Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
prince lucija boosted
ls_phoenix
ls_phoenix
@ls_phoenix@infosec.exchange  ·  activity timestamp last week

Feminist Linux Meetups Vienna

4.2. Text wrangling with Vim
4.3. LaTeX hangout
1.4. Alternative input sources for computing
6.5. Intro to Cryptography
3.6. Soldering Workshop

https://feminist-linux.diebin.at/category/termine/

#vienna #wien #linux #floss #latex #soldering #vim #crypto #cryptography #flintA #austria #meetup #meetings #feminism #feminist

Termine | Feminist Linux Meetup für Frauen*, Non-Binary*, Trans* und Inter* Personen

  • Copy link
  • Flag this post
  • Block
@reiver ⊼ (Charles) :batman: and 1 other boosted
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

Cryptographic public-keys are one way that one can have an identity (on the Fediverse, and elsewhere) while also having privacy — through a pseudonymous identity.

Yes, we have Fediverse IDs such as:

@joeblow@example.com

But a (non-delegated) public-key can function as a PORTABLE form of identity on the Fediverse.

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this post
  • Block
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

Cryptographic public-keys are one way that one can have an identity (on the Fediverse, and elsewhere) while also having privacy — through a pseudonymous identity.

Yes, we have Fediverse IDs such as:

@joeblow@example.com

But a (non-delegated) public-key can function as a PORTABLE form of identity on the Fediverse.

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this post
  • Block
Inside Fediverse boosted
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

3/

All that requires that a Fediverse user can have multiple public-keys specified for them.

...

Although https://w3id.org/security/v1 seems to allow for multiple public-keys —

I wonder how much Fediverse software could actually handle multiple public-keys (rather than just one)?

(And, don't just assume one public-key?)

How mucg Fediverse software could handle public-keys changing over time?

Etc?

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this post
  • Block
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

2/

To handle public-key cryptography safely, often a user should be able to have multiple public-keys.

For example, a user might have a different public-key on each device, rather than sharing public-keys.

A user might delegate to a 3rd party — and there may be a delegated versus non-delegated public-key distinction.

Key-rotation is also often necessary for safety reasons.

Etc.

...

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social replied  ·  activity timestamp 21 hours ago

3/

All that requires that a Fediverse user can have multiple public-keys specified for them.

...

Although https://w3id.org/security/v1 seems to allow for multiple public-keys —

I wonder how much Fediverse software could actually handle multiple public-keys (rather than just one)?

(And, don't just assume one public-key?)

How mucg Fediverse software could handle public-keys changing over time?

Etc?

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this comment
  • Block
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

1/

One way ActivityPub can be extended is — through JSON-LD namespaces.

For example, many Fediverse servers use the following JSON-LD namespace to specify cryptographic public-key(s) for the user.

https://w3id.org/security/v1

(This particular namespace is an HTTPS URL.)

...

But, does extant Fediverse software support cryptographic public-key(s) well?

...

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social replied  ·  activity timestamp 21 hours ago

2/

To handle public-key cryptography safely, often a user should be able to have multiple public-keys.

For example, a user might have a different public-key on each device, rather than sharing public-keys.

A user might delegate to a 3rd party — and there may be a delegated versus non-delegated public-key distinction.

Key-rotation is also often necessary for safety reasons.

Etc.

...

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this comment
  • Block
Inside Fediverse boosted
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

1/

One way ActivityPub can be extended is — through JSON-LD namespaces.

For example, many Fediverse servers use the following JSON-LD namespace to specify cryptographic public-key(s) for the user.

https://w3id.org/security/v1

(This particular namespace is an HTTPS URL.)

...

But, does extant Fediverse software support cryptographic public-key(s) well?

...

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this post
  • Block
@reiver ⊼ (Charles) :batman:
@reiver ⊼ (Charles) :batman:
@reiver@mastodon.social  ·  activity timestamp 21 hours ago

1/

One way ActivityPub can be extended is — through JSON-LD namespaces.

For example, many Fediverse servers use the following JSON-LD namespace to specify cryptographic public-key(s) for the user.

https://w3id.org/security/v1

(This particular namespace is an HTTPS URL.)

...

But, does extant Fediverse software support cryptographic public-key(s) well?

...

#ActivityPub #Cryptography #Fedidev #Fedidevs #Fediverse #JSONLD

  • Copy link
  • Flag this post
  • Block
Larvitz :fedora: :redhat:
Larvitz :fedora: :redhat:
@Larvitz@burningboard.net  ·  activity timestamp 7 days ago

What a project. Did configure StepCA in my home-lab with a real physical HSM for the CA's private key. Using a SmartcardHSM (https://www.smartcard-hsm.com) from CardContact Systems.

Now I have acme (automated cert provisioning) working internally as long as the HSM is plugged into my server.

All running in an isolated FreeBSD 15-RELEASE jail.

Yay! It works!

#freebsd #stepca #devops #acme #certificates #tls #smartcard #hsm

3 media
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sam Lehman :nixos:
Sam Lehman :nixos:
@Lehmanator@fosstodon.org replied  ·  activity timestamp 7 days ago

@Larvitz How is Step CA? Are you coming from another CA solution?

Been thinking about running #stepca in my #kubernetes cluster, but have been apprehensive because of how many features seem to be gated behind smallstep's proprietary version. Would love to have this integrated with #certmanager and using the #tpm on my nodes. Was going to do a rearchitecting of my entire #auth and #cryptography stack when I switch from the deprecated #Ingress API to the #GatewayAPI

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Code of Conduct