Skip to content
  • Kategorien
  • Aktuell
  • Tags
  • Beliebt
  • World
  • Benutzer
  • Gruppen
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Standard: (Kein Skin)
  • Kein Skin
Einklappen

other.li Forum

  1. Übersicht
  2. Uncategorized
  3. Have you seen this news?

Have you seen this news?

Geplant Angeheftet Gesperrt Verschoben Uncategorized
mastodonfediversee2ee
61 Beiträge 26 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • ? Gast

    @dusk
    @benpate

    Signal and similar tools tightly control trust models (trusted by default with centralized keys and safety number/verification UX), while federated SNS would have to pick between a similar central authority or a more fragile, user‑managed web‑of‑trust‑style setup.

    ? Offline
    ? Offline
    Gast
    schrieb zuletzt editiert von
    #51

    @dusk
    @benpate

    To introduce E2EE into public‑facing SNS & simultaneously try to “solve” abuse, moderation, & legal exposure, the path of least resistance is likely to be “just verify everyone”, pushing identity‑linked, KYC‑style identity checks as a way to “anchor” trust & accountability.

    The loudest voices may start demanding identity verification.

    Awful for privacy, & it’s exactly why I strongly believe E2EE should be kept out of the core social layer & kept within dedicated tools instead.

    1 Antwort Letzte Antwort
    0
    • ? Gast

      @benpate did you hear that Mastodon’s next version implemented Activity Intents, as well? Things keep getting better!

      ? Offline
      ? Offline
      Gast
      schrieb zuletzt editiert von
      #52

      @andypiper Activity Intents, abbreviated as AI?

      1 Antwort Letzte Antwort
      0
      • ? Gast

        @dusk
        @benpate

        Signal and similar tools tightly control trust models (trusted by default with centralized keys and safety number/verification UX), while federated SNS would have to pick between a similar central authority or a more fragile, user‑managed web‑of‑trust‑style setup.

        ? Offline
        ? Offline
        Gast
        schrieb zuletzt editiert von
        #53
        @rusty__shackleford @dusk @benpate dealing with spam (and other forms of abuse) when e2ee is mixed with federated SNS seems really hard. agree 100% with your assessment
        ? ? 2 Antworten Letzte Antwort
        0
        • ? Gast
          @rusty__shackleford @dusk @benpate dealing with spam (and other forms of abuse) when e2ee is mixed with federated SNS seems really hard. agree 100% with your assessment
          ? Offline
          ? Offline
          Gast
          schrieb zuletzt editiert von
          #54

          @sampler @benpate @dusk

          I'm going to do a more succinct write up of this to share.

          ? ? 2 Antworten Letzte Antwort
          0
          • ? Gast

            Have you seen this news?

            #Mastodon just got funding to add end to end encryption into their software.

            So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

            Im so excited about this.

            Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

            Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

            #E2EE

            https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

            ? Offline
            ? Offline
            Gast
            schrieb zuletzt editiert von
            #55

            @benpate

            Interesting times ahead. I wonder if they will go for the Signal Protocol Post-Quantum Ratchets or similar? 🙂

            ? 1 Antwort Letzte Antwort
            0
            • ? Gast

              @sampler @benpate @dusk

              I'm going to do a more succinct write up of this to share.

              ? Offline
              ? Offline
              Gast
              schrieb zuletzt editiert von
              #56
              @rusty__shackleford @benpate @dusk i think a good middle ground for letting people to have private discussions on fediverse is just allowing people to do PGP themselves or in 3rd party clients, with a "buyer beware" kind of scenario

              building it into servers puts a lot more responsibility in the hands of server admins. and risk for abuse. i don't want my admin holding onto my private keys and i don't necessarily trust my server to generate keys for me either ...

              people with the know-how to generate and manage their own keys can deal with the potential negatives and headaches associated with it. just running servers as they already exist is plenty of work for mastodon admins i would imagine
              ? 1 Antwort Letzte Antwort
              0
              • ? Gast

                @benpate

                Interesting times ahead. I wonder if they will go for the Signal Protocol Post-Quantum Ratchets or similar? 🙂

                ? Offline
                ? Offline
                Gast
                schrieb zuletzt editiert von
                #57

                @simonzerafa

                Not Signal, MLS, which is similar but run by a group of industry organizations.

