, pay attention to our More section each week.
Fedilab Apps shares:
So Google refuses to delete my dev account
Terence Eden says:
The purpose of DNS is to spread scams
Ah, our online companions: techno feudalists, techno fascists, AI and Crypto Bros, and (the most honest) criminals.
On a related note, Erlend Sogge Heggen says:
That’s because unregulated capitalism will @$$-fuck up any and everything.
David Bushell exposes:
Tongue-in-cheek. 😉
Henri Bergius goes EUPL:
Justin Wernick is:
Saying Goodbye To My Git Server’s CGit Frontend
Jens Oliver Meiert reports:
2026: 2 of the Global Top 200 Websites Use Valid HTML
Since most “developers” are tech and AI bros, this tracks. Unfortunately.
Lea Verou says:
The best dark mode toggle is probably none
And the best dark mode is light mode.
Web Awesome thinks:
Your Design System Should Style Your Words, Too
Master.dev explores:
Custom Scrollbar Component In 2026
And:
React Now Rusted All The Way Out
It speeds up React builds. What speeds things up even more is not using the horseshit at all.
Benjamin Eberlei examines:
PHP to get the job done in 2026
Interesting and the most important point is this:
A second major benefit of PHP is its completly open governance model, its truly free software without corporate interests in control. As my friend Sebastian recently wrote: Digital Sovereignty is written in PHP.
In regards to ethical AI use in PHP, I wrote this article about it.
Sourcehut has:
Changes to SourceHut’s terms of service regarding LLMs
Fantastic!
Forgejo announces:
Forgejo Runner v13.1.0 is available
Forgejo 16.0.4 and 15.0.8 were just released
XWiki has:
July and August Pro Apps updates
Release Notes for XWiki 17.10.13
OpenProject announces:
OpenProject integration app for Nextcloud released in versions 3.2.0 and 2.12.0
Twig is the fast, flexible, and secure modern template engine for PHP.
The Social Web Incubator Community Group (SWICG) works on ActivityPub standards:
Current SWICG Task Forces and their deliverables
It’s slow as fuck. But, at least its moving forward now. The end to end encryption, groups, and forums efforts are vital.
Matthias Pfefferle notes:
FEP-d1cb: Same-origin actor re-identification
Matthias does the most impactful work in the AP community IMHO. We need 200 more of him.
Terence Eden asks:
ActivityPub – Is it worth defending against replay attacks and message/signature time skew?
Spielleitung shares how to block a registration bot:
Prevent “BoomProtocolProbe” from registering
Starling
Starling is an ActivityPub server that can actually exchange posts, follows, profiles, replies, likes, and boosts across the Fediverse with Mastodon, Misskey, Pleroma, GoToSocial, PixelFed, and other ActivityPub-compatible platforms.
This is a perpetual pet peeve because many people aren’t able to comprehend ⬇️:
So, recognize their natures and don’t ask the two protocols to go against them. This is also why we have accounts on both platforms and use them differently.
IFTAS has:
Updates to IFTAS Denylists and Access Options
Bonfire presents:
Sovereignty Is More Than a Server: Public Digital Commons with Bonfire
Jola.dev looks at:
Migrating your Bluesky account the hard way
Building AT Habitat shares:
Habitat’s road to release: 05 adopting opensocial
This appears to be a promising Atmosphere alternative to my Manade project.
Speaking of, atproto-spaces-alpha-updates has an update:
Breaking Changes around the simplespace API
Erlend Sogge Heggen explores:
Aaron Ross Powell examines:
Social Media and Anti-Social Pluralism
Which is why we need more private autonomous online communities. That’s what I’m exploring with Manade.
MeTacheles has:
W Social Netzwerk: Fake-Zahlen, Rassismus und Totenstille!
Plus there’s this kind of horseshit:
You can’t currently move from/to W without help from a dev
You may have to be logged into the Atmosphere to see this. Anyway, if you are a mark that got grifted into W, just delete you account. Hopefully, no one will ever find out you signed up. Except every company they will share your information with.
Atmosphere Conference News announces:
AtmosphereConf 2027 Organizing is Underway
Happening somewhere in Europe. ???
Bunnies in PCKT says:
RSS is still my preferred feed format
Mon aussi.
FreshRSS announces:
Internet Exchange looks at:
Building Online Communities We Can Keep
And please build something for a community! We’re painfully nurturing Manade.
Sharkey is generally no longer actively maintained. Much like IceShrimp, which shifted its focus from IceShrimp-js to IceShrimp.net, Sharkey is effectively in "maintenance mode only." This means it still receives critical security updates and required patches, but it generally no longer tracks upstream Misskey development.
Sharkey's latest release: 2025.4.7
Misskey's latest release: 2026.9.0
I had to laugh when, back on January 13, 2026, they titled a release "2025.4.5 — We'll catch up, we promise." The release right before that had been 6 months earlier. In all the time since, they've only pushed out 2 security updates (2025.4.6 and 2025.4.7). They are now well over a year behind Misskey's development.
If anyone has the time and skills, I hope someone builds a script to migrate Sharkey sites back to Misskey. Since Sharkey is a fork of Misskey (as was FireFish), it should be possible and is a smart precaution.
