{"p":"","h":{"iv":"ROXSYW+cfvEbFHu5","at":"ocxplSQjdRC3tXEtB/9/wg=="}}

@feditips so I think fedifed is a useful signal for the legitimacy of an account. Though it shouldn't bill itself as the one and only solution.

Given the skill at which some people set up phishing web sites that are indistinguishable from the legitimate site a sufficiently motivated attacker may still be able to impersonate someone who is using rel=me validation.

Also I think it has a time limit for its utility in its current form as the pool of people subject to impersonation attacks will change over the years and "validated by twitter befor elno" is frozen in time.

Over the long term it might help to have some identity verification services specializing in certain countries or communities being willing to attest to high value targets identities

Just because they say their a central authority doesn't mean anyone has to believe they're a central authority.

0
Share
Share on Mastodon
Share on Twitter
Share on Facebook
Share on Linkedin
Replies