Skip to main content


psa wanting my account to be discoverable to the public isn't consent to have all my shit scraped and sold for profit

zaki reshared this.


Sensitive content

This entry was edited (18 hours ago)

reshared this


zaki reshared this.


pls gib tips on buying maid dress (i am currently in japan)

reshared this


zaki reshared this.


New sensitive breach: Lexipol had 672k email addresses breached last month by self-proclaimed "Puppygirl Hacker Polycule". Data included name, phone and MD5 or SHA-256 password hashes. 23% were already in @haveibeenpwned. Read more: them.us/story/puppygirl-hacker…
in reply to Have I Been Pwned

1. I'm prolly in there, my work email that is
2. Don't care that I am. Get em/us, puppygirls

zaki reshared this.


Wake up babe, @GIMP 3.0 was just tagged 👀

gitlab.gnome.org/GNOME/gimp/-/…
gitlab.gnome.org/GNOME/gimp/-/…

You can get GIMP 3.0 on Flathub: flathub.org/apps/org.gimp.GIMP

#GIMP #GNOME #Flathub #Flatpak

This entry was edited (1 week ago)

reshared this


zaki reshared this.


⚠️ FEDIVERSE WARNING - FEDIBLOCK ⚠️

🇬🇧 English version below.

---
🇪🇦 URGE #fediblock a freysa.ai / social.freysa.ai

Esta instancia cuenta 1500 usuarios, todos ellos generados por IA, enviando spam random al fediverso en forma de estados con #hashtags creando falsos trendings. Se han detectado 1787915 estados generados por IA con #hashtags mientras escribo esto. (ver imagenes)

Ejemplo, ver linea local:
- social.freysa.ai/api/v1/instan…
- social.freysa.ai/public/local

Esto además, puede causar que las bases de datos de las instancias con las que federe gasten recursos y espacio en disco innecesarios almacenando esta basura.

Estas cuentas generadas por IA y con estados podrian usarse para realizar ataques de SPAM a usuarios del fediverso con @mentions
--

🇬🇧 URGENT #fediblock to freysa.ai / social.freysa.ai

This instance has 1500 users, all of them AI-generated, sending random spam to the fediverse in the form of posts with #hashtags that create fake trending topics. As I write this, 1,787,915 AI-generated posts with #hashtags have been detected (see images).

Example, see local endpoint:
- social.freysa.ai/api/v1/instan…
- social.freysa.ai/public/local

This can also cause the databases of federated instances to waste resources and disk space by unnecessarily storing this garbage.

These AI-generated accounts and posts could be used to carry out SPAM attacks on fediverse users using @mentions.

- Trankten :tkz:

reshared this



zaki reshared this.


reshared this


zaki reshared this.


FYI if you got a framework 16 prior to november 2024 you should check to see if you having thermal issues and consider requesting a replacement

reshared this


zaki reshared this.


A proposal by BlueSky to allow you to opt out of training AI.

Oh lookie here.

First, some background.

Speaking at the SXSW conference in Austin on Monday, Bluesky CEO Jay Graber said the social network has been working on a framework for user consent over how they want their data to be used for generative AI.

Now onto this.

Link below but #Bluesky will start selling your data to train AI. The fact this is a proposal and something the CEO is pushing for should tell you that this is a small step towards selling everyone's data, regardless of whatever you want to happen.

Many here are willing to actually trust CEO's for some reason.

A CEO wants to make money. Period. That is their primary function.

This proposal is opt out, not opt in. Otherwise, they wouldn't go on the record with this comment...

Speaking at SXSW, Graber explained that the company has engaged with partners to develop a framework for user consent over how they would want their data to be used — or not used — for generative AI.

The fact a CEO is considering something multiple times should tell you your wishes will be violated to make a profit. If not now, but eventually.

github.com/bluesky-social/prop… #AI #socialmedia

This entry was edited (2 weeks ago)

reshared this

in reply to Robert Kingett

@ErickaSimone It doesn’t say anything to that effect though? If anything that looks like a good proposal for Mastodon/Fedi to adopt, and create a structured version of what people just stuff into their bios freeform right now, giving people more tools for consent.
in reply to Alec Perkins

@alec @ErickaSimone

Nonsense. You don't need to put a sign on your car saying you do not authorize people to break into your car. This is total baloney.

in reply to Mastodon Migration

@mastodonmigration you would if the terms of service you had to agree to in order to get your license said that you agree that your car can be broken into at any time, and that the terms of service can be changed at any time and your continuing to drive after the effective date constitutes your acceptance of the new terms.
in reply to Mastodon Migration

@mastodonmigration if that’s the metaphor we’re going with, then this is a proposal for implementing valet keys.


zaki reshared this.


