Proposal to create a collective to own the topic-based Lemmy instances
When information is cheap, attention is expensive
May I interest you in one shiny topic-based Lemmy instance? How about fifteen?Raphael Lullis
like this
aasatru likes this.
I think this sounds like a good idea. A problem when starting a community is that one wants to find a stable home; it might make sense to set up camp at, say, hardware.watch, but without knowing who operates it it might feel more uncertain than lemmy.world.
And then, as a result, if lemmy.world ever disappears or has problems, it'll take way too many communities with it.
If these topic-specific instances had some sort of collective ownership, I guess we could more effectively guarantee for their continued survival, and it might be more tempting for existing communities to move over there.
I'd be interested in hearing the thoughts of some admins - would !football@lemmy.world be interested in moving to !football@soccer.forum
, given the right organization?
And a piece of constructive feedback: Vague community names like !main@soccer.forum is probably less likely to attract attention than something specific like !nba@nba.space - when searching for a community, people look up the community name rather than the domain.
like this
aasatru likes this.
I'd be interested in hearing the thoughts of some admins - would !football@lemmy.world be interested in moving to !football@soccer.forum
, given the right organization?
I'm not the main mod of !football@lemmy.world so it's really not my decision to make, but moving the community to a domain with the word soccer in it is a tough pill to swallow. As silly as it may sound, there's a lot of people that don't like having football referred to as soccer.
Moving away from lemmy.world and their annoying VPN restrictions would be nice though.
moving the community to a domain with the word soccer in it is a tough pill to swallow. As silly as it may sound, there’s a lot of people that don’t like having football referred to as soccer.
Sounds silly indeed, but I agree (feddit.org/comment/2048090 )
Feel free to register a football domain. I will host it for you, free of charge.
aasatru likes this.
As I'm sure my home instance reveals, I do like the idea of focused instances. I think a general sports focused instance would be better than sport specific instances though, at least with lemmy's current size. It's not sustainable to pop up an instance for every sport out there, like strongman or arm wrestling.
And people would also have to be able to sign up to the instance. Which if I remember correctly you had a very different opinion on when you spoke to Snowe on !meta@programming.dev about programming.dev. Just from a technical standpoint, the federation latency and general wonkiness is real and is why my football bots are running on Lemmy.world despite programming.dev being my preferred instance. Near real-time communication is important during live games where minutes may drastically change the topic.
And while I'm sympathetic to your cause, inertia is a real thing and lemmy.world is competently run, even if I strongly disagree with their VPN restriction.
If you somehow managed to convince the other sports communities to migrate to a common instance I'd happily follow along though, but I find it very unlikely happen. ReadyUser31@lemmy.world is the one primarily in charge of !football@lemmy.world
I had a feeling that would be an issue!
On the one hand, football@soccer would be a good compromise.
On the other, we're right, the Americans are wrong. Simple as that. So I sympathise with the lack of willingness to compromise on the matter.
Americans are wrong
Don't forget Australia, NZ, S Africa, and a few other places like Japan.
like this
aasatru likes this.
I'm sure the Irish call it football when they speak English, but what about in Irish? If Google translate to Irish is trustable,
English to Irish
Football = Peil
But also
Soccer = Sacar
So maybe there's two accepted variants. But where does Pail come from anyway? Let's translate it back to English:
Peil = Very big potato
So most of the world plays football, some strange corners of it play soccer, and the Irish play very big potato.
I'd love if a native speaker could confirm this.
#Irish #Gaeilge #football @gaeilge@a.gup.pe @football@a.gup.pe
If a moderator is from a different instance, can they effectively moderate? So isn't it a problem if all moderators would be from different instances?
I remember after the exodus community discovery in Lemmy was hard, and it made sense to create instances like these. But nowadays with Lemmy Explorer and with multiple community promo communities I think it's not really hard to find the topics you are interested in.
I would assume the "rendezvous" instance would collect all posts from all communities it is subscribed to, and show them to the users as if it came from a single instance. So moderation would be limited to the moderators of the actual instance behind it.
The explorer makes it easier to discover them, but would be even better if that's automated.
If a moderator is from a different instance, can they effectively moderate?
Yes, I haven't had any issue moderating things from communick.news, even on communities that are not here.
But nowadays with Lemmy Explorer and with multiple community promo communities I think it’s not really hard to find the topics you are interested in.
This approach does not address two issues that would be resolved by separating "community instances" from "people instances":
- Centralization of communities around the big instances, creating a "too big to fail" scenario. Last I checked, more than half of the top 100 communities are on LW.
- Political/Ideological differences among larger instances causing needless fragmentation of the communities. E.g, there were discussions before about moving communities from .ml because some people didn't want to be associated with the Lemmy devs. Some were in favor, some were against. By having the communities on neutral ground, not only this whole issue is sidestepped, it also makes it easier for both sides of the table to be able to join one single community and make the overall fediverse stronger.
I don't like this kind of community/user instance because 2 instances have to deal with the same problem. E.g. a rogue user can troll on most community instances until they are banned by their user instance.
The instance fragmentatios is not as big issue as it's quite easy to create new accounts. There was a thread about this some days ago here, I also use different accounts on different instances for different topics.
I understand your concerns with moderation, but I don't see how what I am proposing would make things more difficult?
What would stop a troll to create different accounts on all the other different instances, or create another account whenever they get banned?
but I don’t see how what I am proposing would make things more difficult?
Now when a user reports a troll, the report goes to the moderators of the community. But in special cases the admins of the user instances should deal with banning. So the admins of the community instances have to deal with reports, but the solution is at the hand of the user instance admins. It's the same as dealing with users from other instances, but an edge case.
My recommendations would be something like this: (I'm just a random user, so it's just my point of view)
- Shut down the fully inactive instances. Noone will even even notice it
- Merge the semi active communities to a handful of instances, like sports and technology... . I've seen active communities move instances, it would be possible, take a look how !europe@feddit.de migrated to !europe@feddit.org. Give enough time for subscribers to notice and subscribe to the new one.
- Allow registration of moderators on these instances, so they can work around the current limitations of moderation tools. Maybe an invite only solution or something like this.
- You could find help more easily if you look for admins for 3-4 instances instead of for 18 instances.
This would be useful for you and other admins, because you would have to admin much less number of instances. They would be still considered small instances, compared to big one, so you still not at the "too big to fail" level. For users it would help community discovery, there are overlap between followers of similar topics, e.g. I have friends who follow both European football and NBA at the same time, I read both selfhosting related topics and about general tech support, etc...
- I am not planning to close any instances. I am not working on them based on their current activity, but I am keeping them for a scenario where a mass migration away from Reddit actually happens.
- When I say admins only, that can be extended to moderators as well.
Yes, I haven’t had any issue moderating things from communick.news, even on communities that are not here.
Reports still do not federate, that's the main issue with federated moderation
If a moderator is from a different instance, can they effectively moderate? So isn’t it a problem if all moderators would be from different instances?
Reports are still not federated
I personally am not a huge fan of this idea. Instances are at the end of the day communities of their own in a way. One community may want to discuss a topic in one way and another community may want to discuss it in another way. This seems to be a way to centralize all discussion around a topic in one community, but we should rather go for decentralized communities.
But hey that's just my opinion, if others like it, go for it.
You are running an instance that is geared to serve people of an specific region. And I agree that they kind stay between the two extremes of the "group-focused" and "people-focused" instances.
The idea of topic-based instances are for the cases where the culture is more-or-less universal, but it doesn't mean that they should be absolute. So, if you want to talk about Apple stuff in general, !apple@hardware.watch would make more sense, but if you are trying to reach a group of Apple users in your area, then you can have a community on your local instance as well.
for the cases where the culture is more-or-less universal
When is this ever true? The idea of a "universal culture" is exactly what I mean with this encouraging centralization. Even a specific community (subreddit) on a centralized service like Reddit will have a specific culture that is not in line with any "universal culture" (it's likely to be skewed towards whatever culture exists in western english-speaking countries, just to mention an example).
like this
Maeve likes this.
I don't mean universal in the sense of "totalitarian", I mean it in the sense of "large common denominator".
Do you think that the conversation around, e.g, python programming or wood turning techniques will vary so much that it warrants many specific flavors?
it’s likely to be skewed towards whatever culture exists in western english-speaking countries
This is good enough for most people and does not hinder the ability of those that are in the minority to create a different/specialized community.
Centralization/decentralization is a spectrum. No one is proposing to force everyone into a single box. The idea is only to combine efforts for the things that exist in common and to avoid unnecessary redundancies.
Do you think that the conversation around, e.g, python programming or wood turning techniques will vary so much that it warrants many specific flavors?
I don't see why not. Human culture is like a fractal after all :P. At least I don't think we should discourage creating different places for the same topics, because different approaches is part of decentralization.
like this
Maeve likes this.
At least I don’t think we should discourage creating different places for the same topics
I'm not discouraging it. To repeat: the idea is not to push a "there can be only one" mentality, but to set up a system that can work well for the 80% of people who can be satisfied with the median case.
I don't run any instances, but that does seem potentially like a pretty neat idea.
I am really curious about the unexpected behaviors of your instance members though! What are they doing, just treating it as a general instance and not really engaging with the local theme?
like this
Fitik likes this.
I assumed, by "They are not being as used as I expected/hoped.", that the OP was implying, "- by the members of said instances". And that the closed-registration bit was part of the proposal, not the existing state of affairs. I didn't realize their instances were already closed-registration.
Ah, I see. I misread a bit. I thought they were being used differently than expected, not less than expected.
I am not sure what "instance members" you are referring to, here.
The topic-based instances are closed for registration, so there are no users there.
If you are referring to the communick.news instance: it is only configured to have admins creating communities on it and the general instructions are to use fediverser.network as the place to discover communities.
like this
Fitik likes this.
I think this idea is good. I remember seeing those domain names last year. At the time it seemed muddy and uncomfortable to me, since there was a whole scheme of Reddit ghost accounts posting, while I understood there were good intentions behind it, mirrored posts were flooding users' All feed to the point I started blocking a bunch of subs, and many admins defederated.
