Elektrine lite

← Feed

silverpill

silverpill@mitra.social

<p>Developer of ActivityPub-based micro-blogging and content subscription platform <a href="https://codeberg.org/silverpill/mitra" rel="noopener">Mitra</a>. I help maintain the <a href="https://codeberg.org/fediverse/fep" rel="noopener">FEP repository</a> and write my own <a href="https://codeberg.org/silverpill/feps" rel="noopener">FEPs</a> too. Currently working on <a href="https://codeberg.org/ap-next/ap-next" rel="noopener">ActivityPub Next</a>.</p>

Posts

  • View post

    Updating FEP-5219: Groups and permissions: https://codeberg.org/fediverse/fep/pulls/944/files I&#39;ve introduced a new property, audiences, which lets you define collections containing actors with a specific role / privilege / affiliation: { &quot;id&quot;: &quot;https://social.example/group&quot;, &quot;type&quot;: &quot;Group&quot;, &quot;audiences&quot;: { &quot;admin&quot;: &quot;https://social.example/group/admins&quot;, &quot;moderator&quot;: &quot;https://social.example/g...

  • View post

    FEP-171b has been updated: https://codeberg.org/fediverse/fep/pulls/931 The document now mentions canReply property which is used in reference implementations (Streams and Forte). { &quot;type&quot;: &quot;Note&quot;, &quot;canReply&quot;: [&quot;https://alice.example/followers&quot;], ... } #fep_171b #ConversationContainers

  • View post

    @julian Parts of FEP-5219 are implemented in Mitra. You could be the next implementer :D It&#39;s not really ready though, I am still collecting feedback from developers that need fine-grained permissions. We need a system that works for them as well as for simple forums where two roles is enough (user and admin). @Profpatsch@mastodon.xyz

  • View post

    I think there should be a &quot;Prior art&quot; or &quot;History&quot; section.

  • View post

    @julian So why does 8b32 allow for dropping the HTTP signature? My best guess is that the wording is vague and the intention is that an object integrity proof at top level means an HTTP signature can be discarded. You&#39;re right, the sentence was poorly written. It was meant to apply to top-level proofs only. I&#39;ll update the FEP. I know of no situation where an AP-compliant server POSTs another server without an HTTP Signature. Pretty sure any attempt to do so would just mean the acti...

  • View post

    We&#39;ve introduced a new metadata field for FEPs: tags https://codeberg.org/fediverse/fep/pulls/885 Tags are free-form and should be specified as a YAML array: tags: [&quot;groups&quot;, &quot;permissions&quot;] #fep

  • View post

    The ap-next developer guide was removed from the https://activitypub.rocks website: https://github.com/swicg/activitypub.rocks/issues/63 (by the father of the Fediverse, no less). The reason: It&#39;s a fork outside the SocialCG. This is utter nonsense. The guide refers to the original ActivityPub specification and even to SocialCG reports covering Webfinger and HTTP signatures. The other ap-next project is NomadPub - a collection of FEPs that significantly expand the capabilities of the prot...

  • View post

    The biggest problem for peer to peer ActivityPub is the fact that ActivityPub is primarily a &quot;pull&quot; protocol. You need to fetch a remote actor before interacting with it. This is not feasible in the environment where nodes are intermittently online. What if we used a special activity to request objects? I&#39;ve described this idea in more detail in Asynchronous object retrieval: https://codeberg.org/silverpill/feps/src/branch/main/aef6/fep-aef6.md I think this mechanism, if combine...

  • View post

    I added a list of recommended libraries to the ActivityPub developer guide: https://codeberg.org/ap-next/ap-next/src/branch/main/guide.md#libraries - activity (Go, used in GoToSocial) - Fedify (JavaScript, used in Hollo and Ghost) - Fedipub (Ruby, used in Manyfold) - activitypub_federation (Rust, used in Lemmy) - APx (Rust, used in Mitra) This list only includes libraries that are actually used somewhere. Libraries that are not used, or used in projects with too few users are not included. #...

  • View post

    Private groups Lately, I&#39;ve been seeing various people claiming that fediverse doesn&#39;t have private groups. They often point to some task force at w3c that is supposedly working to fill the gap. However, fediverse has had private groups for a very long time: - Hubzilla channels. This project probably had private groups before ActivityPub. The implementation was later adapted for ActivityPub and refined in subsequent forks, Streams and Forte. It is now partially documented in FEP-171b:...

  • View post

    FEP-0806: Simple client-side encryption https://codeberg.org/silverpill/feps/src/branch/main/0806/fep-0806.md The FEP now includes the recommended algorithm parameters. I consider it finished but I don&#39;t plan to continue working on my implementation or publishing to the main FEP repository. It would be better to focus on group messaging with forward secrecy (MLS or similar). #fep_0806 #e2ee

  • View post

    Setting up a Forgejo instance: https://code.mitra.social/silverpill/mitra It will be mirroring repositories related to the #Mitra project. I don&#39;t plan to migrate from Codeberg right now, but it wouldn&#39;t hurt to have a self-hosted instance in case they decide to enforce the new anti-crypto policy. This will also allow me to test the implementation of federation in Forgejo.

