Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

Vi siete segnatə vero che domenica 13 alle 14:30 alla Città dell'Utopia in via Valeriano 3f a #Roma c'è la quarta assemblea di istanza di Puntarella?

Come scrivevamo ieri, uno dei punti all'odg pensiamo possa essere la proposta di blocco delle istanze che fanno mirroring da X. Altre questioni che ci eravamo segnate sono: emendare la policy sulla moderazione di istanze/utenti spam; eventuali altri servizi da installare sul nostro server.

Chiediamo però a voi puntarelle di quali ulteriori temi pensate sia utile discutere: usate questo thread oppure, a patto di toottare in modalità pubblica, l'hashtag #PuntAssemblea

roma.convoca.la/event/quarta-a…


Quarta Assemblea di Puntarella.party - A/Social indipendente de Roma
Inizia: Domenica Aprile 13, 2025 @ 2:30 PM GMT+02:00 (Europe/Rome)
Finisce: Domenica Aprile 13, 2025 @ 6:30 PM GMT+02:00 (Europe/Rome)
La quarta assemblea di istanza di #Puntarella sarà esattamente un anno dopo la terza: domenica 13 aprile, dalle 14:30 a La Città dell'Utopia, in via Valeriano 3f a #Roma.
Come sempre, sarà un'occasione per confrontarci sulla nostra community, sulle regole che ci diamo, sull'infrastruttura tecnica, sulla vita, il fediverso e tutto quanto.

The media in this post is not displayed to visitors. To view it, please log in.

A new security fund for the fediverse, and the Lemmy developers held an AMA.


Fediverse Report – #111

A new security fund for the fediverse, and the Lemmy developers held an AMA.

The News


The Nivenly Foundation, the organisation that administers the Hachyderm.io instance, is opening a new security fund to sponsor contributors who disclose security vulnerabilities. All software has security vulnerabilities, and the fediverse is no exception. The recent Pixelfed vulnerability, which affected non-Pixelfed servers, is a clear example of how fediverse software can make software vulnerabilities more complex due to the interaction between different software platforms.

The Nivenly Fediverse Security Fund will sponsor $250 USD for vulnerabilities that are rated as high risk (7-9 CVSS score) and $500 USD for vulnerabilities with a critical score (9+ CVSS). The program will run until the end of September 2025. Nivenly members “hold a member vote to determine if we want to continue the program, and to establish a longer-term committee to steward and maintain the program.”

Last week, I wrote how Pixelfed’s vulnerability actually showed three different problems: The main problem is Pixelfed’s software vulnerability itself, but there were also two other problems: other software like Mastodon do not make it clear which risk comes with their private posts feature. And once a leak like this one happens, very few fediverse software admins communicated to their users that they might have been affected.

A security fund contributes to combating software vulnerabilities, but it can also help with communication to the rest of the fediverse once a vulnerability is found. It incentives that standard industry practices regarding software vulnerability get followed, and make communication clearer to a wider audience. For example, if Pixelfed’s recent vulnerability had gotten a CVSS classification, it might have been easier to make the severity of the vulnerability explicit to other fediverse software admins. In turn, this might have made it more likely that server admins would communicate the situation with their users.

In last week’s email essay I also wrote about how the fediverse is missing governance infrastructure that connects the various independent nodes and communities. One way to view the fediverse is as a response to centralised Big Tech platforms. These platforms have centralised governance, and are under the control of few people. The fediverse’s response to this is to build a social network that consists of tens of thousands of independent communities, all with their own governance structure. The fediverse has been successful in decentralising the single entity that oversees a social network into many pieces that all oversee a small portion of the network. But it has struggled to build a governance structure that ties all these individual pieces together again.

The Nivenly Fediverse Security Fund is a good example of this problem: software security impacts all the thousands of independent fediverse communities, but there is no overarching structure to collaborate and improve the security. It took one server taking the initiative into their own hands and provide a service for the entire network, at their own cost. Ideally, communities would collaborate on such a security fund instead. Nivenly’s announcement does leave space for such a future direction of the fund, saying that they are open to “establish a longer-term committee to steward and maintain the program”.

