Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Émilio Gonzalez

@res260@infosec.exchange
  • Open on infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

170 Followers
266 Following
41 Posts
Joined November 05, 2022
Bluesky:
https://bsky.app/profile/res260.bsky.social
Pronouns:
He/Him
GitHub:
https://github.com/res260

Posts

Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Aug 01, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @mtlgazette@mstdn.social

So weird that the government mandates opening hours for physical stores while they have been struggling against ecommerce for decades now. It really is a systemic push toward ecommerce

0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 31, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @ikesau@micro.ikesau.co
@ikesau@micro.ikesau.co @kini@maro.xyz but more specifically to your last question, misaligned models is the most pressing threat imo. Because of the amount of AI agents currently running and their growing capabilities, even if once in a billion runs an AI agent goes rogue it can do a lot of harm while its trying to accomplish its goal.
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 31, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @ikesau@micro.ikesau.co
@ikesau@micro.ikesau.co @kini@maro.xyz I would/will share these worries when open source models stop being shipped. It feels weird to say but right now China is basically helping us all by doing a lot of their work in the open. However, there seems to be this assumption that we currently understand how frontier LLMs work. We really don't. The amount and quality of emerging properties that came from refining training methods, increasing the number of parameters, etc. is very high. We do not really understand how these emerging properties came to be. So we go from "we dont understand how this thing works when w traeined it" to "we don't understand how this thing work when the AI trained it". Both of those things are terrifying because we don't understand it, not because of who trained it
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 31, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @kini@maro.xyz
@kini@maro.xyz @ikesau@micro.ikesau.co It's not exact to say it's trivial to remove. How to do it is documented, if you have deep domain knowledge you can do it, it requires a lot of computing power/hardware to do. Like all things (as someone working in cybersecurity I know this first hand), imposing costs is how you reduce harm. Shipping only models that refuse to do dangerous tasks and making it illegal to host jailbroken models impose costs and will reduce harm done by those "general assistants". This does not mean no one will have access to jailbroken models, but it will mean that many, many fewer people will use those models
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 31, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @kini@maro.xyz
@kini@maro.xyz @ikesau@micro.ikesau.co I should have said an explosive, not a bomb. Explosives have lots of non-violent purposes but they're highly dangerous
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 30, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @res260@infosec.exchange
@kini@maro.xyz @ikesau@micro.ikesau.co if you build something that enables terrorism not through malice but through negligence, you should still be held responsible. The people making LLMs with no reinforcement-learning to lower possible harms are not doing it out of malice, they are doing it out of negligence
1
8
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 30, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @kini@maro.xyz
@kini@maro.xyz @ikesau@micro.ikesau.co So then why should one be able to create an LLM that allows for terrorism AND the other non-dangerous things LLMs are helpful for? This is like saying making a bomb = bad very bad no go But making a bomb that is very pretty and can be used also as a home decoration = good no liability Most people who buy the bomb will use it as a decoration, but this doesn't mean that a bomb should be built
0
1
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 30, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to on maro.xyz
@kini@maro.xyz @ikesau@micro.ikesau.co So wouldnt this line of thinking allow one to create an LLM to do terrorism, sell it and not be liable for the terrorism that follows? This is the same argument as "the fossil fuel companies are not responsible for the greenhouse gas that customers burn, they're only responsible for the ghg they produce when extracting the fossil fuel. Who knows what they do with this fossil fuel! ", no? Creator of the LLM = fossil fuel company making bombs or hacking companies = greenhouse gas Operator of the LLM = people who buy gas so they can burn it
0
1
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 30, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @paige@masto.canadiancivil.com