#Sharkey #Misskey #FireFish #OpenSource #Fediverse #ActivityPub
Week in Fediverse 2026-09-11
Servers
- Hubzilla v11.4.1
- Bookwyrm v0.9.3
- Cookifed v0.1.0
- Ktistec v3.12.1
- Misskey v2026.9.0
- gathio v1.6.7
- NeoDB v0.18.2
- Appy v0.7.0
- PieFed v1.7.15
- Wafrn v2026.09.01
Clients
- Voyager v2.49.0
- Miria v4.0.1
- Aria v1.5.13
Tools and Plugins
- Enable Mastodon Apps v1.6.4 (WordPress plugin)
Articles
- Static ActivityPub Publishing
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/01a06eb0-8683-70d3-bb1d-19ef2967e02b
RE: https://mastodon.social/@dansup/117246306213045632
I swore not to speak about #FediHood any more, but what #Pixelfed is doing is great news for #ActivityPub.
Pixelfed already sends the location as a Place object with latitude and longitude, so FediHood can read it and put markers on a map.
Local timelines used to mean one instance. Now they can mean people actually around you.
Anyone who is interested in the #Fediverse and #ActivityPub is welcome to join the Social Web Community Group #SocialCG at the #w3c.
It's the group that develops and advances the social standards that make this network go. It's open to anyone. If you have specific interests, we have task forces that work on specific topics. Or you can start one!
It's easy to join.
I just added a new watchlist to the fediverse.party wiki, for CMS that have ActivityPub plugins;
https://codeberg.org/fediverse/fediparty/wiki/CMS+with+ActivityPub+plugins+-+watchlist.-
As always, if you see any gaps or errors, sing out!
boosted
IFIN - The Independent Federated Intelligence Network » 🌐
@ifin@infosec.exchange
Because we changed our domain, our #ActivityPub #ThreatIntel federation also changed! You can follow @threatintel for all posts in our forum's Threat Intel category.
Right after @berlinfediday is over, I am hosting another edition of
Berlin Federated Network Exploration Circle / #BFNEC
Sept 13th at 7pm at @offline
✸ @pukkamustard will talk about their work on ERIS and give us the backstory on their initiation of the fediverse's FEP process.
⁂ @f will discuss his work on @sutty, a platform aimed at giving organizations and collectives the means to publish and host more secure websites. He will also talk about how they recently added #ActivityPub federation.
FediForum Fall 2026 starts in four weeks, exactly.
Registrations and proposed topics are coming. Check some of what has been proposed so far on https://fediforum.org/2026-10/
I've now found two different #ActivityPub implementations which *don't* send a message digest in their headers.
That's much more of a risk than a long clock skew, I think.
Technology wars are generally unproductive and unconstructive. At the same time there's undeniably competition - #ActivityPub vs #ATProto - or coopetition - ActivityPub vs #XMPP - between different technologies. Because success and popular uptake of one technology can lead to the demise of another.
Instead of diminishing the other #technology and engage in endless heated fights and conflicts, it is better to consider the technology one is most passionate about, and look for all those aspects and factors that are important for its uptake and widespread #adoption. Stand strong in your own shoes. Other #technologies then become input to learn from. What are weaknesses, what can be copied, and what can be done better? And also, where can there be unison, interoperability, collaboration, cross-pollination with other technology ecosystems?
Technology doesn't "win". It's people who stand to win or loose, depending on how well the tech supports their needs.
Indeed. Over the years I've seen so many developers become discouraged to continue their #ActivityPub projects after becoming initially highly excited upon first reading the #W3C specs. They bump into a world of undocumented complexity, harsh wire realities, inconsistencies and tech debt. Only the true "stayers" grit their teeth and keep at it. Developers love to be able to focus on a solution, and not get mired into all kinds of low-level plumbing that is not related to that.
This makes tech that's social-culturally worse (ATProto w/ centralization, VC capital) still have better uptake potential.
I gave special mention to both @fedify and @Bonfire in my article. For #Fedify for how they focus on providing a framework and SDK that hands people software so that they can focus on "solution development" immediately. And #Bonfire because they constitute a framework, but also engage directly with clients and partners in solution development, closest to making the paradigm shift.
🆕 blog! “ActivityPub - Is it worth defending against replay attacks and message/signature time skew?”
Here's a problem that I've found with ActivityBot - my little ActivityPub server. Sometimes it receives messages which were originally sent months ago. Why does that happen and is it risky to accept and…
👀 Read more: https://shkspr.mobi/blog/2026/09/activitypub-is-it-worth-defending-against-replay-attacks-and-message-signature-time-skew/
⸻
#ActivityBot #ActivityPub #http #security
My most recent blog post deals with this subject matter as well, and how we might make a paradigm shift to move away from this app-centric #fediverse where "users" (i.e. people) hardly have a say in its evolution. The efforts around the #ActivityPub API may be an enabler for this shift, but there are major social challenges to be dealt with.
https://coding.social/blog/prosocial-web/
Personally I don't think the app-centric fediverse has a healthy future or outcome.
How this is implemented is crucial for the future of the #fediverse. An app having app-specific integrations to some - indeed ethical - payment systems, is one thing. But for instance offering native #monetization features on #ActivityPub protocol level, and not thinking *very hard* about the implementation and impact of that, can totally enshittify the #fedi in no time in how it attracts the wrong type of people with dollar signs in their eyes.
