this post was submitted on 26 Jan 2024
1 points (100.0% liked)

Fediverse

17735 readers
3 users here now

A community dedicated to fediverse news and discussion.

Fediverse is a portmanteau of "federation" and "universe".

Getting started on Fediverse;

founded 5 years ago
MODERATORS
 

Is decentralised federated social media over engineered?

Can't get this brain fart out of my head.

What would the simplest, FOSS, alternative look like and would it be worth it?

Quick thoughts:

* FOSS platforms intended to be big single servers, but dedicated to ...
* Shared/Single Sign On
* Easy cross posting
* Enabling and building universal Multi-platform clients.
* Unlike email, supporting small servers

No duplication/federation/protocol required, just software.

#fediverse
@fediverse

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 0 points 9 months ago (7 children)

@maegul How would servers share accounts and passwords? Allowing any server to know what a user’s password should be is not very good for security.

@fediverse @maegul @1984 @mindlight

[–] [email protected] 0 points 9 months ago (2 children)

@Aatube @[email protected] @1984 @mindlight @[email protected]
Couldn't it be like public-private keys such PGP protocols, where the users have the private key and the platforms have the public key? It's seems quite good privacy, some would even say it's "pretty good privacy".

[–] [email protected] 0 points 9 months ago (1 children)

@Sean Nice pun :D

I don’t think requiring users to use a really long and virtually unmemorizable password (the private key) would be a pretty good idea for a social network either.

@fediverse @maegul @1984 @mindlight @maegul

[–] [email protected] 0 points 9 months ago

@Aatube @[email protected] @1984 @mindlight @[email protected]
The private key doesn't need to be memorized, it stays saved on the device that the client software is on, allowing the user to integrate mobile device's biometric reader (fingerprint/face/iris/whatever) to confirm identity, or use security key, there are already different ways to implement it that doesn't require pw memorization.

I've got a long unmemorizable string for Firefox sync, Brave, Proton Mail/Pass, it's still more secure than pw memorized

load more comments (4 replies)