If we can promote the community first approach where the domain is the space for discussion to be held and stored, with users connecting from across the Fediverse, this would be excellent, a good alternative to massive centralized Lemmy servers. Collective ownership would ensure preservation of content if one or more go offline.
I think there may be a challenge or challenges that you haven't pinned down yet. First is: what problem does this solve?
Second is, how will people know that they are housed under the same roof, so to speak? A small instance dedicated to NBA basketball may be interesting, but if it seems disconnected then people would be wary. Small specialty instances can be shut down without warning for all sort if reasons.A consortium of instances may help with this issue, as long as it is immediately clear through common branding that they are part if the same group.
Third is that different communities have different needs.
like this
Fitik likes this.
Also, if we assume that the entire idea is to have more than one admin, then what change does that actually include?
You now have 3-4 people that can go and randomly delete the whole server instead of 1? Do you know that right now, only 1 person has the credentials to the admin account of whatever server you're talking about?
It seems kind of slimy.
If you don't want the communities, stop squatting them. Having no users seems like just a way to keep costs down so you can hold onto more urls and is bad for the general ecosystem anyways.
It's amazing, there is always someone that will look at other people are doing and find the worst possible take.
I decided to reach out to other admins precisely because I got tired of hearing "you are running all these instances by yourself, who guarantees that you are not going to do something nasty with them or disappear if you lose interest?", even though I'm running all these instances by myself, keeping them up to date, posting regularly on a good number of them, trying to get more people involved for over an year and (most importantly) outliving a bunch of "community-based instances" .
Seriously, this crab mentality is the worst. What a disgrace.
Just coordinate the release of the urls and the transfer of the instance.
I'm skeptical about this since you are squatting on at least 18 urls while trying to get volunteers to create value out of them. Nothing leads me to assume you are being altruistic.
Edit: misattributed something, woops
It seems like you are waiting for the next influx to potentially monetize and trying to hold the most potential instances without putting any work or money into it. It's just my impression.
I also think instances without users are a terrible idea and I'd rather real instances come about organically instead created by people that actually care about the subject.
like this
Maeve likes this.
Just coordinate the release of the urls and the transfer of the instance.
This is exactly what I am offering. I want to transfer these instances to a consortium to own this collectively.
without putting any work or money into it.
Just yesterday I renewed 10 of these domains. That cost me ~400€. I renewed nba.space and nfl.community last month, each cost ~650€.
Running all these instances is costing me ~200€/month.
I'm not even looking to dump these costs on the potential new co-owners, this is why I said that I don't mind keep running them.
It seems like you are waiting for the next influx to potentially monetize
First, we'd have to argue the implication. You are implying that any attempt at building anything that is financially sustainable is immoral, something that I said many times is completely misguided, and a point of view that is starting now to be shared by other prominent figures in the Fediverse.
Second, I am offering the instances to be co-owned precisely to assuage those concerns. By having other admins co-owning the instances, I'd hope that less people would be pushing those accusations against me.
Just yesterday I renewed 10 of these domains. That cost me ~400€. I renewed nba.space and nfl.community last month, each cost ~650€. Running all these instances is costing me ~200€/month.
Thank you for providing the numbers, these domains are quite pricey if you have to pay 1700 € per year on domains alone.
I'm thinking in terms of costs because those could prevent any admins potentially interested in joining you to do so.
Lemmy.ml still runs on a server which costs 80€ per month (lemmy.ml/comment/13507604). A .ml domain name costs 61€ per year on gandi.
Your hosting costs are 2.5x higher, your domain costs are 27 times higher.
Maybe you'll find other admins who agree with you that it's worth it.
You are asking a consortium of different admins to collectively own those instances with you.
If the idea is that those other admins can take over should something happen to you, then it makes sense for them to assess whether the whole project is viable from a financial perspective, otherwise it would just lead to them closing most of the instances, which is just the same as them not owning those instances with you.
There are plenty of ways where people can enter into an equity agreement without having to pay directly with money.
can take over should something happen to you
Are you trying to get rid of me? Then why are you arguing as if (a) something bad might happen to me or (b) I am somehow unable/unfit to manage this?
No matter what I do/offer/propose, you will always try to find an excuse to rationalize your unwillingness to contribute to what I am doing, like I'm failing some type of BS purity test.
Are you trying to get rid of me? Then why are you arguing as if (a) something bad might happen to me or (b) I am somehow unable/unfit to manage this?
I wish you the very best (as I generally do to all admins), but at the same time I'm doing some due diligence. As you mentioned earlier in this thread, other instances have disappeared overnight, and one way to prevent this is to have multiple people in charge.
No matter what I do/offer/propose, you will always try to find an excuse to rationalize your unwillingness to contribute to what I am doing, like I’m failing some type of BS purity test.
No matter what people tell you (you've got plenty of comments in this thread which are not from me), you do not take them into account.
This thread is 2 days old, it was the week-end, maybe people will jump in tomorrow or later, but at this very moment, it does not seem like you were able to convince anyone to want to join you in managing a pool of instances for 6500€ per year.
I feel like I have been discussing this with you several times. You have a certain vision on how to manage those instances, but until you find other people sharing it with you and wanting to work on this together with you, you won't convince people to move communities to your instances.
Sorry, I can not let go of this. I don't know if you realized that the whole reason that I am doing this is because you kept pushing this idea that you'd be more than willing to contribute to different instances and that the only thing that is stopping you is that you'd be worried about me being the only person.
Even with me telling you that I have other people to take over my operations, you were doubting me.
Now that I am actually going forward and offering to get more people onboard, while asking for NOTHING in return, you are putting this bullshit, pretending to be worried about price of domains.
What you are doing is just Concern Trolling, and I am frankly tired of this. You have put no Skin in the Game, yet you continue to find ways to rationalize your senseless idea that this is going to grow magically without getting people to put significant resources at stake.
So are you willing to give up ownership of the url and have the instance be transfered to someone else's hardware?
Maybe I misunderstood where you are going with this.
To be precise, I'm willing to give up some ownership. I still want to participate in its governance.
someone else’s hardware?
If a new consortium is formed and if the collective decision is to move it, yes. If the decision is to keep as it is, also fine.
Please, spare me from the cheap rhetoric.
I've been for over an year offering alternatives, attempting to bring actionable proposals to the table, putting resources on the line (go take a look at the matrix room and you may find me telling people that I registered selfhosted.forum and I wanted to give it for free to the /r/selfhosted mods) and every time there is any type of push for concrete effort, I am met with apathy at best and suspicion at worst.
Everyone keeps crying about Zuckerberg/Threads/Venture Capitalists/Spez, but when push comes to shove no one wants to mobilize and put up a proper fight.
It's tiring and frustrating.
Community collections should be a thing. Something like /cc/Technology could pull in lemmy.world/ other instances and collections of communities. It makes it easier if one instance dies, an instance de-federates itself, or just wanting to consolidate all the different /c/Technology
communities across instances.
It would also be nice if communities had the option to vote on their admins once in a while. Having individuals lord over different communities is a problem in reddit.
That's an argument that is:
- application specific
- agency-removing (only Lemmy devs can do something about)
- orthogonal to the stated problem
Excellent! Thanks. Ill take a look at it sometime. github.com/LemmyNet/lemmy/issu…
Last time I checked, there was still discussion on how people want this to work. Because its easy to say, but hard to get everyone to agree.
New users to lemmy usually aren't going to join communities if they can't register there. And people who are really invested in a topic will want to have that domain for their account. You're cutting off a lot of the users that would grow your communities.
I don't mind the idea of a collective to handle a bunch of instances, but I feel like you're going about it the wrong way. When the same person make a bunch of instances about a variety of topics, it looks as if they aren't that invested in any specific community. From my experience, the most active communities start off with a few people who care almost obsessively about that topic.
Also the idea that communities can be 'neutral ground' doesn't make sense to me. People will leave or join based on how the admins and mods run them, whether or not the users are hosted there. In some situations it might work out fine, but if anyone thinks it's caused by how you're running your sites, they may defederate from the whole collection.
aren’t going to join communities if they can’t register there.
Why?! The whole point of federation is to let people join communities even when they don't have an account in the same server.
the most active communities start off with a few people who care almost obsessively about that topic.
There are two different, orthogonal issues here:
- people that are looking for a community in a niche interest, do not find it, and go back to Reddit.
- people that are in a big instance and create (or sometimes, recreate) a community for a popular topic. This happens quite often and not because they were not satisfied with the existing communities, but just because they could not find them.
The idea of having topic-specific instances is an attempt to mitigate issue #2.
People will leave or join based on how the admins and mods run them, whether or not the users are hosted there.
Not my experience. A few examples:
- No one complained about the mods from !linux@lemmy.ml, yet I've witnessed endless discussions about moving away from lemmy.ml.
- Beehaw defederated from LW, so this forced users of these instances to "choose" between the communities and/or create accounts on both of them if they wanted to keep following the whole conversation.
- Personally, I do not want to join or participate extensively in communities that are on LW if we have a topic-specific instance for it. I know that I am not the only one.
Why?! The whole point of federation is to let people join communities even when they don't have an account in the same server.
For people who've used lemmy or the rest of the fediverse yes, but most people don't know that yet. If someone shares a post from your site with their friends or a facebook group, they're not going to look into how lemmy works to sign up elsewhere.
- people that are looking for a community in a niche interest, do not find it, and go back to Reddit.
- people that are in a big instance and create (or sometimes, recreate) a community for a popular topic. This happens quite often and not because they were not satisfied with the existing communities, but just because they could not find them.
The idea of having topic-specific instances is an attempt to mitigate issue #2.
I'd prefer it if topic specific instances were more popular too. I just think that letting people making accounts tied to their favorite topics would get more people interested in joining them.
I feel a technical solution like federation pulling in lists of communities with would help more with discoverability.
Not my experience. A few examples:
- No one complained about the mods from !linux@lemmy.ml, yet I've witnessed endless discussions about moving away from lemmy.ml.
I'm not sure how that goes against what I said. That's mostly people disliking the admins.
- Beehaw defederated from LW, so this forced users of these instances to "choose" between the communities and/or create accounts on both of them if they wanted to keep following the whole conversation.
Similar issues could happen even if users are separate from the communities. Beehaw could defederate your instances, and lemmy world could defederate programming dev or something, and people would need other accounts if they want to see everything.
- Personally, I do not want to join or participate extensively in communities that are on LW if we have a topic-specific instance for it. I know that I am not the only one.
Me too. I usually avoid lemmy world communities unless there isn't an active community elsewhere.
I just think that letting people making accounts tied to their favorite topics would get more people interested in joining them.
Could be, but I guess we now just arguing opinions. And given that I am personally hold the opposite view and I don't want to be be identified by my interests, I am not going to push for something that I fundamentally disagree with.
The whole point of federation is to let people join communities even when they don’t have an account in the same server.
[citation needed], because it disagrees with the "whole point" I can find
Why?
That just locks communities off. Wh ich you could readily do before Lemmy, just host a forum. Discourse is a pretty damn cool software for it. Close registrations, close visibility, and allow users in on a per-user basis. That's also a lot how Tildes works, and I remember people here don't like that very much.
like this
aasatru likes this.
Now it makes even less sense.
So instead of one admin being able to take it all down we have multiple, and we also don't allow local users. But we have multiple admins, so these instances would be uniquely able to process very large numbers of users on account of having more than one admin? There's still the problem of course of how to handle someone being an admin on a technical level, and I don't see a solution to that. Could go and notarize shared ownership of a bare metal server I suppose?
But still, what's the point? It doesn't improve anything, in fact it actively makes it worse. If you want communities to be resistant to server removal, you'd need a way to... federate the community. So that even if the original instance is gone, everyone keeps interacting with their local federated community-copy and these keep federating to each other (copy). As in, there's no original any more, but good luck keeping all of that consistent. 😅 In particular because that still doesn't solve the problem because now you got people able to either moderate each others copy (good luck with that power trip bonanza) and no central admin to remove the mods, or they cannot moderate each other, in which case good luck figured out how to block on a per-post basis depending on laws in your particular country getting the content federated over.
Dear Lord, I had no idea one could be so lost and still be so confident when making an argument.
I am not trying to be mean, it's just that you are arguing against things that are completely made up.
So instead of one admin being able to take it all down we have multiple
Shared ownership is a policy to prevent single-points-of-failure. Every large-ish instance has multiple admins. This is even a requirement in the Mastodon Covenant: your instance is only listed on the joinmastodon site if the instance has at least two people who can independently access the admin panel.
Could go and notarize shared ownership of a bare metal server I suppose?
You don't need any of that. As long as the collective has control over the domains and that backups are created and available for everyone, admins could simply move the instance to a new place with a new deployment and a DNS change.
It does not mean that every admin needs to have direct access to the server, and it does not mean that the server will go down if one of them goes rogue. Every minimally competent organization has security processes in place to avoid that.
But we have multiple admins, so these instances would be uniquely able to process very large numbers of users on account of having more than one admin?
I can't even imagine how you go to this non-sequitur. The idea of having multiple admins is only to ensure that these instances are not under control of a single individual and would not be represent a systemic risk to the overall Fediverse.
If you want communities to be resistant to server removal
Another non-sequitur.
So that even if the original instance is gone, everyone keeps interacting with their local federated community-copy
How is that working out for the communities on feddit.de, and the many other instances that disappeared in the last year? Did you notice they are gone?
In particular because that still doesn’t solve the problem because now you got people able to either moderate each others copy
Another non-sequitur. Are you sure you have a clear understanding of how federation works?
like this
aasatru likes this.
Are you sure you have a clear understanding of how federation works?
I'm not sure they do, I was confused by their comment as well.
like this
aasatru likes this.
Ah, sorry if that wasn't clear, the entire second half was theoretical about a better way of doing this.
A type of federation where there is no "home" for a community any more. It exists equally on all servers, so any being removed would have ~0 effect.
I mentioned that basically because I feel that's a much better solution to the problem than shared ownership + locked registrations. Sorry if that wasn't clear, not my primary language.
A type of federation where there is no "home" for a community any more.
This is not federation anymore, but an entirely different architecture. Nostr works like this, but it also has its flaws.
- Your key is your identity. If it's lost or stolen, you can not revoke it. That alone will make it virtually impossible to be used as an official application protocol for any organization.
- Usability is even worse than anything on ActivityPub
- Moderation is entirely punted to the end user.
- (not technical, but relevant) it is completely dominated by Bitcoin maxis
Also, maybe it’s because I’m a US citizen but I don’t get what so problematic about individualism and allowing users the ability to drive their own experiences.
You mention the keys that’s still under user control as if instances have not gone down with users identities, content and social graphs
Usability worse than anything on AP that’s very broad. Go point for point with comparisons
You can filter out any content related to Bitcoin.
If you have examples of relays differentiating themselves based on moderation policies, it would be appreciated. Not just "we are extreme free speech holders" vs "we pay attention to some laws here". What nostr relay is actually running a strict filter, or do any type of analysis on the message content beyond "payment only"?
as if instances have not gone down with users identities.
If instances go down, there are still lots of possible backups: someone can recover the domain name and regenerate keys (or even recover a database copy). If someone loses a private key, there is no turning back. The fact that (some) poorly managed system are not recoverable does not mean that it is as fragile as something as nostr that gives up completely on making it.
allowing users the ability to drive their own experiences.
The same can be achieved on ActivityPub, no new protocol is needed for that.
Also, this is not matter of individualism, but of UX. It's "nice" when users have the ability to make decisions on their own, but it is terrible when they have to make all decisions on their own to get started.
Nos.social is one, there is github.com/atrifat/nostr-filte… amongst other tools integrated into some relays.
You said that like that’s been reality, I’m not going based on simply what’s possible but what’s happened when instances suddenly shutdown
If the same came be achieved why hasn’t it been? It is a matter of individualism. People often see instances as communities, I don’t agree with this assessment with the exception of coop and special interest instances.
Looks more like you are interested in more influence power, and control for yourself.
What qualifies you to be in a leadership position that directly affects content control?
Your instances are not being used the way you wanted, so you propose structural and organizational changes that, suprise, benefit your administrative influence from your instances.
You're so focused on the details of your solution, you don't seem to be holding or acknowledging any objective perspectives.
benefit your administrative influence from your instances
They are not going to be "my" instances.
acknowledging any objective perspectives.
Oh, I thought it was pretty clear: my objective with these instances have been to build the infrastructure necessary to get people out of Reddit. I want to gain from the growth of the network, where I expect to profit from getting customers on my hosting business.
I don't need/want to make money out of these instances, I am just commoditizing the complements.
like this
aasatru likes this.
ITT: People who don't understand IAM or how to build a healthy federated structure. There should be identity services and instances just to host content separately. This way a spammer from a service won't de-federate content from everyone else and there could be easier moderation splitting the task between users and the comms.
lol I think you are right about this. You'll never get these lemmitors to see it i guess.
like this
aasatru likes this.
there could be easier moderation splitting the task between users and the comms.
On the other hand, for some communities moderation of the communities and the members are specific and should not be generalized.
Beehaw is an example that comes to mind, lemmy.ml as well
Even though the community is contained the cloud resources should still be split in two between identity and operations to be in alignment with all the industry best practices and potential for scalability. Remember the unix philosophy is do one thing well.
Beehaw should operate their own Beehaw fediverse IDP (Identity provider) for the users to sign in with, that would manage their tos agreements, privacy policies and user based security. Separately they should operate their Lemmy server which hosts pictures and links organized by communities. They could just use a single IDP for their instance and have the same experience as now only better with better architecture.
Source: I am a cloud services architect.
I'm familiar with IAM concepts, and indeed having a separate IdP and content instances would be a better architecture.
However the reality is that the platforms (Lemmy, Mbin, Piefed) are being developed by very small teams (Piefed is a 2 or 3 people team, and Lemmy might be around 5).
Lemmy is focusing on features delivery (join-lemmy.org/news/2024-09-11…), which could help the platform grow more than a new IAM architecture.
There will probably be a point in time where performance will require a rework, but at the moment, it does not seem to be a priority
But nothing needs to be done to meet this OPs desires for community only instances that are well federated with other instances (IE at least one user is subscribed to each community on each instance). This way those admins just manage those communities and Beehaw and Lemmy.ml can run their combined servers.
The users and the subscribed to communities cause nearly all the load on the servers too, it is a way to keep costs down.
Who would manage all of those community instances?
The current setup works well with the limited number of admins and mods we have overall. I'm regularly looking for mods on communities I mod, there isn't so many of them (e.g. !showsandmovies@lemm.ee )
Also, with the federation currently being broken, mods would need to have an account on each community to be able to get the reports: github.com/LemmyNet/lemmy/issu…
Regarding costs, the cost of these community instances suggested by OP is around 6500€ per year, so 540€ per month (lemmy.world/comment/12595221)
It currently costs 80€ per month to host lemmy.ml, which is the 4th most active instance with 2300 monthly active users
I mean that is what is is asking, he is looking for a team of people to manage the instances in this post. That is what this post is about, he is looking for a team of people to run them as admins while maintaining his (imo correct) vision for how it should be structured.
I forgot to mention the biggest fact- the users are where all the risk are. If people are just posting pictures to your instance of communities you have minimized risk as you can just gatekeep what is posted. Once you allow users in who can then post on other federated communities you take on a lot more risk.
They are not being as used as I expected/hoped.
Have you considered it's because of this?:
My only requirement: these instances should remain closed for registrations and used only to create communities.
I wouldn't run an instance that didn't allow users to sign up as it would impede growth and uptake.
It also would have the interesting effect of pushing a lot of the load onto other instances, which doesn't seem true to the Fediverse spirit.
like this
aasatru likes this.
I was the only one who could create communities on them.
Typically the only one who can create magazines/communities are local users of the instance. With registration closed, that means only you (or the new instance owner) would be able to do this.