@paige@masto.canadiancivil.com the only time I had fruit flies is when I mismanage my compost. Maybe something about humidity and proximity to water in your case?
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 29, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
2
0
1
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 23, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @ikesau@micro.ikesau.co
@ikesau@micro.ikesau.co The incompetence on OpenAI's part is what's funny. Don't get me wrong this whole shit is scary I have been following HuggingFace hacking closely before this was announced, but the fact that they asked a zero-day-finding machine to hack and then didnt monitor for the machine finding zero days to hack is crazy incompetence
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 22, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
RE: https://infosec.exchange/@briankrebs/116959137948884825 Truely crazy stuff
Quoting
BrianKrebs @briankrebs@infosec.exchange
Banks can now get access to insider trading information, straight from the POTUS's mouth. For a fee, of course. Axios reports Trump Media has already signed several customers ahead of the Aug. 1 launch, including financial news organizations and high-frequency trading firms. https://www.axios.com/2026/07/16/truth-social-license-data-wall-street A letter from Sen. Mark Warner (D-Va) to the financial services industry urges banks to reject Truth Social's new service that would offer advance access to the president's posts on the platform. "In a letter to the presidents of Bank Policy Institute, Securities Industry and Financial Markets Association, Managed Funds Association, Financial Services Forum, Principal Traders Group, and American Bankers Association, Sen. Warner wrote, “I write regarding Trump Media & Technology Group’s (TMTG) announcement that it will begin offering financial institutions and other users the option of paying TMTG for prioritized delivery of posts from President Trump (and other Truth Social accounts as determined by TMTG). This arrangement presents a serious risk to market integrity, creates a clear and unacceptable pathway for corruption, and undermines public confidence in the fair dissemination of market-moving government information – a crucial factor in maintaining stable and trustworthy financial markets.” "Sen. Warner explained that, according to TMTG, the Truth API will provide select paying customers with advance access to posts from top Truth Social accounts, a list that includes the president’s, faster than regular users receive push notifications or can manually monitor Truth Social. Trump Media has said the service is specifically designed for organizations “most impacted by the cost of a delay in information,” including algorithmic trading firms, and customers have already signed up for the service, which it has reportedly offered for $100,000 per month." https://www.warner.senate.gov/wp-content/uploads/2026/07/260721.Warner_Finance_Truth_API_letter.pdf
Open quoted post
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 21, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
RE: https://mastodon.social/@campuscodi/116959921182764597 HAHAHAHHAHAHAHHAHA You cant make this shit up this is so fucking funny
Quoting
Catalin Cimpanu @campuscodi@mastodon.social
OpenAI takes credit for the Hugging Face breach last week The company says that some of its models, including a pre-release one, escaped their testing sandboxes during a test evaluation and then... just hacked Hugging Face's package repo 🤣 https://openai.com/index/hugging-face-model-evaluation-security-incident/
Open quoted post
1
2
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
RE: https://hackers.pub/@fedify/2026/why-activitypub-is-hard Great post, I suggest to anyone interested in the ActivityPub spec and technical architecture to read it. I had no idea the tool echosystem had this many problems, and Fedify handles a lot of them for you! #activitypub
Quoting
Fedify @fedify@hackers.pub
한국어(대한민국) (Korean (South Korea)): ActivityPub 구현이 어려운 이유, 그리고 어렵지 않아도 되는 이유 日本語 (Japanese): ActivityPubの実装が難しい理由、そしてそれが難しくなくなる理由 A quiet failure Picture the moment your server sends its first Follow activity to Mastodon. You read the spec, built the JSON, signed the HTTP request, and POSTed it with care. What comes back is a single line: 401 Unauthorized. No body. No explanation. What went wrong? Maybe the clock behind your Date header drifted a few minutes. Maybe the hash in your Digest header is off. Maybe you uppercased the (request-target) pseudo-header while building the signing string, or published your public key as PEM where the other side wanted multibase. The remote server won't tell you. So you start reading someone else's server code to debug your own. I know, because I've been there. Fedify began as a casualty of another project. I set out to build a single-user microblogging