Show newer

Mastodon 4 adds a new endpoint, /api/v1/instance/domain_blocks

This endpoint contains your instance's block list in an easily machine-readable format. As far as I know, the only tool that currently uses this endpoint is the kiwifarms one.

The endpoint does not require any form of authentication, so it's very easy to scrape. I recommend editing your web server configuration to prevent access to the endpoint until there's something legitimate that uses it.

#fediblock #mastoadmin

I wish we could rely on governments or companies or other institutions to be there for us. But increasingly we will not be able to. *We have to do it ourselves.*

Housing, community safety, cyclist/pedestrian infrastructure, local journalism, education, preventing drug overdoses, running social media…It is all up to us. There is no one else.

It's a dizzying realization. It's terrifying…but also incredibly empowering.

Does anyone else feel this way?

🐦

Relatedly: I wish Objection.js actually had meaningful error feedback instead of just throwing a meaningless stacktrace nested 10 levels deep

Show thread

TIL: in VS Code's file switcher 'command bar', you can just enter a path:line:char stacktrace entry and it'll jump directly to the correct location

infosec meta 

The thing that gets me about the infosec.exchange thing is that at least Jerry seems to understand and respect the choice to defederate...

... which is something that cannot be said for seemingly its entire usebase

I blocked infosec.exchange, in line with Scholar's no-cops policy (I know, strictly speaking not cops, but DHS is close enough for us)

A user on Scholar wanted to migrate there, asked me to un-suspend them while they did that

It took ~ 35 mins for users on infosec.exchange to start sending us harassing messages

Not cool

if the ear resonates with sound waves for your brain to interpret as sound, does that mean when I put a square wave in Famitracker my ear drum is doing binary

@ifixcoinops I'm trying to find #theowlhouse people
PLEASE!
No one seems to have moved from the bird app. I don't think they learnt how to fly yet....or they're all penguins in which case i'm in big trouble because I was only on there for the artists 😭

For other instance admins 

It's okay to say "we don't allow police on our instance"

Scholar has had that in our About for at least a year:

scholar.social/about

We also had a "no institutions, only individuals" policy for even longer

This has done us well

I just want to remind you that you don't have to provide volunteer tech support and hosting for agents of the government, for-profit companies, or other institutions

You can just, not

And it's bad for your community if you do

operator precedence parsing was solved 100 years ago, y'all just cowards

Everything *else* aside, having a government account hosted on a community server seems an awful lot like having a government website hosted at something like

bobspersonalpage.com/users/~InternalRevenueService

Just spotted some graffiti that said "abolish bedtimes"

Results of today's trip:
- The optician was closed due to an eye surgery
- The social housing corporation's office is up for rent
- There are now two branches of the same flower shop within the same shopping area. In addition to the two supermarkets of the same chain we already had.

I couldn't make this stuff up if I tried.

infosec meta, question 

So, uh. Are there any infosec instances left that *aren't* buddy-buddy with feds/cops/fascists/etc.?

The modern German train experience of "your train is delayed, so you wouldn't make your connection. However that train is also delayed, so you'll make it" 😅😅

I have mixed feelings about the Tumblr ActivityPub thing. On one hand, that's a lot of users that will now be able to interact with our open community here, and I feel like that can be a good thing. I always felt like fedi culture and Tumblr culture were very similar too. However, a major company becoming part of the ecosystem is an entry point for companies to take over the ecosystem. I think the current owners of Tumblr are decent people, but if Automattic or Tumblr get acquired again we may end up in a situation where a company wants to take over fedi for the benefit of its shareholders.

subtoot, infosec 

"If these people don't want the feds to read things, they shouldn't use the internet."

That isn't the fucking point, you goddamned wet noodle.

No one is sitting here thinking that intelligence agencies can't read shit. It's that we don't want to *welcome them into our spaces*. We know where that gets us. And it's never been anywhere good.

subtoot, infosec 

Fucking dorks sitting there like THEN DON'T USE THE INTERNET.

Idk, jackass. Why don't you try to think about how we use OUR spaces? How we build things with intentionality?

Why not use your skills for actual safety and getting these fuckers *out of our lives* instead of supporting them? Unless, of course, you want the same power they have and you're working your way into that.

Show thread

Many government agencies are expressing concerns about how to communicate with the public without Twitter, especially in emergencies. Of course, it was a bad idea to become dependent on Twitter to such an extent in the first place, and no matter what happens, this needs rethinking.

Show older
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.