Though one can get around this with some bot magic ( lemmit.online had a magazine that was dedicated to new sub/magazine requests - once someone made the request, the bot would create and own the magazine but add the requestor as the moderator )
Do you intend to have open magazine creation on these instances or would that still be restricted to the owners of the consortium?
Objection! Hehe... No, wait. Really, I see a problem...
If registration are closed, mods would be exclusively from outside. And, since reports are not federated, this communities would be prone to difficulties for moderation. Unless reports are correctly federated, I don't think this is a good idea. And, even if you were to open registrations only for mods, we would have only moved the inconvenience to this (who wants to have so many accounts, really?)
There's also the problem with centralization of domain names under you. I don't know you, and perhaps you're well intended.. So, it's fine for the most part, let's just assume that's okay. Now, what happens if you had an accident or decided to go live in a farm? Without domain name renewals, etc. all communities would be in trouble. There's centralization in the shape of a single point of failure.
I can't see this happening even if the domain names are cool.
And, leaving disadvantages aside. What's the point on this? Can you name any advantage?? I agree that it would be more ordered and I like that. But it's quite subjective, and hardly anything huge to really break the inertia or status quo of things as they're now...
Thanks for the intentions. Let's focus on some new ideas, they'll come...
If registration are closed, mods would be exclusively from outside. And, since reports are not federated, this communities would be prone to difficulties for moderation. Unless reports are correctly federated, I don’t think this is a good idea.
It wouldn't be that difficult to write a little bot that can keep track of each moderator is on each community, and make the report on the instance of the moderator directly.
centralization of domain names under you.
The idea is to have the domains under the control of this collective.
Can you name any advantage??
- Less concerns about political fights among "user" instances affecting communication among communities
- Less tribalism regarding "what community is the canonical one". Users and admins are of course completely free to create their own communities, but for the majority at large they could just look at the topic-based instance and think "ok, that one will be a good entry point".
- Less load on all servers. LW has a good chunk of the most active communities, so all activity from other users end up going through that. More instances with cleaner separation => better load balancing.
- Easier content discovery: no matter if users go to a small or big instance, they can be pointed to the different servers to browse according to their interests.
hardly anything huge to really break the inertia or status quo of things as they’re now…
As it is right now, yes. But I am working for a potential future where we can migrate 10, 20, 50 times more users than we already have. Consider that I am also working on a tool to help people migrate from Reddit and in making some modifications on the Voyager app to integrate automatic migration from Reddit to Lemmy. If the gates finally open, this will be very much needed.
Riksdagspartiernas inställning till Chat Control. Kamratdataföreningen Konstellationen har skickat ut en enkät med frågor till samtliga riksdagspartier om deras inställning till Chat Control, övervakning och personlig integritet.
Jag är ordförande i Vänsterpartiet Guldheden-Johanneberg-Krokslätt. En av Göteborgs större lokala partiföreningar. Men långt ifrån den största. Men större än Angered där Kristofer Lundberg är ordförande. Jag delar Kristofer Lundbergs åsikt om att PFLP precis som PKK bör tas bort från terrorlistan. Båda två finns med på EU: sådana listor idag.
blog.zaramis.se/2024/09/27/ord…
FediForum September 2024 Demo Videos
Speed demos made at FediForum September 2024, the online unconference that brings together the people who move the open social web and the Fediverse forward.
Also available on YouTube
FediForum September 2024
Speed demos from FediForum September 2024. More info: https://fediforum.org/2024-09/Spectra Video
like this
johannesalbretch likes this.
I'd say pretty much all of those are worth a look!
Personally I'm curious how Bonfire and the Open Science Network will develop. Bandwagon also seems to have a lot of potential.
Would be curious to hear if anyone have tried using Quiblr! It's not really for me I think, but it does look like an interesting service.
like this
Fitik likes this.
Last Week in Fediverse – ep 85
It’s been an eventful week in the fediverse, with the Swiss government ending their Mastodon pilot, the launch of the Social Web Foundation, Interaction Policies with GoToSocial and more!
Last Week in Fediverse – ep 85It’s been an eventful week in the fediverse, with the Swiss government ending their Mastodon pilot, the launch of the Social Web Foundation, Interaction Policies with GoToSocial and more!
Swiss Government’s Mastodon instance will shut down
The Swiss Government will shut down their Mastodon server at the end of the month. The Mastodon server was launched in September 2023, as a pilot that lasted one year. During the original announcement last year, the Swiss government focused on Mastodon’s benefits regarding data protection and autonomy. Now that the pilot has run for the year, the government has decided not to continue. The main reason they give is the low engagement, stating that the 6 government accounts had around 3500 followers combined, and that the contributions also had low engagement rates. The government also notes that the falling number of active Mastodon users worldwide as a contributing factor. When the Mastodon pilot launched in September 2023, Mastodon had around 1.7M monthly active users, a number that has dropped a year later to around 1.1M.The Social Web Foundation has launched
The Social Web Foundation (SWF) is a new foundation managed by Evan Prodromou, with the goal of growing the fediverse into a healthy, financially viable and multi-polar place. The foundation launches with the support of quite a few organisations. Some are fediverse-native organisations such as Mastodon, but Meta, Automattic and Medium are also part of the organisations that support the SWF. The Ford Foundation also supports the SWF with a large grant, and in total the organisation has close to 1 million USD in funding.The SWF lists four projects that they’ll be working on for now:
- adding end-to-end encryption to ActivityPub, a project that Evan Prodromou and Tom Coates (another member of the SWF) recently got a grant for.
- Creating and maintaining a fediverse starter page. There are quite a variety of fediverse starter pages around already, but not all well maintained.
- A Technical analysis and report on compatibility between ActivityPub and GDPR.
- Working on long-form text in the fediverse.
The SWF is explicit in how they define two terms that have had a long and varied history: they state that the ‘fediverse’ is equivalent with the ‘Social Web’, and that the fediverse only consists of platforms that use ActivityPub. Both of these statements are controversial, to put it mildly, and I recommend this article for an extensive overview of the variety of ways that the term ‘fediverse’ is used by different groups of people, all with different ideas of what this network actually is, and what is a part of it. The explicit exclusion and rejection of Bluesky and the AT Protocol as not the correct protocol is especially noteworthy.
Another part of the SWF’s announcement that stands out is the inclusion of Meta as one of the supporting organisations. Meta’s arrival in the fediverse with Threads has been highly controversial since it was announced over a year ago, and one of the continuing worries that many people express is that of an ‘Extend-Embrace-Extinguish’ strategy by Meta. As the SWF will become a W3C member, and will likely continue to be active in the W3C groups, Meta being a supporter of the SWF will likely not diminish these worries.
As the SWF is an organisation with a goal of evangelising and growing the fediverse, it is worth pointing out that the reaction from a significant group within the fediverse developer community is decidedly mixed, with the presence of Meta, and arguments about the exclusive claim on the terms Social Web and fediverse being the main reasons. And as the goal of the SWF is to evangelise and grow the fediverse, can it afford to lose potential growth that comes from the support and outreach of the current fediverse developers?
Software updates
There are quite some interesting fediverse software updates this week that are worth pointing out:GoToSocial’s v0.17 release brings the software to a beta state, with a large number of new features added. The main standout feature is Interaction Policies, with GoToSocial explaining: “Interaction policies let you determine who can reply to, like, or boost your statuses. You can accept or reject interactions as you wish; accepted replies will be added to your replies collection, and unwanted replies will be dropped.”
Interaction Policies are a highly important safety feature, especially the ability to turn off replies, as game engine Godot found out this week. It is a part where Mastodon lags behind other projects, on the basis that it is very difficult in ActivityPub to fully prevent the ability for other people to reply to a post. GoToSocial takes a more practical route by telling other software what their interaction policy is for that specific post, and if a reply does not meet the policy, it is simply dropped.
- Peertube 6.3 release brings the ability to separate video streams from audio streams. This allows people now to use PeerTube as an audio streaming platform as well as a video streaming platform.
- The latest update for NodeBB signals that the ActivityPub integration for the forum software is now ready for beta testing.
- Ghost’s latest update now has fully working bi-directional federation, and they state that a private beta is now weeks away.
In Other News
IFTAS has started with a staged rollout of their Content Classification Service. With the opt-in service, a server can let IFTAS check all incoming image hashes for CSAM, with IFTAS handling the required (for US-based servers) reporting to NCMEC. IFTAS reports that over 50 servers already have signed up to participate with the service. CSAM remains a significant problem on decentralised social networks, something that is difficult to deal with for (volunteer) admins. IFTAS’ service makes this significantly easier while helping admins to execute their legal responsibilities. Emelia Smith also demoed the CCS during last week’s FediForum.The Links
- All the speed demo videos of last week’s FediForum are now available on PeerTube.
- Evan Prodromou’s book about ActivityPub, ‘ActivityPub: Programming for the Social Web‘ has officially launched.Lemmy Development Update.
- PieFed’s Development update for September 2024.
- A tool to make sure you see all replies on a fediverse posts (and an explanation on how it differs from FediFetcher).
- A work-in-progress Rust library for ActivityPub.
- The German Data Protection Office updated their Data Protection Guidelines for running a Mastodon server.
- The Revolution Will Be Federated – WeDistribute.
- This week’s updates for fediverse software.
That’s all for this week, thanks for reading!
fediversereport.com/last-week-…
like this
Someplaceunknown likes this.
Did a top NIH official manipulate Alzheimer's and Parkinson’s studies for decades? (alt: Eliezer Masliah's papers under investigation)
A Science News report about Dr. Eliezer Masliah (who held a highly important role at the National Institute of Aging), a 300-page dossier composed of misconducts at his lab, as well as followups... Featuring everyone's favorite research integrity sleuths (Elizabeth Bik, Mu Yang, "Cheshire", ...) and more.
Post URL points to archive.org due to soft paywall on Science News. Here's the original link
like this
originalucifer and ShaunaTheDead like this.
