this post was submitted on 11 Jun 2025
639 points (96.0% liked)

Fediverse memes

1776 readers
450 users here now

Memes about the Fediverse.

Rules

General
Specific

Elsewhere in the Fediverse

Other relevant communities:

founded 10 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] grrgyle@slrpnk.net 9 points 2 months ago (1 children)

We might eventually have to get more exclusive, or have separate "public" and "private" modes/communities, maybe like how masto handles post visibility...

I'm not sure if the open internet can ever be fully trusted, especially now with roving packs of predatory crawlers scraping for genuine human OC for their plagiarism machines.

[–] irelephant@lemmy.dbzer0.com 3 points 2 months ago (1 children)

I doubt they're crawling stuff over AP, you usually need a HTTP signature for that, and no bot is going to bother with those.

Most crawling would just be spamming the web interface.

[–] jerkface@lemmy.ca 1 points 2 months ago (1 children)

If by HTTP signature you mean an SSL certificate signed by an authority, those do not present a burden for bots to obtain any longer.

[–] irelephant@lemmy.dbzer0.com 3 points 2 months ago (1 children)

I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit,

Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request.

There's a better explaination here: https://docs.joinmastodon.org/spec/security/

A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway.

[–] jerkface@lemmy.ca 3 points 2 months ago

Sorry, forgot to whom I was speaking.