You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
To avoid impersonation each message should be signed #17
changed the title [-]To avoid impersonation each message should be verified[/-][+]To avoid impersonation each message should be signed[/+]on Jan 10, 2026
Any gotchas or lessons learned from the SolidOS implementation we should know about?
the key management system never broke but use is not high
there is no incentive for a user to delete the private key.
if missing the public key is automatically recreated by the chat-app when an owner use the SolidOS chat
security side is in my opinion high enough due to it's usage : only in chat even private only
The main issue is the key creation/re-creation that is SolidOS chat dependant.
A better way would be SolidOS dependant. But where ?
I was thinking to solid-logic near authentication.
The draw back is that only SolidOS user can create the key.
I don't think it is a good idea to have it created by any app.
This has been implemented in SolidOS chat.
Using public/private key stored on the msg creator pod.
Discovering the private key is made complex to the owner by protecting access by an ACL
Readonly by theowner.For SolidOS reference