Mushrooms are an Internet for trees.
Notices by 64 Islands Airship Cooperative (airshipper@cloudisland.nz)
-
Embed this notice
64 Islands Airship Cooperative (airshipper@cloudisland.nz)'s status on Saturday, 28-Jan-2023 08:44:44 JST 64 Islands Airship Cooperative -
Embed this notice
64 Islands Airship Cooperative (airshipper@cloudisland.nz)'s status on Saturday, 07-Jan-2023 06:41:04 JST 64 Islands Airship Cooperative @silverwizard @davidgarywood @evan well, you get to decide, right?
just so we’re clear, i wasn’t suggesting that your private key be protected by your account password, which your admin can easily capture. all signing and decryption should happen in the client, where they could get caught serving patched javascript
-
Embed this notice
64 Islands Airship Cooperative (airshipper@cloudisland.nz)'s status on Saturday, 07-Jan-2023 06:22:13 JST 64 Islands Airship Cooperative @silverwizard @davidgarywood @evan nothing, of course. but if it’s done in the client, you can trust your app rather than the admin.
-
Embed this notice
64 Islands Airship Cooperative (airshipper@cloudisland.nz)'s status on Saturday, 07-Jan-2023 06:14:29 JST 64 Islands Airship Cooperative @evan @davidgarywood you could start with a less audacious goal, which would be for all posts to be signed, and dms encrypted, but your home instance is entrusted with an (optionally) password-protected keypair.
so your local admin might have a shot at brute-forcing your key, but everything else just works.
actually just having a standard for publishing a public key on your profile for clients to pick up and use for signature verification and encryption could get us pretty far.