Okay, Mastodon friends, I rarely ask for amplification about my day job, but I personally pushed for my employer to make a big investment in enabling the fediverse, and I'd love for everyone to show that the support is appreciated. On June 28, you can join us for a (FREE!) hands-on conversation about how the Fastly team worked to support @Mastodon while the service was under a *massive* DDOS attack. Everyone who cares about scaling the fediverse should join: https://learn.fastly.com/security-mitigating-ddos-and-traffic-surges-with-mastodon @devs
Mitigating DDOS in the Fediverse with Mastodon | Fastly

Experts from Mastodon and Fastly’s CSOC team share lessons learned from mitigating DDOS attacks on Mastodon Social and techniques for protecting federated architectures.

@anildash I started to sign up, but the form gives me “corporate sales” vibes, and I try to avoid those. 🤷‍♂️ I hope it’s a good webinar.
@tylermumford yeah, fair. The actual event is not that, but have definitely shared with the team that the signup form isn't really the energy that this community goes for.
@anildash @tylermumford i feel like a simple peertube video url to repost/like/bookmark would be a way simpler and directer way to connect with a community
@dym @tylermumford maybe in the future! The marketing team at most publicly-traded companies are not generally going to prioritize that over systems they’re familiar with, though I hope platforms like peertube become part of that toolkit over time.
@anildash a boost in return seems like the least we can do

@anildash I definitely want to hear about this. I'm deeply concerned with centralizing in order to scale.

My question going into this is, how can Fastly or anyone protect from DDOS without centralizing, and thus weakening the federated nature of the network?

@anildash @Mastodon @devs

Fastly is a publicy-traded company with revenues in the hundreds of millions. Are "Publicly-traded cloud computing company" and "decentralized, privacy-focused social media service" compatible concepts?

@yowtfbecool @anildash @Mastodon @devs Why not? The best decentralized example is email. Everyone uses it, no matter how big.

@markusr @anildash @Mastodon @devs gmail is no more decentralized than facebook.

privacy concerns have as much to do w/ who has access to data as they do w/ how it's stored and how much, how it's protected and what the paper trail looks like. for comparison, take VPNs. what are the criteria for a good one?

public companies care about the end-user until it makes financial sense not to, which is usually right before they sell. a cloud company's main asset is data. fool me once...

@yowtfbecool @markusr @anildash @Mastodon @devs Not Gmail. Email. You're part of the problem. Email is not Gmail. You can sign up to any email service and still interact with another. There's other services like mailbox.org, fastmail, etc

@natemtn @markusr @anildash @Mastodon @devs gmail is google, facebook is meta, fastly is fastly. u missed the point. probably my fault. character limits.

e-mail can contact e-mail, so why choose proton over yahoo? the service providers are not decentralized. i guess one could use Tor, but a multilayered approach would be prudent, if not preferable. Tor into a decentralized, privacy-focused social media service that doesn't deal with publicly-traded data companies. 👍❤️

@yowtfbecool @anildash @Mastodon @devs I don't see why it would be incompatible without a lot of effort.

A cloud infra company thrives with many successful subscribers and chokes when they're big enough to run their own infrastructure (i.e. Facebook doesn’t need Fastly). Privacy invasion comes from an ad-based revenue model when end-users need to be converted to revenue; cloud infra is B2B subscription model with neither incentive nor easy access to end-users.

@opendna @anildash @Mastodon @devs

you're right that they aren't necessarily incompatible. a major undertaking, but it will happen if there is a good opportunity there.

wrt ad-rev model: the data handled by cloud services will be of relative low quality. however, it won't be of zero value, meaning revenue potential exists. now, consider that a public company has a duty to generate returns f/ investors. what value ($$) represents an opportunity? see: the credit collections industry.

@yowtfbecool @anildash @Mastodon @devs You're right and I don't dispute your logic. Fastly trades on a certain ethic which precludes the behavior I think you're describing. It would be an exceptional bag which made betraying both customers and employees attractive to shareholders.

Unlikely but, as we saw with Twitter, not impossible.

@opendna @anildash @Mastodon @devs

in the end, something is better than nothing. if we trust in our paranoia and remain vigilant, we can, at the very least, afford ourselves the delusion of privacy.

@anildash @Mastodon @devs Good call. DDoS protection like this is exactly the kind of thing we'll need as it scales up. It'll be impossible to knock out the entire Fediverse, but individual servers are much more vulnerable. I don't need it for my own little server, but if I ever have to scale, I'm glad to have you guys on side.

