Re: Major Security Issue with AP: Server-Stored Private Keys in ActivityPub

On Tue, 15 Apr 2025 14:11:43 +0200
Melvin Carvalho <melvincarvalho@gmail.com> wrote:

> Your identity model breakdown is helpful:
> - Server owns identity — Facebook, ActivityPub
> - Server owns identity with exit option — Bluesky, Mastodon?
> - User owns identity — Matrix, Nostr

let me bring another take to the table:

- User owns Server (owns identity) - #Seppo

A web of emancipated participants. Think of indieweb without devops duties. If you think that's infeasible/utopian, I'd love to discuss the fosdem presentation https://mro.name/offdem/slides.pdf. I second however, that it was rarely tried. Hell, that would decentralise the internet!

The discussion about keys is all about expectations. With the AP implementations, keys are not for the end users, sadly. They are there for server hygiene. (Maybe they shouldn't even be personal and in fact they aren't.) So the server holds them, not the user. Just like the account deletion button. And who decides deletion ultimately owns. (So I challenge the matrix 'user own identity' slogan for most users.)

Cheers,
Marcus

Received on Tuesday, 15 April 2025 13:09:52 UTC