Earlier quoted context omitted.
Mastodon is by design about small niche communities rather than centralised twitter alternative.
That is not the point. If someone sent any link or post that is from that Mastodon instance and it went viral, the entire instance will be sent to the ground and out for hours, making the post unavailable to be viewed. The worst part is journalists and the media have to be told that posting a link from a 'small niche community' on Mastodon will send a flood of traffic that will knock it down offline also giving the i…
So this guy is now S3. All of S3
271–280 of 522 posts
Re: So this guy is now S3. All of S3
#272Earlier quoted context omitted.
Adding a new DNS record for a new, specific purpose is simple and low-impact, technically.
…which gets promptly forgotten about after it’s initial use case and years later your user database gets sold on the internet. How many “low-impact” things have been compromised over the years, I wonder?
Re: So this guy is now S3. All of S3
#273Solution is also on the works like use /.well-known/, so this is more like funny, rather than a big problem. Key to trick was to have bucket named "xrpc" and store a file there: https://s3.amazonaws.com/xrpc/com.atproto.identity.resolveHa... There is also another funny thing in the image, the user posting about is sending one from "retr0-id.translate.goog", which is odd. Somehow he has got https://retr0-id.translate.…
Google Translate recently moved translated web pages to domains like this. If you plug a webpage into GT it will put the translated content under - .translate.goog. This user's actual domain is https://retr0.id
Re: So this guy is now S3. All of S3
#274Original has a 429, alternative link for this post thanks to the Fediverse! https://mastodon.social/@jonty@chaos.social/1103075321453803...
Re: So this guy is now S3. All of S3
#275Earlier quoted context omitted.
Bluesky was started within Twitter as a federated social protocol in 2019. Spun out in 2021 as a standalone company and it was also being used in the Crypto group at Twitter until Elon came in. I'm sure just because of its age and principals involved it's been heavily influenced by the crypto crowd. But suddenly, without anything else really stepping in to fill the void, it's the Twitter alternative of the day. Anywa…
> I'm sure just because of its age and principals involved it's been heavily influenced by the crypto crowd. It builds off of several specifications that came from the crypto crowd. It does not use a proof of stake or proof of work blockchain, though, so depending on how you use the words "crypto" and "blockchain," it either is or is not those things.
> It builds off of several specifications that came from the crypto crowd. It does not use a proof of stake or proof of work blockchain, though, so depending on how you use the words "crypto" and "blockchain," it either is or is not those things.
From the protocol's FAQ docs itself:
> Is ATP a blockchain?
> No. ATP is a federated protocol. It's not a blockchain nor does it use a blockchain.
https://atproto.com/guides/faq#is-atp-a-blockchain
Architecturally, it's an attempt at improving ActivityPub in terms of account transfers & portability between federated instances, which ActivityPub doesn't inherently support. Mastodon, by comparison, requires one of those steps to be the explicit export into a locally-saved file, rather than communications between the federated instances themselves.
Re: So this guy is now S3. All of S3
#276Re: So this guy is now S3. All of S3
#277Re: So this guy is now S3. All of S3
#278Re: So this guy is now S3. All of S3
#279Earlier quoted context omitted.
Both http and dns verification are stupid. Neither of them prove you own the domain. http verification proves you temporarily control IP space relative to a viewer. dns verification proves you temporarily control name resolution relative to a viewer. Both are trivially hacked, multiple ways. By the time someone finds out you did it ( if they closely monitor CT logs, which nobody does) you've already had hours, days,…
I can get behind registrar-level proof. And I can see why it won't happen, and it isn't because it's a bad idea. One problem I see is the extra overhead for the registrars. Now they have one more thing to do: verify (sign) certificate requests. That extra work is probably enough to get registrars to push back against such a system. The registrar would be assuming some of the functions of a CA. This would make it easi…
Re: So this guy is now S3. All of S3
#280Earlier quoted context omitted.
Describing or at least providing context is not editorializing. I don't know how this "discouragement" is phrased, but it should instead encourage (if not require) that titles mean something to a general audience (at least as represented by HN's users). I am routinely down-modded and even banned for merely asking for more-descriptive titles. It's anti-user, anti-community, anti-usefulness, and douchey. All we needed…
> Describing or at least providing context is not editorializing. Absolutely. I'm not saying that I think that the title here is good. Just that I understand why it ended up as the title. > I don't know how this "discouragement" is phrased, You can find the guidelines here: https://news.ycombinator.com/newsguidelines.html To quote the relevant part: > Otherwise please use the original title, unless it is misleading o…