I have a request.
Bad actors will soon figure out - if they haven't already - that setting up impersonations of important organizations now will allow them to set off an explosion of chaos and confusion at a time of their choosing.
So if you run an account for an organization (especially #LGBTQ), please set up link verification between your Mastodon account profile and your organization's website.
If not, please boost.
Instructions are here under "Link Verification":
https://docs.joinmastodon.org/user/profile/
To all mastodon admins:
Hi! I’m Evan Phoenix, the primary author of puma, the ruby webserver that powers mastodon!
Please reply or DM me if you need tuning help! I’ve got no officiation with the mastodon, just want to see you succeed!
(Quick Tip: set WEB_CONCURRENCY to core count * 1.5 and then tune MAX_THREADS. High thread values will see diminishing returns!)
Starting this instance on a server with "some space and an IPv4 address available" was a naive thing. I'll figure out how to move to the bigger machine next week. So far everything worked with zero downtime, but moving to a bigger server might mean ~15 minutes unavailable when I either have to move a subnet or change IP address – or both.
Better.Boston service announcement/postmortem
Our server has seen record numbers today. At 1:30pm EST, our server became backlogged and couldn't keep up with the number of posts that needed to be pulled from other servers.
This was noticed at 1:53pm, and we quickly used an idling server that was on standby to catch up on the backlog of posts (as soon as I got back from lunch)
The system fully caught up by 2:09pm EST, and seems to be back to full health.
Worked without downtime: xl block-attach on the Xen side and btrfs add on the toot side did the job. But expect toot.bike to be a bit laggier the next few hours since filesystem balancing is on the way.
Reading through the pages I have not seen anything that can be punished under german law. But still so much hate. I am so happy with the decentralized Fediverse: Large platforms can be forced to contract (nice #GermanWord Kontrahierungszwang), here we first can say: 1. Go, build your own Fediverse instance, protocols are open! 2. Blocking your instance does not stiffle free speech, every potential recipient can look at your local timeline!
updated to indicate only glitch-soc is affected. There are other security updates in mastodon 4.0.x so not wasted effort to update if not running glitch-soc
This message for everyone on the fediverse:
First, please ensure you go into your account settings and enable two/multi factor authentication. No, I mean do it right now. I’ll wait till you’re done.
…
…
Ok, thank you.
Now, if you are the admin of a mastodon instance running glitch-soc, please go upgrade to 4.0.2 ASAP.
Background: https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
Should we show the local timeline or the federated timeline for non-members clicking
https://toot.bike/public ?
We are moderating toot.bike. Please follow us, since we will also provide information on downtimes etc. Most of the time Mattias Schlenker is tooting here.