this post was submitted on 11 Jun 2025
661 points (96.2% liked)

Fediverse memes

1486 readers
234 users here now

Memes about the Fediverse.

Rules

General
Specific

Elsewhere in the Fediverse

Other relevant communities:

founded 8 months ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] jerkface 1 points 2 days ago (4 children)

If by HTTP signature you mean an SSL certificate signed by an authority, those do not present a burden for bots to obtain any longer.

[–] [email protected] 3 points 2 days ago (3 children)

I do not, ActivityPub uses HTTP signatures to make sure messages and requests from other servers are legit,

Essentially, it adds a "signature" header which contains a link to a users public key, a list of headers in the message and a signed hash of all the headers and the request.

There's a better explaination here: https://docs.joinmastodon.org/spec/security/

A delicated bot to scrape ActivityPub posts is possible, but generic bots shouldn't work. If a delicated bot is made, people can block its keys or server anyway.

[–] [email protected] 3 points 2 days ago (1 children)

Signatures are only used to deliver activities to inboxes. The Activitypub json data of posts is usually available without any auth.

[–] [email protected] 1 points 1 day ago

A lot of servers require signatures on GET requests as well, for private posts and to block specific people/servers.

load more comments (1 replies)
load more comments (1 replies)