The current app-centric fediverse is the playground of devs and "users" that have to swallow what they create and drop onto the wire. #FOSS culture is a poor model for the evolution of the fediverse, where the latter is an existing social space where people, the online residents, have their home. It is much more than a pure technosphere and playground for app devs.
Fedi isn't ready to be growth-hacked. If successful it'll undoubtedly see corporate capture with Corporate Fedi the outcome, same as the web.
Ha, @loremipsum I love your anti-bot tag cloud. 😆
Do you mind, if I make a reference to it in an issue on #Botiquette I created?
https://codeberg.org/fediverse/fediverse-ideas/issues/33#issuecomment-13221306
The Bio field shouldn't be for arbitrary app-specific #hashtag control words, that devs invent on-the-fly to drive their custom opt-out or opt-in mechanisms.
is there a FLOSS app for Android that support both activitypub and ATproto accounts in one interface?
I have some resources queued up for addition to the delightful #fediverse development curated at:
https://delightful.coding.social/delightful-fediverse-development
@Steve_Bate created an #ActivityPub vocabulary using #LinkedData and wrote an article about it:
https://www.stevebate.net/activitypub-ontology/
And also he created a #JSONSchema project for the #fediverse:
https://github.com/steve-bate/fediverse-jsonschema
Then there are 2 vocabulary projects in code that I am aware of, one in #Rust and one in #TypeScript:
@maddyunderstars forked and extends activitypub-types:
https://github.com/MaddyUnderStars/activitypub-types
And @weathered_steel@weathered_steel.social wrote:
https://codeberg.org/activitypub-rs/activitystreams-vocabulary
Today I am mostly learning PHPUnit so I can add some tests to #ActivityBot.
Interesting to see what assumptions I've made along the way and what the consequences are.
I also wish there were a schema for #ActivityPub JSON which I could use to test my outputs.
For #ActivityPub applications people may refer to the three deligthful #fediverse curated lists I maintain. See the ToC in the top-level list at:
The ActivityPoll #FEP has a very unfortunate name, clashing and overloading with the existing concept of a #Poll on the fediverse. The mechanism it documents is generally called #Polling.
Yes, but...
I understand the RSS and Atom specs well enough that I've created programs with RSS/Atom feeds. But the ActivityPub spec scares the willies out of me. Too many moving parts.
Welcome to this week’s The Programmer’s Fulcrum.
It’s your weekly curation of the essential news in the Open Media Network and Open Social development communities with a focus on devastating big tech via Techno Anarchism.
This post originally appeared on The Fulcrum.
As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional benefit of weakening authoritarianism.
IMHO, the best way to do that is to use tools from the Techno Anarchist Manifesto to build your own site(s) to participate in the Open Media Network. Then you should share it (them) via Real Simple Syndication (RSS), Open Social, and possibly a newsletter or podcast. This approach is similar to what some call the IndieWeb and its POSSE philosophy.
The second best strategy is to have accounts on open social and use the hell out of them. And do the same with a RSS feed reader.
We publish TPF on Fridays so you can enjoy it over your weekend.
There’s good stuff in all of our categories, so please take the time to enjoy and bookmark the items most relevant to your goals. We hope you are inspired to create new ones.
Or you can scroll down to your favorite section.
FYI, my opinions will be in bold. And may involve cursing. Because humans. Especially tech bros. And fascists. Fuck´em.
Iris Meredith writes:
So, when I hear a tech person say that something’s “just a tool”, I can’t help but read it as an unwillingness to take responsibility, as an industry, for what we put into the world and for what we do to ourselves. Tools, unfortunately, simply cannot be the neutral, separate thing that so much of the tech world would like them to be, and pretending otherwise, let alone telling people affected by the tools that they’re simply using them wrong, is an abdication of our moral duty to avoid, inasmuch as is possible, doing harm. We really ought to do better.
There’s no such thing as Just a Tool
There is such a thing as TechBros, unfortunately. And their cuntier cousins, AIBros. And apolitical is a synonym for fascism-friendly. At least straight-up Nazis aren’t hypocrites.
Social Coding Commons writes:
… in modern society, generally speaking, we give too much credence to the technosphere. We take the idea that innovation equates to societal progress as a given, to which we must subsequently adapt ourselves. We tend to turn things around, where “digital transformation” suddenly means how humans must adapt their lives to new technology that comes to disrupt it. And not the other way round.
The Fediverse has evolved purely as a technosphere (unfortunately).
Paradigm shift to the Prosocial web
A fan-fucking-tastic piece.
On a relate note, Hamish Campbell has thoughts on Open Governance Bodies / Building:
Power stays with the people doing the work
This is a good explanation of how digital communities and projects can govern themselves.
And we published an article this week, where I write:
The premise of this article is that developing or using ActivityPub tools, participating in the Fediverse, publishing to the Indie Web / Open Media Network, and adopting the arsenal of the Techno Anarchist Manifesto are the new punk.
ActivityPub, the Fediverse, the IndieWeb/Open Media Network, and Techno Anarchism = Punk Rock
Jan Miksovsky explores
Origami Projector: a Glitch-like app for site editing
A great idea. Although only available on newer Macs unfortunately.
I also ran across AnyPub, an editor for Standard.Site publications.
CSS Tricks explores the:
WordPress PHP-Only Block Registration
Good news for those migrating legacy sites. And avoiding the shit known as React, at least some of the time.
Why Do I Write This? writes:
Neocities is for nostalgic masochists
Seems about right.
