Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Chiaro
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Scuro
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Cerulean)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Fediverso
  4. Have you seen this news?

Have you seen this news?

Pianificato Fissato Bloccato Spostato Fediverso
mastodonfediversee2ee
185 Post 56 Autori 6 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Risposta alla discussione
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • earth_walker@mindly.socialundefined earth_walker@mindly.social

    @benpate I'm wondering what the advantage of e2ee private messages on Mastodon is when we have Signal, Matrix and other robust encrypted messaging tools that you could invite a friend to if you want to have a private conversation.

    Is anyone worried about this creating moderation issues?

    Generally I'm in favor of privacy and security, but I'm just not sure what the value of this feature is on Mastodon. Maybe you or others can provide your perspective on this.

    ovoao@mastodon.socialundefined Questo utente è esterno a questo forum
    ovoao@mastodon.socialundefined Questo utente è esterno a questo forum
    ovoao@mastodon.social
    scritto su ultima modifica di
    #61

    @earth_walker @benpate

    If people are already on Signal, good for them. But the real issue is getting people off the Meta apps. So if there's a good Fedi Messenger, that can definitely help!
    😊👍

    1 Risposta Ultima Risposta
    0
    • benpate@mastodon.socialundefined benpate@mastodon.social

      Have you seen this news?

      #Mastodon just got funding to add end to end encryption into their software.

      So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

      Im so excited about this.

      Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

      Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

      #E2EE

      https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

      kaifi@pitha.socialundefined Questo utente è esterno a questo forum
      kaifi@pitha.socialundefined Questo utente è esterno a questo forum
      kaifi@pitha.social
      scritto su ultima modifica di
      #62

      RE: https://mastodon.social/@benpate/116403046724832335

      @benpate super stoked!!!

      1 Risposta Ultima Risposta
      0
      • evan@cosocial.caundefined evan@cosocial.ca

        @earth_walker @benpate

        It's not either-or. You can use both.

        If you prefer to switch apps and identities and go over to Signal, awesome.

        If you'd rather message someone with your ActivityPub identity, you can do that securely now, too.

        The E2EE work on ActivityPub uses an open standard, MLS, to encrypt data. One reason we chose it was so it's at least possible to bridge to other social and messaging networks while keeping the data encrypted from end to end.

        earth_walker@mindly.socialundefined Questo utente è esterno a questo forum
        earth_walker@mindly.socialundefined Questo utente è esterno a questo forum
        earth_walker@mindly.social
        scritto su ultima modifica di
        #63

        @evan @benpate that makes sense :)

        1 Risposta Ultima Risposta
        0
        • benpate@mastodon.socialundefined benpate@mastodon.social

          Have you seen this news?

          #Mastodon just got funding to add end to end encryption into their software.

          So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

          Im so excited about this.

          Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

          Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

          #E2EE

          https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

          groupnebula563@mastodon.socialundefined Questo utente è esterno a questo forum
          groupnebula563@mastodon.socialundefined Questo utente è esterno a questo forum
          groupnebula563@mastodon.social
          scritto su ultima modifica di
          #64

          @benpate how long do we wanna bet it takes for @soatok to find a crippling encryption flaw /j

          bluewinds@tech.lgbtundefined benpate@mastodon.socialundefined 2 Risposte Ultima Risposta
          0
          • benpate@mastodon.socialundefined benpate@mastodon.social

            Have you seen this news?

            #Mastodon just got funding to add end to end encryption into their software.

            So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

            Im so excited about this.

            Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

            Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

            #E2EE

            https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

            quantillion@mstdn.ioundefined Questo utente è esterno a questo forum
            quantillion@mstdn.ioundefined Questo utente è esterno a questo forum
            quantillion@mstdn.io
            scritto su ultima modifica di
            #65

            @benpate
            Ideas for how I explain this to my swaths of very-non-tech friends & family? (Most of whom are happy with FB & Insta & Wassap.)

            benpate@mastodon.socialundefined 1 Risposta Ultima Risposta
            0
            • groupnebula563@mastodon.socialundefined groupnebula563@mastodon.social

              @benpate how long do we wanna bet it takes for @soatok to find a crippling encryption flaw /j

              bluewinds@tech.lgbtundefined Questo utente è esterno a questo forum
              bluewinds@tech.lgbtundefined Questo utente è esterno a questo forum
              bluewinds@tech.lgbt
              scritto su ultima modifica di
              #66

              @GroupNebula563 @benpate @soatok "How are they managing public keys" was my very first question, inspired by our own furry blogger's work on the subject! 🦊

              benpate@mastodon.socialundefined 1 Risposta Ultima Risposta
              0
              • benpate@mastodon.socialundefined benpate@mastodon.social

                Have you seen this news?

