検索

Tips: 変な人間が変な事してるのを変な奴らが盛り上げている故に身内ノリが合わなければ他のサーバーに行くという手段があります Fediverseに属していれば他のサーバーに居ても投稿が見れるほか、サーバーごとに機能が違っていたりもするのでioにアカウントを作っておいて普段の活動は他の場所という運用方法もアリです Q.他のサーバーはどこが良いの? A.こことか確認してみると良いかもしれません

:[email protected]: 1

返信 0 · Renote 3
CW: block recommendation - shotakey.everythingyaoi.com (pedophilia, fedinuke)
Enby.Life has defederated and purged media from shotakey.everythingyaoi.com for shotacon and federating with other lolisho instances including shota.house - not to mention federation with fedinuke sites including poa.st.

Reciepts are available on the front page (it's a sharkey instance that does not have its timelines locked down) and /about#federation - be warned that it is advised to use a VPN or tor browser to review the instance as it may contain media that is risky in your jurisdiction. #FediBlock #InstanceBlock #BlockRecommendation
返信 0 · Renote 0
Concept for discussion: Replacing HTTP Signatures with Bearer Tokens for ActivityPub Federation Curious what other people think about this idea. What if federation security was re-worked to use target-assigned bearer tokens to authenticate GET/POST requests? This would remove the need for complicated signing schemes and reduce system load under heavy traffic bursts (as no cryptography is required).

A basic implementation could look like this:
1. When instance A (a.example.com) first attempts to federate with instance B (b.example.com), a POST request is made to a dedicated registration endpoint. (for discussion, we'll say it's https://b.example.com/activity-pub/register-instance). This request includes fields necessary for verification, including the source domain name, target domain name, and a securely-generated verification token. Other metadata could be included to allow instance B to selectively allow/prohibit federation based on other criteria, but this is optional.
2. Instance B makes a POST request back to a dedicated verification endpoint on instance A (for discussion, we'll say it's https://a.example.com/activity-pub/verify-registration). This request must include the target domain name and verification token provided in step 2.
3. Instance A checks the verification token (and verify that it matches the target domain name) and return a successful value. The verification code must be invalidated after this call!
4. Instance B, after verifying instance A's request, returns a securely-generated federation key back to instance A. This federation key is a bearer token used to authenticate all requests from instance A to instance B. This key must be unique to instance A!
5. Instance A completes the original request with the Authorization header set to Bearer {federation_key}.
6. Instance B receives the request, detects the federation key, and checks it against the list of registered instances.
7. If the key does not exist or A has been defederated, then a [403 Forbidden error](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/401) is returned.
8. If the key is expired or revoked, then [401 Unauthorized error](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/401) is returned. Upon receiving a 401 error, instance A should start over from step 1 to re-authenticate and complete the request with a new token. This process should not be repeated for recursive failures!
9. If the key is approved, then a [200 OK response](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/200) or [202 Accepted response](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Status/202) is returned, and A can consider the request as successful.

Advantages versus HTTP Signatures:
- No cryptography requirements.
- Simple logic, no edge cases around HTTP query parameters or header order.
- Equally effective for all request types.
- Keys can be easily revoked or rotated.
- Supports authorized fetch and defederation use cases "by default".

Disadvantages versus HTTP Signatures: - Breaks the actor model - instances are required as a first-class concept. (but really, the actor model is basically dead already. you can't even federate reliably without a WebFinger server, at minimum.) - Requires multi-request "handshake" before communication. (but this is already required in practice, since a signature can't be validated without first requesting the signing actor.) - Out-of-band protocol - communication can't happen over ActivityPub / ActivityStreams because this is a prerequisite to authenticate any request. (but again, we already require WebFinger and some software requires NodeInfo for full support.) So, what are your thoughts? Good idea? Bad idea? Did I miss something? Please let me know, I welcome replies here! #ActivityPub #AP #Federation
返信 0 · Renote 0
CW: block recommendation (rumraisin.cc), lolicon, pedophilia, mentions the word "rape"
Enby.Life has fully defederated rumraisin.cc for posting and boosting lolicon, as well as appearing to be unmoderated and federating with known lolicon and pedophilia instances including pawoo.net, rkgk.moe, and rape.pet.

Respective receipts are available by going to the domain and going to /timeline and /about#federation. Note: it is advised to only review these through tor or a VPN and clearing your browser's media cache once you are finished with your review, as some of the cached images could be a legal risk in your jurisdiction. #FediBlock #InstanceBlock #BlockRecommendation
返信 0 · Renote 0
<center>SPAM対策BOTの充実化に伴うサーバーブロックの緩和について</center> 対策BOTくんが頑張ってくれているので、pawooを始めとしたいくつかのサーバーのブロックを解除しました。 様子を見ながら調整を続けたいと思います。 現在のブロックリスト: https://labo.takusuki.com/blocklist.html ※https://takusuki.com/about#federationからも確認できます~ #管理人からのお知らせ

:otsusamadesu@.: 29 :itumoarigatou@.: 12

返信 0 · Renote 1

返信元:

@windfallxyz 連合一覧は?[こちら(https://takusuki.com/about#federation )から確認できます。(数が多いので重いかも) 状態を切り替えるとioさんが今は配信停止になっているみたいですねぇ。 重くて一時的に遮断されている可能性もありますので、詳しいことは管理人さんにお問い合わせしてみてもいいかもしれません~ #Re_教えて卓すきー!
返信 1 · Renote 0
Whenever Twitter is #down, people will recommend Mastodon as a better alternative since it's a federated system which can't go offline as a whole. While #federation is great in terms of independence and resistance to censorship, I don't think #TwitterDown is the best argument to attract new #Mastodon users, since – for the individual user – it wouldn't make any difference whether #Twitter or the respective Mastodon home server is #offline.
返信 0 · Renote 0