@anildash @Mastodon @devs Done.

Also, thank you. Thank you for the "Opt In:" GDPR set to unselect by default. Small design choices have big impacts on those that appreciate the technique and talent to make such choices.

My inbox appreciates you.

@anildash @[email protected] @devs hey not only does this sound really cool but it's actually a time that I can attend! Holy shit!
@anildash Will this be recorded and posted anywhere? I will be busy at that time, sadly :(
@anildash @Mastodon @devs wow, I’m actually interested in this subject. Just can’t be bothered to sign up; I just want to watch a video or read about it online.

@anildash @Mastodon @devs very cool! I’m hoping some of the Fastly team can help the new Lemmy instances coming to life during this Reddit exodus and getting slammed by new users (both malicious and legit) as well.

One of the beautiful aspects of it is that even though I’ve been unable to sign up at the most popular instances like @support and @lemmy, I was able to sign up at https://infosec.pub and continue posting/accessing them via federation.

Infosec.Pub

@simonkaluza @anildash @Mastodon @devs @support @lemmy we’re happy to help! Just reach out fastly.com/forward

@anildash @Mastodon @devs So... decentralized social media by centralizing on Fastly?

This makes as much sense as everyone shoving their instances on AWS and Digital Ocean.

@anildash @Mastodon @devs I'll be teaching on my own webinar at that time, but signed up for the replay.
@anildash @Mastodon @devs would love to talk to you sometime about what it takes just to make the internet ~work~
@mimsical @Mastodon @devs yeah! I think about that a lot, we have this extraordinary and unlikely pile of absurdities that make the whole thing happen. Drop me a line to [email protected], would love to chat.
@anildash @Mastodon ummmmm you know, the whole point about the fediverse is fedi-eration, not scaling a huge monopolist instance!
@mirabilos @Mastodon I do know! which is why we need to provide tools for all those instances to scale, and information on how to do it.
@anildash @Mastodon erm no, we need instances to not scale, so people run their own instances. Moderators don’t scale either, after all.

@ienvision @anildash @Mastodon @devs

Woot! Sharon, thanks! Registration completed. Can't wait! fwiw @MrAdamJohn is where I follow security and other more technical topics, and I'm always open to connection and conversation there as well. Thank you all!

@anildash @Mastodon @devs will this be recorded? I am VERY interested, but will be at a work event that day.
@anildash @Mastodon @devs Okay. I'm going to sign up for it. But: if the email address that I'm going to use for that receives ANYTHING, EVER not related to this particular event, then I'm going to be very unhappy and will do my best to see that Fastly ends up on every blacklist.

@anildash @Mastodon @devs

Will this be recorded / on again another time? Looks interesting but can't make it unfortunately :'(

@rubenwardy @anildash @Mastodon It will be recorded and shared afterward. :)
@anildash it's in my calendar to be there!
@anildash @Mastodon @devs 1 pm on a weekday, I will be at my real job. But thanks for letting us know, if I could attend I would. Not that I would understand much of it. Anyway thank you for your effort

@anildash @Mastodon @devs Sounds like a cool idea, but as a hint: The form requires a field "company" and while it's obviously not really checking anything, since the fediverse is often run by volunteers, it's probably not helpful to have it there.

You know, target audience and stuff ;)

@anildash @Mastodon @devs

I may be flying at that time, but if I'm sitting in the airport, I'll try and join.

@anildash @Mastodon @devs didn’t know you were with Fastly…. my company is a happy Signal Sciences user.

@anildash @Mastodon @devs FYI you can still buy the Bernie coat. I have it, and it is a great joy when some punk kid shouts “I am once again asking!" at me.

https://www.burton.com/us/en/p/mens-burton-gore%E2%80%91tex-edgecomb-down-jacket/W19-205271.html

Men's Burton GORE-TEX Edgecomb Down 3-in-1 Jacket | Burton.com Winter 2019

Shop the Men's Burton GORE-TEX Edgecomb Down 3-in-1 Jacket along with more winter jackets and outerwear from Winter 2019

Burton Snowboards
@sayrer @anildash @Mastodon @devs sadly it’s sold out now 😪
@Fluzbug @anildash @Mastodon @devs they remake everything that hits, it’ll be in September (also buy your Burton socks at this time)
@Fluzbug @anildash @Mastodon @devs I really have it, and I know Burton manufacturing patterns.