If some account claiming to be me cannot do that, it's an obvious fake.
@Gargron if there were pinned toots u could say if somethin like that wasnt pinned it wasnt u
@Gargron what is it ?
@Gargron It would be cool if keybase supported a mastodon proof
so keybase like, supports masto fo reels or is that just walls of text copypaste now w
@Gargron I think that was a kind of joke...
This verifies a connection to my Keybase account, which also links to my GitHub and Twitter accounts, it's signed using the key listed on zeonfederated.com, which was my domain for many years and uses SSL.
@Gargron you should add your mastodon contact information to the top of zeonfederated.com ! bump twitter a notch or two ;)
@Gargron I still think rel="me" (and maybe rel="notme") is a better answer than adding yet another thing to check as a key.
@Gargron what stops people from doing a copypasta on the thing you just published?
@ajroach42 The message says "I am Gargron@mastodon.social" 😂
@Gargron oh. Derp. I guess that make sense.
@memeity @ajroach42 You can't do that because you don't have my private key that I sign it with.
@Gargron Can't a fake account just copy and paste that into their own toot?
@deadsuperhero @Gargron no. because if you do something like copy that into a file and then do something like `keybase verify < file` it's linked to his keybase, but also has a message that includes username @ instance
@Gargron @deadsuperhero someone _could_ just copy/paste that but it wouldn't do them any good
@Gargron @deadsuperhero you can verify it using keybase.. https://ryanmaynard.co/mastodon-keybase
@donnerdrummel @Gargron Sorry, I don't think this is entirely clear. Maybe I'm missing something.
I get that only one person can generate an authentic signature; an imitator cannot easily generate their own. That said, can't the text in the top-level post here be copied and pasted into an entirely new status by an imitator, and still essentially be a valid signature that checks out? It's not like accounts are tethered to Keybase accounts.
@deadsuperhero @donnerdrummel The signed text names my account
@Gargron @donnerdrummel Got it, that seems pretty practical.
@bob @donnerdrummel @Gargron There are pros and cons in deciding whether to store those credentials on the server somewhere, or shift the dependencies to a third party.
@Gargron “obvious” for some non-zero amount of work to make it obvious. Better than nothing, though!
@Gargron How can we tell if you're the right Eugen behind this account?