Brutkey

Jess👾👾
@JessTheUnstill@infosec.exchange
Jess👾👾
@JessTheUnstill@infosec.exchange

At the VERY least, do a periodic tabletop operation of "We no longer can use this core piece of cloud software/platform/infrastructure, what would be ways we could recover?"
Partial recovery in 14 days, full recovery in 30 days?
Welp, guess we just close down the company?
We keep around a small experimental environment on some other provider/a few VPS/some colo servers/some servers running in the closet that we could use as a foundation to scale up when required?"

Jess👾👾
@JessTheUnstill@infosec.exchange

With the continued blatant enshittification of GitHub, your periodic reminder:

Cloud services and SaaS in particular is simply "someone else's computer". They can and will "I have altered the the deal and pray I won't alter it further" whenever it suits them. So it's always going to be best to leave your stuff as lightly coupled to someone else's computers as possible.

Jess👾👾
@JessTheUnstill@infosec.exchange

"Business Continuity Planning" isn't just about "US-EAST-1 went offline, how do we manage fail over and uptime". It also includes things like "this whole platform has been discontinued/gone bankrupt/KilledByGoogle/quintupled in price/been MegaBreached, how does my business/project survive?"

Jess👾👾
@JessTheUnstill@infosec.exchange

With the continued blatant enshittification of GitHub, your periodic reminder:

Cloud services and SaaS in particular is simply "someone else's computer". They can and will "I have altered the the deal and pray I won't alter it further" whenever it suits them. So it's always going to be best to leave your stuff as lightly coupled to someone else's computers as possible.

Jess👾👾
@JessTheUnstill@infosec.exchange

@jasmine@chaosfem.tw Or just leave it as "I don't really care what you tell people I'm unlikely to know. If you want to be homophobic/biphobia and misgender me because you don't have the guts to say my ex-wife, that's on you. Deal with it. I'm not going to give you permission to deadname or misgender me, but you're an adult, do what you will."

Jess👾👾
@JessTheUnstill@infosec.exchange

Of course crime is up in DC. The gang's headquarters is 1600 Pennsylvania Ave

Jess👾👾
@JessTheUnstill@infosec.exchange

"Maybe if I assimilate hard enough the hets will like me" ...

Jess👾👾
@JessTheUnstill@infosec.exchange

Lukewarm take:

Pete Buttigieg is the straightest gay man the world has ever seen.

Jess👾👾
@JessTheUnstill@infosec.exchange

Okay fine. Here's your user story.

As a Fediverse user, I would like to limit replies to a post or retroactively remove replies to a post for use cases like the following:


An Open Source project with a large number of followers makes an announcement about a new release of their software. The replies start being filled with abuse and slander against people involved in their projects. Similar, the post gets replies of people wanting to spam their own stuff also unrelated to the original thread.


A person with a stalker has their stalker invading their mentions with a revolving list of sock puppets to continue their stalking, abuse, slander, and harassment leaving the victims no way to keep this person from continuing their abuse.


Similar, but a group of people whip up a dogpile lynch mob against a person and any time they make a post, the mentions are flooded with abuse.

"Solutions" like "Well just mute your replies" means that the original poster can no longer participate in the replies of their thread with people they want to engage with.

"Well you can't stop people from talking about you!" I understand. At best you could appeal to their moderators but that is its own thing. However, you should be able to limit them from polluting your mentions with their abuse, harassment, or spam. There's a categorical difference between someone making posts about "jesstheunstill is an awful person in these reprehensible ways" on their own account, and the same person replying to every post I make using an endless number of sock puppets posting the same message, both continuing the abuse, as well as making everyone who visits the mentions of my post be aware of said abuse.

There are undoubtedly more use cases than that, but they're all tied together by a common thread:

The problem is not only limited to the original poster having to see the unwanted content in their replies, but also: they have no way to limit them from putting their abuse in front of the eyes of everyone else who wants to read their mentions, and trying to use replies as a weapon.

@cy@fedicy.us.to @dragonfrog@mastodon.sdf.org

Jess👾👾
@JessTheUnstill@infosec.exchange

I mean, yes there's decentralized ways to get partway there around replies control. But it'd all be down to post-hoc server specific implementations and clients playing nice with each other. And I have little to no hope of that ever becoming a widespread functionality across the Fediverse. Especially when we still haven't seen other moderation and abuse tools properly implemented in many of these platforms despite people asking for them for years and years now. So in the meantime, I just bitch at the clouds.

@cy@fedicy.us.to @dragonfrog@mastodon.sdf.org

Jess👾👾
@JessTheUnstill@infosec.exchange

Some days, you're in a 1080p zoom meeting mood
Other days, 320x240 seems to be the best you got

Jess👾👾
@JessTheUnstill@infosec.exchange

https://infosec.exchange/@JessTheUnstill/115011747742796121