Live data from Hacker News

So this guy is now S3. All of S3

chaos.social

271–280 of 522 posts

Re: So this guy is now S3. All of S3

#271
post #227

Earlier quoted context omitted.

Mastodon is by design about small niche communities rather than centralised twitter alternative.

That is not the point. If someone sent any link or post that is from that Mastodon instance and it went viral, the entire instance will be sent to the ground and out for hours, making the post unavailable to be viewed. The worst part is journalists and the media have to be told that posting a link from a 'small niche community' on Mastodon will send a flood of traffic that will knock it down offline also giving the i…

Seems like a correct impression, then.

Re: So this guy is now S3. All of S3

#272

Earlier quoted context omitted.

Adding a new DNS record for a new, specific purpose is simple and low-impact, technically.

…which gets promptly forgotten about after it’s initial use case and years later your user database gets sold on the internet. How many “low-impact” things have been compromised over the years, I wonder?

Unless you have anyone competent running the DNS config, or have a ticketing workflow of any kind, and I can't figure out what you think a DNS record with a onetime validation token could do if left unmanaged beyond some adversary discovery.

Re: So this guy is now S3. All of S3

#273
post #28
post #5

Solution is also on the works like use /.well-known/, so this is more like funny, rather than a big problem. Key to trick was to have bucket named "xrpc" and store a file there: https://s3.amazonaws.com/xrpc/com.atproto.identity.resolveHa... There is also another funny thing in the image, the user posting about is sending one from "retr0-id.translate.goog", which is odd. Somehow he has got https://retr0-id.translate.…

Google Translate recently moved translated web pages to domains like this. If you plug a webpage into GT it will put the translated content under - .translate.goog. This user's actual domain is https://retr0.id

Oof. This will not be the last time that decision causes a problem.

Re: So this guy is now S3. All of S3

#274

Original has a 429, alternative link for this post thanks to the Fediverse! https://mastodon.social/@jonty@chaos.social/1103075321453803...

That doesn't work either, it just redirects back to the 429'd page on chaos.social. It's because the admins of the site put this up temporarily to deal with HN load.

Re: So this guy is now S3. All of S3

#275

Earlier quoted context omitted.

Bluesky was started within Twitter as a federated social protocol in 2019. Spun out in 2021 as a standalone company and it was also being used in the Crypto group at Twitter until Elon came in. I'm sure just because of its age and principals involved it's been heavily influenced by the crypto crowd. But suddenly, without anything else really stepping in to fill the void, it's the Twitter alternative of the day. Anywa…

> I'm sure just because of its age and principals involved it's been heavily influenced by the crypto crowd. It builds off of several specifications that came from the crypto crowd. It does not use a proof of stake or proof of work blockchain, though, so depending on how you use the words "crypto" and "blockchain," it either is or is not those things.

> > I'm sure just because of its age and principals involved it's been heavily influenced by the crypto crowd.

> It builds off of several specifications that came from the crypto crowd. It does not use a proof of stake or proof of work blockchain, though, so depending on how you use the words "crypto" and "blockchain," it either is or is not those things.

From the protocol's FAQ docs itself:

> Is ATP a blockchain?

> No. ATP is a federated protocol. It's not a blockchain nor does it use a blockchain.

https://atproto.com/guides/faq#is-atp-a-blockchain

Architecturally, it's an attempt at improving ActivityPub in terms of account transfers & portability between federated instances, which ActivityPub doesn't inherently support. Mastodon, by comparison, requires one of those steps to be the explicit export into a locally-saved file, rather than communications between the federated instances themselves.

https://docs.joinmastodon.org/user/moving/

Re: So this guy is now S3. All of S3

#279

Earlier quoted context omitted.

Both http and dns verification are stupid. Neither of them prove you own the domain. http verification proves you temporarily control IP space relative to a viewer. dns verification proves you temporarily control name resolution relative to a viewer. Both are trivially hacked, multiple ways. By the time someone finds out you did it ( if they closely monitor CT logs, which nobody does) you've already had hours, days,…

I can get behind registrar-level proof. And I can see why it won't happen, and it isn't because it's a bad idea. One problem I see is the extra overhead for the registrars. Now they have one more thing to do: verify (sign) certificate requests. That extra work is probably enough to get registrars to push back against such a system. The registrar would be assuming some of the functions of a CA. This would make it easi…

Instead of certificates, could you not use published tokens, using the same mechanism that registrars already use for publishing DNS NS "glue" records?

Re: So this guy is now S3. All of S3

#280

Earlier quoted context omitted.

Describing or at least providing context is not editorializing. I don't know how this "discouragement" is phrased, but it should instead encourage (if not require) that titles mean something to a general audience (at least as represented by HN's users). I am routinely down-modded and even banned for merely asking for more-descriptive titles. It's anti-user, anti-community, anti-usefulness, and douchey. All we needed…

> Describing or at least providing context is not editorializing. Absolutely. I'm not saying that I think that the title here is good. Just that I understand why it ended up as the title. > I don't know how this "discouragement" is phrased, You can find the guidelines here: https://news.ycombinator.com/newsguidelines.html To quote the relevant part: > Otherwise please use the original title, unless it is misleading o…

Thanks for the info! I'll check it out.
Post reply on HN