The fraud surrounding Alzheimer's research continues... Not too long ago the fraud was related to amyloid (archive version). That article was even written by the same author and features many of the same investigators.
I work in Pharma R&D (on the manufacturing side) and the company I work for has run trials for Alzheimer's products based on research that has since been found to be fraudulent. As a published scientist myself, I would like to think that this level of manipulation and fabrication is the exception rather than the rule. However, I do think it is worth asking at this point what it is about Alzheimer's research in particular that has led to this being so prevalent and, more importantly, so impactful. Basically, how did it go so far before anything was caught?
I suspect at least part of the answer is due to the large influx of money into the field. Researchers were tripping over themselves to earn those grants and then, once they had them, produce results to keep them. I am not in academia, so I don't have great insight into the NIH, NIA or their processes, but this should be a wake up call to put up a certain amount of guard rails.
I have a suspicion it's not just an Alzheimer's issue but rather quite systemic to lots of competitive fields in academia... There definitely needs to be guard rails. I think the sad thing with funding is... these days you have to be exceptionally good at grant writing to even have a chance of getting into the lottery, and it mostly feels like a lottery with success rates in the teens... and apparently no grant=no lab, no career for most ppl (seriously why are most PI roles soft money-funded anyway). Hard to not try and cut the corners if there's so much pressure on the line
Not to mention, apparently even if you are a super ethical PI who wants to do nothing wrong, if the lab gets big enough, there might eventually be some unethical postdoc trying to make it big and falsify data (that you don't have time to check) under your name so... how the hell do people guard against that.
I'm honestly impressed how science is still making progress with all of these random nonsense in the field
Reading about this is making me feel sick. It's so sad how many people's lives have been negatively affected because of this Masliah's dishonesty. I think people who fake research like this belong in jail.
Sadly I think low key dishonesty is even more prevalent than what this guy did - the way we dole out money encourages researchers in every field to cherry pick data so that they can keep getting funding.
It's definitely way more prevalent. There actually is this post from Retractionwatch just a few days ago too. This is kind-of a systematic issue induced by how scientific funding & the system works...
My current PI is actually co-mentoring a student who was studying scientific fraud, but the problem is... being a fraud researcher is apparently a really good way to alienate a lot of people, which ensures you never make it in academia (which is heavily dependent on networking/knowing people)... so I don't know how many ppl would seriously study this.
Tasmota Nous Sockets mit Python verwalten
Erster Schritt in der Häusle-Tech war es, die meisten Sachen im Haus an Tasmota Nous A1T Steckdosen anzustecken. Das Besondere an diesen Dingern ist, dass sie eine eigene IP Addresse haben, mit der man sie in Home Assistant einbinden kann oder halt auch mit einem sehr einfachen Python script steuern kann.
Erstmal das Script:
#!/path/to/.venv/bin/pythonimport sysimport requestsimport jsonsys.path.append("/path/to/.venv/lib/")SOCKETS = [ {"ip": "192.168.1.2", "alias": "Socket One (Mikka's Room)"}, # Add more sockets with IP addresses and aliases as needed]def control_sockets(command): if command not in ["on", "off", "toggle"]: print("Invalid command. Use 'on','off', or 'toggle'.") return for socket in SOCKETS: ip = socket["ip"] alias = socket["alias"] url = f"http://{ip}/cm?cmnd=Power%20{command.capitalize()}" try: response = requests.get(url, timeout=5) if response.status_code == 200: print(f"Successfully turned {command} socket '{alias}' at {ip}") else: print(f"Failed to turn {command} socket '{alias}' at {ip}. Status code: {response.status_code}") except requests.RequestException as e: print(f"Error communicating with socket '{alias}' at {ip}: {e}")def get_power_usage(ip): url = f"http://{ip}/cm?cmnd=Status%208" try: response = requests.get(url, timeout=5) if response.status_code == 200: data = response.json() today = data.get('StatusSNS', {}).get('ENERGY', {}).get('Today', 0) yesterday = data.get('StatusSNS', {}).get('ENERGY', {}).get('Yesterday', 0) total = data.get('StatusSNS', {}).get('ENERGY', {}).get('Total', 0) return today, yesterday, total else: print(f"Failed to get usage data from {ip}. Status code: {response.status_code}") except requests.RequestException as e: print(f"Error communicating with socket at {ip}: {e}") return None, None, Nonedef show_usage(): total_today = 0 total_yesterday = 0 total_all_time = 0 for socket in SOCKETS: ip = socket["ip"] alias = socket["alias"] today, yesterday, total = get_power_usage(ip) if today is not None: print(f"{alias}:") print(f" Today: {today:.2f} kWh") print(f" Yesterday: {yesterday:.2f} kWh") print(f" Total: {total:.2f} kWh") print() total_today += today total_yesterday += yesterday total_all_time += total print("Total usage across all sockets:") print(f" Today: {total_today:.2f} kWh") print(f" Yesterday: {total_yesterday:.2f} kWh") print(f" All-time: {total_all_time:.2f} kWh")if __name__ == "__main__": if len(sys.argv) != 2: print("Usage: tasmota <on|off|toggle|usage>") sys.exit(1) command = sys.argv[1].lower() if command == "usage": show_usage() else: control_sockets(command)
So geht’s:
- Script kopieren und in eine Text-Datei in einem Folder irgendwo ablegen.
- In dem Folder ein Terminal aufmachen und ein Python Virtual Environment anlegen
- (Sich merken wo das ist)
requests
installieren (pip install requests)- Im Script den Pfad im Hashbang und im sys.path anpassen und das Gemerkte oben einfügen.
- IP Addressen und Aliase angeben
- Script ausführbar machen (chmod u+x oder ug+x)
- Script soft in den Pfad verlinken
- Profit
Und so schaut das dann aus!
Achtung: Die Tasmota API hat keine zusätzliche Sicherung durch Passwort. Wenn Du also nicht willst, dass Jede:r, der in Deinem Netzwerk ist, Deine Sachen an und ausschalten kann, solltest Du die Dinger in ein eigenes, per ACL gesichertes Subnetz einlegen. In meinem Fall kann nur mein Handy, mein Computer, und der Home Assistant auf dieses Netz zugreifen.
Viel Spaß.
Sapo3, a tui audiobook generator, in Bash
gitlab.com/christosangel/sapo3
- Sapo3 is a suite of scripts-tools that can help the user convert a text
file to an audio file. - It uses the tts-edge API for text-to-speech conversion.
- Big txt files can be easily converted to audio books, using a wide
range of customization capabilities.
When the user runs Sapo3, they will be presented with a menu of options:
o option
: Fix name pronunciation with Fix Names
c option
: Split text to chapters with Chapterizev option
: Convert File to audiof option
: Check every sentence outcome with Fix Audio option.
m option
: Merging Audio Filesp option
: Configuring Preferences
like this
ShaunaTheDead and Noxious like this.
Unauthenticated RCE Flaw With CVSS 9.9 Rating For Linux Systems Affects CUPS
There's been talk of this unauthenticated RCE vulnerability coming with a CVSS 9.9 rating but none of the technical details were publicly known until it was made public just now at the top of the hour. Simone Margaritelli discovered this vulnerability and has shared a write-up around this potentially very impactful Linux vulnerability.This vulnerability, fortunately, doesn't affect the Linux kernel but rather CUPS... The print server commonly used on Linux systems and other platforms.
...
From Attacking UNIX Systems via CUPS, Part I:
"A remote unauthenticated attacker can silently replace existing printers’ (or install new ones) IPP urls with a malicious one, resulting in arbitrary command execution (on the computer) when a print job is started (from that computer)."
...
This remote code execution issue can be exploited across the public Internet via a UDP packet to port 631 without needing any authentication, assuming the CUPS port is open through your router/firewall. LAN attacks are also possible via spoofing zeroconf / mDNS / DNS-SD advertisements.Besides CUPS being used on Linux distributions, it also affects some BSDs, Oracle Solaris, Google Chrome OS, and others.
As of writing there is no Linux fix available for this high profile security issue. In the meantime it's recommended to disable and remove the "cups-browsed" service, updating CUPS, or at least blocking all traffic to UDP port 631.
Unauthenticated RCE Flaw With CVSS 9.9 Rating For Linux Systems Affects CUPS
There's been much speculation since this morning over a reported 'severe' unauthenticated remote code execution (RCE) flaw affecting Linux systems that carries a CVSS 9.9.9 score..www.phoronix.com
like this
ShaunaTheDead, chookity, NataliaTheDrowned2 and imecth like this.
reshared this
Tech Cyborg reshared this.
Looks like a number of patches are landing in Ubuntu to address this: bugs.launchpad.net/ubuntu/+sou…
Update: CUPS Remote Code Execution Vulnerability Fix Available
Remember when printers were connected by a USB cable?
Also, sudo ss -tunlp
to see what ports are listening on your system and which applications/services use them. (Linux)
ss -K
closes dead ports
If you didn't explicitly open a port, ask why it needs to be open (listening). (25, 22, 67, 53,5353)
Make sure what you did open is opened at the right addresses. Ie localhost, 0.0.0.0, 127.0.0.1, etc for the purpose.
Use a firewall and block ALL incoming traffic.
like this
originalucifer and echomap like this.
Wasn't it supposedly affecting ALL Gnu/Linux PLUS others?
That's so weird that my GNU/Linux isn't affected by this vulnerability...
Next time that margarine is going to scream "wolf", I will take it with a grain of salt...
like this
andyburke and fistac0rpse like this.
like this
andyburke likes this.
So if Cups is properly sandboxes this is less of an issue? Still not good but not show stopping
I don't think this is 9.9 worthly
Update:
You can use this to get a shell as the lp service user
Not according to RedHat, who I trust a hell of a lot more than a Phoronix article that cites a blog post.
CVE-2024-47176 cups-browsed (7.5)
CVE-2024-47076 cups-filter libcupsfilters (8.2)
CVE-2024-47175 libppd cups cups-filter (7.7)
CVE-2024-47177 cups-filters foomatic (6.1)
the reporter is a real asshat, judging by their twitter.
first:
then, later:
Yep. Also claimed "it affects all GNU/Linux" while it only really does CUPS and so on.
