Important progress has been made regarding bringing MLS end-to-end encryption to the ActivityPub protocol, with developers already building implementations and providing feedback to a future version of the protocol spec.

  • iltg@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    34
    ·
    edit-2
    19 小时前

    this is misleading and sensationalistic. if emissary implements e2ee, it’s not “e2ee for the fediverse”, it’s " e2ee for emissary users". did mastodon talk about e2ee? did lemmy?

    also the MLS-in-activitypub draft proposes for trusted key exchange either " trust the server" (lmao), use a centralized key authority (wow) or have users manually verify their keys out of band (so basically use matrix to assure your chat is encrypted). source: https://swicg.github.io/activitypub-e2ee/architectural-variations.html#validating-end-to-end-encryption

    fedi devs need to stop clickbaiting, and fedi users should learn a bit more about their protocol to avoid getting misled this way

  • dhruv3006@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    1 天前

    We should always have more alternatives to chose from - good to see so many players.

  • 9tr6gyp3@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 天前

    MLS will eventually be included in all messengers.

    It was initially introduced by Wire as an RFC, but they fumbled the federation by making it an enterprise only feature. Because of that, other messengers will do the federating for them. iMessage, Google Messenger, Matrix, and Germ DM (Bluesky) do or partly have it implemented.

      • Rioting Pacifist@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        1 天前

        That’s not really going to be the case if you’re using a website instead of an audited app like signal/matrix.

          • Rioting Pacifist@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            1 天前

            Any we client including Matrix webclient is incredibly vulnerable to the server just injecting JS and reading your messages.

            Like there is no point of E2E encryption in Twitter, Musk can read your messages if you open them on any device he can execute arbitrary code on.

            • Jean-luc Peak-hard@piefed.social
              link
              fedilink
              English
              arrow-up
              2
              ·
              24 小时前

              Any we client including Matrix webclient is incredibly vulnerable to the server just injecting JS

              That doesn’t preclude fediverse clients from enabling E2EE. A web-client isn’t a requirement.

              Like there is no point of E2E encryption in Twitter, Musk can read your messages if you open them on any device he can execute arbitrary code on.

              Agreed, nobody should trust twitter, but I would trust most mastodon clients to send encrypted messages, if/when implemented correctly. Does it guarantee that messages will never be read? No, but it does an extra layer that wasn’t there before.

    • KNova@infosec.pub
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 天前

      One benefit is that Signal controls all the infrastructure and some people do not like that. Sure, you could also spin up a Matrix home server, but that isn’t an ideal solution for everyone either. Some people want to do messaging via their existing ActivityPub infrastructure and that’s OK.

    • Sean Tilley@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 天前

      So, I used messaging here in the broad sense. One possible application for it is instant messaging, which there are ActivityPub implementations out there doing that. But it can also be used for statuses or pretty much anything else that gets federated.

      • Rioting Pacifist@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 天前

        That actually sounds cool, I wonder if they could support Hidden containers, so the same message can be decypted to different messages by different users.

  • doug@lemmy.today
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    1 天前

    Finally I can discuss my scat fetish with my fellow scat enthusiasts away from the prying eyes of the NSA!

    Nyeh-heh heh heeh!