Developer of ActivityPub-based micro-blogging and content subscription platform Mitra. I help maintain the FEP repository and write my own FEPs too. Currently working on ActivityPub Next.
Public Key
npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw Profile Code
nprofile1qqsx5he4ms5pyakrp3f8uyjqaa4660hj008e9d877qtacl66tsc7tmqpz4mhxue69uhhyetvv9ujumt0wd68ytnsw43qz9thwden5te0wfjkccte9ejxjar5duh8qatz3u9m92
Show more details
Published at
2026-08-18T23:12:09+02:00 Event JSON
{
"id": "fcc8f960b9ba784e58b7adfd83a68ffad3e43c5512bf42aa5ec07e12affedabe" ,
"pubkey": "6a5f35dc281276c30c527e1240ef6bad3ef27bcf92b4fef017dc7f5a5c31e5ec" ,
"created_at": 1787087529 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://mitra.social/users/silverpill",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"silverpill\",\"about\":\"Developer of ActivityPub-based micro-blogging and content subscription platform Mitra. I help maintain the FEP repository and write my own FEPs too. Currently working on ActivityPub Next.\",\"picture\":\"https://mitra.social/media/6a785bf7dd05f61c3590e8935aa49156a499ac30fd1e402f79e7e164adb36e2c.png\",\"nip05\":\"[email protected] \",\"fields\":[[\"Code\",\"https://codeberg.org/silverpill/\"],[\"Matrix\",\"@silverpill:unredacted.org\"],[\"XMPP\",\"[email protected] \"],[\"$XMR\",\"48YM8jwJqDkeUvD38vepSXFeMZH1zsjbvGwTTuaNSSq6Q5GyeWaeiheAZUsSmNn72YdyLpw8geb4FL3opZfGbguJLUj8Mi9\"],[\"XMR subscription\",\"https://mitra.social/@silverpill/subscription\"],[\"PGP\",\"0541 49E3 0F91 C6D7 8FFA C49C 955F 5A6E 2123 25F0\"],[\"OMEMO fingerprint\",\"689a2fb0ec87a9481fb45cb7d8870da6aeb4d8247bd69a39017701133b901f04\"],[\"Matrix (backup)\",\"@silverpill:poa.st\"]]}" ,
"sig": "0c87f8aca9bd4bdf4c66557f56fffb1c12b021bd3080cce4a66a340bf6ae4b57a7b20e9384634347e334687765d7e1520bd73f55b4cfee73a134c62fad342125"
}
Last Notes npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…vgdh @nprofile…q5n4 I think there is a big difference between being defederated and being deplatformed. In fediverse you don't need to start from scratch, you can move between servers and you can start your own. Some people may not like you and be very loud about it, but ultimately they only have as much power as others give them. The best strategy is to ignore the haters and keep doing your own thing. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag @nprofile…8udl My self-hosted Forgejo instance is doing fine, but maybe scrapers simply haven't discovered it yet. If that becomes a problem, I'll probably make it an onion service. I think it's better than switching to a different software npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag I don't want to use it because it's a shitcoin project. Let's build a peer to peer forge on ActivityPub. I figured out how to do p2p, I think ForgeFed can be adapted to that. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag Oh no, I hate this UI. Logged in and looked around, everything seems to be working as expected. >rad://z2gAKC6ESt5ZBV419uVPf2vFtEHCT How to resolve that URL? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…mzmr Hi, I tried to implement the mechanism described in the FEP and decided to use HPKE (RFC-9180). What do you think of it? HPKE seems to address the issue you pointed out back then: https://www.rfc-editor.org/rfc/rfc9180.html#name-forward-secrecy. At least if used properly. The library I am using hard-codes "info" and "aad" strings: https://github.com/rustonbsd/ed25519-dalek-hpke/blob/27b010a9ae25ba4ce051510eadfd103a179dd715/src/lib.rs#L98-L104 Anyway, here's an updated FEP: https://codeberg.org/silverpill/feps/src/branch/main/0806/fep-0806.md @nprofile…m70s @nprofile…t3h7 @nprofile…pnc4 @nprofile…pl32 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…834j "data did not match any variant of untagged enum AnnouncableActivities" npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill Lemmy can see my groups, and it can discover posts with "Search": https://voyager.lemmy.ml/post/17669 But it can't follow a group because it doesn't like my Accept activity: https://github.com/LemmyNet/lemmy/issues/6595 RE: https://mitra.social/objects/019f053a-9069-7fd1-89f9-60b7318a368f #nevent1q…22zk npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…s0sp >why instances like ryona.agency, tsundere.love, annihilation.social aren't loading images Might be caused by bad connectivity. But if this behavior is consistent, I could look into it. >why @relaystalker is STILL getting stuck on follow requesting with relay accounts https://github.com/yukimochi/Activity-Relay/issues/102 Maybe a clanker could fix it? >how to get tor/tor federation up with this docker setup >how to federate over I2P https://codeberg.org/silverpill/mitra/src/branch/main/docs/onion.md https://codeberg.org/silverpill/mitra/src/branch/main/docs/i2p.md But I don't know how to make it work with docker >duplicate key bug I am interested in debugging this. Database integrity should be maintained. >how to pull past posts from profiles quickly so I am not looking at a profile timeline with gaping holes Make yourself an admin and click on "Load latest posts" in profile menu. