@trwnh@evan anyway I like mutual TLS in theory but in practice there’s the problem that most instances are running behind TLS terminators so they don’t necessarily have access to their own TLS keys
Gleason walked into the SocialHub to drop his latest innovation and I’m sitting here trying to work out whether he just proudly announced that he introduced a security bug into his own software or not
Specifically the key ID isn’t signed so if you’re sharing private keys, someone who captures a signed message can just swap key IDs
Capturing a signed message sounds hard but if you do manage to do it you can probably e.g. read private posts accessible to anyone on your instance
So its probably not an issue for mostr because that’s a bridge to libertarian hellscape where everything is public all the time but in general I dunno the security calculus is nontrivial
@james@terraboops I also feel like there's a big expectations communications issue in general
I make very clear to people that I have an anchor partner who I have a very long lasting and strong relationship with, and you've gotta understand that I just don't have the emotional capacity to be *that* close to multiple people at once. Doesn't mean we can't become very close, but you have to understand those dynamics; if you're looking for something that tight with me, you're going to be disappointed
It alarms me how many people have been banging the "Machine Learning is just Money Laundering for bias" drum for years, yet claim that algorithmically curated block lists are a way of avoiding it
https://ns.erincandescent.net/ap#Scream - Activity, represents that the actor is screaming
Properties:
as:target: Optional, indicates the target that the user is screaming at
https://ns.erincandescent.net/ap#Void - Special purpose Object, representing the Void. When used as the target of a Scream activity, indicates that the user is screaming into the void
immigrant | they/them | software engineer in card paymentsliker of ISO 8583, the 8051, ASN.1 and EBCDIC.I wrote the ActivityPub initial draft, so this social network is in some way my fault.Formerly @erincandescent@queer.af Instance admin, queer.af (2018-07 - 2024-02, RIP)