Quand #Lemmy a pas envie de te faire marrer (parce qu'il est pas là pour ça, Lemmy), il fait ça. Tu crois quoi ? Que Motörhead c'est des clowns ???
(en plus les clowns en vrai ça fait un peu peur, cf Terry Pratchett)https://youtu.be/ET07vTF_y94?si=VuyUENh4EOrNRMoK
#Sharkey's recent vulnerability and their handling of it is still miles better than #Lemmy's #XSS exploit which actually took down a big instance and is something even more elementary than what Sharkey experienced.
Like seriously, the first thing you do when #Markdown parsing is involved is to sanitize the hell out of it, both in the Markdown input and the HTML output. And you put up a strict #CSP for good measure. Lemmy spectacularly failed on both counts, despite existing as a project for years and a lot more instances (and therefore users, which rivals #Mastodon) using their software!
I can cut some slack for the Sharkey devs here because:
they're relatively new (only months since the project started)
it only affected note imports from #Twitter which is already niche enough
it was easy to mitigate (just disable note import)
it didn't affect single-user instances IIUC
I haven't seen any Sharkey instance get actually exploited by this
they're taking steps to make sure this shit doesn't happen again (haven't seen this from Lemmy yet, and last I checked their CSP is still shit)
So this is not worth blowing over in the #fediverse. Your assessment is exaggerated, this energy could've been spent somewhere else, and you owe the Sharkey devs an apology.
Having #reddit host (and therefore own) the conversation space on any subject is ridiculous. But the way #Lemmy & #kbin work presents the same problem. Basically they are not really decentralized etc. But if there were no communities/magazines, if hashtags only served that sorting function, and we instead merged the best parts of those conversation tools with the decentralized feed of #mastodon etc, we'd have something better than the closed corporate silos could ever provide. #fediverse
It is still early enough in the #redditmigration that #lemmy or #kbin can easily be replaced if something superior comes along. So if #piefed or #sublinks can develop their consumer facing products better and faster then they will inevitably get the community support. And since sublinks uses the existing Lemmy API it might have the best chance to do so.
You never know, the current Lemmy devs might be pushed aside tomorrow, anything could happen.
Is there a way to follow #Lemmy communities through Mastodon in a way where you would only get new posts into your timeline? So filtering out the comments?
Ugh, the naturally chaotic use of #hashtags on #Mastodon can make it very frustrating to use one of them for specific topics. I want to try and find other people talking about #GenerativeAI and particularly #AIArt like #StableDiffusion, but the last two are swarmed with just people posting images. How does one make a tag that is both easy to (think of to) tag with, and signifies discussion on a topic, instead of image-posting?
It's very much why things like #Lemmy are necessary.
It’s crazy how much of the comments about #Subllinks on the threadiverse are mad that the author is using #Java or just complaining that they chose to build another implementation.
Most of it seems to be #Lemmy users who think that #kbin, #mbin, #piefed, etc don’t exist and no other federated link aggregator should exist.
Seems like an interesting effort. A developer is building an alternative Java-based backend to Lemmy’s Rust-based one, with the goal of building in a handful of different features. The dev is looking at using this compatibility to migrate their instance over to the new platform, while allowing the community to use their apps...
OC Sublinks Aims to Be a Drop-In Replacement for Lemmy (wedistribute.org)
Seems like an interesting effort. A developer is building an alternative Java-based backend to Lemmy’s Rust-based one, with the goal of building in a handful of different features. The dev is looking at using this compatibility to migrate their instance over to the new platform, while allowing the community to use their apps...
Memery Alpha - Star Trek memes and shitposting (kbin.social)
A place for enjoying Star Trek memes in the kbin quadrant