                #Mastodon just got funding to add end to end encryption into their software.

                So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

                Im so excited about this.

                Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

                Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

                #E2EE

                https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

                bookstardust@bildung.socialundefined Questo utente è esterno a questo forum
                bookstardust@bildung.socialundefined Questo utente è esterno a questo forum
                bookstardust@bildung.social
                scritto su ultima modifica di
                #67

                @benpate 🥳🥳🥳
                Relevant!

                1 Risposta Ultima Risposta
                0
                • benpate@mastodon.socialundefined benpate@mastodon.social

                  Have you seen this news?

                  #Mastodon just got funding to add end to end encryption into their software.

                  So, some time next year, you’ll be able to send truly private messages to the vast majority of the #Fediverse

                  Im so excited about this.

                  Because it’s an open spec, this opens the doors for every Fediverse app to join the party.

                  Yesterday, this project was a proof of concept. Today, Mastodon has turned it into a stampede.

                  #E2EE

                  https://blog.joinmastodon.org/2026/04/sovereign-tech-agency-funding/

                  jaz@toot.walesundefined Questo utente è esterno a questo forum
                  jaz@toot.walesundefined Questo utente è esterno a questo forum
                  jaz@toot.wales
                  scritto su ultima modifica di
                  #68

                  @benpate

                  OK, I'll say it out loud.

                  If it ships and I'm unable to turn it off, I will have to stop being a Mastodon service provider.

                  Do I use E2EE platforms? Absolutely yes.

                  Do I want to be in the business of operating one? Absolutely no.

                  Please ensure this is an optional feature for service providers, especially those in well-regulated markets that will immediately become subject to a swath of additional responsibilities, risk, and legal liabilities.

                  benpate@mastodon.socialundefined 1 Risposta Ultima Risposta
                  0
                  • bluewinds@tech.lgbtundefined bluewinds@tech.lgbt

                    @GroupNebula563 @benpate @soatok "How are they managing public keys" was my very first question, inspired by our own furry blogger's work on the subject! 🦊

                    benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                    benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                    benpate@mastodon.social
                    scritto su ultima modifica di
                    #69

                    It’s using “MLS” - a well documented, tested, and tooled protocol.

                    Private keys are generated on your device (browser, app, whatever). Each device manages its own private keys.

                    Public keys are posted to your ActivityPub actor profile.

                    Keys are rotated *very* frequently.. like every time you join a new group.

                    When someone sends you a message, they address your ActivityPub inbox using a “group key” that includes all of your devices.

                    @bluewinds @GroupNebula563 @soatok

                    benpate@mastodon.socialundefined 1 Risposta Ultima Risposta
                    0
                    • jaz@toot.walesundefined jaz@toot.wales

                      @benpate

                      OK, I'll say it out loud.

                      If it ships and I'm unable to turn it off, I will have to stop being a Mastodon service provider.

                      Do I use E2EE platforms? Absolutely yes.

                      Do I want to be in the business of operating one? Absolutely no.

                      Please ensure this is an optional feature for service providers, especially those in well-regulated markets that will immediately become subject to a swath of additional responsibilities, risk, and legal liabilities.

                      benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                      benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                      benpate@mastodon.social
                      scritto su ultima modifica di
                      #70

                      @jaz I agree 100%

                      It’s too early for anyone to say how Mastodon will design this (even Mastodon)

                      But this is exactly how I’m doing it in Emissary. Domain owners can choose if they want to support E2EE on their server, and for which groups of users.

                      Users can also opt in to publishing encryption keys or not.

                      It’s easy to build this as completely opt-in, so it’s a fair bet that’s how mastodon will architect it.

                      Make sure they hear your voice as the project gets going in 2027.

                      jaz@toot.walesundefined 1 Risposta Ultima Risposta
                      0
                      • benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                        benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                        benpate@mastodon.social
                        scritto su ultima modifica di
                        #71

                        @hiker

                        Yes. While it’s possible to have encrypted “public” discussions, it makes no sense to me and I don’t know why anyone would do that.

