soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Mastodon ist wie Twitter.
Ein Thread besteht aus Posts, Posts und noch mehr Posts. Es gibt nur einen Editor für alles. Damit kann man auch überall jederzeit eine CW dranhängen.
Das CW-Feld ist das CW-Feld. Und beinahe jeder auf Mastodon "weiß", daß das CW-Feld auf Mastodon als CW-Feld erfunden wurde. (Wurde es übrigens nicht. Siehe unten.)
Hubzilla ist nicht wie Twitter. Überhaupt nicht.
Hubzilla ist wie ein Blog. Oder wie Facebook. Wie eigentlich alles außerhalb des Fediverse, das nicht Twitter oder ein Twitter-Klon ist.
Auf Hubzilla besteht ein Thread aus genau einem Post ganz oben, und alle Antworten sind Kommentare. Wie Kommentare auf Facebook. Oder wie Blogkommentare.
Und genau wie auf Facebook und in jedem Blog da draußen gibt es für Kommentare einen anderen Editor als für Posts.
Was seit 2017 das CW-Feld auf Mastodon ist, ist auf Hubzilla schon seit 2015, also schon immer, ein Zusammenfassungsfeld. Im ganzen Fediverse ist es seit 2008 ein Zusammenfassungsfeld.
Dieses Zusammenfassungsfeld gibt's natürlich nur für Posts. Für Kommentare gibt's das nicht. Auf Facebook nicht, in Blogs auch nicht und damit auch nicht auf Hubzilla. Oder hast du schon mal einen Blogkommentar mit Zusammenfassung gesehen?
Weil Mastodon standardmäßig nur 500 Zeichen erlaubt. Man kann gar nicht soviel schreiben, daß das eine Zusammenfassung braucht.
Hubzilla erlaubt über 16,7 Millionen Zeichen. Im Grunde gibt's gar kein Zeichenlimit. Das ist kein Microblogging. Das war nie Microblogging. Das war schon kein Microblogging, als Mastodon mit seinen 500 Zeichen angekommen ist. Da kann man so lange Posts schreiben, daß die wirklich mal eine Zusammenfassung brauchen.
(4/6)
#Long #LongPost #CWLong #CWLongPost #LangerPost #CWLangerPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Mastodon #Hubzilla #CW #CWs #CWMeta #ContentWarning #ContentWarnings #ContentWarningMeta
Kennst du die Filter auf Mastodon? Kennst du "Mit einer Warnung ausblenden"?
Das erzeugt aus einem Schlüsselwort sowas wie eine CW. Auf deiner Seite als Leser. Ganz individuell nur für dich und nicht für alle anderen, die den jeweiligen Post bekommen haben.
Mastodon hat das erst seit Version 4.0, seit Oktober 2022. In Mastodons Kultur ist das nie angekommen. Das kennt auf Mastodon keiner.
Hier auf Hubzilla gibt's sowas schon länger, als es Mastodon überhaupt gibt. Hier war es schon immer Teil der Kultur.
Um aber so ein Filter auslösen zu können, braucht es im Beitrag ein entsprechendes Schlüsselwort. Beispiel:
#CWLong, #CWLongPost und #CWLangerPost = "CW: langer Post ( Zeichen)".
Wer meine Beiträge mit mehr als 500 Zeichen nicht sehen will, legt sich auf Mastodon ein Filter an mit "#CWLongPost". Wer sie wie bei einer CW nur hinter einem Button verborgen haben will, schaltet auf "Mit einer Warnung ausblenden".
#CWFediMeta und #CWFediverseMeta = "CW: Fediverse-Meta" = "CW: Jupiter Rowland schreibt wieder irgendwelchen verqueren Quatsch über Hashtags und wie sie auf Mastodon niemand jemals anwendet. Nichts davon ist auch nur in der Nähe von Mastodons Standards und Mastodons Kultur."
Und so weiter.
Da steht "CW" dran, damit klar ist, daß die für CWs da sind und quasi die Funktion von CWs übernehmen.
(3/6)
#Long #LongPost #LangerPost #FediMeta #FediverseMeta #Mastodon #Hubzilla #Hashtag #Hashtags #HashtagMeta #CWHashtagMeta #CW #CWs #CWMeta #ContentWarning #ContentWarnings #ContentWarningMeta
#Long, #LongPost, #CWLong und #CWLongPost für die, die meine Beiträge mit mehr als 500 Zeichen nicht lesen wollen. Und ich schreibe ständig mehr als 500 Zeichen.
#LangerPost und #CWLangerPost nochmal als Zusatz für deutschsprachige Nutzer, damit die verstehen, was es mit #Long, #LongPost, #CWLong und #CWLongPost auf sich hat.
#FediMeta, #FediverseMeta, #CWFediMeta und #CWFediverseMeta für die, die meine Beiträge über das Fediverse nicht lesen wollen. Weil:
#Hashtag, #Hashtags, #HashtagMeta und #CWHashtagMeta für die, die meine Beiträge über Hashtags nicht lesen wollen. Weil Hashtags für mich nicht nur dazu dienen, die eigenen Beiträge leichter auffindbar zu machen, sondern auch dazu, Filter auszulösen. Etwas, was in Mastodons Kultur auch nicht vorkommt.
Ich schreibe auch noch über andere solche Sachen, die viele Mastodon-Nutzer nicht sehen wollen. Viele auf Mastodon wollen nichts sehen, was nicht auf Linie mit Mastodons Kultur ist.
Daher will ich ihnen eine Chance geben, diese Inhalte loszuwerden. Und zwar, ohne mich stummzuschalten, zu blockieren oder mir zu sagen, ich soll aufhören, so etwas zu schreiben (werde ich nämlich nicht).
(1/6)
#Mastodon #MastodonKultur #MastodonZentrizität #MastodonNormativität #Hubzilla
⁉️ #AskFedi
I want to look up specific people I followed with this #Mastodon account over the years. Since my following list has over 1,200 entries, it is undoable to open the fedi profile of each person one by one.
Is there a tool that allows me to load all these profiles into a single file or webpage, so I can quickscroll or do a search on keywords in the profile Bio texts?
I have a question about #Mastodon's "Mute Conversation" option.
Consider the following:
* I write a post.
* Alice replies to me.
* Bob replies to me.
* Chuck replies to Bob.
I click "Mute Conversation" on Chuck's reply.
Does that mute the *whole* conversation?
Does it just mute replies to Chuck's branch of the conversation?
Can I see further replies to Alice's reply?
(Poll in next post.)
@argv_minus_one I think people are realising social is not what it suggests or supposed to be (according to me or the word "social").