Note: if you sign up for my email newsletter, you get a weekly essay about the open social web that I do not publish anywhere else. You can sign up right here:

The Lemmy developers, Dessalines and nutomic, held an Ask Me Anything recently, and here are some of the answers that stood out to me:

  • Lemmy is working towards their 1.0 release. This is currently expected to be in the fall, although nutomic also says that “these things always take longer than expected”. He also expects some instances like lemmy.ml already to upgrade some months before.
  • One of the main features for Lemmy 1.0 is private communities, where only approved accounts can browse and posts to the community. This type of closed group functionality is in high demand, and both Mastodon and Pixelfed have tried to implement it. Mastodon got a grant for it, but the proof-of-concept code has been sitting there since 2022. Pixelfed has announced and teased a group feature multiple times over the year and showed screenshots of it, but it also is not publicly available yet.
  • Lemmy posts are interoperable with Mastodon, but the interoperability is not great: a Lemmy post appears on Mastodon as the title plus the URL. There has been many conversations about how Mastodon handles content from other platforms, with no changes so far. In this AMA, nutomic is explicit in saying that it is up to Mastodon to change this. While Mastodon seems open to the idea, and has been in conversations with developers from platforms like Ghost and NodeBB on how to show their content better on Mastodon, there has been little indication that Mastodon is taking steps towards making Lemmy content also better visible on Mastodon.
  • On the subject of how Lemmy can grow, Dessalines describes it as an organic progress, saying: “niche communities on reddit will keep getting fed up with the changes, and migrate to lemmy.” Nutomic describes a similar dynamic for fedi and Bluesky more broadly, saying that he expects that over the long term the fediverse might grow in a similar manner: “when the Bluesky admins make decisions that the community doesnt like, and then there may be another migration wave to the Fediverse”. Both replies indicate Lemmy’s vision of how the project can grow in the long run: stay consistently working on your product, and because platforms like Lemmy are not beholden to investors, they can have a longer lifespan, and outlive platforms who are beholden to shareholder expectations.
  • Grouping of communities (similar to PieFed’s topics or Reddit’s multireddits) “will be implemented soon“.

Ahoy! is a one-day conference for the European Social Web, and will be held on April 24th 2025 in Hamburg, Germany. The conference is mainly focused on Bluesky and the AT Protocol, and has some super fascinating speakers of people who are in the forefront of building new communities on the open social web. If you’re around I can definitely recommend it. I’ll be doing some interviews with people there, so if you are considering joining, let me know and we can say hi!

The Links


That’s all for this week, thanks for reading! You can subscribe to my newsletter to get all my weekly updates via email, which gets you some interesting extra analysis as a bonus, that is not posted here on the website. You can subscribe below:

#fediverse

fediversereport.com/fediverse-…


Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

Da #PropagandaLive di venerdì scorso, LA NIÑA - Figlia d' 'a Tempesta: la7.it/propagandalive/video/fi…
Dal sito di Noi Donne il testo: noidonne.org/articoli/la-nia-e… #donne #femminismo #uguaglianza #lotte #diritti #canzoni
@macfranc
@scuola
@lindasartini
@Puntopanto
@maupao
@goofy
@Frau_Mensch
@alephoto85
@ebc974

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

One thing that's wild about climate change policy is that the US considers a carbon tax an absolute non-starter despite the critical need to reduce GHGs and then puts a 25% tariff on cars for practically no good reason.

reshared this

in reply to Evan Prodromou

I recall reading several months ago what seemed to be wishful thinking speculation (hmm, maybe _slightly_ better than that, based on quick search source may have been the then soon to be nominated treasury secretary reuters.com/world/us/bessent-c…) that a CBAM (likely only kind of tariff I'd be in favor of) could be part of the mix.

Instead we get massive stupidity, which happens to include tariffs on cars: even a crazy clock is occasionally correct-ish.

in reply to Evan Prodromou

This was interesting. As I mentioned in the comments, the Israeli government has a new department dedicated to "voluntary" departure of Palestinians to other countries in the world. I don't think starving people, under bombardment, have any kind of realistic consent, especially when lacking a right of return. So, I'd say no.

