3 ms·
With cryptography.
by daveid 9y ago
With cryptography.
- yellowsir 9y agohow? in the example the data is not signed, what is stopping a other server from changing the content i posted?
- Shoothe 9y agoThe real world example as used by Mastodon uses signing to protect content but the process is kind of complicated (normalization of json to RDF triples etc.)
- daveid 9y agoThe exact methods of authentication are simply "out of scope" for the ActivityPub standard itself. As far as I understand simply for bureaucratic reasons. In reality there's already agreed upon mechanisms for doing this. Each actor has an RSA keypair. Server-to-server requests are authenticated using HTTP signatures (that's a different spec), so you know a delivery is legit and on behalf of which actor it is. For messages that are passed directly between origin and destination there is no reason to believe the sender has tampered with the message (SSL is a prerequisite anyway). For messages that are about other messages, such as reblogs, you would not trust the sender, you would look up the message by its ID on its origin server instead. This is always possible because ActivityPub prescribes IDs to be resolveable URIs. There's also another method to verify the authenticity of a passed message, called Linked-Data Signatures (that's a different spec). It's a way of signing JSON inside JSON, it's a bit of a bother to implement though (To make sure the signature works regardless of how the payload is re-formatted or re-ordered in transit, the JSON is "canonicalized" using RDF)