                Post-quantum is possible in MlS, depending on the crypto algorithms you choose.

                There’s more info about the project in general on https://emissary.dev/e2ee — though Mastodons announcement is a big new development I haven’t covered yet.

                1 Antwort Letzte Antwort
                0
                • ? Gast
                  @rusty__shackleford @benpate @dusk i think a good middle ground for letting people to have private discussions on fediverse is just allowing people to do PGP themselves or in 3rd party clients, with a "buyer beware" kind of scenario

                  building it into servers puts a lot more responsibility in the hands of server admins. and risk for abuse. i don't want my admin holding onto my private keys and i don't necessarily trust my server to generate keys for me either ...

                  people with the know-how to generate and manage their own keys can deal with the potential negatives and headaches associated with it. just running servers as they already exist is plenty of work for mastodon admins i would imagine
                  ? Offline
                  ? Offline
                  Gast
                  schrieb zuletzt editiert von
                  #58

                  @sampler @rusty__shackleford @dusk

                  A) that excludes 99% of the population, who deserve the same level of privacy as you do.

                  B) since it’s E2EE, most of the work is on your client. The updates to the server are minimal (C2S API + publish public key packages). So EVERY Fediverse server could support this. You’d just need a client that can send/receive encrypted messages.

                  C) Don’t let “perfect” be the enemy of “good” - giving people easy, modern tools is a win, even if the NSA can hack it.

                  1 Antwort Letzte Antwort
                  0
                  • ? Gast

                    @sampler @benpate @dusk

                    I'm going to do a more succinct write up of this to share.

                    ? Offline
                    ? Offline
                    Gast
                    schrieb zuletzt editiert von
                    #59

                    @rusty__shackleford @sampler @benpate

                    Really well articulated, totally makes sense! 🙌

                    1 Antwort Letzte Antwort
                    0
                    • ? Gast
                      @rusty__shackleford @dusk @benpate dealing with spam (and other forms of abuse) when e2ee is mixed with federated SNS seems really hard. agree 100% with your assessment
                      ? Offline
                      ? Offline
                      Gast
                      schrieb zuletzt editiert von
                      #60

                      @sampler @rusty__shackleford @dusk

                      That is one of Mastodon’s big issues to address. It’s not a protocol thing, but a server software issue that I know they’re going to address.

                      1 Antwort Letzte Antwort
                      0
                      • ? Gast

                        @benpate I'm wondering what the advantage of e2ee private messages on Mastodon is when we have Signal, Matrix and other robust encrypted messaging tools that you could invite a friend to if you want to have a private conversation.

                        Is anyone worried about this creating moderation issues?

                        Generally I'm in favor of privacy and security, but I'm just not sure what the value of this feature is on Mastodon. Maybe you or others can provide your perspective on this.

                        ? Offline
                        ? Offline
                        Gast
                        schrieb zuletzt editiert von
                        #61

                        @earth_walker @benpate

                        If people are already on Signal, good for them. But the real issue is getting people off the Meta apps. So if there's a good Fedi Messenger, that can definitely help!
                        😊👍

                        1 Antwort Letzte Antwort
                        0
                        • monkee@chaos.socialM monkee@chaos.social shared this topic
                        Antworten
                        • In einem neuen Thema antworten
                        Anmelden zum Antworten
                        • Älteste zuerst
                        • Neuste zuerst
                        • Meiste Stimmen


                        • Anmelden

                        • Anmelden oder registrieren, um zu suchen
                        • Erster Beitrag
                          Letzter Beitrag
                        0
                        • Kategorien
                        • Aktuell
                        • Tags
                        • Beliebt
                        • World
                        • Benutzer
                        • Gruppen