RPW 🥑

@esizkur
294 Followers
51 Following
59 Posts
Why would you want to look verified when you could have an awesome avocado instead?
Stealing passwords from infosec Mastodon - without bypassing CSP https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
Stealing passwords from infosec Mastodon - without bypassing CSP

The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose

PortSwigger Research
@tinker Just got onto pixelfed myself and I am loving it so far. Such talented artists, photographers, and other creators. Who needs Instgram? Oh right, corporations . . .
Langsam, fast unmerklich, fahre ich die Exklusivnutzung von Mastodon weiter hoch. LOL!

Some Mastodon thoughts, for bird-site expats (which include myself). I'm aggregating these from posts I've boosted before, so little of this is my own brain.

- There's no algorithm here. That means favoriting/liking doesn't do anything except communicate approval to the OP and others (which is still nice!).

- No algorithm means boosting ("retweeting") is the true method to increase a post's visibility. Do that more than you did on birdsite.

- There's no post-quoting here, and that's by design. Look at quote-tweets on the birdsite; it's a feature primarily used for toxicity.

- There's no direct word-search here either; that means you want to use hashtags to make posts more searchable. This is also intended, since word-searching posts was often used to harass/stalk on the birdsite and elsewhere, so that was left by the wayside here. This also means hashtags are much more a thing here than any of the algorithm-powered sites.

- It's encouraged to put in text descriptions when you post images; a lot of Mastodon users use screen-readers due to various disabilities, and getting an image description read out loud helps them immensely.

- Speaking of screen-readers: using capitalization in your hashtags allows the screen-readers to read them more easily, especially if you're smashing multiple words together. #rockmusic = unreadable. #RockMusic = readable.

- The best way to make threads is to make set your first post as public, but "unlist" all of your replies. This prevents your whole thread from clogging up feeds.

- Content Warnings should be used more liberally here. If you haven't gotten the impression yet, much of Mastodon was built and populated by marginalized groups who were harassed/bullied off of other platforms. This is the culture they built, to respect each other's mental health. It's not a rule, but it's well-appreciated.

- Consider chipping a few bucks towards whomever runs the server you're on; the strain is real, and most server admins were likely paying out of pocket before so don't have an existing donation base. The growth here has been extremely fast, and that means money's needed.

- DMs are just posts with privacy settings. So if you @ someone in a DM, you pull them into the thread. That could be embarrassing.

- Also, no, DMs aren't end-to-end encrypted, but they aren't on Twitter either. Don't use either if you want true privacy.

- Including your Mastodon handle in your birdsite profile will help people find you here; there's a tool (pruvisto.org/debirdify/ is one of them that's used) people can use to pull Mastodon handles from Twitter profile.

- Use the blocking and reporting features liberally, if needed. This should go without saying, but they work, and work well!

- If there's an entire Mastodon server you don't want to hear from, you can block the whole thing too.

- Preferences -> Appearance -> "Slow Mode": this can make larger "Local" feeds and any "Federated" feed much more readable.

I'll reply with some more as I see them, or reply here too. I've only been here 4 days but I'm loving it so far.

There are enough people on Mastodon now that we may need to start posting actual content soon.
Woah - German government has got its own Mastodon instance and most of the ministries and many agencies already have accounts.
Verification problem at least partially solved - just need to check the domain is right!
I've also seen newspapers like theatlantic.com set up instances themselves. Looks like verification will be worked out sooner or later.
https://social.bund.de/explore
Explore social.bund.de

Discover users based on their interests

Mastodon hosted on social.bund.de
Make the net weird again. Hand write sites like it’s the 90s. Pick interesting domain names and make fan sites or random knowledge known to everyone. Don’t monetize anything. Spearhead new protocols like Gemini. Make mods for games on your site. Make FAQs for obscure games no one knows about. Make public software services available to anyone. Make a news site about a really random subject. Create music in all kinds of different formats. Most of all, do it because you want to!
Machine-learning models, the ultimate closed-source binary blob.
Hammersbald, der nordische Gott der Ungeduld.
Denn das Glück dieser Erde liegt auf den Rechnern der Nerde.