Scraps! expounds:
Mark W.Rites says:
Alt Text is the Ocean You Thought Was a Pond
Faircamp announces:
And Vidnight has:
I disagree with the take that the internet is dead
Enjoy the open web peeps. It helps keep me sane. And I am happy to see this from a 20 year old. 🙂
Spectral Web Services has:
I accidentally built an image library for Ghost
This should be in Ghost core. It sucks that it isn’t.
Their competitor, Magic Pages has:
Good stuff.
Tuta has:
Digital Sovereignty Study: EU IT leaders are quitting U.S. Big Tech
U.S. Sanctions against Autistici / Inventati are the next wake-up call for digital sovereignty
KDE examines:
NLNet urges:
Apply for funding before November 3rd 2026
They are going the correct direction with AI use, which is to severely restrict it.
Organic Maps has:
Threat Model shows us:
Mullvad is:
Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
FluffyChat shows us:
How to use end-to-end encryption in FluffyChat
About Signal reports:
Signal introduces new notification settings for Android and Desktop
Servo shares:
July in Servo: more platforms, faster canvas, web fonts in SVG, and more!
9to5Linux reports:
Mozilla Firefox 155 Is Now Available for Download, Here’s What’s New
Remember to use Firefox forks like Zen, Waterfox, or Librewolf.
Webkit has:
Submit your ideas for Interop 2027
Fixing Top-Level Await in Safari
Remember not to use Safari for anything you want kept private. And preferably not at all.
Nextcloud shows us:
Fuck Google!
Joplin shares:
The new table editor in the Markdown editor is awesome. The addition of AI features sucks. At least they are optional you can use a local model.
LibreOffice announces:
Bon. AI should almost never be used, but if it is (translation), it should be as an optional extension.
Kdenlive announces:
9to5Linux reports:
OpenShot 4.0 Open-Source Video Editor Officially Released, Here’s What’s New
Audacity 4.0 Open-Source Audio Editor Officially Released, Here’s What’s New
And:
Debian Project Formalizes Responsible Use of Generative AI
Like Linux core, Debian chooses to slowly ensloppify and likely enshittify.
F-Droid has its weekly summary:
Searching complexity and Taler update
Dokieli
Write, publish, and annotate articles from your web browser. Your content stays yours.
Typemill expounds:
On the way to automate user manuals and knowledge bases
This is a legitimate use of local AI. It’s the second most legit use after translation.
The Linux Foundation has a useful course for KISS developers (rare for them):
Share Smarter GPU Resources and Master Git
from First Commit to Merge Conflict
Their learning platform subscription is not cheap, but this might be worth a one month one while you finish the course.
Vasilis van Gemert explores:
What are we not talking about anymore?
Master.dev examines:
New Things You Should Know About HTML Here in Mid 2026
Great stuff.
Vale says:
As in unnecessary.
Ollie Williams explores:
Highlighting a range of text inside an input or textarea
A rarely needed though legitimate use of JavaScript.
So AI is now fucking over tech conferences as well:
Lettre ouverte pour la survie des événements techniques en France
And freelancers:
Freelancers are getting buried with ‘soulless’ AI slop cleanup: ‘It’s a shame we need to do it’
One of the main purposes of AI is to drive down the cost of labor (it’s a fascist artifact). And these are the consequences when you use it.
OakChris1955 looks at:
Migrating from Cloudflare Pages to Codeberg Pages wasn’t that difficult, actually
I have used Codeberg to deploy a test Publii site. And it worked great. But, you were limited to one site at that point.
Write for your website and documentation. And not for AI.
ActivityPub for WordPress shares:
9.3.0 — Modern Signatures and a Summer of Security Reports
This is a perfect example of what an update announcement should be. 😉
Social Coding Commons opines:
I argue that ForgeFed and ActivityPub should support multi-types as specified in Activity Streams
They are correct and this provides an insight into why AP development is so slow and convoluted. And to why there is much less innovation in the Fediverse as compared to the Atmosphere with ATProto. ActivityPub is just more anarchic.
Not that its a bad thing, as I point out in my featured article. Plus, it’s definitely more enshittification-resistant.
Plus, core ATProto has much more money and developers behind it than ActivityPub does.
Terence Eden has:
A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP
ActivityBot is the recipient of an NLnet grant!
In effect he’s creating something similar to Starling for bots. And it’s for use as a developer learning tool.
A review of the ActivityPub book.
Andros Fenollosa explores:
Building a decentralized bulletin board (and accidentally reinventing Nostr)
Abuuba announces:
Interesting.
Mobilizon needs you:
ForgeFed
ForgeFed is a federation protocol for software forges and code collaboration tools for the software development lifecycle and ecosystem.
This is a perpetual pet peeve because many people aren’t able to comprehend ⬇️:
So, recognize their natures and don’t ask the two protocols to go against them. This is also why we have accounts on both platforms and use them differently.
TootSDK announces:
A new release of TootSDK – 23.3.0
Owncast announces:
Owncast v0.3.0 has been released!
Fedilab Apps has:
FediHood now lets you sign up and log in with your Mastodon account
This definitely makes it more useful.
Mastodon announces:
We just released Mastodon v4.7.1, v4.6.7, v4.5.17 and v4.4.24
And the Real Grunfink announces:
I’ve just published version 2.95 of Snac
Bonfire has:
Bonfire 1.0.7: what’s new and what’s next
Great stuff.
