soatok / mastodon-e2ee-specification

Soatok's Proposal for End-to-End Encryption in Mastodon
https://soatok.blog/2022/11/22/towards-end-to-end-encryption-for-direct-messages-in-the-fediverse/
GNU Affero General Public License v3.0
206 stars 4 forks source link

Suggestion (most likely premature): Use unlisted toots and account attributes #2

Open kyanha opened 1 year ago

kyanha commented 1 year ago

I would like to suggest using unlisted toots to contain the appropriate data for remote users to establish e2ee sessions, replies to those toots to maintain updates (and to provide metadata for what key signs the new key for key continuity), and the use of one account attribute to provide a URL to the toot containing the root of the key continuity chain.

Since this is almost certainly premature as a suggestion (and offered by someone who has only the barest idea of Mastodon's privacy levels), I rather expect that this idea will get either summarily roundfiled, or put on the back burner until someone gets around to tearing holes in it. Still, it seems that it would be useful to do something like keybase did, albeit without forcing the key/account-claim data into everybody's feed.