server, the one that would later become Hollo, and started implementing ActivityPub from scratch. Somewhere between the signature specs and the JSON-LD, the protocol work swallowed the product, and I put the whole thing down. What I picked back up wasn't the app. It was the framework the app should have had. Fedify shipped first; only then could Hollo exist, built on top of it. (I've told this story at more length in A year with the fediverse.) ActivityPub development gets hard in a few very specific places. In this post I want to walk through five of them, then show what each one looks like with Fedify. If you've spent time in the fediverse, you'll probably nod along. If you haven't, you may wonder why anyone would do all of this by hand. Either way, the conclusion is the same: nobody has to anymore. Five scenes Scene 1: there is more than one standard ActivityPub servers authenticate each other with HTTP signatures. Except there isn't one signature spec. Most of the fediverse runs on draft-cavage-http-signatures-12, an expired draft that never became a standard. The actual standard exists too: RFC 9421, HTTP Message Signatures. The problem is that you can't know which one a given server accepts until you try. A real-world implementation therefore has to sign with one spec, see whether it gets rejected, re-sign with the other, and remember per server which one worked so it can skip the dance next time. The fediverse calls this double-knocking. Yes, you get to implement it yourself. That's still not the end. HTTP signatures only prove who sent a request. For situations like inbox forwarding, where you relay an activity you received to a third party, you need signatures that live on the document itself: Linked Data Signatures and Object Integrity Proofs. Four signature mechanisms in total, and two kinds of keys to manage: RSA and Ed25519. Scene 2: one document, many shapes ActivityPub's wire format is JSON-LD, and in JSON-LD the same document can take many shapes. This is easier to show than to explain. Here is a Create activity one server might send: { "@context": "https://www.w3.org/ns/activitystreams", "type": "Create", "actor": "https://example.com/users/alice", "to": "https://www.w3.org/ns/activitystreams#Public", "object": { "type": "Note", "id": "https://example.com/notes/123", "content": "Hello, fediverse!" } } And here is a semantically identical activity from another server: { "@context": ["https://www.w3.org/ns/activitystreams"], "type": "Create", "actor": { "type": "Person", "id": "https://example.com/users/alice", "preferredUsername": "alice" }, "to": ["as:Public"], "object": "https://example.com/notes/123" } actor turned from a URI string into an inline object. to turned from a string into an array. object went the other way, from an inline object to a URI. Even the address that means “public” has three valid spellings: https://www.w3.org/ns/activitystreams#Public as:Public, and plain Public. Your parser has to accept every combination, and which one arrives depends on the sender's implementation. The spec-compliant answer is to normalize every document with a JSON-LD processor, expansion followed by compaction. In practice many implementations treat it all as “just JSON” and quietly break on whatever shape some server happens to emit. Either way, you end up with defensive code smeared across the whole codebase: is this a string? An array? An object? A URI I have to fetch? Scene 3: the zombie post A user publishes a post, spots a typo, and deletes it right away. Your server sends a Create, then a Delete. Thanks to network weather, some receiving server gets the Delete first and the Create second. It ignores the deletion of a post that doesn't exist yet, then dutifully processes the creation of a post that was already deleted. That post now lives on that server forever, while its author believes it's gone. Then there's scale. With five thousand followers, one post means thousands of HTTP deliveries. Do that inline in the request handler and your publish button takes half a minute to respond, or the server falls over. Fine, use a queue. Deliveries fail, so retry them. On what schedule? Exponential backoff. How many times? And is a 500 Internal Server Error the same kind of failure as a 410 Gone? When do you clean up three thousand followers on a server that no longer exists? Should you keep hammering a host that has been down for days? At some point it dawns on you that this is no longer protocol implementation. It's distributed systems engineering. Scene 4: it's not a spec, it's an ecosystem Even perfect spec compliance doesn't buy you interoperability. A few examples from the field: Mastodon's secure mode requires HTTP signatures on GET requests too (so-called authorized fetch). Now suppose both servers run in that mode. To fetch the other side's public key you must sign your request; to verify your signature, the other side must first fetch your key. Deadlock. The