Conversation
Notices
-
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 03:32:53 JST @kirby @DutchBoomerMan @paula @PeachySummer If you have regular authorized fetch mode enabled, the instance checks the signatures of incoming GET requests on objects and fetches your internal.fetch signature if there's none in its database. If you disallow viewing local statuses in adminfe, I think what happens is that authorized fetch mode gets implicitly enabled *plus* your instance just stops attempting fetching signatures of unknown actors that request objects. How I fixed it on my side is a trade secret but if you have an idea how federation works, I think you'll figure it out. -
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 03:34:29 JST @kirby @DutchBoomerMan @PeachySummer @paula Ideally, of course, someone should tell paula or whoever's hosting the instance to uncheck a single checkbox in adminfe so that no one would have issues anymore. † top dog :pedomustdie: likes this. -
Bankizo (bankizo@goreslut.xyz)'s status on Thursday, 11-Jan-2024 03:45:50 JST Bankizo @mint @DutchBoomerMan @kirby @PeachySummer im an admin where in adminfe is that config -
Himbo Techbro (r000t@ligma.pro)'s status on Thursday, 11-Jan-2024 05:01:26 JST Himbo Techbro @mint Okay so, I've never looked that close at how authorized fetch behaves, but I have one question, if anybody here is familiar with the behavior....
Originally, the big idea of shared inboxes was that, if you have Server A, Server B, and Server C, and a user on Server A has 1,000 followers on Server B, and 1,000 on Server C, then Server A is delivering to 2,000 people by making two /inbox requests.
My initial understanding of signed fetches is that now Server A is going to do *something* (the same thing?) to inform these other two servers that there's a status to fetch, and then Server B and Server C are now going to sign 1,000 requests each and make 1,000 HTTP requests that *have* to hit Server A's backend and cannot be cached, each?
@DutchBoomerMan @paula @kirby @PeachySummer likes this. -
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 05:05:12 JST @r000t @DutchBoomerMan @paula @kirby @PeachySummer There's no informing about a status to fetch aside from regular federation flow when your server fetches a missing post in thread's context. But yes, with authorized fetch there's no way to cache responses for incoming fetch requests aside from caching objects themselves internally and immediately returning them after checking signature. -
Himbo Techbro (r000t@ligma.pro)'s status on Thursday, 11-Jan-2024 05:08:40 JST Himbo Techbro @mint how incredibly wasteful to provide zero actual security @DutchBoomerMan @paula @kirby @PeachySummer
likes this. -
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 05:09:46 JST @r000t @DutchBoomerMan @paula @kirby @PeachySummer Precisely. Not like they don't know about it, even the first issue pitching the idea mentioned how easy it is to circumvent. † top dog :pedomustdie: likes this. -
Himbo Techbro (r000t@ligma.pro)'s status on Thursday, 11-Jan-2024 05:11:57 JST Himbo Techbro @mint I've noticed a repeating pattern in the github threads for these features (the current one is a flag allowing/disallowing quoting statuses), and it's basically "oh we know this can't be enforced, but once the feature's added to every software suite, we can seek out and punish instances that make the decision to bypass it"
and we're right back where we started with, anybody *worth* hiding something from isn't going to make a huge spectacle that they've gotten it anyway, they're just going to keep quiet and let you think you're a big winner
likes this. -
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 05:14:23 JST @r000t @DutchBoomerMan @paula @kirby @PeachySummer Those people are oversocialized and thus can't really comprehend people unbound by their social contract. All they have is an ability to shun people in their cliques out which won't work if you're already an outsider. -
(mint@ryona.agency)'s status on Thursday, 11-Jan-2024 05:17:47 JST @r000t @DutchBoomerMan @PeachySummer @kirby @paula Sure they declare you a non-person and move on. But you're still here, standing and observing. The lingering sight never goes away. Gangstalking has never been easier than in current day and age. † top dog :pedomustdie: likes this. -
Pawlicker (purpcat@clubcyberia.co)'s status on Thursday, 11-Jan-2024 05:23:29 JST Pawlicker @mint @DutchBoomerMan @paula @kirby @r000t @PeachySummer the people who make this shit would socially shame you until they cry about getting that ass banned
https://ulven.zone/p/2024-01-10-free-speech-is-not-a-noble-goal-to-pursue/ likes this.
-