Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Todd Sundsted

@toddsundsted@epiktistes.com
ktistec 3.13.0
  • Open on epiktistes.com
Better dead than bored.
0 Followers
0 Following
28 Posts
Introduction:
https://epiktistes.com/introduction
GitHub:
https://github.com/toddsundsted/ktistec
Pronouns:
he/him
🌎:
Sector 001
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 2mo ago
Replying to
@jamie@zomglol.wtf "hopes and dreams tests" is my new forever name for these tests
1
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 3mo ago
Replying to
@jamie@zomglol.wtf there is often no obvious relationship between some people's confidence and their competence.
1
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 6mo ago
Replying to
@ObsidianUrbex@mstdn.social marshmallow!
2
1
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
Replying to
@johncarlosbaez@mathstodon.xyz this is amazing! thank you for taking the time to post it!
1
1
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 6mo ago
Replying to
@norwescon@social.seattle.wa.us it's killing me not to be there!
1
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 6mo ago

a glance is worth a thousand words

a black and white husky malamute fluffer mix glancing upward with blue and brown mismatched eyes

#DogsOfMastodon #Saki

epiktistes.com

Epiktistes | #DogsOfMastodon

0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 6mo ago
Replying to
@silverpill what's the entry point for trying this out? consuming portable objects?
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 5mo ago
I’m working on handling OAuth token expiry as part of #ktistec Mastodon API support. Is my understanding that Mastodon issues OAuth tokens with no expiration correct?!?
0
1
1
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago

This release continues my focus on security instead of new features. As I wrote earlier this week, I rebuilt the template framework Ktistec uses with type safety as a central principle. What does that mean?

Imagine that you have an instance of a String that holds federated data. Where can you safely render that in a browser, and what operations (sanitization, escaping, etc.) do you need to do first?

The only way to answer that is to look carefully at the lineage of that data: where it came from, how it was stored, how it was transformed, and where it's rendered. A name holds text; an href or src attribute holds a URL. If you want to render a name inside an HTML element you should HTML escape it. You should escape href and src, too, but the escaping rules for URLs are slightly different from the HTML rules. It's easy to make mistakes.

Ktistec uses four "safe" types to express the contracts:

SafeHTML: A String wrapper marking HTML markup safe to emit raw into HTML data slots (text content, between tags).

SafeAttrValue: A String wrapper marking a value safe to emit raw inside a double-quoted HTML attribute (attr="..."), other than URL or event-handler slots.

SafeURI: A String wrapper marking a URL safe to emit raw into a URL attribute slot (href, src, action, etc.).

SafeJSON: A String wrapper marking JSON output safe to emit raw into the body of a </code> block.</p><p>Using the wrong type at a call site is either a compile-time error, or it triggers automatic sanitization of the underlying string value.</p><p>Here's the full changelog:</p><p><strong>Added</strong></p><ul><li>String safety framework with typed "safe" strings.</li><li>New Slang template engine with compile-time safety checks.</li><li>Vendored <code>WebFinger</code> and <code>HostMeta</code> client shards.</li></ul><p><strong>Fixed</strong></p><ul><li>Prevent delivery to unknown IRIs.</li><li>Narrow Like/Dislike addressing to the liked object's author.</li></ul><p>I have at least one more cleanup pass to do, and then I'll turn my attention back to the Mastodon-compatible API and a few features I've been looking forward to—like scheduled posts.</p><p><ahttps://epiktistes.com/tags/ktistec" target="_blank" rel="noopener noreferrer" class="text-primary hover:text-accent hover:underline decoration-2 underline-offset-2 font-medium transition-all duration-200">https://epiktistes.com/tags/ktistec" class="hashtag" rel="tag">#ktistec</a> <ahttps://epiktistes.com/tags/crystallang" target="_blank" rel="noopener noreferrer" class="text-primary hover:text-accent hover:underline decoration-2 underline-offset-2 font-medium transition-all duration-200">https://epiktistes.com/tags/crystallang" class="hashtag" rel="tag">#crystallang</a> <ahttps://epiktistes.com/tags/activitypub" target="_blank" rel="noopener noreferrer" class="text-primary hover:text-accent hover:underline decoration-2 underline-offset-2 font-medium transition-all duration-200">https://epiktistes.com/tags/activitypub" class="hashtag" rel="tag">#activitypub</a> <ahttps://epiktistes.com/tags/fediverse" target="_blank" rel="noopener noreferrer" class="text-primary hover:text-accent hover:underline decoration-2 underline-offset-2 font-medium transition-all duration-200">https://epiktistes.com/tags/fediverse" class="hashtag" rel="tag">#fediverse</a></p>