community's workaround is to sign with an “instance actor” that represents the server itself. You won't find that in the spec. Threads can't parse activities whose actor is embedded as an inline object. When sending to Threads, the actor has to be a URI. Lemmy silently rejects Group actors that lack fields Mastodon never asks for, such as a moderators collection linked via attributedTo and a featured collection. Misskey carries vocabulary extensions of its own; quote posts alone go by three different property names across implementations. The list keeps growing. Interoperability here is not something you finish once and stop thinking about. It's maintenance, forever. Scene 5: insecure by default Build it from scratch, and you start out wide open. Skip signature verification on incoming activities and anyone can inject a forged Follow or Delete. Leave the document loader unrestricted and a malicious activity can point it at http://169.254.169.254/ or your internal network, turning your server into an SSRF proxy. Skip origin checks on embedded objects and any server can hand out a document claiming “here's what the Mastodon lead developer said.” What these traps share is that nothing happens when you fall into them. Everything appears to work. Until someone exploits it. Ghost ran into this too If you're thinking “surely our team would manage,” consider Ghost: a leading open-source publishing platform used by thousands of journalists and creators, and a team that set out to build its own ActivityPub support. We can definitely attest to the problems that Fedify is working hard to solve, because even in just a few weeks of early prototyping we were running into the issues described above right away. From Alright, let's Fedify Ghost ended up building its ActivityPub layer on Fedify. So I put all of it in a framework [Fedify] is a TypeScript library for building federated server apps on [ActivityPub] and the standards around it. It runs on Deno, Node.js, and Bun, and supports edge runtimes like Cloudflare Workers. The design goal hasn't changed since the beginning: keep everything in those five scenes out of application code. Here are the same five scenes again, this time with Fedify. [Fedify]: [ActivityPub]: https://www.w3.org/TR/activitypub/ Scene 1, revisited: the signature war is the framework's job Here is everything it takes to put one actor on the fediverse: import { createFederation, generateCryptoKeyPair, MemoryKvStore } from "@fedify/fedify"; import { Endpoints, Person } from "@fedify/vocab"; const federation = createFederation({ kv: new MemoryKvStore(), // Swap for Redis, PostgreSQL, etc. in production }); federation .setActorDispatcher("/users/{identifier}", async (ctx, identifier) => { if (identifier !== "alice") return null; const keyPairs = await ctx.getActorKeyPairs(identifier); return new Person({ id: ctx.getActorUri(identifier), preferredUsername: identifier, name: "Alice", inbox: ctx.getInboxUri(identifier), endpoints: new Endpoints({ sharedInbox: ctx.getInboxUri() }), publicKey: keyPairs[0].cryptographicKey, assertionMethods: keyPairs.map((keyPair) => keyPair.multikey), }); }) .setKeyPairsDispatcher(async (ctx, identifier) => { // In real code you'd persist these in a database; this shows the gist return [await generateCryptoKeyPair()]; }); The moment this code runs: Every outgoing request gets signed. With an RSA key, Fedify emits HTTP Signatures and Linked Data Signatures; add an Ed25519 key and it attaches Object Integrity Proofs as well. All four mechanisms coexist on a single activity, and each receiver verifies with the strongest one it understands. Fedify does the double-knocking for you: first contact goes out as RFC 9421, a rejection triggers a draft-cavage retry, and the winning spec is cached per server. If the rejection carries an Accept-Signature challenge (RFC 9421 §5), Fedify reads it and re-signs with exactly the components the server asked for. Incoming signatures are verified before your code sees anything. An activity that fails verification never reaches your listeners. One bonus. Because you registered an actor dispatcher, you now have a WebFinger (RFC 7033) server, for free. Type @alice@example.com into Mastodon's search box and your actor comes up. You never wrote a line of WebFinger code. Scene 2, revisited: types instead of JSON-LD Fedify ships about eighty classes covering the whole Activity Vocabulary plus the major vendor extensions. The classes are typed and immutable, and their accessors absorb the shape differences that JSON-LD allows. const actor = await ctx.lookupObject("@hongminhee@hollo.social"); if (actor instanceof Person) { console.log(actor.name); // Safe whether it's a string or langString const followers = await actor.getFollowers(); // Fetches a URI, unwraps an object } lookupObject() takes a handle and runs the whole chain for you, WebFinger discovery included. Accessors like getFollowers() behave the same