Un nuovo fondo di sicurezza viene attivato per aiutare a proteggere il fediverso

La @The Nivenly Foundation (Nivenly Foundation), ha annunciato il lancio di un nuovo fondo di sicurezza che pagherà coloro che rivelano in modo responsabile le vulnerabilità di sicurezza che interessano le app e i servizi fediverse.

techcrunch.com/2025/04/02/a-ne…

@Che succede nel Fediverso?


Over the past year, we've been thinking about how we can improve the security of the Fediverse to provide a safer, more trustworthy experience for people of the Fediverse.

Today we're launching a time-and-funds limited Fediverse Security Fund, where we will pay researchers and contributors for the responsible disclosure of security vulnerabilities in open-source Fediverse software.

We're starting small as an experiment to gauge interest, figure out our processes, and eventually decide if/how to expand this program and make it more permanent. If you're a security researcher or upstream contributor, join us in making the Fediverse a safer place.

You can read more about this program on our blog: nivenly.org/blog/2025/04/01/ni…


reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

I'm doing my first indoor germination this Northern spring. A dozen different sets of #NativePlants seeds, from Jerusalem artichokes to smooth aster to monarda fistulosa to pearly everlasting. They're going to live inside the house for about 6 weeks, and then harden off and move into the garden. It's exciting work! #gardening
Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

It was National Indigenous Languages Day yesterday.

canada.ca/en/prairies-economic…

reshared this

in reply to Evan Prodromou

Indigenous languages of North America can be very different in structure and vocabulary from European languages like English and French. I found the experience extremely challenging, and really mind-expanding. If your local indigenous community has language classes available to non-native people, I really recommend it.
Questa voce è stata modificata (1 anno fa)

reshared this

in reply to Evan Prodromou

It's also important to note that many indigenous communities consider their language a cultural treasure, and are not open to outsiders learning. Definitely use native-created materials and native-led courses if you are going to try to learn, to make sure you're using the treasure with respect and consent.
Questa voce è stata modificata (1 anno fa)

Joe Vinegar reshared this.

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

How different are your two most different Internet personae?

#EvanPoll #poll

  • 0-25% (56%, 70 votes)
  • 26-50% (23%, 29 votes)
  • 51-75% (9%, 12 votes)
  • 76-100% (10%, 13 votes)
124 voters. Poll end: 1 anno fa

Mastodon | i social media rafforzano il giornalismo indipendente: apritivo e presentazione al Festival Internazionale del Giornalismo di Perugia

Unitevi ai Mastodon per un aperitivo al Festival Internazionale del Giornalismo!

Siete curiosi di sapere come Mastodon sta plasmando il panorama mediatico per i giornalisti indipendenti? Organizzeremo un aperitivo insieme con una breve presentazione sulle ultime tendenze e sviluppi in Mastodon. Dopo la nostra presentazione, partecipate a una discussione e a una sessione di networking con il team di Mastodon, dove potrete condividere le vostre idee ed esperienze.

Saranno offerti drink e spuntini leggeri gratuiti.

Questo evento è aperto a tutti, ma è richiesta la registrazione, poiché lo spazio è limitato. Si prega di confermare la propria presenza tramite questo link.

Luogo: Umbrò , Via Sant'Ercolano 4, Perugia.

Informazioni di contatto: philip@joinmastodon.org

Organizzato da @Mastodon

poliverso.org/objects/0477a01e…


Mastodon | social media empowering independent journalism (Perugia International Journalism Festival)
Inizia: Venerdì Aprile 11, 2025 @ 6:30 PM GMT+02:00 (Europe/Rome)
Finisce: Venerdì Aprile 11, 2025 @ 8:30 PM GMT+02:00 (Europe/Rome)

Join Mastodon for an aperitivo at the International Journalism Festival!

Are you curious about how Mastodon is shaping the media landscape for independent journalists? We will host an aperitivo together with a short presentation covering the latest trends and developments in Mastodon. After our presentation, join a discussion and networking session with the Mastodon team, where you can share your ideas and experiences.