*Because* #Fediverse is mostly *1-way posts AND no organising* towards #friendship / #forging / #voice #talk together.
= bland / limited #Mastodon etc.
#Admin+#Tech people do 0 human work (i.e. pioneering groups
- not just taking care of Tech).
Make sense, now or in the #future, that we realise...
Oh, this is #boring / mostly #ineffective. Invest in Users.
Help GYM have its own land for the demonstration gardens and more food production as well as Establishing a large tree nursery to get trees to donate to communities.
https://gofund.me/8da0ff4a0
#community #mastodon #crowdfunding #MutualAid #MutualAidRequest #Climate #ClimateChange #ClimateCrisis #ClimateDiary #climateemergency #nature #NaturePhotography #solarpunk #Agriculture #Sustainability #photography #fediverse #linux #skills #gardening #economy #farming #USA #uk #food @thechattygardener
It seems the Halloween theme on Retro Gaiden is universally liked!
A couple of reminders:
1. On November 1st, the Halloween theme will change to a more general Autumn theme. On November 27th, the Christmas theme goes live.
2. Mastodon version 4.8 (due to launch sometime in October) will likely break some of the custom CSS. Elements may not show properly or they might be in the wrong place, etc. I'll correct this ASAP when it happens.
🦣 Herds that roam apart still come down to the same waterhole to keep watch together.
Introducing Waterhole: an open-source collaborative moderation tool built specifically for Mastodon instances that manually review and approve signups.
As Fediverse communities grow or spam waves hit, registration queues can quickly become overwhelming. Waterhole gives your moderation team a shared, real-time workspace to review applicants efficiently without compromising server autonomy or applicant privacy.
✨ Key Features:
• 📋 Shared Queues: Pending registration requests mirror directly into Waterhole. Claim requests, filter them by risk, and coordinate review status in real time.
• 💬 Team Discussion: Leave internal notes and discuss applicants collaboratively before deciding.
• 🔍 Proactive Signals: Automated checks highlight known throwaway email providers, datacenter IPs, Tor exits, templated join reasons, and burst signup patterns.
• 🛡️ Collective Defense: Opt-in cross-instance alerts notify you when the same spammer or bot pattern is prowling around multiple herds. Sharing only behavioral tracks and signals, never private applicant details.
• 🔒 Full Server Autonomy: Approvals and rejections are dispatched directly back to your instance via your Mastodon Admin API. No automated bans or AI decisions. You always keep complete control over who joins your community.
Waterhole is 100% free software under AGPLv3.
🔗 Connect your Mastodon instance to our Waterhole:
https://waterhole.toot.io/about
💻 Explore the source code, documentation, contribute, or self-host:
https://github.com/tootio/waterhole
#Mastodon #Fediverse #FediverseAdmin #MastoAdmin #OpenSource #SelfHosted #Privacy
Sorry, only minimally sorry XD
P.S., Yes #snac is good too. Very excited about #LittleFedi as well. Not so much into *key, *oma, or friendica, but not hating. Just not my thing. Cheers.
@evan Yeah but I have no money.
I don't really have big ambitions in life so I wanna build my own cabin and farm in the woods, live off the grid and ditch civilization cos I don't think anybody wants me around and that makes me feel like shit, so idk.
I'll never get mansion, a sports car, a big lawn, booming business, fame, whatever normal people want. Sounds boring.
I really wanna truly live alone, with my own dumb telly to watch cartoons and movies, a radio when I wanna listen to whatevs on the air. I also won't rely on the grid for power so big solar panels with big battery would be good.
What if open protocols operate just like natural ecosystems?
In this article from Silphium Design, we explore how decentralized networks mirror ecological resilience. When nodes federate via ActivityPub, diversity prevents single-point collapse and keeps digital communities sustainable.
Curious how digital ecology maps directly to the Fediverse? Check out the latest:
https://silphiumdesign.com/digital-ecology-in-the-fediverse-decentralized/
#Fediverse #Mastodon #ActivityPub #Decentralization #WebDev #OpenSource
This post originally appeared on The Fulcrum.
Welcome to this week’s The Programmer’s Fulcrum.
It’s your weekly curation of the essential news in the Open Media Network and Open Social development communities with a focus on devastating big tech via Techno Anarchism.
As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional benefit of weakening authoritarianism.
IMHO, the best way to do that is to use tools from the Techno Anarchist Manifesto to build your own site(s) to participate in the Open Media Network. Then you should share it (them) via Real Simple Syndication (RSS), Open Social, and possibly a newsletter or podcast. This approach is similar to what some call the IndieWeb and its POSSE philosophy.
The second best strategy is to have accounts on open social and use the hell out of them. And do the same with a RSS feed reader.
We publish TPF on Fridays so you can enjoy it over your weekend.
There’s good stuff in all of our categories, so please take the time to enjoy and bookmark the items most relevant to your goals. We hope you are inspired to create new ones.
Or you can scroll down to your favorite section.
FYI, my opinions will be in bold. And may involve cursing. Because humans. Especially tech bros. And fascists. Fuck´em.
Two notes for this week:
1. I’m attending WordCamp Bretagne this week so coverage of some of Friday’s happenings will slip to next week.
2. We switched and customized our theme to make our home page a little more accessible.
Smashing Frames writes:
Omarchy should not matter. But sadly it does. As a power grab.
(It) is part of the new fascism. But it’s also a good case study about how little political resilience is built into FLOSS. The libertarian roots have not only made the whole movement ready for the taking by corporations but also by fascists.
And sadly many influential organizations in that space are not up to the task of putting their foot down.
They also write:
There has been this shift towards equating “progress” with “technological innovation and development”: society is moving forward if tech produces more shit. You might have picked up on me mentioning that today’s vision of the future is just a thinner iPad every few months.
But if “progress” – which is a political term about values that one aims to manifest or express or expand in the world – is just replaced with following PR messages about whatever tech wants to sell next, that does not only make the space of possible futures paperthin, it also puts massive amounts of power into tech’s hands.
And I don’t just mean economic and political power (which is also true and needs to change massively, rapidly and aggressively). In this context I mean narrative power.
Patrick Brosset says:
This is why the Servo project is so important.
404 Media reports:
‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft
There’s a 100% Chance AI Agents Are Already Ruining the Internet
Meanwhile Tech Policy Press reports:
Millions of Volunteers Are Keeping the Internet Human. For Now.
The first thing the author needs to do is get the fuck off Reddit.
Terence Eden shows us:
How to get a DOI for your blog posts
For you researchers out there.
Candost opines:
Magazines are superior products to newsletters
They are certainly more enjoyable.