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…sygg There is nothing new. All kinds of decentralized social networks have been tried in 2010s, the clear winners are Fediverse and SSB. What happens if you try to combine the two? FEP-ef61 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…vgdh @nprofile…k4nn What kind of component? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…krnx @nprofile…gunk npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…mq95 @nprofile…krnx There is no formal procedure. The list consists of clients with friendly and responsive maintainers and clients that I can debug myself. I am not familiar with Emacs but if it works well let's add it to the list. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…0jt2 This site provides comparison tables for various protocol features: https://funfedi.dev/support_tables/ npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…s2sp @nprofile…p3lz I don't use docker in production, so I am happy that others take care of images. Haven't decided on CI yet. My plan was to move to my own self-hosted Forgejo instance once forge federation is implemented, and start building advanced infrastructure there. But the work on federation is progressing very slowly. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill What status code you use get? It might be a temporary issue. The best practice, I think, is to stop delivering after some time (1 month, for example). npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2y8k @nprofile…xsag Some interesting data here: https://funfedi.dev/support_tables/object_types/ npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…lqwx It is useful if you want a micro-blog account that is not tied to a single server / domain name. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…s2sp HTTP signature bypass is serious, but I can't figure out what it going in this PR. Looks like a bunch of unrelated changes npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…z7ps I usually add "on your own hardware" npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill https://www.openwall.com/lists/oss-security/2026/03/09/7 Misskey and Sharkey, ActivityPub-based social network services (similar to Mastodon), have released updates to patch vulnerabilities Sharkey maintainers describe as "extremely severe". Details have not been not published yet but "missing permission checks" and "authentication bypass" sound like vulnerabilities that could be prevented by following recommendations from FEP-fe34: Origin-based security model. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ekds I have a couple of comments regarding the spec https://codeberg.org/portafed/portafed/src/branch/main/portafed-spec/spec.md It contains a comparison with FEP-ef61, but it is not quite correct: - FEP-ef61 identity is not actor-rooted. The closest equivalent of FEP-ef61 identity in normal ActivityPub is a server with a domain name. A single FEP-ef61 authority can manage multiple actor documents. - FEP-ef61 does not lack a migration flow. Strictly speaking, it doesn't need one, because data is not attached to a server and can be continuously synchronized between multiple servers. But a more familiar migration flow is also possible via outbox export-import. @nprofile…e40t npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…3mlc The Mastodon API is open source, but it is not an open standard. It is designed, maintained, and changed by one project, without input from the rest of the ecosystem. Not without. The design of this API is shaped by the needs Mastodon users. Sometimes PRs are submitted by developers of 3rd party clients and by developers of other servers. Independent implementers of Mastodon API often extend it, and copy each other's extensions, there is even a discussion about Mastodon API Enhancement Proposals (similar to FEPs). So I think that by now it is very much an open standard. ActivityPub API may have W3C's stamp or approval, but that doesn't mean anything if nobody uses it. P.S. Does you blog not federate anymore? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tc7m The site was built by @nprofile…k5jq, I also contribute to this project from time to time. Yes, authors are responsible for maintaining implementation lists, but FEP process is meant to be collaborative and others can add missing implementations by opening a PR. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill FEP-0151 is now FINAL, with 5 implementations: https://codeberg.org/fediverse/fep/pulls/760 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill FEP website now displays the number of implementations for each implementable proposal: https://fediverse.codeberg.page/fep/final/ These numbers are based on the information that authors provide in the "Implementations" section of a proposal. By default, proposals are informational, so authors need to opt in by adding type: implementation to the metadata block. #fep #fedidev npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…rxpq Paying for it with monero npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill minimitra now uses #PGlite instead of postgres: https://pglite.dev It's a portable database, so the installation process will not require any sysadmin skills. You just need to install the rust compiler and npm (the latter is required for pglite, I plan to remove this dependency in the future). I had to reset my database because pg_restore didn't work with pglite, but identity and actor ID have been preserved: @nprofile…z3wv. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag Hosted copies of an object may diverge, but the latest version of it is always available on the client side, because servers can't sign objects (unless server and client are a single application). How those annotations work? I think instance actor could propose a change, which the author may later accept (and publish an Update activity, for example). npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…6wm2 Hey, nice to see you online again. What is this bot? Looks interesting npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2gus Changed it to Create: https://codeberg.org/fediverse/fep/pulls/770 @nprofile…u8dh @nprofile…d8rs @nprofile…53ta npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2y8k I believe most implementations do that. My server re-fetches a key only if the cached key is 1 day old, for example. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2gus Publishing process doesn't change much. A generic server should deliver activities to actors specified in to and cc fields. It should keep track of collections, such as followers collection, and "expand" them before delivery. This part is not different from the regular ActivityPub. I think ID assignment should also work the same. In the FEP I proposed Add activity without object as a special activity for creating collections, but now I see that it will not work if IDs are minted by a server (no FEP-ae97). Perhaps it should be a Create, after all, as @nprofile…u8dh described in an adjacent comment. I was hesitant to use Create because this is a problem for FEP-ae97 clients (not a big one though). @nprofile…d8rs @nprofile…u8dh npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…u8dh @nprofile…davq @nprofile…d8rs No, my goal is to interoperate with many Fediverse servers, not just Mastodon. I agree that a generic server is supposed to support any activity, this is exactly what I was arguing about for the last two days, and this is what my FEP is about. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2gus Let's assume that my client is a music player. It publishes a Listen activity where object is an Audio. This activity should increase playCount on the Audio object. One way to support this on the server side is to teach it about Listen, Audio and how to update playCount. This is how most existing servers are built. But a server described in my FEP would work differently: - It doesn't know anything about Listen, Audio or playCount. - Upon receiving Listen, it will recognize it as an activity, and embedded Audio as an object. - Since this is not a CRUD operation, it will not check permissions. - If Listen activity has a result property, the server will process that activity as well. - If result is an Update activity, the server will recognize it as a CRUD operation and will check permissions: Update.actor and Audio.attributedTo must be the same. - The server will save both activities, Listen and Update. - Then it will deliver them to intended recipients (to and cc). Effects are client's responsibility now, it must provide an Update activity if it wants to update playCount. There are other requirements too, for example all objects should have an attributedTo property, which is needed for permission checks. But in this setup a single server can work with any kind of client. @nprofile…d8rs @nprofile…u8dh npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…s2sp @nprofile…xsag @nprofile…t3h7 @nprofile…y6jc @nprofile…tsag I think you're right about FEPs and cooperation. The optimal strategy is cooperate by default and defect only when the other side defects. With quotes we were almost successful. The initial version of Mastodon's consent-respecting quotes was based on FEP-e232, but later they decided to introduce a new property. Now there's FEP-521a (public keys), which they expressed interest in implementing. Even with Mastodon, it's worth trying. >Groups I think Lemmy's implementation is not bad. There is also Conversation Containers from Hubzillaverse, and a possibility of convergence, see this thread https://lemmy.ml/post/43519233 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…davq Nevermind, side effects