Heeey, look, it's me!
I'm super hyped to announce that @bsky.app have given me a grant to work on the standards for the Federated Credential Management API (or FedCM) to make them really work for all decentralized web applications.
Hey people who are EU citizens, please sign this petition to ban conversion therapy EU wide.
It's a practice that's very harmful towards LGBTQ+ people.
It's already banned in some countries but we need a EU wide ban!
eci.ec.europa.eu/043/public/#...
#europe #lgbtq #germany
Whelp, this is a pretty major vulnerability. If you use ffmpeg make sure you update
www.securityweek.com/ffmpeg-pixel...
Recently there has been a lot of dividing & heated discourse about ActivityPub and AT Protocol.
Yesterday at the Social Web CG meeting, I proposed releasing a statement on this discourse, you can read the full statement here:
github.com/swicg/genera...
#activitypub #atprotocol #atproto #SocialWeb
So I've been trying to understand the legal structure that W Social has to better understand the separation between W Identity and W Social, and it's quickly looking like it's all for show.
I wrote up a piece on how standards are made, because of some folks being very negative about the grant on other social networks: writings.thisismissem.social/how-standard...
So a not too well known thing about me: I'm the co-author of the Client ID Metadata Documents internet draft that Bluesky / AT Proto uses for OAuth.
This document came about due to my work on Mastodon's OAuth implementation.
If you'd like to support my work: support.thisismissem.social
Seeing the @ec.europa.eu bend over backwards to support a for-profit closed source ID-gated social network is really quite something.
Obviously they've either learned nothing from dealing with Meta & X/Twitter over the past decade, or they want to replicate them but have control over it.
Counterpoint: this is the intended effect: to disenfranchise sex workers and remove their economic power because they also tend to be community organisers and activists, and want to see better for their communities.
So here's a short write up explaining what happened today and what I'm going through, at a high level. It does include some history too, but I tried to keep it brief.
It's pretty funny how everyone has seemingly forgotten why W Social went closed source: initially they were open source, and various people from the community looked through their fork of the bluesky codebases, and went "lol wat no".
So something interesting that happened this week: Mastodon announced that they'd received €614,000 from Sovereign Tech Agency (german), and with part of that funding they're going to be implementing support for the FediMod FIRES protocol which I spent last year building whilst barely surviving.
This is the super secret project I've been working on; Looks different with the full set of apps:
Okay so – with a big caveat that we still need to write a lot more documentation – between the @roost.tools team, @dcallies.bsky.social and myself we've managed to ship a new documentation site for ThreatExchange / HMA: facebook.github.io/ThreatExchan...
Said something interesting to a friend today when they asked about different open social web protocols. It might be a little bit controversial, but:
I think that ActivityPub is decentralized in principle, whereas AT Protocol is decentralized in practice. 🧵
If I noticed a tool of mine was acting like this, I'd replace that tool.
github.com/jqwik-team/j...
The exact same thing happened to a german tourist, who's hopefully being released soon: www.theguardian.com/us-news/2025...
Hopefully becky can be home again soon too
@ec.europa.eu any thoughts on W Identity's recent security vulnerability, poor response, and lack of appropriate means for security researchers to disclose vulnerabilities?
This was GDPR failure & insufficiently handled.
bsky.app/profile/wsoc...
Bluesky gained that for me without any mind games and without forcing itself on me at every chance through all the other apps that company has.
I'm incredibly proud to announce the Fediverse Security Fund from Nivenly Foundation (@nivenly.bsky.social). It's a time-and-funds limited experiment, where they will pay for the responsible disclosure of high & critical security issues in open-source Fediverse software:
nivenly.org/blog/2025/04...
Gee, this using AI thing really isn't working out well for Deloitte:
Fun story for everyone with the AT Protocol trademark: the Mastodon trademark for many many years was owned just by Eugen personally, not by the Mastodon gGmbH, which is part of the reason they had to recently pay Eugen €1 million euros.
So what @sebastian.eurosky.social couldn't show you all in the demo was the redesign I've just done on the @eurosky.social portal with all the apps listed:
Hey friends, did you know you can hire me either as a consultant or developer and I can help you build for AT Protocol? No? Well now you do!
I generally program in typescript, but I can usually advise & review implementations in a multitude of other languages, especially when it comes to OAuth.
In Australia, if we can't pass a budget, the government must resign or call a double dissolution (dissolving both house & senate) for a complete reelection