Complimentary drinks and light bites will be provided.

This event is open to all, but registration is required, as space is limited. Please RSVP via this link.

Venue: Umbrò, Via Sant'Ercolano 4, Perugia.

Contact info: philip@joinmastodon.org

Organised by Mastodon.

Posizione: Via Sant'Ercolano 4, Perugia

reshared this

Apr 11
Mastodon | social media empowering independent journalism (Perugia International Journalism Festival)
Ven 18:30 - 20:30 Europe/Rome Via Sant'Ercolano 4, Perugia
Poliverso - notizie dal Fediverso ⁂

Join Mastodon for an aperitivo at the International Journalism Festival!

Are you curious about how Mastodon is shaping the media landscape for independent journalists? We will host an aperitivo together with a short presentation covering the latest trends and developments in Mastodon. After our presentation, join a discussion and networking session with the Mastodon team, where you can share your ideas and experiences.

Complimentary drinks and light bites will be provided.

This event is open to all, but registration is required, as space is limited. Please RSVP via this link.

Venue: Umbrò, Via Sant'Ercolano 4, Perugia.

Contact info: philip@joinmastodon.org

Organised by Mastodon.

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

We watched "A Complete Unknown" last night. It was a great movie about what making music means to a culture and to oneself. Timothée Chalamet does a great job as Bob Dylan. The music is awesome and moving. Ed Norton is a sweet, deep Pete Seeger. The emotional stakes are high, and the Night That Dylan Went Electric feels like a personal and movement watershed. Don't miss it.

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

Which of these is the best word for a 250th anniversary?

#EvanPoll #poll

  • Semiquincentennial (21%, 28 votes)
  • Bisesquicentennial (13%, 18 votes)
  • Sestercentennial (6%, 8 votes)
  • Quarter millennial (58%, 76 votes)
130 voters. Poll end: 1 anno fa

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

"4. All Members shall refrain in their international relations from the threat or use of force against the territorial integrity or political independence of any state, or in any other manner inconsistent with the Purposes of the United Nations."

en.m.wikisource.org/wiki/Chart…

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

The media in this post is not displayed to visitors. To view it, please go to the original post.

In giro per #Milano oggi c'è un #tram chiamato #Liberazione. Nella foto in piazza Fontana. #Liberazione80 #ANPI #MobilitàSostenibie @scuola
@lindasartini
@Puntopanto
@macfranc

reshared this

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

Is the Fediverse part of the solution to the global rise of far-right populism?

#EvanPoll #poll

  • Yes (30%, 255 votes)
  • Yes, but... (41%, 338 votes)
  • No, but... (14%, 122 votes)
  • No (13%, 110 votes)
825 voters. Poll end: 1 anno fa

Mastodon-LaTeXclient

Lavori in ambito scientifico o in un ambiente in cui, in ogni caso, potresti leggere PDF con margini ampi impostati in Computer Modern? Vuoi rilassarti durante le ore di lavoro? Ecco il client Mastodon perfetto e di sola lettura per te: Mastodon-LaTeXclient trasforma la tua cronologia in un documento, così puoi tenerla aperta in modo molto discreto su uno schermo di lato!

github.com/halcy/Mastodon-LaTe…

@Che succede nel Fediverso?

Tratto dal blog di @halcy​

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

US Politics

Sensitive content

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

This newbie who just celebrated 100 days of #selfhosting was able to install #Apache and #Varnish on her #Ubuntu VPS (to prevent the "Mastodon Hug of Death" for link preview cards on her self-hosted Ghost blog). She's very proud of herself for all the sudo commands she successfully ran today. And she's weirded out talking about herself in the third person, so: I did it YAY.

LOVE LOVE LOVE this Linux / self-hosting journey I'm on. Thank you for all your support & encouragement ❤️

Poliverso - notizie dal Fediverso ⁂ ha ricondiviso questo.