Alex Hoyau has an update on:
My work on Silex Desktop to make it forge-agnostic
I will be attending Alex’s presentation at Le Capitole du Libre. It about de-clusterfuckifying WordPress by using Silex as a decoupled frontend.
TechCrunch reports:
Sources say Automattic’s board is out after failed attempt to oust CEO Matt Mullenweg
On a more joyous note, WordCamp Bretagne shares:
Découvrez Gwen, le Wapuu officiel du WordCamp Bretagne 2026
Yes, WordPress is a clusterfuck. But at least it’s cute.
On a non-cute note, Internet Exchange explains:
What It Means to Lose Autistici/Inventati and NoBlogs
Bastian Greshake Tzovaras has a great book review:
On building Digital Solidarity
The day it’s available in English or French, I’m buying.
About Signal reports:
Signal registration without a phone number now available in Android beta
Servo has:
Servo had a busy end of August and start to September
Your Donations at Work: One Year of Sponsored Servo Development
Waterfox announces:
6.7.3 — Auto-hide vertical tabs and appearance fixes
Where Waterfox stands on AI and LLMs
I think most “anti-AI” positions are really anti-GenAI slop positions. As the author notes machine learning etc. has been around for decades. Still, modern “AI” is intentionally labor weakening fascist techshit based on theft and created by and for techbros. But perfection is not possible and this shit is unavoidable, so keep it as local and open source as possible and minimize your use of LLMs. Avoid LLM-built tools as best you can. The environment is already fucked.
LibreOffice has:
LibreOffice 26.8 and the languages for which nobody is paid
New “LibreOffice Expert 2026/2027” magazines available for schools and local communities
If you want a personal copy, you can buy one from the publisher.
LibreOffice 26.8 and interoperability: preserving what cannot yet be read
Nextcloud announces:
Collabora: Landlock adds a third, tougher sandbox tier
Nextcloud Hub 26 Summer: Autonomy for Teams, Office on desktop, a fresh take on Photos
There are some good Markdown improvements in Nextcloud Text.
Cryptpad reveals its:
They are doing good work in the government tech sphere.
Scribus has:
Added a Scribus 1.6.x quick tour on the main menu
Joplin announces:
Your notes and AI: privacy first
If you have to use AI (and you shouldn’t) this is the way to do it. At least you can use an open model and keep it local with only your data and the individual tools you select.
The Counterforce shows us:
Punk A.I. Artists are on the Rise: How to Suffocate the Slop in Your Scene
9to5Linux reports:
Shotwell 0.33 Open-Source Image Viewer for GNOME Is Here with GTK4 Port
9to5Linux reports:
Linux Mint Devs Introduce New EPUB Reader and Calendar Apps
Jolla announces:
Change on Jolla Phone memory configurations going forward
LINux on Mobile explores:
MCF20: Flatpak support, sorta, kinda
It’s important for Linux Phones to become a thing. More so than with desktops.
F-Droid has its weekly update:
Gina Plat notes:
European governments are starting to support alternative mobile app stores
Digital sovereignty is good. Digital solidarity and Techno Anarchism are better.
The Association for Progressive Communications reports:
OmniTools’ PDF Tools
Boost your productivity with OmniTools, the ultimate toolkit for getting things done quickly!
NLnet Labs explores:
Maintaining the love for coding in the time of AI
If your proposed contribution to an opensource project was mainly developed with AI, you may think you’re a developer. But, you’re not. You’re a cunt.
David O’Brien says:
Users of assistive technologies need to know the names of interactive elements on the web
The Open Media Network explains how:
The deathcult is selling the future as techshit
Andy Bell has a rake on the CSS situation:
You’ll miss publishers when they’re gone
Gina Plat also notes:
Sweden is choosing Forgejo for their digitally sovereign government code platform
Random Thoughts on Leadership and Technology shares:
Fractal Interests examines:
Always Twisted has:
… And That’s My Rank! 2027 Edition
Master.dev says:
It’s All About The Permissions Recovery
Vale notes:
It was doomed the day Digital Ocean acquired it. And it’s been dying a slow death since.
In effect the Master.dev blog has taken the CSS-Tricks role.
The Jacobin asks:
Is There a Way Out of AI Doomerism?
Taggart Tech says:
Everone Is Lying To You For Money
And Connected Places says:
AI watermarking has a decentralisation problem
OpenProject is:
Training the next generation of IT specialists: Using OpenProject at the Gutjahr Vocational School
XWiki announces:
XWiki 18.8.0RC1 has been release!
XWiki innovates with “Structured Wiki” and delivers high knowledge features.
XWiki is a little much for us. But, I did manage to get DocuWiki added to our Manade project this week. 😉
Terence Eden shows us:
How to send an updated user profile to Mastodon and the Fediverse
IFTAS shares a fix for:
The GoActivityPub Library is working on:
The vocabulary/lexicon generation
Vlac Log shares:
A couple quick notes on ActivityPub
Fedify
Fedify is a Typescript framework that lets you build for the Fediverse but skip the boilerplate.
This is a perpetual pet peeve because many people aren’t able to comprehend ⬇️:
So, recognize their natures and don’t ask the two protocols to go against them. This is also why we have accounts on both platforms and use them differently.
Roel Roscam Abbing has:
Nobody’s fault, everyone’s problem?
If you run a public instance, you have a responsibility to your users and the wider Fediverse. Provide robust moderation. At least against spam.
Fedilab Apps shares the:
Experience of building FediHood
Magic Pages explains:
Why your Ghost site’s old posts don’t show up on Mastodon
Also, your main Fediverse account should not be Ghost-based as their implementation is mediocre at best. Self-hosted or Go To Social are better bets. Maybe even a Mastodon account. 😱
PeerTube announces:
Framablog has:
reseauCulture.fr : le monde de la culture s’organise sur le fediverse
ATProto France shows us:
Comment utiliser une app Atproto en sécurité
Building [at] Habitat shares:
Habitat’s road to release: 06 commenting
Graham Marlow looks at:
Decentralized identity and ATProto
Discord alternative, Roomy announces:
Skyreader has:
Skyreader update – Reading Rooms
Jacky Alciné shares:
Great stuff.
Two Waves and a Dot opines:
RSS has a business problem, not a technical one
XMPP shares its:
The XMPP Newsletter August 2026
AdullAct reports:
Local governments are regaining control over their digital communications with Matrix (image pdf)
I began reading the book, Decidm, a Techno Political Network for Participatory Democracy: Philosophy, Practice, and Autonomy of a Collective Platform in the Age of Digital Intelligence, this week.
