GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    silverpill (silverpill@mitra.social)'s status on Wednesday, 26-Feb-2025 06:59:32 JST silverpill silverpill
    in reply to
    • Julien Genestoux
    • Raphael Lullis
    • Ryan Barrett

    @raphael @snarfed.org @Julien51 Key ownership can be verified out of band, for example via personal website or by meeting IRL. When this is not possible, we have to Trust On First Use.

    In conversation Wednesday, 26-Feb-2025 06:59:32 JST from gnusocial.jp permalink
    • Embed this notice
      Raphael Lullis (raphael@mastodon.communick.com)'s status on Wednesday, 26-Feb-2025 06:59:33 JST Raphael Lullis Raphael Lullis
      in reply to
      • Julien Genestoux
      • Ryan Barrett

      @snarfed.org @Julien51

      But assume that your server receives a random message. It is properly signed and you can verify the actor. How can you guarantee that the message was sent by the user and not the admin?

      In conversation Wednesday, 26-Feb-2025 06:59:33 JST permalink
    • Embed this notice
      Ryan Barrett (snarfed.org@fed.brid.gy)'s status on Wednesday, 26-Feb-2025 06:59:34 JST Ryan Barrett Ryan Barrett
      in reply to
      • Julien Genestoux

      In practice on the fediverse today, as @raphael says, most fediverse servers do custodial keys. Client-managed keys and signing are still possible though! See @silverpill's FEP-ae97 on client signing. LD Signatures are also relevant; they're not ubiquitous like HTTP Sigs, but still somewhat common, eg Mastodon does them. Also see the SWICG HTTP Sigs report.

      cc @Julien51

      In conversation Wednesday, 26-Feb-2025 06:59:34 JST permalink
    • Embed this notice
      Raphael Lullis (raphael@mastodon.communick.com)'s status on Wednesday, 26-Feb-2025 06:59:35 JST Raphael Lullis Raphael Lullis
      in reply to
      • Julien Genestoux

      @Julien51

      Do you mean that it hasn't been tempered by the server admin? No. The keys are managed by the server. So a malicious admin could generate messages on behalf of the user.

      In conversation Wednesday, 26-Feb-2025 06:59:35 JST permalink
    • Embed this notice
      Julien Genestoux (julien51@mastodon.cloud)'s status on Wednesday, 26-Feb-2025 06:59:36 JST Julien Genestoux Julien Genestoux

      In the activitypub world is there any way to know *for sure* (cryptographically) that a specific use posted a toot?

      In conversation Wednesday, 26-Feb-2025 06:59:36 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.