3 ms·
Well I hope so, but it would take something more exotic than the directory service described in this article, right? ... thinking it through, maybe not. I gue
by ineptech 2y ago
Well I hope so, but it would take something more exotic than the directory service described in this article, right?
... thinking it through, maybe not. I guess if a client initiates AddVerification for some twitter handle, and the directory service sends that handle a private twitter message with some guid, and then the client sends AddVerificationStepTwo with that guid, the directory service could append both of those messages to attest that that user is associated with that handle. A malicious directory service (or a real directory service that's calling a malicious twitter clone) could fail to correctly verify someone, but it wouldn't be able to add a verification for the wrong client or for a client that didn't initiate it, which is probably good enough?
edit: just realized you're the author, thanks for working on this stuff!