epiktistes.com
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
how widely adopted/supported/implemented is FEP-8a8e? is that a safe direction to converge for federated events?
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
Boosted by @fedicat@pc.cafe
Release v3.3.9 of Ktistec continues the security hardening work from recent releases, with further progress on the Mastodon-compatible API. Of note: all network connections now go through a new Ktistec::Network module. This allows Ktistec to limit the size of HTTP bodies it reads, on both inbound and outbound requests, and ensures it only opens connections to valid remote IP addresses. Here's the full changelog: Added New Mastodon-compatible APIs. Fixed Close DNS rebinding window for outbound HTTP requests.Limit the size of HTTP bodies the server reads.Sanitize RSS feed output to prevent CDATA breakout.Destroy all sessions and access tokens on account termination. Changed Ensure all GET and POST requests utilize Ktistec::Network.Process local recipients in-process in inbox/outbox activity processors. As always, it's worth upgrading for the security fixes! #ktistec #crystallang #activitypub #fediverse
0
0
1
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
Boosted by @fedicat@pc.cafe
This release fixes a small number of bugs found in recent releases. The full changelog: Fixed Prevent runaway recursion when handling filtered posts.Ensure profile header and header_static images are always present.Render the inline replies collection for local objects.Exclude blocked actors from object statistics and notifications. Changed Return 410 Gone instead of 404 Not Found for missing actors. Removed Tag counts on public pages. This release fixes a hard-to-exploit but potentially server-crashing bug. If you're running v3.3.9 or v3.4.0, you should upgrade. #ktistec #crystallang #activitypub #fediverse
Release v3.4.1 of Ktistec
Epiktistes

Release v3.4.1 of Ktistec

This release fixes a small number of bugs found in recent releases. The full changelog: Fixed Prevent runaway recursion when handling filtered posts. Ensu…

