3 ms·
This is a directory of public keys, which every secure messaging app including Keybase must also have, but federated rather than centralized. That's a necessit
by ineptech 2y ago
This is a directory of public keys, which every secure messaging app including Keybase must also have, but federated rather than centralized. That's a necessity for e2ee and it's very cool to implement it as an append-only version of the pub-sub messaging the fediverse already has.
It has nothing to do with the identity verification a la Keybase, unfortunately, as that would be a really good and useful feature for the fediverse, but I think it would be a lot harder to do.
- some_furry 2y agoNothing prevents other people from stapling identity verification on top of this.
- ineptech 2y agoWell I hope so, but it would take something more exotic than the directory service described in this article, right? ... thinking it through, maybe not. I guess if a client initiates AddVerification for some twitter handle, and the directory service sends that handle a private twitter message with some guid, and then the client sends AddVerificationStepTwo with that guid, the directory service could append both of those messages to attest that that user is associated with that handle. A malicious directory service (or a real directory service that's calling a malicious twitter clone) could fail to correctly verify someone, but it wouldn't be able to add a verification for the wrong client or for a client that didn't initiate it, which is probably good enough? edit: just realized you're the author, thanks for working on this stuff!