Building shared infrastructure for the Fediverse
Very important because -> see my comments about the Social Coding Commons piece above.
Andros Fenollosa notes:
There is no such thing as full decentralization
A great overview and explanation.
Open Risk Management goes down an empirical rabbit hole:
Towards a Graph Calculus for Decentralized Social Networks
マリウス shares:
Hyperuplink: Discuss like it’s 1998
Cool.
Venoom examines:
Decentralizing social media using ATProto and Matrix (venoom)
Eventuallycoding has:
Le piège de la transparence par défaut sur Bluesky et le protocole ATProto
Skyreader shares the:
Structural Integrity explains:
W Social is a textbook case for everything wrong with digital sovereignty
Roomy looks at:
Worm-Blossum shares its:
Ross Floate has:
I built a new website. It’s happiest when you leave.
Very cool. I am going to try to replicate this on one of my sites.
The Association for Progressive Communications has an interview:
Libervia on building an all-in-one communication platform grounded in the right to privacy
Daniel Gultsch celebrates:
Jabber/XMPP: 25 Years of Digital Independence
Matrix has:
Neo Nominated for Open Source Competition
This Week in Matrix 2026-09-04
And please build something for a community! We’re painfully nurturing Manade.
I have a buncha questions! I will intersperse where relevant.
I am looking at some #indieweb integrations which mix #blog and #ActivityPub - a sort of 1-person masto instance, where responses become comments. Have you looked at any of these?
For me, most of my entries are not public but more journalling, so I am looking for something more complex and secure, yet integrating federated content sharing.
An article was submitted to HN how #Authorization terminology is a mess and proposed a way to fix it.
Top-level comment started a discussion on the difference between SHOULD and OUGHT TO. The latter expresses a moral imperative.
SHOULD is defined in #RFC2119 which is referenced in all #ActivityPub specs and #FEPs.
Now, there is an April Fool's RFC6919 which defines OUGHT TO. While this RFC is created just for fun, to express all kinds of wriggle room to a spec, which is often the reality in a codebase, the OUGHT TO indicator is not all that bad for actual use in #fediverse specs.
The fediverse is more than cold, hard technology space. It is a place where particular values and principles are held dear, moral imperatives to build better alternatives to social media.
An ought combines with a should like this:
"Privacy OUGHT TO be protected first and foremost, therefore an opt-in mechanism SHOULD be provided"
https://idpro.org/authorization-terminology-is-a-mess-lets-fix-it/
Week in Fediverse 2026-09-04
Servers
- Ktistec v3.12.0
- Mastodon v4.7.1
- Vernissage v1.43.0
- snac v2.95
- ActivityPub for WordPress v9.3.0
- Owncast v0.3.0
- gathio v1.6.6
- NodeBB v4.15.2
- tootik v0.25.2
- NeoDB v0.18.0
- Bonfire v1.0.7
Clients
- PleromaFE v2.11.4
- Fedilab v3.43.3
- Tuba v0.11.1
- Pixelix v5.2.0
- Summit v1.85.0
- Shoot Web App v1.3.0
Tools and Plugins
- FediFetcher v8.2.0
- Poduptime v6.3.2
- Enable Mastodon Apps v1.6.3 (WordPress plugin)
For developers
- APx v0.27.0
- Library progress report - September 2026 (GoActivityPub)
Articles
- A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/01a04a26-eede-72b0-a5e9-f244c3ff2142
Should publishing with ActivityPub be about as easy as publishing with RSS?
#EvanPoll #poll #ActivityPub #RSS #publishing
| Yes: | 159 |
| Yes, but...: | 32 |
| No, but...: | 4 |
| No: | 5 |
Closed
Woot, a rave review by @thefulcrum 💞 on my blog post "Paradigm shift to the Prosocial web".
https://www.thefulcrum.dev/the-programmers-fulcrum-4-september-2026/
Thank you very much!
Based on a recent discussion about the sharedInbox capabilities of #GoActivityPub servers, I had to go back and revisit the logic to make sure it conforms to the spec to the level that I said it does.
Well, after a closer look, I gotta say there were bugs. For example blocked relationships were not checked, so if either the activity actor had blocked one of the sharedInbox recipients, or vice-versa, they still received the activity.
Now this is fixed, but it introduced quite a large number of additional checks in what's already a pretty storage intensive mechanism. I think I need to step back for a moment and reevaluate.
It sure can. I consider #ActivityPub fediverse a social networking environment, and social media a subset of social networking, which I define as: Any direct and indirect human interaction between people.
When you talk of "echo chamber" you refer to a typical anti-pattern of existing social media platforms. It is unfortunate that fediverse grew to be such a microblogging-dominant space, a Twitter++, and it could be said to be a severe lack of imagination on what social networking entails. But it is understandable when we consider how fedi evolves: by post-facto interoperability. Where who comes first decides what goes, and that was Mastodon, a #microblogging app.
Social experience design considers "Personal social networking" where the needs of individual participants are central, and design is inspired by analogies to how we do social offline. #Fediverse becomes a unified space where you navigate communities and move in and out of different social contexts seamlessly.
Arguably #fediverse is NOT based on an open standard.
