Some LAUTI instances have been facing extended DDoS attacks lately. For our own instance @eintopf@sueden.social we reduced the load by deploying @CrowdSec@infosec.exchange which seems to have stablized the situation. We'll keep monitoring and see how it goes. Any other instances having these issues?
Some point this year I tried to test the services queerit.org is offering including a Fediverse instance running on bonfire. This seems to be very buggy. My account there is @livho@social.queerit.org . When I log in into that account I can see most of my notifications I see here on my main account @livho . Basically all notifications with mentions of @livho regardless of the server. And the account mirrors parts of my main account as if it was sent by that account (Very visible from the public profile: https://social.queerit.org/@livho ). It also creates some other glitches where the account appears in the notifications of other people.
To me this sounds like a very bad bug that allows anyone to basically clone a profile of someone else and start interacting with followers of that profile.
@livho@social.queerit.org we fixed quite a lot of bugs in recent versions - 1.0.5 is much more stable nowadays
@mayel@bonfire.cafe @ivan@bonfire.cafe
Hey guys. Autonomic set up a Bonfire test instance for me. Now it's 404ed and they are not returning my emails. Do you know if they went belly up? I know you work with them sometimes. I was on your test instance for a while and wrote all the Bonfire articles on Manade. https://site.manade.org/notes If you could contact them, I would really appreciate it.
@thefulcrum@www.thefulcrum.dev @ivan pinged them now
Progress is slow but steady on our road to implement #activitypub
The next piece of the puzzle is raedy: storing incoming activities and adding the the followers collection to the instance actor
codeberg.org/Klasse-Methode/...
Reviews are highly appreciated as always 🙏 #fedidev
One thing I keep coming back to when comparing #ActivityPub and AT Protocol: ActivityPub is basically a convention on top of the #web stuff we already have. An actor is a JSON-LD document you GET. An inbox is an endpoint you POST to. If you already run a website, you can bolt this on without changing the site's basic shape. Ghost didn't set out to join the #fediverse, and then years later it could, just by adding an endpoint.
AT Protocol feels less like that to me. Running a PDS means a signed repo, a Merkle search tree, a firehose, a DID. It's not a layer you add to an existing site. It's closer to standing up another backend beside it.
I think that's why ActivityPub keeps making sense to me. You can join later. You don't have to have built the whole thing with federation in mind from day one.
@hongminhee@hollo.social yeah that's exactly why I decided years ago to go "all in" on ActivityPub instead of scuttlebutt.nz which was in every other way a very cool technology and community.
Utenti del fediverso. Ho un quesito: c’è un weblate/crowdin dove tradurre il codice di @Bonfire ?
Mi piacerebbe moltissimo tradurlo il lmo.
Fatemi sapere grazie 🙏🏻
@emanuelecariati@varese.social non sono sicuro di averti aggiunto correttamente...mi confermi appena puoi?
Bonfire Social 1.0.5 is out! 🔥
Archipelago mode means instead of open federation (connect to everyone, then play whack-a-mole blocking bad actors), you can now choose to federate *only* with a hand-picked allow-list of trusted people or servers. Communities can link up into an "archipelago" of like-minded "islands" with shared rules, ideal for tight-knit groups, neighbourhoods, assemblies, co-ops, or orgs that want to connect with each other but not necessarily the whole internet.
We also added new admin throughput controls as our latest take on "calm empowerment": simple defaults first, curated overrides next, and full advanced control behind an explicit gesture. In practice, you can keep a busy instance responsive by picking a speed preset, prioritising certain kinds of activity, or fine-tuning each background task queue, no config files or restarts needed.
Also new in 1.0.5:
- Faster search, now powered by Sonic
- Broadcast announcements to everyone on your instance
- Embeddable widgets: put your pinned posts on any website
- PGP-encrypted system emails
- Plus lots of improvements and fixes (federation, polls, media, accessibility, mobile)
Blog post and changelog: bonfirenetworks.org/posts/bo...
Utenti del fediverso. Ho un quesito: c’è un weblate/crowdin dove tradurre il codice di @Bonfire ?
