๐Ÿ’พ Archived View for bbs.geminispace.org โ€บ s โ€บ Gemini โ€บ 1729 captured on 2023-07-10 at 13:47:58. Gemini links have been rewritten to link to archived content

View Raw

More Information

โฌ…๏ธ Previous capture (2023-06-16)

โžก๏ธ Next capture (2023-07-22)

๐Ÿšง View Differences

-=-=-=-=-=-=-

How does one verify someone's identity is what they claim to be?

Basically, if someone else would make new identity after my name, how one could know it's not, well, me?

Like for PGP there is keyoxide.

https://keyoxide.org/akselmo%40akselmo.dev

Is there something similar for geminispace?

I assume one could add a fingerprint of their identity to their own site?

Posted in: s/Gemini

๐ŸฆŽ Akselmo

2023-06-09 ยท 4 weeks ago

6 Comments โ†“

๐Ÿš€ skyjake

There is nothing comparable to keyoxide on Gemini.

โ€” Hence this discussion...

There are manual ways to provide some assurance, like:

๐Ÿš€ skyjake

I assume one could add a fingerprint of their identity to their own site?

A client certificate fingerprint that is corroborated from a secondary source might help a server verify your identity, but it's of limited use to other people, since you're not sending your certificate to them, only privately to the server.

๐ŸฆŽ Akselmo

I see, thanks. Two way links seem the way to go. Also my cert is from letsencrypt, and Keyoxide shows it as mine as well.

๐Ÿš€ jsreed5

For what it's worth, I use one client certificate everywhere, and I publish the SHA1 and SHA256 fingerprints of that certificate on my capsule. Unfortunately this is only useful to those who can see details about my certificate--which in practice is almost exclusively capsule operators. I think it would be handy if more capsules publicly displayed user certificate fingerprints (or gave the option to do so).

โ˜•๏ธ Morgan

@jsreed5

Yes, that's the biggest missing piece I think.

2023-06-10 ยท 4 weeks ago

๐Ÿš€ stack

Client certificates and TOFU are pretty much pointless as far as security or authentication goes (although makes it a tiny bit easier to track a session for a game, or lock up some resource only you yourself can see).