Conversation

new jynpost https://jyn.dev/distributed-identity/

yes this mentions ATProto, no it's not about Bluesky. please be normal y'all i'm trusting you.

5
0
1

@jyn is gpg key metadata mutable? i wonder if could integrate into the existing git signing stuff for association of commit to a crypto ID rather than mutable identity

1
0
0

@cb my understanding of GPG is that once it’s on a keyserver it’s basically there forever
i don’t know if that’s true but that’s my understanding

1
0
0

@cb you could imagine a setup where the public key doesn’t actually have any identity attached. that would work i think, you’d still sign like normal but other people couldn’t see who signed it

0
0
0

@jyn

> Changing names after the fact, in such a way that the previous name isn't detectable.

This is almost immediately going to be used for identity fraud. I'm highly concerned of such a feature. Also don't forget that a bunch of people would spinn up archiving and tracking services to counter this almost immediately too.

1
0
0

@agowa338 how is the “identity fraud” any different than git letting you run git config user.name “Linus Torvalds”?

yes, archivers are a problem as mentioned in the post, but at least this way you have some amount of control over your identity. the goal isn’t to make it impossible to find you, it’s to make it annoying enough that people give up.

0
0
0
@jyn This has for the past quite a few years been one of my big annoyances about git, every now and then I look at some historical commits and just gets a friends deadname shoved in my face which at least to me feels uncomfortable.

I think something like what you propose here would be good.

Maybe something like webfinger could also be used though then you bind yourself up on a domain.
1
0
1

@erk did:web would totally work! it goes directly through a domain rather than through a PDS. it does mean if you ever lose control of the domain that you lose the identity, though.

0
0
1