Live data from Hacker News

So this guy is now S3. All of S3

chaos.social

361–370 of 522 posts

Re: So this guy is now S3. All of S3

#361
post #324
post #165

Earlier quoted context omitted.

[flagged]

If fediverse was going to succeed anywhere it would be on places like HN. The average user doesn't even know what "federation" means.

The fediverse has a problem with discovery, I agree on that piece. Coming from outside the network and trying to access a particular post or user profile is not smooth, mostly because it takes you to the wrong server (I don't use chaos.social, links to there are useless to me).

I've explained in other comments how a URL scheme would help with this.

There are many non-technical users on fediverse and it's working just fine for them, I see their posts all the time saying that they're having a good time despite your scare quotes. The problem in this case is HN users who aren't on the network anywhere, and there's not much I can do about that. I think if you were on it and had a home server this would not be that confusing, you'd just search for the post. Ideally you could skip the search step as well which is why I keep coming back to a URL scheme solution.

Re: So this guy is now S3. All of S3

#362

Earlier quoted context omitted.

Mastodon is written in Ruby on Rails and there are some inherent performance issues with that, it generates a huge number of Sidekiq jobs that can bog down a server quite easily. There are other, non-Ruby implementations aiming for compatibility with the Mastodon API though, so I’m curious to see how it will all shake out.

People can make a case for the developer productivity benefits of rails to a startup or business, but it’s hard to see it as worth the cost to the Mastodon community as a whole. But maybe it’s won the Fediverse market because of the depth of features which is a benefit of that productivity.

My read is it's mostly social, there's a lot of people accustomed to Mastodon and not much interest in exploring other options. There are implementations in Elixir (Pleroma, Akkoma) and work being done in Rust (Calckey, currently node but moving towards a Rust implementation). Mastodon dev team are not particularly open to criticism so my general sense is that admins should choose another project.

Re: So this guy is now S3. All of S3

#363
post #330

Last night I opened this, saw the HTTP 429 and figured "ah too many requests, I'll check the comments and try in the morning". The comments were all people swooning in shock about why some non-specific they (S3? Amazon? Someone else?) didn't use ".well-known" and others complaining about Mastodon and/or the fediverse. I had to read multiple comments to piece together the story, I swear it was like Elden Ring[0]. What…

> However that "somewhere" was just a location one of the devs at BlueSky chose, rather than somewhere relatively standardised, like under the ".well-known" path I've not looked into BlueSky's domain based identity thing in any detail so I might be missing a point somewhere, but… If someone can manipulate its special location what would there be to stop the same someone being able to manipulate content under .well-kn…

> Are we just relying on .well-known having some extra protection [...] ? If so then .well-known is little safer than any other arbitrary location in this respect.

If .well-known had just been invented, that would be true. It's fairly well established at this point, though. For example, if someone can create arbitrary files in .well-known, they are also able to pass http-01 ACME challenges and thus issue TLS certs for your domain (modulo CAA) and MITM you. At this point, allowing users to modify .well-known is about as good an idea as allowing them to receive mail for postmaster@ or accepting incoming packets from 192.168.0.0/16 into your LAN.

Amazon S3 specifically would not be vulnerable because bucket names can’t have dots in them; same for every other service that doesn’t allow those. Neither would services that prefix usernames with ~ or @ or similar, nor services that already use http-01 ACME challenges to get certs thus are already using that path.

I’d be much happier if proving domain control were only done through DNS challenges, but that ship has sailed.

Re: So this guy is now S3. All of S3

#364
post #344

Earlier quoted context omitted.

> The next part is that someone posted about it on this https://chaos.social Mastodon instance, which got overwhelmed, the owners decided to save their server by electing to return a 429 response for that specific post if users don't belong to chaos.social, and that is why people are upset about Mastodon. It's like all these newfangled webapps don't understand the concept of caching static pages for anonymous users.…

So the thing is that in one respect they actually do get caching, almost to a fault. One of the complaints I've seen among some Mastodon instance operators is that they end up storing some pretty hefty amounts of data locally as their instance caches remote posts, images and profiles from other instances that its members follow. One source of problems, which may have been resolved, was that even though there's a job…

I think the GP was referring to caching on the other end, caching static html that can be raised for all anonymous users.

The question is whether the server was having issues with a flood of new posts being sent in and stored, or a flood of anonymous users clicking a link and blogging down when the same html was getting rendered over and over.

Knowing Mastodon, I have a bunch of was the latter with the server coming out on all the new data it was trying to store locally

Re: So this guy is now S3. All of S3

#365
post #327

Earlier quoted context omitted.

They redirect you if you aren't logged in so you can't use them as an anonymous proxy. If you're logged in on your homeserver, you'll get that server's view of the post.

