Re: Show: blog about http signatures

Hi perillamint.

meanwhile https://social.coop/@django/113278730846217623 nailed it for me saying:

"When a certain implementor wasn't convinced of its necessity I forged a message from their own account 🥸

https://mediaformat.org/2023/10/signature-verification-in-wordpress/"

And Evan elaborated on why TLS being capable in principle may not practical. https://lists.w3.org/Archives/Public/public-swicg/2024Oct/0013.html

Who could put this into implementors notes or amend https://swicg.github.io/activitypub-http-signature/?

On Wed, 9 Oct 2024 05:53:39 +0900 (GMT+09:00)
perillamint <perillamint@silicon.moe> wrote:

> > P.S.: attacker M, what a coincidence, lol.
> 
> Uhh, actually, I intended A(lice), B(ob) and M(allory or any Malicious word) in there. Sorry if you were offended.

Sad you think so. On the contrary, I had a good laugh! (The lol was real)

/Marcus

Received on Thursday, 10 October 2024 07:25:31 UTC