Dear fedi audience viewing this post

I am gonna fucking loose it.

RE: bsky.app/profile/did:plc:xknqt…

This entry was edited (2 weeks ago)

reshared this


zaki reshared this.


i really need to follow more filipinos and filipino furries in particular there are far too little of them on my feeds

reshared this


zaki reshared this.


mh-, disorder, help appreciated

Sensitive content

reshared this


zaki reshared this.


look i don't care if ur classes are suspended or not if the heat index is 46C don't fucking go to class if you can't survive that

reshared this


zaki reshared this.


:boost_requested:​ send me your favorite artists please i wanna look at cool art especialyl gay furries

reshared this


zaki reshared this.


:boost:​ Hi! I'm planning on escaping my current place to move to a safer location with friends, where I'd be able to actually live my life.

For that I need around 600 euros to cover travel expenses and food for the time it'll take me to find a job and stable housing, for the first month. I'm planning on leaving first week of April, but this may change.

Goal: 612/600 euros

If you don't want that money to be lost forever, you can lend me money and I'll make sure to refund you whenever I'm able to. That'd be very appreciated. No matter what, every cent I get through this will be invested back into mutual aid again once I'm out of this mess.

Thank you so much for your help, it helps me so so much! ❤

XMR: 48xs4QpbS6DhzR1gKg3HEEWfhAm3f7VD9XYAZriAkykcheRtKfKu6Eqj5wysquqgE25i2QQPewo9qYQZL1qtKPR6JE1AKXP

liberapay.com/tasiaiso/
ko-fi.com/tasiaiso/
IBAN: FR76 1390 6000 0400 1941 3656 074

ETH: 0x55C578E2b588C4617CEd436A7fcC9392a0ebe0A5

BTC: bc1qxqvnzt5xw6fr78czptzsn67a9qcanf5smdx9v4

#mutualaid #mutualaidrequest #transcrowdfund #transmutualaid@mutualaid@a.gup.pe @crowdfunding@a.gup.pe

in reply to tasia :therian:

boosting this post also helps me a lot ❤


Boosts appreciated :3 ​:boost:
Me and my friends have made these paracord collars a bit ago and they're pretty fun to make, so if you want me to make one for you or a friend, i'd be glad to do it! I can also make similar bracelets.

You have complete control over the colors and accessories. Also, we can put an NFC tag on it to point to a website, a fedi account or contact information when someone scans your collar.

You can DM me here or on Matrix (@tasiaiso:vulpinecitrus.info) for more info.



zaki reshared this.


cursed art idea

Sensitive content

reshared this



zaki reshared this.


