Skip to content

To avoid impersonation each message should be signed #17

Description

@bourgeoa

This has been implemented in SolidOS chat.
Using public/private key stored on the msg creator pod.

Discovering the private key is made complex to the owner by protecting access by an ACL Read only by the owner.

For SolidOS reference

Activity

  1. changed the title [-]To avoid impersonation each message should be verified[/-] [+]To avoid impersonation each message should be signed[/+] on Jan 10, 2026
  2. melvincarvalho commented on Jan 15, 2026

    @melvincarvalho
    Contributor

    Thanks for raising this! Message signing is definitely important for preventing impersonation.

    Since you implemented the original in SolidOS, I'd love your feedback on porting it to solid-chat/app. Here's my understanding of the approach:

    Implementation Sketch (based on SolidOS)

    1. Use Schnorr signatures (secp256k1)

    import { schnorr } from '@noble/curves/secp256k1'
    import { sha256 } from '@noble/hashes/sha256'

    2. Sign on send

    const msg = { id: msgUri, created: timestamp, content: text, maker: webId }
    const hash = sha256(JSON.stringify(msg))
    const sig = schnorr.sign(hash, privateKey)
    
    ins.push($rdf.st(msgNode, SEC('proofValue'), sig, doc))

    3. Verify on render

    const signature = store.any(msgNode, SEC('proofValue'))
    const publicKey = await getPublicKey(makerWebId)
    const valid = schnorr.verify(signature, hash, publicKey)
    
    if (!signature) messageRow.style.background = 'red'  // unsigned

    4. Key storage

    <#me> solid:publicKey "HEX_PUBLIC_KEY" .  # world-readable
    <#me> solid:privateKey "HEX_PRIVATE_KEY" . # owner-only ACL

    Is this the right approach? Any gotchas or lessons learned from the SolidOS implementation we should know about?

    (We have more detailed analysis in #18 including security concerns)

  3. bourgeoa commented on Jan 15, 2026

    @bourgeoa
    Author

    Any gotchas or lessons learned from the SolidOS implementation we should know about?

    • the key management system never broke but use is not high
    • there is no incentive for a user to delete the private key.
    • if missing the public key is automatically recreated by the chat-app when an owner use the SolidOS chat
    • security side is in my opinion high enough due to it's usage : only in chat even private only

    The main issue is the key creation/re-creation that is SolidOS chat dependant.

    A better way would be SolidOS dependant. But where ?
    I was thinking to solid-logic near authentication.
    The draw back is that only SolidOS user can create the key.
    I don't think it is a good idea to have it created by any app.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions