Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Holos Social
Holos Social
@HolosSocial@mastodon.social  ·  activity timestamp last week

End-to-end encrypted DMs through ActivityPub will be available in the next release #HolosSocial

3 media
Holos conversation with E2EE enabled. Blue banner shows "Messages are end-to-end encrypted" with lock icons on messages.
Holos conversation with E2EE enabled. Blue banner shows "Messages are end-to-end encrypted" with lock icons on messages.
Holos conversation with E2EE enabled. Blue banner shows "Messages are end-to-end encrypted" with lock icons on messages.
E2EE options menu showing "View safety number" and "Reset encryption session" actions available in encrypted conversations.
E2EE options menu showing "View safety number" and "Reset encryption session" actions available in encrypted conversations.
E2EE options menu showing "View safety number" and "Reset encryption session" actions available in encrypted conversations.
Holos conversation with Mastodon user. Gray banner shows "This user does not support encryption", demonstrating fallback to standard DMs.
Holos conversation with Mastodon user. Gray banner shows "This user does not support encryption", demonstrating fallback to standard DMs.
Holos conversation with Mastodon user. Gray banner shows "This user does not support encryption", demonstrating fallback to standard DMs.
  • Copy link
  • Flag this post
  • Block
GatoOscuro ⁂¯\_ (ツ) _/¯⁂
GatoOscuro ⁂¯\_ (ツ) _/¯⁂
@ElGatoOscuro@mastodon.social replied  ·  activity timestamp last week

@HolosSocial Sorprendente.

  • Copy link
  • Flag this comment
  • Block
Farshid Hakimy / فرشید
Farshid Hakimy / فرشید
@farshidhakimy@chaos.social replied  ·  activity timestamp last week

@HolosSocial is there any server with registration enabled?
It would be cool if I could try it out.

  • Copy link
  • Flag this comment
  • Block
Deus Figendi.jwd
Deus Figendi.jwd
@deusfigendi@troet.cafe replied  ·  activity timestamp last week

@HolosSocial

I tried to use PGP over ActivityPub (tbh: over Mastodon) but quickly ran into the length limit. Even with very short content, PGP encrypted messages are always longer then 500 chars.

But it worked if I put the encrypted message into the ALT-Text of one or more images.

To have this native would be nice but hard to implement in browser apps I think.

  • Copy link
  • Flag this comment
  • Block
Holos Social
Holos Social
@HolosSocial@mastodon.social replied  ·  activity timestamp last week

@deusfigendi
That's why Holos uses Signal Protocol instead of PGP. We store the encrypted data in a custom ActivityPub field (signalCiphertext), not in the content field which has length limits. The content just shows a placeholder text. This avoids character limits while maintaining compatibility with existing servers.

  • Copy link
  • Flag this comment
  • Block
🪨
🪨
@Varpie@peculiar.florist replied  ·  activity timestamp last week

@HolosSocial@mastodon.social @deusfigendi@troet.cafe Since the custom field will be useless if the recipient doesn't support it anyway, wouldn't it be better to just create a custom type, like SignalMessage or something, instead of an extension of Note?

  • Copy link
  • Flag this comment
  • Block
Holos Social
Holos Social
@HolosSocial@mastodon.social replied  ·  activity timestamp last week

@Varpie
You're right, a dedicated type would be cleaner. We started with a Note extension for immediate compatibility, but we're planning to propose an EncryptedNote type through a FEP. Both approaches can coexist during the transition period. ActivityPub is designed to evolve through community proposals, we should contribute to that evolution.
@deusfigendi

  • Copy link
  • Flag this comment
  • Block
Negative12DollarBill
Negative12DollarBill
@negative12dollarbill@techhub.social replied  ·  activity timestamp last week

@HolosSocial What's a safety number?

  • Copy link
  • Flag this comment
  • Block
Holos Social
Holos Social
@HolosSocial@mastodon.social replied  ·  activity timestamp last week

@negative12dollarbill
An optional security feature that lets you verify you're talking to the right person. Most users don't need this, your conversations are automatically encrypted and secure.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct