Let me just put this out here:
If you're coming to me hoping to "mediate" between Matrix or even "win Soatok over"
You're wasting your fucking time.
Let me just put this out here:
If you're coming to me hoping to "mediate" between Matrix or even "win Soatok over"
You're wasting your fucking time.
@soatok out here like.
It's like PGP.
If I see a thing uses OpenPGP in any capacity, I immediately bail out.
Because I do not want even a second of my life to be wasted on helping spread the misconception that anyone should be using PGP.
Nor do I want to inadvertently make something built on PGP accidentally more secure by the nature of looking at it.
I'd rather it burns to the ground.
But I like Matrix/PGP/MTProto and want it to be better!
Then: Get good.
I literally blog about applied cryptography for free. If you steal the info I've shared and use it to benefit projects I hate, I'll be none the wiser.
But if you do this, please don't fucking tell me about it.
What about JSON Web Tokens?
Listen: If you can make JWTs secure without reinventing Macaroons or PASETO, you deserve a Levchin fucking prize.
@Sominemo This is the correct response
@soatok whenever people suggest JWTs I get (ir?)rationally angry
@soatok I tried out PGP (using GPG) for a little while. It is so terrible & unpleasant to use, & the cryptography used is absolutely ancient. The usage cycle is convoluted & confusing.
I'm sure it could be decent to use with a nice UI, but it could never feel secure. You're always going to have to downgrade your security for certain people with it too. It feels like something LockPickingLawyer would open in a few seconds after learning cryptography once he exhausts all physical locks.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.