3 ms·
How do you plan on managing the signing keys?
by acid__ 6y ago
How do you plan on managing the signing keys?
- rudolph9 6y agoHardware security module
- acid__ 6y agoSeems like it would be a nice feature for security-minded folks, and would probably be pretty difficult to roll out to regular consumers. Does Mastodon have something like this? Sounds like something their userbase would appreciate.
- rudolph9 6y agoYou could literally dump the signature in at the end of the utf-8 tweet. A tweet can contain about 500 bytes, the signature is 64 bytes; encode it using utf8 characters and you got plenty of room room for a message and a signature I’m honestly surprised this isn’t common already in the crypto space and kinda wonder if I’m missing something
- acid__ 6y agoFor sure, the hard part isn't building it, it's getting people to actually use it. The amount of effort involved of actually acquiring and transporting a hardware security key is well beyond what most "normal" people are willing to do. Plus, reading your example in a different comment, it's completely jarring to someone who isn't used to reading things in that format.
- rudolph9 6y agoI get why everyday users don’t use it but why doesn’t an org like coinbase? Yes the quick and dirty poc I built in 5 minutes is a bit jarring but it could easily be adjusted so the beginning of the tweet reads like it normally would and the end is the cryptographic signature nearly separated from the main message.