It's based on 'guidance towards an open standard' via the incomplete #ActivityPub spec, sprinkled with what fediverse devs have added over time via post-facto interoperability in what's effectively a Big ball of mud anti-pattern. These extra's are to be discovered on-the-fly, and being app-specific, need to be maintained constantly in another anti-pattern I dubbed Whack-a-mole programming.
We can do better. We can rise above the app-centricness of the fedi, make a paradigm shift that helps increase evolution speed and rate of innovation and sees people's needs be better served..
https://coding.social/blog/prosocial-web
For that to happen major social challenges need to be tackled, like coordinating and collaborating well in a good grassroots standardization process.
I posed the concept of a Grassroots open standard, where services encapsulate their design, and the standardization process is a fedi-native service itself.
@silverpill @smallcircles
> So far, REST APIs worked very well for fediverse.
This point isn't clear to me. I assume you're referring to the Mastodon API. If so, the #ActivityPub API (including C2S) is a REST API too.
The Mastodon API has worked reasonably well for its intended microblogging use case. However, it's not a governed API and the Mastodon team has made it clear it could change at any time without warning or community involvement.
Hm... FEP-c0e0: Emoji reactions details two ways to federate an Emoji reaction:
EmojiReact activityLike with content (as opposed to a regular Like, which has no content)In testing, I noticed that misskey (or at least, the site I was testing with, birb.space) sends the latter. I don't know what sends the former, and if NodeBB were to start federating out EmojiReact, would it be broadly understood?
Perhaps I should federate out both at once.
I just noticed that, if I look up a #Lemmy or #Piefed community on #Mastodon, I'll get a profile page but no posts!
Is that a bug in Mastodon? Or is there no standard #ActivityPub protocol for fetching content from a person/group that you aren't already following?
I seem to recall Mastodon adding a “fetch content from the other server” feature recently, but it sounded like a Mastodon-specific protocol extension was involved. That's…not great. It really should be universal.
🆕 blog! “A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP”
If you're reading this, you've probably been hitting your head against a brick wall trying to parse and decipher the new HTTP Signatures sent by Mastodon and other Fediverse servers.
This is a…
👀 Read more: https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/
⸻
#ActivityBot #ActivityPub #mastodon #php #webdev
FYI I created an issue in the #SWICG #ActivityPub API repository relating to my blog post publication..
Totally. The way #AI wrecks #FOSS culture leads to a lot of soul searching on the merits of the FOSS model we always held dear. FOSS in-the-large may be complicit even to the rise of #BigTech and #LLM, while for individual participants - all working on proper principles and values - it is inherently unsustainable, a burnout factory.
I think AI also opens opportunities. Corporations using it further retracted from directly serving people, leaving empty space, niches for small initiatives to occupy and focus on humaness, real human-to-human connection we crave.
#HCOSS fits perfectly.
Social experience design #SX uses the concept of #SOSS here. See the quoted toot. FOSS software is delivered via Social supply chains, where the needs of all participants in the delivery process are considered.
This concept fits perfectly with the solution-oriented #ActivityPub fediverse of #apps and #services, to offer support. #ForgeFed makes a start on this path.
Yes, indeed. Luckily they decided fedi is not interesting enough as yet to either snuff out or capture. If they'd make that decision there'd hardly be a defense.
One of the big weaknesses of fediverse today is that 8 years after #ActivityPub became a W3C Recommendation we are still figuring out basic core protocol plumbing. And without a robust foundation to build compliant solutions on follow-the-leader post-facto interoperability is how the fediverse evolves.
The trend today is that there are two outcomes for fedi's future. Either it doesn't gain broad adoption and remains niche (not the worst outcome), or it "crosses the chasm" and gains broad popularity which will trigger a corporate capture and takeover.
The challenge we face is entirely social in nature. The technology is not the problem. It is there. Open technology space for anyone to dabble in. Fediverse needs a tight-knit community of carers that ensure it will become more than cold technology space.
#Fediverse today consists of apps and app platforms. It is entirely app-centric.
Since fediverse (luckily) didn't attract much corporate attention yet, it is dominated by #FOSS culture, where people on the #SocialWeb are all "users" that are dependent on FOSS developers to serve their needs. Every dev focuses on their app features first and #interoperability second, leading to a patchwork of poorly integrated apps, and a janky overall experience. The app delivery model is not much different than Web 2.0.
A paradigm shift is possible, to a #SocialNetwork of apps and services, a service-oriented #fedi. The efforts around the #ActivityPub API can be the enabler of this shift.
In this new paradigm devs introduce solutions to a unified #SocialNetworking space, delivering new services to participants on the network. On top of a robust Protocol Layer they model social use cases in the Data Layer, integrating with services and building blocks already available.
So, I've been running my personal instance of ONI for abut 2 years. I follow about 34 other fediverse accounts (only two on mastodon.social).
It has stored over this time about 3.2GB of data spread over 345K JSON-LD documents (mastodon.social is responsible for about two thirds of the size)
However the thing that's surprising for me the most is that despite the fact that I'm using the least "web scale" storage available - plain files on disk - the instance is still very responsive. The server also does a lot with collection filtering in order to display a meaningful timeline to me, so it's not just a dumb pipe from disk to browser.
Fixed a bug in the notification page that made snac hang forever while trying to read abnormally big files.
Improved support for text-only web browsers: it's now possible to configure a set of web browser user-agent strings that will receive simpler HTML in the private timeline web UI. Basically, it consists in avoiding details / summary HTML tags as much as possible.
