6 ms·
This protocol is a successor to OStatus (GNU Social), and mostly made by the same people. From what I remember, Mastodon switched from OStatus to ActivityPub a
by kemenaran 9y ago
This protocol is a successor to OStatus (GNU Social), and mostly made by the same people.
From what I remember, Mastodon switched from OStatus to ActivityPub a few releases ago. In the past they had to extend the OStatus protocol for private messages, which meant some clients may not honor the private status of theses posts. ActivityPub has private messages defined properly in the spec.
It seems PeerTube (https://github.com/Chocobozzz/PeerTube https://github.com/Chocobozzz/PeerTube) will also use ActivityPub.
- carussell 9y agoLast summer I tried untangling the OStatus/pump.io/ActivityPub/ActivityStreams nest hoping to piece together a big picture mental image based mostly on what Wikipedia has to say, and found it mostly frustrating. For anyone who's similarly curious or confused, LWN published a pretty great overview last month—their "Federation in social networks" article: https://lwn.net/Articles/741218/ https://lwn.net/Articles/741218/
- coldacid 9y agoThanks for this. I was grinding my wheels much the same way, so hopefully this LWN article will clear things up for me.
- Xeoncross 9y agoThanks! After reading that article I'm curious where public key cryptography fits into this.
- rogerbraun 9y agoIn AP, messages are signed with http signatures (https://tools.ietf.org/html/draft-cavage-http-signatures-09 https://tools.ietf.org/html/draft-cavage-http-signatures-09). OStatus has a similar mechanism called salmons, which are signed XML payloads.
- Xeoncross 9y agoserver-to-server signatures are a good start, but what about encrypting messages end-to-end? I assume the servers already talk over HTTPS.
- rogerbraun 9y agoit's really not worth it. If people want to exchange encrypted messages, they should use a proper tool for that.
- Xeoncross 9y agoPlease don't say that. We already had such pain from HTTP, FTP, and SMTP not starting with it. If building the next version of internet discussion and sharing, we really need first-class support for encryption.
- rogerbraun 9y agono, we really don't. Not every tool needs to be equipped for private discussions. ActivityPub and OStatus are used for Twitter-style communication. Those aren't high security communication services.
- CodeMage 9y agoI might be wrong, but I would think that end-to-end public crypto can be used for more than just ensuring privacy.
- recursive 9y agoHTTPS ensures more than just privacy. For instance, authenticity.
- freshhawk 9y agoThey turn into security problems in aggregate. For example, the threat to me from actors slurping up social media data to nudge/manipulate people at a large scale is much larger than the threat to me than someone reading my group chats to my friends or a lot of other personal info that is generally considered more private and more in need of high security. If my personal twitter-style communication got out it would be worse to me than my more private messages, but it is worse to me personally if all the twitter style communication gets out than only my more private messages. You have to account for manipulative big data risks in your analysis, thinking only about your personal data is an outdated approach.
- jcrawfordor 9y agoI'm the author of the LWN article, so glad to hear the positive feedback. I wrote it because I run a Mastodon instance and have been getting pretty confused about how these fit together. ActivityPub is a very exciting direction and I'm hoping to see Mastodon implement it completely (right now their support is only partial). OStatus comes with a lot of historical baggage - down to the name itself - and that's bumping up poorly against modern expectations like privacy.
- rogerbraun 9y agoPrivacy on the level of AP would have been very easy to add, by just using a different salmon endpoint for private messages. This was discussed at length back then, but Mastodon still chose to implement the leaky-by-default changes. There's nothing in AP that can't be done using OStatus, with very very minor extensions.
- NetOpWibby 9y agoCould you elaborate on "salmon endpoint"?
- rogerbraun 9y agoIn OStatus 'salmons' are messages sent from one server to another that contain posts. They are signed, so the receiving server knows if it can trust it. If person peter@example.com mentions bob@differentsite.org, a salmon is sent from example.com to differentsite.org containing the message. The endpoint that this is posted to is the 'salmon endpoint'. Using a second endpoint for privacy enhanced messages would have the way to go. Old servers wouldn't ever receive private messages, while new servers that understood the extensions could have kept 90% of their old code and infrastructure.
- NetOpWibby 9y agoOh that's nice, thanks for the explanation. I'm currently working on a social network and I like the idea of being able to connect with other ones via open standards. I need to do more research on implementation.
- rogerbraun 9y agothere's #social on freenode, although it's not very active. You might have more luck asking your questions on #pleroma on freenode (another Ostatus/AP server) or on the mastodon discord.
- 9y ago
- nothrabannosir 9y ago> which meant some clients may not honor the private status of theses posts. Does this mean they may have accidentally published a message intended as private, to the public? If so, I don’t think I can imagine a more efficient way to rob me of any confidence I ever had in Mastodon…
- rogerbraun 9y agoYes, and this was known to the main developer. There were easy ways to make it at least private if the other server was trusted, but they chose to not implement them.
- kemenaran 9y agoWhich is why they switched to dual OStatus / ActivityPub broadcasting – except for private messages, which are now only sent over ActivityPub. All of this without breaking compatibility across instances running different versions; quite a nice piece of engineering IMHO.
- rogerbraun 9y agothis doesn't make much sense. The very easy way to add AP-level privacy to ostatus was to just use a different salmon endpoint for private messages. This way, messages would never have federated to servers that don't respect privacy settings (by accident. if the server leaks on purpose, that's a different story). This solution was discussed at length with mastodon devs before the implementation of the private messages. It was ignored. Now we have a situation were Mastodon is likely to switch off OStatus soon, leaving behind all those projects that don't have the dev resources to rewrite their core federation systems every few years. The Ostatus/AP dual stack is also pretty hacky and not even valid according to the AP spec, although it's getting better all the time.
- deleted 9y ago[deleted]
- ams6110 9y ago
- evanprodromou 9y agoThat's probably a fair consideration. I and others worked on an intermediate system called pump.io, and the ActivityPub interface is very similar to the pump.io client-to-server API and federation protocol. The biggest advantages of ActivityPub over OStatus are: JSON instead of Atom XML; a defined client-to-server API; and private distribution, including to contact lists (like Diaspora's aspects). As someone who has worked on this type of standard for over a decade, I can say that it's the best federation standard I've ever seen, and I've seen them all.