Post #3650066
2026-07-07 10:29 UTC
Replies (1)
-
@deFractal@infosec.exchange 2026-07-07 13:49
@ohir@social.vivaldi.net The point of “social vouching,” as I mean the term, is that if, for example, someone joins Infosec Exchange or any instance which federates with it, and cites me as someone who knows they’re human, their account approval remains on hold till I confirm, “yes, I know that’s a person.” If I respond that I don’t know that person, their application gets denied. If I vouch for a bunch of accounts I don’t know to belong to people, and they turn out to be bots, presumably my account gets suspended, and I lose the ability to vouch for new users. Under this system, to join the #Fediverse, someone already here would have to already know you’re not a bot. To avoid fatiguing one person with requests, presumably there’d need to be a limit on pending requests per person. If someone deliberately or negligently lets in a bunch of undisclosed bots, or if a bot gets in and auto-approves a bunch more bots, the tree of which account approved which could be traced back (through cooperation of administrators across instances) to ots first common node, to identify all the approved bot accounts and the person who approved them or at least the first of them. There’s enough people here that, in principle, this may be feasible, but I’m not sure. There may still be actual people who want to join but have not even a passing acquaintance with anyone who already has an account on some Fediverse instance that’s federated with most of the others, in which case, some secondary system may be necessary. There may be some risk to done applicants in disclosing to the administrator of the instance to which they apply that a particular pre-existing approved user knows the applicant at least well enough to assure that they exist, but I’m not sure. I just suggested the first idea that came to mind that’d be a step more open than making instance joining by invitation only.