Notices by :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site), page 39
-
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:47:26 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@roka @1iceloops123 @ffs @fluffy @lnxw48a1 @nepfag
no, this person has a custom AP server that floods the network. analysis so far does indicate that there are some implementation flaws in their spammer. being more strict may mitigate the spam issue considerably. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:36:35 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@ffs @roka @fluffy @1iceloops123 @lnxw48a1
i'm aware, and it's probably not the same person who hit my instance with 230gbit of NTP amplification the other day. who it is ultimately is irrelevant, as investigating who it is doesn't lead to mitigations. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:31:53 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@mario
brilliant. thanks. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:22:06 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@fluffy @ffs @1iceloops123 @lnxw48a1 @roka
there is somebody going around DoSing instances they don't like by flooding them with useless messages. that's most likely what happened to FSE. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:19:00 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@mario
you do? i observe keyIds of "https://hub.somaton.com/channel/mario/public_key_pem" on your actor. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:17:42 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@waifu what are stories? -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:16:26 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@sjw
this has been in progress for a few months now.
@absturztaube built the prototype and now it's being implemented in Pleroma FE itself. -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:14:55 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
misskey be all like “we have
isCat
mode and emoji reactions using__misskey_emoji
”meanwhile Pleroma community is all like “hold my beer”
-
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:10:12 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@alexa that's the idea -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:05:51 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
tired: emoji reactions
wired: sticker reactions -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:04:44 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
stickers are coming to Pleroma! https://git.pleroma.social/pleroma/pleroma-fe/merge_requests/885 -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 16:04:21 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@karen
i'll write a blog about it, but it's intended to be a transitional mitigation until OCAP is ready.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 15:52:34 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
part 4 is the easy part, mapping signed fetches as proof of possession of the "fetch" capability.
note that i keep talking about mapping signatures from specific actors to capabilities. this is so that *internally* it's all translated OCAP. that means once OCAP is ready, we can just flip a switch and have it.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 15:50:57 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
parts 1 and 2 of our "secure mode" implementation are now merged.
now to do part 3: signing outbound object fetches with the instance fetch actor.In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 15:32:53 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
hey @mario -- as part of the work to lock down AP object fetching I noticed that Hubzilla uses a different keyId scheme on it's HTTP signatures verses what the rest of us use.
this results in unnecessary actor refetches from Hubzilla instances for both Pleroma and Mastodon instances.
would it be possible to use either the actor URI or the actor URI with the key name as a fragment, like we do?In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 14:15:35 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
now to fight the war against blind http signatures (ones wherein we don't have a key on file) In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 09:04:03 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
An object was deleted In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Wednesday, 17-Jul-2019 08:41:26 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@JoYo I think mogrifun is a demo that intentionally distorts the image In conversation from pleroma.site permalink -
:abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy: (kaniini@pleroma.site)'s status on Tuesday, 16-Jul-2019 21:44:20 EDT :abunhdhappyhop: :abunhdhappy: :abunhdhop: :abunhd: :abunhdhappyhop: :abunhdhappy:
@StarshineLunacy this isn't really front seat. front seat is like juche.town or something. In conversation from pleroma.site permalink