Comments

This profile is from a federated server and may be incomplete. Browse more on the original instance.

fubo, to asklemmy in So, how does the fediverse work?

If you’re up for reading Internet standards documents, start here with the official standard for ActivityPub, the protocol that it’s all built on.

fubo, to asklemmy in What's the best way to get rid of house centipede?

House centipedes are predators. They're only there because there's food for them to eat — prey animals that they are hunting.

Now, what are their prey animals? Here's some critters that house centipedes eat:

  • Cockroaches
  • Termites
  • Bedbugs
  • Silverfish
  • Ants

You have house centipedes because you have these.

The centipedes are eating them.

Now, what was it you wanted to get rid of?

fubo, to asklemmy in Lighthearted, upbeat shows for adults?

That was years ago :)

fubo, to mildlyinteresting in Twins!

Yep. This is called candling the egg, because it was first done by candlelight.

fubo, to asklemmy in What do you think of people making memes/jokes about the recent Titan tragedy?

Did these folks make fun of Kobe Bryant and his daughter?

fubo, to asklemmy in Can you steal a user's identity if you gain their old domain name?

I've only read the ActivityPub spec; I haven't read the Lemmy code.

With that in mind, my impression is —

The new domain owner — if they set up an ActivityPub server instance (e.g. a Lemmy) and got a list of the old user's post URLs — might be able to delete or edit the old user's posts stored on other instances. That is a vulnerability, albeit a small one.

If the old user was still listed as a moderator of communities hosted on other instances, the new domain owner might be able to take over that moderator role.

One way to fix this would be for instances to issue a public-key cryptographic identity to each user, and distribute users' public keys to other instances. Then activities purporting to be from that user would need to be signed by that user's private key.

Users' private keys would stay local to their home instance, so users don't have to do any key management themselves.

This would mean that if an instance goes away (and its key material is destroyed) then nobody can ever act as any of those users again. A new user created with the same username and domain would be a distinct user for all other instances too.

fubo, to asklemmy in How do we feel about Meta joining the Fediverse?
  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #