Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 9 hours ago

If you're designing E2EE in 2026

And your expectation for the user experience is that even half your users will

  • manually verify key fingerprints, safety numbers, etc.
  • know what to do when these mechanisms fail

Then you have not been paying attention to the research at all!

That isn't the normal behavior for how we use software.

When's the last time someone you kmow that doesn't know what "TCP" is inspected a website's certificate before sending it their password?

  • Copy link
  • Flag this post
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 9 hours ago

This is a proposal for how to ensure keys aren't tampered with in group chats:

https://github.com/swicg/activitypub-e2ee/issues/43#issuecomment-3929554771

Some power users might find this useful, or even comforting.

This will not help Johnny encrypt. It demands perfect discipline and training from everyone at all times.

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 8 hours ago

I'm trying to solve this problem differently: https://publickey.directory

Key Transparency inverts the responsibility model. It ensures everyone has the same view of the relationships between Actors and Keys at every point in time.

It accomplishes this with an append only data structure.

If anyone is being disciplined or paranoid, and therefore witnessing updates, they can assure the entire protocol is being followed honestly. And most people need to take no action other than use the software normally to be secure.

If power users want to verify fingerprints on top of this, fine, I'm not here to kinkshame.

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 8 hours ago

If you don't meet people where they already are, and don't have billions to spend on experiential marketing to train them, you're setting yourself up for disappointment.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.32 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct