Does anyone running a misskey/mastodon instance know if it would be possible for you to steal someone's profile? May it be by simply deleting and recreating the same username on the same instance but with you in control, or by other means?
I'm asking because I think we could all benefit from a private/public keys system like there is on keybase.io in order to be sure that we are interacting with the right user.
@gaijin May it be by simply deleting and recreating the same username on the same instance but with you in controlWhen you delete an account the name will still be reserved unless an admin changes this manually, so no. I assume Mastodon does the same thing, though I never ran it myself. I'm asking because I think we could all benefit from a private/public keys system like there is on keybase.io in order to be sure that we are interacting with the right user.A similar feature already exists, it's called authorized fetch. Most fedivsrse software implements it. https://www.w3.org/wiki/ActivityPub/Primer/Authentication_Authorization
@gaijin@dushman work is being done to make it possible for a user to have custody of their own private key but this work will go nowhere because mastodon will refuse to support it.
@sun@shitposter.world@dushman@den.raccoon.quest Why aren't we letting users see the public key of others in order to compare? And the owner download his private key to keep it on a safe storage?
@gaijin@dushman there is some hesitancy here because if you mention crypto wallets (now probably the biggest end-user deployment of public key encryption ever), even though you're not even touching a blockchain or expending carbon to do the key operations, a bunch of people start pissing and shitting themselves uncontrollably with rage at the suggestion.
@dushman@sun@shitposter.world Could be done by a browser extension like crypto wallets do. Then you could connect to fedi with your private key somehow. I'm not well informed on how it works to be honest.
@dushman@sun@shitposter.world Depends on the blockchain and the confirmation system they are using. PoW (Proof of Work) is indeed insane but alternatives are being found like the Solana one with their PoH (Proof of History)
@dushman@gaijin I did say that the key operations don't do transactions, they are just normal cryptography on the client machine alone.
eth wallets are what are usually on the table and they switched to a system a couple of years ago that doesn't boil oceans so everybody just switched their argument to "it's still bad because it USED TO do that"
@dushman@gaijin most people here are extremely anti-crypto no matter what. I'm not talking about you, who has some concerns/objections, but people that have a giant emotional reaction to the idea of using a crypto wallet for any purpose.
@sun@shitposter.world@gaijin@den.raccoon.quest I did say that the key operations don't do transactions, they are just normal cryptography on the client machine alone.I know. I was asking if someone made a fuss about that for some reason.
@dushman@gaijin that is fair but at the same time consider that all of this applies to anyone in normal finance and these same people still beg using paypal
@sun@shitposter.world@gaijin@den.raccoon.quest Yeah I guess a lot of them are here. Overly enthusiastic cryptobros are just as cringe though. Also energy usage aside, seeing more use as a vehicle for speculation than actual currency is another big problem imo.