5 ms·
You hit the nail pretty much on the head. While you're correct that a 4chan-like mechanism would provide a means of authentication, the hash would not be human
by publiush 5y ago
You hit the nail pretty much on the head. While you're correct that a 4chan-like mechanism would provide a means of authentication, the hash would not be human-recognizable easily (basically, not meaningful). Using a naming block chain like Handshake, you essentially solve Zooko's Trilemma [1].
[1] https://en.wikipedia.org/wiki/Zooko%27s_triangle https://en.wikipedia.org/wiki/Zooko%27s_triangle
- sombremesa 5y ago> While you're correct that a 4chan-like mechanism would provide a means of authentication, the hash would not be human-recognizable easily (basically, not meaningful) This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation, albeit with a different connotation than traditional login.
- deleted 5y ago[deleted]
- publiush 5y ago> This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation because most websites will use something like Metamask, which you have to log into. A gravatar is great for a profile photo, but in the end, there's no guarantee that the message viewed by a user was actually written by the poster. A site admin could simply inject posts as that user. With signed messages, only those who possess the key could have created the signature for the signed message. Even a site admin cannot edit the message and get away with it (since the signature wouldn't validate).
- sombremesa 5y ago> in the end, there's no guarantee that the message viewed by a user was actually written by the poster If you think about it, this is also true for web3 — true enough that it's broken. We don't live in a world where you can't take things from people, etc. Ultimately, society works because we don't really need ironclad guarantees — and we don't have any.
- publiush 5y ago> If you think about it, this is also true for web3 — true enough that it's broken. You absolutely cannot fake a message being cryptographically signed without providing a broken verification function. > We don't live in a world where you can't take things from people, etc. The half glass empty approach is one method. The other method is to review the primitives we have in place today and explore different permutations that allow us to route around our adversities. That's the Hacker way. Of course, we do it with code. > Ultimately, society works because we don't really need ironclad guarantees like that. The society you live in is very different from mine. Fraud and impersonation are real. [1] [1] https://www.theverge.com/2016/11/23/13739026/reddit-ceo-steve-huffman-edit-comments https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...
- sombremesa 5y agoBetween "there's no guarantee that the message viewed by a user was actually written by the poster" and "You absolutely cannot fake a message being cryptographically signed without providing a broken verification function" you moved the goalposts so hard it gave me whiplash and I'm afraid I can't continue this discussion due to my concussion.
- publiush 5y ago> Between "there's no guarantee that the message viewed by a user was actually written by the poster" and "You absolutely cannot fake a message being cryptographically signed without providing a broken verification function" you moved the goalposts so hard it gave me whiplash and I'm afraid I can't continue this discussion due to my concussion. I think it might be wise to review what signing means to understand that I didn't "move the goalposts" at all [1], but thanks for the discussion, as I merit it will help a lot of people to better understand the power of cryptography as I'm guessing it's a new field here as of yet. Happy New Year! [1] https://en.wikipedia.org/wiki/Digital_signature https://en.wikipedia.org/wiki/Digital_signature
- wyattpeak 5y ago
- woojoo666 5y agoI'm not too familiar with 4chan and handshake, but my current understanding of this is that it's like using public-private key cryptography for creating user identities, and then using blockchain to map public keys to usernames? So if I wanted to make a post, I first generate a public-private key pair, and then sign posts using my public key?
- Zababa 5y agoMost tripcodes on 4chan are relatively recognizable, since they are combined with the names: https://en.m.wikipedia.org/wiki/Imageboard https://en.m.wikipedia.org/wiki/Imageboard