nemobis,
@nemobis@mamot.fr avatar
renchap,
@renchap@oisaur.com avatar

@nemobis Thanks for this initiative! We wanted to do it, but did not had the infrastructure in place.
I started drafting a design doc to get update alerts built into Mastodon, and I hope to find the time to finish it and publish it soon so someone can look at implementing it :)

nemobis,
@nemobis@mamot.fr avatar

@renchap Great to hear!

floho,

@nemobis I’m another one of the people who were very happy to get your email. Thanks for your efforts to keep the community alive and safe! Your writeup was very interesting - we live in awesome times, looking at the power of those tools that enabled you to put this together in, quote, „a few hours of work over the weekend“ 🙌

nemobis,
@nemobis@mamot.fr avatar

@floho Thank you!

devnull,
@devnull@crag.social avatar

@nemobis 🙂

Between you and a bunch of others I ended up being advised to upgrade by at least 4 or 5 separate people hah!

Really really solid work by the community to get the word out. Very envious and really demonstrates the power of the

In my case I already had a migration to scheduled, so that's why I was lagging behind on the upgrades 😳

nemobis,
@nemobis@mamot.fr avatar

@devnull Well done!

Hopefully the notification redundancy isn't overwhelming yet for most admins. :)

gruifor,
@gruifor@floe.earth avatar

@nemobis Yeah, thanks for that. Without the notification, I also wouldn't have upgraded so fast as I'm on vacation.

christopotamus,

@nemobis you rock!

ernie,
@ernie@writing.exchange avatar

@nemobis worked on me!

GossiTheDog,
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • nemobis,
    @nemobis@mamot.fr avatar

    @GossiTheDog Thank you! It was made easier by being able to quote you on the risks.

    acka47,
    @acka47@openbiblio.social avatar

    @nemobis That was a great read. I appreciate you informed about the whole process, your considerations along the way and the tools used.

    olaf,
    @olaf@social.secret-wg.org avatar

    @nemobis an excellent example of collaborative security…

    Andres,
    @Andres@mastodon.hardcoredevs.com avatar

    @nemobis
    Great work!
    I'm also trying to help the :fediverse: announcing a weak point on the way the user actions are handled and notified to the origin instance:
    hardcoredevs.com/fediverse-interactions-and-their-consecuences/
    So far without any luck.

    nemobis,
    @nemobis@mamot.fr avatar

    @Andres Interesting. I don't know how heavy these actions are in practice. I also filed a report about a specific case of inefficient federation, it's about user deletions: https://github.com/mastodon/mastodon/issues/21674

    Andres,
    @Andres@mastodon.hardcoredevs.com avatar

    @nemobis
    Nice!
    The interactions are not heavy at all, but those can be unlimited in amount, due to the lack of any rate-limit.
    I imagine a 1 person DDoS is possible from a big instance to a smaller one.

    nemobis,
    @nemobis@mamot.fr avatar

    @Andres Yes, Aral famously is one such big user able to melt other people's instances. ;) https://ar.al/2022/11/09/is-the-fediverse-about-to-get-fryed-or-why-every-toot-is-also-a-potential-denial-of-service-attack/

    However I think the far worse problem is that by default Mastodon doesn't control at all whether ActivityPub requests are coming from a "real" ActivityPub server/user, so I believe it's still easy to produce a spam wave like https://github.com/mastodon/mastodon/issues/21977 .

    Andres,
    @Andres@mastodon.hardcoredevs.com avatar

    @nemobis
    Thanks for the link to Aral's article!
    Yes I have been thinking about exactly that an how a potential millions-of-followers user back in Threads would kill any instance.

    andypiper,
    @andypiper@macaw.social avatar

    @nemobis wow, thank you - lots of learnings here. Appreciate you!

    pierobosio,
    @pierobosio@soc.bosio.info avatar

    @nemobis

    Iniziativa lodevole. Io devo ancora aggiornare. Sono fuori sede in ferie. Ho il server in self hosting a casa chiuso alle registrazioni e al momento non è semplice raggiungerlo da remoto su connessione mobile per aggiornare. Ho da fare prima un backup e poi dopo aggiornare. Tutti i programmatori dovrebbero sapere che ogni applicazione che gestisce un pur qualsiasi banale input sarà sempre potenzialmente vulnerabile e occorre fare estesi penetration test.

    nemobis,
    @nemobis@mamot.fr avatar

    @pierobosio Verissimo. (Ti ho risposto anche per posta elettronica.)

    legoktm,
    @legoktm@wikis.world avatar

    @nemobis TIL about a mastodon-admin mailing list, link please? :)

    nemobis,
    @nemobis@mamot.fr avatar
    lffontenelle,
    @lffontenelle@mastodon.social avatar

    @nemobis

    🤔 IIRC the Public Knowledge Project has a mailing list to announce updates to administrators of OJS (and OMP and OPS I guess) instances. I thought @Mastodon has the same!!

    Nikoh,

    @nemobis beh tutto sommato mi sembra sia andata bene 😅

    nemobis,
    @nemobis@mamot.fr avatar

    @Nikoh Rimangono ancora 3000 istanze da aggiornare però. 😬

    Nikoh,

    @nemobis vero però credo sia inevitabile, così tanta libertà comporta (o dovrebbe) un po' più di attenzione da parte degli utenti nello scegliere l'istanza a cui iscriversi. Comunque ad esempio a me non è arrivata la tua email, probabilmente perché ero alla 4.1.2....

    nemobis,
    @nemobis@mamot.fr avatar

    @Nikoh Oh. Nella mia lista del 2023-07-08T20:00:00Z risulta che la tua istanza fosse già su 4.1.4+glitch, è falso?

    Nikoh,

    @nemobis è corretto, fino al giorno prima era 4.1.2

    nemobis,
    @nemobis@mamot.fr avatar

    @Nikoh Bene. Ho aspettato la fine di sabato perché ho immaginato che chi gestisce un'istanza da 10 utenti attivi non lo faccia nel tempo lavorativo.

    downey,
    @downey@floss.social avatar

    @nemobis This is the way! 🏆

  • All
  • Subscribed
  • Moderated
  • Favorites
  • mastodon
  • PowerRangers
  • DreamBathrooms
  • osvaldo12
  • magazineikmin
  • InstantRegret
  • everett
  • Youngstown
  • ngwrru68w68
  • slotface
  • rosin
  • GTA5RPClips
  • tester
  • kavyap
  • thenastyranch
  • provamag3
  • mdbf
  • ethstaker
  • cisconetworking
  • Durango
  • vwfavf
  • normalnudes
  • tacticalgear
  • khanakhh
  • modclub
  • cubers
  • Leos
  • anitta
  • megavids
  • All magazines