#dev 2017-12-18

2017-12-18 UTC
#
KartikPrabhu
what are all these pages^?
#
Zegnat
I think they are the default pages linked in the indieweb footer
#
Zegnat
Less sure who Arlo is though
#
KartikPrabhu
those seems to be new pages there does not appear to be any edit history
#
gRegorLove
Yeah, MediaWiki default links in footers
#
gRegorLove
Mentioned here but forgotten about :) /2016/newskin#Issues
#
gRegorLove
Privacy policy would be good. Not sure we need a General disclaimer
#
gRegorLove
CoC would be good there
#
gRegorLove
and/or in the sidebar
eli_oat, krup and Loqi joined the channel
#
krup
i think all of freenode is being affected
#
dansup
The spammer is spamming a legit show, happened on efnet earlier
#
ben_thatmustbeme
and it kicked the wrong person
#
dansup
someone called into that live youtube stream and asked why there channel was being spammed, its some disgruntled fan
#
wagle
yeah, this wave was about 4 of my toomanychannes
#
kline
dansup, who was it, specifically?
#
kline
i usually tune in but im busy just now
#
dansup
someone in the channel #krustykrabs on efnet, who is into some illegal stuff on TOR. I watched that youtube stream for a few minutes
#
aaronpk
At least Loqi was klined for most of those messages that were sent. How many got into the logs?
#
kline
dansup, so, opal then?
#
aaronpk
Just one, muahaha
#
kline
maybe wowaname?
#
Loqi
hehe
#
kline
dansup, im looking for a name, mostly
#
KartikPrabhu
aaronpk: it would be good if these spam things could be marked in the logs
#
dansup
that was posted by the youtube channel about the spammer
snarfed joined the channel
#
aaronpk
KartikPrabhu: already done
#
aaronpk
You can send a PR to the logs to mark those lines too. I'll add a note about how to the readme
#
KartikPrabhu
aaronpk: I meant't if some Loqi command would automate that like the "rt" command with some confirmation
#
kline
dansup, do you hjave a quick summary of those 3k lines that i might want to know?
#
aaronpk
I don't think it's happened enough to warrant that kind of automation yet
#
KartikPrabhu
fair enough
#
dansup
kline: I don't have much information other than watching the link that was spammed and finding out it has to do with that youtuber and some racist spammer.
#
dansup
People called into the live show and asked why it was being spammed, the host explained it a little bit. I bet more people will call in, check it out
#
KartikPrabhu
don't feed the trolls
#
dansup
I noticed #indieweb was spammed earlier, though I'm not sure its the same spammer.
#
ben_thatmustbeme
they have been doing this across all of freenode
#
ben_thatmustbeme
i've seen it in multiple rooms
#
KartikPrabhu
i even got a bunch of "dm chat" invitations through freenode early last morning
#
dansup
I kicked 2 spammers from #cjdns on efnet about an hour ago, this was the host info
#
dansup
AdAMM207 (~fmfkj@cpe-76-184-153-207.tx.res.rr.com)
#
dansup
d-ti384 (~yzvfumhg@99-126-202-247.lightspeed.cicril.sbcglobal.net) joined the channel
kl1n3, KartikPrabhu and wins83 joined the channel; kl1n3 left the channel
[5 lines deleted]
#
GWG
We need to figure out a auto-block for flooding with references to multiple names
#
jjuran
ben_thatmustbeme: ^
[3 lines deleted]
#
krup
oh boy
[4 lines deleted]
#
GWG
Someone save us
[1 line deleted]
#
gRegorLove
!kick wins83
#
jjuran
Huh. Can anybody do that?
#
aaronpk
Channel ops
#
gRegorLove
I was being silly. aaronpk actually kicked
#
jjuran
GWG: Even better would be temporarily moderating new room members.
#
aaronpk
It's really not something we should worry about making policies for. This is a wide spread attack on all of Freenode, and has happened only once or twice here in the last 7 years
#
KartikPrabhu
!spammer wins83
#
KartikPrabhu
!block wins83
#
Loqi
Okay, I blocked "wins83" from all IndieWeb Twitter searches
#
aaronpk
That's just for twitter
#
krup
Have we resisted making this a registered channel?
John____, renem and krup joined the channel
#
aaronpk
it's nice to see all these new faces in IRC, you should all introduce yourselves and add yourselves to https://indieweb.org/irc-people
[miklb] joined the channel
#
[miklb]
aaronkpk++
#
Loqi
aaronkpk has 1 karma in this channel (2 overall)
#
[miklb]
aaronpk++
#
Loqi
aaronpk has 94 karma in this channel (1506 overall)
#
[miklb]
lol, I’m not the 1st to make that typo
snarfed, tracya, [chrisaldrich], krup, chrisaldrich and gRegorLove joined the channel
#
GWG
aaronpk: Is a Micropub endpoint supposed to authenticate before querying?
snarfed and cweiske joined the channel
#
Zegnat
GWG how do you mean?