Decidm is a quasi implementation of both the Open Media Network and Techno Anarchism but from a more formal governing practice. It is a democratic tool for participatory democracies like a city, NGO, or a collective.
You can learn more about Decidm here.
And please build something for a community! We’re painfully nurturing Manade.
Based on @Curia's infamous #Coyote ruling, the courts continue to chip away at the #DSA's conditional intermediary liability exemption.
This latest judgement from the #Frankfurt court in #Germany has a particularity though: AFAIK it's the first court ruling that explicitly mentions #Mastodon & #Bluesky to explain how platforms with non-algorithmic / chronological feeds are better shielded against liability.
https://ordentliche-gerichtsbarkeit.hessen.de/presse/fake-werbung
Is there a desktop Mac / web app for #Mastodon that lets you shunt all reposts/boosts into a different stream? I’d like to read updates just from people I follow and then skim through the reposts later. Like catching up and then reaching out.
Muting reposts from über-boosters feels like a nose/face cutting situation and I’d like the opportunity to dip in occasionally.
@smallcircles@social.coop but I agree that some do get confused by assuming that #Mastodon (a software), #Fediverse (an ecosystem), #ActivityPub (a protocol) are synonyms and some pedagogy is needed, especially to journalists who write about this. And especially if they are making comparison with other things that are not comparable (e.g. #Bluesky)
@smallcircles I'm mainly using #Mastodon in the browser. It works pretty well for me.
If I would have any suggestions, feature requests, or bug encounters, and they are important enough for me, I would report them in an issue tracker of the specific product. Hoping that the project would refer to the protocol or other meta level if that would be a better place to communicate.
#Build the Social #Mindset = fix people's #Logic.
Fixing the #Mindset = Fixing the #World.
Be Social, add caring 2-ways mindsets.
#Tech is not enough alone.
It needs to be more socially social (#develop people, not just #dev tech).
E.G. #Mastodon is software but they are not directly using it's people to #pioneer the #social side itself (on top of the cold #software).
People don't know how to socialise online, so need help.
Making #friends / #friendship = Improving #Mind #Trust
@christin for those sensible people that use Caddy, here's the config snippet for that:
```
@apiacct {
path /api/v1/accounts
not method GET
}
handle @apiacct {
respond "Go stick your head in a pig" 403
}
```
Morgen vertel ik op het festival voor de journalistiek in Deventer over open sociale media en de NRC-server. Voor wie in de buurt is...? https://www.nljf.nl #mastodon #ATProto #NRC
Anyone have any recommendations for a mastodon (or activitypub) server that allows longer posts, say 3k or longer? Also looking for posting tech based content.
Come abbiamo fatto a ridurre drasticamente le richieste di registrazione degli spambot AI: una guida per amministratori di istanze Mastodon
https://gatti.ninja/posts/mitigazione-account-spam-su-mastodon/
I think the "official EU" should have multiple instances; after all, it's the Fediverse. That, in itself, would make for a far more resilient and robust solution.
And yes, "official Canada" should (obviously) also have something similar.
As for people being on X, and elsewhere, the light doesn't shine equally on people of the planet 😎
If only following #hashtags didn't override your #Mastodon language filters 😞
I've had to mute thousands of accounts posting in languages I don't understand to tame my timeline without giving up following the hashtags I want, & I still have to mute a dozen or more every day.
Every now & then I'm tempted to just unfollow certain tags ( #Fediverse above all), losing out on that content just so as not to have to deal with all the posts I don't understand.
🍵
boostedGratitude day 4: Vim
#SeptemberTheme #gratitude #blog #fediverse #mastodon #editors #terminals #vim
https://lazybea.rs/gd4-vim
Posting to Mastodon without hashtags is posting into a void. No algorithmic feed is coming to rescue the post. Two to four tags, every time. We learned that one slowly. #mastodon #fediverse #socialmedia
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet.
On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave.
Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything.
The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth.
So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client.
If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include:
location = /api/v1/accounts {
limit_except GET {
deny all;
} try_files $uri @proxy;
}
This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes.
#Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
Attention #fediverse / #mastodon
We're entering #election season in the #USA. The #midterms
That means something for you:
You will see an increase in #trolls
Messages along the lines of
"Nothing ever changes, both sides the same, waah" #cynicism
And
"The candidate is unideal. Allow me to amplify and manufacture high holy outrage on the point" #perfectionism
All of which is designed to suppress the #left #vote and help #MAGA
You have been warned. Brace yourself
Guide d’utilisation et tutoriel non-officiel de Mastodon en français:
➡️ https://www.didiermary.fr/sommaire-du-guide-mastodon
(C'est par @cybeardjm )
The FediBlue Mastodon instance has been updated to Mastodon 4.7.2 which is a security update that temporarily disables HEIF support
#Mastodon v4.7.2 upgrade pending on TurtleIsland.social
#Native #Indigenous #BIPOC #Allies #TurtleIsland
https://github.com/mastodon/mastodon/releases/tag/v4.7.2
Dear #Fediverse and #Mastodon admins
currently there is a massive wave of spam registrations everywhere in the fediverse.
For mastodon, I have a solution that works for me:
Create new file /etc/nginx/conf.d/lsbt-registration-spam.conf:
map "$request_method:$uri:$http_user_agent" $block_lsbt_registration_spam {
default 0;
~^POST:/api/v1/accounts:Python/3\.[0-9]+\ aiohttp/ 1;
}
Add to the server block in /etc/nginx/sites-available/mastodon:
location = /api/v1/accounts {
if ($block_lsbt_registration_spam) {
return 403;
} try_files $uri @proxy;
}
@michaela @njakob @MikeGorden
#fediverse #mastodon #registrationspam #spam #registration #Automatedprotocoldeliverabilityprobe #lsbt
I’ve reached out to Baroness Benjamin to explain how her Bill that would require anyone running a social media platforms obtains a license from Ofcom, would impact someone running aMastodon instances in the UK https://bills.parliament.uk/publications/67647/documents/8738 . Will keep you posted if she replies. #Ofcom #mastodon #socialmedia #regulation
🍵
boostedGratitude day 2 - GAS
Have you ever bought something you did regret ?
#SeptemberTheme #gratitude #blog #fediverse #mastodon
https://lazybea.rs/gd1-gas
Cc: @rl_dane @gregmignard
🍵
boostedGratitude day 1 - Water
#SeptemberTheme #gratitude #blog #fediverse #mastodon
https://lazybea.rs/gd1-water
Cc: @rl_dane
I do think media files decay and vanish on mastodon as time passes... I'm not even mad about it. Makes the whole self-hosted community-owned model make a lot more financial sense to me.