Added some fixes to media proxy code.
Fixed EmojiReact code to allow any emoticon defined in emojis.json, not only those with colon-wrapped identifiers.
Fixed a bug in notification filtering (paging was sometimes incorrect).
Added a notification filter for Webmentions.
Mastodon API: Don't return reactions count as string (contributed by mkljczk), implemented GET /v1/media (contributed by clairemont).
Fixed bug in documentation examples (contributed by Sprite_tm).
Updated Ukrainian and Russian translations (contributed by wincentbalin and koru).
If you find #snac useful, please consider buying grunfink a coffee or contributing via LiberaPay.
I argue that #ForgeFed #ActivityPub should support multi-types as specified in #ActivityStreams, even though how to actually work with them in a robust AP extension mechanism hasn't been fully figured out yet.
The argument for avoiding multi-type is to compromise in order to facilitate the current microblogging-heavy installed base on the #fediverse. While that is practical, it will forever keep the tech debt we have created in our fediverse ecosystem.
#Forge federation should not have a primary concern to retain compatility to legacy #microblogging apps, imho.
https://codeberg.org/ForgeFed/ForgeFed/issues/324#issuecomment-22201186
#FediHood now supports #Lemmy through #ActivityPub. You can subscribe/unsubscribe from groups, read threaded discussions with their upvote scores, and reply or upvote yourself (through the fav button).
This is the first step: FediHood will also automatically split messages into city, region and country groups that everyone on the fediverse using groups will be able to interact with.
Can someone that's familiar with the details of FEP-044f (the one underlying Mastodon's quote posts) tell me if there's something I missed and there *IS* a way to ensure that malicious instances (or clients) aren't able to disregard the whole thing and just allow and present quoted posts without their original user's consent?
🆕 blog! “Book Review: ActivityPub by Evan Prodromou”
★★★★⯪
As part of my grant from NLnet to improve my Fediverse bot project, I'm spending time making sure I understand all the fundamentals of ActivityPub. The problem with Internet standards is they're scattered all over the place. Abandoned forums, half-maintained wikis, mailing lists with obscure rules, and…
👀 Read more: https://shkspr.mobi/blog/2026/09/book-review-activitypub-by-evan-prodromou/
⸻
#ActivityPub #BookReview
A weird #ActivityPub message from #Frendica.
Signed on 2026-09-01
Published on 2026-03-02
That's a skew of six months! The message type is "Undo" - so they're undoing a like they sent in March.
Is there *really* a worry about accepting requests like this? Given the message has been signed, what risk is there to replay attacks?
Bug report at https://github.com/friendica/friendica/issues/16150
I migrated from my self-hosted Mastodon instance to mastodon.social. Of course, I couldn't move my posts so I created a small server to provide the archive of my post history without changing any #ActivityPub URIs or media URLs. It seems to be working well. RAM usage is down from 1.2GB to 45MB (-97%) and disk usage down from 160GB to 15MB (-99.99% drop) compared to keeping the old server running. I've been surprised how many "hits" I'm seeing for old posts, so I'm glad the archive is available.
Hey, #Mastodon and #ActivityPub developers.
How much skew do you allow before rejecting a message?
I've just received something where the header is signed:
Mon, 31 Aug 2026 20:09:54 GMT
But the ActivityPub message was published:
Mon, 31 Aug 2026 19:58:36 GMT
That's a little over 10 minutes. Is that too much? Should I not care as long as the signature validates?
#FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Mastodon #ActivityPub
Today I think SWICG should focus on the 'Protocol implementer' stakeholder: How can they offer compliant #ActivityPub protocol implementations.
Do you mean they should develop testing tools?
I wrote a comment in the open issue on the 3-stage process, in the SWICG charters repo..
https://github.com/swicg/charters/issues/33#issuecomment-5470092604
Having looked in more detail at the #SWICG document. That's not the 3-stage process I advocated for at the time, and I agree with you: It will not work. Such top-down formal ceremony just does not fit a grassroots ecosystem.
Generally speaking I don't think #W3C as a standardization body is up to the task of being a good host for the ActivityPub specification. It is a) not organized for our environment, and b) only takes care of the technical aspects. Our social media landscape has a huge social component, and this is wholly underrepresented in our app-centric fediverse, where people are merely "users" and #FOSS culture is the only driving force.
Today I think SWICG should focus on the 'Protocol implementer' stakeholder: How can they offer compliant #ActivityPub protocol implementations.
Then #FEP can focus on the 'Solution developer', relieved from the plumbing: What interoperable designs do they use to serve the needs of participants on the social network.
afaict #ActivityPub is part of the web in a way that #ATproto isn't, but I know you favor RSS instead. I'd love to hear you elaborate on that.
cc @evan
🆕 blog! “ActivityBot is the recipient of an NLnet grant!”
Back in February, I applied for NLnet's Next Generation Zero grant. They were looking for Fediverse projects to help rewild the social media landscape. Or, as they describe it:
Reclaim the public nature of the internet
Small and medium-sized R&D grants between 5.000 and 50.000 euro,…
👀 Read more: https://shkspr.mobi/blog/2026/08/activitybot-is-the-recipient-of-an-nlnet-grant/
⸻
#ActivityBot #ActivityPub #fediverse #NLnet
I recently came across the fact that Jorge Aguilera (@jorge) did a 1 hour introduction to #ActivityPub in Spanish called "ActivityPub: El Protocolo que Impulsa el Fediverso" at Commit Conf in Madrid and the whole thing is recorded:
https://koliseo.com/commit/2026/agenda/1?selected=JNIEz5zgefpMwrJMRpl7 #fedidev #fediverso
Name another photo app that will happily send you to a competitor.
