@helene ok but what if like just hear me out here what if we took pleroma right and then like right we got pleroma and then like we could like idk you know what i'm saying put it on the ethereum? so like pleroma on the blockchain you know what i'm saying
@helene wait do i understand correctly that the signature fields get added inside of the content after the signature is made and to test the signature you have to remove thoso fields before?
@ukko it's because they want activities to be relayed without needing to contact the original instance if you support the feature and because they didn't want to break federation still a terrible idea
@helene yea but they could have the signed data be encapsulated not mixed with the signature. make sure to design it so that older versions drop&ignore it and have some grace period where mastodon would still send unsigned or http-signed messages
@helene@ukko why couldn't they borrow from signed email? where a pgp message signature is an attachment. you can read the message without parsing the signature, but the sig is proof that the message is unaltered & from whoever claimed to send it
I guess it's like a lot of modern tech "we'll make it new & not look at what's already worked"
@helene fwiw ld sigs are recommended against and were only implemented for relays, which people largely don't even use anyway
if i were doing a greenfield project i simply would not bother, as i find relays conceptually flawed in their current form and also i think you can generally trust what was sent to you without having to verify it 100% -- like, have the relay do the verification before sending it out, then implicitly trust the relay
@helene possibly idk, there are some limited cases where ld sigs are used/supported and there will probably never be more bc mastodev is against using them in general due to how terribad and complex they are
i think favs are not relayed, they are sent directly to the author instead of your followers
deletes are generally sent out via "best effort" paths which is roughly like sending it out to the whole known fedi