Just alone full disclosure is a shit thing to do. Do not even mention the part where it was intended as a responsible disclosure.
Wtf???? "All GNU/Linux"???? This guy made me think Linus personally had to descend to Kernel-land and fix perhaps the most horrendous memory bug in existence. But no, surely CUPS IS ON EVERY MACHINE, RIGHT??????????
Fuck you to whoever blew this out of proportion.
Yup, called it: non-mandatory piece of software. Plus you have to have been dumb enough to deliberately forward the port at your router for the general-case attack, and you have to print something (which I do maybe twice a month) for any command injection to take place.
This does need to be patched, since there is some risk if you have CUPS running and another device on your LAN has already been compromised, but it's definitely not the earthshattering kaboom the discoverer misrepresented it as.
No port forwarding needed when the ISP provides a proper IPv6 subnet.
Normal IPv6 router advertisement will then provide a public reachable address for every IPv6 capable device.
But with the size of IPv6 it makes searching for that not really easy, so it only a small attack vector.
They only used NAT as firewall, so without configured port forwarding nothing could be reached with IPv4.
But for IPv6: If you know the IPv6 for any system on the local network it is free available on all ports.
It is the first thing I check when someone asks me to check their network or configure their internet, and only Fritz!Box have a sane default for IPv6 (but to be honest my other experiences are mostly with shitty Vodafone and german Telekom routers so it is a very limited set, and I really hope that most others are better.)
Hmm, never had cups-browsed enabled as I do not need network printing with LDAP or legacy cups. Discovery using DNS-SD/mDNS and driverless printing work perfectly fine without it.
I am not sure if the driverless discovery ever can generate a PPD with arbitrary commands.
like this
ShaunaTheDead, chookity, bacon_saber and imecth like this.
Entirely personal recommendation, take it or leave it: I’ve seen and attacked enough of this codebase to remove any CUPS service, binary and library from any of my systems and never again use a UNIX system to print. I’m also removing every zeroconf / avahi / bonjour listener. You might consider doing the same.
Great advice. It would appear these developers don’t take security seriously.
Mdns is something most people have no idea exists.
Oh, neat, all my devices broadcast all their open ports, services, addresses, hardware and names? Cool!
No.
It depends. If you're using a laptop and say you take it to university or work then you're not on your LAN. You're on someone else's LAN and they may have no interest in trying to stop these types of attacks via any kind of client isolation or it may be incomplete.
I can imagine it's a very normal scenario for university students to have CUPS running and available on all networks as they may need to print at their university.
They're standardised zeroconnf protocols. Apple was part of the early development.
Bonjour is the apple implementation for mDNS.
Avahi is the GPL compliant implementation.
mDNS, llmnr (ms developed), have been known for ages to be vulnerable.
en.m.wikipedia.org/wiki/Zero-c…
*I don't like apple
cups-browsed <= 2.0.1 binds on UDP INADDR_ANY:631 trusting any packet from any source
Well that would explain why I didn't have it installed (although I did have other parts of cups until jwz coincidentally reminded us two days ago that it can all be removed if you don't have a printer.) I clear out anything that opens ports I don't need to be open. A practice I would recommend to anyone.
BRB.
sudo apt purge cups
Done. This should not even be part of baseline Ubuntu desktop. Speaking for myself but I have not had a printer for about 15 years. The paperless office really did become reality.
About 25 years for me.
For most people it's a better option to use a local print shop for the odd times that they need something printed.
More options for printing too.
I mean, OK, it's a vulnerability and there are interesting implications, but this is hardly significant in any pracitcal sense of the word.
the potential victim has to run their system without a firewall, has to print to the printer they've never interacted with before and then the attacker can run shit with whatever the printing system's user id is, which shouldn't be an issue on any reasonably modern distro.
I routinely remove cups and friends from any system I run because I have no need for printing and it bothers me to see it constantly during every system upgrade.
Worse than the exploit, is hearing the struggles the author faced to report it
Twenty-two days of arguments, condescension, several gaslighting attempts, more or less subtle personal attacks, dozens of emails and messages, more than 100 pages of text in total. Hours and hours and hours and hours and fucking hours. Not to mention somehow being judged by a big chunk of the infosec community with a tendency of talking and judging situations they simply don’t know.
Until then it is only a binary sitting in a folder, nothing more.
And cups-browsed can't only be bind to localhost, it would defeat the whole purpose of that tool. For it to be able to find other printers in the network it needs to be bound to a non-localhost-IP address.
So, not much to sandbox
Tor and Tails Merge to Fight Global Surveillance and Censorship
Tor and Tails Merge to Fight Global Surveillance and Censorship
Tor Project & privacy-focused Tails Linux distro join forces to boost global internet freedom and enhance online privacy.Bobby Borisov (Linuxiac)
like this
originalucifer, themadcodger, Oofnik, Unleaded8163, bizarroland, ShaunaTheDead and RV5 like this.
reshared this
Tech Cyborg reshared this.
According to: en.wikipedia.org/wiki/Tails_(o…
Tails was first released on June 23, 2009. It is the next iteration of development on Incognito, a discontinued Gentoo-based Linux distribution.[9] The original project was called Amnesia. The operating system was born when Amnesia was merged with Incognito.[10] The Tor Project provided financial support for its development in the beginnings of the project.[8] Tails also received funding from the Open Technology Fund, Mozilla, and the Freedom of the Press Foundation.[11]
Open Technology Fund
Which is funded by US Congress, and they also funded Signal.
For those do not wish to use privacy-related projects funded by a world government, what is a good (in your opinion) alternative? Both with and without Tor involvement (since US govt funded that too).
Yes I realize encryption, computers and the internet are all also govt-funded, but everyone is free to pick their battles.
like this
sunzu2 likes this.
I think any "privacy oriented OS" is inherently a questionable (kneejerk: Stupid and reeks of stale honey) strategy in the first place.
A very good friend of mine is a journalist. The kind of journalist where... she actually deals with the shit the average person online larps and then some. And what I and her colleagues have suggested is the following:
Two flash drives
- One that is a livecd for basically any linux distro. If you are able to reboot the machine you are using and boot to this, do it. That helps with software keyloggers but obviously not hardware
- One that is just a folder full of portable installs of the common "privacy oriented" software (like the tor browser) supporting a few different OS types.
Given the option? Boot the public computer to the live image. Regardless, use the latter to access whatever chat or email accounts (that NEVER are logged into on any machine you "own" or near your home) you need.
... mostly the other way around?
Theoretically it is possible that a compromised machine could compromise a USB stick. If you are at the point where you are having to worry about government or corporate entities setting traps at the local library? You... kind of already lost.
Which is the thing to understand. Most of what you see on the internet is, to borrow from a phrase, Privacy Theatre. It is so that people can larp and pretend they are Steve Rogers fighting a global conspiracy while necking with a hot co-worker at an Apple store. The reality is that if you are actually in a position where this level of privacy and security matters then you need to actually change your behaviors. Which often involves keeping VERY strong disconnects between any "personal" device and any "private" device.
There have been a lot of terrible (but wonderfully written) articles about journalists needing to do this because a government or megacorporation was after them. Stuff like having a secret laptop that they never even take out of a farraday cage unless they are closer than not to an hour away from wherever they are staying that night.
If you are at the point where you are having to worry about government or corporate entities setting traps at the local library? You… kind of already lost.
What about just a blackmailer assuming anyone booting an OS from a public computer has something to hide? And then they have write access and there's no defense, and it doesn't have to be everywhere because people seeking privacy this way will have to be picking new locations each time. An attack like that wouldn't have to be targeted at a particular person.
Don't entirely discount a project only because it is funded by the US government. Do take that as a big yellow flag, but not auto reject. Better to just asses the project for what it is with caution.
I find it much more likely that the US government has a huge interest in giving the public access to secure communication software that would be unbreakable by surveillance from a typical government. Why? Because those are the governments that are enemies of the US, and where the US is interested in regime change. And the existence of this software is much more influential towards regime change in those countries, rather than being threat to the US.
In fact, these softwares are barely a threat to the US. The US has no issue with them existing because they have such a powerful hold on their state.
Yes. In order to launder your dirty traffic, you need to mix it with lots of other traffic. And you need it to be safe to avoid attribution.
The US military (and various 3-letter agencies) needs the service to be secure, provide strong anonymity, and to include a sea of traffic thats mostly not their own
privacy these days is really hard to achieve
Which is exactly why claims like this should be backed with evidence.
COSMIC Alpha 2 Released
cross-posted from: lemmy.ndlug.org/post/1167059
COSMIC’s Alpha 2 release builds upon that work with functionality built out for Files, additional Settings pages, considerable infrastructure work for screen reader support+, and some highly requested window management features. System76 is ecstatic at the level of excitement and collaboration so far with alpha testers and early app & applet developers, and we look forward to seeing what comes from these new additions.
...
The second COSMIC alpha will be released on September 26th. Those participating in Alpha 1 on Pop!_OS can simply update through the COSMIC App Store to transition. This alpha will be followed by monthly alpha releases until all core features have been built out.
More coverage:
like this
ShaunaTheDead, Aatube and Noxious like this.
reshared this
Tech Cyborg reshared this.
I tried Alpha 1 and it was completely unusable for me (granted I use a tri monitor setup), hopefully this offers an improvement (I will update if it works).
(Edit: it somehow works even worse, now it wont even launch)
like this
sunzu2 likes this.
i tried to daily drive it... but it could not handle having all my normal shit open with out blinking etc, games would not play.
going to give it another try. high hopes for cosmic!
I tried Alpha 1 and it was completely unusable
You mean like an alpha version?
like this
sunzu2 likes this.
like this
Aatube likes this.
Isn't that already true for QT apps on a gtk desktop and GTK apps on a QT desktop?
In my experience, GTK apps feel pretty good on Cosmic, and it has support for automatically theming them with your Cosmic theme. QT apps feel out of place, but this is an issue I've had on every non-Plasma desktop, because I struggle to get theming to work.
like this
MyTurtleSwimsUpsideDown and KaRunChiy like this.
