I was struggling to wrap my head around how federated social media works until I realized that email has basically been doing the same thing for 30 years. Different email servers are like instances of a federated network. You can send emails to people from within a single server or you can send emails to people on any other mail server. Your email address is a username followed by an ‘@’ and the server address, just like on Lemmy. Email is a decentralized service I’ve been using the whole time!

  • jmp242
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    The nominal answer to that was PKI, i.e. TLS (and maybe SMIME). But that’s just a different shitshow.

    The other challenge is IMHO there’s two kinds of tasks here that are related but not the same.

    One situation is for stuff like most e-mail and posts online etc. You don’t care or need a strong identity guarantee, you just need to be able to say ID1 from yesterday is strongly confirmed to be ID1 today. For things you make first contact and only contact online - this is really all you need, along with the privacy of the content. Stuff like PGP and SSH do this just fine. Self Signed TLS certs do too, except for browsers somehow treating them as worse than unencrypted.

    The other is where you do want a strong identity verification. This is where TLS how most people use it works, except it’s a false sense of verification. People want something like a Government ID - so you KNOW Amazon is Amazon verified by a trusted third party. But this sadly isn’t how the certificate authorities actually work, and now it’s considered so hard to take care of your keys that a certificate lasting more than a year (pushing for 90 days) is “too big a risk”. Imagine any other ID you had to renew every 3 months! It clearly doesn’t work, and only continues IMHO because it’s how the web ended up working. But in actual practice IMHO - you basically get the same thing you would have from option 1 for most people. It’s not like there’s an enforced standard or anything for the CAs, it’s just can you pay. And with LetsEncrypt for those 90 day renewals there’s not even payment so it really might as well be just telling you it’s encrypted and forget about the identity alltogether.