you are viewing a single comment's thread
view the rest of the comments
[–] 9 points 1 year ago (2 children)

We might eventually have to get more exclusive, or have separate "public" and "private" modes/communities, maybe like how masto handles post visibility...

I'm not sure if the open internet can ever be fully trusted, especially now with roving packs of predatory crawlers scraping for genuine human OC for their plagiarism machines.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 1 year ago (1 child)

    I doubt they're crawling stuff over AP, you usually need a HTTP signature for that, and no bot is going to bother with those.

    Most crawling would just be spamming the web interface.

  • source
  • parent
  • hideshow 2 child comments
  • [+] 1 point 1 year ago* (last edited 6 months ago) (1 child)
  • [–] 3 points 1 year ago (2 children)

    I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit,

    Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request.

    There's a better explaination here: https://docs.joinmastodon.org/spec/security/

    A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway.

  • source
  • parent
  • hideshow 4 child comments