▲ 669 ▼ They Have No Idea How Fun The Water Park Is! (lemmy.ca) submitted 1 year ago by Sunshine@lemmy.ca to c/fedimemes@feddit.uk 91 comments fedilink hide all child comments
[+] jerkface@lemmy.ca 1 point 1 year ago* (last edited 6 months ago) (1 child) [removed by mod] permalink fedilink source parent hideshow 2 child comments replies: [–] irelephant@lemmy.dbzer0.com 3 points 1 year ago (2 children) I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit, Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request. There's a better explaination here: https://docs.joinmastodon.org/spec/security/ A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway. permalink fedilink source parent hideshow 4 child comments replies: [–] nutomic@lemmy.ml 3 points 1 year ago (1 child) Signatures are only used to deliver activities to inboxes. The Activitypub json data of posts is usually available without any auth. permalink fedilink source parent hideshow 2 child comments replies: [–] irelephant@lemmy.dbzer0.com 1 point 1 year ago A lot of servers require signatures on GET requests as well, for private posts and to block specific people/servers. permalink fedilink source parent [+] jerkface@lemmy.ca 3 points 1 year ago* (last edited 6 months ago) [removed by mod] permalink fedilink source parent
[–] irelephant@lemmy.dbzer0.com 3 points 1 year ago (2 children) I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit, Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request. There's a better explaination here: https://docs.joinmastodon.org/spec/security/ A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway. permalink fedilink source parent hideshow 4 child comments replies: [–] nutomic@lemmy.ml 3 points 1 year ago (1 child) Signatures are only used to deliver activities to inboxes. The Activitypub json data of posts is usually available without any auth. permalink fedilink source parent hideshow 2 child comments replies: [–] irelephant@lemmy.dbzer0.com 1 point 1 year ago A lot of servers require signatures on GET requests as well, for private posts and to block specific people/servers. permalink fedilink source parent [+] jerkface@lemmy.ca 3 points 1 year ago* (last edited 6 months ago) [removed by mod] permalink fedilink source parent
[–] nutomic@lemmy.ml 3 points 1 year ago (1 child) Signatures are only used to deliver activities to inboxes. The Activitypub json data of posts is usually available without any auth. permalink fedilink source parent hideshow 2 child comments replies: [–] irelephant@lemmy.dbzer0.com 1 point 1 year ago A lot of servers require signatures on GET requests as well, for private posts and to block specific people/servers. permalink fedilink source parent
[–] irelephant@lemmy.dbzer0.com 1 point 1 year ago A lot of servers require signatures on GET requests as well, for private posts and to block specific people/servers. permalink fedilink source parent
[+] jerkface@lemmy.ca 3 points 1 year ago* (last edited 6 months ago) [removed by mod] permalink fedilink source parent