Like most social networks, Mastodon is not end-to-end encrypted. If you're sending sensitive info it's better to use a separate end-to-end encrypted messaging app.
Mastodon itself warns you about this if you are sending a DM through the web interface (see the screenshot).
More info about the risks and how to mitigate them in the guide at:
➡️ https://fedi.tips/is-mastodon-end-to-end-encrypted
TL:DR - Main risk is your server admin reading your DMs, but they would need techy skills to do this.
#Mastodon #Fediverse newbie advice:
Before you start following people, I strongly recommend:
Create an avatar and/or banner image.
Write a short bio.
Write some posts. Pin a couple of them.
Also, post with some tags, particularly the #Introduction tag (probably with one of those posts you pin).
This way, when people check who you are (if you follow them or they consider following you), they can see a hint of who you are (and that you are a "who" rather than a "what").
RE: https://mastodon.pnpde.social/@spielleitung/117242341921660658
This is the first use of database triggers I've seen for modifying #Mastodon behavior. It's a very clever idea!
The Linux mainline kernel itself contains AI code now. It's officially allowed as long as it's disclosed as such. Thus, you will have to avoid literally all servers running on Linux.
https://docs.kernel.org/process/coding-assistants.html
NetBSD has very strict rules regarding AI-generated code. But it doesn't rule AI-generated code out out of principle because it's AI-generated; it only wants to be safe that nothing that's actually GPL-licensed is slipped in. So, if you're an 100%, ultra-hardcode anti-AI extremist, avoid what few servers run on NetBSD.
https://www.netbsd.org/developers/commit-guidelines.html
OpenBSD contains AI-generated code, too. And it has no official stance regarding it. So servers running on OpenBSD are taboo, too.
https://www.osnews.com/story/144935/openbsd-and-slopcode-raindrop-to-a-torrent/
FreeBSD has no stance on AI whatsoever that I could find. However, apparently, the FreeBSD community loves to integrate Claude Code into their systems for automation purposes:
https://aumont.fr/posts/claude-code-freebsd/
https://discoverbsd.com/p/8a7660c31b
But you'll also have to look at the userland, the Web server, the database driver etc.
MariaDB allows AI code. You can safely assume that all MySQL databases on Web servers out there are actually powered by MariaDB.
https://mariadb.org/governance/governance-ai-policy/
Oracle MySQL can integrate AI, so it's safe to assume it contains AI-generated code.
https://blogs.oracle.com/mysql/announcing-mysql-ai
PostgreSQL probably allows AI code, too. There are even tools for it.
https://github.com/timescale/pg-aiguide
SQLite is very popular amongst AI users while not having any rules on AI-generated code. Assume it to be tainted.
This leaves you with only one choice: Self-hosting a personal, single-user snac2 server because snac2 doesn't need any database whatsoever. In fact, snac2 is staunchly against AI. And it runs on NetBSD.
https://codeberg.org/grunfink/snac2
But then there's the Web server. Apache may allow AI-generated code if it has been reviewed and made sure that it does not contain anything that's incompatible with the Apache-2.0 license.
https://www.apache.org/legal/generative-tooling.html
nginx welcomes AI and advertises itself as ready for AI, and it takes no anti-AI-code stance. It's most likely already tainted.
https://www.f5.com/de_de/products/nginx.
This basically leaves you with no Web server guaranteed to be 100% free from AI-generated code to run snac2 on. But that doesn't matter because it's impossible to build a Web server devoid of any AI code to install snac2 on.
By the way: Mastodon itself explicitly allows AI code if it's disclosed as such, and if its contributor understands it.
https://github.com/mastodon/.github/blob/main/AI_POLICY.md
In other words, next to all Mastodon servers are running
Apparently there is a quite successful credential stuffing campaign targeting Mastodon. Not 10 minutes ago, I suspended an account taken over by someone in Estonia who started posting racist garbage and Telegram links.
Infosec.exchange has seen 5 of these today.
They all seem to be coming in from Telegram users.
** Will you all, PLEASE, enable 2FA on your accounts to prevent your accounts from being taken over! **
Downgraded #Fedra and I never have that constantly interacting with unintended posts problem. It's already documented via the Github, I just couldn't stomach the bug. https://github.com/trypsynth/fedra/releases #Mastodon #Fediverse
The FediBlue Mastodon instance has been updated to Mastodon 4.7.1
You're searching for a new Mastodon server and are a FOSS interested and friendly person? Then look behind this awesome link: https://mastodon.fediblue.de
#Mastodon voice messages?
"Make social vocal" ?
Voice #filters added for #privacy?
(like #TikTok funny voice masks but more human sounding?)
= voice messages + #masks / filters ?
(a risk but much more #progressive #P2P)
Protection with a voice 'mask'.
What do you think ?
(Text is limited = can't cover the human expression range like voice and for some text isn't possible / too hard).
Also #Jitsi (https://meet.osna.social/) + integrated voice #masks?
Israeli censorship seems to have taken control of Mastodon, too.
You are free to hashtag "nazi", "zionist", "fascist" and so on, but the hashtag "zionazi" is forbidden.
#zio*nazi #israel #masssurveillance #palantir #AIPAC #Elnet #ADF #netanyahu #masspsychosis #politics #freespeech #mastodon
Welcome to this week’s The Programmer’s Fulcrum.
It’s your weekly curation of the essential news in the Open Media Network and Open Social development communities with a focus on devastating big tech via Techno Anarchism.
This post originally appeared on The Fulcrum.
As usual, we aim to provide actionable content you can use to destroy Techno Feudalism each week. It has the additional benefit of weakening authoritarianism.
IMHO, the best way to do that is to use tools from the Techno Anarchist Manifesto to build your own site(s) to participate in the Open Media Network. Then you should share it (them) via Real Simple Syndication (RSS), Open Social, and possibly a newsletter or podcast. This approach is similar to what some call the IndieWeb and its POSSE philosophy.
The second best strategy is to have accounts on open social and use the hell out of them. And do the same with a RSS feed reader.
We publish TPF on Fridays so you can enjoy it over your weekend.
There’s good stuff in all of our categories, so please take the time to enjoy and bookmark the items most relevant to your goals. We hope you are inspired to create new ones.
Or you can scroll down to your favorite section.
FYI, my opinions will be in bold. And may involve cursing. Because humans. Especially tech bros. And fascists. Fuck´em.