                        This is exclusively for real private messages (not just “direct” messages)

                        1 Risposta Ultima Risposta
                        0
                        • benpate@mastodon.socialundefined benpate@mastodon.social

                          @jaz I agree 100%

                          It’s too early for anyone to say how Mastodon will design this (even Mastodon)

                          But this is exactly how I’m doing it in Emissary. Domain owners can choose if they want to support E2EE on their server, and for which groups of users.

                          Users can also opt in to publishing encryption keys or not.

                          It’s easy to build this as completely opt-in, so it’s a fair bet that’s how mastodon will architect it.

                          Make sure they hear your voice as the project gets going in 2027.

                          jaz@toot.walesundefined Questo utente è esterno a questo forum
                          jaz@toot.walesundefined Questo utente è esterno a questo forum
                          jaz@toot.wales
                          scritto su ultima modifica di
                          #72

                          @benpate

                          >But this is exactly how I’m doing it in Emissary. Domain owners can choose if they want to support E2EE on their server, and for which groups of users.

                          Tidy, cheers.

                          1 Risposta Ultima Risposta
                          0
                          • benpate@mastodon.socialundefined benpate@mastodon.social

                            It’s using “MLS” - a well documented, tested, and tooled protocol.

                            Private keys are generated on your device (browser, app, whatever). Each device manages its own private keys.

                            Public keys are posted to your ActivityPub actor profile.

                            Keys are rotated *very* frequently.. like every time you join a new group.

                            When someone sends you a message, they address your ActivityPub inbox using a “group key” that includes all of your devices.

                            @bluewinds @GroupNebula563 @soatok

                            benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                            benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                            benpate@mastodon.social
                            scritto su ultima modifica di
                            #73

                            Also, we’ve chatted with @soatok abiut this project. They recommended a different management structure, using separate network of key authentication servers.

                            That’s not off the table, but is more than we can manage right not. It could be another way for us to validate keys in the future.

                            @bluewinds @GroupNebula563 @soatok

                            soatok@furry.engineerundefined 1 Risposta Ultima Risposta
                            0
                            • earth_walker@mindly.socialundefined earth_walker@mindly.social

                              @benpate I'm wondering what the advantage of e2ee private messages on Mastodon is when we have Signal, Matrix and other robust encrypted messaging tools that you could invite a friend to if you want to have a private conversation.

                              Is anyone worried about this creating moderation issues?

                              Generally I'm in favor of privacy and security, but I'm just not sure what the value of this feature is on Mastodon. Maybe you or others can provide your perspective on this.

                              ohmu@social.seattle.wa.usundefined Questo utente è esterno a questo forum
                              ohmu@social.seattle.wa.usundefined Questo utente è esterno a questo forum
                              ohmu@social.seattle.wa.us
                              scritto su ultima modifica di
                              #74

                              @earth_walker @benpate
                              Yes.
                              The very first thing that occurred to me reading this was: "Hmm. Adding E2EE without first implementing the long requested tools to make it less easy to harass people is going to potentially make moderation more challenging and Mastodon more unsafe than it is."

                              1 Risposta Ultima Risposta
                              0
                              • groupnebula563@mastodon.socialundefined groupnebula563@mastodon.social

                                @benpate how long do we wanna bet it takes for @soatok to find a crippling encryption flaw /j

                                benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                                benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                                benpate@mastodon.social
                                scritto su ultima modifica di
                                #75

                                I would love for that to happen. As soon as I can make a public beta server, you’re all welcome to come and break my code. I’ll pass out treats.

                                @GroupNebula563 @soatok

                                1 Risposta Ultima Risposta
                                0
                                • quantillion@mstdn.ioundefined quantillion@mstdn.io

                                  @benpate
                                  Ideas for how I explain this to my swaths of very-non-tech friends & family? (Most of whom are happy with FB & Insta & Wassap.)

                                  benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                                  benpate@mastodon.socialundefined Questo utente è esterno a questo forum
                                  benpate@mastodon.social
                                  scritto su ultima modifica di
                                  #76

                                  @Quantillion

                                  1. “I left Instagram, so this is how you contact me now…”

                                  2. FB paid a billion dollars for WhatsApp. They wouldn’t do that if they couldn’t use it to profile you. Even if the messages are encrypted.