  • View post

    Proposal: Replace gateways query parameter in &#39;ap&#39; URIs with @gateway, which can be used multiple times https://codeberg.org/fediverse/fep/pulls/890 Before: ?gateways=https%3A%2F%2Fserver1.example,https%3A%2F%2Fserver2.example After: ?@gateway=https%3A%2F%2Fserver1.example&amp;@gateway=https%3A%2F%2Fserver2.example Query parameters are often used to specify collection filters. The @ prefix will make it clear that gateway parameter is special. #fep_ef61

  • View post

    Codeberg is banning &quot;cryptocurrency projects&quot;: https://codeberg.org/Codeberg/org/pulls/1254#issuecomment-19820413 I don&#39;t know if Mitra qualifies as such, but I guess it is time to move to a self-hosted forge.

  • View post

    I finally got around to trying #iroh It nicely complements FEP-ef61, because it allows you to connect to another actor by its did:key. In theory, we can completely replace the federation of HTTP servers with a federation of iroh nodes. However, I&#39;m not convinced that iroh is the best solution. The most obvious problem is a lack of anonymity. Newer versions of iroh support custom transports, and Tor transport is among them, though still experimental. The work on I2P transport has not starte...

  • View post

    The NomadPub intro page now includes a &quot;Research&quot; section: https://codeberg.org/ap-next/ap-next/src/branch/main/nomadpub.md#research I listed the most important open research problems there: key management (alt-DIDs), alternative transports, E2EE and generic servers. #NomadicIdentity

  • View post

    I managed to send an encrypted message from one Mitra Mini account to another. The gateway should run the latest development version of Mitra. Spec: https://codeberg.org/silverpill/feps/src/branch/main/0806/fep-0806.md

  • View post

    Updating FEP-ef61: Portable Objects: https://codeberg.org/fediverse/fep/pulls/883 I added a section about key management. This part of nomadic identity was often misunderstood - some people thought that secret keys need to be managed by servers, and that servers could impersonate users. No, there are 3 options: - Server-side signing: secret keys are managed by a server (gateway). Activities are generated and immediately signed by a server. - Delegated signing: secret keys are managed by a sep...

  • View post

    Finally implemented FEP-0806: Simple client-side encryption in Mitra Mini. Right now it only does encryption-decryption. No delivery yet - because gateways don&#39;t support EncryptedActivity activities. The scheme was changed to HPKE (RFC 9180 Hybrid Public Key Encryption). #fep_0806

  • View post

    Minor FEP-5219 update: https://codeberg.org/fediverse/fep/pulls/880 I started implementing this FEP in Mitra, here&#39;s how an affiliations collection looks like: https://mitra.social/ap/actors/019f0e0d-b949-7600-aa86-0df8e275c291/affiliations #fep_5219

  • View post

    I&#39;ve got a report about Mastodon v4.7.0-alpha.1 not federating with Mitra. Can anybody confirm this? They recently merged FEP-8b32 signature verification, that might be relevant. All Mitra activities are signed

  • View post

    New @minimitra release: 0.4.2 This version supports post edits. There are also some big changes under the hood that will allow me to copy features from Mitra to Mini with less effort in the future. RE: https://mitra.social/.well-known/apgateway/did:key:z6MkumzpDj1cYZD2GrBbVT86xL6CfPuyqWZAEXMfSqN9j3hf/objects/019f2891-61e1-77b1-8638-10f33b4d4df9

  • View post

    Regarding the validity of at:// URIs in atproto: https://bnewbold.leaflet.pub/3mph4hzvbdc2v We have a similar problem with FEP-ef61 &#39;ap&#39; URIs. In their canonical form, they are not valid RFC-3986 URIs. I think if atproto devs decide to move away from ://did:.. syntax, we&#39;ll have to do that as well. #fep_ef61

  • View post

    FEP-8b32 update: https://codeberg.org/fediverse/fep/pulls/874 - Recommendation for expired proofs: try other authentication methods. - Added a link to Quantum-Resistant Cryptosuites v1.0 - Added Mastodon to the implementation list (verification only for now) #fep_8b32

  • View post

    I&#39;m requesting final comments on FEP-7628: Move actor #fep_7628 #fep #activitypub

  • View post

    FEP-ef61: Portable Objects has been updated: https://codeberg.org/fediverse/fep/pulls/872 The ap+ef61 URI scheme is now allowed, while ap remains the recommended one. This is to ensure compatibility with @fedify@hollo.social whose maintainers decided to use the ap+ef61 scheme until the specification is finalized. #fep_ef61 #nomadicidentity

  • View post

    FEP-5219: Groups and permissions has been added to the FEP repository. #fep #fep_5219 RE: https://mitra.social/objects/019e87e9-62a6-71d1-8edc-3a8a63e96c9f

  • View post

    I tried to implement the &quot;standard&quot; ActivityPub #C2S API in Mitra. It&#39;s an interesting exercise, but I am not sure if I&#39;ll ever enable it by default. Permitting clients to publish arbitrary JSON is equivalent to allowing them to publish unsanitized HTML. This may be acceptable if you&#39;re an admin on a single-user instance, but it is a really stupid thing to do when there are multiple users. Although it might be possible to validate activities using strict JSON schemas, tha...

  • View post

    FEP-f228: Backfilling conversations has been updated: https://codeberg.org/fediverse/fep/pulls/853 I added tootik and Lemmy to the implementation list and did a little cleanup. This FEP feels complete, so I am requesting final comments. Full text: https://fediverse.codeberg.page/fep/fep/f228/ #fep_f228 #fep #fedidev

  • View post

    @swetland@chaos.social FEP-8b32 implementations use Ed25519: https://codeberg.org/fediverse/fep/src/branch/main/fep/8b32/fep-8b32.md#implementations But for HTTP signatures everyone still uses RSA because dominant implementations don&#39;t support Ed25519