Jenniferplusplus
trans lesbian
staff software engineer
devops, reliability, resilience, sociotechnical systems
also, that gay shit
Google, probably: I have made containers!
me: you've ruined a perfectly good process is what you've done. Look at it, it's got agoraphobia
@JessTheUnstill@infosec.exchange
This is an interesting idea, have you given thought to how it could be implemented? I was just looking at the spec, and that's going to make things challenging. It requires that persistent objects (like actors) have an ID that is a publicly dereferenceable URI under the authority of the origin server. Which is entirely understandable. And I think an awful lot of the rest of the spec rests on the assumption that you can dereference those IDs.
@hrefna@hachyderm.io @JessTheUnstill@infosec.exchange
If we could depend on people acting like adults, this wouldn't even be a concern 🙃
Of those options, the 3rd party identity/actor hosting seems the most viable. I think it requires the least coordinated change across federating software, and it doesn't require every single person to run their own internet infrastructure or do their own key/identity custody.
@hrefna@hachyderm.io @JessTheUnstill@infosec.exchange That would be great. Misbehaving admins is a threat that I would love to have some kind of answer to.
@JessTheUnstill@infosec.exchange DNS has the advantage of being an outside system.
But I suppose an independent webfinger service could work? Maybe? Webfinger also requires that the object belongs to the same authority as the webfinger service.
That's maybe a more solvable problem.
@jdp23@indieweb.social @thisismissem@hachyderm.io @hrefna@hachyderm.io Yeah, I haven't dug into the logic too deeply, but mastodon does decided whether to forward at least in part on some properties of the http signature.