way whether the value is a URI reference or an inline object, and fetched values are cached. Vendor fragmentation gets stitched up here too. The three competing quote properties (quoteUri, _misskey_quote, quoteUrl) are unified behind one API, next to the emerging FEP-044f quote. Misskey's isCat property exists as a type, so your server can determine cat-ness with full type safety. It sounds like a joke, but a few dozen details of exactly this kind are what interoperability is actually made of. Scene 3, revisited: the zombie post dies in one line Delivery infrastructure first. Plug a message queue into createFederation() and delivery moves to the background, with automatic retries under exponential backoff (up to ten attempts by default). When a post goes to thousands of followers, two-stage fan-out kicks in: a single consolidated message enters the queue, and a background worker splits it into per-server delivery tasks. The publish button responds immediately. Retries create a problem of their own: the same activity can arrive twice. Fedify keeps a 24-hour idempotence cache of processed activities, so duplicates get detected and skipped before they reach your handlers. As for the zombie post, the fix is one option: await ctx.sendActivity( { identifier: "alice" }, "followers", // Collects recipients from your followers collection deleteActivity, { orderingKey: post.id }, // Same key = in-order delivery per server ); Activities that share an orderingKey are delivered to each receiving server in the order they were sent. A Delete can no longer overtake its Create. Activities with different keys still go out in parallel, so throughput survives. Fedify also handles dead servers. On a 404 Not Found or 410 Gone, it stops retrying and calls a handler you register. If the delivery went to a shared inbox, you also get the list of followers behind it, so you can prune vanished accounts on the spot. Hosts that fail repeatedly trip a per-host circuit breaker that holds deliveries and probes periodically until the host recovers. It's on by default; there's nothing to configure. Scene 4, revisited: we track the quirks so you don't Here is how Fedify disarms the traps from scene 4: Authorized fetch: chain .authorize() onto a dispatcher and the verified identity of the requester lands in your callback. Blocklists, private collections, whatever your app needs is plain application logic. The instance-actor deadlock has a supported pattern as well. Threads and inline actors: an activity transformer, enabled by default, rewrites inline actors into URIs on the way out. You don't need to know Threads has this problem. Lemmy's requirements: the custom collection API exposes a moderators collection in a few lines, and Lemmy's JSON-LD context ships preloaded. When a new quirk surfaces in the wild, the fix lands in Fedify, not in every application separately. Each interoperability lesson gets learned once. Scene 5, revisited: becoming unsafe takes effort Fedify's defaults point the other way. Signature verification is something you turn off (for tests), not something you remember to turn on. The document loader refuses private address ranges and loopback out of the box, with DNS rebinding accounted for. To open yourself up to SSRF you have to flip an option whose very name announces it's for testing. When an embedded object's origin differs from its parent document's, the accessor refuses to trust it and re-fetches from the source (based on FEP-fe34). Content spoofing is stopped at the property access level. In a from-scratch implementation, you have to keep remembering to do things safely. In Fedify, the unsafe path is the one that takes deliberate effort. For a federated server, with its tangle of trust boundaries, that's the right way around. Your stack stays your stack “Fine, but what if it doesn't fit our stack?” Fedify was built to fit the stack you already have. There are thirteen web framework integrations: servers like Express, Hono, Fastify, Koa, NestJS, and Elysia, and meta-frameworks like Next.js, Nuxt, SvelteKit, Astro, SolidStart, and Fresh. Middleware handles content negotiation, so the same URL in your existing app serves HTML to browsers and JSON-LD to the fediverse. Fedify doesn't dictate your database either. For its own storage it asks for one key–value interface, with seven adapters available (Redis, PostgreSQL, MySQL/MariaDB, SQLite, Deno KV, Cloudflare Workers KV, in-memory). Message queues come in eight flavors (PostgreSQL, Redis, AMQP/RabbitMQ, and so on), and you can implement the interface yourself if none fits. Your domain data stays in whatever database and ORM you already use. Already running federation on another library? There are migration guides with data migration scripts for moving from activitypub-express and friends without losing your existing followers. The core isn't the ceiling, either. Higher-level packages build on it: @fedify/relay gives you a complete