Post AdUZ1144Fosb1CvFya by silverpill@mitra.social
(DIR) More posts by silverpill@mitra.social
(DIR) Post #AdTLPYSEAe6X0a4OY4 by marcua@hachyderm.io
2024-01-03T14:18:52Z
0 likes, 1 repeats
This proposal to separate your ActivityPub identity from the server on which you reside is promising (and addresses my biggest gripe with AP), though I'm naive to the process. How far could it be from making it into the standard, and what sort of migration pains would implementations like Mastodon face?https://codeberg.org/fediverse/fep/src/branch/main/fep/ef61/fep-ef61.md
(DIR) Post #AdTLPaoHPcvsJYP2CO by marcua@hachyderm.io
2024-01-03T14:21:30Z
0 likes, 0 repeats
Ah! I didn't credit the author @silverpill! I apologize!
(DIR) Post #AdTLPboffeq7R3arRo by silverpill@mitra.social
2024-01-03T15:00:06.409759Z
1 likes, 0 repeats
@marcua I'm still working out the details, but here is what I think could cause migration pains:- With FEP-ef61, one account can use multiple servers. But many existing projects are designed for one-to-one relationship, and in these cases a lot of internal refactoring might be required.- It changes how moderation works, in particular instance blocks. I think instance blocks will remain effective, but will be less effective than today, and a lot of people may not like it.- It changes privacy expectations, because messages are signed and can be forwarded without asking a permission from an originating instance. Many protective measures like authorized fetch and follower-only visibility will likely be weakened. I think encryption standards must be developed to offset this.
(DIR) Post #AdTaqdF9yGqYzdKKzw by marcua@hachyderm.io
2024-01-03T16:58:13Z
0 likes, 0 repeats
@silverpill This was so helpful, thank you! Ouch on the last one. Is that something the atproto team has addressed? Given this proposal and that protocol use DIDs, I wonder what else one could take inspiration from.
(DIR) Post #AdTaqe252NyjRMDPFY by silverpill@mitra.social
2024-01-03T17:52:58.067199Z
0 likes, 0 repeats
@marcua AFAIK atproto doesn't have private messages yet: https://github.com/bluesky-social/atproto/discussions/121. Some Nostr apps may have encryption, I'm not sure which ones.I think our main source of inspiration should be Matrix, which is also federated and supports encryption for both direct messages and entire rooms.
(DIR) Post #AdTbmT3S0kDeBlQcbo by silverpill@mitra.social
2024-01-03T18:02:38.383392Z
0 likes, 0 repeats
@marcua Secure Scuttlebutt also uses encryption: https://ssbc.github.io/docs/ssb/end-to-end-encryption.html
(DIR) Post #AdToNUgO7USrP13xb6 by marcua@hachyderm.io
2024-01-03T19:07:25Z
0 likes, 0 repeats
@silverpill Makes sense! Thank you!Curiously, how much time do these RFCs typically take from being accepted/rejected from the standard?
(DIR) Post #AdToNVJ1npNBKr8opE by silverpill@mitra.social
2024-01-03T20:24:33.549073Z
0 likes, 0 repeats
@marcua FEPs? They are just proposals, and may never become standards. I can only say that the first FEP-ef61 implementation may appear somewhere in the middle of 2024.
(DIR) Post #AdTuhMyB6cx8zuFESO by mikedev@fediversity.site
2024-01-03T21:06:16Z
0 likes, 0 repeats
@silverpill Could you perhaps add an example of the Link header for inbox/outbox ?
(DIR) Post #AdTuhVLVxkNCybDywS by silverpill@mitra.social
2024-01-03T21:35:14.765766Z
0 likes, 0 repeats
@mikedev Yes, I'll add it.(And a number of other changes too. I've been collecting feedback and will publish an updated version soon)
(DIR) Post #AdUHxTDtv9O3yJFHBQ by bnewbold@social.coop
2024-01-03T23:32:49Z
0 likes, 0 repeats
@silverpill @marcua how would key rotation work with did:apkey (based on did:key)? not allowing for key rotation feels a bit brittle for a longer-term identity.
(DIR) Post #AdUHxUN9eENpXIaBFI by silverpill@mitra.social
2024-01-04T01:55:55.758363Z
0 likes, 0 repeats
@bnewbold @marcua did:apkey does not support key rotation. But other DID methods could be extended in the same way as did:keyFor example did:web -> did:apweb. The base DID method describes an identity, and "ap" extension describes how to access associated data via DID URLs
(DIR) Post #AdUZ1144Fosb1CvFya by silverpill@mitra.social
2024-01-04T05:07:25.114634Z
0 likes, 0 repeats
@mikedev Done: https://codeberg.org/fediverse/fep/pulls/224