meta
@discordiankitty@mastodon.me.uk So there's two components to this, really:
1. This is just a fundamental technical limitation of any federated system, it's the same limitation that eg. e-mail has. This just isn't possible to solve (at least in the way you're looking for) without a centrally-arbitrated 'identity registry', which has a whole host of its own fundamental issues.
2. Another way to look at it, is that the server name is *part of* the username. It's true that people often move servers, but at the same time that leaves behind an account-move notice on the old identity, so it should still be just as verifiable as if the account hadn't moved.
While it's certainly true that there could be better verification mechanisms (eg. keybase-like mechanisms), it's also important to realize that this impersonation issue isn't actually specific to the fediverse or even federated systems in general; for example, on Twitter, there has likewise been a long-standing and widespread impersonation issue that wasn't solved by centralized handles either.
If anything, while the verification is still imperfect, the fediverse currently deals with this slightly *better* than Twitter; because there's actually an active mod response here, and malicious accounts will either disappear quickly, or instances that deliberately originate them will be quickly blocked by other instances. Twitter doesn't even have that :/
@schmittlauch It's surprisingly safely implemented - if there are multiple packages offering the same binary name then it'll make you choose one first, and it only fetches packages from nixpkgs, which has at least had nominal review :)
(So basically, it avoids the two biggest security issues that eg. npx has)
In a world where your servers are operated by volunteers rather than big well-resourced SV corporations with security teams, it’s interesting to think about how we can make identity and authentication require fewer shared secrets.
Musing while setting up 2FA: one of the nice old auth systems I remember is S/KEY. It allowed you to generate one-time codes such that the server only needs to store a “public key” (verification key) rather than a shared secret. https://en.m.wikipedia.org/wiki/S/KEY
@drifa If there's one thing I've learned over the past few days, it's that with some people over on Twitter who complain that "Mastodon can't replace Twitter", it's probably better for everybody involved that they don't come over to the fediverse...
Polite reminder, if you request a follow to a locked account without reading that person's pinned toots, you're likely gonna be disappointed
I had 4 follow Req's I had to deny today, because they didn't tell me the basic info about who they are in their bio. A stream / wordcloud of tags, especially tech terms isn't a bio, it's a CV. Write who you really are in your bio, and read other people's profiles to find out who they really are before clicking follow. There's no prize for following the most people.
I require as a minimum pronouns in your bio and a DM telling me why you chose to follow me. Mastodon's "most private" post setting is "followers only" so if I let you follow me I am trusting you to see a more intimate side of my account. I feel it's fair you tell me why I trust you with this.
This is all written up in my pinned toots, but most people don't both to read those. Actually it seems most clients hide them these days 😔
Read profiles or expect disapointment.
If you're response to coming to a place whose mostly-queer denizens have already created rules that allow them to interact comfortably with each other and scream about how you shouldn't have to follow those rules, you're just an asshole, whether you nominally belong to my group or not.
Read the room, learn the history, interact politely. Being a good citizen of a space is not rocket science.
I'm absolutely thrilled to see https://blacktwitter.io is a thing! I've been hoping to see instance centered around the experiences and moderation needs of Black people in particular.
@jfhbrook That's mostly just things being slow because the userbase size tripled overnight without a corresponding growth in instances :p
I see a lot of people talking about how Mastodon "Feels like the Internet I remember from 20 years ago."
That's no accident. That's Federation. That's UseNet, IRC, Email, Message Boards, etc. What do they all have in common?
Federation: Users congregating around watering holes of common interest, but still being a part of a larger whole.
THIS IS HOW THE INTERNET WAS DESIGNED TO BE. And I am HERE for it.
@aeva Oh no, I was criticizing tendencies of programmers, not your toot :)
@aeva That programmers are often elitist by assuming they are linearly more intelligent than everybody else, and believing that they can speak for everybody else, and therefore anything that bothers them must bother everyone else too
When I joined #mastodon, I just wanted an open-source #twitter clone.
I got more than that. Subtle design differences made for healthier conversations in ways I wasn't expecting.
Here's a blog post to try to capture those differences and why they matter. https://scott.mn/2022/10/29/twitter_features_mastodon_is_better_without/
fedi meta
Interesting to note that the authors of ActivityPub (the protocol Mastodon is based on), including @cwebber whose thread I just boosted, have received very little attention compared to the Mastodon guy. https://www.w3.org/TR/activitypub/
Realized I didn't do an #introduction, so here goes -
I'm a #woodworker & #artist in #Hamilton #Ontario #Canada making #sculpture, #marquetry, #boxes, plus various other projects including #spooncarving, small #furniture, and acoustic treatments.
Really enjoying Mastodon and the Fediverse so far. This place seems to be absolutely exploding with amazing artists and makers.
Looking forward to being part of this community.
Here's a box. I posted it before, but this is a better quality pic :)
@ZaneSelvans From what I can tell, searching for a hashtag really *searches for that hashtag*, and not stuff tagged with it. It then turns up every hashtag that has ever been seen and is similar enough, with an indicator of current activity. When you click a specific search result (ie. hashtag), you get the feed of currently known toots that contain that hashtag.
Fediblock, journalism
After some consideration, I've suspended journa.host from the server I run (not with this account). There's quite a lot of decent people signed up there, but also at least one prominent right-winger (The National Review's Jonah Goldberg), and I can't risk it.
Also, reporters mining social media for fodder without the authors' knowledge or consent is a plague on every other social media platform, and I think fedi should nip it in the bud.
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.