GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 30-Apr-2026 00:17:55 JST Soatok Dreamseeker Soatok Dreamseeker
    • Elias Mårtenson
    • Chee Aun 🤔

    @eltrac @loke @cheeaun What does faking commit authorship actually buy an attacker?

    In conversation about 5 months ago from furry.engineer permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 30-Apr-2026 00:27:01 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to
      • Elias Mårtenson
      • Chee Aun 🤔

      @loke @eltrac @cheeaun Your suspicion is incorrect. I'm trying to make sure I understand the shape of the problem you're trying to solve.

      You're tying commit authenticity to long-lived keys. You're stapling non-repudiation into your designs. You're assuming a lot of security properties about the cryptography algorithms involved.

      For example: Signatures do not, by themselves, provide a property called exclusive ownership. https://www.bolet.org/~pornin/2005-acns-pornin+stern.pdf

      Many of these properties matter significantly in some use cases. I was probing to see if they mattered here.

      In conversation about 5 months ago permalink

      Attachments


    • Embed this notice
      Elias Mårtenson (loke@functional.cafe)'s status on Thursday, 30-Apr-2026 00:27:02 JST Elias Mårtenson Elias Mårtenson
      in reply to
      • Chee Aun 🤔

      @soatok @eltrac @cheeaun it's reasonably easy to think of various scenarios. But I suspect that whatever I say, the reply will be "that's not a real problem" or "there are other ways to protect against that".

      Suffice it to say that I'm not worried about specific scenarios that I can envision. It's the ones that may happen in the future I'm concerned about. Proving the chain of changes is what I think itbis is just a good idea. Especially since my primary project uses SHA1 hashes.

      In conversation about 5 months ago permalink
    • Embed this notice
      Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 30-Apr-2026 00:31:13 JST Soatok Dreamseeker Soatok Dreamseeker
      in reply to
      • Elias Mårtenson
      • Chee Aun 🤔

      @loke @eltrac @cheeaun If you're using SSH signatures with Ed25519 (very common), you have Universal Exclusive Ownership by design.

      If you're using anything else, it's a "maybe". Most PGP keys I've seen, historically, were RSA keys.

      In conversation about 5 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.