Could you expand on why being an anonymous proxy would be an issue in this case? I can't think of anything interesting off the top of my head. You can't post (because you're not logged in), so there's no issues with moderation. The toot is already federated publically, so there's no issues with unintentional read access. It doesn't need to contact the original server, so there shouldn't be any load/DDoS issues. I mus…

ugh I wish I had tried to generate these through a non-mastodon instance, could have saved a lot of confusion. It works fine through Calckey:

https://calckey.social/notes/9ebxxsy83i

Re: So this guy is now S3. All of S3

#366
post #134

Earlier quoted context omitted.

[flagged]

Found a similar situation, but I think the key is mostly if you're on one of those servers and seek out the content or if you're logged into one of those servers, it won't forward you (even if you click it from here, assuming same browser/container).

This works from a Calckey instance, just confirmed. https://calckey.social/notes/9ebxxsy83i

Re: So this guy is now S3. All of S3

#367

Earlier quoted context omitted.

In general - no, but this kind of fundamental mistake might.

I hope I never work on software you folks use. The grand claims about something that is not even hard to fix is just wild to me.

If your response to a fundamental design flaw of identy verification is "something that is not even hard to fix" then that hope is mutual.

Re: So this guy is now S3. All of S3

#368
post #350

Earlier quoted context omitted.

> [1] - they're doing an open beta and letting a little trickle of users on, who post about it on their Twitter/Mastodon/whatever. Feels a bit deliberate, like they're trying to build anticipation and frankly I detest little manipulative things like that so I'm out Frankly this cynicism feels unwarranted. Bluesky is not a finished product — it is still being built and, even with the small number of invited users so f…

To clarify - it felt like this was an attempt to replicate the mid-00s play of building interest by restricting who can join and making it exclusive (Facebook did this by rolling it out uni-by-uni, Gmail was for a while invite-only and invites were highly valued) and therefore desirable. Maybe that's in my head but layering this feeling on top of BlueSky being yet another microblogging service with a few other things…

Your feelings resonate with me too. My attitude these days is that if a platform wants to make me feel excluded (in order to induce FOMO), then I accept being excluded. They win, I guess?

Re: So this guy is now S3. All of S3

#369
post #263
post #227

Earlier quoted context omitted.

That is not the point. If someone sent any link or post that is from that Mastodon instance and it went viral, the entire instance will be sent to the ground and out for hours, making the post unavailable to be viewed. The worst part is journalists and the media have to be told that posting a link from a 'small niche community' on Mastodon will send a flood of traffic that will knock it down offline also giving the i…

It's a fair criticism but I don't feel so fatalistic. This would look a lot different if everyone was opening this post on their own home server instead of chaos.social. Unfortunately there's no way to construct a link that references the post but opens where it belongs for you . I think there needs to be a fediverse URL protocol to solve for this, ie this HN post would link to `fedi://@jonty@chaos.social/11030753200…

I think this is an absolutely absurd take. A post is the same post no matter who views it - it belongs on the instance where it was posted. Sure it might show up in your timeline or comments somewhere else but for the post itself there should only be one canonical link. If mastodon can't manage to show a simple text post with a small image to anonymous visitors without falling over then it's mastodon that needs to change and not how people interact with it. Most people don't even have a fediverse account ffs.

Re: So this guy is now S3. All of S3

#370
post #263

Earlier quoted context omitted.

It's a fair criticism but I don't feel so fatalistic. This would look a lot different if everyone was opening this post on their own home server instead of chaos.social. Unfortunately there's no way to construct a link that references the post but opens where it belongs for you . I think there needs to be a fediverse URL protocol to solve for this, ie this HN post would link to `fedi://@jonty@chaos.social/11030753200…

I think this is an absolutely absurd take. A post is the same post no matter who views it - it belongs on the instance where it was posted. Sure it might show up in your timeline or comments somewhere else but for the post itself there should only be one canonical link. If mastodon can't manage to show a simple text post with a small image to anonymous visitors without falling over then it's mastodon that needs to ch…

Where is the canonical location to access an email, or read an XMPP message? It's not just that it 'might show up' in my timeline, seeing it on my home server is where I want it to be - that's where I can take actions on it like replying, starring, or boosting. The post belongs in my client because that representation is the one that's relevant to me. I agree that the mastodon software could do better to optimize for public anonymous read, but it's not the most important functionality for the server to do.

> Most people don't even have a fediverse account ffs.

This is why you won't see a Bluesky post linked on HN, no one can open it. Imagine if you could sign up on your choice of thousands of servers and get the same access to the content rather than a central site, that's fediverse, it's not that complex.

Post reply on HN