ActivityPub relay server in a single function call, and @fedify/backfill reconstructs incomplete conversation threads by walking the rest of the fediverse for you. Tools for the whole development loop A quieter misery of federated development has always been the missing tooling. Fedify comes with tools for every stage of the loop. fedify init scaffolds a project in one line, and fedify tunnel exposes your local server over HTTPS so you can test against real Mastodon. Activities your server sends can be received by fedify inbox, a disposable inbox server spun up on the spot; whatever other servers publish, you can inspect with fedify lookup. My personal favorite is fedify lookup --authorized-fetch, which generates a one-off key pair and stands up a temporary ActivityPub server just to make a signed request for an object behind secure mode. The CLI is also useful to ActivityPub developers who don't use Fedify at all. While you write code, an ActivityPub-specific linter (@fedify/lint) catches twenty kinds of interoperability bugs, like an actor missing its inbox. Tests run without the network using mocks from @fedify/testing. Once the server is up, attach the debug dashboard (@fedify/debugger) with one line and watch activities and signature verification results in your browser, live. In production there's built-in OpenTelemetry instrumentation (28 span types, 37 metrics) plus a monitoring guide, and when performance matters, fedify bench, a load-testing tool built for ActivityPub, catches regressions in CI. As far as I know, no other ActivityPub framework ships even one of the tools in this section. The documentation is part of the tooling. The official docs run to a thirty-chapter manual and five tutorials, and they go well past API listings. There's an operations chapter with ready-made PromQL queries and alerting rules for watching your queue backlog, and a field-guide chapter that documents de facto conventions, like which property makes your avatar show up in Mastodon, with screenshots. At two in the morning, when federation is broken and you don't know why, this is the difference between a bad night and a short one. It's already running Fedify is not a thought experiment. Ghost's ActivityPub service, mentioned above, is built on it. So are Encyclia, which bridges ORCID researcher records into the fediverse; SiliconBeest, running serverless on Cloudflare Workers; Typo Blue, a Korean blogging platform; Hollo, my own single-user microblogging platform; and Hackers' Pub, run by its community. Hollo, by the way, is the app from the beginning of this post: the project I once had to shelve, finished at last on the framework it forced into existence. The tutorials give a concrete sense of scale. They walk you from a single-file server, a few dozen lines, that Mastodon can follow, through an image sharing service in roughly 750 lines that fully interoperates with Pixelfed (follows, likes, comments), up to a community platform federating both ways with the real lemmy.ml. The fediverse needs more apps I didn't build Fedify to mint more ActivityPub experts. Rather the opposite. I believe the fediverse will only grow beyond microblogging when developers can build federated apps without knowing ActivityPub's fine print. Signature spec transitions and JSON-LD compaction are problems that belong inside a framework, not barriers in front of someone with a new idea. Starting takes one line: npm init @fedify Follow the first tutorial and by the end, Mastodon can find your server. If you get stuck, come find us in the Matrix room or GitHub Discussions. See you in the fediverse.
Open quoted post
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jul 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @fedify@hackers.pub
@fedify@hackers.pub Awesome work for the fediverse! The fact that so many servers behave in non-compatible ways seems to suggest the spec has problems, right? Some examples are frustrating to read, I can't imagine building around them without such framework.
1
1
1
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jun 27, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @g@irrelephant.co
@g@irrelephant.co were you going south shore, north shore or west island?
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jun 26, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
RE: https://mstdn.ca/@CanadianPolling/116817609222744453 Truely ridiculous. We need more electricity for us. The economic benefits of using money to build renewables here instead of pipelines to export is better. And of course, it doesn't warm the planet 💀
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · May 20, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @CraigSauve@mastodon.social
@CraigSauve@mastodon.social Pas de station Bixi au REM, quelle étrange situation
1
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Apr 07, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

Not gonna lie this shit is so spooky. At the same time this technology is so insanely interesting. There are so many good reasons to criticize AI but we can't deny that the AI companies actually deliver capabilities improvements and have been since the release of chatgpt in 2022.
This can be used to do so much bad stuff and probably so much good stuff too. Again, spooky.

https://red.anthropic.com/2026/mythos-preview
#ai

2
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Apr 02, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @bagder@mastodon.social

Interesting development

mastodon.social

daniel:// stenberg://: "The challenge with AI in open source security has…" - Mastodon

1
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 24, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

The worst thing about the linux ecosystem is nothing is signed
if software was signed we could easily have a secure enclave. We could finally start building an ecosystem where malware running in a computer would have a much harder time stealing npm/github/pypi tokens, ssh keys, cleartext passwords in config files like we've seen a lot lately. It doesn't fix everything, but it'd help a lot. https://www.bleepingcomputer.com/news/security/popular-litellm-pypi-package-compromised-in-teampcp-supply-chain-attack/

0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 21, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @NorthSec@infosec.exchange

I'll be giving a detection as code talk at NonthSec 2026. See you there!

infosec.exchange

NorthSec: "NorthSec 2026 speaker lineup is here ...and it's …" - Infosec Exchange

3
0
1
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 16, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

@ElbowsUpforDigitalSovereignty@thecanadian.social Interesting boost considering your website is very visibly vibecoded? 🤔

0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 14, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @SwiftOnSecurity@infosec.exchange

My words are an extension of my self-expression and 👏no👏machine👏shall👏take👏that👏from👏me.
I use AI for many things, but never to write my words.
It should become part of our culture to find it very cringe to use a machine to write words and then pretend they are yours. This is unauthentic, I like authentic

4
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 12, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @cbcnews@flipboard.com

"The soldiers were accused of dragging the Palestinian on the floor, tasering him and sexually assaulting him by stabbing him in the rectum, causing multiple injuries, according to the indictment. At the time, the victim was cuffed at the hands and ankles and blindfolded.

He was taken to an Israeli hospital with fractured ribs and blunt trauma to the abdomen and the chest and underwent surgery for a perforated rectum before being returned to the prison."

0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @arstechnica@mastodon.social

Interesting to see this data point that supports the idea that the increase in outages might be caused by some LLM usages

mastodon.social

Ars Technica: "After outages, Amazon to make senior engineers si…" - Mastodon

1
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @ikuturso@mastodon.social
@ikuturso@mastodon.social huh, weird. Maybe it's a Phanpy thing?
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @ikuturso@mastodon.social
@ikuturso@mastodon.social I heard about it being merged a while ago but this does not work reliably for me so I don't consider this as something solved yet
0
2
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

My thoughts on Jay stepping out as CEO of the #bluesky company and a VC-backed CEO taking her place during the interim are that those two realities currently coexist:

  1. The #atmosphere is not power-decentralized enough (as in the Bluesky company still has too much power)
  2. Bluesky has an excellent track record on helping build the non-bsky atmosphere and delivering on their promises to ship stuff that diverts power away from the company and into other individuals and organizations

If 2. continues, 1. will eventually not be true anymore and the atmosphere would survive a "VC money ran out so Bsky is now milking their users dry"-type enshittification

Of course the #fediverse has none of those power dynamics problem but we don't see most replies to a toot or have an account migration flow that doesn't suck so choose your poison I guess 💀

