Elektrine lite

← Feed

@lumi@snug.moe

Post #2478175

2026-04-23 22:37 UTC

@hipsterelectron@circumstances.run @mollyim@fosstodon.org i feel like this issue could be addressed by requiring invites and/or introductions. it could also be augmented with web of trust, possibly i think this would work with adding contacts and with small groups, but for large groups i feel the point-to-point model becomes more of a burden and many of its advantages will be lost. at that point you also will likely not want double ratchet anymore, or you may want to ditch e2ee entirely. big community spaces are a whole other use case that i am not covering here so, with this, invite links/codes need to be generated before you can add someone, these could be one-use, limited-time use, limited-count use or have some other criteria. these also should be revocable in case someone abuses them. in case of massive spam, the client can detect that one invite is used a lot in rapid succession and pre-emptively block it, notifying the user. possibly quarantining every add since the flood started and having the user manually confirm it (or bulk deny) this means that you cannot add someone directly using their identity, however. maybe some revocable human-readable invite shortcode mechanism could be made for this? i don't know this could also be combined with approaches like web-of-trust, if your contacts are willing to expose parts of their social graphs. maybe there are ways to do this without revealing too much information? i don't know another way to add someone would be via introductions via mutual contacts. i think it is alright to assume you would trust your contacts at least somewhat the client can keep track of the graph of how people got invited, by who they got introduced, etc, to make it easier to detect issues and address them

Replies (0)

No replies.