                                  3. E2EE is being removed from Instagram in a few weeks. Besides, Instagram is creepy and addictive. You can still trade pics on the Fediverse, so…

                                  1 Risposta Ultima Risposta
                                  0
                                  • benpate@mastodon.socialundefined benpate@mastodon.social

                                    Also, we’ve chatted with @soatok abiut this project. They recommended a different management structure, using separate network of key authentication servers.

                                    That’s not off the table, but is more than we can manage right not. It could be another way for us to validate keys in the future.

                                    @bluewinds @GroupNebula563 @soatok

                                    soatok@furry.engineerundefined Questo utente è esterno a questo forum
                                    soatok@furry.engineerundefined Questo utente è esterno a questo forum
                                    soatok@furry.engineer
                                    scritto su ultima modifica di
                                    #77

                                    @benpate @bluewinds @GroupNebula563 I think you're confused.

                                    The public keys that are rotated frequently are encryption public keys.

                                    The thing I've proposed are for identity public keys.

                                    Using your identity secret key to sign each encryption public key, and having your recipient verify them, is basically a one-liner:

                                    https://github.com/swicg/activitypub-e2ee/issues/35#issuecomment-3738855995

                                    benpate@mastodon.socialundefined 1 Risposta Ultima Risposta
                                    0
                                    • andypiper@macaw.socialundefined andypiper@macaw.social

                                      @benpate did you hear that Mastodon’s next version implemented Activity Intents, as well? Things keep getting better!

                                      adamhotep@infosec.exchangeundefined Questo utente è esterno a questo forum
                                      adamhotep@infosec.exchangeundefined Questo utente è esterno a questo forum
                                      adamhotep@infosec.exchange
                                      scritto su ultima modifica di
                                      #78

                                      @andypiper @benpate there's no mention (yet?) of this in the ticket (that @benpate opened) at https://github.com/mastodon/mastodon/issues/33984

                                      andypiper@macaw.socialundefined 1 Risposta Ultima Risposta
                                      0
                                      • benpate@mastodon.socialundefined benpate@mastodon.social

                                        @earth_walker

                                        I don’t have all the answers, but I believe there’s a network effect at work.

                                        Signal is fantastic. I use it for lots of things. But it’s “yet another” place to go.

                                        But the Fediverse is my primary place to talk with people (like you)

                                        If you and I could have a truly private follow-on discussion without switching networks, it would be a win for the Fediverse.

                                        jaz@toot.walesundefined Questo utente è esterno a questo forum
                                        jaz@toot.walesundefined Questo utente è esterno a questo forum
                                        jaz@toot.wales
                                        scritto su ultima modifica di
                                        #79

                                        @benpate @earth_walker

                                        Signal also has 50 employees and money in the bank to pay the lawyers.

                                        benpate@mastodon.socialundefined reflex@retrogaming.socialundefined 2 Risposte Ultima Risposta
                                        0
                                        • adamhotep@infosec.exchangeundefined adamhotep@infosec.exchange

                                          @andypiper @benpate there's no mention (yet?) of this in the ticket (that @benpate opened) at https://github.com/mastodon/mastodon/issues/33984

                                          andypiper@macaw.socialundefined Questo utente è esterno a questo forum
                                          andypiper@macaw.socialundefined Questo utente è esterno a questo forum
                                          andypiper@macaw.social
                                          scritto su ultima modifica di
                                          #80

                                          @adamhotep @benpate thanks for the pointer! We should fix that and link it to the PRs mentioned in Trunk & Tidbits this month… 😧

                                          1 Risposta Ultima Risposta
                                          0

                                          Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.

                                          Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.

                                          Con il tuo contributo, questo post potrebbe essere ancora migliore 💗

                                          Registrati Accedi
                                          Rispondi
                                          • Risposta alla discussione
                                          Effettua l'accesso per rispondere
                                          • Da Vecchi a Nuovi
                                          • Da Nuovi a Vecchi
                                          • Più Voti


                                          • 1
                                          • 2
                                          • 3
                                          • 4
                                          • 5
                                          • 6
                                          • 9
                                          • 10
                                          Feed RSS
                                          Have you seen this news?
                                          @pierobosio@soc.bosio.info
                                          V4.10.1 Contributors
                                          • Accedi

                                          • Accedi o registrati per effettuare la ricerca.
                                          • Primo post
                                            Ultimo post