wouldn't be a problem. However, it still doesn't seem to be compatible with ActivityPub... Because Announce activity is not defined in C2S context :) https://www.w3.org/TR/activitypub/#client-to-server-interactions @nprofile…834j @nprofile…d8rs npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…davq Placing activities in the target inbox is not always enough, sometimes there are side effects. In my FEP I discuss how we can deal with that. There is more to it, see my response to @nprofile…834j: https://mitra.social/objects/019ca012-a698-5c2a-a6fa-a547373294cc @nprofile…d8rs npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…davq what Vocata did This project is often brought up as an example of a generic server, but it never reached production stage. The last commit was in 2023. It is one thing to have an idea and build a prototype, and a completely different thing to build an application that is secure and interoperates with the rest of the network. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2y8k Yes, the signature contains key ID, from which you can obtain actor ID and perform origin / ownership checks. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…davq What happens when you send a "Offer" message to an actor on Mastodon? The behavior of Offer activity is not described in ActivityPub, so Mastodon is not required to support it. Curiously, ActivityPub mentions Offer when it talks about the side effects of Accept: The side effect of receiving this in an inbox is determined by the type of the object received, and it is possible to accept types not described in this document (for example, an Offer). ...This statement is not compatible with the idea of a generic server. Can I create a group actor on Mastodon? I don't know. But it can create Service actors, I guess it can be easily patched to allow creation of Group actors too. Can I use this actor to boost other actor's posts and have it visible on a Lemmy client? I think FEP-1b12 Announce is not compatible with ActivityPub. It has different side effects, doesn't update shares collection. How can a Mastodon client ask the server to get a collection of all images with an specific tag? Maybe something like /api/v1/timelines/tag/{tag}?only_media=true ? @nprofile…d8rs npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ut88 Better developer tooling is the only correct answer to rising complexity. Getting 200 different servers to smoothly interoperate is impossible, but we can do that with 10 libraries. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…2y8k I don't know Alloy, but I tried to analyze how authorization should be done in ActivityPub. The result is this document: https://fediverse.codeberg.page/fep/fep/fe34/ npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…834j It looks simple on the surface, but in reality it is much more complicated than a non-generic server. In addition to activity transfer, generic server needs to maintain collections. First of all, a followers collection, which is often used as a delivery target. Then likes, shares etc. It needs to enforce permissions, to prevent actors on the same server from deleting each other posts. This is doable if you only care about activities defined in ActivityPub. But then you want to introduce context collection. And then 50 other extensions. How to do that without special-casing every one of them? This is where duck typing (FEP-2277) and unified security model (FEP-fe34) become really handy. No matter what the client sends, you can figure out what it is (an object, an actor, or a collection), and enforce permissions. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…d8rs Mastodon supports all standard activities and has a wide variety of clients. I don't find softwares with similar capabilities impressive, although I respect your work (the only ActivityPub server-client project that is not a vaporware). I doubt that language choice makes much difference, and Rust is not a dynamically typed language anyway. The difficulty you might be facing is likely due to JSON-LD. The thanks was for your input with regards to collection management. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill 1. I don't care much about the "official" version of AP. It is outdated and increasingly irrelevant, most of the real development happens elsewhere. 2. Interledger is a part of Ripple/XRP cryptocurrency project, which is a scammy crypto company. Please don't spread FUD. Especially when it's so obviously counterproductive. Seems like maybe you need to touch grass a bit more often Oh my. Counterproductive to what? All you do here is talking about things you know nothing about and trying to insult me. You're pathetic. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…20nh How much it is tied to Mastodon? Is it possible to use Fediway with other servers? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ks9l I am pretty sure that nice things are within reach. Fediverse-ActivityPub already significantly diverges from W3C-ActivityPub. I think eventually they will become completely different protocols, that just requires a bit of coordination among devs. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…53ta If by "sufficiently improve" you mean throwing it away and replacing with a better protocol, then yes it's possible. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill I enabled compatible IDs in minimitra, so @nprofile…z3wv actor should now be reachable from most fedi servers. Follow/unfollow may also work, but only if your activity IDs are resolvable. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…z7ps If you're talking about digital technology, today we have more freedom than 10-20 years ago. But an average internet user has no freedom at all, for them internet is like TV. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…qhdx Opened an issue: https://github.com/astro/buzzrelay/issues/136 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…77cu Information about implementations is also present in FEPs, but it is similarly incomplete. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…de6s >but the governance infrastructure for consent, a way to distinguish deliberate community choices from defaults, is not discussed at all Let's discuss ActivityPub relays. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill And here is a post on the same subject from @nprofile…l5yp https://w.on-t.work/activitypub/c2s npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill It might be not possible to create a generic #ActivityPub server, but nevertheless this is an interesting thought experiment that helps simplify the protocol and figure out the best way to extend it. I've been thinking about generic servers for quite some time (because this complements my work on nomadic clients), here are my notes: https://codeberg.org/silverpill/feps/src/branch/main/fc48/fep-fc48.md @nprofile…ks9l RE: https://mastodon.social/users/eyeinthesky/statuses/116095929503245071 #nevent1q…3k4a npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…834j @nprofile…8qd7 @nprofile…ks9l @nprofile…d8rs @nprofile…c7yq Yes, they are building blocks, together with Create, Update and Delete. Everything else can be constructed from them. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ks9l I think Add / Remove should be used for extended collections. Like, Announce etc look like legacy / tech debt to me. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill Yeah that's pretty much what I meant. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill Often fanfare is the only thing that is being shipped npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill what defines "correct" here? Inflated or randomized stats, for example. I don't like "incorrect" here, but haven't found a better word yet. also, is a SHOULD NOT here sufficient? No, I think data aggregators like fediverse.observer are useful services, and there is no good reason to disrupt their operation by poisoning data. these requirements read as redundant, and also the 2nd requirement is more restrictive than the 1st which is weird I think these should be separate requirements. The first one is about any NodeInfo parameters, including metadata. There is a FEP about advertising capabilities using metadata (FEP-9fde), I want to discourage this practice, but this method is already used in the wild, hence a SHOULD. On the other hand, I can't think of any good reason to rely on software. This is a discriminatory practice, because as a developer you can easily add a feature flag to your NodeInfo metadata, but you can't change software to e.g. mastodon. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ks9l https://schemas.funfedi.dev/ npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ks9l SocialWG will not do that. But Fediverse developers may adopt JSON schema. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag @nprofile…ehgy There is an ActivityPub-based alternative. I didn't use it myself though, only tried to federate: https://github.com/MaddyUnderStars/shoot-client npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…e5wd @nprofile…s2sp Boost bots are for Mastodon. In our parts of Fediverse, we have FEP-1b12 and conversation containers, which are more powerful, and can be easily extended to support Join/Leave and roles (good topics for FEPs, by the way). I don't think anybody who matters actually cared about W3C approval. By 2023, we had FEP process going and ecosystem leaders (Mastodon, Lemmy) were contributing. The rebooting of SWICG was absolutely unnecessary. The intentions behind this effort were quite clear from the start, but it would have lost momentum quickly if you hadn't participated, but you did and continue to do, and now these Github repos are becoming a problem. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…8udl Yes @nprofile…qcew is our hero npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…umlp It does (but import currently requires admin involvement) npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…z753 @nprofile…s2sp It's fun when the other side is cooperating. Unfortunately this is not always the case, some developers just don't care about anything but Mastodon. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill If you don't understand the message, maybe it is not for you. These organizations are the participants of the AP working group. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…s2sp >Hidden Fetcher Activity Connect creates clones of actors to help users on disconnected instances communicate. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag @nprofile…xsag @nprofile…qlnp @nprofile…y6jc I would appreciate if you keep me in the loop. Also +1 for idiomatic ActivityPub and ignoring Mastodon npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…xsag @nprofile…y6jc @nprofile…tsag This is also interesting. I want to support hats in Mitra, it's a cool idea @nprofile…qlnp npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tsag @nprofile…y6jc I would love to see this in the FEP repository npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…6rwt Does it work as described in FEP-ae97? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…z7ps No backup? https://codeberg.org/silverpill/mitra/src/branch/main/docs/backup_and_restore.md You can skip the media and just do a database dump. It is usually small, mine is only 90MB. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…mcsn minimitra will use an embedded database, but not SQLite, because mitra needs many postgres features that don't exist in SQLite. Most likely it will be pglite: https://codeberg.org/silverpill/mitra/issues/28#issuecomment-6605416 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…z7ps What happened? I see fedi.libresolutions.network now redirects to fedi.gabe.rocks npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…gzt8 I don't see the like, it doesn't seem to be delivered. Mike once said that he doesn't want to support plain ap URIs, maybe this is why it doesn't work? Anyway, I just realized that even other Mitra servers can't load the post because there is problem with WebFinger :] npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill https://extensiblewebmanifesto.org/ Today, most new features require months or years of standardization, followed by careful implementation by browser vendors, only then followed by developer feedback and iteration. We prefer to enable feature development and iteration in JavaScript, followed by implementation in browsers and standardization. This was in 2013, and I think the web is in much better shape now. Tons of features have been added, and most of them are actually useful. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…uteg Forte and tootik are usable implementations, but they keep identity key on a server, as far as I know. I am working on another implementation, where keys are kept on the client side, so it is closer to a Nostr client: https://codeberg.org/silverpill/minimitra. It is not ready yet :) npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…faqy Just in case square avatars are actually important: in version 4.17.0 you can customize their roundness using the --avatar-border-radius CSS variable. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill This sounds quite similar to an ActivityPub relay: https://codeberg.org/fediverse/fep/src/branch/main/fep/ae0c/fep-ae0c.md Relays are often deployed as standalone services, but some servers (e.g. Pleroma) can host a relay actor that announces all public activities, just like you described. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…uteg The future is federated. Because we can have cryptographic identities in the Fediverse: https://codeberg.org/fediverse/fep/src/branch/main/fep/ef61/fep-ef61.md npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…sygg fep-ae97-client stores "you" as a collection of JSON files (including identity, which is just a secret key). It is very limited though. Representing some protocol data such as follow relationships, as static files, is going to be quite a challenge. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…ks9l Our everything accounts will be even better because Bluesky users don't really own their did:plc npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…qhdx I announced a tagged post to a hashtag actor, the response was 202. Not sure how to verify, though. Does FediBuzz distribute posts back to the originating instance? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…qhdx Apparently I am still affected by https://github.com/astro/buzzrelay/issues/132, can't follow a hashtag. I will try to send the Announce activity manually (without a follow relationship), though this will require a bit of work. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…tyzc tags.pub is a project to implement that feature -- collecting tagged content and redistributing it by hashtag This is exactly what FediBuzz does. It works great and @nprofile…qhdx just added a nice feature to it, which I am about to test. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…qhdx Thank you for adding support for Create/Update! Do you ingest these activities through hashtag actor inboxes? This might explain amplification, as hashtags can be followed by regular users too. This is how I use FediBuzz -- I just follow hashtags from this account, and relayed posts appear as reposts (boosts) in my feed. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…6jeq @nprofile…hccw When this document was written, decentralized identity in ActivityPub was just a theory. Specifications changed a lot since then, and today we have several independent implementations: Forte, tootik and Mitra. https://codeberg.org/ap-next/ap-next/src/branch/main/nomadpub.md npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…t3h7 We need to figure out what to do when one of the peers is offline. Other than that, the protocol is ready for p2p. In my current setup activities are stored and distributed by server(s), similar to Nostr. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill I am working on a new project, called minimitra. It's a FEP-ae97 client that implements Mastodon API. Minimitra is similar to Mitra, but it is designed to run as a desktop application and supports portable accounts. That means: offline-first, full identity/data ownership, Tor/I2P friendly. Currently minimitra can only send and receive public messages, but I expect that porting features will not be difficult because most of the code will be shared. Other limitations / downsides: - Requires postgresql server. - Can't post to multiple gateways. - No cross-client portability. Fortunately, all of that can be fixed! #fep_ef61 #fep_ae97 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…mzmr I am thinking about ActivityPub client-server connections. In my experience, fedi software is well-suited for extreme conditions (e.g. I always connect to my instance through Tor), but I'd like to learn more about @nprofile…racq 's experience. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…mycl Sounds similar to my issue https://github.com/astro/buzzrelay/issues/132 >hyper/reqwest I assume it's one their side (because Stegodon is written in Go)? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…racq I would expect P2P solutions to be less efficient, but does TLS really make any difference? npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill FEP-ef61 update: https://codeberg.org/fediverse/fep/pulls/717 - Added a section explaining how to compare 'ap' URIs. - Origin tuples are replaced with "cryptographic origins". The result is the same, but now we don't have to use port 0. - Outboxes and FEP-ae97 are not required anymore. This means implementers can use a different activity synchronization mechanism. #fep_ef61 #NomadicIdentity npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill With the latest release of #Mitra, the media proxy feature has stabilized and is ready to use. When enabled, it significantly reduces storage requirements because the remote media is not saved to disk. It also guarantees that you don't accidentally store anything illegal. However, since it is a proxy, the media is not loaded directly from remote hosts, so they won't learn your IP address and browser fingerprint, only the time when you're online. Media proxy can be enabled for all hosts or only for selected ones (because it is a part of the federation filter system): mitra add-filter-rule proxy-media '*' mitra add-filter-rule proxy-media pawoo.net RE: https://mitra.social/objects/0198be5c-dfef-8dca-3ac4-b370a79d372f #nevent1q…8mh4 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…w3qa At the ICANN level? That would be bad, but I think this is not going to happen anytime soon. Country-level blocks are much less of a problem, it happens all around the world already and people learned to circumvent those blocks. And there are 30000 instances, ActivityPub is really good at forcing people to spread out (it's much better at this than every other protocol). >I'm in the process of deciding how much I care about hanging on to a clearnet internet presence. But of course, investing in anon tech wouldn't hurt npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…wl4m I think they should be displayed as replies by an automated actor. npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…vps0 Fedify supports RFC-9421 and I've seen incoming RFC-9421 requests from Ghost instances (Ghost is based on Fedify). My software can verify RFC-9421, but signing is done with Cavage-12 npub1df0nthpgzfmvxrzj0cfypmmt45l0y770j260auqhm3l45hp3uhkqx27gmw silverpill @nprofile…pksn Exactly. Key custody is also possible, but currently the work is focused on non custodial solutions.