I just added an issue to the nodeinfo repo about bots and groups:
https://github.com/jhass/nodeinfo/issues/110
Has anyone else dealt with this before?
Topics from outside of this forum. Views and opinions represented here may not reflect those of this forum and its members.
<p>Everything about Lemmy; bugs, gripes, praises, and advocacy.</p>
<p>For discussion about the lemmy.ml instance, go to <a href="https://lemmy.ml/c/meta" rel="nofollow">!meta@lemmy.ml</a>.</p>
<p>Memes about the Fediverse.</p>
<h4>Rules</h4>
<h6>General</h6>
<ol>
<li>Be respectful</li>
<li>Post on topic</li>
<li>No bigotry or hate speech</li>
<li>Memes should not be personal attacks towards other users</li>
<li>We are not YPTB. If you have a problem with the way an instance or community is run, then take it up over at !yepowertrippinbastards@lemmy.dbzer0.com.
<ul>
<li>Addendum: Yes we know that you think ml/hexbear/grad are tankies and or .world are a bunch of liberals but it gets old quickly. Try and come up with new material.</li>
</ul>
</li>
<li>This is not the place to start flamewars between Lemmy, Mbin and Piefed.</li>
</ol>
<h4>Elsewhere in the Fediverse</h4>
<p>Other relevant communities:</p>
<ul>
<li>!fediverse@lemmy.world</li>
<li>!yepowertrippinbastards@lemmy.dbzer0.com</li>
<li>!lemmydrama@lemmy.world</li>
<li>!fediverselore@lemmy.ca</li>
<li>!bestofthefediverse@lemmy.ca</li>
<li>!fedigrow@lemmy.zip</li>
</ul>
<p>A community to talk about the Fediverse and all it’s related services using ActivityPub (Mastodon, Lemmy, Mbin, etc).</p>
<p>If you wanted to get help with moderating your own community then head over to <a href="https://lemmy.world/c/moderators" rel="nofollow">!moderators@lemmy.world</a>!</p>
<h2>Rules</h2>
<ul>
<li>Posts must be on topic.</li>
<li>Be respectful of others.</li>
<li>Cite the sources used for graphs and other statistics.</li>
<li>Follow the general <a href="https://lemmy.world/legal" rel="nofollow">Lemmy.world rules</a>.</li>
</ul>
<p><strong>Learn more</strong> at these websites: <a href="https://joinfediverse.wiki/" rel="nofollow">Join The Fediverse Wiki</a>, <a href="https://fediverse.info/" rel="nofollow">Fediverse.info</a>, <a href="https://en.wikipedia.org/wiki/Fediverse" rel="nofollow">Wikipedia Page</a>, <a href="https://the-federation.info/" rel="nofollow">The Federation Info (Stats)</a>, <a href="https://fedidb.org/" rel="nofollow">FediDB (Stats)</a>, <a href="https://sub.rehab/" rel="nofollow">Sub Rehab (Reddit Migration)</a></p>
<p dir="auto">Discussion and Questions for the End-to-End Encryption (E2EE) Task Force. For meeting dates and times, check the <a href="https://www.w3.org/groups/cg/socialcg/calendar/" rel="nofollow ugc">SWICG Calendar</a>.</p>
<p dir="auto">Not that Meta, but meta-discussions about this site, its contents, moderation concerns, governance, etc. all go here.</p>
<p dir="auto">A place for news and analysis about the new generation of social networks, build on open protocols, such as Bluesky and the fediverse.</p>
"Umamusume" "gaming" """"discussion""""<br/><br/>op: <span class="h-card"><a class="u-url mention" data-user="AKBjxyu1ZtFuKCqQMa" href="https://eientei.org/users/menherahair" rel="ugc">@<span>menherahair</span></a></span>
<p dir="auto">Any non-ActivityPub discussion goes here.</p>
<p><strong>Welcome to /c/SoftwareGore!</strong></p>
<hr />
<p>This is a community where you can poke fun at nasty software. This community is your go-to destination to look at the most cringe-worthy and facepalm-inducing moments of software gone wrong. Whether it’s a user interface that defies all logic, a crash that leaves you in disbelief, silly bugs or glitches that make you go crazy, or an error message that feels like it was written by an unpaid intern, this is the place to see them all!</p>
<p>Remember to read the rules before you make a post or comment!</p>
<hr />
<details><summary>Community Rules - Click to expand</summary><p>—
These rules are subject to change at any time with or without prior notice.
<em>(last updated: 7th December 2023 - Introduction of Rule 11 with one sub-rule prohibiting posting of AI content)</em>
—
<p>
Cryptography, Cryptopolitics, Blockchain, Decentralization.</p>
<p>This is <strong>not</strong> a place for shilling currencies, market analysis and/or pump’n’dump schemes.</p>
<p>Questions and answers are encouraged. <strong>Be excellent to each other.</strong>
️</p>
<p dir="auto">Topics and dispatches about the annual FediCon conference in Vancouver, BC</p>
Primary channel for the Fireside Fedi show.
Fireside Fedi is a show where we sit down with folks that are a part of the Fediverse and get to know them. A relaxing chill time. Powered fully by Fediverse connected tech.
@ozoned@btfree.social
@ozoned@tubefree.org
@ozoned@stream.ozoned.net
@ozoned@stream.firesidefedi.live
@ozoned@worksonmymachine.live
<p dir="auto">General non-specific discussion about ActivityPub-related topics.</p>
<p>Icon base by <a href="https://lorcblog.blogspot.com/" rel="nofollow">Lorc</a> under <a href="https://creativecommons.org/licenses/by/3.0/" rel="nofollow">CC BY 3.0</a> with modifications to add a gradient</p>
<p dir="auto">Need help with installing or configuring NodeBB? Look here.</p>
<p dir="auto">Focused discussion related to ActivityPub integration in NodeBB</p>
<p dir="auto">Found a bug? Why not make a bug report here?</p>
<p>Stay tuned here to hear more about new releases and features of NodeBB!</p>
<p dir="auto">Technical discussion about ActivityPub-related topics.</p>
A world of content at your fingertips…
Think of this as your global discovery feed. It brings together interesting discussions from across the web and other communities, all in one place.
While you can browse what's trending now, the best way to use this feed is to make it your own. By creating an account, you can follow specific creators and topics to filter out the noise and see only what matters to you.
Ready to dive in? Create an account to start following others, get notified when people reply to you, and save your favorite finds.
Register LoginI just added an issue to the nodeinfo repo about bots and groups:
https://github.com/jhass/nodeinfo/issues/110
Has anyone else dealt with this before?
My thoughts:
I don't necessarily think FEP fe34 is strict enough to be a guiding principle for security across federated instances. The reporter said:
> "at minimum" means same-origin is the floor, not the ceiling.
... and he's right, there's more you should do to verify that only the owner or a designated moderator can update and delete an object.
However we don't have a widely-used ability to determine who the moderators or admins are for any given instance. Mastodon may have an endpoint (in their API), threadiverse software use their own (as directed by 1b12, and even then it's optional), other software <img class="not-responsive emoji" src="https://activitypub.space/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=8161d5c9b56" title="
" /> ?
So we fall back to origin-based security model and hand off the responsibility of determining who can and cannot alter somebody else's objects to the sending server.
That's a risk we take with this model. Not sure if there is more that can be done to tighten this up.