Android uses forked versions of the Linux kernel, based on Linux LTS versions. They added in Rust support in 2019 and most new code since then has been written in Rust in order to avoid memory safety vulnerabilities. And memory safety vulnerabilities have been significantly down since 2019.
Now that upstream Linux is adopting Rust, we should hopefully see a similar results. Though likely slower than Google (they went all-in on Rust) while upstream Linux new code will seemingly be mainly C for the foreseeable future.
like this
KaRunChiy likes this.
Now that upstream Linux is adopting Rust,
is it? From what I read the old kernel developers are really opposing it
Bendable non-silicon RISC-V microprocessor - Nature
Semiconductors have already had a very profound effect on society, accelerating scientific research and driving greater connectivity. Future semiconductor hardware will open up new possibilities in quantum computing, artificial intelligence and edge computing, for applications such as cybersecurity and personalized healthcare. By nature of its ethos, open hardware provides opportunities for even greater collaboration and innovations across education, academic research and industry. Here we present Flex-RV, a 32-bit microprocessor based on an open RISC-V instruction set fabricated with indium gallium zinc oxide thin-film transistors on a flexible polyimide substrate, enabling an ultralow-cost bendable microprocessor. Flex-RV also integrates a programmable machine learning (ML) hardware accelerator inside the microprocessor and demonstrates new instructions to extend the RISC-V instruction set to run ML workloads. It is implemented, fabricated and demonstrated to operate at 60 kHz consuming less than 6 mW power. Its functionality when assembled onto a flexible printed circuit board is validated while executing programs under flat and tight bending conditions, achieving no worse than 4.3% performance variation on average. Flex-RV pioneers an era of sub-dollar open standard non-silicon 32-bit microprocessors and will democratize access to computing and unlock emerging applications in wearables, healthcare devices and smart packaging.
Bendable non-silicon RISC-V microprocessor - Nature
Flex-RV, a 32-bit microprocessor based on an open RISC-V instruction set fabricated with indium gallium zinc oxide thin-film transistors on a flexible polyimide substrate, enables an ultralow-cost bendable and flexible microprocessor.Nature
like this
Lasslinthar and ShaunaTheDead like this.
This could be big. The fact that it's sub-dollar, open-source, AND could be put on FlexPCBs opens up a whole lot of applications.
Only concern is the same as for RFID. They end up so cheap they're tossed into landfills or end up in waterways without a second thought. At least there, people are working on biodegradable solutions: bioplasticsnews.com/2020/01/12…
If the Flex-RV people address sustainability, they could have a real winner.
So it's printed on plastic, how's that for dissipating heat?
We can already make processors pretty small, and we could make them in a lot of different form factors, but heat management is probably the trickiest part.
Go back to stock kernel from surface kernel
publication croisée depuis : sh.itjust.works/post/25672147
Hi everyone!For a while, I've been using the surface kernel for my Surface Go using Fedora 40. The other day I tried to clone my installation with Clonezilla to put it on another old computer I had lying around.
It didn't work and I have a suspicion that it didn't because of the surface kernel so I'm trying to use the stock kernel instead.
After a few modifications, usinge uname -a, this is the output I get:
Linux surface-go-fedora-de-guillaume 6.10.10-200.fc40.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Sep 12 18:26:09 UTC 2024 x86_64 GNU/LinuxWhen using uname -mrs, this is the output I get:
Linux 6.10.10-200.fc40.x86_64 x86_64Can someone with more knowledge than me confirm that everything is back to stock form as I don't know if the SMP PREEMPT thing shoud be there? Doe's anyone know if the Surface Kernel is probably what prevented me from cloning my installation and putting it on another computer?
like this
ShaunaTheDead likes this.
That looks like a normal kernel to me. The mention of the surface is the hostname which comes from /etc/hostname
.
Exactly how does it not work? Does the kernel even try to boot? Tried verbose mode?
You might need to regenerate your initramfs for the new hardware, I think on Fedora that's Dracut? That usually does include machine specific drivers that needs to be available during early boot, but just regenerating it should fix that.
Well to be honest I don’t remember exactly how it didn’t work on my other computer since it was months ago.
I just want to future proof the ability to clone my Surface Go install on any future computer just in case.
Well I’ve tried again with a new image from my Surface Go that I’ve just created with Clonezilla. All I’m getting is a black screen with — on the left side without anything happening.
The computer I’m trying to clone the image on is an old Acer Aspire 5737z.
After a year of operation, Switzerland's government closes its Mastodon instance
TL;DR:
Pilot Project Conclusion: The Swiss Federal Chancellery’s Mastodon instance pilot project, launched in September 2023, has ended as the conditions for continuation were not met.Low Engagement: The six official accounts on Mastodon had around 3500 followers in total, with low engagement rates compared to other platforms like X and Instagram.
User Decline: The number of active Mastodon users globally is decreasing, contributing to the decision to end the project.
Closure: The social.admin.ch instance will be closed at the end of the month.
Article translated in English :
Confederation closes its Mastodon instance
Bern, 25.09.2024 - Since September 2023, the Federal Chancellery has been operating a Mastodon instance for the federal administration.
The pilot project, limited to one year, ends today as the conditions for its continuation have not been met.
As part of their statutory information mandate, the Federal Council and the federal administration have also been communicating on social media for many years and are constantly examining whether platforms not used until now are eligible.
In September 2023, the Conference of Federal Information Services decided to launch a pilot project on the decentralised Mastodon platform.
The Federal Chancellery then opened the social.admin.ch instance, on which members of the Federal Council and departments could manage official accounts. The pilot project was limited to one year.
Mastodon has useful features for government communication. Thanks to its decentralised organisation, the platform is not subject to the control of a single company or to any state censorship. Its source code is open, it complies with data protection and is not driven by algorithms.
Too few active users
On the social.admin.ch instance, three departments managed five accounts, and the Federal Chancellery managed one account for the entire Federal Council. The six accounts of the Confederation had around 3,500 subscribers in total.
On platforms such as X or Instagram, the Federal Council and the Federal Administration reach many more subscribers with comparable accounts.
In addition, the contributions of the Mastodon accounts of the Federal Council and the Federal Administration have rather low engagement rates (likes, shares, comments).
Finally, the number of active users of Mastodon worldwide is once again falling.
The Conference of Information Services of the Confederation therefore considers that the conditions for continuing the pilot project have not been met, and activities on the Mastodon accounts of the Federal Council and the federal administration are suspended as of today.
The social.admin.ch instance will be closed at the end of the month.
Bund schliesst seine Mastodon-Instanz
Aktuelle Informationen aus der Verwaltung. Alle Medienmitteilungen der Bundesverwaltung, der Departemente und Ämter.www.admin.ch
like this
NataliaTheDrowned2 and chookity like this.
How do you mean? It's majorly US centric, and that was part of why Mastodon worked better as a Twitter-replacement here in the EU at first.
But as always, something like Reddit or Twitter benefits from centralization, as far as user interactions go. So slowly, people drift to whatever the single largest alternative is when they leave the current status quo, and in alternative-Twitter-land, this seems to be either Threads or Bluesky, and their cases are fairly incomparable.
Doesn't make it the perfect solution, but like always in Engineering, the perfect solution is rarely the best one.
like this
Fitik likes this.
If you speak Portuguese maybe.
I did some tests here, setting up my browser config to show content preferably in Italian, then German, then Portuguese, then English. It showed something like 5~10 posts in English for each post in Portuguese. (No content was shown in either Italian or German, so odds are that Bluesky doesn't even take the browser config into account.)
Granted, for most Portuguese speakers it should be 7:00 now, so it might be worth repeating the test for the later afternoon, dunno, 18:00 or so. Or in the weekend.
Repeated the test now (Friday, 18:30); same lang settings as above. Couldn't find a single post in Portuguese after rolling across ~30 of them.
x.com and twitter.com are still inaccessible here.
Bluesky seems to work better as an alternative.
Until they run out of VC money.
Then the enshittification happens, to pay the bills.
Yeah, not unlikely. Can't truly know ahead of time of course, but it feels like that would eventually happen. I wish governments in particular had jumped harder onto Mastodon, slowly moving attention there.
But it's probably also difficult to justify, because from their perspective it's just one "someone else's solution" vs another. They'd have to first make their own twitter like fediverse software I bet.
The EU at least is still sticking around, which is cool.
I have to say I'm a believer in slow growth here. It wouldn't be good if one Mastodon server completely dominated; neither would it be good if Mastodon as a software was the only viable alternative. Right now we're in a great spot where a bunch of different solutions are being developed.
I think this development is healthy, and it be depends on slower more organic growth. And it might not be a linear process, but eventually I believe activitypub integration will be as obvious as having an RSS feed. Doesn't matter much if it takes a while to get there.
On that note it would be good if governments didn't just sometimes use Mastodon, but rather integrate activitypub into their actual web sites.
I don’t know where they got their numbers, to me it feels like they needed an excuse to cut costs.
like this
Fitik likes this.
like this
Fitik likes this.
like this
chookity likes this.
FediDB reports that the Mastodon active user count is on the decline the last year, from more than. 1.2 million to 820k thousand. The number seems to maybe stabilize a little, but it appears as a slow decline when studying the last year.
Then again, this is following from a huge bump of new users with the twitter exodus. It's natural that not all will stick around, so a decline in active user now is not so surprising. It does indicate a lack of ability to move the momentum, but it's an open source project with very limited funding, not a venture capital startup. It's not here for explosive growth.
Furthermore, the number of Mastodon users is not a perfect measure. If it was matched by a huge number of users on gotosocial or misskey, it wouldn't really matter. The Swiss should maybe have waited for Threads to federate both ways before deciding to leave on account of limited interactions.
Anyway, they're not entirely wrong to say Mastodon is on the decline. But they're not entirely right either.
Just for the record, I know little about gotosocial, but I've looked into Misskey a fair bit and I think it's irrelevant here.