Imperial war

Sensitive content

reshared this

in reply to Evan Prodromou

@Evan Prodromou We are doing everything in our power to prevent abuses by the government. We've been trying for years, and we can't guarantee that we will succeed. Especially considering that the courts and politicians won't even stop flagrant violations of our rights. You basically just blamed the Jews for not stopping Hitler. I know you mean well, but that is extremely upsetting and inappropriate.
in reply to Evan Prodromou

Thanks everyone who replied. My answer is "Yes, but". I think it's better for people in Canada and Europe than in the US; I don't know much about the rest of the world. I think for people in the US or traveling to the US, it's a good idea to be careful. Oh, and obviously if you're posting about how great the Trump Gaza Casino will be, I think you're going to be OK in the US and you might be complicit in crimes against humanity in other places.

The media in this post is not displayed to visitors. To view it, please log in.

The ATmosphereConf was last weekend, independent relays are starting to appear, and more.


ATmosphere Report – #109

The ATmosphereConf was last weekend, independent relays are starting to appear, and more.

Conference


This weekend was the first ATProto conference, the ATmosphereConf, in Seattle. Over two days there were a large number of speakers and sessions, with over 150 people in attendance, and a significant number watching the live streams as well. I could not make it to the US, so for a full overview of the event, I recommend this extensive article by TechCrunch’ Sarah Perez, who was present at the event. The entire event was livestreamed, and all talks can be viewed via this YouTube playlist.

Some assortment of thoughts I had while watching the livestream and VODs over the last few days:

  • Bluesky CEO Jay Graber gave a short speech, about her background as a digital rights activist, and how she is now “holding the door open, so people can see another world is possible”. Graber is clearly aware of her position, where she is seen as a figurehead of the network, while also wanting to build a decentralised network where there is place for competing platforms. Being a figurehead of a network, without becoming the de facto leader of the network, while also holding the leadership position of by far the largest organisation in the network, is a challenging position to balance.
  • Bluesky CTO Paul Frazee talked about where Bluesky came from and where it is going. One of the things he talked about is the consideration of why Bluesky decided on their own protocol and not ActivityPub. His answer focuses on practical considerations, especially how ActivityPub handles identity and account migration. Watching the ATProto Ethos talk by Bluesky protocol engineer Daniel Holmgren it struck me that the question could also be framed as a matter of lineage. Holmgren talks about how ATProto takes inspiration from the Web, Peer to Peer systems as well as Distributed Systems. Placing it in such a context makes it clear that ATProto has quite a different background and other ways of thinking than ActivityPub has.
  • Ændra Rhinisland talked about how community projects can become load-bearing for the network, without adequate support structures for the people who run such projects. She also runs the popular news feeds using Graze. Graze has been adding support for advertisements, and Ændra is one of the first to take advantage. In her talk she walked through how at current usage rates, the feeds could generate over $20k per month in ad revenue. She plans to use this revenue to support the queer communities building on ATProto, and showed early plans for a self-sustaining fund powered by Graze’s feed revenue, to support initiatives such as Northsky.
  • The talk by Ms Boba is a great indication of how much under-explored design space there is on Bluesky and ATProto. Her talk focuses on labelers and fandom communities, and has some great examples of how they can be used outside of moderation.
  • Blacksky founder Rudy Fraser gave an excellent talk, describing Bluesky as a skeuomorphism, meaning that it imitates the design of the product it’s replacing. This phase is a part of the adoption cycle for new technologies, but Fraser does not to stop at imitation but instead explore the new ways that communities can be build online. Fraser is specifically interested in building platforms that can serve mid-sized communities, ranging from hundreds of thousands to a few million people. The Blacksky community is an example of this, and Fraser hopes that Blacksky can inspire other communities to do the same. His framing of content moderation as community care and not a cost of business also resonated with me.
  • Erin Kissane’s talk goes into detail about vernacular institutions, local and grassroots organisations and practices that are often illegible to outsiders but deeply embedded in local communities. This allows them to be close to the needs of their community members, but makes them hard to see and understand from the outside. This outside illegibility is a double-edged sword: IFTAS served a crucial role for trust and safety in the fediverse ecosystem, but had to shut down to a lack of funding as a result of being illegible to financiers.

