▲ 1487 ▼ Welp that answers a lot of why all .ml are down (i.imgur.com) submitted 3 years ago* (last edited 3 years ago) by BarterClub@sh.itjust.works to c/technology@lemmy.world 521 comments fedilink hide all child comments https://very.bignutty.xyz/notes/9hf13it1ced3b2za
[–] Wander@yiffit.net 176 points 3 years ago (8 children) No, the signatures wouldn't match. permalink fedilink source parent hideshow 8 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 4 points 3 years ago (7 children) That's an assumption that lemmy will quit federating with a server that does not match. And what signature are we talking about anyway? Is not certificates... permalink fedilink source parent hideshow 7 child comments replies: [–] Wander@yiffit.net 17 points 3 years ago Activitypub signatures that each user and group sends out their messages with. permalink fedilink source parent [–] priapus@sh.itjust.works 1 point 3 years ago (5 children) It's not an assumption, it's how activitypub works. permalink fedilink source parent hideshow 5 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 0 points 3 years ago (4 children) Can you show me documentation that shows communities or servers are signed? permalink fedilink source parent hideshow 4 child comments replies: [–] priapus@sh.itjust.works 2 points 3 years ago (3 children) https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization permalink fedilink source parent hideshow 3 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] Saik0Shinigami@lemmy.saik0.com 4 points 3 years ago (7 children) That's an assumption that lemmy will quit federating with a server that does not match. And what signature are we talking about anyway? Is not certificates... permalink fedilink source parent hideshow 7 child comments replies: [–] Wander@yiffit.net 17 points 3 years ago Activitypub signatures that each user and group sends out their messages with. permalink fedilink source parent [–] priapus@sh.itjust.works 1 point 3 years ago (5 children) It's not an assumption, it's how activitypub works. permalink fedilink source parent hideshow 5 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 0 points 3 years ago (4 children) Can you show me documentation that shows communities or servers are signed? permalink fedilink source parent hideshow 4 child comments replies: [–] priapus@sh.itjust.works 2 points 3 years ago (3 children) https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization permalink fedilink source parent hideshow 3 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] Wander@yiffit.net 17 points 3 years ago Activitypub signatures that each user and group sends out their messages with. permalink fedilink source parent
[–] priapus@sh.itjust.works 1 point 3 years ago (5 children) It's not an assumption, it's how activitypub works. permalink fedilink source parent hideshow 5 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 0 points 3 years ago (4 children) Can you show me documentation that shows communities or servers are signed? permalink fedilink source parent hideshow 4 child comments replies: [–] priapus@sh.itjust.works 2 points 3 years ago (3 children) https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization permalink fedilink source parent hideshow 3 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] Saik0Shinigami@lemmy.saik0.com 0 points 3 years ago (4 children) Can you show me documentation that shows communities or servers are signed? permalink fedilink source parent hideshow 4 child comments replies: [–] priapus@sh.itjust.works 2 points 3 years ago (3 children) https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization permalink fedilink source parent hideshow 3 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] priapus@sh.itjust.works 2 points 3 years ago (3 children) https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization permalink fedilink source parent hideshow 3 child comments replies: [–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] Saik0Shinigami@lemmy.saik0.com 1 point 3 years ago (2 children) So looking at that spec... Nothing there is validation that current messages originate from an "original" server... I don't think either of these signature options for Server to Server communications means that my current lemmy.saik0.com instance can't be torn down (delete LXC container) and reconfigured as a brand new instance (New LXC container) and other instances wouldn't know that there's been a change to the instance running here... or more accurately would flag a change. I think these signatures are all about not being able to spoof OTHER instances. eg, lemmy.ml can't send messages on behalf of lemmy.world. permalink fedilink source parent hideshow 2 child comments replies: [–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] priapus@sh.itjust.works 1 point 3 years ago (1 child) I assumed that once federated the public key would be remembered and signatures that do not match it would be handled, but you may be correct. I do wonder whether this could be a problem as instances close down over time. I'll have to spend some more time researching to see if there's a more clear answer, or if any ActivityPub implementations have their own way of handling that situation. permalink fedilink source parent hideshow 1 child comment replies: [–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent
[–] Saik0Shinigami@lemmy.saik0.com 2 points 3 years ago Yeah that's my worry. I'm pretty sure(and could be wrong) that message/ keys are only checked on ingestion. So i would get key value for a message coming in and can check that is currently valid, not that it's "changed" since 2 months back. I think this could allow for some one to ressurrect an old Lemmy service and masquerade as the old one... communities , users... all of it. permalink fedilink source parent