The domain `mirage.foxb612.com` and IP address `65.108.53.178` have been blocked (defederated) from Enby.Life. These are part of a fediverse crawler system that indexes servers based on the country where they are physically located. This wouldn't normally be against our rules, but the crawler goes to great lengths to de-anonymize instances, including sending fake-signed ActivityPub probes to obtain the server's true IP address. Requests from the crawler use a web browser's User Agent to evade filters, and documentation on the website mentions that CloudFlare bypasses are also in use. Given the complexity of setting up something like this, we believe that the crawler is likely operating with bad intentions. While there could be some use for an index of instances based on community region, tracking the actual *physical location* of the server backends is highly suspicious. I'd encourage all instance admins to consider whether something like this poses a threat, and to take appropriate action. For anyone interested in going beyond a simple domain block, please see these log excerpts typical of being crawled via AP probes. Logs are taken from a non-standard Sharkey deployment and may not directly translate to other software, but I've tried to include as much detail as possible anyway. Sharkey admins can check whether you've been scanned by searching for backend log patterns like this (make sure to replace your instance hostname where appropriate): ```log Feb 17 20:10:21 campsite run-sharkey.sh[241576]: INFO * [apserv sigcheck] req-yzi /users/9fpwmts9tv (by Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0) apparently from mirage.foxb612.com: we don't know the user for keyId mirage.foxb612.com/kiite/key/e… trying to fetch via mirage.foxb612.com/kiite/key/e… ``` Alternately, anyone with Activity Logging in place can check for AP fetch errors like this: ```csv id,at,duration,host,request_uri,object_uri,accepted,result,object,context_hash a4n23pddff,2025-02-24 20:10:24.433000 +00:00,894.86,mirage.foxb612.com,mirage.foxb612.com/kiite/key/e… invalid content type of AP response - content type is not application/activity+json or application/ld+json: mirage.foxb612.com/kiite/key/e… ``` A final indicator is reverse-proxy logs showing this domain as part of an HTTP Signature header. Here's an example from our Caddy server: ```json Feb 24 20:10:25 campsite caddy[916]: 2025/02/24 20:10:25.329 ERROR http.log.access.log0 handled request { "request": { "remote_ip": "65.108.53.178", "remote_port": "53964", "client_ip": "65.108.53.178", "proto": "HTTP/1.1", "method": "GET", "host": "enby.life", "uri": "/users/9fpwmts9tv", "headers": { "Accept-Encoding": [ "gzip, deflate" ], "Accept": [ "application/activity+json" ], "Connection": [ "keep-alive" ], "Content-Type": [ "application/activity+json" ], "Date": [ "Mon, 24 Feb 2025 20:10:23 GMT" ], "Signature": [ "keyId=\"https://mirage.foxb612.com/kiite/key/enby.life/1740427823/Y93ZjgZHZlxNSuxa/main-key\",algorithm=\"rsa-sha256\",headers=\"(request-target) host date\",signature=\"5umGzjOXHeV8DdI4NjQqwbag6ChMKYS6\"" ], "User-Agent": [ "Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0" ] }, "tls": { "resumed": false, "version": 772, "cipher_suite": 4865, "proto": "http/1.1", "server_name": "enby.life" } }, "bytes_read": 0, "user_id": "", "duration": 0.901198418, "size": 254, "status": 500, "resp_headers": { "Date": [ "Mon, 24 Feb 2025 20:10:25 GMT" ], "Access-Control-Allow-Origin": [ "*" ], "Alt-Svc": [ "h3=\":443\"; ma=2592000" ], "Content-Type": [ "application/json; charset=utf-8" ], "Strict-Transport-Security": [ "max-age=15552000; preload" ], "Access-Control-Allow-Methods": [ "GET, OPTIONS" ], "Content-Length": [ "254" ], "Access-Control-Allow-Headers": [ "Accept" ], "Server": [ "Caddy" ], "Access-Control-Expose-Headers": [ "Vary" ], "Cache-Control": [ "private, max-age=0, must-revalidate" ] } } ``` #FediBlock #BlockRecommendation #Moderation #Crawler #Scraper


found a weird new fedi crawler thing, will post details and block instructions soon

This entry was edited (3 weeks ago)

reshared this

in reply to Hazelnoot

this only works on cloudflare proxied instances anyway, right? Where you'd end up deanonomyzing yourself by publishing to an inbox?

IE if you have wire guard on a VPS you're fine

in reply to Julia :v_bi:

no, it works on regular instances too. I verified by checking for Enby.Life which has never used CloudFlare. It correctly identifies the server as being located in the USA.
in reply to Hazelnoot

I'm not so concerned about country, but like, I'm worried about exact IP addresses, which SHOULD be masked by wire guard, but if they're not they could lead back to the city my mom lives in
in reply to Julia :v_bi:

if I move it back to my own house that could be a serious safety issue
in reply to Julia :v_bi:

does your instance proxy outbound requests through WireGaurd? If so, then you should be fine.
in reply to Hazelnoot

yes, it does, for exactly this reason
in reply to Hazelnoot

I totally forgot to mention, this thing sends probes using a web browser user agent (Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0) and an ActivityPub content type (application/activity+json). This will never be done by a legitimate instance, and is another way to reliably detect malicious requests.
This entry was edited (3 weeks ago)

zaki reshared this.


long (if it gets cut off view on my instance), confession, actually not a shitpost, i'm so sorry fedi, can y'all help me out with this pretty please

Sensitive content

reshared this

in reply to Latte macchiato :blobcoffee: :ablobcat_longlong:

long (if it gets cut off view on my instance), confession, actually not a shitpost, i'm so sorry fedi, can y'all help me out with this pretty please

Sensitive content

in reply to shellbyte

long (if it gets cut off view on my instance), confession, actually not a shitpost, i'm so sorry fedi, can y'all help me out with this pretty please

Sensitive content


zaki reshared this.