Iris Meredith writes:
So, when I hear a tech person say that something’s “just a tool”, I can’t help but read it as an unwillingness to take responsibility, as an industry, for what we put into the world and for what we do to ourselves. Tools, unfortunately, simply cannot be the neutral, separate thing that so much of the tech world would like them to be, and pretending otherwise, let alone telling people affected by the tools that they’re simply using them wrong, is an abdication of our moral duty to avoid, inasmuch as is possible, doing harm. We really ought to do better.
There’s no such thing as Just a Tool
There is such a thing as TechBros, unfortunately. And their cuntier cousins, AIBros. And apolitical is a synonym for fascism-friendly. At least straight-up Nazis aren’t hypocrites.
Social Coding Commons writes:
… in modern society, generally speaking, we give too much credence to the technosphere. We take the idea that innovation equates to societal progress as a given, to which we must subsequently adapt ourselves. We tend to turn things around, where “digital transformation” suddenly means how humans must adapt their lives to new technology that comes to disrupt it. And not the other way round.
The Fediverse has evolved purely as a technosphere (unfortunately).
Paradigm shift to the Prosocial web
A fan-fucking-tastic piece.
On a relate note, Hamish Campbell has thoughts on Open Governance Bodies / Building:
Power stays with the people doing the work
This is a good explanation of how digital communities and projects can govern themselves.
And we published an article this week, where I write:
The premise of this article is that developing or using ActivityPub tools, participating in the Fediverse, publishing to the Indie Web / Open Media Network, and adopting the arsenal of the Techno Anarchist Manifesto are the new punk.
ActivityPub, the Fediverse, the IndieWeb/Open Media Network, and Techno Anarchism = Punk Rock
Jan Miksovsky explores
Origami Projector: a Glitch-like app for site editing
A great idea. Although only available on newer Macs unfortunately.
I also ran across AnyPub, an editor for Standard.Site publications.
CSS Tricks explores the:
WordPress PHP-Only Block Registration
Good news for those migrating legacy sites. And avoiding the shit known as React, at least some of the time.
Why Do I Write This? writes:
Neocities is for nostalgic masochists
Seems about right.
Scraps! expounds:
Mark W.Rites says:
Alt Text is the Ocean You Thought Was a Pond
Faircamp announces:
And Vidnight has:
I disagree with the take that the internet is dead
Enjoy the open web peeps. It helps keep me sane. And I am happy to see this from a 20 year old. 🙂
Spectral Web Services has:
I accidentally built an image library for Ghost
This should be in Ghost core. It sucks that it isn’t.
Their competitor, Magic Pages has:
Good stuff.
Tuta has:
Digital Sovereignty Study: EU IT leaders are quitting U.S. Big Tech
U.S. Sanctions against Autistici / Inventati are the next wake-up call for digital sovereignty
KDE examines:
NLNet urges:
Apply for funding before November 3rd 2026
They are going the correct direction with AI use, which is to severely restrict it.
Organic Maps has:
Threat Model shows us:
Mullvad is:
Shutting down our public encrypted DNS servers and sponsoring Quad9 instead
FluffyChat shows us:
How to use end-to-end encryption in FluffyChat
About Signal reports:
Signal introduces new notification settings for Android and Desktop
Servo shares:
July in Servo: more platforms, faster canvas, web fonts in SVG, and more!
9to5Linux reports:
Mozilla Firefox 155 Is Now Available for Download, Here’s What’s New
Remember to use Firefox forks like Zen, Waterfox, or Librewolf.
Webkit has:
Submit your ideas for Interop 2027
Fixing Top-Level Await in Safari
Remember not to use Safari for anything you want kept private. And preferably not at all.
Nextcloud shows us:
Fuck Google!
Joplin shares:
The new table editor in the Markdown editor is awesome. The addition of AI features sucks. At least they are optional you can use a local model.
LibreOffice announces:
Bon. AI should almost never be used, but if it is (translation), it should be as an optional extension.
Kdenlive announces:
9to5Linux reports:
OpenShot 4.0 Open-Source Video Editor Officially Released, Here’s What’s New
Audacity 4.0 Open-Source Audio Editor Officially Released, Here’s What’s New
And:
Debian Project Formalizes Responsible Use of Generative AI
Like Linux core, Debian chooses to slowly ensloppify and likely enshittify.
F-Droid has its weekly summary:
Searching complexity and Taler update
Dokieli
Write, publish, and annotate articles from your web browser. Your content stays yours.
Typemill expounds:
On the way to automate user manuals and knowledge bases
This is a legitimate use of local AI. It’s the second most legit use after translation.
The Linux Foundation has a useful course for KISS developers (rare for them):
Share Smarter GPU Resources and Master Git
from First Commit to Merge Conflict
Their learning platform subscription is not cheap, but this might be worth a one month one while you finish the course.
Vasilis van Gemert explores:
What are we not talking about anymore?
Master.dev examines:
New Things You Should Know About HTML Here in Mid 2026
Great stuff.
Vale says:
As in unnecessary.
Ollie Williams explores:
Highlighting a range of text inside an input or textarea
A rarely needed though legitimate use of JavaScript.
So AI is now fucking over tech conferences as well:
Lettre ouverte pour la survie des événements techniques en France
And freelancers:
Freelancers are getting buried with ‘soulless’ AI slop cleanup: ‘It’s a shame we need to do it’
One of the main purposes of AI is to drive down the cost of labor (it’s a fascist artifact). And these are the consequences when you use it.
OakChris1955 looks at:
Migrating from Cloudflare Pages to Codeberg Pages wasn’t that difficult, actually
I have used Codeberg to deploy a test Publii site. And it worked great. But, you were limited to one site at that point.
Write for your website and documentation. And not for AI.
ActivityPub for WordPress shares:
9.3.0 — Modern Signatures and a Summer of Security Reports
This is a perfect example of what an update announcement should be. 😉
Social Coding Commons opines:
I argue that ForgeFed and ActivityPub should support multi-types as specified in Activity Streams
They are correct and this provides an insight into why AP development is so slow and convoluted. And to why there is much less innovation in the Fediverse as compared to the Atmosphere with ATProto. ActivityPub is just more anarchic.
Not that its a bad thing, as I point out in my featured article. Plus, it’s definitely more enshittification-resistant.
Plus, core ATProto has much more money and developers behind it than ActivityPub does.
Terence Eden has:
A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP
ActivityBot is the recipient of an NLnet grant!
In effect he’s creating something similar to Starling for bots. And it’s for use as a developer learning tool.
A review of the ActivityPub book.
Andros Fenollosa explores:
Building a decentralized bulletin board (and accidentally reinventing Nostr)
Abuuba announces:
Interesting.
Mobilizon needs you:
ForgeFed
ForgeFed is a federation protocol for software forges and code collaboration tools for the software development lifecycle and ecosystem.