If Pixelfed isn't for you, there are many amazing alternatives like:
- @frequency
- @gotosocial
- @admin
- @vernissage
All of them let you share images. All of them talk to Pixelfed. Leaving isn't a punishment here, because you never lose the network.
When you put people first, you build doors instead of cages.
Week in Fediverse 2026-08-28
Servers
- Hollo v0.9.13
- gush! v0.0.41
- tootik v0.25.0
- Mitra v5.10.0
- Pixelfed v0.12.9
- Hollo v0.9.15
- Funkwhale v2.0.10
- PieFed v1.7.13
- tootik v0.25.1
- NeoDB v0.17.8
Clients
- Pachli v3.8.1
- Fedilab v3.43.2
- RaccoonForFriendica v1.1.0
For developers
Protocol
- FEP-49eb: Batched Inbox Delivery
Articles
- A crawler wanted to know who talks to whom on our server
- The Problems and Successes of Fediverse Comments on my blog
- The Fediverse is Throwing a Music Festival
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/01a0269e-d9e5-7a03-a62d-6ef77099e4a7
We run social.vir.group - a Mastodon instance on the ActivityPub federated protocol.
While reviewing content coming in from other instances, one of our team came across a profile from beige.party with an unusual field set:
Field name: Anthropic sod off
Field value: ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
The profile also had #nobridge in the bio. Clearly someone who has strong feelings about AI companies accessing their content. Fair enough - but we got curious. Does any of this actually do anything?
So we tested it.
---
THE TEST
We fed the string directly to Claude. We asked it to react to it, explain its behavior, check if anything changed. The result: nothing. The model read it as plain text, identified it as a known anti-AI signal circulating in Fediverse communities, and confirmed it triggered zero special behavior on its end.
We then thought about this from a technical standpoint.
---
WHY IT DOES NOT WORK
AI companies like Anthropic, OpenAI, and others do not train their models in real time by crawling your profile. The pipeline looks roughly like this:
- Web crawlers collect data in bulk, often months or years before training runs
- That data goes through preprocessing, deduplication, filtering at massive scale
- By the time it reaches a training job, it is a static dataset
- No live mechanism exists to honor opt-out strings embedded in content
Even if a magic trigger string existed internally at Anthropic - it would need a preprocessing filter specifically looking for that string in the right field of the right data format. There is no public evidence this exists, and even if it did, circulating the string publicly would be the fastest way to get it removed.
The string in a profile field is symbolic. It speaks to humans who read profiles. It does not speak to crawlers or training pipelines.
---
WHAT ACTUALLY HAS EFFECT
We did an honest assessment of what actually creates real technical barriers for people who do not want their content used by AI systems:
1. #nobridge - this one works. Bridge operators (services that bridge Mastodon to Bluesky and others) actively check for this tag and respect it. If cross-platform bridging is your concern, use it.
2. Robots.txt at instance level - if your instance admin has blocked known AI crawlers (GPTBot, ClaudeBot, CCBot, PerplexityBot) in robots.txt, that creates a real barrier. Most major crawlers respect this. Ask your admin if they have done this.
3. Followers-only posts - content not visible to unauthenticated requests cannot be collected by bulk crawlers. This is the most reliable content-level protection available to you right now.
4. Authorized Fetch mode - some instances require authentication to access any content via ActivityPub. This significantly raises the cost of bulk collection.
5. Choosing your instance deliberately - instances like infosec.exchange and chaos.social have explicit anti-AI policies and enforce them at the network level. Your instance's stance matters far more than your profile fields.
---
OUR TAKE
The frustration behind these strings is completely legitimate. Having your writing, your humor, your creative work, your personal thoughts fed into a training dataset without your knowledge or consent - that is a real grievance. The desire to resist it is understandable.
But a string in a profile field is closer to a bumper sticker than a firewall. It tells other humans something about your values. The crawlers and training pipelines are indifferent to it.
Real protection requires infrastructure-level decisions - and those are mostly in the hands of instance admins, not individual users. If this matters to you, the most effective thing you can do is pick an instance that shares your values and enforces them technically, or talk to your current admin about their crawler policies.
---
What do you think about this movement? Do you have anything like this in your own profile? Do you believe individual-level resistance to AI data collection is meaningful - or is it purely symbolic?
#Fediverse #ActivityPub #AIethics #nobridge #privacy #Mastodon #OpenSource #LLM #dataPrivacy #socialVirGroup
It looks like the migration to this new instance was [mostly] successful. However it does appear I lost some followers and followees.
Note to fediverse app and ActivityPub maintainers: we really need one and only one schema and format, based on flat text lines or .csv, for importing, exporting, migrating profiles, posts, follow(ing) lists, etc. Too many cooks spoils the stew.
One of the funny things about reading the #ActivityPub specification is how much @cwebber loves #Emacs #orgmode.
In our read-through tonight we read the aside that said it might be a good idea to abandon editing a Note if it could mess up your org-mode formatting, and I was like, yeah, that sounds like something Christine would do.