Elektrine lite

← Feed

@hallam@infosec.exchange

Post #2175092

2023-03-30 14:14 UTC

@markd@hachyderm.io I think we need to go into a bit of semiotics at this point. A callsign is a name, it has the property of thirdness, the relationship between the signifier and the signified is purely a matter of convention. A fingerprint such as a UDF has the property of secondness, the signifier is derived from the signified by a formal construction (SHA2/SHA3) As a result, fingerprints are going to be much more robust as identifiers when used internally. The role of callsigns is really limited to hailing, that is establishing connections between parties. So while MASHZ-E3WR4-.. is the better unique identifier for the machines, there is a value to that layer of indirection. You can put @markd@infosec.exchange on your business card for instance. You can give it out over the phone. My vision here is that we use this technology to support applications like healthcare so you give your callsign to your doctor and it is used as a locator for your private information. So I call up the pharmacy on a legacy telephone, give my callsign @hallam@infosec.exchange and I get a 2FA challenge to my watch to prove I am me. That is not a 1% requirement.

Replies (1)

  • @markd@hachyderm.io 2023-03-31 03:46

    @hallam@infosec.exchange You are going further than I was thinking. My goal is that you own your data forever. When you establish a relationship with a social media/fediverse/blog site you give them your forever domain and credentials so that they store your content in some designated spot on your forever domain. With a few APIs conventions anyone can implement a forever domain server which social media/blog sites interact with and render from. MASHZ... is a trigger pattern to recognize a forever domain.

    Open ##2175093