This is a perpetual pet peeve because many people aren’t able to comprehend ⬇️:
So, recognize their natures and don’t ask the two protocols to go against them. This is also why we have accounts on both platforms and use them differently.
TootSDK announces:
A new release of TootSDK – 23.3.0
Owncast announces:
Owncast v0.3.0 has been released!
Fedilab Apps has:
FediHood now lets you sign up and log in with your Mastodon account
This definitely makes it more useful.
Mastodon announces:
We just released Mastodon v4.7.1, v4.6.7, v4.5.17 and v4.4.24
And the Real Grunfink announces:
I’ve just published version 2.95 of Snac
Bonfire has:
Bonfire 1.0.7: what’s new and what’s next
Great stuff.
Building shared infrastructure for the Fediverse
Very important because -> see my comments about the Social Coding Commons piece above.
Andros Fenollosa notes:
There is no such thing as full decentralization
A great overview and explanation.
Open Risk Management goes down an empirical rabbit hole:
Towards a Graph Calculus for Decentralized Social Networks
マリウス shares:
Hyperuplink: Discuss like it’s 1998
Cool.
Venoom examines:
Decentralizing social media using ATProto and Matrix (venoom)
Eventuallycoding has:
Le piège de la transparence par défaut sur Bluesky et le protocole ATProto
Skyreader shares the:
Structural Integrity explains:
W Social is a textbook case for everything wrong with digital sovereignty
Roomy looks at:
Worm-Blossum shares its:
Ross Floate has:
I built a new website. It’s happiest when you leave.
Very cool. I am going to try to replicate this on one of my sites.
The Association for Progressive Communications has an interview:
Libervia on building an all-in-one communication platform grounded in the right to privacy
Daniel Gultsch celebrates:
Jabber/XMPP: 25 Years of Digital Independence
Matrix has:
Neo Nominated for Open Source Competition
This Week in Matrix 2026-09-04
And please build something for a community! We’re painfully nurturing Manade.
One reason I post on #Mastodon but no longer on Twitter/X or their spin-off Bluesky. My complaint a year ago was marked spam, but it is a true testimony!
I just noticed that, if I look up a #Lemmy or #Piefed community on #Mastodon, I'll get a profile page but no posts!
Is that a bug in Mastodon? Or is there no standard #ActivityPub protocol for fetching content from a person/group that you aren't already following?
I seem to recall Mastodon adding a “fetch content from the other server” feature recently, but it sounded like a Mastodon-specific protocol extension was involved. That's…not great. It really should be universal.
🆕 blog! “A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP”
If you're reading this, you've probably been hitting your head against a brick wall trying to parse and decipher the new HTTP Signatures sent by Mastodon and other Fediverse servers.
This is a…
👀 Read more: https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/
⸻
#ActivityBot #ActivityPub #mastodon #php #webdev
More than 60k followers on #Mastodon 🎉💪
What a great community ❤️
Connected to our latest post on how to turn off Gemini?!
Can someone that's familiar with the details of FEP-044f (the one underlying Mastodon's quote posts) tell me if there's something I missed and there *IS* a way to ensure that malicious instances (or clients) aren't able to disregard the whole thing and just allow and present quoted posts without their original user's consent?
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
Hey, #Mastodon and #ActivityPub developers.
How much skew do you allow before rejecting a message?
I've just received something where the header is signed:
Mon, 31 Aug 2026 20:09:54 GMT
But the ActivityPub message was published:
Mon, 31 Aug 2026 19:58:36 GMT
That's a little over 10 minutes. Is that too much? Should I not care as long as the signature validates?
I am seeing reports of a small number of #GazaVerified accounts hounding people who have donated in the past with posts at the rate of “one every few minutes”.
This has to stop.
If you’re doing this, your servers will suspend your accounts and we will not step in to help nor will we reverify a new account.
This is harming everyone on #GazaVerified and the reputation of Palestinians in general and we won’t be tolerating it.
And the people who sympathise with the cause and have donated in the past do not deserve to be harassed in this way.
Please stop.
sometimes later, i'm going to continue work on the #mastodon command line agent I've been working on for a while.
I need to work on it , and I plan on fixing a few bugs, and woof woof, meow meow.
the reason I haven't worked on n it is because I have other projects to work on at the same time
#FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Mastodon #ActivityPub
setup a new #opentelemetry collector in my #mastodon namespace, successfully shipping traces from the various components into #grafanaLoki as well as configuring traces from #agentgateway to Loki :)
Mankind (mostly) or machines (mostly) ?
Can you imagine a better #society with less-tech / less machines than today ?
(still having with plenty of tech & machines but not only the primary focus if we agree most in life are doing similar tech related things).
Becoming less-tech & having #people make friends using basic #tech? (only #Jitsi & 2+ people needed).
Seems simple. Make friends with ALL sectors with good people in them. Not just tech.
#mastodon #nginx logs -> json-formatted, bespoke logging operator flow to parse the json, properly ingested into #grafanaloki 💪 way to end the weekend :) still need to figure out alerts.
I don't have to worry about a corp waking up one day and deciding that something I posted deserves to get my account deleted.
Love machines.
Not growing people?
Pioneering people / social needs #Mastodon to have staff / people to back it and get people to really talk to each other (both light and DEEPER/RARE stuff).
Fund it if they have to as a better exchange (not machine development time, but social / #SOCIETY).
Thanks for hearing me out and even "let's do it" if you're interested in doing something / anything about it.
@renardboy For example #Mastodon = 100% great #software
but
Bringing people more socially up themselves = near-0
Mastodon as ' a bit better crowd than twitter who moved from there') is limited.
It's about #Pioneering people / principles UP!
Even forums (#phpBB) or #ICQ #AIM ~20 years again did better if people were driving / motivating it.
Maybe #Tech and #Money (#banks) go together well so people settled for diving banks pockets and power deeper and deeper.
It looks like the migration to this new instance was [mostly] successful. However it does appear I lost some followers and followees.
Note to fediverse app and ActivityPub maintainers: we really need one and only one schema and format, based on flat text lines or .csv, for importing, exporting, migrating profiles, posts, follow(ing) lists, etc. Too many cooks spoils the stew.
If you clean a vacuum cleaner, you are a vacuum cleaner.
If you push a lawnmower, you are a lawnmower.
If you #boost this toot, you are the algorithm.
RE: https://rpi0w.stefanomarinelli.it/@stefano/01a0448d-c9e8-7b7e-a225-b22fc0333f0f
Mastodon is great. But littleFedi, snac, GoToSocial, Mitra, Akkoma, etc. - they all share a mission: make sure people will be able to self host their instances without investing a huge sum.