0
0
1
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 3mo ago
Boosted by @fedicat@pc.cafe
There are two significant new additions in release v3.8.0 of ktistec. First, the actor cards on the followed/following pages show relevant actor status. On the followed page, it tells you how long it has been since that actor published an activity (create, announce, like, etc.) that was sent to your server. It's a proxy for how active they are (or are not). On the following page, it tells you how long it has been since you have been able to send to that server. It's a proxy for whether that server is reachable or that actor is still alive. Second, the backend for user-defined algorithmic feeds is in place, along with a keyword/hashtag/mention feeds implementation. You can't set up a feed via the user-interface, but the feeds work if you set one up directly in the database—which is how I've been previewing them. I plan to release the frontend next week. Here's the full changelog: Added Display activity status on actor cards.Back-end support for user-defined algorithmic feeds.Apply community-relayed moderator deletes received as a Group's wrapped Announce.Follow a web page's rel="alternate" link when searching. Fixed Avoid loading entire has_many collections when constructing child records.Evaluate the same-origin fetch gate against an embedded node's own identifier.Accept a delete of an uncached object or actor without verification.Catch MIME::Multipart::Error in local file-upload handling.Map malformed request-body parse failures to Bad Request. #ktistec #crystallang #activitypub #fediverse
0
0
1
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 1w ago
Boosted by @dansup@mastodon.social
RE: https://techhub.social/users/manlycoffee/statuses/117355106009404188 whenever i take a few weeks away and then come back, the fediverse always feels like it's become a little more hostile, like it's increasingly the place where people come to wallow in their anger. the real weird trend, lately, seems to be crapping on the developers (volunteers) and the site admins/mods (also volunteers). where is the winning strategy with that move?
Open quoted post
Quoting
Sal Rahman
@manlycoffee@techhub.social
Can someone explain to me why was Pixelfed, Loops, and Dansup being singled out for AI use? There's no shortage of Fediverse software that are either built with AI assistance (including vibe coding), or welcomes AI contribution, but I'm not seeing the same level of outrage. Did Pixelfed, Loops, and Dansup specifically promise to be AI-free? #Fediverse #ActivityPub
Open quoted post
techhub.social
0
0
1
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 5mo ago
Replying to
@EdBruce@infosec.exchange @dangoodin@infosec.exchange that's fair and i'm skeptical end users are paying the actual cost of inference right now, but i recently dropped $50K on a pen test. even at 100x the out of pocket costs, equivalent results from LLMs cost a fraction of that.
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 5mo ago
Replying to
@dangoodin@infosec.exchange you don’t even need mythos. anyone who cares to can run a state of the art model against their code, and with a little persistence find exploitable vulnerabilities. this shouldn’t even be surprising. before LLMs, anyone who cared to could run a high quality pen test on their code and find exploitable  vulnerabilities. all LLMs have done is lowered the cost of doing that!
0
2
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 10mo ago
Replying to
thank you for all of the hard work @Gargron@mastodon.social  i can say for certain that if you hadn't demonstrated what's possible with mastodon, i wouldn't have taken the step of building ktistec. i'm excited to see what you do next!
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 2mo ago
Replying to
@benpate@mastodon.social @mro@digitalcourage.social this is really the heart of the problem: a small number of very loud people see themselves as judges of what the "fediverse" means, or "federated" or "diverse". and i don't accept their authority. and i do think the loudest are destroying the fediverse. i worry that when they're done, the fediverse will be perfectly in agreement on all "principles" and there will be like 23 people on it. it was pointed out elsewhere on this thread that many of the loudest see themselves as refugees from corporate social media, and don't want to see the fediverse become like that. i get that—it's literally why i'm here. but i still don't think the fediverse needs their stewardship!
0
3
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 2mo ago
Replying to
@benpate@mastodon.social @mro@digitalcourage.social i have the advantage of running my own server software (#ktistec) so i have lots of levers. right now it comes down to mostly 1) liberal blocking and 2) effective "algorithmic" feeds (that just means flexible hashtag, mention, keyword filtering and they're still work in progress). so far i haven't had to resort to blocking instances. it's a good question though. like i said, i came here as a refugee myself and my goal is to build my own "safe space" on the fediverse. i just don't think anyone should be the arbiter of anyone else's definition of "safe space".
0
1
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 14mo ago
Replying to
@fribbledom@mastodon.social resonates...!
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 8mo ago
Replying to
@reiver@mastodon.social I’d love to see this but is it feasible without mastodon on board?
0
5
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
Replying to on mastodon.social
@reiver@mastodon.social i don't mind type but the leading hash always feels redundant
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 4mo ago
Replying to on metalhead.club
@mariusor@metalhead.club @silverpill@mitra.social a good question! one and the same thing for me. i'm just tired of having to go "somewhere else" to interact with events. fwiw, my personal bar is pretty low, but i increasingly think this is a major missing piece.
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 2mo ago
Replying to
@mariusor@metalhead.club I’d love to hear more about this!
0
4
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 2mo ago
Replying to
@mariusor@metalhead.club okay this is intriguing
0
1
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 45mo ago
Replying to
@kyle@social.librem.one it's an interesting question. the turing test is appealing because it's so simple, but i wonder what other benchmark would distinguish between a really effective tool, and a possibly thinking machine. i also wonder if deception is a hallmark of all kinds of intelligence, or just maybe ours...
0
0
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 5mo ago
Replying to
@jamie@zomglol.wtf 🎶 "never gonna open that up..."
0
1
0
0
Open post
Todd Sundsted @toddsundsted@epiktistes.com
· 3mo ago
Replying to
@jamie@zomglol.wtf We’ve stopped doing reviews. or more specifically, we’ve stop doing anything more than giving PRs thumbs up (can merge) or thumbs down (can’t merge). Reviews don’t contain feedback unless the feedback is specifically instructions for an agent. Learning, which agents can’t do but is crucial for human development, now happens off line. TL;DR if your PR is rejected and you want to understand why, you have a discussion on a separate channel.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:39:29 UTC