Mi piacerebbe moltissimo tradurlo in LMO.
Fatemi sapere grazie 🙏🏻
@emanuelecariati@varese.social You're welcome to join localisation efforts at app.transifex.com/bonfire/bo... thanks!
LAUTI instances are shown with a black/white pin.
@Bonfire YOU DID ARCHIPELAGOS!!!!!
@oli@olifant.social big fan of your work!
@Bonfire@bonfire.cafe not related to this, but I don't think I ever got an email for where to sign up for an install party as a part of the Indiegogo campaign. What are the deets for that?
@unsafelyhotboots@sharkey.world ah we sent some surveys out a while ago to gather peoples preferences, timezones, etc. We still need to start actually scheduling them but did you receive that?
🔥 The Bonfire Social 1.0.5 release candidate is out!
This one brings archipelago mode (opt-in, allow-list federation for tightly-knit communities and networks), a more lightweight search backend (see changelog for migration steps), broadcasting announcements, another embeddable widget, PGP-encrypted emails, and many UX improvements and fixes.
If you're running an instance and want to give it a go, please let us know if you run into any issues.
Full changelog: docs.bonfirenetworks.org/cha...
Our next two #activitypub pull requests are ready for review:
- adding a public key to our instance actor codeberg.org/Klasse-Methode/... (note we use rsa for now as recomended in swicg.github.io/activitypub-..., but we will propably support more keys in the future)
- adding an empty inbox with #httpsig verification codeberg.org/Klasse-Methode/... #fedidev
Hard to get any work done. The view from my wife's office downstairs. #Alaska #Anchorage #BearValley #Moose #WildLifePhotography
@Bonfire@bonfire.cafe would it be possible to have federation deletion jobs that don't find the thing to delete not be considered a failed job? I seem to get an awful lot of them (enough to drop federation job success rates down to ~60% sometimes) which makes it hard to spot actual problems when they do happen. Especially because (it appears?) some servers keep on sending the deletion requests, meaning that it's showing errors for things that have already been successfully deleted.
@mavnn@bonfire.mavnn.eu yeah good idea, the reason there's so many is that mastodon sends Delete activities far and wide to try and ensure no deleted posts linger on other servers, we've tried optimising that in the past with github.com/bonfire-networks/... but we have an open issue to tackle it better: github.com/bonfire-networks/...
ok! i think @Bonfire@bonfire.cafe has resolved the federation issues in 1.0.5-beta.1!
@christopher@gay.amsterdam yay 😊 thanks for your help debugging them!
The directory name is ".claude", the filename is "CLAUDE.md", the content looks rather like LLM prompts, and there is a well-known LLM online service called #Claude.
Since I don't do vibe-coding and haven't (yet) had to check vibe-coded code, I can't say more than "a clue". People with experience looking at Claude-vibe-coded code might want to comment here.
@boud@framapiaf.org we're drafting our AI policy and will share publicly as soon as it's ready...
@UlrikeHahn@fediscience.org @Bonfire @brembs@mastodon.social @olibrendel@scicomm.xyz @A_J_Millar@fediscience.org @fresseng@universites.social
@fresseng @A_J_Millar @Bonfire
It needs to be one of the registered users of openscience.net such as
@brembs
Or
@UlrikeHahn
😁
@olibrendel@scicomm.xyz fyi the sandbox instance is only meant for testing how it looks like, it's not intended to be a fully working / federated instance as we do not aim for running flagship instances (decentralisation ftw). That said, we will send you an invite soon
@fresseng@universites.social @UlrikeHahn@fediscience.org @brembs@mastodon.social @A_J_Millar@fediscience.org
@Bonfire@bonfire.cafe I have no idea why Astro was unable to download it automatically? Other outbound http on the container are working fine, so I'd guess a file system permissions issue within the container but I might be totally wrong.
@mavnn@bonfire.mavnn.eu yeah apparently something changed in new astro version. We temp commented it in beta.3 since it was using only in the weather widget for showing moon phases, and the widget is currently on hold anyway