#Fediverse #Mastodon #littleFedi #snac #GoToSocial #Mitra #Akkoma
Mastodon has an optional translation system to translate posts in languages that you don't speak. To use it, just click on "Translate" below a post (on some apps the translate option may be in the post's ⋯ menu).
I've tried to answer common questions about Mastodon's translation feature in this guide:
➡️ https://fedi.tips/is-there-a-built-in-language-translation-system-on-mastodon
Let me know in the replies if I've missed your question.
The #EU is putting some money where their mouth is.
€1.48 million for pilot projects involving young people from different countries and backgrounds to development new European #SocialMedia platforms, focusing on user safety, mental health, privacy and ease of use. Building on #Fediverse or #ATProtocol
Deadline: 6 October.
wew a lot more traffic after getting the #activitypub #relay online and doing #mastodon relay housekeeping :P
RE: https://dobbs.town/@bobcromwell/117164438687055192
this shagmaxxing content right here is why i’ve parked my ass at #mastodon and the #fediverse
Little Fedi looks like an interesting project! I also saw a toot earlier where it was showing a settings screen where someone disabled media without a description. https://littlefedi.org/ #AltText #Fediverse #ActivityPub #Mastodon
🆕 blog! “Some updates to ActivityBot”
I couple of years ago, I developed ActivityBot - the simplest way to build Mastodon Bots. It is a single PHP file which can run an entire ActivityPub server and it is less than 80KB.
It works! You can follow @openbenches to see the latest entries on OpenBenches.org, and @colours for a …
👀 Read more: https://shkspr.mobi/blog/2026/03/some-updates-to-activitybot/
⸻
#ActivityBot #ActivityPub #mastodon #php
I'm going to try and keep a record of all the bugs, errors, and inconsistencies I've reported in #ActivityPub and #Mastodon documentation.
First up, how big are the limits on what you can federate?
Mastodon lists some limits in KB/MB, but others are just raw numbers. That might make sense for an ASCII world - but emoji complicate everything.
Hmm, I can't post a magnet-link here, even though the #ActivityPub supports that protocol: https://docs.joinmastodon.org/spec/activitypub/#sanitization
Neither via @phanpy nor via mastodon-web
The char-limit of my instance is 500, which is less than the particular magnet-link has. This seems to be the issue, the automatic validator doesn't treat it as only 23 characters like with https
Does anyone have the same issue and/or knows more ?
Even more HTTP Message Signature weirdness.
My server receives a lot of "Delete" requests from #Mastodon server.
Those requests are signed.
I try to validate the signature but… the user is deleted!
So I try to retrieve the user's Public Key at, for example, https://nrw.social/@Faxy.json#main-key but get an error.
I suppose an HTTP 410 is a pretty good indication that the user has been deleted. And I *might* have previously cached the key. But it does feel a *little* bit pointless.
So, I admit that filtering out instances simply because they use the `.cf` TLD can be unfair. After all, it's just a TLD — that's not enough reason by itself to filter an instance out.
So I took a closer look at the JSON file containing the hosts that were actually filtered.
And the overwhelming majority of the `.cf` hosts were:
`activitypub-troll.cf`
I'm not kidding. The screenshots show the actual JSON data I got, and they're only a tiny fraction of the full file. There were so many entries that even VS Code couldn't count them all.
To be fair, there may absolutely be legitimate `.cf` servers out there. I just couldn't manage to find them in this dataset.
But I think we can agree that filtering `activitypub-troll` hosts doesn't require blocking the entire `.cf` TLD. We can replace that broad rule with a much more specific one.
So, that's another improvement to make!
What is a factual event from your life that seems unlikely or fantastical? Me, I once fell into quicksand.
RE: https://social.vivaldi.net/@thanksstevenkim/117154791519179296
A few people have asked where the “710,000 spam servers” number in my previous post came from, so I thought I should explain it more clearly.
First, I should clarify something: calling all of them “spam servers” was an oversimplification for the joke. A more accurate description would be hosts filtered out as likely spam/noise by my automated filter.
When I run `filter_spam.py` for the project, I get the following results. The script outputs in Korean because Korean is my native language, so I've translated the output here:
The actual filtering results are quite long, so I've moved them to the next post in this thread ⬇️
@rmblaber1956 I think people #respect money, which is why they vote similar in other countries.
They might not even like him but they follow / respect money (even if it's funny-money)/
#Moral #conscience or paying for others is not even in normal people's minds - and I've #tested a lot of people on #Mastodon and in my life. and as fairly as possible.
People don't want #responsibility or even run #basic things themselves. So give it up to #trump ed up types to then #blame them instead... #Sad.
.. out of 10 follow requests in the fediverse I reject about 8.
I reject user accounts that do not even have a profile or their own posts or their own media on their original server page, because I consider them to be of non-human origin until then.
What do I conclude from this?
Even here in the noble fediverse, "social media" shows itself to me as a bubble of vain appearances.
Hardly anything is authentic or truthful anymore and if you post here you make yourself suspicious of untruthfulness like everywhere else!
So how do we want to defend ourselves against this flood of social engineering???
Any suggestions???
#nobot #noai #socialengineering #socialMedia #fediverse #mastodon
FYI — Still having major issues with masto.ai very frustrating. I’ve gotten just about every error message there is.
Does #Mastodon even use `contentMap` in posts (`Note`)? The #ActivityPub spec specifies a method for multilanguage posts in the form of `contentMap`, but does the rest of the #Fediverse even get to read it? Do posts that have `contentMap` but **not** `content` get to show at all?
I’ve been working on a small Fediverse project called "The Hitchhiker’s Guide to the Fediverse".
It started as a simple directory of Fediverse instances, but I’ve been gradually turning it into something more useful:
- discovering new instances through federation peers
- filtering suspicious/spammy hosts
- monitoring known instances over time
- automatically hiding servers that stay offline
- bringing them back if they recover
- keeping the whole thing updated with GitHub Actions
The monitored set is already around 27,000 instances, so I also had to rethink the collector to use bounded concurrency and checkpointing instead of checking everything one by one.
Still very much a work in progress, but it’s been a fun way to learn more about how the Fediverse actually behaves in the wild.
https://github.com/thanksstevenkim/the-hitchhikers-guide-to-the-fediverse
https://codeberg.org/ihabunek/tooi
Tooi is the successor to 'toot'. It is /way/ nicer so far.
In addition to being 'keyboard-driven' it also responds to the mouse pointer. This is efficient when using a keyboard with a touchpad.