@micahflee Is it anything you could help with on github?
#MastoDev
@Falkreon the hard problems would be key management, key verification, and multi-device support I think
@micahflee I guess. I feel like associating pubkeys with accounts really needs to be addressed in the scope of OAuth though. Sort of tangential to mastodon.
@Falkreon it's not an easy problem to solve -- no one has solved it really well yet anywhere else either.
If it's addressed through OAuth, then do you trust your OAuth service to act as a CA and to not facilitate MITM attacks? Do you try to build in a web of trust like with PGP? Or do you do TOFU with fingerprint verification like Signal (I think this is the best option)?
@micahflee I feel like PGP was made to solve exactly this kind of problem. Would we even need to change anything, except maybe relaxing the 500-character limit?