Show newer
xianc78 boosted

Pleroma / Akkoma / Rebased need to be patched, but here’s how you can secure your site without any code changes:

yoursite.com/media -> media.yoursite.com
yoursite.com/proxy -> proxy.yoursite.com

To do this, add the following configuration to your site:

config :pleroma, Pleroma.Upload, base_url: "https://media.yoursite.com" config :pleroma, :media_proxy, base_url: "https://proxy.yoursite.com"

You will need to add DNS records for the subdomains. For media, it’s recommended to use an S3 bucket (or equivalent). For the proxy, you can simply point the DNS to the same server, and edit your Nginx file. A sample Nginx file is here: https://termbin.com/tj7q You’re on your own setting up letsencrypt, etc.

Here’s what does NOT work:

A CSP one-liner in Nginx. That’s not how CSP works. CSP affects the page it was loaded on, not other resources. This is straight up misinformation.
Disabling the media proxy on its own. The media proxy does appear to be vulnerable, but it cannot be the only action you take.

EDIT: Also, after you do this make sure to specifically block /proxy from your main site by adding location /proxy { return 404; }

@Tadano @PhenomX6 People don't realize that there are otherwise of doing single-threaded server software.

@dushman @meso @vriska I'M NOT A PEDO!!! I've been on this instance long before the influx of pedophiles on here. I've joined this instance in particular because I'm also a gamedev and like to post my progress.

@meso @dushman @vriska Last time we argued, you thought that libertarians were in favor of central banking. You have no place to judge.

@PhenomX6 @dushman @vriska @nyx This is why terms like "Hispanic", "Latino", "Latina", and "Latinx" all need to die.

@PhenomX6 @dushman @vriska @nyx Because the Spanish didn't bring women with them on the ship. It's why most Mexicans are a mix of Mesoamerican and Spanish.

@dushman @vriska @nyx I do opposed that. Not every single colonial town was founded on stolen land. Native American tribes were spread out. The ones that weren't found on stolen land didn't violate the NAP.

@dushman @vriska @nyx Innovations like 3D printing might allow us to return to decentralized cottage industries.

@dushman @vriska @nyx Officially they were still under government control, but given the distance between them and the government, it might as well be anarcho-capitalist.

@rohrkrepierer@merovingian.club @vriska Fear of labor pain, probably.

@PhenomX6 @matrix I've been using this for 3 years and I never seen the word "scope" in my life. Mastodon has also silently changed the word "toot" to "post" (thank God).

@dushman @vriska @nyx As I have already demonstrated, history proves otherwise.

@PhenomX6 Have you looked into any of the Mastodon forks. GameLiberty runs on a Masto fork maintained by @matrix. I think Qoto's fork has things like BBCode. Librem.social runs on a fork, but I think they removed DMs, which given the current situation, isn't that much of a loss.

@dushman @vriska And you think anarcho-communism (or any other form of left-anarchism) would be any different?

xianc78 boosted
Knowing the Pleroma exploit out now, what software stack should I use for a new fedi instance when I launch the multi user instance?
100% serious btw

@dushman @vriska Not anymore. I joined this instance because I'm also a gamedev.

@dushman @vriska Capitalism as in the voluntary exchange of goods and services. These societies were stateless with some even having privatized courts and security (in the case of Ireland and Iceland). Bronze Age India had large cities with infrastructure funded by merchants. The towns in the American Old West were built on private infrastructure, including the security.

Show older
Game Liberty Mastodon

Mainly gaming/nerd instance for people who value free speech. Everyone is welcome.