[eddie] joined the channel
#
[eddie]
!tell GWG: Yes, when doing the config query of the Micropub endpoint, the endpoint should verify authentication token before responding. (https://www.w3.org/TR/micropub/#configuration)
#
Loqi
Ok, I'll tell them that when I see them next
#
[eddie]
“When a user initially logs in to a Micropub client, the client will want to query some initial information about the user's endpoint. The client should make a query request q=config to obtain initial configuration information.”
#
[eddie]
!tell GWG The key being “when a user initially logs in” as the beginning statement of the Micropub config query.
#
Loqi
Ok, I'll tell them that when I see them next
gRegorLove, j12t and [pfefferle] joined the channel
#
sknebel
Zegnat: regarding our recent JSON discussion, I just discovered https://tools.ietf.org/html/rfc7493 <- that seems like a good guideline
#
sknebel
only I'm not aware of parsers you can set to enforce this
KartikPrabhu, eli_oat, snarfed, [eddie], [miklb], gRegorLove_, [pfefferle] and dougbeal|mb1 joined the channel
#
Zegnat
You will probably require custom JSON writers and readers for that, sknebel :(
renem, krup and snarfed joined the channel
#
snarfed
fyi for anyone using the facebook API, update your oauth settings by march or it may break: https://developers.facebook.com/blog/post/2017/12/18/strict-uri-matching/
jackjamieson joined the channel
#
aaronpk
oh that's a good change
#
aaronparecki.com
edited /Microsub-spec (+836) "/* Channels */ update channel name"
(view diff)
florida and snarfed joined the channel
#
GWG
snarfed, will squash after work as I sous vide
#
Loqi
GWG: [eddie] left you a message 11 hours, 34 minutes ago: Yes, when doing the config query of the Micropub endpoint, the endpoint should verify authentication token before responding. (https://www.w3.org/TR/micropub/#configuration)
#
Loqi
GWG: [eddie] left you a message 11 hours, 34 minutes ago: The key being “when a user initially logs in” as the beginning statement of the Micropub config query.
[miklb] joined the channel
#
[miklb]
are you sous vide cooking squash?
#
snarfed
realized that i'm embedding my oauth state param in the redirect url, instead of passing it to the provider, which means my redirect urls are unique and never match the whitelist
#
snarfed
...and that code is nontrivial to extract 😭
#
snarfed
(at least i'm only doing this inexplicable thing for facebook!)
#
GWG
miklb, chicken, but squashing commits.
tbbrown, krup and [pfefferle] joined the channel
#
www.boffosocko.com
created /poke (+3024) "stub; examples"
(view diff)
[kevinmarks] and raretrack joined the channel
#
gregorlove.com
edited /poke (+155) "/* IndieWeb Examples */ +me"
(view diff)
#
gRegorLove_
I really thought I'd done an indie-poke previously, but can't find it.
#
raretrack
things i don't miss from about 10 years ago: item #1 - pokes... ;)
[eddie] joined the channel
#
[eddie]
The interesting thing is that both pokes and even Facebook's new possible "greetings" are really just emoji reactions to a homepage. No actual new microformats would be needed. Also a lot more flexible. It allows any emotional messages to send. For example, if I want to remind someone I'm watching them: 👀 Or if I want to do a routine check on how someone's constipation is going... :poop: voila! Very flexible 😉 😆
#
[eddie]
While obviously 👀 and :poop: is a joke, I do think that any emoji sent to a homepage should be able to function as a "greeting" rather than needing some form of markup
jackjamieson and [miklb] joined the channel
#
gRegorLove
pokes raretrack ;)
j12t, jackjamieson, krup, tbbrown, tantek, KartikPrabhu and snarfed joined the channel
#
loqi.me
edited /Amazon_S3 (+385) "tantek added "2017-07-12 [http://5newsonline.com/2017/07/12/verizon-data-of-6-million-users-leaked-online/ Verizon Data Of 6 million Users Leaked Online] <blockquote>…[[[NICE Systems]]] made a security setting public, instead of private, on an Amazon..."
(view diff)
#
tantek.com
edited /Amazon_S3 (+492) "/* See Also */ blockquote to illustrate pattern of supposedly private S3 storage being made public"
(view diff)
#
loqi.me
edited /Android (+321) "tantek added "2017-06-16 [https://www.digitaltrends.com/mobile/xavier-andoid-malware/ Newly discovered Android malware Xavier clandestinely steals your data] <blockquote>…a Trojan dubbed Xavier, which is embedded in more than 800 applications on And..."