It's honestly laughable how we went from an era where the only universally agreed upon bad browser was IE, and now we're at a point where there isn't a universally agreeable good one

reshared this




zaki reshared this.


If you're thinking about switching away from Firefox, at least make sure you don't put your trust in a company which is worse, because that would be fucking pointless.

reshared this


zaki reshared this.


"they had no other choice mozilla is insanely under paid"

HAHAHAHA

in reply to Emil Jacobs - Collectifission

Just the CEOs salary alone should be enough money to pay en entire team of fulltime developers to maintain the entire browser.
in reply to SuperDicq

if they believe in AI so much, it should have no problem doing the job of CEO.

zaki reshared this.


this is probably a dumb question, but, like, I don't understand why there isn't a good Firefox fork at this point ?

is it really that hard to fork Firefox and remove all of the monetization decisions made by mozilla over the past few years, while keeping the rest of the browser ?

like, I realize that if the open-source community is treating bad mozilla leadership like a problem we'll have to deal with, it's probably because there's a reason why it's difficult to just remove their bullshit from the browser and keep using the rest. but I'd like to understand what the reason is.

reshared this


zaki reshared this.


mozilla have just removed their "we will never sell your personal data" statement from their ToS

github.com/mozilla/bedrock/com…

reshared this


zaki reshared this.


pol, question

Sensitive content

reshared this


zaki reshared this.


USPol, Furry Related

Sensitive content

reshared this


zaki reshared this.


diapers, pee, boosts ok obviously

Sensitive content

reshared this


zaki reshared this.


why does it feel like framework enshittification has begun

reshared this


zaki reshared this.


petition for trans rights

Sensitive content

This entry was edited (1 month ago)

zaki reshared this.


how long till we get federated barq

reshared this


zaki reshared this.


We're announcing some products tomorrow that many of you have been waiting a long time for!

reshared this

in reply to Framework :fedora: :ubuntu:

You guessed right! It’s a new Ryzen AI 300 Series Mainboard for Framework Laptop 13!
in reply to Framework :fedora: :ubuntu:

ngl... putting the mainboard in a printer output.....
Either it's just "heh, mainboard fresh off the printer"

OR IT'S HINT RIGHT IN OUR FACES, that a #Framework PRINTER is in the works!?!

We see right through you Framework!!!

XDDD 👍 (low key excited for a printer though if that's actually happening. It'd instantly preorder 2)

This entry was edited (1 month ago)
in reply to Framework :fedora: :ubuntu:

why does it appear to be in a printer? 🤔 🤔 🤔
This entry was edited (1 month ago)
in reply to Framework :fedora: :ubuntu:

is this board drop in compatible with existing amd based framework 13s?

zaki reshared this.


Did you know that the hardware that hosts foggyminds.com has worms inside of it
in reply to Lesbian Liv

how the fuck did RFK infect our infrastructure god damn it

zaki reshared this.


Your lucky instance is: final.town. Go out and make some new friends!

zaki reshared this.


did any of the instances that have "$INSTANCE" support ever try using that shit in a FediBlock post

reshared this


in reply to Amber (WoofGPT6.9)

the logic on that is simply that when you create a note your instance has to send a Create(Note) activity to several other instances. during this time you can change what the content is depending on the instance you're sending it to. In this case it's simple variable substitution. if you have auth fetch enabled you can expand it a bit more to change the content depending on who's fetching it (because you need to verify the signature requiring you to know what instance is requesting it to grab their key)

zaki reshared this.


Recently, Google has pushed out two new system apps to many Android devices: Android System Safety Core and Android System Key Verifier. There has been a lot of outrage and misinformation about that, which has been blindly shared without bothering to check the truth or dig deeper. There is a great blog post by @SteffoSpieler and @finn about that whole thing, which you should read: steffo.blog/outrage-warps-real…
This entry was edited (1 month ago)

Unknown parent