4 ms·
Well, I'm not just hand-waving (at least I don't think I am), I'm actually got burnt by this. I was building a demo of my app on top of libp2p, and then I disco
by folex 6y ago
Well, I'm not just hand-waving (at least I don't think I am), I'm actually got burnt by this. I was building a demo of my app on top of libp2p, and then I discovered that I need to issue domain name and certificate for each node in my p2p network.
This wasn't hard – caddy2 makes it super easy. But I see it as a pretty weird requirement. I don't understand, why can't I sign some data with public key without being on secure origin.
> The only reason you can think of is a weird conspiracy?
I didn't mean to assume conspiracy theories, I agree that this is a pretty unprobable story. I'm just saying: "It's so weird that my only sound explanation is a weird conspiracy theory", meaning that I don't understand how this came to be, and motivation behind that :)
- tialaramex 6y ago> why can't I sign some data with public key without being on secure origin. I'm guessing you mean sign with a private key. In a secure context the Browser gets to promise the context that this private key stays private if it wants. For example, should the the private key be posted to Twitter? In a secure context you get to decide, because only code your wrote runs in that context, if you don't add "post private key to Twitter" code then it doesn't happen. But in insecure contexts any on-path attacker can substitute their own code for yours. Now your "private" key is in a Twitter post, hilarious.