4 ms·
> This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' ba
by publiush 5y ago
> This part can be addressed easily with avatars such as those Gravatar makes. Using a blockchain instead seems like a huge overkill, and also brings 'login' back into the equation because most websites will use something like Metamask, which you have to log into.
A gravatar is great for a profile photo, but in the end, there's no guarantee that the message viewed by a user was actually written by the poster. A site admin could simply inject posts as that user.
With signed messages, only those who possess the key could have created the signature for the signed message. Even a site admin cannot edit the message and get away with it (since the signature wouldn't validate).
- sombremesa 5y ago> in the end, there's no guarantee that the message viewed by a user was actually written by the poster If you think about it, this is also true for web3 — true enough that it's broken. We don't live in a world where you can't take things from people, etc. Ultimately, society works because we don't really need ironclad guarantees — and we don't have any.
- publiush 5y ago> If you think about it, this is also true for web3 — true enough that it's broken. You absolutely cannot fake a message being cryptographically signed without providing a broken verification function. > We don't live in a world where you can't take things from people, etc. The half glass empty approach is one method. The other method is to review the primitives we have in place today and explore different permutations that allow us to route around our adversities. That's the Hacker way. Of course, we do it with code. > Ultimately, society works because we don't really need ironclad guarantees like that. The society you live in is very different from mine. Fraud and impersonation are real. [1] [1] https://www.theverge.com/2016/11/23/13739026/reddit-ceo-steve-huffman-edit-comments https://www.theverge.com/2016/11/23/13739026/reddit-ceo-stev...
- sombremesa 5y agoBetween "there's no guarantee that the message viewed by a user was actually written by the poster" and "You absolutely cannot fake a message being cryptographically signed without providing a broken verification function" you moved the goalposts so hard it gave me whiplash and I'm afraid I can't continue this discussion due to my concussion.
- publiush 5y ago> Between "there's no guarantee that the message viewed by a user was actually written by the poster" and "You absolutely cannot fake a message being cryptographically signed without providing a broken verification function" you moved the goalposts so hard it gave me whiplash and I'm afraid I can't continue this discussion due to my concussion. I think it might be wise to review what signing means to understand that I didn't "move the goalposts" at all [1], but thanks for the discussion, as I merit it will help a lot of people to better understand the power of cryptography as I'm guessing it's a new field here as of yet. Happy New Year! [1] https://en.wikipedia.org/wiki/Digital_signature https://en.wikipedia.org/wiki/Digital_signature
- wyattpeak 5y agoNo, they're absolutely right. You can steal a person's computer. You can get them drunk and ask them to hand over their keys. There are a dozen ways off the top of my head that you can have a message that's not written by the supposed poster without a broken cryptographic function. As always, there's a relevant XKCD https://xkcd.com/538/ https://xkcd.com/538/
- publiush 5y agoThis is solved with key management and security as opposed to with the fact on whether or not the technology has merit. Now, we're really moving goalposts. ;)
- 5y ago