Some more articles on the events:


On relays


Bluesky PBC has been working on a new version of the relay that makes it easier and cheaper to host, under the Sync 1.1 proposal. This new version is now starting to roll out, showing a significant drop in resource usage. Bluesky engineer Bryan Newbold shared some statistics here. Independent ATProto developer @futur.blue set up his own relay as a speedrun. He shows that a full network relay can be run on a 50USD Raspberry Pi, with an easy-to-follow tutorial here.

That full network ATProto relays are cheap to run has been known for a while within the ATProto developer community, but that knowledge has not spread much yet. One reason for this is that independent developers have set up relays primarily for their own use, sharing access with a few friends, but no other publicly accessible full-network relays exist yet1.

Upcoming short-form video platform Spark is building their own complete infrastructure. Spark’s relay will publicly accessible, and hosted in Brazil. Having ATProto infrastructure outside of US jurisdiction is a conversation that has come up regularly, and often followed by the assumption that the alternative is to have infrastructure like a relay hosted in Europe. Spark is bringing in a slightly unexpected twist here, by having the first publicly accessible relay that is not owned by Bluesky PBC being hosted in Brazil instead.

Having other relays that are not owned by Bluesky PBC has been the subject of a lot of conversation, and the Free Our Feeds campaign was founded on the idea that a significant financial investment is needed to do so. Furthermore, it assumes that such a relay is not only expensive, but that it requires an extensive governance infrastructure to manage it. The current developments regarding relays call both of these assumptions into serious question: relays are cheap, not expensive. Furthermore it seems that there is enough incentive that organisations that are serious about building their own ATProto platforms are willing to run their own relays.

In Other News


Bluesky PBC has published a proposal on how they want to handle OAuth Scopes. OAuth Scopes is one of the main projects on the roadmap for the first half of this year. Currently, logging into an ATProto app via OAuth requires you to give that app permission to access all the data for your account. OAuth Scopes allows an app to only ask for the permissions that are necessary, and not the entire account. There are two problems that need to solve: the technical part of making it work, as well as the handling the UX to communicate clearly to people what data an app wants to access. The challenging part of the UX is how to handle the translation from the technical description of the data that is requested (stylised like ‘app.bsky.feed.getFeed’, for example), into a way that is understandable for the everyday user. The second challenge is that apps require permission not for one, but for many types of this lexicon data. A third-party Bluesky client that is restricted to only Bluesky data will still have to request a dozen of these Lexicons. A long list of technical lexicon names makes it impossible for regular people to have an informed opinion on what data is and is not being accessed. Bluesky PBC’s proposal is to group different lexicons into bundles, and create new lexicons that reference these bundles. Scoped OAuth can then request access to a bundle of lexicons, with a description that is legible for regular people.

Git repository platform Tangled is working on news ideas how a GitHub alternative might do things differently, and one of their first proposals is defining two types of pull requests. For another look at Tangled, this blog post experiment with what the platform allows.

One of the talks at the ATmosphereConf was by independent developer Rashid Aziz, who is the co-founder of basic.tech. Basic is a protocol for user-owned data, and seems to be fairly comparable to the PDS part of ATProto, with the major difference that Basic allows for private data on their version of a PDS. Aziz used the combination of these two protocols to create private bookmarks for Bluesky.

The new Record Collector labeler automatically displays if someone has been using other apps in the ATmosphere outside of Bluesky.

Rocksky is a new music scrobbler service on ATProto, that is currently in closed beta testing. It allows people to connect their Spotify account and automatically ‘scrobble’ (track) the music they are listening to.

The Links


Some tech-focused links for ATProto:

That’s all for this week, thanks for reading! If you want more analysis, you can subscribe to my newsletter. Every week you get an update with all this week’s articles, as well as extra analysis not published anywhere else. You can subscribe below, and follow this blog @fediversereport.com and my personal account @laurenshof.online on Bluesky.


  1. Cerulea.blue is a publicly accessible relay, using a custom implementation, but it is limited to non-Bluesky PDSes. ↩︎

#bluesky

fediversereport.com/atmosphere…