Email or username:


Forgot your password?
28 posts total
Emelia 👸🏻

So I mentioned last night that my open-source work on the fediverse (mastodon, pixelfed, etc) was funded for 10-13 hours per month, in my head I had a figure of €1000/month that I was using as the donation income I receive.

I just checked and it's actually closer to €700/month.

Your support for my work is greatly appreciated & helps enable work that quietly affects about a million people.

Emelia 👸🏻

”But Mastodon also has [...] a lot on its plate including integration with Threads“

It's lines like this that makes me completely unable to take those calling for a hard fork of Mastodon seriously.

All Mastodon do for Threads is the same they for any fediverse developer having issues federating with them. (And there's certainly limits to that)

Along with perhaps writing more FEPs to standardize behaviour, which benefits *everyone*


Show previous comments
Jocelynephiliac :reclaimer:

@thisismissem mmm, I think they’re talking about the inevitable scaling needs that come with handling all that federation traffic


@thisismissem You often make perfect sense, and I often feel a bit guilty going on about quoted posts. But only because I saw us in a race to capture journalists. That ship has sailed. But we can now pivot and let Threads lure them in, then contribute new tools to support them and everyone else.

Emelia 👸🏻

Okay, so, remember how I had some big news? Well, I didn't get to announce it yesterday as I was unwell (I've been unwell most of the month and could really do with extra financial support right now!)

The big news is that my FIRES project has been granted funding by NLNet (@NGIZero) Entrust fund.

What is FIRES? It's a project I've been slowly working since September last year, and provides a server for maintaining and distributing moderation advisories and recommendations.

Show previous comments

Yes to a safer federation, and don’t forget the oxygen mask principle 🤗

@thisismissem @NGIZero

Uriel Fanelli

@thisismissem @NGIZero

just a little question: who the heck are you to tell others how to manage their own instances?


@thisismissem @NGIZero Soooo happy for you girl!! I remember the miscommunication and how difficult that was, and I’m glad you did resolve it because this project will have such an impact across many fediverse projects!!

You totally deserve this, and I’m glad your hard work is being acknowledged and funded!

You’re a fucking fediverse rockstar, and now you’ll shine even brighter with the grant and resources to see this through. Gosh I’m just so happy for you ❤️

Emelia 👸🏻

I do really want to thank @nivenly (and especially @esk) for sponsoring the work to fix the critical security vulnerability found in @pixelfed earlier in February:

Nivenly stepped up, even though they don't have a stake in Pixelfed, they just wanted to see the Fediverse be safer, more secure and all that.

Without their support, I wouldn't have been able to dedicate the time to handling that (since I'm a freelancer)

See also:

#nivenly #pixelfed

I do really want to thank @nivenly (and especially @esk) for sponsoring the work to fix the critical security vulnerability found in @pixelfed earlier in February:

Nivenly stepped up, even though they don't have a stake in Pixelfed, they just wanted to see the Fediverse be safer, more secure and all that.

Emelia 👸🏻

(edited to clarify I meant February 10th, not like.. March. I mean: time & months changing, what is this business 😂 )

Esk 🐌⚡💜

@thisismissem thanks for being awesome and doing the hard work to research & close it out! ❤️

and thanks @pixelfed for building something awesome for the fedi ❤️

Emelia 👸🏻

Details of the @pixelfed security vulnerability from February 10th have now been published.

If you are still using a vulnerable version (39.5% of pixelfed instances as of today), then you should update immediately, otherwise someone may just be able to turn off federation for your instance.

#pixelfed #security #fediverse

Emelia 👸🏻

Paper on Trust & Safety, titled ‘Securing Federated Platforms: Collective Risks and Responses’ from last year's panels with the Carnegie Endowment for International Peace cohosted by @yoyoel is now available, and it's well worth a read:

Very pleased that I could participate & contribute to this in a small part.

#Mastodon #Fediverse #TrustAndSafety

Emelia 👸🏻

That's something I'd love a reporter covering this spam wave to know: Discord is being used to coordinate illegal activity, and discord has no mechanisms for people to report abuse.

abuse@ and support@ emails are dead ends, and their contact form has no "report abuse" option that works. Reporting it via the child safety team also didn't work.

Update: TechCrunch covered it:

Show previous comments
grant :blobcatgoogly:​

@thisismissem @verge @404mediaco @theregister I’ve attempted contacting them through their normal support channels and got declined because “they only allow for messages to be reported”

Incredibly helpful.

Kevin Karhan

@thisismissem @verge @404mediaco @theregister

That is nothing new re: Discord, as it's just garbage SaaS and worse than even Slack or Teams.

IMHO noone should use it just by it's Terms and Enshittification alone.

#Discord #Cybercrime #Enshittification #SaaS #MicrosoftTeams #Slack #ToS #Spam #Cybercrime

Flit 🦊 ❄️

@thisismissem Discord’s support channels have been frustratingly useless for years, this is sadly not surprising to me :/

Emelia 👸🏻

So for an idea of just how much spam there was, for a moment fedidb was showing user-growth during the attack of 40 million accounts:

Looks like most of that can be attributed to a test server that had ridiculously inflated user counts.

Barkeeper Tom :damnified:

@thisismissem if I understoof correctly, this is rather unrelated to the spam problem and was caused by someone who was experimenting with a development instance that they created. Something went wrong ...

Emelia 👸🏻

Just 51.4% of #Pixelfed servers are still vulnerable; really hoping we reach below 50%, and ideally below 30% by the 25th February when the responsible disclosure period ends & details can be published.

Emelia 👸🏻

Wowzers, that Mastodon CVE recently was quite something:

• You can inject a post that is attributed to any remote user
• You can overwrite the server's copy of any remote user
• You can rekey the server's copy of any remote user, by just listing another key

The full technical write up is worth a read:

Show previous comments

@thisismissem @arcanicanis money quote:


But yet, Mozilla paid for a formal security audit of the Mastodon codebase, missed this, and yet this just tumbles into my lap. Great, I just resent the typical nature of the 'security consultancy' industry even more,



I've had suspicions based upon observation.

This fits.

cc: @jerry @paco


Emelia 👸🏻

58.5% of @pixelfed servers still have a critical vulnerability left unpatched.

I'll just highlight something: the vulnerability allows a third-party to gain administrative control over your instance if you don't update.

You really want to update as soon as possible, there's a reason this is a 9.9/10 vulnerability score.


Emelia 👸🏻

To the 208 @pixelfed servers that have upgraded so far, thank you!

Kevin Karhan

@thisismissem @pixelfed Consider reporting it to @certbund & @cert_eu ...

Maybe once it's acknowledged then hosters will intervene because they don't want shit to get abused for malware...

Matrix9180 :ruby: :rust:

@thisismissem @pixelfed hmmm... maybe I can white knight this shit and be the hacker that breaks in, upgrades their instance and leaves lol. Like jailbreakme back in the day. Lol

Emelia 👸🏻

Okay, have just submitted a PR to a fediverse project to fix a critical security vulnerability; CVE score is like 9.9/10.

More news once administrators of this servers using this project can upgrade safely.

Update: CVE was in @pixelfed, and the advisory is published here:

Emelia 👸🏻

Have submitted confidentially pull requests that fix both their main branch and currently released version.

(yes, I manually backported the fix from main branch to their last release because the vulnerability is that critical to fix)

Awaiting response from the project maintainers now.

Emelia 👸🏻

What should we call a group of fediverse servers working together in moderation & community practices?

I've been using Bloc in quotes, because I'm not sure if that's the right or most correct word for it.

#moderation #fediverse #TrustAndSafety

Anonymous poll


0 people voted.
Voting ended 11 January at 19:44.
Show previous comments
Joel Krampus Meador 🌰

@thisismissem Ring would please me more for the throwback and other uses it echoes. I like all the options you presented though, especially bloc and coalition

Liminal witch 🧙‍♀️ Sarah

@thisismissem group? May be those group will name themselves and in couple of years we'll have Alliance, Horde, Federation, Union, Hierarchy, Collective and Space.

Boris Mann

@thisismissem a co-op ;)

I don’t know that this needs to or should be labeled.

I totally understand that technically one might want to describe something.

But do we have labels for “working together” or other relationships, aka “it’s complicated” ;)

Emelia 👸🏻

To all folks working on #activitypub and the wider #fediverse: happy holidays & merry Christmas!

It's okay to take a break, relax, etc. our work can wait a few days to a week, the world won't implode.

Tim Chambers

@thisismissem Good advice... what a year. Take a breather.

And hope you have a great holiday break, @thisismissem !

Emelia 👸🏻

So that big news?

It's that I'm joining the @iftas Advisory Board, bringing my technical expertise to the challenges of moderation and trust & safety that they're working on for independent federated social media.

This has been a little while in the making, so I'm very happy that we can announce it.


Emelia 👸🏻

Hmm, I'd really love to find a project sponsor for my work on Mastodon, where it's like €500-1000 per month to dedicate a certain amount of time per month to Mastodon.

My work is mostly on the Mastodon Streaming server, but also the OAuth 2.0 setup where I'm trying to make it more standardised.

Also, you'd get listed on my website & potentially as a line in PR comments/descriptions.

Emelia 👸🏻

In an AMAZING update, two very generous individuals have gone above and beyond in supporting my work on moderation tooling and trust & safety in the Fediverse.

One ( @defn ) became an Active Supporter (€20/month) but also made a one-time contribution of €300, which is coming at a much needed time for me.

The other became a Tier 1 Sponsor (€250/month), bringing the total monthly recurring income to €590!!!

If you'd like to support my work, then:

Emelia 👸🏻

Just €20 in recurring monthly donations to go until I reach €300 / mo! Wooo!

I'm also working on some really awesome stuff at the moment, which I hope to be able to share with y'all soon. Have also been having some really interesting conversations with @dansup about #Pixelfed!


Emelia 👸🏻

TIL: The maximum length of a domain name is 253 characters, and each label (`.` separated part) can only be 63 characters, and this is consistent regardless of whether you use punycode or not.


I had to point a customer at the RFC and translate it for them when they were insisting they
needed a hideously long name for their host.


@thisismissem as somebody who has managed to bounce off the default length limits for

- Windows IIS Application Pools names
- Windows IIS upload limits
- MS Active Directory Usernames
- Windows files names
- Windows IIS query strings (this one is embarassing, it's 2048 chars)
- Various length-limit crimes in SQL Server.

I take this rule as both a challenge and an insult.

@thisismissem as somebody who has managed to bounce off the default length limits for

- Windows IIS Application Pools names
- Windows IIS upload limits
- MS Active Directory Usernames
- Windows files names
- Windows IIS query strings (this one is embarassing, it's 2048 chars)
- Various length-limit crimes in SQL Server.

Go Up