Natanji ‏✅ is a user on awoo.space. You can follow them or interact with them if you have an account anywhere in the fediverse.

Mastodon's federation introduces UX challenges.

One that worries me a lot is about message forgery. Anyone can forge a twoot, even cross-server.

Whereas Twitter Inc might be trustworthy enough to not forge transcripts. Anyone can run a Mastodon server and might want to abuse it to influence people (see Russian troll campaigns).

Should Mastodon "home servers" cryptographically sign updates? Should there be end-to-end signatures? Anyone has thoughts on this?

Natanji ‏✅ @natanji

@fj In what way can forgery happen? Can you elaborate on that? The way I understood it, another server could make another account called @natanji, but it would be natanji@someother.server and this would clearly be shown when the toot is distributed in the network?

· Web · 0 · 0