(view diff)
#
loqi.me
edited /MongoDB (+417) "tantek added "2017-12-15 [https://mackeepersecurity.com/post/cyber-criminals-steal-voter-database-of-the-state-of-california Seems Like Cyber Criminals Steal Database Containing Every Registered Voter in the State of California] <blockquote>In early De..."
(view diff)
#
loqi.me
edited /MongoDB (+414) "tantek added "2017-01-12 [https://www.databreaches.net/need-help-because-your-mongodb-installation-was-hit-by-ransomware/ Need help because your MongoDB installation was hit by ransomware?] <blockquote>… wave of ransomware attacks hitting misconfigur..."
(view diff)
#
loqi.me
edited /MongoDB (+172) "tantek added "2017-01-06 MongoDB.com: [https://www.mongodb.com/blog/post/how-to-avoid-a-malicious-attack-that-ransoms-your-data How to Avoid a Malicious Attack That Ransoms Your Data]" to "See Also""
(view diff)
snarfed joined the channel
#
tantek
interesting, just found this link on venmo's docs: https://venmo.com/?txn=pay&note=Enter%20your%20note%20here
#
tantek
whoa, adding &amount=10 worked!
#
tantek
and yes those params on the existing username link works!
#
tantek
confirmed and deployed
#
tantek.com
edited /payment (+383) "/* How to */ clearer examples of pay links, and add venmo link with amount!"
(view diff)
#
tantek
FYI aaronpk ^^^ :)
#
tantek
feels pretty 1337 today :D
#
tantek.com
edited /payment (-45) "link Venmo to its own page, move direct links there"
(view diff)
#
tantek
whoa venmo has some archive.org busting JS!
#
tantek
their old dev site redirects to "business" https://developer.venmo.com/docs/payment-links
#
tantek
and looking that up in archive.org briefly gives you a visible page which then gets blanked by JS
#
tantek.com
edited /Venmo (+1001) "move link documentation here, add another newer page, note problem with older page (and no archive.org usable copy), details of what was discovered from inspecting the documentation and guessing"
(view diff)
#
tantek
Venmo << 2017-03-16 NBC5(DFW) [https://www.nbcdfw.com/news/tech/Warning-Venmo-Payments-From-Strangers-Can-Cost-You-416276333.html Warning: Venmo Payments From Strangers Can Cost You] <blockquote>Venmo's user agreement says, "personal accounts may not be used to receive business, commercial or merchant transactions."</blockquote>
#
Loqi
ok, I added "2017-03-16 NBC5(DFW) [https://www.nbcdfw.com/news/tech/Warning-Venmo-Payments-From-Strangers-Can-Cost-You-416276333.html Warning: Venmo Payments From Strangers Can Cost You] <blockquote>Venmo's user agreement says, "personal accounts may not be used to receive business, commercial or merchant transactions."</blockquote>" to the "See Also" section of /Venmo
#
loqi.me
edited /Venmo (+324) "tantek added "2017-03-16 NBC5(DFW) [https://www.nbcdfw.com/news/tech/Warning-Venmo-Payments-From-Strangers-Can-Cost-You-416276333.html Warning: Venmo Payments From Strangers Can Cost You] <blockquote>Venmo's user agreement says, "personal accounts may..."
(view diff)
#
tantek
payment << 2016-01-10 lifehacker: [https://lifehacker.com/money-transfer-showdown-square-cash-vs-venmo-vs-payp-1752058723 Money Transfer Showdown: Square Cash vs. Venmo vs. PayPal]
#
Loqi
ok, I added "2016-01-10 lifehacker: [https://lifehacker.com/money-transfer-showdown-square-cash-vs-venmo-vs-payp-1752058723 Money Transfer Showdown: Square Cash vs. Venmo vs. PayPal]" to the "See Also" section of /payment
#
loqi.me
edited /payment (+172) "tantek added "2016-01-10 lifehacker: [https://lifehacker.com/money-transfer-showdown-square-cash-vs-venmo-vs-payp-1752058723 Money Transfer Showdown: Square Cash vs. Venmo vs. PayPal]" to "See Also""
(view diff)
#
tantek
what is Google Wallet
#
Loqi
It looks like we don't have a page for "Google Wallet" yet. Would you like to create it? (Or just say "Google Wallet is ____", a sentence describing the term)
#
tantek
heh - I wonder if anyone here uses it
#
tantek
what is Apple Pay
#
Loqi
Apple Pay is a payment and wallet service from Apple https://indieweb.org/Apple_Pay
[kevinmarks] joined the channel
#
[kevinmarks]
I have used Google wallet, but it does not work with my UK banks
#
tantek.com
edited /payment (+235) "/* Tantek */ amount support at IWC Austin, figured out Venmo amount param as well"
(view diff)
#
tantek.com
edited /payment (+210) "/* Brainstorming */ Payment page with reason, note Venmo support for "note" param"
(view diff)