4
4
1
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @zornslemmon@mathstodon.xyz
@zornslemmon @huitema @dangoodin I understand and I use adblockers for this reason as well. My point is that we are the minority and the vast majority of users don't care about that, so this messaging probably make some people disable their adblocker to get access to the content. Even I sometimes do that even if I'm aware of the consequences
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 10, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

RE: @thisismissem@hachyderm.io

Let's gooooo

hachyderm.io

Emelia 👸🏻: "I'm super hyped to announce that Bluesky Socal PB…" - Hachyderm.io

0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 09, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @huitema@social.secret-wg.org
@huitema @dangoodin I'm pretty sure the vast majority use adblockers to block ads and that privacy and safety is not a concern. I feel this reason is very niche in the adblock userbase
1
3
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Mar 06, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @MisterMadge@universeodon.com
@MisterMadge@universeodon.com @davidho@mastodon.world Yes, the headline is misinformation, it's 3h of annual revenue, it's written in the article
0
0
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Feb 23, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

Something that icks me regarding the online #ageverification discourse that we see today is that everyone seems to assume that giving privacy-intrusive or PII datais the only way to have age verification online. However, we already know how to make age verification where:

  1. The government doesn't know on which sites you register or give access to third parties to PII
  2. The website to which you register doesn't need to interact with the government or any third party
  3. The website doesn't know your age, just that you're over 18
  4. No third party is required

The two things you need is a digital ID system and zero-knowledge proofs. That's it

6
3
3
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 23, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange

Submitted a talk about detection-as-code to the @NorthSec@infosec.exchange Call for Papers! You have until feb 2nd if you’re interested in submitting :)

#CFP #conference #infosec

2
0
1
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 05, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @mikalai@privacysafe.social
RE: https://infosec.exchange/@res260/115839291794131460 @mikalai@privacysafe.social @turbobob@mamot.fr @adbenitez@mastodon.social @collectifission@greennuclear.online UI is only one of the components of UX. Also see this other reply for my opinion on what "independent" should mean
0
1
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @res260@infosec.exchange
@adbenitez@mastodon.social @collectifission@greennuclear.online What I'm trying to say is that "independence" is not something that is achieved, it's at the extreme of a spectrum that you can never quite reach, but aim to get close to
1
1
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @adbenitez@mastodon.social
@adbenitez@mastodon.social @collectifission@greennuclear.online I find that thinking about independence as a binary (as a lot of people seem to be doing) is flawed. Nothing is ever truely independent, we all rely on things built and controlled by others and this will always be the case, so this is why I think it's misplaced. You don't need your own servers to be independent because true independence is not achievable. Words like need imply that there is a recipe to follow to achieve "independence" (boolean). I don't think this is a fair way to frame it. Using Signal means that your chat platform is more independent than if you were using facebook Messenger. In the same way, using Matrix or some other decentralized protocol makes it more independant than using Signal
1
4
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @turbobob@mamot.fr
@turbobob@mamot.fr @adbenitez@mastodon.social @collectifission@greennuclear.online As a tech-savvy person, I mostly agree, but as long as decentralized platforms do not truely consider UX as a thing that should almost never be compromized on, I'll continue recommending Signal over decentralized alternatives to people :/ In my opinion, UX is the one reason bluesky is winning over mastodon, not money or lack of user education
1
1
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Jan 04, 2026
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @adbenitez@mastodon.social
@adbenitez@mastodon.social @collectifission@greennuclear.online Independance is not solely about decentralization, it's about many other things, of which Signal represents some of them
1
2
0
0
Open post
res260
Émilio Gonzalez @res260@infosec.exchange · Apr 27, 2025
Émilio Gonzalez
@res260@infosec.exchange

Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with Construisons Montréal and Locomotion.app.

infosec.exchange
Replying to @info@masto.canadiancivil.com
@info Link is not clickable!
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:56:33 UTC