Elektrine lite

← Feed

@markd@hachyderm.io

Post #2175091

2023-03-30 05:05 UTC

@hallam@infosec.exchange For me, I'm happy to post here as @markd@hachyderm.io and couldn't care less whether anyone believes my "callsign" or not. And most readers don't care anyway. But in another forum @hallam might need to present serious credentials as proved by https://callsigns so you go to the trouble of supplying credentials and getting validated. But that's a 1% activity. What the callsigns website does is provide the "reverse DNS" confirmation that your claim to @hallam in their namespace is valid.

Replies (1)

  • @hallam@infosec.exchange 2023-03-30 14:14

    @markd@hachyderm.io I think we need to go into a bit of semiotics at this point. A callsign is a name, it has the property of thirdness, the relationship between the signifier and the signified is purely a matter of convention. A fingerprint such as a UDF has the property of secondness, the signifier is derived from the signified by a formal construction (SHA2/SHA3) As a result, fingerprints are going to be much more robust as identifiers when used internally. The role of callsigns is really limited to hailing, that is establishing connections between parties. So while MASHZ-E3WR4-.. is the better unique identifier for the machines, there is a value to that layer of indirection. You can put @markd@infosec.exchange on your business card for instance. You can give it out over the phone. My vision here is that we use this technology to support applications like healthcare so you give your callsign to your doctor and it is used as a locator for your private information. So I call up the pharmacy on a legacy telephone, give my callsign @hallam@infosec.exchange and I get a 2FA challenge to my watch to prove I am me. That is not a 1% requirement.

    Open ##2175092