FediDB data on active users seems off (a low ~12k MAU), but even if the real number is much greater, most are on the flagship instance (misskey.io) which has multiple CSAM censures on fediseer.
Put another way, it's almost counterproductive to include Misskey in these topics because simply federating with its biggest instance could be a liability for most 1st world western instances.
I doubt the Swiss government would get much out of Misskey.
I just mentioned them because they're microblog sites, so in theory they do the exact same thing as Mastodon. The number of Mastodon users doesn't matter; the number of people on Fediverse platforms compatible with Mastodon matters.
So Lemmy users are not very helpful, but Mbin users maybe more so. Or Friendica.
The point is just that the number of Mastodon users is, in theory, irrelevant, as you don't just communicate with Mastodon users. Maybe misskey was a bad example, I don't know anything about it.
like this
Fitik and falseprophet like this.
like this
falseprophet likes this.
Is your reading comprehension broken or something? I even gave you a freaking range of scenarios. I'm literally using mbin for various parts of the Fediverse, including Lemmy and Mastodon. I think I have a pretty good grasp of it.
Simple! According to this thread, it is:
- an arbitrary standard of censorship
- nonexistent
- constant abuse of power
- the Chinese Communist Party
It doesn't even need to make sense on a conceptual level!
The Fediverse is not one thing. It's a bunch of different sites that are interconnected. You can join a site that has strict moderation, or you can join one that has no moderation at all.
Personally, I'm not here because I think moderation on Instagram and X is too active. Rather to the contrary.
For better or worse, the moderation policies of Lemmy.world is seen as "the fediverse".
Almost everyone decided to use that instance, so... It's the default choice still.
Then again, the only person in these comments actually using lemmy.world seemed pretty happy with his experience.
It would be nice if people had an easier way of knowing the level of moderation before joining a server. One idea could be for services like Fediverser could include an indicator of moderation level - for example "relaxed" if few instances are defederated, "moderate" if moderation is more active, and "strict" for more restrictive communities. Data from Fediseer might be useful in this regard.
That way the people fleeing Reddit because of censorship would know where to go, and the rest of us wouldn't have to be bothered by them unless we really wanted to.
The biggest problem, I guess, is that it's a lot of work, and I certainly don't have the time nor skill-set required. So people will just have to read their instance rules. :)
Depends on what you get moderated for. I once posted a question about trans people and I got banned from some Lemmy.ml community because they thought I was trolling them. I wasn't.
It's just sometimes hard for moderators to know what kind of person they are dealing with. But someone's posting history is usually enough to see if they are trolling or not.
Also what is trolling. It's supposed to mean that you intentionally upset people for fun. How can anyone know if it's intentionally or not. To some people, asking a question is trolling because they don't see why anyone would ask that if they didn't try to upset people.
So.. It's interesting.
The thing is, i think social media today has created a lot of censorship out of necessity. There are people out there who just aren't mature or intelligent enough to have a conversation without insulting or pushing people down.
And because of they, we all suffer. We get over-moderated, we get called trolls etc.
I think I would like a platform where people actually have to act like adults. But that's hard. Hacker news have kind of made it, but they are also well known for not being open minded at all.
Moderation is when you take down material because the recipient doesn't want to see it. Censorship is when you take down content because you don't want the recipient to see it, regardless of how the recipient feels about it.
— vintermann, Hacker News
— vintermann, Hacker News
I don't know who this person is, but adding "Hacker News" doesn't give their words more credibility. It gives them less, if anything.
Imagine I quoted someone and, underneath it, added:
— PM_ME_UR_FEET, Reddit
Both of these enjoy the same level of base, intrinsic trust to me: none.
The arbitrary standard for the censorship in Fediverse is extremely bad.
"The pirates code... Be more like... guidelines."
You can always make your own instance and moderate your own comments.
Be aware that no one is forced to keep federated with your instance.
"We've also closed the wheelchair ramps as the stairs are more popular."
Sometimes avoiding corporatism or maintaining your privacy feels like an accessibility issue (I'm looking at you, open source projects who direct their community to Discord).
It's accessibility, and it's also sovereignty.
Another way of rephrasing this decision is "we have decided to stop publishing information on our official website, as we receive more interaction on X". Which is pretty questionable.
(I'm looking at you, open source projects who direct their community to Discord)
This is surprisingly very common. Even for stuff that prioritise privacy. The interesting part is why discord is kept under the covers by everyone - despite its security offences, and anti-user practices.
There isn't much talk about discord like there is about browsers. However, it might be just an undeveloped branch of the oss community.
A good quality open source "federated discord" would be as important as lemmy or mastadon. But there isn't much hype around it. Afaik matrix is still far behind discord quality wise and the architecture has limitations for anonymity and encryption.
Discord is just high quality and so easy to use because making a server is so easy.
As a disabled person I don’t think that’s a fair comparison to use.
People on mastodon have a choice, it’s an awful choice which comes with privacy and contributing to corporate trash, being advertised at non-stop compromises, which in my opinion no one should have to make.
But you can still see it. Disabled people just straight up can’t use the stairs. It’s not that it’s a shit compromise for us. It’s that we are physically unable too.
like this
disguised_doge likes this.
I dunno. You could throw yourself down the stairs. It's an awful choice, but you could still do it...
The point is, a choice with all kinds of negative consequences to it isn't really a choice.
like this
disguised_doge likes this.
Agreed. By @FundMECFSResearch's distinction, you (well, Americans) could choose to not pay taxes. You literally are able to not do it. Of course, you then have to deal with the consequences, but it falls in the same category of "optional."
Gender-affirming surgery is "optional." Eating food other than cat food is optional. Simply having the ability to make a choice between two options is not sufficient to justify saying both options are satisfactory.
Yes definitely for hard of hearing and hard of sight people it can be an accessibility issue. I’m mostly deaf myself.
But comparing the situation for abled people in the way it was above doesn’t really work.
like this
dandi8 likes this.
Switzerland doesn't have the same sheet weight Brazil has.
And it probably doesn't wants to ruffle big US tech companies with so many having their big European HQs in Zurich.
It's still operating for now, right? Because if I look at random government pages in a browser that profile that doesn't block the social media widgets I can see links to facebook, twitter, instagram, whatsapp, youtube, and threema. There seems to be no mention anywhere that a mastodon server exists.
They're complaining about the low number of users. Did they bother to tell people that it exists?
But yes I'm very annoyed that they didn't share much of the instance outside a small notification on the admin.ch website.
But the goal of this whole pilot test is that if Mastodon became big within the year, they would already have an instance running with officials accounts. But instead I guess they will focus on Bluesky.
like this
dandi8 likes this.
Decisions like these are why they can't move away from proprietary platforms. How much does it really cost to host and maintain this? A single employee could host a mastodon, peertube, and lemmy instance. The employee could also work full-time on one of the projects to address issues.
They also only had 6 accounts on the instance - out of how many politicians and bureaus?
Anyway... shame.
like this
Fitik likes this.
The main cost is probably the extra workload put on their social media team having to publish to and interact with even more platforms.
While it's nice, I also don't think the government should spend time and money on a platform that people obviously don't use much.
The main cost is probably the extra workload put on their social media team having to publish to and interact with even more platforms.
They've yet to be caught actually interacting with someone. They've run the whole instance as nothing but a shoutbox.
The Fediverse is not only Lemmy and Mastodon. Even the microblogging side is not only Mastodon.
Mastodon itself has a whole bunch of forks such as Ecko, Hometown and the very popular Glitch.
There's also Pleroma with its probably even more popular fork Akkoma.
There's Misskey with literally dozens of forks, including but not limited to Firefish (formerly Calckey), Iceshrimp (its rewrite Iceshrimp.NET won't be a fork anymore, though), Sharkey, CherryPick, Catodon etc. etc.
If you want something with more power, something that's much more like Facebook, there's Friendica and has been since 2010.
If you want something with vastly more power, think Facebook meets WordPress meets Google Cloud Services meets Fandom etc., there's Hubzilla. Whenever someone thinks "the Fediverse" needs to introduce a certain new feature just because Mastodon doesn't have it, chances are Hubzilla has had it for longer than Mastodon has even been around.
And so forth.
like this
end0fline likes this.
The irony is that all it would take is one high profile person or a nation state to commit to using Mastodon, and slowly you would see the numbers start to increase.
Um, nope.
George Takei is on Mastodon. I've yet to see masses of Trekkies piling into Mastodon.
Greta Thunberg is on Mastodon. There has never been a huge influx of FFF members. Or Zoomers, for that matter.
The Dutch government has its own instance. The Federal German government has its own instance. Doesn't lure anyone into the Fediverse.
Do you explain the Internet to your grandparents by explaining HTTP first?
Sorry to say, but the Fediverse would be a great deal smaller if it wasn't for millions of Twitter users who were railroaded straight to mastodon.social, not knowing anything about it except that it's allegedly "literally twitter without musk".
There are still people who have been on Mastodon since shortly after Musk bought Twitter out, and who shit brix upon discovering for the first time that the Fediverse is, in fact, surprisingly, who woulda thunk it, not only Mastodon.
These people wouldn't be here, had their introduction to the Fediverse started with an explanation of ActivityPub.
not as normie as threads I think.
I really struggle to find good accounts to follow on bluesky, and most of the french accounts/content are inactive for months (I even have a better content/experience on mastodon since they federated w/ threads and flipboard).
But beyond mastodon, it's really sad that they leave the fediverse for now, hope they'll comeback one day or another (on mastodon or any other plateform)
The six accounts of the Confederation had around 3,500 subscribers in total.
Seriously, what did they expect?
As many followers as they've built up in the Birdcage? With maybe 1% of users altogether? In a much shorter timespan?
And by running the accounts as pure shoutboxes with no interaction with replies that could just as well be unmarked crossposter bots?
unknowing8343
in reply to Leaflet • • •Another week, another incorrect weekday format.
It's 2024-W39, you are welcome.
Leaflet
in reply to unknowing8343 • • •unknowing8343
in reply to Leaflet • • •